The cluster properties file#

フェールオーバーマネージャークラスター内の各ノードには、それが存在する個々のノードのプロパティを含むプロパティファイルデフォルトでの名前付けefm.properties があります。 Failover Managerインストーラーは、 /etc/edb/efm-5.<x> ディレクトリにefm.properties.in という名前のプロパティファイルのファイルテンプレートを作成します。

フェールオーバーマネージャーのインストールが完了したら、ファイルの内容を変更する前にテンプレートの作業コピーを作成します。

#  cp /etc/edb/efm-5.2/efm.properties.in /etc/edb/efm-5.2/efm.properties

テンプレートファイルをコピーした後、ファイルの所有者をefmに変更します。

#  chown efm:efm efm.properties

注釈

デフォルトでは、フェールオーバーマネージャーはクラスタープロパティファイルの名前が`efm.properties` と命名されます。プロパティファイルに`efm.properties` 以外の名前を付ける場合、サービススクリプトまたはユニットファイルを変更して、フェールオーバーマネージャーに別の名前を使用するように指示します。

クラスタープロパティファイルを作成した後、必要に応じて構成パラメーター値を追加または変更します。各プロパティの詳細については、 クラスタープロパティの指定 を参照してください。

Failover Managerサービススクリプトは、 /etc/edb/efm-5.<x> ディレクトリでファイルを見つけようとします。プロパティファイルを別の場所に移動する場合は、新しい場所を指定するシンボリックリンクを作成する必要があります。

注釈

プロパティファイルで参照されるすべてのユーザースクリプトは、Failover Managerユーザーとして呼び出されます。

クラスタープロパティの指定#

クラスタープロパティファイルにリストされているプロパティを使用して、フェールオーバーマネージャークラスターの接続プロパティと動作を指定できます。プロパティ設定の変更は、フェールオーバーマネージャーの起動時に適用されます。プロパティ値を変更する場合は、フェールオーバーマネージャーを再起動して変更を適用する必要があります。

プロパティ値は大文字と小文字が区別されます。 Postgresはパラメーター値で引用符で囲まれた文字列を使用しますが、フェールオーバーマネージャーではプロパティ値で引用符で囲まれた文字列を使用できません。たとえば、Postgres構成パラメーターでIPアドレスを次のように指定できます。

listen_addresses='192.168.2.47'

フェールオーバーマネージャーを使用する場合、値を引用符で囲まないでください。

bind.address=192.168.2.54:7800

efm.properties ファイルのプロパティを使用して、Failover Managerの接続、管理、および操作の詳細を指定します。

凡例 次の表において

  • A プライマリまたはスタンバイノードで必要

  • W 監視ノードで必要

  • S すべてのノードで同じである必要があります

  • Y はい

クラスタープロパティ#

次のプロパティを使用して、フェールオーバーマネージャークラスターの接続の詳細を指定します。

#  The value for the password property should be the output from

#  efm encrypt -- do not include a cleartext password here. To

#  prevent accidental sharing of passwords among clusters, the

#  cluster name is incorporated into the encrypted password. If

#  you change the cluster name (the name of this file), you must

#  encrypt the password again with the new name.

#  The db.port property must be the same for all nodes.

db.user=
db.password.encrypted=
db.port=
db.database=

指定されたdb.user には、Failover Managerに代わって選択したPostgreSQLコマンドを呼び出すための十分な権限が必要です。詳細については、 前提条件 を参照してください。

データベースユーザーのパスワードの暗号化については、 Encrypting your database password を参照してください。

db.service.owner プロパティを使用して、フェールオーバーマネージャーによって管理されているクラスターを所有するオペレーティングシステムユーザーの名前を指定します。このプロパティは、専用の監視ノードでは必要ありません。

#  This property tells EFM which OS user owns the $PGDATA dir for

#  the db.database. By default, the owner is either postgres

#  for PostgreSQL or enterprisedb for EDB Postgres Advanced

#  Server. However, if you have configured your db to run as a

#  different user, you will need to copy the /etc/sudoers.d/efm-XX

#  conf file to grant the necessary permissions to your db owner.

#
#  This username must have write permission to the

#  db.data.dir specified below.

db.service.owner=

サービスの開始または停止時にservice またはsystemctl コマンドを使用する場合、 db.service.name プロパティにデータベースサービスの名前を指定します。

#  Specify the proper service name in order to use service commands

#  rather than pg_ctl to start/stop/restart a database. For example, if

#  this property is set, then service <name> restart or systemctl

#  restart <name>

#  (depending on OS version) will be used to restart the database rather

#  than pg_ctl.

#  This property is required if running the database as a service.

db.service.name=

データベースサービスを開始または停止するたびに、同じサービス制御メカニズムpg_ctl 、service 、またはsystemctl を使用します。 pg_ctl プログラムを使用してサービスを制御する場合、 db.bin プロパティでpg_ctl プログラムの場所を指定します

#  Specify the directory containing the pg_controldata/pg_ctl commands,

#  for example:

#  /usr/edb/as12/bin. Unless the db.service.name property is used, the

#  pg_ctl command is used to start/stop/restart databases as needed

#  after a failover or switchover. This property is required.

db.bin=

db.data.dir プロパティを使用して、 standby.signal またはrecovery.conf ファイルを作成する場所を指定します。このプロパティは、プライマリノードとスタンバイノードで必要です。専用の監視ノードでは必要ありません。

#  This is the directory where a standby.signal file will exist for a standby node.

#  If a primary database fails, a recovery.conf file will be written in this

#  location to ensure that the failed database can not be restarted as the

#  primary database.

#  This corresponds to database environment variable PGDATA and should be same

#  as the output of query show data_directory; on respective database.

db.data.dir=

データベース構成ファイルがrecovery.conf またはstandby.signal ファイルと同じディレクトリに保存されていない場合、 db.config.dir プロパティを使用してデータベース構成ファイルの場所を指定します。これは、EDB Postgres Advanced ServerまたはPostgreSQLインストールのconfig_file パラメーターディレクトリで指定された値です。この値は、データベースを停止、起動、または再起動するときにEDB Postgres Advanced Server data ディレクトリの場所として使用されます。

#  Specify the location of database configuration files if they are

#  not contained in the same location as the standby.signal

#  file. This is most likely the case for Debian installations. The location

#  specified will be used as the -D value (the location of the data directory

#  for the cluster) when calling pg_ctl to start or stop the database.

#  If this property is blank, the db.data.dir location specified by the

#  db.data.dir property will be used.

#  This corresponds to the output of query show config_file; on respective database.

db.config.dir=

データベース構成ファイルの詳細については、 PostgreSQL website にアクセスしてください。

jdbc.sslmode プロパティを使用して、SSL接続を使用するようにフェールオーバーマネージャーに指示します。デフォルトでは、SSLは無効になっています。

#  Use the jdbc.sslmode property to enable ssl for EFM

#  connections. Setting this property to anything but disable

#  will force the agents to use ssl=true for all JDBC database

#  connections (to both local and remote databases).

#  Valid values are:

#

#  disable - Do not use ssl for connections.

#  verify-ca - EFM will perform CA verification before allowing

#  the certificate.

#  require - Verification will not be performed on the server

#  certificate.

jdbc.sslmode=disable

注釈

jdbc.sslmode の値を`verify-ca` に設定し、証明書の検証にJavaトラストストアを使用する場合、次の値を設定する必要があります。この行は、クラスタープロパティファイルのどこにでも追加できます。

jdbc.properties=sslfactory=org.postgresql.ssl.DefaultJavaSSLFactory

SSLの構成と使用については、PostgreSQLドキュメントの Secure TCP/IP Connections with SSL および Using SSL を参照してください。

user.email プロパティを使用して、フェールオーバーマネージャーによって送信された通知を受信する電子メールアドレスまたは複数の電子メールアドレスを指定します。

#  Email address(es) for notifications. The value of this property must

#  be the same across all agents. Multiple email addresses must

#  be separated by space. This is required if not using a script.notification

#  script. Either/both can be used.

user.email=

from.email プロパティは、フェールオーバーマネージャーからのメール通知の送信者のアドレスとして使用する値を指定します。次のことができます。

  • from.email を空白のままにして、デフォルト値 efm@localhost を使用します。

  • 電子メールアドレスのカスタム値を指定します。

  • %h プレースホルダーを使用して、ノードホストの名前たとえば example@%h などを表すカスタムメールアドレスを指定します。プレースホルダーは、Linuxホスト名ユーティリティによって返されたホストの名前に置き換えられます。

通知の詳細については、 Notifications を参照してください。

#  Use the from.email property to specify the from email address that

#  will be used for email notifications. Use the %h placeholder to

#  represent the name of the node host (e.g. example@%h). The

#  placeholder will be replaced with the name of the host as returned

#  by the hostname command.

#  Leave blank to use the default, efm@localhost.

from.email=

notification.level プロパティを使用して、フェールオーバーマネージャーがユーザー通知を送信する最小の重大度レベル、または通知スクリプトが呼び出されるタイミングを指定します。通知の完全なリストについては、 Notifications を参照してください。

#  Minimum severity level of notifications that will be sent by

#  the agent. The minimum level also applies to the notification

#  script (below). Valid values are INFO, WARNING, and SEVERE.

#  A list of notifications is grouped by severity in the users

#  guide.

notification.level=INFO

notification.text.prefix プロパティを使用して、すべての通知の先頭に追加するテキストを指定します。

#  Text to add to the beginning of every notification. This could

#  be used to help identify what the cluster is used for, the role

#  of this node, etc. To use multiple lines, add a backslash \ to

#  the end of a line of text. To include a newline use \n.

#  Example:

#  notification.text.prefix=Development cluster for Example dept.\n\

#  Used by Dev and QA \

#  See Example group for questions.

notification.text.prefix=

script.notification プロパティを使用して、通知サービスとして機能するユーザー指定スクリプトへのパスを指定します。スクリプトには、メッセージの件名とメッセージ本文が渡されます。スクリプトは、フェールオーバーマネージャーがユーザー通知を生成するたびに呼び出されます。

#  Absolute path to script run for user notifications.

#

#  This is an optional user-supplied script that can be used for

#  notifications instead of email. This is required if not using

#  email notifications. Either/both can be used. The script will

#  be passed two parameters: the message subject and the message

#  body.

script.notification=

bind.address プロパティは、フェールオーバーマネージャークラスターの現在のノード上のエージェントのIPアドレスとポート番号を指定します。

#  This property specifies the ip address and port that jgroups

#  will bind to on this node. The value is of the form

#  <ip>:<port>.

#  Note that the port specified here is used for communicating

#  with other nodes, and is not the same as the admin.port below,

#  used only to communicate with the local agent to send control

#  signals.

#  For example, <provide_your_ip_address_here>:7800

bind.address=

external.address プロパティを使用して、NAT環境内の他のすべてのFailover Managerエージェントとの通信に使用するIPアドレスまたはホスト名を指定します。

#  This is the ip address/hostname to be used for communication with all

#  other Failover Manager agents. All traffic towards this address

#  should be routed by the network to the bind.address of the node.

#  The value is in the ip/hostname format only. This address will be

#  used in scenarios where nodes are on different networks and broadcast

#  an IP address other than the bind.address to the external world.

external.address=

admin.port プロパティを使用して、フェールオーバーマネージャーが管理コマンドをリッスンするポートを指定します。

#  This property controls the port binding of the administration

#  server which is used for some commands (ie cluster-status). The

#  default is 7809; you can modify this value if the port is

#  already in use.

admin.port=7809

is.witness プロパティをtrue に設定して、現在のノードが監視ノードであることを示します。 is.witness がtrue の場合、ローカルエージェントはローカルデータベースが実行されているかどうかを確認しません。

#  Specifies whether or not this is a witness node. Witness nodes

#  do not have local databases running.

is.witness=

EDB Postgres Advanced Server pg_is_in_recovery() ファンクションは、データベースの復旧状態を報告するブールファンクションです。このファンクションは、データベースが復旧している場合はtrue を、データベースが復旧していない場合はfalse を返します。エージェントは起動すると、ローカルデータベースに接続し、pg_is_in_recovery() ファンクションを呼び出します。

  • サーバーがtrueで応答した場合、エージェントはスタンバイのロールを引き継ぎます。

  • サーバーがfalseで応答した場合、エージェントはプライマリのロールを引き継ぎます。

  • ローカルデータベースがない場合、エージェントはアイドル状態になります。

注釈

is.witness が`true` の場合、フェールオーバーマネージャーは復旧状態をチェックしません。

次のプロパティは、エージェントのローカルデータベースサーバーに適用されます。

  • local.period プロパティは、データベースサーバーへの接続を試行する秒数を指定します。

  • local.timeout プロパティは、障害チェックを続行する前にデータベースサーバーからの肯定的な応答をエージェントが待機する時間秒単位を制限します。

  • local.timeout.final プロパティは、以前のチェックが失敗した後の最後の接続試行中にエージェントが待機する時間秒単位を制限します。最後の接続試行が失敗するか、指定された時間内にデータベースが応答しない場合、Failover Managerエージェントはデータベースに到達不能であると考えます。接続が確立されると、エージェントは通知を送信し、監視を再開します。

例、デフォルト値の場合

  1. ローカルデータベースlocal.period のチェックは10秒ごとに発生します。

  2. ローカルデータベースに接続しようとして、60秒以内に正の結果が返されなかった場合 local.timeout 、フェールオーバーマネージャーは最後の接続試行を開始します。

  3. 最後の接続試行が失敗した場合、または応答が10秒以内に受信されなかった場合 local.timeout.final 、フェールオーバーマネージャーは次のステップに進み、データベースに到達可能かどうかをクラスターの残りの部分に尋ねます。

これらのプロパティは、専用の監視ノードでは必要ありません。

#  These properties apply to the connection(s) EFM uses to monitor

#  the local database. Every local.period seconds, a database

#  check is made in a background thread. If the main monitoring

#  thread does not see that any checks were successful in

#  local.timeout seconds, then the main thread makes a final

#  check with a timeout value specified by the

#  local.timeout.final value. All values are in seconds.

#  Whether EFM uses single or multiple connections for database

#  checks is controlled by the db.reuse.connection.count

#  property.

local.period=10
local.timeout=60
local.timeout.final=10

必要に応じて、ビジネスモデルに合わせてこれらの値を変更します。

remote.timeout プロパティを使用して、エージェントがリモートエージェントまたはデータベースからの応答を待機する秒数を制限します。エージェントは、クラスターイベント中にのみ相互にメッセージを送信します。例は次のとおりです。

  • エージェントは、ローカルで到達不能になった後、データベースに接続できるかどうかを他のエージェントに尋ねます。

  • スイッチオーバーの一部としてスタンバイエージェントから復旧設定を要求するプライマリエージェント。

  • フェールオーバーマネージャークラスターを停止するときにシャットダウンの準備をするようにノードに指示します。

#  Timeout for a call to check if a remote database is responsive.

#  For example, this is how long a standby would wait for a

#  DB ping request from itself and the witness to the primary DB

#  before performing failover.

remote.timeout=10

node.timeout プロパティを使用して、ノードに障害が発生したかどうかを判断するときにエージェントが別のノードからのハートビートを待機する秒数を指定します。

#  The total amount of time in seconds to wait before determining

#  that a node has failed or been disconnected from this node.

#
#  The value of this property must be the same across all agents.

node.timeout=50

!!!note タイムアウトプロパティの概要/比較 - local.* プロパティは、エージェントのローカルデータベースの障害検出用です。・ node.timeout プロパティは、他ノードの障害検出用です。 - remote.timeout プロパティは、エージェントが他のエージェントからの応答を待機する時間を制限します。

#  Set to true to encrypt messages that are sent between agents.

#  This property must be the same on all agents or else the agents

#  will not be able to connect.

encrypt.agent.messages=false

enable.stop.cluster プロパティを使用して、 stop-cluster コマンドを有効または無効にします。このコマンドは一部の環境では便利ですが、意図せず呼び出されると問題が発生する可能性があります。イーガーフェールオーバーモードでは、このコマンドはフェールオーバーなしでEDB Postgres Advanced Serverを停止します。

#  Whether or not the efm stop-cluster <cluster name> command is enabled.

#  Set to false to disable the command, in which case all Failover

#  Manager agents must be stopped individually. Note that stopping each

#  agent separately will change the .nodes files on remaining agents

#  unless stable.nodes.file is also true. This property value must

#  be the same on all agents if set. The default is true if not set.

enable.stop.cluster=true

stop.isolated.primary プロパティを使用して、プライマリエージェントが分離されたことを検出した場合にデータベースをシャットダウンするようにフェールオーバーマネージャーに指示します。 true デフォルトの場合、フェールオーバーマネージャーはscript.primary.isolated プロパティで指定されたスクリプトを呼び出す前にデータベースを停止します。

#  Shut down the database after a primary agent detects that it has

#  been isolated from the majority of the efm cluster. If set to

#  true, efm will stop the database before running the

#  script.primary.isolated script, if a script is specified.

stop.isolated.primary=true

stop.failed.primary プロパティを使用して、プライマリデータベースがデータベースに到達できない場合にシャットダウンを試行するようにフェールオーバーマネージャーに指示します。 true の場合、フェールオーバーマネージャーは、データベースをシャットダウンしようとした後、script.db.failure プロパティで指定されたスクリプトを実行します。

#  Attempt to shut down a failed primary database after EFM can no

#  longer connect to it. This can be used for added safety in the

#  case a failover is caused by a failure of the network on the

#  primary node.

#  If specified, a script.db.failure script is run after this attempt.

stop.failed.primary=true

primary.shutdown.as.failure プロパティを使用して、プライマリノードでのFailover Managerエージェントのシャットダウンを障害として扱います。このプロパティがtrue に設定されており、プライマリエージェントがシャットダウンされている場合、クラスターの残りの部分はシャットダウンを障害として扱います。これには、ノード全体のシャットダウンなど、エージェントの適切なシャットダウンが含まれます。この場合、タイムアウトプロパティはどれも適用されません。エージェントが終了すると、クラスターの残りの部分にすぐに通知されます。エージェントが終了すると、残りのクラスターは、プライマリエージェントに障害が発生した場合に発生する checks を実行します。 checks には、プライマリデータベースへの接続の試行、VIPを使用する場合に到達可能かどうかの確認などが含まれます。

  • データベースに到達すると、エージェントのステータスを通知する通知が送信されます。

  • データベースに到達しない場合、フェールオーバーが発生します。

#  Treat a primary agent shutdown as an agent failure. This can be set

#  to true to treat a primary agent shutdown as a failure situation.

#  Caution should be used when using this feature, as it could

#  cause an unwanted promotion in the case of performing primary

#  database maintenance.

#  Please see the users guide for more information.

primary.shutdown.as.failure=false

primary.shutdown.as.failure プロパティは、プライマリノードの誤ったシャットダウンなどの障害ではなく、ユーザーエラーをキャッチすることを目的としています。ノードの適切なシャットダウンは、クラスターの残りの部分には、ユーザーがプライマリデータベースのメンテナンスを実行するなど、プライマリフェールオーバーマネージャーエージェントを停止したように見える場合があります。 primary.shutdown.as.failure プロパティをtrue に設定する場合、メンテナンスの実行には注意してください。

primary.shutdown.as.failure がtrue のときにプライマリデータベースのメンテナンスを実行するには、プライマリエージェントを停止し、プライマリエージェントに障害が発生したがデータベースはまだ実行されているという通知を受信するまで待ちます。次に、プライマリデータベースを停止しても安全です。または、 stop-cluster コマンドを使用して、障害チェックを実行せずにすべてのエージェントを停止できます。

update.physical.slots.period プロパティを使用して、スロットの前進周波数を定義します。 update.physical.slots.period が正の整数値に設定されている場合、プライマリエージェントは、 update.physical.slots.period 秒ごとに物理レプリケーションスロットの現在のrestart_lsn を読み取ります。この情報は、 pg_current_wal_lsn およびprimary_slot_name postgresql.conf ファイルで設定されている場合 スタンバイに送信します。エージェントが物理スロットを見つけるには、プライマリに物理スロットが既に存在する必要があります。物理スロットがスタンバイにまだ存在しない場合、スタンバイエージェントはスロットを作成し、これらのスロットのrestart_lsn パラメーターを更新します。プロモーション不可のスタンバイは、新しいスロットを作成しませんが、存在する場合は更新します。

スロットのrestart_lsn 値を更新する前に、エージェントはxmin 値が設定されているかどうかを確認します。これは、これが以前にプライマリノードであった場合に発生する可能性があります。スロットにxmin 値が設定されている場合、エージェントはrestart_lsn 値を更新する前にスロットをドロップおよび再作成します。

注必要に応じて現在のプライマリに設定されたスロットを含むすべてのスロット名は、一意である必要があります。

#  Period in seconds between having the primary agent update promotable

#  standbys with physical replication slot information so that

#  the cluster will continue to use replication slots after a failover.

#  Set to zero to turn off.

update.physical.slots.period=0

ping.server.ip プロパティを使用して、フェールオーバーマネージャーがネットワーク接続に問題がないことを確認するために使用できるサーバーのIPアドレスを指定します。

#  This is the address of a well-known server that EFM can ping

#  in an effort to determine network reachability issues. It

#  might be the IP address of a nameserver within your corporate

#  firewall or another server that  *should*  always be reachable

#  via a ping command from each of the EFM nodes.

#

#  There are many reasons why this node might not be considered

#  reachable: firewalls might be blocking the request, ICMP might

#  be filtered out, etc.

#

#  Do not use the IP address of any node in the EFM cluster

#  (primary, standby, or witness) because this ping server is meant

#  to provide an additional layer of information should the EFM

#  nodes lose sight of each other.

#
#  The installation default is Googles DNS server.

ping.server.ip=8.8.8.8

ping.server.command プロパティを使用して、ネットワーク接続のテストに使用するコマンドを指定します。

#  This command will be used to test the reachability of certain

#  nodes.

#
#  Do not include an IP address or hostname on the end of

#  this command - it will be added dynamically at runtime with the

#  values contained in virtual.ip and ping.server.ip.

#

#  Make sure this command returns reasonably quickly - test it

#  from a shell command line first to make sure it works properly.

ping.server.command=/bin/ping -q -c3 -w5

auto.allow.hosts プロパティを使用して、許可ホストリストの設定を開始する最初のノードの.nodes ファイルで指定されたアドレスを使用するようにサーバーに指示します。 auto.allow.hosts をtrue に設定してこのプロパティを有効にすると、クラスターの起動が簡素化されます。

#  Have the first node started automatically add the addresses from

#  its .nodes file to the allowed host list. This will make it

#  faster to start the cluster when the initial set of hosts

#  is already known.

auto.allow.hosts=false

stable.nodes.file プロパティを使用して、ノードがクラスターに参加または離脱するときにノードファイルを書き換えないようにサーバーに指示します。このプロパティは、IPアドレスが変更されないクラスターで最も役立ちます。

#  When set to true, EFM will not rewrite the .nodes file whenever

#  new nodes join or leave the cluster. This can help starting a

#  cluster in the cases where it is expected for member addresses

#  to be mostly static, and combined with auto.allow.hosts makes

#  startup easier when learning failover manager.

stable.nodes.file=false

db.reuse.connection.count プロパティを使用すると、管理者は、フェールオーバーマネージャーが同じデータベース接続を再利用してデータベースの状態を確認する回数を指定できます。デフォルト値は0で、フェールオーバーマネージャーが毎回新しい接続を作成することを示します。このプロパティは、専用の監視ノードでは必要ありません。

#  This property controls how many times a database connection is

#  reused before creating a new one. If set to zero, a new

#  connection will be created every time an agent pings its local

#  database.

db.reuse.connection.count=0

auto.failover プロパティは、自動フェイルオーバーを有効にします。デフォルトでは、auto.failover はtrue に設定されます。

#  Whether or not failover will happen automatically when the primary

#  fails. Set to false if you want to receive the failover notifications

#  but not have EFM actually perform the failover steps.

#  The value of this property must be the same across all agents.

auto.failover=true

auto.reconfigure プロパティを使用して、プライマリスタンバイがプライマリに昇格した後、残りのスタンバイサーバーの自動再構成を有効または無効にするようにフェールオーバーマネージャーに指示します。自動再構成を有効にする場合はプロパティをtrue デフォルトに設定し、自動再構成を無効にする場合はfalse に設定します。このプロパティは、専用の監視ノードでは必要ありません。

#  After a standby is promoted, Failover Manager will attempt to

#  update the remaining standbys to use the new primary. Failover

#  Manager will change the host parameter of the primary_conninfo

#  entry in postgresql.auto.conf and restart the database. The

#  restart command is contained in either the efm_db_functions or

#  efm_root_functions file; default when not running db as an os

#  service is: "pg_ctl restart -m fast -w -t <timeout> -D <directory>"

#  where the timeout is the local.timeout property value and the

#  directory is specified by db.data.dir. To turn off

#  automatic reconfiguration, set this property to false.

auto.reconfigure=true

注釈

primary_conninfo は、keyword=valueペアのスペース区切りのリストです。

auto.rewind および/またはauto.basebackup プロパティがtrue に設定されている場合、エージェントはpg_rewind またはpg_basebackup を使用して、障害が発生したまたは置換されたプライマリデータベースをスタンバイとして再構成しようとします。適用されるいくつかのケース

  • プライマリデータベースの障害 新しいプライマリ用に再構成するようにエージェントが通知されると、元のプライマリエージェントは、再構築する必要があるかどうかを確認します。

  • 分離されたプライマリノード ノードがクラスターに再接続されると、プライマリエージェントは、新しいプライマリに置き換えられたかどうかを確認し、リビルドまたはプロモーションがなかった場合はプライマリとして再開する必要があるかどうかを確認します。

  • 起動時 エージェントがクラスター内に既にプライマリデータベースが存在し、ローカルデータベースがスタンバイとして構成されていないことを確認した場合、再構築する必要があるかどうかを確認します。

エージェントは、再構築の必要があることを確認した場合、現在のデータベース構成設定を収集し、以下を実行します。

  • auto.rewind がtrueに設定されている場合、エージェントは--dry-run オプションを指定してpg_rewind を実行して、巻き戻しが必要かどうかを確認し、指示されている場合は巻き戻し、監視を再開する前にデータベースをスタンバイとして再構成します。 pg_rewind の実行中にエラーが発生し、auto.basebackup がtrueに設定されている場合、エージェントはpg_basebackup でリビルドします。

  • auto.rewind がfalseに設定され、auto.basebackup がtrueに設定されている場合、エージェントはpg_basebackup を使用してデータベースを再構築し、監視を再開しようとします。

注釈

この機能は、障害が発生したノードをクラスターに自動的に戻す必要があり、障害の原因が既知および予測可能なユースケースを対象としているため、注意して使用します。 EFMが障害が発生したプライマリを再構築できず、手動介入がまだ必要である状況が発生する場合があります。

#  Set either or both of these properties to true to have this agent

#  attempt to reconfigure a failed primary database as a standby after

#  failover. If both properties are set to true, the agent will attempt

#  to use pg_rewind first, and then pg_basebackup if the rewind fails.

#  See the users guide for more information.

auto.rewind=false
auto.basebackup=false

注釈

auto.rewindは内部でpg_rewindを使用するため、このパラメーターを設定する前に pg_rewind のすべての前提条件を満たす必要があります。これは、 on に set wal_log_hints を設定するか、 data_checksums を手動で有効にする必要があることを意味します。

promotable プロパティを使用して、ノードを昇格させないことを示します。 promotable プロパティは、プライマリエージェントの起動時に無視されます。これにより、スイッチオーバーまたはフェイルオーバーの後に、元のプライマリへのスイッチングが簡単になります。設定をオーバーライドするには、実行時にefm set-priority コマンドを使用します。 efm set-priority コマンドの詳細については、 Using the efm utility を参照してください。

#  A standby with this set to false will not be added to the

#  failover priority list, and so will not be available for

#  promotion. The property will be used whenever an agent starts

#  as a standby or resumes as a standby after being idle. After

#  startup/resume, the node can still be added or removed from the

#  priority list with the efm set-priority command. This

#  property is required for all non-witness nodes.

promotable=true

同じ量のデータが複数のスタンバイノードに書き込まれ、フェールオーバーが発生した場合、use.replay.tiebreaker 値は、フェールオーバーマネージャーが置換プライマリを選択する方法を決定します。 use.replay.tiebreaker プロパティをtrue に設定して、ログシーケンス番号で決まり、より早く復旧するノードにフェールオーバーするようにフェールオーバーマネージャーに指示します。ログシーケンス番号を無視し、ユーザー設定に基づいてノードをプロモートするには、 use.replay.tiebreaker をfalse に設定します。

#  Use replay LSN value for tiebreaker when choosing a standby to

#  promote before using failover priority. Set this property to true to

#  consider replay location as more important than failover priority

#  (as seen in cluster-status command) when choosing the "most ahead"

#  standby to promote.

use.replay.tiebreaker=true

standby.restart.delay プロパティを使用して、プロモーション後に新しいプライマリに従うように再構成stoppstarts前にスタンバイが待機する時間を秒単位で指定します。

#  Time in seconds for this standby to delay restarting to follow the

#  primary after a promotion. This can be used to have standbys restart

#  at different times to increase availability. Caution should be used

#  when using this feature, as a delayed standby will not be following

#  the new primary and care must be taken that the new primary retains

#  enough WAL for the standby to follow it.

#  Please see the users guide for more information.

standby.restart.delay=0

application.name プロパティを使用して、古いプライマリノードをスタンバイとして再起動する前に、primary_conninfo パラメーターにコピーするアプリケーションの名前を提供できます。

#  During a switchover, recovery settings are copied from a standby

#  to the original primary. If the application.name property is set,

#  Failover Manager will replace the application_name portion of the

#  primary_conninfo entry with this property value before starting

#  the original primary database as a standby. If this property is

#  not set, Failover Manager will remove the parameter value

#  from primary_conninfo.

application.name=

注釈

プライマリおよびプロモーション可能なスタンバイで`application.name` プロパティを設定します。フェールオーバー/スイッチオーバーが発生すると、プライマリノードが再びスタンバイノードになる可能性があります。

restore.command プロパティを使用して、新しいプライマリが昇格したときにrestore_command 値を更新するようにフェールオーバーマネージャーに指示します。 %h は、新しいプライマリのアドレスを表します。フェールオーバーマネージャーは、 %h を新しいプライマリのアドレスに置き換えます。 %f および%p は、サーバーが使用するプレースホルダーです。プロパティが空白のままの場合、フェールオーバーマネージャーは、プロモーション後にスタンバイのrestore_command 値を更新しません。

restore_command の使用の詳細については、 PostgreSQLドキュメントを参照してください。

#  If the restore_command on a standby restores directly from the

#  primary node, use this property to have Failover Manager change

#  the command when a new primary is promoted.

#

#  Use the %h placeholder to represent the address of the new primary.

#  During promotion it will be replaced with the address of the new

#  primary.

#

#  If not specified, failover manager will not change the

#  restore_command value, if any, on standby nodes.

#
#  Example:

#  restore.command=scp <db service owner>@%h:/var/lib/edb/as12/data/archive/%f %p

restore.command=

backup_wal プロパティを使用して、新しいプライマリに従うように再構成中にスタンバイでローカルWALのバックアップを作成するようにフェールオーバーマネージャーに指示します。

#  When a standby is reconfigured to follow a new primary, its local WAL

#  is removed. Set this property to true to create a backup of the WAL first.

#  This is generally not necessary; the property has been added to allow

#  backwards compatibility with the behavior of versions of Failover Manager

#  before version 5. If not specified defaults to false.

backup.wal=false

プライマリノードのデータベースパラメーターsynchronous_standby_names は、データの受信を確認してプライマリノードが書き込みトランザクションを受け入れられるようにする同期スタンバイサーバーの名前と数を指定します。 reconfigure.num.sync プロパティがtrue に設定されている場合、フェールオーバーマネージャーは同期スタンバイサーバーの数を減らし、プライマリノードの構成をリロードして現在の値を反映します。

#  Reduce num_sync when the number of synchronous standbys drops below

#  the value required by the primary database. If set to true, Failover

#  Manager will reduce the number of standbys needed in the primarys

#  synchronous_standby_names property and reload the primary

#  configuration. Failover Manager will not reduce the number below 1,

#  taking the primary out of synchronous replication, unless the

#  reconfigure.sync.primary property is also set to true.

#  To raise num_sync, see the reconfigure.num.sync.max property below.

reconfigure.num.sync=false

reconfigure.num.sync.max プロパティを使用して、スタンバイがクラスターに追加されたときにnum-syncを上げることができる最大数を指定します。

#  If reconfigure.num.sync is set to true and this property is set,

#  Failover Manager will check if num_sync can be raised when a standby

#  is added to the cluster.

#  Failover Manager will not raise the value above the maximum set here.

#  If the primary database has been taken out of synchronous mode

#  completely (see the reconfigure.sync.primary property), then Failover

#  Manager will not reconfigure the primary database if standbys are

#  added to the cluster.

reconfigure.num.sync.max=

スタンバイノードの数が必要なレベルを下回った場合に、プライマリデータベースを同期レプリケーションモードから解除するには、 reconfigure.sync.primary プロパティをtrue に設定します。同期レプリケーションを中断せずにスタンバイ数が低下した場合に通知を送信するようにreconfigure.sync.primary 〜false を設定します。

#  Take the primary database out of synchronous replication mode when

#  needed. If set to true, Failover Manager will clear the

#  synchronous_standby_names configuration parameter on the primary

#  if the number of synchronous standbys drops below the required

#  level for the primary to accept writes.

#  If set to false, Failover Manager will detect the situation but

#  will only send a notification if the standby count drops below the

#  required level.

#
#  CAUTION: TAKING THE PRIMARY DATABASE OUT OF SYNCHRONOUS MODE MEANS

#  THERE MAY ONLY BE ONE COPY OF DATA. DO NOT MAKE THIS CHANGE UNLESS

#  YOU ARE SURE THIS IS OK.

reconfigure.sync.primary=false

注釈

5.0より前のフェールオーバーマネージャーバージョンの場合 reconfigure.num.sync または`reconfigure.sync.primary` プロパティを使用している場合、プライマリデータベースの`wal_sender_timeout` 値が`efm.node.timeout` 値より少なくとも10秒小さく設定されていることを確認します。 Failover Managerバージョン5.0以降、num_syncチェックはクラスターの変更の結果ではなく、定期的に発生します。

check.num.sync.period プロパティを使用して、プライマリデータベースに必要な数より多いまたは少ない同期スタンバイがあるかどうかを確認する秒単位の期間を定義します。 reconfigure.num.sync またはreconfigure.sync.primary プロパティがtrueに設定されている場合、フェールオーバーマネージャーは必要に応じてプライマリのsynchronous_standby_names を変更します。両方のプロパティがfalseの場合、プライマリに必要な数の同期スタンバイが存在しない場合、フェールオーバーマネージャーは通知を送信します。

#  Period in seconds between checking if the primary database has more or fewer

#  synchronous standbys than it requires. If the reconfigure.num.sync or

#  reconfigure.sync.primary properties are used, Failover Manager will change

#  synchronous_standby_names on the primary as needed. If the primary

#  database is not in synchronous mode, this property has no effect.

check.num.sync.period=30

注釈

エージェントログがいっぱいになるのを回避するために、フェールオーバーマネージャーはDEBUGレベルでプライマリノードの同期スタンバイに関する情報をログに記録します。この情報は、任意のノードで`efm cluster-status` コマンドを実行することにより、必要に応じてINFOレベルでログに記録できます。定期的なバックグラウンドステータスチェックによっても、情報がログに記録されます。

minimum.standbys プロパティを使用して、クラスターに保持するスタンバイノードの最小数を指定します。スタンバイ数が指定された最小値まで低下すると、プライマリノードの障害が発生した場合にレプリカノードは昇格されません。

#  Instead of setting specific standbys as being unavailable for

#  promotion, this property can be used to set a minimum number

#  of standbys that will not be promoted. Set to one, for

#  example, promotion will not happen if it will drop the number

#  of standbys below this value. This property must be the same on

#  each node.

minimum.standbys=0

priority.standbys プロパティを使用して、このノードが昇格した後、スタンバイの優先度を指定します。

#  Space-separated list of standby addresses that are high priority for

#  promotion when this node is the primary. If set, when this node is

#  promoted, addresses in this list will be added to the front of the

#  standby priority list. If this list contains addresses that are not

#  standbys at the time of promotion, they will not be added.

priority.standbys=

recovery.check.period プロパティを使用して、データベースが復旧していないかどうかを確認する前にフェールオーバーマネージャーが待機する秒数を指定します。

#  Time in seconds between checks to see if a promoting database

#  is out of recovery.

recovery.check.period=1

restart.connection.timeout プロパティを使用して、ノード上のデータベースが接続を受け入れる準備をしているときに、フェールオーバーマネージャーが新しく再構成されたプライマリまたはスタンバイノードに接続を試行する秒数を指定します。

#  Time in seconds to keep trying to connect to a database after a start

#  or restart command returns successfully but the database is not

#  ready to accept connections yet (a rare occurrence). This applies to

#  standby databases that are restarted when being reconfigured for a new

#  primary, and to primary databases that are stopped and started as

#  standbys during a switchover.

#
#  This retry mechanism is unrelated to the auto.resume.*.period parameters.

restart.connection.timeout=60

auto.resume.startup.period プロパティを使用して、エージェントがそのデータベースの監視を再開する秒数を指定します。このプロパティは、IDLEモードで起動するときに適用されます。

#  Period in seconds for agents to try to resume monitoring when starting

#  in IDLE mode. Set to 0 for agents to not try to resume (in which case

#  the efm resume <cluster> command is used after bringing a database up).

auto.resume.startup.period=0

auto.resume.failure.period プロパティを使用して、エージェントがそのデータベースの監視を再開する秒数を指定します。このプロパティは、監視対象データベースに障害が発生し、エージェントがアイドル状態になった後に適用されます。

#  Period in seconds for IDLE agents to try to resume monitoring after

#  a database failure. Set to 0 for agents to not try to resume (in

#  which case the efm resume <cluster> command is used after

#  bringing a database back up).

auto.resume.failure.period=0

!!!注Failover Managerバージョン4.xでは、両方の動作を制御する単一のプロパティauto.resume.period がありました。構成を4.xから5.xにアップグレードする場合、アップグレードユーティリティはauto.resume.startup.period およびデフォルトのauto.resume.failure.period の元の値をゼロに維持します。

フェールオーバーマネージャーは、仮想IPを使用するクラスターのサポートを提供します。クラスターが仮想IPを使用する場合、 virtual.ip プロパティにホスト名またはIPアドレスを指定します。 virtual.ip.prefix プロパティで、対応する接頭辞を指定します。 virtual.ip のままにして、仮想IPサポートを無効にします。

virtual.ip.interface プロパティを使用して、VIPが使用するネットワークインターフェイスを提供します。

指定された仮想IPアドレスは、クラスターのプライマリノードにのみ割り当てられます。 virtual.ip.single=true を指定すると、フェールオーバーが発生した場合に新しいプライマリで同じVIPアドレスが使用されます。 false の値を指定して、クラスターの各ノードに一意のIPアドレスを提供します。

仮想IPアドレスの使用については、 Using Failover Manager with virtual IP addresses を参照してください。

#  These properties specify the IP and prefix length that will be

#  remapped during failover. If you do not use a VIP as part of

#  your failover solution, leave the virtual.ip property blank to

#  disable Failover Manager support for VIP processing (assigning,

#  releasing, testing reachability, etc).

#

#  If you specify a VIP, the interface and prefix are required.

#

#  If you specify a host name, it will be resolved to an IP address

#  when acquiring or releasing the VIP. If the host name resolves

#  to more than one IP address, there is no way to predict which

#  address Failover Manager will use.

#
#  By default, the virtual.ip and virtual.ip.prefix values must be

#  the same across all agents. If you set virtual.ip.single to

#  false, you can specify unique values for virtual.ip and

#  virtual.ip.prefix on each node.

#
#  If you are using an IPv4 address, the virtual.ip.interface value

#  should not contain a secondary virtual ip id (do not include

#  ":1", etc).

virtual.ip=
virtual.ip.interface=
virtual.ip.prefix=
virtual.ip.single=true

注釈

プライマリエージェントが起動し、ノードに現在VIPがない場合、Failover Managerエージェントがそれを取得します。プライマリエージェントを停止しても、ノードからVIPはドロップされません。

check.vip.before.promotion プロパティをfalse に設定して、フェールオーバーマネージャーが、障害が発生した場合に新しいプライマリに割り当てる前にVIPが使用中であるかどうかを確認しないようにします。これにより、複数のノードが同じVIPアドレスでブロードキャストする場合があります。プライマリノードが分離されている場合、または別のプロセスを介してシャットダウンできる場合を除き、このプロパティをto true に設定します。

#  Whether to check if the VIP (when used) is still in use before

#  promoting after a primary failure. Turning this off may allow

#  the new primary to have the VIP even though another node is also

#  broadcasting it. This should only be used in environments where

#  it is known that the failed primary node will be isolated or

#  shut down through other means.

check.vip.before.promotion=true

VIPが到達不能になるまでにデフォルトの60秒より長くかかる可能性がある場合は、 check.vip.timeout プロパティを使用して、フェールオーバーマネージャーが待機する最大時間を増やします。

#  If check.vip.before.promotion is set to true, use this property to set

#  the total amount of time in seconds to wait for the VIP (when used) to

#  become unreachable.

check.vip.timeout=60

release.vip.* プロパティは、VIPがノードから解放されるタイミングを制御するために使用できます。詳細については、 Using Failover Manager with virtual IP addresses を参照してください。

#  In certain networks, there can be errors trying to connect to remote databases

#  at the same time the VIP is being released (i.e. on the primary node during a

#  switchover). Set the release.vip.background property to false to have the agent

#  pause while the VIP is being released. The pre and post wait periods can add

#  time (in seconds) to wait before and after the VIP is released in case there

#  are other network effects that require them.

release.vip.background=true
release.vip.pre.wait=0
release.vip.post.wait=0

pgpool.enable プロパティを使用して、高可用性のためにフェールオーバーマネージャーとPgプールの統合を有効にするかどうかを指定します。非sudoモードDB所有者として実行でPgプール統合を有効にする場合、PCPPASSファイルはDB所有者オペレーティングシステムユーザーが所有し、ファイル許可を600に設定する必要があります。

#  A boolean property to enable Failover Manager managed Pgpool HA.

#  If enabled, Failover Manager would natively update the joining

#  and leaving status of database nodes to active pgpool instance.

#  Failover manager expects properly configured and running pgpool

#  instances on required nodes. It does not manage setup and

#  configuration of pgpool on any node.

#
#  By default the property is disabled.

pgpool.enable=false

次のパラメーターを使用して、Pgpool統合に使用する値を指定します。

#  Configurations required for pgpool integration.

#  pcp.user - User that would be invoking PCP commands

#  pcp.host - Virtual IP that would be used by pgpool. Same as

#  pgpool parameter delegate_IP

#  pcp.port - The port on which pgpool listens for pcp commands.

#  pcp.pass.file - Absolute path of PCPPASSFILE.

#  pgpool.bin - Absolute path of pgpool bin directory

#  These properties are required if pgpool.enable is set to true.

pcp.user=
pcp.host=
pcp.port=
pcp.pass.file=
pgpool.bin=

次のプロパティを使用して、スイッチオーバーまたはプライマリ障害シナリオが発生した場合にロードバランサーを再構成するスクリプトへのパスを提供します。スクリプトは、スタンバイ障害が発生したときにも呼び出されます。これらのプロパティを使用している場合、クラスターのすべてのノードプライマリ、スタンバイ、および監視でそれらを提供して、データベースノードに障害が発生すると、別のノードが障害が発生したノードのアドレスでデタッチスクリプトを呼び出すようにします。

ロードバランサーソリューションとしてPgpoolを使用し、Pgpool統合プロパティを設定している場合、次のプロパティを設定する必要はありません。

script.load.balancer.attach プロパティにちなんで名前付けたスクリプトを提供して、ノードをロードバランサーに接続するときに呼び出すスクリプトを指定します。 script.load.balancer.detach プロパティを使用して、ロードバランサーからノードを切断するときに呼び出すスクリプトの名前を指定します。 %h プレースホルダーを含めて、クラスターに接続または削除されるノードのIPアドレスを表します。文字列にpプライマリノードの場合またはsスタンバイノードの場合を含めるようにフェールオーバーマネージャーに指示するには、 %t プレースホルダーを含めます。

#  Absolute path to load balancer scripts

#  The attach script is called when a node should be attached to

#  the load balancer, for example after a promotion. The detach

#  script is called when a node should be removed, for example

#  when a database has failed or is about to be stopped. Use %h to

#  represent the IP/hostname of the node that is being

#  attached/detached. Use %t to represent the type of node being

#  attached or detached: the letter m will be passed in for primary nodes

# and the letter s for standby nodes.

#
#  Example:

#  script.load.balancer.attach=/somepath/attachscript %h %t

script.load.balancer.attach=
script.load.balancer.detach=
  1. 0以降のバージョンでは、この値はデフォルトでfalse に設定されます。これは、プライマリエージェントに障害が発生した場合でも、フェールオーバーマネージャーはロードバランサーからノードを切断しないが、データベースにはまだ到達可能であることを意味します。以前のバージョンでは、デフォルトはtrue に設定されていました。値を初期のフェールオーバーマネージャー動作との下位互換性が必要な場合にのみtrue に設定します。

#  If set to true, Failover Manager will detach the node from load

#  balancer if the primary agent fails but the database is still

#  reachable. In most scenarios this is NOT the desired situation. In

#  scenarios where the detach script should run with a failed primary

#  agent, even when the primary database is still healthy this parameter

#  should be set to true. If no value specified it defaults to true (for

#  backwards compatibility).

#  This is not applicable for standbys.

detach.on.agent.failure=

script.fence プロパティは、スタンバイノードからプライマリノードへの昇格中に呼び出すオプションのユーザー指定スクリプトへのパスを指定します。

#  absolute path to fencing script run during promotion

#

#  This is an optional user-supplied script that will be run

#  during failover on the standby database node. If left blank,

#  no action will be taken. If specified, EFM will execute this

#  script before promoting the standby.

#
#  Parameters can be passed into this script for the failed primary

#  and new primary node addresses. Use %p for new primary and %f

#  for failed primary. On a node that has just been promoted, %p

#  should be the same as the nodes efm binding address.

#
#  Example:

#  script.fence=/somepath/myscript %p %f

#
#  NOTE: FAILOVER WILL NOT OCCUR IF THIS SCRIPT RETURNS A NON-ZERO EXIT

#  CODE.

script.fence=

script.post.promotion プロパティを使用して、スタンバイノードがプライマリに昇格した後に呼び出すオプションのユーザー指定スクリプトへのパスを指定します。

#  Absolute path to fencing script run after promotion

#

#  This is an optional user-supplied script that will be run after

#  failover on the standby node after it has been promoted and

#  is no longer in recovery. The exit code from this script has

#  no effect on failover manager, but will be included in a

#  notification sent after the script executes.

#

#  Parameters can be passed into this script for the failed primary

#  and new primary node addresses. Use %p for new primary and %f

#  for failed primary. On a node that has just been promoted, %p

#  should be the same as the nodes efm binding address.

#
#  Example:

#  script.post.promotion=/somepath/myscript %f %p

script.post.promotion=

script.resumed プロパティを使用して、エージェントがデータベースの監視を再開したときに呼び出すユーザー指定スクリプトへのオプションのパスを指定します。

#  Absolute path to resume script

#

#  This script is run before an IDLE agent resumes

#  monitoring its local database.

script.resumed=

script.db.failure プロパティを使用して、監視対象データベースに障害が発生したことをエージェントが検出した場合にフェールオーバーマネージャーが呼び出すオプションのユーザー指定スクリプトへの完全なパスを指定します。

#  Absolute path to script run after database failure

#  This is an optional user-supplied script that will be run after

#  an agent detects that its local database has failed.

script.db.failure=

script.primary.isolated プロパティを使用して、プライマリがフェールオーバーマネージャークラスターの大部分から分離されていることをプライマリデータベースを監視するエージェントが検出した場合に、フェールオーバーマネージャーが呼び出すオプションのユーザー指定スクリプトへの完全なパスを指定します。このスクリプトは、VIPが解放された直後に呼び出されますVIPが使用中の場合。

#  Absolute path to script run on isolated primary

#  This is an optional user-supplied script that will be run after

#  a primary agent detects that it has been isolated from the

#  majority of the efm cluster.

script.primary.isolated=

script.remote.pre.promotion プロパティを使用して、ノードがデータベースをプライマリに昇格させようとしているときに、プロモーションに関係しないエージェントノードで呼び出すスクリプトのパスと名前を指定します。

%pプレースホルダーを含めて、新しいプライマリノードのアドレスを指定します。

#  Absolute path to script invoked on non-promoting agent nodes

#  before a promotion.

#
#  This optional user-supplied script will be invoked on other

#  agents when a node is about to promote its database. The exit

#  code from this script has no effect on Failover Manager, but

#  will be included in a notification sent after the script

#  executes.

#

#  Pass a parameter (%p) with the script to identify the new

#  primary node address.

#
#  Example:

#  script.remote.pre.promotion=/path_name/script_name %p

script.remote.pre.promotion=

script.remote.post.promotion プロパティを使用して、プロモーションが発生した後に非プライマリノードで呼び出すスクリプトのパスと名前を指定します。

%pプレースホルダーを含めて、新しいプライマリノードのアドレスを指定します。

#  Absolute path to script invoked on non-primary agent nodes

#  after a promotion.

#
#  This optional user-supplied script will be invoked on nodes

#  (except the new primary) after a promotion occurs. The exit code

#  from this script has no effect on Failover Manager, but will be

#  included in a notification sent after the script executes.

#
#  Pass a parameter (%p) with the script to identify the new

#  primary node address.

#
#  Example:

#  script.remote.post.promotion=/path_name/script_name %p

script.remote.post.promotion=

script.custom.monitor プロパティを使用して、 custom.monitor.interval プロパティで秒単位で指定される定期的に呼び出すオプションスクリプトの名前と場所を提供します。

custom.monitor.timeout を使用して、スクリプトの実行の最大時間を指定します。スクリプトの実行が指定された時間内に終了しない場合、フェールオーバーマネージャーは通知を送信します。

custom.monitor.safe.mode からtrue を設定して、スクリプトからゼロ以外の終了コードを報告するようにフェールオーバーマネージャーに指示しますが、終了コードの結果としてスタンバイをプロモートしません。

#  Absolute path to a custom monitoring script.

#

#  Use script.custom.monitor to specify the location and name of

#  an optional user-supplied script that will be invoked

#  periodically to perform custom monitoring tasks. A non-zero

#  exit value means that a check has failed; this will be treated

#  as a database failure. On a primary node, script failure will

#  cause a promotion. On a standby node script failure will

#  generate a notification and the agent will become IDLE.

#

#  The custom.monitor.\* properties are required if a custom

#  monitoring script is specified:

#
#  custom.monitor.interval is the time in seconds between executions

#  of the script.

#
#  custom.monitor.timeout is a timeout value in seconds for how

#  long the script will be allowed to run. If script execution

#  exceeds the specified time, the task will be stopped and a

#  notification sent. Subsequent runs will continue.

#
#  If custom.monitor.safe.mode is set to true, non-zero exit codes

#  from the script will be reported but will not cause a promotion

#  or be treated as a database failure. This allows testing of the

#  script without affecting EFM.

#
script.custom.monitor=

custom.monitor.interval=
custom.monitor.timeout=
custom.monitor.safe.mode=

sudo.command プロパティを使用して、拡張されたアクセス許可を必要とするタスクを実行するときに呼び出すフェールオーバーマネージャーのコマンドを指定します。このオプションを使用して、システム認証に固有のコマンドオプションを含めます。

sudo.user.command プロパティを使用して、データベース所有者が実行するコマンドを実行したときに呼び出すフェールオーバーマネージャーのコマンドを指定します。

#  Command to use in place of sudo if desired when efm runs

#  the efm_db_functions or efm_root_functions, or efm_address

#  scripts.

#  Sudo is used in the following ways by efm:

#
#  sudo /usr/edb/efm-<version>/bin/efm_address <arguments>

#  sudo /usr/edb/efm-<version>/bin/efm_root_functions <arguments>

#  sudo -u <db service owner> /usr/edb/efm-<version>/bin/efm_db_functions <arguments>

#

#  sudo in the first two examples will be replaced by the value

#  of the sudo.command property. sudo -u <db service owner> will

#  be replaced by the value of the sudo.user.command property.

#  The %u field will be replaced with the db owner.

sudo.command=sudo
sudo.user.command=sudo -u %u

lock.dir プロパティを使用して、フェールオーバーマネージャーロックファイルの代替の場所を指定します。このファイルは、フェールオーバーマネージャーがノード上の単一のクラスターに対して複数の孤立する可能性のあるエージェントを起動するのを防ぎます。

#  Specify the directory of lock file on the node. Failover

#  Manager creates a file named <cluster>.lock at this location to

#  avoid starting multiple agents for same cluster. If the path

#  does not exist, Failover Manager will attempt to create it. If

#  not specified defaults to /var/lock/efm-<version>

lock.dir=

log.dir プロパティを使用して、エージェントログファイルを書き込む場所を指定します。ディレクトリが存在しない場合、フェールオーバーマネージャーはディレクトリを作成しようとします。 efm.properties ファイルで定義されたlog.dir パラメーターは、EFMログが保存されるディレクトリパスを決定します。このパラメーターはEFMログにのみ適用され、他のコンポーネントまたはサービスのロギング構成には影響しません。

EFMバージョン4.xの起動ログの場所を変更するには、EFM binディレクトリにあるrunefm.sh スクリプトを変更します。このスクリプトでLOG パラメーターを設定して、目的のログファイルの場所を定義します。

#  Specify the directory of agent logs on the node. If the path does not exist,

#  Failover Manager will attempt to create it.

#  If not specified defaults to /var/log/efm-<version>.

#  If using a custom log directory, you must configure logrotate separately.

#  Use man logrotate for more information.

log.dir=

フェールオーバーマネージャーホストでUDPまたはTCPプロトコルを有効にした後、syslogへのロギングを有効にできます。 syslog.protocol パラメーターを使用してプロトコルタイプUDPまたはTCPを指定し、 syslog.port パラメーターを使用してsyslogホストのリスナーポートを指定します。 syslog.facility 値は、エントリーを作成したプロセスの識別子として使用できます。 LOCAL0〜LOCAL7の値を使用します。

#  Syslog information. The syslog service must be listening on

#  the port for the given protocol, which can be UDP or TCP.

#  The facilities supported are LOCAL0 through LOCAL7.

syslog.host=localhost
syslog.port=514
syslog.protocol=UDP
syslog.facility=LOCAL1

file.log.enabled およびsyslog.enabled プロパティを使用して、実装するロギングのタイプを指定します。ファイルへのロギングを有効にするには、 file.log.enabled をtrue に設定します。 UDPプロトコルまたはTCPプロトコルを有効にし、syslog.enabled をtrue に設定してsyslogへのロギングを有効にします。ファイルとsyslogの両方へのロギングを有効にできます。

#  Which logging is enabled.

file.log.enabled=true
syslog.enabled=false

syslogログの構成の詳細については、 syslogログファイルエントリの有効化 を参照してください。

jgroups.loglevel 、efm.loglevel 、およびjdbc. loglevel パラメーターを使用して、フェールオーバーマネージャーによってログに記録される詳細レベルを指定します。デフォルト値はINFO です。ロギングの詳細については、 Controlling logging を参照してください。

#  Logging levels for JGroups and EFM.

#  Valid values are: TRACE, DEBUG, INFO, WARN, ERROR

#  Default value: INFO

#  It is not necessary to increase these values unless debugging a specific

#  issue. If nodes are not discovering each other at startup, increasing

#  the jgroups level to DEBUG will show information about the TCP connection

#  attempts that may help diagnose the connection failures.

#  If there are issues with creating database connections, increasing

#  the jdbc.loglevel level will show more information.

#  TRACE level logging should be used for diagnosing problems only.

#  It is not supported for production use.

jgroups.loglevel=INFO
efm.loglevel=INFO
jdbc.loglevel=INFO

jvm.options プロパティを使用して、JVM関連の構成情報を渡します。デフォルト設定では、Failover Managerエージェントが使用できるメモリの量を指定します。

#  Extra information that will be passed to the JVM when starting

#  the agent.

jvm.options=-Xmx128m

encrypting_database_password