Configuring PgBouncer
=====================

PEMデータベースサーバーと連携するようにPgBouncerを構成する必要があります。

前提条件
--------

- EDB Postgres Advanced Serverを実行している場合、
  `EDB PgBouncer <https://www.enterprisedb.com/docs/pgbouncer/latest/installing>`_ をインストールします。

- EDB Postgres Extended
  ServerまたはPostgreSQLを実行している場合、コミュニティ `PgBouncer <https://www.pgbouncer.org/install.html>`_ 
  をインストールします。

EDB PgBouncerおよびPgBouncerインストールの考慮事項
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

構成手順でのディレクトリとファイルの名前と場所、およびユーザーは、PgBouncerのコミュニティバージョンとEDB
PgBouncerのどちらをインストールしたかによって異なります。コミュニティPgBouncerをインストールした場合コミュニティリポジトリとEDBリポジトリからインストールするかにかかわらず、作業例のファイルとディレクトリの名前をPgBouncerの値に置き換えます。

.. csv-table::
  :header: Name,PgBouncer,EDB PgBouncer
  :widths: 12,25,15
  :align: left
  :class: longtable

  PgBouncer directory,`/etc/pgbouncer`,`/etc/edb/pgbouncer<1.x>`
  ini file,`pgbouncer.ini`,`edb-pgbouncer.ini`
  HBA file,`/etc/pgbouncer/hba_file`,`/etc/edb/pgbouncer<1.x>/hba_file`
  Service file,`pgbouncer`,`edb-pgbouncer-<1.x>`
  User,`postgres`,`enterprisedb`

PgBouncerの構成
---------------

この例では、enterprisedbシステムユーザーを使用してEDB
PgBouncerを構成します。

コミュニティPgBouncerを実行している場合は、
:ref:`EDB PgBouncerおよびPgBouncerインストールの考慮事項 <EDB PgBouncerおよびPgBouncerインストールの考慮事項>` の説明に従って、ディレクトリ、ファイル、およびユーザーの名前を置き換えます。

1. ターミナルウィンドウを開き、PgBouncerディレクトリに移動します。

2. PgBouncerの\ ``etc`` ディレクトリ\ ``edb-pgbouncer.ini``
   が存在する場所の所有者を\ ``enterprisedb``
   に変更し、ディレクトリのアクセス許可を\ ``0700`` に変更します。

.. code:: shell

       chown -R enterprisedb:enterprisedb /etc/edb/pgbouncer<1.x>
       chmod 0700 /etc/edb/pgbouncer<1.x>

1. ``edb-pgbouncer.ini`` ファイルの内容を変更します。

.. code:: ini

       [databases]
       ;; Change the pool_size according to maximum connections allowed
       ;; to the PEM database server as required.
       ;; auth_user will be used for authenticate the db user (proxy
       ;; agent user in our case)
       pem = port=5444 host=127.0.0.1 dbname=pem auth_user=pgbouncer pool_size=80 pool_mode=transaction
     - = port=5444 host=127.0.0.1 dbname=pem auth_user=pgbouncer pool_size=10

       [pgbouncer]
       logfile = /var/log/edb/pgbouncer<1.x>/edb-pgbouncer-<1.x>.log
       pidfile = /var/run/edb/pgbouncer<1.x>/edb-pgbouncer-<1.x>.pid
       listen_addr = *
       ;; Agent needs to use this port to connect the pem database now
       listen_port = 6432
       ;; Set to require to ensure SSL certificates are used for connections
       ;; for PEM Agents
       client_tls_sslmode = require
       ;; These are the root.crt, server.key, server.crt files present
       ;; in the present under the data directory of the PEM database
       ;; server, used by the PEM Agents for connections.
       client_tls_ca_file = /var/lib/edb/as16/data/root.crt
       client_tls_key_file = /var/lib/edb/as16/data/server.key
       client_tls_cert_file = /var/lib/edb/as16/data/server.crt
       ;; Allow pgBouncer to use pem_agent_pool certificate
       ;; and key for connections to the server.
       server_tls_key_file = /var/lib/edb/.postgresql/pem_agent_pool.key
       server_tls_cert_file = /var/lib/edb/.postgresql/pem_agent_pool.crt
       ;; Use hba file for client connections
       auth_type = hba
       ;; HBA file
       auth_hba_file = /etc/edb/pgbouncer<1.x>/hba_file
       ;; Use pem.get_agent_pool_auth(TEXT) function to authenticate
       ;; the db user (used as a proxy agent user).
       auth_query = SELECT * FROM pem.get_agent_pool_auth($1)
       ;; DB User for administration of the pgbouncer
       admin_users = pem_admin1
       ;; auth_dbname and auth_user allow
       ;; admin console login by admin_users and stats_users
       auth_dbname = pem
       auth_user = pgbouncer
       ;; DB User for collecting the statistics of pgbouncer
       stats_users = pem_admin1
       server_reset_query = DISCARD ALL
       ;; Change based on the number of agents installed/required
       max_client_conn = 500
       ;; Close server connection if its not been used in this time.
       ;; Allows to clean unnecessary connections from pool after peak.
       server_idle_timeout = 60

!!!note `auth_user` の詳細については、 `Authentication settings <https://www.pgbouncer.org/config.html#authentication-settings>`_ を参照してください。 .. ::
   1.次のコンテンツを含むPgBouncerのHBAファイル `/etc/edb/pgbouncer<1.x>/hba_file`  を作成します。

.. code:: ini

       # Use the authentication method scram-sha-256 for local connections
       # between the pem database & the pgbouncer (virtual) database.
       local pgbouncer all scram-sha-256
       # Use the authentication method scram-sha-256 for remote connections
       # to pgbouncer (virtual database) using the enterprisedb user.
       host pgbouncer,pem pem_admin1 0.0.0.0/0 scram-sha-256
       # Use the authentication method cert for TCP/IP connections
       # to the pem database using pem_agent_user1
       hostssl pem pem_agent_user1 0.0.0.0/0 cert

1. HBAファイル\ ``(/etc/edb/pgbouncer<1.x>/hba_file)``
   の所有者を\ ``enterprisedb`` に変更し、ディレクトリ権限を\ ``0600``
   に変更します。

.. code:: shell

       chown enterprisedb:enterprisedb /etc/edb/pgbouncer<1.x>/hba_file
       chmod 0600 /etc/edb/pgbouncer<1.x>/hba_file

1. PgBouncerサービスを有効にし、サービスを開始します。

.. code:: shell

       systemctl enable edb-pgbouncer-<1.x>
       __OUTPUT__
       Created symlink from
       /etc/systemd/system/multi-user.target.wants/edb-pgbouncer-<1.x>.service
       to /usr/lib/systemd/system/edb-pgbouncer-<1.x>.service.

.. code:: shell

       systemctl start edb-pgbouncer-<1.x>
