フェイルオーバーマネージャーのパーミッションの拡張

Failover Managerのインストール中に、インストーラーは efm という名前のユーザーを作成します。 efm には、通常データベース所有者またはオペレーティングシステムのスーパーユーザーに制限されている管理機能を実行するための十分な特権がありません。

  • データベースのスーパーユーザー特権を必要とする管理機能を実行する場合、 efm は efm_db_functions スクリプトを呼び出します。

  • オペレーティングシステムのスーパーユーザー特権を必要とする管理機能を実行する場合、 efm は efm_root_functions スクリプトを呼び出します。

  • 仮想IPアドレスの割り当てまたは解放時に、efmは efm_address script を呼び出します。

efm_db_functions または efm_root_functions スクリプトは、 efm ユーザーの代わりに管理機能を実行します。

sudoersファイルには、ユーザー efm が postgres または enterprisedb が所有するクラスターのFailover Managerサービスを制御できるようにするエントリが含まれています。 sudoersファイルのコピーを変更して、他のユーザーが所有するPostgresクラスターを efm に管理する権限を付与できます。

efm-39 ファイルは /etc/sudoers.d にあり、次のエントリが含まれています:

# Copyright EnterpriseDB Corporation, 2014-2020. All Rights Reserved.
#
# Do not edit this file. Changes to the file may be overwritten
# during an upgrade.
#
# This file assumes you are running your efm cluster as user
# 'efm'. If not, then you will need to copy this file.
# Allow user 'efm' to sudo efm_db_functions as either 'postgres'
# or 'enterprisedb'. If you run your db service under a
# non-default account, you will need to copy this file to grant
# the proper permissions and specify the account in your efm
# cluster properties file by changing the 'db.service.owner'
# property.

efm ALL=(postgres) NOPASSWD: /usr/edb/efm-3.9 /bin/efm_db_functions
efm ALL=(enterprisedb) NOPASSWD: /usr/edb/efm-3.9
/bin/efm_db_functions

# Allow user 'efm' to sudo efm_root_functions as 'root' to
# write/delete the PID file, validate the db.service.owner
# property, etc.
efm ALL=(ALL) NOPASSWD: /usr/edb/efm-3.9 /bin/efm_root_functions
# Allow user 'efm' to sudo efm_address as root for VIP tasks.
efm ALL=(ALL) NOPASSWD: /usr/edb/efm-3.9 /bin/efm_address
# relax tty requirement for user 'efm'
Defaults:efm !requiretty

Failover Managerを使用して、 postgres または enterprisedb 以外のユーザーが所有するクラスターを監視している場合は、 efm-38 ファイルのコピーを作成し、ユーザーがアクセスできるようにコンテンツを変更しますクラスターを管理する efm_functions スクリプト。

権限の問題のためにエージェントを開始できない場合、デフォルトの/ etc / sudoersファイルのファイルの最後に次の行が含まれていることを確認してください。

## Read drop-in files from /etc/sudoers.d (the # here does not # mean a comment)

#includedir /etc/sudoers.d

sudoなしでフェールオーバーマネージャーを実行する

デフォルトでは、Failover Managerはsudoを使用して、システム機能へのアクセスを安全に管理します。 sudoアクセスなしで実行するようにフェールオーバーマネージャーを構成する場合、次の操作にはルートアクセスが必要であることに注意してください。

  • Failover Manager RPMをインストールします。

  • フェールオーバーマネージャーのセットアップタスクを実行します。

sudoを使用せずにフェールオーバーマネージャーを実行するには、フェールオーバーマネージャーに代わって管理機能を実行する権限を持つデータベースプロセスの所有者を選択する必要があります。ユーザーは、デフォルトのデータベーススーパーユーザー(enterprisedbやpostgresなど)または別の特権ユーザーである可能性があります。ユーザーを選択した後:

  1. 次のコマンドを使用して、ユーザーを efm グループに追加します。

    usermod -a -G efm enterprisedb

    これにより、ユーザーは /var/run/efm-3.9 および /var/lock/efm-3.9 に書き込むことができます。

  2. クラスター名を再利用する場合は、以前に作成したログファイルを削除します。新しいユーザーは、デフォルト(または他の)所有者が作成したログファイルに書き込むことができません。

  3. クラスタプロパティテンプレートファイルとノードテンプレートファイルをコピーします。

    su - enterprisedb

    cp /etc/edb/efm-3.9/efm.properties.in <directory/cluster_name>.properties

    cp /etc/edb/efm-3.9/efm.nodes.in <directory>/<cluster_name>.nodes

    次に、クラスタープロパティファイルを変更し、 db.service.owner プロパティでユーザーの名前を指定します。 db.service.name プロパティが空白であることも確認する必要があります。 sudoがないと、ルートアクセスなしでサービスを実行できません。

構成を変更した後、新しいユーザーは次のコマンドでフェールオーバーマネージャーを制御できます。

/usr/edb/efm-3.9/bin/runefm.sh start|stop <directory/cluster_name>.properties

ここで、 <directory/cluster_name.properties> はクラスタープロパティファイルのフルパスと名前を指定します。ユーザーは、デフォルト以外のユーザーがエージェントを制御しているとき、またはefmスクリプトを使用しているときは常に、プロパティファイルへのフルパスを提供する必要があることに注意してください。

新しいユーザーがFailover Managerをサービスとして管理できるようにするには、カスタムスクリプトまたはユニットファイルを提供する必要があります。

フェイルオーバーマネージャーは、 /usr/edb/efm-3.9/bin/secure/ にあるmanage-vipという名前のバイナリを使用して、sudo権限なしでVIP管理操作を実行します。このスクリプトは、setuidを使用して、仮想IPアドレスの管理に必要な特権を取得します。

  • このディレクトリには、ルートと efm グループのユーザーのみがアクセスできます。

  • バイナリはルートと efm グループによってのみ実行可能です。

セキュリティ上の理由から、 /usr/edb/efm-3.9/bin/secure/ ディレクトリまたは manage-vip スクリプトのアクセス権限を変更しないことをお勧めします。

sudoなしでFailover Managerを使用する方法の詳細については、次のWebサイトをご覧ください。

https://www.enterprisedb.com/blog/running-edb-postgres-failover-manager-without-sudo