Security and Roles¶
Beyond basic package installation and configuration, HARP itself does requirePostgres permissions to operate. These allow it to gather information aboutPostgres or BDR as necessary to maintain node status within the ConsensusLayer.
Postgres Permissions¶
The role specified in the node.dsn parameter must have been created
oneof the following ways:
CREATE USER ...CREATE ROLE ... WITH LOGIN
This ensures the role is capable of logging into the database in order togather diagnostic information.
Similarly, an entry must exist in pg_hba.conf for this role. This
can be donemany ways. As an example, consider a VPN subnet where all
database hosts arelocated somewhere in 10.10.*. In such a case, the
easiest approach is to adda specific line:
# TYPE DATABASE USER ADDRESS METHOD
hostssl all harp_user 10.10.1.1/16 scram-sha-256
!!! Note * In this case we’ve used the more modern scram-sha-256
authentication rather than md5 which is now deprecated. We’ve also
elected to require SSL authentication by specifying hostssl.
BDR Permissions¶
BDR nodes have metadata and views that are only visible when certain roles aregranted to the HARP-enabled user. In this case, the HARP user requires thefollowing:
GRANT bdr_monitor TO harp_user;
The bdr_monitor BDR role is meant for status monitoring tools to
maintainongoing information on cluster operation, thus is perfectly
suited to HARP.
BDR Consensus Permissions¶
When the dcs.driver configuration parameter is set to bdr, HARP
will utilize BDR itself as the Consensus Layer. As such, it requires
access to API methods that are currently only available to the
bdr_superuser role. This means the HARP-enabled user requires the
following:
GRANT bdr_superuser TO foobar;
This may change in future versions of BDR, but currently access to the BDRconsensus model does require superuser equivalent permission.
!!! Important * BDR Superusers are not Postgres superusers. The
bdr_superuser role is merely granted elevated privileges within BDR
itself, such as access to restricted functions, tables, views, and other
objects.