Configuring the PEM agent#
前提条件#
Install the PEM agent 。
!!!note PgBouncerを介して接続するようにagent.cfg
ファイルでtrue に設定されたenable_smtp 、enable_snmp
、またはenable_webhook
を使用してPEMエージェントを構成しないでください。
SNMP、SMTP、およびWebhookスプーラーは、Postgresが提供するLISTEN/NOTIFYメカニズムを使用して、通知を非同期に送信します。
PgBouncerはトランザクションモードでのLISTEN/NOTIFYメカニズムをサポートしていないため、エージェントをPgBouncerに接続すると、通知が遅延されるか、まったく配信されない場合があります。代わりに、PEMエージェントをPEMバックエンドデータベースに直接接続します。
新しいPEMエージェントの構成#
PEMエージェントをインストールした後、特定のPEMデータベースサーバーと連携するように構成します。
PGSSLMODE=require PEM_SERVER_PASSWORD=pem_admin1_password \
/usr/edb/pem/agent/bin/pemworker \
--register-agent \
--pem-server 172.16.254.22 \
--pem-port 6432 \
--pem-user pem_admin1 \
--pem-agent-user pem_agent_user1 \
--display-name *Agent_Name* \
__OUTPUT__
Postgres Enterprise Manager Agent registered successfully!
このコマンドでは、 --pem-agent-user 引数は、
pem_agent_user1データベースユーザーのSSL証明書とキーペアを/root/.pem
ディレクトリに作成するようにエージェントに指示します。
例
/root/.pem/pem_agent_user1.crt
/root/.pem/pem_agent_user1.key
PEMエージェントは、キーを使用してPEMデータベースサーバーにpem_agent_user1として接続します。また、/usr/edb/pem/agent/etc/agent.cfg
という名前のエージェント構成ファイルも作成します。
使用するagent-userを記載した行がagent.cfg
構成ファイルにあります。例
cat /usr/edb/pem/agent/etc/agent.cfg
[PEM/agent]
pem_host=172.16.254.22
pem_port=6432
agent_id=12
agent_user=pem_agent_user1
agent_ssl_key=/root/.pem/pem_agent_user1.key
agent_ssl_crt=/root/.pem/pem_agent_user1.crt
log_level=warning
log_location=/var/log/pem/worker.log
agent_log_location=/var/log/pem/agent.log
long_wait=30
short_wait=10
alert_threads=0
enable_smtp=false
enable_snmp=false
enable_webhook=false
max_webhook_retries=3
allow_server_restart=true
allow_package_management=false
allow_streaming_replication=false
max_connections=0
connect_timeout=-1
connection_lifetime=0
allow_batch_probes=false
heartbeat_connection=false
既存のPEMエージェントの構成#
既存のPEMエージェントを使用している場合、SSL証明書とキーファイルをターゲットマシンにコピーし、ファイルを再利用できます。ファイルを変更し、新しいパラメーターを追加して、既存のagent.cfg
ファイル内のいくつかのパラメーターを置き換える必要があります。
agent_userをエージェントとして使用する行を追加します。
agent_user=pem_agent_user1
ポートを更新してPgBouncerポートを指定します。
pem_port=6432
証明書とキーパスの場所を更新します。
agent_ssl_key=/root/.pem/pem_agent_user1.key
agent_ssl_crt=/root/.pem/pem_agent_user1.crt
別の方法として、エージェント自己登録スクリプトを実行できます。ただし、そのプロセスは新しいエージェントIDを作成します。エージェント自己登録スクリプトを実行する場合、新しいエージェントIDを既存のIDに置き換え、
pem.agent
テーブルの新しいエージェントIDのエントリを無効にする必要があります。例
pem=# UPDATE pem.agent SET active = false WHERE id = <new_agent_id>;
__OUTPUT__
UPDATE 1
注釈
既存のSSL証明書、キーファイル、およびエージェント構成ファイルのバックアップを保存します。