pg_hba.conf

pg_hba.conf#

Postgresドキュメントでは、 pg_hba.conf で使用可能なさまざまなオプションについて説明しています。

デフォルトでは、TPAはクラスター用に適切なpg_hba.conf を生成し、インスタンス間のレプリケーション、および認証されたクライアントからの接続を許可します。

postgres_hba_settings のリストを提供することにより、デフォルト構成にエントリを追加できます。

cluster_vars:
  postgres_hba_settings:
  - "# let authenticated users connect from anywhere"
  - hostssl all all 0.0.0.0/0 scram-sha-256

postgres_hba_local_auth_method: md5 を設定することにより、pg_hba.confのデフォルトのlocal all all peer 行をオーバーライドできます。

デフォルトのエントリが不要な場合は、postgres_hba_template を変更できます。

cluster_vars:
  postgres_hba_template: pg_hba.lines.j2
  postgres_hba_settings:
  - "# my lines of text"
  - "# and nothing but my lines"
  - "# …not even any clients!"
  - hostssl all all 0.0.0.0/0 reject

クラスターディレクトリにtemplates/my_hba.conf.j2 を作成し、次のように設定することもできます。

cluster_vars:
  postgres_hba_template: my_hba.conf.j2

クラスターディレクトリのtemplates サブディレクトリの外部にテンプレートファイルを配置する場合、ファイルへの絶対パスを指定してください。

#  in the root of the cluster directory

cluster_vars:
  postgres_hba_template: "{{ cluster_dir }}/my_hba.conf.j2"
#  in a subdirectory of the cluster directory that is NOT templates

cluster_vars:
  postgres_hba_template: "{{ cluster_dir }}/subdirectory/my_hba.conf.j2"
#  in a directory outside of the cluster directory

cluster_vars:
  postgres_hba_template: /path/to/file/outside/cluster_dir/my_hba.conf.j2

既存のpg_hba.conf だけを残したい場合は、それもできます。

cluster_vars:
  postgres_hba_template:

さまざまなインスタンスで異なるようにpg_hba.conf を構成することは可能ですが、スイッチオーバーやフェイルオーバーなどのトポロジを変更するイベント後のアクセスとレプリケーションの問題を回避するために、一般的に均一な構成を推奨します。