Extending Failover Manager permissions

Extending Failover Manager permissions#

フェールオーバーマネージャーのインストール中に、インストーラーはefmという名前のユーザーを作成します。 efmは、通常データベース所有者またはオペレーティングシステムのスーパーユーザーに制限されている管理機能を実行するための十分な特権がありません。

  • 仮想IPアドレスの割り当てまたは解放時に、efmはefm_db_functions スクリプトを呼び出します。

  • オペレーティングシステムのスーパーユーザー権限を必要とする管理機能を実行する場合、efmはefm_root_functions スクリプトを呼び出します。

  • 仮想IPアドレスを割り当てまたは解放するときに、efmはefm_address スクリプトを呼び出します。

  • Pgpool統合を有効にすると、efmはefm_pgpool_functions スクリプトを呼び出します。

efm_db_functions またはefm_root_functions スクリプトは、 efmユーザーに代わって管理機能を実行します。

sudoers ファイルには、ユーザーefmがpostgresまたはenterprisedbが所有するクラスターのFailover Managerサービスを制御できるエントリが含まれています。 sudoers ファイルのコピーを変更して、他のユーザーが所有するPostgresクラスターを管理する権限をefmに付与できます。

efm-50 ファイルは/etc/sudoers.d にあり、次のエントリが含まれています。

#  Copyright EnterpriseDB Corporation, 2014-2025. All Rights Reserved.

#

#  Do not edit this file. Changes to the file may be overwritten

#  during an upgrade.

#
#  This file assumes you are running your efm cluster as user efm.  If not,

#  then you will need to copy this file.

#  Allow user efm to sudo efm_db_functions as either postgres or enterprisedb.

#  If you run your db service under a non-default account, you will need to copy

#  this file to grant the proper permissions and specify the account in your efm

#  cluster properties file by changing the db.service.owner property.

efm    ALL=(postgres)      NOPASSWD:   /usr/edb/efm-5.2/bin/efm_db_functions
efm    ALL=(enterprisedb)  NOPASSWD:   /usr/edb/efm-5.2/bin/efm_db_functions

#  Allow user efm to sudo efm_root_functions as root to write/delete the PID file,

#  validate the db.service.owner property, etc.

efm    ALL=(ALL)           NOPASSWD:   /usr/edb/efm-5.2/bin/efm_root_functions

#  Allow user efm to sudo efm_address as root for VIP tasks.

efm    ALL=(ALL)           NOPASSWD:   /usr/edb/efm-5.2/bin/efm_address

#  Allow user efm to sudo efm_pgpool_functions as root for pgpool tasks.

efm    ALL=(ALL)           NOPASSWD:   /usr/edb/efm-5.2/bin/efm_pgpool_functions

#  relax tty requirement for user efm

Defaults:efm !requiretty

フェールオーバーマネージャーを使用して、postgresまたはenterprisedb以外のユーザーが所有するクラスターを監視している場合、efm-50 ファイルのコピーを作成します。次に、コンテンツを変更して、ユーザーがefm_functions スクリプトにアクセスしてクラスターを管理できるようにします。

権限の問題のためエージェントが起動できない場合は、デフォルトの/etc/sudoers ファイルの最後に次の行が含まれていることを確認します。

##  Read drop-in files from /etc/sudoers.d (the # here does not # mean a comment)

# includedir /etc/sudoers.d

sudoなしでフェールオーバーマネージャーを実行する#

既定では、フェールオーバーマネージャーはsudoを使用して、システム機能へのアクセスを安全に管理します。 sudoアクセスなしで実行するようにフェールオーバーマネージャーを構成する場合、次の操作には引き続きルートアクセスが必要です。

  • Failover Manager RPMをインストールします。

  • フェールオーバーマネージャーのセットアップタスクを実行します。

sudoを使用せずにフェールオーバーマネージャーを実行するには、フェールオーバーマネージャーに代わって管理機能を実行する権限を持つデータベースプロセスの所有者を選択する必要があります。ユーザーは、デフォルトのデータベーススーパーユーザーたとえば、enterprisedbまたはpostgresまたは別の特権ユーザーです。ユーザーを選択した後

  1. 次のコマンドを使用して、ユーザーをefm グループに追加します。

usermod -a -G efm enterprisedb

このコマンドにより、ユーザーは/var/run/efm-5.<x> および/var/lock/efm-5.<x> に書き込むことができます。

  1. クラスター名を再利用する場合は、以前に作成したログファイルを削除します。新しいユーザーは、デフォルトまたは他の所有者が作成したログファイルに書き込むことができません。

  2. クラスタープロパティテンプレートファイルとノードテンプレートファイルをコピーします。

su - enterprisedb

cp /etc/edb/efm-5.2/efm.properties.in <directory/cluster_name>.properties

cp /etc/edb/efm-5.2/efm.nodes.in <directory>/<cluster_name>.nodes

次に、クラスタープロパティファイルを変更し、 db.service.owner プロパティにユーザーの名前を指定します。また、 db.service.name プロパティが空白であることを確認します。 sudoがないと、ルートアクセスなしでサービスを実行できません。

構成を変更した後、新しいユーザーは次のコマンドでフェールオーバーマネージャーを制御できます。

/usr/edb/efm-5.2/bin/runefm.sh start|stop <directory/cluster_name>.properties

<directory/cluster_name.properties> は、クラスタープロパティファイルのフルパスを指定します。ユーザーはデフォルト以外のユーザーがエージェントを制御しているとき、またはefm スクリプトを使用しているときは常に、プロパティファイルへのフルパスを提供します。

新しいユーザーがフェールオーバーマネージャーをサービスとして管理できるようにするには、カスタムスクリプトまたはユニットファイルを提供します。

フェールオーバーマネージャーは、 /usr/edb/efm-5.<x>/bin/secure/ にあるmanage-vip という名前のバイナリを使用して、sudo特権なしでVIP管理操作を実行します。このスクリプトは、setuidを使用して、仮想IPアドレスの管理に必要な特権を取得します。

  • このディレクトリには、rootとefmグループのユーザーのみがアクセスできます。

  • バイナリは、rootおよびefmグループのみが実行可能です。

セキュリティ上の理由から、 /usr/edb/efm-5.<x>/bin/secure/ ディレクトリまたはmanage-vip スクリプトのアクセス権限を変更しないことをお勧めします。

sudoなしでフェールオーバーマネージャーを使用する方法の詳細については、次のWebサイトをご覧ください。

https://www.enterprisedb.com/blog/running-edb-postgres-failover-manager-without-sudo