Setting agent privileges#
デフォルトでは、PEMエージェントは、オペレーティングシステムホストのroot権限とデータベースサーバーのスーパーユーザー権限でインストールされます。これらの特権により、PEMエージェントは、システムの使用状況について監視対象ホストおよびデータベースサーバーで無制限のプローブを呼び出し、情報を取得してPEMサーバーに返すことができます。
rootユーザーと非rootユーザー#
PEMエージェントの権限が低下すると、PEM機能が低下します。完全な機能を実現するには、rootとしてPEMエージェントを実行します。 次の表は、特権を制限した場合の影響の高レベルの概要を示しています。 詳細については、後続のセクションで説明します。
Feature name |
Works with root user |
Works with non-root user |
Works with remote PEM agent |
|---|---|---|---|
Audit Manager |
yes |
The Audit Log Manager might not be able to apply requested modifications if the service can't be restarted. The user running the PEM agent might be different from the user who owns the data directory of the database server. Thus the user running the PEM agent might not be able to change the configuration and also might not be able to restart the services of the database server. |
no |
Capacity Manager |
yes |
yes |
yes Note: There's no correlation between the database server and operating system metrics |
Log Manager |
yes |
The Log Manager might not be able to apply requested modifications if the service can't restart. The user running the PEM agent might be different from the user who owns the data directory of the database server. Thus the user running the PEM agent might not be able to change the configuration and also might not be able to restart the services of the database server. |
no |
Manage Alerts |
yes |
yes |
yes Note: When Run Alert Script on the database server is selected, it runs on the machine where the bound PEM agent is running and not on the actual database server machine. |
Manage Charts |
yes |
yes |
yes |
Manage Dashboards |
yes |
Some dashboards might not be able to show complete data - see below for more details. |
Some dashboards might not be able to show complete data. For example, the operating system information of the database server doesn't appear as not available. |
Manage Probes |
yes |
Some PEM probes cannot run, and some return incomplete data - see below for more details. |
Some of the PEM probes don't return information, and some of the functionality might be affected. |
Scheduled Tasks |
yes |
Limited - see below for more details. |
Scheduled tasks work only for the database server. Scripts run on a remote agent. |
System Reports |
yes |
yes |
yes |
Core Usage Reports |
yes |
yes |
The Core usage report doesn't show complete information. For example, the platform, number of cores, and total RAM aren't displayed. |
オペレーティングシステムの権限の制限によって影響を受ける機能#
非rootユーザーとしてPEMエージェントを実行する場合、機能のレベルは、エージェントユーザーが持つ正確な権限によって異なります。以下のセクションでは、OSユーザー権限の影響を受ける操作と、通常の操作に必要な権限について説明します。
プローブ#
Probe |
Operating system |
PEM functionality affected |
|---|---|---|
Session Information |
Linux/Windows |
The probe will be missing the following ‘per-process’ columns if the agent user is not either root or the same user as Postgres: memory_usage_mb, swap_usage_mb, cpu_usage, io_read_bytes, io_write_bytes. |
Patroni Node Status |
Linux/Windows |
Requires permission to execute patronictl. No data will be returned otherwise. |
Patroni Cluster Status |
Linux/Windows |
Requires permission to execute patronictl. No data will be returned otherwise. |
PG HBA Conf |
Linux/Windows |
Requires permission to read pg_hba.conf. No data will be returned otherwise. |
Data and Log File Analysis |
Linux/Windows |
Requires permission to read PGDATA. No data will be returned otherwise. |
WAL Archive Status |
Linux/Windows |
Requires read access to the WAL directory. No data will be returned otherwise. |
Failover Manager Node Status |
Linux/Windows |
Requires permission to execute efm. No data will be returned otherwise. |
Failover Manager Cluster Info |
Linux/Windows |
Requires permission to execute efm. No data will be returned otherwise. |
サービスの再起動#
Audit Log ManagerとServer Log Managerでは、PEMエージェントユーザーがPostgresサービスを再起動して変更を有効にする必要があります。エージェントユーザーがサービスを再起動するための十分な特権がない場合通常、これにはルートアクセスが必要です、これらの機能は機能しません。
バッチ/シェルタスク#
Windowsでは、エージェントユーザーが管理者権限を持っていない限り、PEMエージェントはバッチタスクを実行できません。
Linuxでは、PEMエージェントは、エージェントユーザーがagent.cfg
で指定されたbatch_script_user
になることができる場合にのみシェルタスクを実行できます。これは、
rootユーザーとbatch_script_user に常に当てはまります。
データベース特権の制限によって影響を受ける機能#
PEMエージェントが非スーパーユーザーアカウントを使用して監視対象データベースに接続する場合、使用可能な機能は、そのユーザーに付与された特定の特権に基づいて制限されます。 以下のセクションでは、どのPEM操作がPostgresのユーザー権限の影響を受けるか、および標準の監視機能に必要な特権について説明します。
PEMエージェントは、ほとんどのSQLベースのプローブのpg_catalogスキーマからデータを読み取ります。通常、 pg_monitorロールをエージェントユーザーに割り当てるだけで十分です。ただし、特定のカタログファンクションとプローブは、pg_monitorを超える追加の特権を必要とする場合があります。
さらに、エージェントユーザーは、プローブを実行する必要があるすべてのターゲットデータベースに接続できる必要があります。
エージェントがデータベースに接続できない場合、そのインスタンスではデータベースレベルのプローブは実行されません。このような場合、サーバーレベルのメトリックたとえば、pg_stat_database
から収集されたもののみが使用できます。
次の表は、pg_monitor
に加えて権限を必要とするプローブをリストしています。
Probe |
Operating system |
Additional permissions required |
|---|---|---|
All PGD probes |
Linux/Windows |
Require SELECT permission on tables and views, and EXECUTE permission on functions, in the bdr schema of the replicated database. |
Number of WAL Files |
Linux/Windows |
Requires EXECUTE on pg_ls_dir(). |
Streaming Replication Lag Time |
Linux/Windows |
Requires the ability to execute pg_last_xlog_receive_location(), pg_last_xlog_replay_location(), and pg_last_xact_replay_timestamp(). This can be provided by granting the pg_wal_monitor role. |
Streaming Replication |
Linux/Windows |
Requires the ability to execute pg_xlogfile_name_offset() and pg_xlog_location_diff(). This can be provided by granting the pg_wal_monitor role. |
System Waits & Session Waits |
Linux/Windows |
Require SELECT permission on the system_waits and session_waits views respectively. |
SQL Protect |
Linux/Windows |
Requires SELECT on sqlprotect.edb_sql_protect_stats. |
User Information |
Linux/Windows |
Requires SELECT on pg_user. |
xDB Replication |
Linux/Windows |
Requires SELECT on EDB Replicator views. |
エラー処理#
プローブは、十分な権限なしでオペレーティングシステムを検索している場合、プローブはpermission denied
エラーを結果ことができます。プローブが十分な権限なしでデータベースを照会している場合、プローブはpermission denied
エラーを返すか、返されたデータを空の値としてPEMチャートまたはグラフに表示する場合があります。
プローブが失敗すると、プローブの名前、プローブが失敗した理由、問題の解決に役立つヒントを含むエントリがログファイルに書き込まれます。
サーバーで発生したプローブ関連のエラーをプローブログダッシュボードで表示したり、PEMワーカーログファイルのエラーメッセージを確認したりできます。 Linuxでは、ログファイルのデフォルトの場所は次のとおりです。
/var/log/pem/worker.log
Windowsでは、 Event Viewerでログ情報を利用できます。