pg_hba.conf¶
Postgresのドキュメントでは、 pg_hba.conf で使用可能なさまざまなオプションについて説明しています。
デフォルトでは、TPAはクラスターに適切なpg_hba.conf
を生成し、インスタンス間のレプリケーション、および認証済みクライアントからの接続を許可します。
postgres_hba_settings
のリストを提供することにより、デフォルト構成にエントリーを追加できます。
cluster_vars:
postgres_hba_settings:
- "# let authenticated users connect from anywhere"
- hostssl all all 0.0.0.0/0 scram-sha-256
postgres_hba_local_auth_method: md5
を設定することにより、pg_hba.confのデフォルトのlocal all all peer
行をオーバーライドできます。
デフォルトのエントリが不要な場合は、 postgres_hba_template
を変更できます。
cluster_vars:
postgres_hba_template: pg_hba.lines.j2
postgres_hba_settings:
- "# my lines of text"
- "# and nothing but my lines"
- "# …not even any clients!"
- hostssl all all 0.0.0.0/0 reject
クラスターディレクトリにtemplates/my_hba.j2
を作成して設定することもできます。
cluster_vars:
postgres_hba_template: my_hba.j2
既存のpg_hba.conf をそのままにしたい場合は、それもできます。
cluster_vars:
postgres_hba_template:
pg_hba.conf
をインスタンスごとに異なるように構成することは可能ですが、スイッチオーバーやフェイルオーバーなどのトポロジ変更イベント後のアクセスとレプリケーションの問題を回避するために、一般的に均一な構成をお勧めします。