Extending Failover Manager Permissions

|Failover Manager中インストール時に、インストーラーは efm という名前のユーザーを作成します。 efm には、通常データベース所有者またはオペレーティングシステムのスーパーユーザーに制限されている管理機能を実行するための十分な権限がありません。

  • データベースのスーパーユーザー特権を必要とする管理機能を実行する場合、 efm は efm_db_functions スクリプトを呼び出します。

  • オペレーティングシステムのスーパーユーザー権限を必要とする管理機能を実行する場合、 efm は efm_root_functions スクリプトを呼び出します。

  • 仮想IPアドレスの割り当てまたは解放時に、 efm は efm_address スクリプトを呼び出します。

  • Pgpool統合を有効にすると、 efm は efm_pgpool_functions スクリプトを呼び出します。

efm_db_functions または efm_root_functions スクリプトは、 efm ユーザーに代わって管理機能を実行します。

sudoersファイルには、ユーザー efm がFailover Managerを制御できるようにするエントリが含まれています postgres または enterprisedb が所有するクラスターのサービス。sudoersファイルのコピーを変更して、他のユーザーが所有するPostgresクラスターを efm に管理する権限を付与できます。

efm-41 ファイルは /etc/sudoers.d にあり、次のエントリが含まれています。

# Copyright EnterpriseDB Corporation, 2014-2020. All Rights Reserved.
#
# Do not edit this file. Changes to the file may be overwritten
# during an upgrade.
#
# This file assumes you are running your efm cluster as user 'efm'.  If not,
# then you will need to copy this file.

# Allow user 'efm' to sudo efm_db_functions as either 'postgres' or 'enterprisedb'.
# If you run your db service under a non-default account, you will need to copy
# this file to grant the proper permissions and specify the account in your efm
# cluster properties file by changing the 'db.service.owner' property.
efm    ALL=(postgres)      NOPASSWD:   /usr/edb/efm-4.1/bin/efm_db_functions
efm    ALL=(enterprisedb)  NOPASSWD:   /usr/edb/efm-4.1/bin/efm_db_functions

# Allow user 'efm' to sudo efm_root_functions as 'root' to write/delete the PID file,
# validate the db.service.owner property, etc.
efm    ALL=(ALL)           NOPASSWD:   /usr/edb/efm-4.1/bin/efm_root_functions

# Allow user 'efm' to sudo efm_address as root for VIP tasks.
efm    ALL=(ALL)           NOPASSWD:   /usr/edb/efm-4.1/bin/efm_address

# Allow user 'efm' to sudo efm_pgpool_functions as root for pgpool tasks.
efm    ALL=(ALL)           NOPASSWD:   /usr/edb/efm-4.1/bin/efm_pgpool_functions

# relax tty requirement for user 'efm'
Defaults:efm !requiretty

|Failover Managerを使用している場合 postgres または enterprisedb 以外のユーザーが所有するクラスターを監視するには、 efm-41 ファイルのコピーを作成し、ユーザーが efm_functions スクリプトにアクセスしてクラスターを管理できるようにコンテンツを変更します。

権限の問題のためにエージェントを起動できない場合は、デフォルトの /etc/sudoers ファイルのファイルの最後に次の行が含まれていることを確認してください。

## Read drop-in files from /etc/sudoers.d (the # here does not # mean a comment)

#includedir /etc/sudoers.d

sudoなしでフェールオーバーマネージャーを実行する

デフォルトでは、|Failover Managersudoを使用して、システム機能へのアクセスを安全に管理します。構成することを選択した場合Failover Managersudoアクセスなしで実行するには、rootアクセスがまだ必要であることに注意してください:

  • |Failover ManagerをインストールしますRPM。

  • |Failover Managerを実行します設定タスク。

|Failover Managerを実行するにはsudoを使用しない場合、|Failover Managerの代わりに管理機能を実行する権限を持つデータベースプロセスの所有者を選択する必要があります。ユーザーは、デフォルトのデータベーススーパーユーザー(enterprisedbやpostgresなど)または別の特権ユーザーである可能性があります。ユーザーを選択した後:

  1. 次のコマンドを使用して、ユーザーを efm グループに追加します。

    usermod -a -G efm enterprisedb

    これにより、ユーザーは /var/run/efm-4.1 と /var/lock/efm-4.1 に書き込むことができます。

  2. クラスター名を再利用する場合は、以前に作成したログファイルをすべて削除します。新しいユーザーは、デフォルト(または他の)所有者が作成したログファイルに書き込むことができません。

  3. クラスタプロパティテンプレートファイルとノードテンプレートファイルをコピーします。

    su - enterprisedb
    
    cp /etc/edb/efm-4.1/efm.properties.in <directory/cluster_name>.properties
    
    cp /etc/edb/efm-4.1/efm.nodes.in <directory>/<cluster_name>.nodes

次に、クラスタープロパティファイルを変更し、 db.service.owner プロパティでユーザーの名前を指定します。 db.service.name プロパティが空白であることも確認する必要があります。sudoがないと、ルートアクセスなしでサービスを実行できません。

構成を変更した後、新しいユーザーは次のコマンドでフェールオーバーマネージャーを制御できます。

/usr/edb/efm-4.1/bin/runefm.sh start|stop <directory/cluster_name>.properties

ここで、 <directory/cluster_name.properties> はクラスタープロパティファイルのフルパスを指定します。ユーザーは、デフォルト以外のユーザーがエージェントを制御しているとき、またはefmスクリプトを使用しているときは常に、プロパティファイルへのフルパスを指定する必要があることに注意してください。

新しいユーザーがFailover Managerを管理できるようにするにはサービスとして、カスタムスクリプトまたはユニットファイルを提供する必要があります。

Failover Manager /usr/edb/efm-4.1/bin/secure/ にある manage-vip という名前のバイナリを使用して、sudo権限なしでVIP管理操作を実行します。このスクリプトは、setuidを使用して、仮想IPアドレスの管理に必要な特権を取得します。

  • このディレクトリには、ルートと efm グループのユーザーのみがアクセスできます。

  • バイナリは、ルートおよび efm グループでのみ実行可能です。

セキュリティ上の理由から、 /usr/edb/efm-4.1/bin/secure/ ディレクトリまたは manage-vip スクリプトのアクセス権限を変更しないことをお勧めします。

|Failover Managerの使用の詳細についてはsudoを使用しない場合は、次をご覧ください。

https://www.enterprisedb.com/blog/running-edb-postgres-failover-manager-without-sudo