Configuring Postgres Enterprise Manager (PEM)#
TPA will install and configure PEM when tpaexec configure command is
run with --enable-pem command line option.
The default behavior with --enable-pem is to enable pem-agent
role for all postgres instances in the cluster. pem-agent role
will also be added to barman nodes when --enable-pg-backup-api
command line option is used alongside --enable-pem .
A dedicated instance named pemserver will also be added to the
cluster.
Since PEM server uses postgres backend; pemserver instance implicitly
uses postgres role as well which ensures that pemserver gets a valid
postgres cluster configured for use as PEM backend. All configuration
options available for a normal postgres instance are valid for PEM’s
backend postgres instance as well. See following for details:
Note that PEM is only available via EDB’s package repositories and therefore requires a valid subscription.
Supported architectures#
PEM is supported with all architectures via the --enable-pem
configuration command line option, with the exception of the
BDR-Always-ON architecture when used with EDB Postgres Extended. You can
optionally edit the generated cluster config (config.yml) and assign or
remove pem-agent role from any postgres instance in the cluster in
order to enable or disable PEM there.
PEM component package versions#
By default, TPA installs the latest available version of PEM agent and PEM server.
The version of the PEM agent and PEM server packages that are installed
can be specified by including pem_agent_package_version: xxx and
pem_server_package_version: xxx under the cluster_vars section
of the config.yml file.
cluster_vars:
…
pem_agent_package_version: 9.7.0-1.el9
pem_server_package_version: 9.7.0-1.el9
…
You may use any version specifier that apt or yum would accept.
If your version does not match, try appending a * wildcard. This is
often necessary when the package version has an epoch qualifier like
2:... .
PEM configuration#
TPA will configure pem agents and pem server with the appropriate instance-specific settings, with remaining settings set to the respective default values. Some of the configuration options may be exposed for user configuration at some point in future.
PEM server’s web interface is configured to run on https and uses 443 port for the same. PEM’s webserver configuration uses self-signed certificates.
The default login credentials for the PEM server web interface use the
postgres backend database user, which is set to postgres for
postgresql and enterprisedb for EPAS clusters by default. You can
get the login password for the web interface by running
tpaexec show-password $clusterdir $user .
Passing additional options when registering PEM agents#
TPA registers each PEM agent in the cluster using the pemworker
utility’s --register agent command.
A list of additional registration options can be passed by including
pemagent_registration_opts in the cluster config.
For example:
pemagent_registration_opts:
- --enable-smtp true
- --enable-heartbeat-connection
- --allow-batch-probes true
- -l DEBUG1
lists more information about registration options.
Useful extensions for the nodes with pem agent#
By default, TPA will add sql_profiler , edb_wait_states and
query_advisor extensions to any instances that have pem-agent
role.
This list of default extensions for pem-agent nodes can be overriden by
setting pemagent_extensions in config.yml.
If this list is empty, no extensions will be automatically included.
Providing an external certificate for PEM server SSL authentication#
By default, the PEM server creates a self-signed certificate pair,
server-pem.crt and server-pem.key and configures the webserver
to use them for HTTPS access.
The size of server-pem.key can be modified adding the variable
pem_rsa_key_size to the cluster_vars section:
(...)
cluster_vars:
pem_rsa_key_size: 4096
The size of the CA certificate expedited by the PEM database can also be
modified adding the variable pem_db_ca_certificate_key_size to the
cluster_vars section:
(...)
cluster_vars:
pem_db_ca_certificate_key_size: 4096
To provide your own certificate pair, create a directory under the root
of the cluster directory named ssl/pemserver and place the
certificate pair inside.
cluster directory
├── ssl
│ └── pemserver
│ ├── externally-provided.crt
│ └── externally-provided.key
Next, set the variables pem_server_ssl_certificate and
pem_server_ssl_key with the respective file names as values for the
vars: under the pem server instance or cluster_vars in the
cluster config file.
TPA will handle copying these files over to the pem server instance and configure the webserver accordingly.
- Name: pemserver
location: main
node: 4
role:
- pem-server
vars:
pem_server_ssl_certificate: externally-provided.crt
pem_server_ssl_key: externally-provided.key