クラスタープロパティファイル¶
Failover Managerの各ノードクラスターには、それが存在する個々のノードのプロパティを含むプロパティファイル(デフォルトでは efm.properties という名前)があります。Failover Managerインストーラーは、 /etc/edb/efm-4.0 ディレクトリに efm.properties.in という名前のプロパティファイルのファイルテンプレートを作成します。
Failover Managerを完了した後インストールの場合、ファイルの内容を変更する前にテンプレートの作業用コピーを作成する必要があります。
# cp /etc/edb/efm-4.00/efm.properties.in /etc/edb/efm-4.00/efm.properties
テンプレートファイルをコピーした後、ファイルの所有者を efm に変更します。
# chown efm:efm efm.properties
Please note: : By default, Failover Manager expects the cluster properties
file to be named efm.properties. If you name the properties file
something other than efm.properties, you must modify the service script
or unit file to instruct Failover Manager to use a different name.
クラスタープロパティファイルを作成したら、必要に応じて構成パラメーター値を追加(または変更)します。各プロパティの詳細については、 :ref:`クラスタープロパティの指定<specifying_cluster_properties>`を参照してください。
プロパティファイルは root によって所有されています。Failover Managerサービススクリプトは /etc/edb/efm-4.0 directory 内のファイルを見つけることを期待しています。プロパティファイルを別の場所に移動する場合、新しい場所を指定するシンボリックリンクを作成する必要があります。
注意: :プロパティファイルで参照されるすべてのユーザースクリプトは、Failover Managerとして呼び出されます。ユーザー。
クラスタプロパティの指定¶
クラスタープロパティファイルにリストされているプロパティを使用して、Failover Managerの接続プロパティと動作を指定できます。クラスター。プロパティ設定の変更は、Failover Managerの場合に適用されます開始します。プロパティ値を変更した場合、再起動する必要がありますFailover Manager変更を適用します。
プロパティ値では大文字と小文字が区別されます。Postgresはパラメーター値に引用符付き文字列を使用しますが、Failover Managerプロパティ値に引用符付き文字列を使用できません。たとえば、Postgres構成パラメーターでIPアドレスを次のように指定できます。
listen_addresses='192.168.2.47'
Failover Manager値を引用符で囲まないでください。
bind.address=192.168.2.54:7800
efm.properties ファイルのプロパティを使用して、Failover Managerの接続、管理、および操作の詳細を指定します。
凡例:次の表:
A:エージェントノードで必要W:監視ノードで必須Y:はい
プロパティ名 |
A |
W |
デフォルト値 |
コメント |
|---|---|---|---|---|
Y |
Y |
データベースのユーザー名 |
||
Y |
Y |
``efmencrypt``を使用して暗号化されたパスワード |
||
Y |
Y |
この値はすべてのエージェントで同じでなければなりません |
||
Y |
Y |
データベース名 |
||
Y |
db.databaseの$PGDATAディレクトリの所有者 |
|||
データベースをサービスとして実行する場合は必須 |
||||
Y |
'/usr/edb/as12/bin'などのpg_controldata/pg_ctlコマンドを含むディレクトリ |
|||
Y |
クエリ'showdata_directory;'の出力と同じ |
|||
クエリ'showconfig_file;'の出力と同じです。*db.data.dir*と同じでない場合に指定する必要があります |
||||
Y |
Y |
無効にする |
:ref:`note<jdbc.note>`を参照してください |
|
この値は、すべてのエージェントで同じでなければなりません。通知スクリプトを使用する場合は空白のままにすることができます |
||||
デフォルトの``efm@localhost``を使用するには空白のままにします |
||||
Y |
Y |
情報 |
:ref:`通知のリスト<notifications>`を参照してください |
|
user.emailプロパティを使用しない場合は必須。両方のパラメーターを一緒に使用できます |
||||
Y |
Y |
例:<ip_address>:<port> |
||
例:<ip_address/hostname> |
||||
Y |
Y |
7809 |
デフォルトのポートがすでに使用されている場合は変更します |
|
Y |
Y |
説明を見る |
||
Y |
10 |
|||
Y |
60 |
|||
Y |
10 |
|||
Y |
Y |
10 |
||
Y |
Y |
50 |
この値はすべてのエージェントで同じでなければなりません |
|
Y |
Y |
偽 |
この値はすべてのエージェントで同じでなければなりません |
|
Y |
本当 |
|||
Y |
本当 |
|||
Y |
Y |
偽 |
||
Y |
0 |
|||
Y |
Y |
8.8.8.8 |
||
Y |
Y |
/bin/ping-q-c3-w5 |
||
Y |
Y |
偽 |
||
Y |
Y |
偽 |
||
Y |
0 |
|||
Y |
Y |
本当 |
||
Y |
本当 |
この値はすべてのエージェントで同じでなければなりません |
||
プロモーション可能 |
Y |
本当 |
||
Y |
Y |
本当 |
この値はすべてのエージェントで同じでなければなりません |
|
0 |
||||
元のプライマリデータベースをスタンバイとして起動する前に、primary_conninfoエントリのapplication_name部分をこのプロパティ値で置き換えるように設定します。 |
||||
例:restore.command=scp
<db_service_owner>@%h:
<archive_path>/%f%p
|
||||
Y |
偽 |
|||
Y |
偽 |
|||
Y |
Y |
0 |
この値はすべてのノードで同じでなければなりません |
|
Y |
2 |
|||
60 |
||||
Y |
0 |
|||
(virtual.ip.singleを参照) |
VIPを指定しない場合は空白のままにします |
|||
VIPを指定する場合は必須 |
||||
VIPを指定する場合は必須 |
||||
Y |
Y |
はい |
この値はすべてのノードで同じでなければなりません |
|
Y |
Y |
はい |
||
例:script.load.balancer.attach=
/<パス>/<アタッチスクリプト>%h%t
|
||||
例:script.load.balancer.detach=
/<パス>/<デタッチスクリプト>%h%t
|
||||
例:script.fence=
/<パス>/<スクリプト名>%p%f
|
||||
例:script.post.promotion=
/<パス>/<スクリプト名>%f%p
|
||||
例:script.resumed=
/<パス>/<スクリプト名>
|
||||
例:script.db.failure=
/<パス>/<スクリプト名>
|
||||
例:script.primary.isolated=
/<パス>/<スクリプト名>
|
||||
例:script.remote.pre.promotion=
/<パス>/<スクリプト名>%p
|
||||
例:script.remote.post.promotion=
/<パス>/<スクリプト名>%p
|
||||
例:script.custom.monitor=
/<パス>/<スクリプト名>
|
||||
カスタム監視スクリプトが指定されている場合は必須 |
||||
カスタム監視スクリプトが指定されている場合は必須 |
||||
カスタム監視スクリプトが指定されている場合は必須 |
||||
Y |
Y |
須藤 |
||
Y |
Y |
sudo-u%u |
||
指定しない場合、デフォルトは'/var/lock/efm-<version>'になります |
||||
指定しない場合、デフォルトは``/var/log/efm-<version>``になります |
||||
ローカルホスト |
||||
514 |
||||
UDP |
||||
Y |
Y |
本当 |
||
Y |
Y |
偽 |
||
情報 |
||||
情報 |
||||
-Xmx128m |
次のプロパティを使用して、Failover Managerの接続の詳細を指定しますクラスター:
# The value for the password property should be the output from
# 'efm encrypt' -- do not include a cleartext password here. To
# prevent accidental sharing of passwords among clusters, the
# cluster name is incorporated into the encrypted password. If
# you change the cluster name (the name of this file), you must
# encrypt the password again with the new name.
# The db.port property must be the same for all nodes.
db.user=
db.password.encrypted=
db.port=
db.database=
指定された db.user には、Failover Managerの代わりに選択されたPostgreSQLコマンドを呼び出すための十分な特権が必要です。詳細については、 :doc:`前提条件<前提条件>`を参照してください。
データベースユーザーのパスワードの暗号化については、 :doc:`データベースパスワードの暗号化<encrypting_database_password>`を参照してください。
db.service.owner プロパティを使用して、フェールオーバーマネージャーによって管理されているクラスターを所有するオペレーティングシステムユーザーの名前を指定します。このプロパティは、専用の監視ノードでは必要ありません。
# This property tells EFM which OS user owns the $PGDATA dir for
# the 'db.database'. By default, the owner is either 'postgres'
# for PostgreSQL or 'enterprisedb' for EDB Postgres Advanced
# Server. However, if you have configured your db to run as a
# different user, you will need to copy the /etc/sudoers.d/efm-XX
# conf file to grant the necessary permissions to your db owner.
#
# This username must have write permission to the
# 'db.data.dir' specified below.
db.service.owner=
サービスを開始または停止するときにserviceコマンドまたはsystemctlコマンドを使用する場合は、 db.service.name プロパティでデータベースサービスの名前を指定します。
# Specify the proper service name in order to use service commands
# rather than pg_ctl to start/stop/restart a database. For example, if
# this property is set, then 'service <name> restart' or 'systemctl
# restart <name>'
# (depending on OS version) will be used to restart the database rather
# than pg_ctl.
# This property is required if running the database as a service.
db.service.name=
データベースサービスを開始または停止するたびに、同じサービス制御メカニズム(pg_ctl、service、またはsystemctl)を使用する必要があります。 pg_ctl プログラムを使用してサービスを制御する場合は、 db.bin プロパティで pg_ctl プログラムの場所を指定します。
# Specify the directory containing the pg_controldata/pg_ctl commands,
# for example:
# /usr/edb/as11/bin. Unless the db.service.name property is used, the
# pg_ctl command is used to start/stop/restart databases as needed
# after a failover or switchover. This property is required.
db.bin=
昇格中にクラスターのプライマリノードで回復ファイルが書き込まれる場所を指定するには、 db.data.dir プロパティを使用します。このプロパティは、プライマリノードとスタンバイノードで必要です。専用の監視ノードでは必要ありません。
# For database version 12 and up, this is the directory where a
# standby.signal file will exist for a standby node. For previous
# versions, this is the location of the db recovery.conf file on
# the node.
# After a failover, the recovery.conf files on remaining standbys are
# changed to point to the new primary db (a copy of the original is made
# first). On a primary node, a recovery.conf file will be written during
# failover and promotion to ensure that the primary node can not be
# restarted as the primary database.
# This corresponds to database environment variable PGDATA and should
# be same as the output of query 'show data_directory;' on respective
# database.
db.data.dir=
データベース設定ファイルが recovery.conf または standby.signal ファイルと同じディレクトリに保存されていない場合は、 db.config.dir プロパティを使用してデータベース設定ファイルの場所を指定します。これは、AdvancedServerまたはPostgreSQLインストールの config_file パラメーターディレクトリで指定された値である必要があります。この値は、データベースを停止、起動、または再起動するときにPostgresの data ディレクトリの場所として使用されます。
# Specify the location of database configuration files if they are
# not contained in the same location as the recovery.conf or
# standby.signal file. This is most likely the case for Debian
# installations. The location specified will be used as the -D value
# (the location of the data directory for the cluster) when calling
# pg_ctl to start or stop the database. If this property is blank,
# the db.data.dir location specified by the db.data.dir property will
# be used. This corresponds to the output of query 'show config_file;'
# on respective database.
db.config.dir=
データベース設定ファイルの詳細については、`PostgreSQLウェブサイト<https://www.postgresql.org/docs/current/runtime-config-file-locations.html>`_をご覧ください。
jdbc.sslmode プロパティを使用してFailover Managerを指示しますSSL接続を使用します。デフォルトでは、SSLは無効になっています。
# Use the jdbc.sslmode property to enable ssl for EFM
# connections. Setting this property to anything but 'disable'
# will force the agents to use 'ssl=true' for all JDBC database
# connections (to both local and remote databases).
# Valid values are:
#
# disable - Do not use ssl for connections.
# verify-ca - EFM will perform CA verification before allowing
# the certificate.
# require - Verification will not be performed on the server
# certificate.
jdbc.sslmode=disable
注釈
jdbc.sslmode の値を verify-ca に設定し、証明書の検証にJavaトラストストアを使用する場合は、次の値を設定する必要があります。
jdbc.properties=sslfactory=org.postgresql.ssl.DefaultJavaSSLFactory
SSLの構成と使用の詳細については、以下を参照してください。
そして
user.email プロパティを使用して、FailoverManagerから送信された通知を受信する電子メールアドレス(または複数の電子メールアドレス)を指定します。
# Email address(es) for notifications. The value of this
# property must be the same across all agents. Multiple email
# addresses must be separated by space. If using a notification
# script instead, this property can be left blank.
user.email=
from.email プロパティは、Failover Managerからの電子メール通知で送信者のアドレスとして使用される値を指定します。次のことができます。
デフォルト値(
efm@localhost)を使用するには、from.emailを空白のままにします。メールアドレスのカスタム値を指定します。
%hプレースホルダーを使用してノードホストの名前を表すカスタムメールアドレスを指定します(例:example@%h)。プレースホルダーは、Linuxホスト名ユーティリティによって返されるホストの名前に置き換えられます。
通知の詳細については、 :doc:`Notifications<notifications>`を参照してください。
# Use the from.email property to specify the from email address that
# will be used for email notifications. Use the %h placeholder to
# represent the name of the node host (e.g. example@%h). The
# placeholder will be replaced with the name of the host as returned
# by the hostname command.
# Leave blank to use the default, efm@localhost.
from.email=
notification.level プロパティを使用して、Failover Managerの最小の重大度レベルを指定しますユーザー通知を送信するか、通知スクリプトが呼び出されます。通知の完全なリストについては、 :doc:`通知<notifications>`を参照してください。
# Minimum severity level of notifications that will be sent by
# the agent. The minimum level also applies to the notification
# script (below). Valid values are INFO, WARNING, and SEVERE.
# A list of notifications is grouped by severity in the user's
# guide.
notification.level=INFO
notification.text.prefix プロパティを使用して、すべての通知の先頭に追加するテキストを指定します。
# Text to add to the beginning of every notification. This could
# be used to help identify what the cluster is used for, the role
# of this node, etc. To use multiple lines, add a backslash \ to
# the end of a line of text. To include a newline use \n.
# Example:
# notification.text.prefix=Development cluster for Example dept.\n\
# Used by Dev and QA \
# See Example group for questions.
notification.text.prefix=
script.notification プロパティを使用して、通知サービスとして機能するユーザー指定のスクリプトへのパスを指定します。スクリプトには、メッセージの件名とメッセージ本文が渡されます。スクリプトは毎回呼び出されますFailover Managerユーザー通知を生成します。
# Absolute path to script run for user notifications.
#
# This is an optional user-supplied script that can be used for
# notifications instead of email. This is required if not using
# email notifications. Either/both can be used. The script will
# be passed two parameters: the message subject and the message
# body.
script.notification=
bind.address プロパティは、Failover Managerの現在のノード上のエージェントのIPアドレスとポート番号を指定しますクラスター。
# This property specifies the ip address and port that jgroups
# will bind to on this node. The value is of the form
# <ip>:<port>.
# Note that the port specified here is used for communicating
# with other nodes, and is not the same as the admin.port below,
# used only to communicate with the local agent to send control
# signals.
# For example, <provide_your_ip_address_here>:7800
bind.address=
external.address プロパティを使用して、NAT環境内の他のすべてのFailoverManagerエージェントとの通信に使用するIPアドレスまたはホスト名を指定します。
# This is the ip address/hostname to be used for communication with all
# other Failover Manager agents. All traffic towards this address
# should be routed by the network to the bind.address of the node.
# The value is in the ip/hostname format only. This address will be
# used in scenarios where nodes are on different networks and broadcast
# an IP address other than the bind.address to the external world.
external.address=
admin.port プロパティを使用して、Failover Managerのポートを指定します管理コマンドをリッスンします。
# This property controls the port binding of the administration
# server which is used for some commands (ie cluster-status). The
# default is 7809; you can modify this value if the port is
# already in use.
admin.port=7809
is.witness プロパティをtrueに設定して、現在のノードが監視ノードであることを示します。is.witnessがtrueの場合、ローカルエージェントはローカルデータベースが実行されているかどうかを確認しません。
# Specifies whether or not this is a witness node. Witness nodes
# do not have local databases running.
is.witness=
The Postgres pg_is_in_recovery() function is a boolean function that
reports the recovery state of a database. The function returns true if
the database is in recovery, or false if the database is not in
recovery. When an agent starts, it connects to the local database and
invokes the pg_is_in_recovery() function. If the server responds true,
the agent assumes the role of standby; if the server responds false, the
agent assumes the role of primary. If there is no local database, the
agent will assume an idle state.
注釈
is.witness が true の場合、Failover Managerリカバリ状態をチェックしません。
次のプロパティは、ローカルサーバーに適用されるプロパティを指定します。
local.periodプロパティは、データベースサーバーへの接続を試行する間隔を秒単位で指定します。local.timeoutプロパティは、エージェントがローカルデータベースサーバーからの肯定的な応答を待つ時間を指定します。local.timeout.finalプロパティは、現在のノード上のデータベースサーバーへの最後の接続試行後にエージェントが待機する時間を指定します。local.timeout.finalプロパティで指定された秒数内にデータベースから応答を受信しない場合、データベースは失敗したと見なされます。
たとえば、これらのプロパティのデフォルト値を指定すると、ローカルデータベースのチェックは10秒ごとに1回行われます。ローカルデータベースへの接続試行が60秒以内に正に戻らない場合、Failover Managerデータベースへの接続を最後に試みます。応答が10秒以内に受信されない場合、Failover Managerデータベース障害を宣言し、user.emailプロパティにリストされている管理者に通知します。これらのプロパティは、専用の監視ノードでは必要ありません。
# These properties apply to the connection(s) EFM uses to monitor
# the local database. Every 'local.period' seconds, a database
# check is made in a background thread. If the main monitoring
# thread does not see that any checks were successful in
# 'local.timeout' seconds, then the main thread makes a final
# check with a timeout value specified by the
# 'local.timeout.final' value. All values are in seconds.
# Whether EFM uses single or multiple connections for database
# checks is controlled by the 'db.reuse.connection.count'
# property.
local.period=10
local.timeout=60
local.timeout.final=10
必要に応じて、ビジネスモデルに合わせてこれらの値を変更する必要があります。
remote.timeout プロパティを使用して、エージェントがリモートデータベースサーバーからの応答を待機する秒数(つまり、フェールオーバーを実行する前にプライマリデータベースが実際にダウンしていることを確認するためにスタンバイエージェントが待機する時間)を指定します。
# Timeout for a call to check if a remote database is responsive.
# For example, this is how long a standby would wait for a
# DB ping request from itself and the witness to the primary DB
# before performing failover.
remote.timeout=10
node.timeout プロパティを使用して、ノードが失敗したかどうかを判断するときにエージェントがノードからの応答を待つ秒数を指定します。node.timeoutプロパティ値は、エージェント間の通信のタイムアウト値を指定します。クラスタプロパティファイルの他のタイムアウトプロパティは、エージェントからデータベースへの通信の値を指定します。
# The total amount of time in seconds to wait before determining
# that a node has failed or been disconnected from this node.
#
# The value of this property must be the same across all agents.
node.timeout=50
encrypt.agent.messages プロパティを使用して、エージェント間で送信されるメッセージを暗号化する必要があるかどうかを指定します。
# Set to true to encrypt messages that are sent between agents.
# This property must be the same on all agents or else the agents
# will not be able to connect.
encrypt.agent.messages=false
stop.isolated.primary プロパティを使用してFailover Managerを指示しますプライマリエージェントがデータベースの分離を検出した場合、データベースをシャットダウンします。true(デフォルト)の場合、Failover Manager script.primary.isolated プロパティで指定されたスクリプトを呼び出す前にデータベースを停止します。
# Shut down the database after a primary agent detects that it has
# been isolated from the majority of the efm cluster. If set to
# true, efm will stop the database before running the
# 'script.primary.isolated' script, if a script is specified.
stop.isolated.primary=true
stop.failed.primary プロパティを使用してFailover Managerを指示しますプライマリデータベースがデータベースに到達できない場合、プライマリデータベースをシャットダウンしようとします。 true の場合、Failover Managerデータベースをシャットダウンしようとした後、 script.db.failure プロパティで指定されたスクリプトを実行します。
# Attempt to shut down a failed primary database after EFM can no
# longer connect to it. This can be used for added safety in the
# case a failover is caused by a failure of the network on the
# primary node.
# If specified, a 'script.db.failure' script is run after this attempt.
stop.failed.primary=true
primary.shutdown.as.failure パラメーターを使用して、Failover Managerのシャットダウンを示します。プライマリノードのエージェントは障害として扱われる必要があります。このパラメーターが true に設定され、プライマリエージェントが(何らかの理由で)停止すると、クラスターはプライマリノード上のデータベースが実行されているかどうかを確認しようとします。
データベースに到達すると、エージェントのステータスを通知する通知が送信されます。
データベースに到達しない場合、フェイルオーバーが発生します。
# Treat a primary agent shutdown as a failure. This can be set to
# true to treat a primary agent shutdown as a failure situation,
# e.g. during the shutdown of a node, accidental or otherwise.
# Caution should be used when using this feature, as it could
# cause an unwanted promotion in the case of performing primary
# database maintenance.
# Please see the user's guide for more information.
primary.shutdown.as.failure=false
primary.shutdown.as.failure プロパティは、プライマリノードの偶発的なシャットダウンなどの障害ではなく、ユーザーエラーをキャッチするためのものです。ユーザーがプライマリを停止したように、ノードの適切なシャットダウンがクラスターの残りの部分に表示されるFailover Managerエージェント(たとえば、プライマリデータベースのメンテナンスを実行するため)。 primary.shutdown.as.failure プロパティを true に設定した場合、メンテナンスの実行時に注意する必要があります。
primary.shutdown.as.failure が true のときにプライマリデータベースでメンテナンスを実行するには、プライマリエージェントを停止し、プライマリエージェントが失敗したがデータベースがまだ実行されているという通知を受信するまで待機する必要があります。その後、プライマリデータベースを停止しても安全です。または、 efm stop-cluster コマンドを使用して、障害チェックを実行せずにすべてのエージェントを停止できます。
update.physical.slots.period プロパティを使用して、データベースバージョン12以降のスロットアドバンス頻度を定義します。 update.physical.slots.period がゼロ以外の値に設定されている場合、プライマリエージェントは update.physical.slots.period 秒ごとに物理複製スロットの現在の restart_lsn を読み取り、 pg_current_wal_lsn でこの情報を送信します``および primary_slot_name (postgresql.confファイルで設定されている場合)スタンバイに。物理スロットがまだ存在しない場合、このパラメーターをゼロ以外の値に設定すると、スロットが作成され、これらのスロットの restart_lsn parameter が更新されます。昇格できないスタンバイは新しいスロットを作成しませんが、存在する場合は更新します。
# Period in seconds between having the primary agent update promotable
# standbys with physical replication slot information so that
# the cluster will continue to use replication slots after a failover.
# Set to zero to turn off.
update.physical.slots.period=0
ping.server.ip プロパティを使用して、サーバーのIPアドレスを指定しますFailover Managerネットワーク接続に問題がないことを確認するために使用できます。
# This is the address of a well-known server that EFM can ping
# in an effort to determine network reachability issues. It
# might be the IP address of a nameserver within your corporate
# firewall or another server that *should* always be reachable
# via a 'ping' command from each of the EFM nodes.
#
# There are many reasons why this node might not be considered
# reachable: firewalls might be blocking the request, ICMP might
# be filtered out, etc.
#
# Do not use the IP address of any node in the EFM cluster
# (primary, standby, or witness) because this ping server is meant
# to provide an additional layer of information should the EFM
# nodes lose sight of each other.
#
# The installation default is Google's DNS server.
ping.server.ip=8.8.8.8
ping.server.command プロパティを使用して、ネットワーク接続のテストに使用するコマンドを指定します。
# This command will be used to test the reachability of certain
# nodes.
#
# Do not include an IP address or hostname on the end of
# this command - it will be added dynamically at runtime with the
# values contained in 'virtual.ip' and 'ping.server.ip'.
#
# Make sure this command returns reasonably quickly - test it
# from a shell command line first to make sure it works properly.
ping.server.command=/bin/ping -q -c3 -w5
auto.allow.hosts プロパティを使用して、許可されたホストリストを更新するために開始された最初のノードの.nodesファイルで指定されたアドレスを使用するようにサーバーに指示します。このプロパティを有効にする(auto.allow.hostsをtrueに設定する)と、クラスターの起動を簡素化できます。
# Have the first node started automatically add the addresses
# from its .nodes file to the allowed host list. This will make
# it faster to start the cluster when the initial set of hosts
# is already known.
auto.allow.hosts=false
stable.nodes.file プロパティを使用して、ノードがクラスターに参加またはクラスターから離脱するときにノードファイルを書き換えないようにサーバーに指示します。このプロパティは、不変のIPアドレスを持つクラスターで最も役立ちます。
# When set to true, EFM will not rewrite the .nodes file whenever
# new nodes join or leave the cluster. This can help starting a
# cluster in the cases where it is expected for member addresses
# to be mostly static, and combined with 'auto.allow.hosts' makes
# startup easier when learning failover manager.
stable.nodes.file=false
db.reuse.connection.count プロパティにより、管理者はFailover Managerの回数を指定できます。同じデータベース接続を再利用して、データベースの状態を確認します。デフォルト値は0です。これはFailover Managerを示す毎回新しい接続を作成します。このプロパティは、専用の監視ノードでは必要ありません。
# This property controls how many times a database connection is
# reused before creating a new one. If set to zero, a new
# connection will be created every time an agent pings its local
# database.
db.reuse.connection.count=0
auto.failover プロパティは自動フェイルオーバーを有効にします。デフォルトでは、auto.failoverはtrueに設定されています。
# Whether or not failover will happen automatically when the primary
# fails. Set to false if you want to receive the failover notifications
# but not have EFM actually perform the failover steps.
# The value of this property must be the same across all agents.
auto.failover=true
auto.reconfigure プロパティを使用してFailover Managerを指示しますプライマリスタンバイがプライマリに昇格した後、残りのスタンバイサーバーの自動再構成を有効または無効にします。プロパティを true に設定して自動再構成を有効にする(デフォルト)か、 false に設定して自動再構成を無効にします。このプロパティは、専用の監視ノードでは必要ありません。AdvancedServerまたはPostgreSQLバージョン11以前を使用している場合、再構成プロセス中に recovery.conf ファイルがバックアップされます。
# After a standby is promoted, Failover Manager will attempt to
# update the remaining standbys to use the new primary. For database
# versions before 12, Failover Manager will back up recovery.conf.
# Then it will change the host parameter of the primary_conninfo entry
# in recovery.conf or postgresql.auto.conf, and restart the database.
# The restart command is contained in either the efm_db_functions or
# efm_root_functions file; default when not running db as an os
# service is: "pg_ctl restart -m fast -w -t <timeout> -D <directory>"
# where the timeout is the local.timeout property value and the
# directory is specified by db.data.dir. To turn off
# automatic reconfiguration, set this property to false.
auto.reconfigure=true
注意: :primary_conninfo は、keyword=valueペアのスペース区切りリストです。
Use the promotable property to indicate that a node should not be
promoted. The promotable property is ignored when a primary agent is started.
This simplifies switching back to the original primary after a switchover or failover.
To override the setting, use the efm set-priority command at
runtime; for more information about the efm set-priority command, see
Using the efm Utility.
# A standby with this set to false will not be added to the
# failover priority list, and so will not be available for
# promotion. The property will be used whenever an agent starts
# as a standby or resumes as a standby after being idle. After
# startup/resume, the node can still be added or removed from the
# priority list with the 'efm set-priority' command. This
# property is required for all non-witness nodes.
promotable=true
同じ量のデータが複数のスタンバイノードに書き込まれ、フェイルオーバーが発生した場合、 use.replay.tiebreaker の値によってFailover Managerが決定されます。置換プライマリを選択します。Failover Managerに指示するには、 use.replay.tiebreaker プロパティを true に設定します。ログシーケンス番号で決定されるように、復旧から早くなるノードにフェールオーバーする。ログのシーケンス番号を無視し、ユーザー設定に基づいてノードを昇格させるには、 use.replay.tiebreaker を false に設定します。
# Use replay LSN value for tiebreaker when choosing a standby to
# promote before using failover priority. Set this property to true to
# consider replay location as more important than failover priority
# (as seen in cluster-status command) when choosing the "most ahead"
# standby to promote.
use.replay.tiebreaker=true
standby.restart.delay プロパティを使用して、昇格後に新しいプライマリを追跡するためにスタンバイが再構成(停止/開始)されるまで待機する時間を秒単位で指定します。
# Time in seconds for this standby to delay restarting to follow the
# primary after a promotion. This can be used to have standbys restart
# at different times to increase availability. Caution should be used
# when using this feature, as a delayed standby will not be following
# the new primary and care must be taken that the new primary retains
# enough WAL for the standby to follow it.
# Please see the user's guide for more information.
standby.restart.delay=0
application.name プロパティを使用して、古いプライマリノードをスタンバイとして再起動する前に primary_conninfo パラメーターにコピーされるアプリケーションの名前を指定できます。
# During a switchover, recovery settings are copied from a standby
# to the original primary. If the application.name property is set,
# Failover Manager will replace the application_name portion of the
# primary_conninfo entry with this property value before starting
# the original primary database as a standby. If this property is
# not set, Failover Manager will remove the parameter value
# from primary_conninfo.
application.name=
注意: プライマリおよびプロモーション可能なスタンバイに application.name プロパティを設定する必要があります。フェールオーバー/スイッチオーバーが発生した場合、プライマリノードが再びスタンバイノードになる可能性があります。
Use the restore.command property to instruct Failover Manager to update the restore_command when a new primary is promoted. %h represents the address of the new primary; Failover Manager will replace %h with the address of the new primary. %f and %p are placeholders used by the server. If the property is left blank, Failover Manager will not update the restore_command values on the standbys after a promotion.
`restore_command<https://www.postgresql.org/docs/current/runtime-config-wal.html#RUNTIME-CONFIG-WAL-ARCHIVE-RECOVERY>`_の使用の詳細については、PostgreSQLのドキュメントを参照してください。
# If the restore_command on a standby restores directly from the
# primary node, use this property to have Failover Manager change
# the command when a new primary is promoted.
#
# Use the %h placeholder to represent the address of the new primary.
# During promotion it will be replaced with the address of the new
# primary.
#
# If not specified, failover manager will not change the
# restore_command value, if any, on standby nodes.
#
# Example:
# restore.command=scp <db service owner>@%h:/var/lib/edb/as12/data/archive/%f %p
restore.command=
プライマリノードのデータベースパラメータ synchronous_standby_names は、データの受信を確認する同期スタンバイサーバーの名前と数を指定して、プライマリノードが書き込みトランザクションを受け入れることができるようにします。 reconfigure.num.sync プロパティがtrueに設定されている場合、Failover Manager同期スタンバイサーバーの数を減らし、プライマリノードの構成を再読み込みして現在の値を反映します。
# Reduce num_sync when the number of synchronous standbys drops
# below the value required by the primary database. If set to true,
# Failover Manager will reduce the number of standbys needed
# in the primary's synchronous_standby_names property and reload
# the primary configuration.
# Failover Manager will not reduce the number below 1, taking
# the primary out of synchronous replication, unless the
# reconfigure.sync.primary property is also set to true.
reconfigure.num.sync=false
スタンバイノードの数が必要なレベルを下回った場合、プライマリデータベースの同期レプリケーションモードを解除するには、 reconfigure.sync.primary プロパティを true に設定します。スタンバイカウントが低下した場合に通知を送信し、同期レプリケーションを中断しないようにするには、 reconfigure.sync.primary を false に設定します。
# Take the primary database out of synchronous replication mode when
# needed. If set to true, Failover Manager will clear the
# synchronous_standby_names configuration parameter on the primary
# if the number of synchronous standbys drops below the required
# level for the primary to accept writes.
# If set to false, Failover Manager will detect the situation but
# will only send a notification if the standby count drops below the
# required level.
#
# CAUTION: TAKING THE PRIMARY DATABASE OUT OF SYNCHRONOUS MODE MEANS
# THERE MAY ONLY BE ONE COPY OF DATA. DO NOT MAKE THIS CHANGE UNLESS
# YOU ARE SURE THIS IS OK.
reconfigure.sync.primary=false
minimum.standbys プロパティを使用して、クラスターに保持されるスタンバイノードの最小数を指定します。スタンバイカウントが指定された最小値まで低下した場合、プライマリノードに障害が発生してもレプリカノードは昇格されません。
# Instead of setting specific standbys as being unavailable for
# promotion, this property can be used to set a minimum number
# of standbys that will not be promoted. Set to one, for
# example, promotion will not happen if it will drop the number
# of standbys below this value. This property must be the same on
# each node.
minimum.standbys=0
recovery.check.period プロパティを使用して、Failover Managerの秒数を指定しますデータベースが回復していないかどうかを確認する前に待機します。
# Time in seconds between checks to see if a promoting database
# is out of recovery.
recovery.check.period=2
restart.connection.timeout プロパティを使用して、Failover Managerの秒数を指定しますそのノード上のデータベースが接続を受け入れる準備をしている間に、新しく再構成されたプライマリまたはスタンバイノードへの接続を試みます。
# Time in seconds to keep trying to connect to a database after a
# start or restart command returns successfully but the database
# is not ready to accept connections yet (a rare occurance). This
# applies to standby databases that are restarted when being
# reconfigured for a new primary, and to primary databases that
# are stopped and started as standbys during a switchover.
# This retry mechanism is unrelated to the auto.resume.period
# parameter.
restart.connection.timeout=60
auto.resume.period プロパティを使用して、エージェントがそのデータベースの監視を再開しようとする秒数(監視対象データベースが失敗し、エージェントがアイドル状態になった後、またはIDLEモードで起動したとき)を指定します。
# Period in seconds for IDLE agents to try to resume monitoring
# after a database failure or when starting in IDLE mode. Set to
# 0 for agents to not try to resume (in which case the
# 'efm resume <cluster>' command is used after bringing a
# database back up).
auto.resume.period=0
Failover Manager provides support for clusters that use a virtual IP. If
your cluster uses a virtual IP, provide the host name or IP address in
the virtual.ip property; specify the corresponding prefix in the
virtual.ip.prefix property. If virtual.ip is left blank, virtual IP
support is disabled.
VIPが使用するネットワークインターフェイスを提供するには、 virtual.ip.interface プロパティを使用します。
指定された仮想IPアドレスは、クラスターのプライマリノードにのみ割り当てられます。 virtual.ip.single=true を指定すると、フェイルオーバーが発生した場合に同じプライマリで新しいVIPアドレスが使用されます。falseの値を指定して、クラスターの各ノードに一意のIPアドレスを提供します。
仮想IPアドレスの使用については、 :doc:`仮想IPアドレスでのフェールオーバーマネージャーの使用<using_vip_addresses>`を参照してください。
# These properties specify the IP and prefix length that will be
# remapped during failover. If you do not use a VIP as part of
# your failover solution, leave the virtual.ip property blank to
# disable Failover Manager support for VIP processing (assigning,
# releasing, testing reachability, etc).
#
# If you specify a VIP, the interface and prefix are required.
#
# If you specify a host name, it will be resolved to an IP address
# when acquiring or releasing the VIP. If the host name resolves
# to more than one IP address, there is no way to predict which
# address Failover Manager will use.
#
# By default, the virtual.ip and virtual.ip.prefix values must be
# the same across all agents. If you set virtual.ip.single to
# false, you can specify unique values for virtual.ip and
# virtual.ip.prefix on each node.
#
# If you are using an IPv4 address, the virtual.ip.interface value
# should not contain a secondary virtual ip id (do not include
# ":1", etc).
virtual.ip=
virtual.ip.interface=
virtual.ip.prefix=
virtual.ip.single=true
注意: :プライマリエージェントが起動され、ノードに現在VIPがない場合、EFMエージェントはそれを取得します。プライマリエージェントを停止しても、ノードからVIPは削除されません。
check.vip.before.promotion プロパティをfalseに設定してFailover Managerを示す障害が発生した場合にVIPを新しいプライマリに割り当てる前に、VIPが使用中かどうかを確認しません。これにより、複数のノードが同じVIPアドレスでブロードキャストする可能性があることに注意してください。プライマリノードが分離されているか、別のプロセスでシャットダウンできない限り、このプロパティをtrueに設定する必要があります。
# Whether to check if the VIP (when used) is still in use before
# promoting after a primary failure. Turning this off may allow
# the new primary to have the VIP even though another node is also
# broadcasting it. This should only be used in environments where
# it is known that the failed primary node will be isolated or
# shut down through other means.
check.vip.before.promotion=true
次のプロパティを使用して、スイッチオーバーまたはプライマリ障害シナリオの場合にロードバランサーを再構成するスクリプトへのパスを提供します。スクリプトは、スタンバイに失敗した場合にも呼び出されます。これらのプロパティを使用している場合は、クラスターのすべてのノード(プライマリ、スタンバイ、および監視)でそれらを提供して、データベースノードに障害が発生した場合に、別のノードが障害ノードのアドレスでdetachスクリプトを呼び出すようにします。
script.load.balancer.attach プロパティの後にスクリプト名を指定して、ノードをロードバランサーにアタッチする必要があるときに呼び出されるスクリプトを識別します。 script.load.balancer.detach プロパティを使用して、ロードバランサーからノードを切り離す必要があるときに呼び出されるスクリプトの名前を指定します。クラスターに接続またはクラスターから削除されるノードのIPアドレスを表す %h プレースホルダーを含めます。Failover Managerを指示する %t プレースホルダーを含めます文字列にp(プライマリノードの場合)またはs(スタンバイノードの場合)を含める。
# Absolute path to load balancer scripts
# The attach script is called when a node should be attached to
# the load balancer, for example after a promotion. The detach
# script is called when a node should be removed, for example
# when a database has failed or is about to be stopped. Use %h to
# represent the IP/hostname of the node that is being
# attached/detached. Use %t to represent the type of node being
# attached or detached: the letter m will be passed in for primary nodes
#and the letter s for standby nodes.
#
# Example:
# script.load.balancer.attach=/somepath/attachscript %h %t
script.load.balancer.attach=
script.load.balancer.detach=
script.fence は、スタンバイノードからプライマリノードへの昇格中に呼び出されるオプションのユーザー指定スクリプトへのパスを指定します。
# absolute path to fencing script run during promotion
#
# This is an optional user-supplied script that will be run
# during failover on the standby database node. If left blank,
# no action will be taken. If specified, EFM will execute this
# script before promoting the standby.
#
# Parameters can be passed into this script for the failed primary
# and new primary node addresses. Use %p for new primary and %f
# for failed primary. On a node that has just been promoted, %p
# should be the same as the node's efm binding address.
#
# Example:
# script.fence=/somepath/myscript %p %f
#
# NOTE: FAILOVER WILL NOT OCCUR IF THIS SCRIPT RETURNS A NON-ZERO EXIT
# CODE.
script.fence=
script.post.promotion プロパティを使用して、スタンバイノードがプライマリに昇格した後に呼び出されるオプションのユーザー指定スクリプトへのパスを指定します。
# Absolute path to fencing script run after promotion
#
# This is an optional user-supplied script that will be run after
# failover on the standby node after it has been promoted and
# is no longer in recovery. The exit code from this script has
# no effect on failover manager, but will be included in a
# notification sent after the script executes.
#
# Parameters can be passed into this script for the failed primary
# and new primary node addresses. Use %p for new primary and %f
# for failed primary. On a node that has just been promoted, %p
# should be the same as the node's efm binding address.
#
# Example:
# script.post.promotion=/somepath/myscript %f %p
script.post.promotion=
script.resumed property を使用して、エージェントがデータベースの監視を再開するときに呼び出されるユーザー指定のスクリプトへのオプションのパスを指定します。
# Absolute path to resume script
#
# This script is run before an IDLE agent resumes
# monitoring its local database.
script.resumed=
script.db.failure プロパティを使用して、オプションのユーザー提供のスクリプトへの完全なパスを指定しますFailover Manager監視するデータベースに障害が発生したことをエージェントが検出した場合に呼び出されます。
# Absolute path to script run after database failure
# This is an optional user-supplied script that will be run after
# an agent detects that its local database has failed.
script.db.failure=
script.primary.isolated プロパティを使用して、オプションのユーザー提供のスクリプトへの完全なパスを指定しますFailover Managerプライマリデータベースを監視するエージェントが、プライマリがFailover Managerの大部分から隔離されていることを検出した場合に起動しますクラスター。このスクリプトは、VIPがリリースされた直後に呼び出されます(VIPが使用中の場合)。
# Absolute path to script run on isolated primary
# This is an optional user-supplied script that will be run after
# a primary agent detects that it has been isolated from the
# majority of the efm cluster.
script.primary.isolated=
script.remote.pre.promotion プロパティを使用して、ノードがデータベースをプライマリに昇格させようとしているときに昇格に関与しないエージェントノードで呼び出されるスクリプトのパスと名前を指定します。
%pプレースホルダーを含めて、新しいプライマリノードのアドレスを識別します。
# Absolute path to script invoked on non-promoting agent nodes
# before a promotion.
#
# This optional user-supplied script will be invoked on other
# agents when a node is about to promote its database. The exit
# code from this script has no effect on Failover Manager, but
# will be included in a notification sent after the script
# executes.
#
# Pass a parameter (%p) with the script to identify the new
# primary node address.
#
# Example:
# script.remote.pre.promotion=/path_name/script_name %p
script.remote.pre.promotion=
script.remote.post.promotion プロパティを使用して、昇格が発生した後に非プライマリノードで呼び出されるスクリプトのパスと名前を指定します。
%pプレースホルダーを含めて、新しいプライマリノードのアドレスを識別します。
# Absolute path to script invoked on non-primary agent nodes
# after a promotion.
#
# This optional user-supplied script will be invoked on nodes
# (except the new primary) after a promotion occurs. The exit code
# from this script has no effect on Failover Manager, but will be
# included in a notification sent after the script executes.
#
# Pass a parameter (%p) with the script to identify the new
# primary node address.
#
# Example:
# script.remote.post.promotion=/path_name/script_name %p
script.remote.post.promotion=
script.custom.monitor プロパティを使用して、定期的な間隔( custom.monitor.interval プロパティで秒単位で指定)で呼び出されるオプションのスクリプトの名前と場所を指定します。
custom.monitor.timeout を使用して、スクリプトの実行を許可する最大時間を指定します。指定した時間内にスクリプトの実行が完了しない場合、Failover Manager通知を送信します。
Failover Managerに指示するには、 custom.monitor.safe.mode を true に設定しますスクリプトからゼロ以外の終了コードを報告しますが、終了コードの結果としてスタンバイをプロモートしません。
# Absolute path to a custom monitoring script.
#
# Use script.custom.monitor to specify the location and name of
# an optional user-supplied script that will be invoked
# periodically to perform custom monitoring tasks. A non-zero
# exit value means that a check has failed; this will be treated
# as a database failure. On a primary node, script failure will
# cause a promotion. On a standby node script failure will
# generate a notification and the agent will become IDLE.
#
# The custom.monitor.\* properties are required if a custom
# monitoring script is specified:
#
# custom.monitor.interval is the time in seconds between executions
# of the script.
#
# custom.monitor.timeout is a timeout value in seconds for how
# long the script will be allowed to run. If script execution
# exceeds the specified time, the task will be stopped and a
# notification sent. Subsequent runs will continue.
#
# If custom.monitor.safe.mode is set to true, non-zero exit codes
# from the script will be reported but will not cause a promotion
# or be treated as a database failure. This allows testing of the
# script without affecting EFM.
#
script.custom.monitor=
custom.monitor.interval=
custom.monitor.timeout=
custom.monitor.safe.mode=
sudo.command プロパティを使用してFailover Managerによって呼び出されるコマンドを指定します拡張アクセス許可を必要とするタスクを実行するとき。このオプションを使用して、システム認証に固有のコマンドオプションを含めます。
sudo.user.command プロパティを使用してFailover Managerによって呼び出されるコマンドを指定しますデータベース所有者が実行するコマンドを実行するとき。
# Command to use in place of 'sudo' if desired when efm runs
# the efm_db_functions or efm_root_functions, or efm_address
# scripts.
# Sudo is used in the following ways by efm:
#
# sudo /usr/edb/efm-<version>/bin/efm_address <arguments>
# sudo /usr/edb/efm-<version>/bin/efm_root_functions <arguments>
# sudo -u <db service owner> /usr/edb/efm-<version>/bin/efm_db_functions <arguments>
#
# 'sudo' in the first two examples will be replaced by the value
# of the sudo.command property. 'sudo -u <db service owner>' will
# be replaced by the value of the sudo.user.command property.
# The '%u' field will be replaced with the db owner.
sudo.command=sudo
sudo.user.command=sudo -u %u
lock.dir プロパティを使用してFailover Managerの代替の場所を指定しますロックファイル。ファイルはFailover Managerを防ぎますノード上の単一クラスターに対して複数の(潜在的に孤立した)エージェントを開始することから。
# Specify the directory of lock file on the node. Failover
# Manager creates a file named <cluster>.lock at this location to
# avoid starting multiple agents for same cluster. If the path
# does not exist, Failover Manager will attempt to create it. If
# not specified defaults to '/var/lock/efm-<version>'
lock.dir=
log.dir プロパティを使用して、エージェントログファイルが書き込まれる場所を指定します。Failover Managerディレクトリが存在しない場合、ディレクトリを作成しようとします。
# Specify the directory of agent logs on the node. If the path
# does not exist, Failover Manager will attempt to create it. If
# not specified defaults to '/var/log/efm-<version>'. (To store
# Failover Manager startup logs in a custom location, modify the
# path in the service script to point to an existing, writable
# directory.)
# If using a custom log directory, you must configure
# logrotate separately. Use 'man logrotate' for more information.
log.dir=
Failover ManagerでUDPまたはTCPプロトコルを有効にした後ホストでは、syslogへのロギングを有効にできます。プロトコルタイプ(UDPまたはTCP)を指定するには syslog.protocol パラメーターを、syslogホストのリスナーポートを指定するには syslog.port パラメーターを使用します。 syslog.facility 値は、エントリを作成したプロセスの識別子として使用できます。値はLOCAL0とLOCAL7の間でなければなりません。
# Syslog information. The syslog service must be listening on
# the port for the given protocol, which can be UDP or TCP.
# The facilities supported are LOCAL0 through LOCAL7.
syslog.host=localhost
syslog.port=514
syslog.protocol=UDP
syslog.facility=LOCAL1
Use the file.log.enabled and syslog.enabled properties to specify the
type of logging that you wish to implement. Set file.log.enabled to true
to enable logging to a file; enable the UDP protocol or TCP protocol and
set syslog.enabled to true to enable logging to syslog. You can enable
logging to both a file and syslog.
# Which logging is enabled.
file.log.enabled=true
syslog.enabled=false
syslogロギングの設定の詳細については、 :ref:`syslogログファイルエントリの有効化<enabling_syslog>`を参照してください。
jgroups.loglevel および efm.loglevel パラメーターを使用して、Failover Managerによって記録される詳細レベルを指定します。デフォルト値はINFOです。ロギングの詳細については、 :doc:`ControllingLogging<controlling_logging>`を参照してください。
# Logging levels for JGroups and EFM.
# Valid values are: TRACE, DEBUG, INFO, WARN, ERROR
# Default value: INFO
# It is not necessary to increase these values unless debugging a
# specific issue. If nodes are not discovering each other at
# startup, increasing the jgroups level to DEBUG will show
# information about the TCP connection attempts that may help
# diagnose the connection failures.
jgroups.loglevel=INFO
efm.loglevel=INFO
JVM関連の設定情報を渡すには、 jvm.options プロパティを使用します。デフォルト設定では、Failover Managerのメモリ量を指定しますエージェントは使用を許可されます。
# Extra information that will be passed to the JVM when starting
# the agent.
jvm.options=-Xmx128m