フェイルオーバーマネージャーのパーミッションの拡張

During the Failover Manager installation, the installer creates a user named efm. efm does not have sufficient privileges to perform management functions that are normally limited to the database owner or operating system superuser.

  • データベースのスーパーユーザー権限を必要とする管理機能を実行する場合、 efm は efm_db_functions スクリプトを呼び出します。

  • オペレーティングシステムのスーパーユーザー特権を必要とする管理機能を実行する場合、 efm は efm_root_functions スクリプトを呼び出します。

  • 仮想IPアドレスの割り当てまたは解放時に、efmは efm_address script を呼び出します。

efm_db_functions または efm_root_functions スクリプトは、 efm ユーザーに代わって管理機能を実行します。

The sudoers file contains entries that allow the user efm to control the Failover Manager service for clusters owned by postgres or enterprisedb. You can modify a copy of the sudoers file to grant permission to manage Postgres clusters owned by other users to efm.

efm-40 ファイルは /etc/sudoers.d にあり、次のエントリが含まれています:

# Copyright EnterpriseDB Corporation, 2014-2020. All Rights Reserved.
#
# Do not edit this file. Changes to the file may be overwritten
# during an upgrade.
#
# This file assumes you are running your efm cluster as user
# 'efm'. If not, then you will need to copy this file.
# Allow user 'efm' to sudo efm_db_functions as either 'postgres'
# or 'enterprisedb'. If you run your db service under a
# non-default account, you will need to copy this file to grant
# the proper permissions and specify the account in your efm
# cluster properties file by changing the 'db.service.owner'
# property.

efm ALL=(postgres) NOPASSWD: /usr/edb/efm-4.00/bin/efm_db_functions
efm ALL=(enterprisedb) NOPASSWD: /usr/edb/efm-4.00/bin/efm_db_functions

# Allow user 'efm' to sudo efm_root_functions as 'root' to
# write/delete the PID file, validate the db.service.owner
# property, etc.
efm ALL=(ALL) NOPASSWD: /usr/edb/efm-4.00/bin/efm_root_functions
# Allow user 'efm' to sudo efm_address as root for VIP tasks.
efm ALL=(ALL) NOPASSWD: /usr/edb/efm-4.00/bin/efm_address
# relax tty requirement for user 'efm'
Defaults:efm !requiretty

Failover Managerを使用している場合 postgres または enterprisedb 以外のユーザーが所有するクラスターを監視するには、 efm-40 ファイルのコピーを作成し、ユーザーが efm_functions にアクセスできるようにコンテンツを変更しますクラスターを管理するスクリプト。

パーミッションの問題のためにエージェントを起動できない場合、デフォルトの /etc/sudoers ファイルの最後に次の行が含まれていることを確認してください。

## Read drop-in files from /etc/sudoers.d (the # here does not # mean a comment)

#includedir /etc/sudoers.d

sudoなしでフェールオーバーマネージャーを実行する

デフォルトでは、Failover Managersudoを使用して、システム機能へのアクセスを安全に管理します。構成することを選択した場合Failover Managersudoアクセスなしで実行するには、rootアクセスがまだ必要であることに注意してください:

  • Failover ManagerをインストールしますRPM。

  • Failover Managerを実行します設定タスク。

Failover Managerを実行するにはsudoを使用しない場合、Failover Managerの代わりに管理機能を実行する権限を持つデータベースプロセスの所有者を選択する必要があります。ユーザーは、デフォルトのデータベーススーパーユーザー(enterprisedbやpostgresなど)または別の特権ユーザーである可能性があります。ユーザーを選択した後:

  1. 次のコマンドを使用して、ユーザーを efm グループに追加します。

    usermod -a -G efm enterprisedb

    これにより、ユーザーは /var/run/efm-4.0 および /var/lock/efm-4.0 に書き込むことができます。

  2. クラスター名を再利用する場合は、以前に作成したログファイルをすべて削除します。新しいユーザーは、デフォルト(または他の)所有者が作成したログファイルに書き込むことができません。

  3. クラスタプロパティテンプレートファイルとノードテンプレートファイルをコピーします。

su - enterprisedb

cp /etc/edb/efm-4.00/efm.properties.in <directory/cluster_name>.properties

cp /etc/edb/efm-4.00/efm.nodes.in <directory>/<cluster_name>.nodes

次に、クラスタープロパティファイルを変更し、 db.service.owner プロパティでユーザーの名前を指定します。 db.service.name プロパティが空白であることも確認する必要があります。sudoがないと、ルートアクセスなしでサービスを実行できません。

構成を変更した後、新しいユーザーは次のコマンドでフェールオーバーマネージャーを制御できます。

/usr/edb/efm-4.00/bin/runefm.sh start|stop <directory/cluster_name>.properties

ここで、 <directory/cluster_name.properties> はクラスタープロパティファイルのフルパスを指定します。ユーザーは、デフォルト以外のユーザーがエージェントを制御しているとき、またはefmスクリプトを使用しているときは常に、プロパティファイルへのフルパスを指定する必要があることに注意してください。

新しいユーザーがFailover Managerを管理できるようにするにはサービスとして、カスタムスクリプトまたはユニットファイルを提供する必要があります。

Failover Manager /usr/edb/efm-4.0/bin/secure/ に存在する manage-vip という名前のバイナリを使用して、sudo特権なしでVIP管理操作を実行します。このスクリプトは、setuidを使用して、仮想IPアドレスの管理に必要な特権を取得します。

  • このディレクトリには、ルートと efm グループのユーザーのみがアクセスできます。

  • バイナリはルートと efm グループでのみ実行可能です。

セキュリティ上の理由から、 /usr/edb/efm-4.0/bin/secure/ ディレクトリまたは manage-vip スクリプトのアクセス権限を変更しないことをお勧めします。

Failover Managerの使用の詳細についてはsudoを使用しない場合は、次をご覧ください。

https://www.enterprisedb.com/blog/running-edb-postgres-failover-manager-without-sudo