Перейти к основному содержимому

Задание 4: Кастомизированная установка

В этом разделе мы изучим различные конфигурации для установки: с использованием сертификатов SSL, а также с аутентификацией по паролю. Кроме того, мы настроим сохранение истории команд psql, выполним запуск установки с кастомизированными настройками и проведем последующую проверку их применения.

Конфигурация для установки с сертификатами SSL​

Для этой лабораторной работы исходным является использование файла конфигурации config.yml, настроенный по умолчанию в задании второго уровня «Кастомизированная установка».

Проверим его содержимое:

[student@srv1 ~]$ less ~/config.yml
Вывод команды:

hosts:
master:
hostname: srv1
username: student
password: student
replica:
hostname: srv2
username: student
password: student
arbiter:
hostname: srv3
username: student
password: student
local_distr_path: /home/student/Distr/distributive
pangolin_license_path: /home/student/license.json
tune_pangolin_local_repo: true
####################################################### 3.2. SECURITY SETTINGS (SSL) ##################################################
mtls_support: true # Turn on SSL mode between cluster components
pkcs12_plugin_enable: false # Enable pkcs#12 support
pkcs12_use_ca_chain_from_container: false # If false, then need fill up 'root_ca_file' or 'root_ca_path' parameter
pkcs12_encrypt_passphrase: true # If true, passphrase in config file will encrypt
pkcs12_update_local_cert_files: false # Update local certs from remote server, if true then update

pg_certs_pwd:
root_ca_path: "{{ '' | default('/pg_ssl/root_dir', true) }}" # Root CA certificate dir for all components\nodes
crl_path: "" # Path to dir with CRL files
pg:
crl_file: "" # Path to CRL file
root_ca_file: "{{ '' | default('/pg_ssl/root.crt', true) }}" # Root CA certificate for all components\nodes
server_cert: "{{ '' | default('/pg_ssl/server.crt', true) }}" # Main server certificate for each node
server_key: "{{ '' | default('/pg_ssl/server.key', true) }}" # Main server private key for each node
server_p12:
use_remote_pki: false # If true, certificate will fetch/generate from SecMan
p12_secman: # Certificate attributes for its generation/search in SecMan
name: "{{ '' | default(ansible_fqdn, true) }}"
common_name: "{{ '' | default(ansible_fqdn, true) }}"
email: "{{ '' | default('test@test.ru', true) }}"
alt_names: "{{ '' | default(ansible_fqdn, true) }}"
ip_sans: "{{ '' | default(ansible_default_ipv4.address, true) }}"
other_sans: "{{ '' | default('', true) }}"
exclude_cn_from_sans: "{{ '' | default(false, true) }}"
p12_path: "{{ '' | default('/pg_ssl/intermediate/server.p12', true) }}" # Path to p12 container for server certificate
p12_pass: "{{ '' | default('test123', true) }}" # Passphrase to p12 container for server certificate
p12_config_path: "{{ '' | default('/pg_ssl/intermediate/server.p12.cfg', true) }}" # Path to config file with p12 container and encrypted passphrase for server certificate
pgbouncer:
crl_file: "" # Path to CRL file
root_ca_file: "{{ '' | default('/pg_ssl/root.crt', true) }}" # Root CA certificate for all components\nodes
server_cert: "{{ '' | default('/pg_ssl/server.crt', true) }}" # Main server certificate for each node
server_key: "{{ '' | default('/pg_ssl/server.key', true) }}" # Main server private key for each node
server_p12:
use_remote_pki: false # If true, certificate will fetch/generate from SecMan
p12_secman: # Certificate attributes for its generation/search in SecMan
name: "{{ '' | default(ansible_fqdn, true) }}"
common_name: "{{ '' | default(ansible_fqdn, true) }}"
email: "{{ '' | default('test@test.ru', true) }}"
alt_names: "{{ '' | default(ansible_fqdn, true) }}"
ip_sans: "{{ '' | default(ansible_default_ipv4.address, true) }}"
other_sans: "{{ '' | default('', true) }}"
exclude_cn_from_sans: "{{ '' | default(false, true) }}"
p12_path: "{{ '' | default('/pg_ssl/intermediate/pgbouncer_server.p12', true) }}" # Path to p12 container for server certificate
p12_pass: "{{ '' | default('test123', true) }}" # Passphrase to p12 container for server certificate
p12_config_path: "{{ '' | default('/pg_ssl/intermediate/pgbouncer_server.p12.cfg', true) }}" # Path to config file with p12 container and encrypted passphrase for server certificate
client_cert: "{{ '' | default('/pg_ssl/pgbouncer.crt', true) }}" # Certificate for connect pgbouncer to PGSE
client_key: "{{ '' | default('/pg_ssl/pgbouncer.key', true) }}" # Private key for connect pgbouncert to PGSE
client_p12:
use_remote_pki: false # If true, certificate will fetch/generate from SecMan
p12_secman: # Certificate attributes for its generation/search in SecMan
name: "{{ '' | default('pgbouncer', true) }}"
common_name: pgbouncer
email: "{{ '' | default('test@test.ru', true) }}"
alt_names: "{{ '' | default(ansible_fqdn, true) }}"
ip_sans: "{{ '' | default(ansible_default_ipv4.address, true) }}"
other_sans: "{{ '' | default('', true) }}"
exclude_cn_from_sans: "{{ '' | default(false, true) }}"
p12_path: "{{ '' | default('/pg_ssl/intermediate/pgbouncer.p12', true) }}" # Path to p12 container for pgbouncer certificate
p12_pass: "{{ '' | default('test123', true) }}" # Passphrase to p12 container for pgbouncer certificate
p12_config_path: "{{ '' | default('/pg_ssl/intermediate/pgbouncer.p12.cfg', true) }}" # Path to config file with p12 container and encrypted passphrase for pgbouncer certificate
patroni:
crl_file: "" # Path to CRL file
root_ca_file: "{{ '' | default('/pg_ssl/root.crt', true) }}" # Root CA certificate for all components\nodes
server_cert: "{{ '' | default('/pg_ssl/server.crt', true) }}" # Main server certificate for each node
server_key: "{{ '' | default('/pg_ssl/server.key', true) }}" # Main server private key for each node
server_p12:
use_remote_pki: false # If true, certificate will fetch/generate from SecMan
p12_secman: # Certificate attributes for its generation/search in SecMan
name: "{{ '' | default(ansible_fqdn, true) }}"
common_name: "{{ '' | default(ansible_fqdn, true) }}"
email: "{{ '' | default('test@test.ru', true) }}"
alt_names: "{{ '' | default(ansible_fqdn, true) }}"
ip_sans: "{{ '' | default(ansible_default_ipv4.address, true) }}"
other_sans: "{{ '' | default('', true) }}"
exclude_cn_from_sans: "{{ '' | default(false, true) }}"
p12_path: "{{ '' | default('/pg_ssl/intermediate/patroni_server.p12', true) }}" # Path to p12 container for server certificate
p12_pass: "{{ '' | default('test123', true) }}" # Passphrase to p12 container for server certificate
p12_config_path: "{{ '' | default('/pg_ssl/intermediate/patroni_server.p12.cfg', true) }}" # Path to config file with p12 container and encrypted passphrase for server certificate
client_cert: "{{ '' | default('/pg_ssl/patroni.crt', true) }}" # User patroni certificate
client_key: "{{ '' | default('/pg_ssl/patroni.key', true) }}" # User patroni private key
client_p12:
use_remote_pki: false # If true, certificate will generation/search from SecMan
p12_secman: # Certificate attributes for its generation/search in SecMan
name: "{{ '' | default('patroni', true) }}"
common_name: patroni
email: "{{ '' | default('test@test.ru', true) }}"
alt_names: "{{ '' | default(ansible_fqdn, true) }}"
ip_sans: "{{ '' | default(ansible_default_ipv4.address, true) }}"
other_sans: "{{ '' | default('', true) }}"
exclude_cn_from_sans: "{{ '' | default(false, true) }}"
p12_path: "{{ '' | default('/pg_ssl/intermediate/patroni.p12', true) }}" # Path to p12 container for patroni certificate
p12_pass: "{{ '' | default('test123', true) }}" # Passphrase to p12 container for patroni certificate
p12_config_path: "{{ '' | default('/pg_ssl/intermediate/patroni.p12.cfg', true) }}" # Path to config file with p12 container and encrypted passphrase for patroni certificate
pangolin_dcs:
crl_file: "{{ '' | default('/pg_ssl/crl/intermediate.crl', true) }}" # Path to CRL file
root_ca_file: "{{ '' | default('/pg_ssl/root.crt', true) }}" # Root CA certificate for all components\nodes
cert: "{{ '' | default('/pg_ssl/server.crt', true) }}" # Certificate for Pangolin dcs
key: "{{ '' | default('/pg_ssl/server.key', true) }}" # Private key for Pangolin dcs
p12:
use_remote_pki: false # If true, certificate will fetch/generate from SecMan
p12_secman: # Certificate attributes for its generation/search in SecMan
name: "{{ '' | default(ansible_fqdn, true) }}"
common_name: "{{ '' | default(ansible_fqdn, true) }}"
email: "{{ '' | default('test@test.ru', true) }}"
alt_names: "{{ '' | default(ansible_fqdn, true) }}"
ip_sans: "{{ '' | default(ansible_default_ipv4.address, true) }}"
other_sans: "{{ '' | default('', true) }}"
exclude_cn_from_sans: "{{ '' | default(false, true) }}"
p12_path: "{{ '' | default('/pg_ssl/intermediate/patroni_server.p12', true) }}" # Path to p12 container for server certificate
p12_pass: "{{ '' | default('test123', true) }}" # Passphrase to p12 container for server certificate
p12_config_path: "{{ '' | default('/pg_ssl/intermediate/patroni_server.p12.cfg', true) }}" # Path to config file with p12 container and encrypted passphrase for server certificate
pangolin_dcs_rest_api:
crl_file: "{{ '' | default('/pg_ssl/crl/intermediate.crl', true) }}" # Path to CRL file
root_ca_file: "{{ '' | default('/pg_ssl/root.crt', true) }}" # Root CA certificate for all components\nodes
cert: "{{ '' | default('/pg_ssl/server.crt', true) }}" # Certificate for Pangolin Rest api
key: "{{ '' | default('/pg_ssl/server.key', true) }}" # Private key for Pangolin Rest api
p12:
use_remote_pki: false # If true, certificate will fetch/generate from SecMan
p12_secman: # Certificate attributes for its generation/search in SecMan
name: "{{ '' | default(ansible_fqdn, true) }}"
common_name: "{{ '' | default(ansible_fqdn, true) }}"
email: "{{ '' | default('test@test.ru', true) }}"
alt_names: "{{ '' | default(ansible_fqdn, true) }}"
ip_sans: "{{ '' | default(ansible_default_ipv4.address, true) }}"
other_sans: "{{ '' | default('', true) }}"
exclude_cn_from_sans: "{{ '' | default(false, true) }}"
p12_path: "{{ '' | default('/pg_ssl/intermediate/patroni_server.p12', true) }}" # Path to p12 container for server certificate
p12_pass: "{{ '' | default('test123', true) }}" # Passphrase to p12 container for server certificate
p12_config_path: "{{ '' | default('/pg_ssl/intermediate/patroni_server.p12.cfg', true) }}" # Path to config file with p12 container and encrypted passphrase for server certificate
etcd:
server_cert: "{{ '' | default('/pg_ssl/server.crt', true) }}" # Certificate for etcd cluster
server_key: "{{ '' | default('/pg_ssl/server.key', true) }}" # Private key for etcd cluster
root_ca: "{{ '' | default('/pg_ssl/root.crt', true) }}" # Root CA certificate for etcd cluster
crl_file: "" # Path to CRL file for etcd

pangolin_certs_rotate:
enable: true # Set up service (actual for only install)
log:
directory: "{{ PGLOGS }}/pangolin-certs-rotate" # Path to log dir
filename: pangolin-certs-rotate-%Y-%m-%d_%H%M%S.log # Log name
level: info # Log level
destination: console,file # Log methods
certs:
enable_update: false # Enable/disable automatic renewal of certificates
poll_period_in_min: 60 # Certificate validity period [min]
retry_interval_in_sec: 30 # Timeout to restart in case of error [sec]
retry_attempts_num: 1 # Number of attempts after a failed launch
watch: # Lots of upgradable certificates
- locations: # Certificate configuration files
paths:
- "{%- if (pg_certs_pwd.pg.server_p12.use_remote_pki or pkcs12_update_local_cert_files) and inventory_hostname in groups['postgres_nodes'] -%}\
{{ pg_certs_pwd.pg.server_p12.p12_config_path }}\
{% endif %}"
on_update: # Commands to run after updating at least one of the certificates
- "{%- if 'patroni' in configuration_type | d('') -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-manager\
{% else %}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload postgresql\
{% endif %}"
- "{%- if 'pgbouncer' in configuration_type | d('') and inventory_hostname in groups['postgres_nodes'] -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-pooler\
{% elif 'poolermt' in configuration_type | d('') and inventory_hostname in groups['postgres_nodes'] %}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-pooler-mt\
{% endif %}"
- locations: # Certificate configuration files
paths:
- "{%- if ('pgbouncer' in configuration_type | d('') or 'poolermt' in configuration_type | d('')) and (pg_certs_pwd.pgbouncer.server_p12.use_remote_pki or pkcs12_update_local_cert_files) and inventory_hostname in groups['postgres_nodes'] -%}\
{{ pg_certs_pwd.pgbouncer.server_p12.p12_config_path }}\
{% endif %}"
on_update: # Commands to run after updating at least one of the certificates
- "{%- if 'patroni' in configuration_type | d('') -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-manager\
{% else %}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload postgresql\
{% endif %}"
- "{%- if 'pgbouncer' in configuration_type | d('') and inventory_hostname in groups['postgres_nodes'] -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-pooler\
{% elif 'poolermt' in configuration_type | d('') and inventory_hostname in groups['postgres_nodes'] %}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-pooler-mt\
{% endif %}"
- locations: # Certificate configuration files
paths:
- "{%- if 'patroni' in configuration_type | d('') and (pg_certs_pwd.patroni.server_p12.use_remote_pki or pkcs12_update_local_cert_files) -%}\
{{ pg_certs_pwd.patroni.server_p12.p12_config_path }}\
{% endif %}"
on_update: # Commands to run after updating at least one of the certificates
- "{%- if 'patroni' in configuration_type | d('') -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-manager\
{% endif %}"
- locations: # Certificate configuration files
paths:
- "{%- if 'patroni' in configuration_type | d('') and (pg_certs_pwd.patroni.client_p12.use_remote_pki or pkcs12_update_local_cert_files) and inventory_hostname in groups['postgres_nodes'] -%}\
{{ pg_certs_pwd.patroni.client_p12.p12_config_path }}\
{% endif %}"
on_update: # Commands to run after updating at least one of the certificates
- "{%- if 'patroni' in configuration_type | d('') and inventory_hostname in groups['postgres_nodes'] -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-manager\
{% endif %}"
- locations: # Certificate configuration files
paths:
- "{%- if ('pgbouncer' in configuration_type | d('') or 'poolermt' in configuration_type | d('')) and (pg_certs_pwd.pgbouncer.client_p12.use_remote_pki or pkcs12_update_local_cert_files) and inventory_hostname in groups['postgres_nodes'] -%}\
{{ pg_certs_pwd.pgbouncer.client_p12.p12_config_path }}\
{% endif %}"
on_update:
- "{%- if 'pgbouncer' in configuration_type | d('') and inventory_hostname in groups['postgres_nodes'] -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-pooler\
{% elif 'poolermt' in configuration_type | d('') and inventory_hostname in groups['postgres_nodes'] %}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-pooler-mt\
{% endif %}"
- locations: # Certificate configuration files
paths:
- "{%- if pangolin_dcs_enable -%}\
{{ pg_certs_pwd.pangolin_dcs.p12.p12_path }}\
{% endif %}"
on_update:
- "{%- if pangolin_dcs_enable -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-manager\
{% endif %}"
- locations: # Certificate configuration files
paths:
- "{%- if pangolin_dcs_enable -%}\
{{ pg_certs_pwd.pangolin_dcs_rest_api.p12.p12_path }}\
{% endif %}"
on_update:
- "{%- if pangolin_dcs_enable -%}\
{% if not systemctl_unit_on_user | d(false) %}sudo systemctl{% else %}systemctl --user{% endif %} reload pangolin-manager\
{% endif %}"
crl:
enable_update: false # Enable/disable automatic renewal of CRL files
poll_period_in_min: 60 # Period for checking for updated CRL files
retry_interval_on_expire_in_sec: 30 # Timeout to retry CRL upload after CRL publish date or expiration date
retry_interval_on_failure_in_sec: 30 # Timeout for retrying CRL upload after failure
retry_attempts_num_on_failure: 1 # Number of attempts to download the CRL by URI list for the given CRL file location path after failure
crl_file_perm: 0644 # Permissions set on uploaded CRL files

pgbouncer_client_tls_sslmode: "{{ '' | default('prefer', true) }}" # Ssl mode for conennections from users side (values: prefer,require,verify-ca,verify-full)
etcd_ciphers_suits: "{{ '' | default('TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384', true) }}" # List of supported TLS cipher suites between server/client and peers in etcd
allowlist_rest_api: "" # list hosts with access unsafe request to rest api patroni

ssl_min_protocol_version: 'TLSv1.2'

Сертификаты должны быть размещены в каталоге /pg_ssl, как это было сделано в задании темы «Сертификаты TLS»:

[student@srv1 ~]$ for comp in srv{1..3}; do echo -e "\n$comp"; ssh $comp sudo ls -lR /pg_ssl; done
Вывод команды:

srv1
/pg_ssl:
итого 72
-rw------- 1 postgres postgres 4338 апр 17 20:34 patroni.crt
-rw------- 1 postgres postgres 4346 апр 17 20:34 patronietcd.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 patronietcd.key
-rw------- 1 postgres postgres 1704 апр 17 20:34 patroni.key
-rw------- 1 postgres postgres 4340 апр 17 20:34 pgbouncer.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 pgbouncer.key
-rw-r--r-- 1 postgres postgres 4145 апр 17 20:34 postgres.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 postgres.key
-rw-r----- 1 postgres pangolin_users 1273 апр 17 20:34 root.crt
drwx---r-x 2 postgres postgres 4096 апр 17 22:20 root_dir
-rw------- 1 postgres postgres 1708 апр 17 20:34 root.key
-rw------- 1 postgres postgres 4504 апр 17 20:34 server.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 server.key

/pg_ssl/root_dir:
итого 8
lrwxrwxrwx 1 postgres postgres 8 апр 17 22:20 d7449d7c.0 -> root.crt
-rw----r-x 1 postgres postgres 1273 апр 17 20:39 root.crt
-rw----r-x 1 postgres postgres 1708 апр 17 20:39 root.key

srv2
/pg_ssl:
итого 72
-rw------- 1 postgres postgres 4338 апр 17 20:34 patroni.crt
-rw------- 1 postgres postgres 4346 апр 17 20:34 patronietcd.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 patronietcd.key
-rw------- 1 postgres postgres 1708 апр 17 20:34 patroni.key
-rw------- 1 postgres postgres 4340 апр 17 20:34 pgbouncer.crt
-rw------- 1 postgres postgres 1708 апр 17 20:34 pgbouncer.key
-rw-r--r-- 1 postgres postgres 4145 апр 17 20:34 postgres.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 postgres.key
-rw-r----- 1 postgres pangolin_users 1273 апр 17 20:34 root.crt
drwx---r-x 2 postgres postgres 4096 апр 17 22:20 root_dir
-rw------- 1 postgres postgres 1708 апр 17 20:34 root.key
-rw------- 1 postgres postgres 4504 апр 17 20:34 server.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 server.key

/pg_ssl/root_dir:
итого 8
lrwxrwxrwx 1 postgres postgres 8 апр 17 22:20 d7449d7c.0 -> root.crt
-rw----r-x 1 postgres postgres 1273 апр 17 20:39 root.crt
-rw----r-x 1 postgres postgres 1708 апр 17 20:39 root.key

srv3
/pg_ssl:
итого 72
-rw-r--r-- 1 postgres postgres 4338 апр 17 20:34 patroni.crt
-rw-r--r-- 1 postgres postgres 4346 апр 17 20:34 patronietcd.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 patronietcd.key
-rw------- 1 postgres postgres 1704 апр 17 20:34 patroni.key
-rw-r--r-- 1 postgres postgres 4340 апр 17 20:34 pgbouncer.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 pgbouncer.key
-rw-r--r-- 1 postgres postgres 4145 апр 17 20:34 postgres.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 postgres.key
-rw-r----- 1 postgres pangolin_users 1273 апр 17 20:34 root.crt
drwxr-xr-x 2 postgres postgres 4096 апр 17 20:39 root_dir
-rw------- 1 postgres postgres 1708 апр 17 20:34 root.key
-rw------- 1 postgres postgres 4504 апр 17 20:34 server.crt
-rw------- 1 postgres postgres 1704 апр 17 20:34 server.key

/pg_ssl/root_dir:
итого 8
-rw-r--r-- 1 root root 1273 апр 17 20:39 root.crt
-rw------- 1 root root 1708 апр 17 20:39 root.key

Конфигурация для установки с паролями​

Пароли по умолчанию заданы в секции 3.6. PASSWORDS файла custom_config_initial.yml.

В этой лабораторной работе требуется установить пароль для суперпользователя.

Добавим в файл конфигурации требуемый пароль, удовлетворяющий ограничениям по сложности:

[student@srv1 ~]$ echo "postgres_db_pass: '<password>'" >> ~/config.yml

Проверим:

[student@srv1 ~]$ tail -1 ~/config.yml
postgres_db_pass: '<password>'

Конфигурация для сохранения истории команд psql​

По умолчанию в СУБД Pangolin не сохраняется история команд psql.

В этой лабораторной работе необходимо настроить файл конфигурации программы установки Pangolin Installer так, чтобы история команд psql сохранялась. Для этого добавьте в файл конфигурации следующую настройку:

[student@srv1 ~]$ echo "psql_save_history: 'on'" >> ~/config.yml

Проверим:

[student@srv1 ~]$ tail -1 ~/config.yml
psql_save_history: 'on'

Запуск установки с кастомизированными настройками​

Активируйте виртуальное окружение:

[student@srv1 ~]$ . /opt/pangolin-ansible-venv-controller/bin/activate
(pangolin-ansible-venv-controller) [student@srv1 ~]$

Запустите кастомизированную установку:

(pangolin-ansible-venv-controller) [student@srv1 ~]$ !954
/opt/pangolin-ansible-venv-controller/bin/pangolin-installer terminal -c config.yml -a install
Вывод команды:

Запуск предварительных проверок.
Предварительные проверки пройдены.
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| clean |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Node | Action | CPU | MEM | Disk available | OS | Version OS | Packages Removed | Packages Installed | Configuration |
|----------------|---------|-----|------|--------------------------|--------|------------|------------------------------------------|--------------------|---------------|
| node: master | install | 1 | 4 GB | / 14G | RED OS | 8.0 | pangolin-ansible-venv-controller (6.7.0) | | cluster |
| ip/dns: (srv1) | | | | | | | pangolin-installer (1.0.3) | | |
| | | | | | | | pangolin-timescaledb-6.7-apache (2.25.0) | | |
| | | | | | | | pangolin-ansible-venv-controlled (6.7.0) | | |
| | | | | | | | pangolin-auth-password (6.7.0) | | |
| | | | | | | | pangolin-certs-rotate (6.7.0) | | |
| | | | | | | | pangolin-security-utilities (6.7.0) | | |
| | | | | | | | pangolin-dbms-6.7 (6.7.0) | | |
| | | | | | | | pangolin-dbms-6.7-client (6.7.0) | | |
| | | | | | | | pangolin-manager-venv (2.1.13) | | |
| | | | | | | | pangolin-manager (2.1.13) | | |
| | | | | | | | pangolin-backup-tools-venv (6.7.0) | | |
| | | | | | | | pangolin-backup-tools (6.7.0) | | |
| | | | | | | | pangolin-pooler (1.5.6) | | |
| | | | | | | | pangolin-diagnostic-tool (6.7.0) | | |
| | | | | | | | pangolin-auth-reencrypt (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-pltcl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-plperl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-jsonb-plperl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-hstore-plperl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-bool-plperl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-plpython3 (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-ltree-plpython3 (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-jsonb-plpython3 (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-hstore-plpython3 (6.7.0) | | |
| | | | | | | | pangolin-tuner (1.1.1) | | |
| | | | | | | | | | |
| node: replica | install | 1 | 4 GB | / 18G | RED OS | 8.0 | pangolin-timescaledb-6.7-apache (2.25.0) | | cluster |
| ip/dns: (srv2) | | | | | | | pangolin-ansible-venv-controlled (6.7.0) | | |
| | | | | | | | pangolin-auth-password (6.7.0) | | |
| | | | | | | | pangolin-certs-rotate (6.7.0) | | |
| | | | | | | | pangolin-security-utilities (6.7.0) | | |
| | | | | | | | pangolin-dbms-6.7 (6.7.0) | | |
| | | | | | | | pangolin-dbms-6.7-client (6.7.0) | | |
| | | | | | | | pangolin-manager-venv (2.1.13) | | |
| | | | | | | | pangolin-manager (2.1.13) | | |
| | | | | | | | pangolin-backup-tools-venv (6.7.0) | | |
| | | | | | | | pangolin-backup-tools (6.7.0) | | |
| | | | | | | | pangolin-pooler (1.5.6) | | |
| | | | | | | | pangolin-diagnostic-tool (6.7.0) | | |
| | | | | | | | pangolin-auth-reencrypt (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-pltcl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-plperl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-jsonb-plperl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-hstore-plperl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-bool-plperl (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-plpython3 (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-ltree-plpython3 (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-jsonb-plpython3 (6.7.0) | | |
| | | | | | | | pangolin-dbms-6-hstore-plpython3 (6.7.0) | | |
| | | | | | | | pangolin-tuner (1.1.1) | | |
| | | | | | | | | | |
| node: arbiter | install | 1 | 4 GB | / 19G | RED OS | 8.0 | | | cluster |
| ip/dns: (srv3) | | | | | | | | | |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

Процедура очистит стенд от компонентов Pangolin. Продолжить? (Y/N): Y
Выполняемая задача: clean
🟢 Роль MAIN PLAY - Завершена! [Время выполнения: 0:02:48] Задач выполнено: 43 | | |#####################################|
Очистка стенда(ов) прошла успешно!
Запуск предварительных проверок.
Предварительные проверки пройдены.
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| install |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Node | Action | CPU | MEM | Disk available | OS | Version OS | Packages Removed | Packages Installed | Configuration |
|----------------|---------|-----|------|--------------------------|--------|------------|------------------------------------------|--------------------|---------------|
| node: master | install | 1 | 4 GB | / 15G | RED OS | 8.0 | pangolin-ansible-venv-controller (6.7.0) | | cluster |
| ip/dns: (srv1) | | | | | | | pangolin-installer (1.0.3) | | |
| | | | | | | | pangolin-timescaledb-6.7-apache (2.25.0) | | |
| | | | | | | | | | |
| node: replica | install | 1 | 4 GB | / 20G | RED OS | 8.0 | pangolin-timescaledb-6.7-apache (2.25.0) | | cluster |
| ip/dns: (srv2) | | | | | | | | | |
| node: arbiter | install | 1 | 4 GB | / 20G | RED OS | 8.0 | | | cluster |
| ip/dns: (srv3) | | | | | | | | | |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
Выполняемая задача: install
🟢 Роль MAIN PLAY - Завершена! [Время выполнения: 0:00:10] Задач выполнено: 20 | | |#####################################|
🟢 Роль PANGOLIN_CHECKS - Завершена! [Время выполнения: 0:07:32] Задач выполнено: 662 | | |#####################################|
🟢 Роль PANGOLIN_LICENSE - Завершена! [Время выполнения: 0:00:04] Задач выполнено: 7 | | |#####################################|
🟢 Роль PANGOLIN_AUTH_PASSWORD - Завершена! [Время выполнения: 0:00:05] Задач выполнено: 8 | | |#####################################|
🟢 Роль ETCD - Завершена! [Время выполнения: 0:00:30] Задач выполнено: 34 | | |#####################################|
🟢 Роль PANGOLIN_CERTS_ROTATE - Завершена! [Время выполнения: 0:00:23] Задач выполнено: 26 | | |#####################################|
🟢 Роль PANGOLIN_SECURITY_UTILITIES - Завершена! [Время выполнения: 0:00:08] Задач выполнено: 18 | | |#####################################|
🟢 Роль PANGOLIN_DBMS - Завершена! [Время выполнения: 0:00:57] Задач выполнено: 96 | | |#####################################|
🟢 Роль PANGOLIN_MANAGER - Завершена! [Время выполнения: 0:01:07] Задач выполнено: 31 | | |#####################################|
🟢 Роль PANGOLIN_BACKUP_TOOLS - Завершена! [Время выполнения: 0:00:15] Задач выполнено: 37 | | |#####################################|
🟢 Роль PANGOLIN_POOLER - Завершена! [Время выполнения: 0:00:18] Задач выполнено: 16 | | |#####################################|
🟢 Роль PANGOLIN_POOLER_MT - Завершена! [Время выполнения: 0:00:00] Задач выполнено: 5 | | |#####################################|
🟢 Роль PANGOLIN_DIAGNOSTIC_TOOL - Завершена! [Время выполнения: 0:00:06] Задач выполнено: 12 | | |#####################################|
🟢 Роль PANGOLIN_AUTH_REENCRYPT - Завершена! [Время выполнения: 0:00:18] Задач выполнено: 20 | | |#####################################|
🟢 Роль PANGOLIN_UNTRUSTED_EXTENSIONS - Завершена! [Время выполнения: 0:01:05] Задач выполнено: 151 | | |#####################################|
🟢 Роль CONFIGURE - Завершена! [Время выполнения: 0:01:51] Задач выполнено: 167 | | |#####################################|
Установка Pangolin прошла успешно!
Запуск предварительных проверок.
Предварительные проверки пройдены.
|---------------------------------------------------------------------------|
| after install |
|---------------------------------------------------------------------------|
| Node | Action | Packages Installed |
|----------------|---------------|------------------------------------------|
| node: master | after install | pangolin-ansible-venv-controller (6.7.0) |
| ip/dns: (srv1) | | pangolin-installer (1.0.3) |
| | | pangolin-timescaledb-6.7-apache (2.25.0) |
| | | pangolin-ansible-venv-controlled (6.7.0) |
| | | pangolin-auth-password (6.7.0) |
| | | pangolin-certs-rotate (6.7.0) |
| | | pangolin-security-utilities (6.7.0) |
| | | pangolin-dbms-6.7 (6.7.0) |
| | | pangolin-dbms-6.7-client (6.7.0) |
| | | pangolin-manager-venv (2.1.13) |
| | | pangolin-manager (2.1.13) |
| | | pangolin-backup-tools-venv (6.7.0) |
| | | pangolin-backup-tools (6.7.0) |
| | | pangolin-pooler (1.5.6) |
| | | pangolin-diagnostic-tool (6.7.0) |
| | | pangolin-auth-reencrypt (6.7.0) |
| | | pangolin-dbms-6-pltcl (6.7.0) |
| | | pangolin-dbms-6-plperl (6.7.0) |
| | | pangolin-dbms-6-jsonb-plperl (6.7.0) |
| | | pangolin-dbms-6-hstore-plperl (6.7.0) |
| | | pangolin-dbms-6-bool-plperl (6.7.0) |
| | | pangolin-dbms-6-plpython3 (6.7.0) |
| | | pangolin-dbms-6-ltree-plpython3 (6.7.0) |
| | | pangolin-dbms-6-jsonb-plpython3 (6.7.0) |
| | | pangolin-dbms-6-hstore-plpython3 (6.7.0) |
| | | pangolin-tuner (1.1.1) |
| | | |
| node: replica | after install | pangolin-timescaledb-6.7-apache (2.25.0) |
| ip/dns: (srv2) | | pangolin-ansible-venv-controlled (6.7.0) |
| | | pangolin-auth-password (6.7.0) |
| | | pangolin-certs-rotate (6.7.0) |
| | | pangolin-security-utilities (6.7.0) |
| | | pangolin-dbms-6.7 (6.7.0) |
| | | pangolin-dbms-6.7-client (6.7.0) |
| | | pangolin-manager-venv (2.1.13) |
| | | pangolin-manager (2.1.13) |
| | | pangolin-backup-tools-venv (6.7.0) |
| | | pangolin-backup-tools (6.7.0) |
| | | pangolin-pooler (1.5.6) |
| | | pangolin-diagnostic-tool (6.7.0) |
| | | pangolin-auth-reencrypt (6.7.0) |
| | | pangolin-dbms-6-pltcl (6.7.0) |
| | | pangolin-dbms-6-plperl (6.7.0) |
| | | pangolin-dbms-6-jsonb-plperl (6.7.0) |
| | | pangolin-dbms-6-hstore-plperl (6.7.0) |
| | | pangolin-dbms-6-bool-plperl (6.7.0) |
| | | pangolin-dbms-6-plpython3 (6.7.0) |
| | | pangolin-dbms-6-ltree-plpython3 (6.7.0) |
| | | pangolin-dbms-6-jsonb-plpython3 (6.7.0) |
| | | pangolin-dbms-6-hstore-plpython3 (6.7.0) |
| | | pangolin-tuner (1.1.1) |
| | | |
| node: arbiter | after install | |
| ip/dns: (srv3) | | |
|---------------------------------------------------------------------------|

Проверка настроек​

Выведите пароль, который должен был установлен для суперпользователя:

[student@srv1 ~]$ grep '^postgres_db_pass:' config.yml
postgres_db_pass: '<password>'

Проверьте, действительно ли установлен пароль, заданный в файле ~/config.yml:

[student@srv1 ~]$ psql "host=srv1 port=5433 user=postgres password='<password>'"
psql (15.15)
SSL-соединение (протокол: TLSv1.3, шифр: TLS_AES_256_GCM_SHA384, сжатие: выкл.)
Введите "help", чтобы получить справку.
postgres=# \conninfo
Вы подключены к базе данных "postgres" как пользователь "postgres" (компьютер "srv1": адрес "<IP-Address1>", порт "5433").
SSL-соединение (протокол: TLSv1.3, шифр: TLS_AES_256_GCM_SHA384, сжатие: выкл.)

Проверка доказала, что используется пароль, установленный в файле конфигурации.

Получите настройку запоминания истории:

postgres=# \dconfig *psql*history*
Список параметров конфигурации
Параметр | Значение
-------------------|----------
psql.save_history | on
(1 строка)

Выйдите из сеанса:

postgres=# \q

Войдите в сеанс снова и выведите команды из истории:

[student@srv1 ~]$ psql "host=srv1 port=5433 user=postgres password='<password>'"
psql (15.15)
SSL-соединение (протокол: TLSv1.3, шифр: TLS_AES_256_GCM_SHA384, сжатие: выкл.)
Введите "help", чтобы получить справку.
postgres=# \s
\conninfo
\dconfig *psql*history*
\q

Подведем итоги​

Вопрос 1

Вопрос 1: В каком файле конфигурации можно найти заданные по умолчанию пароли ролей СУБД?

Вопрос 2

Вопрос 2: Посмотрите на вывод команды:

postgres=# \conninfo
Вы подключены к базе данных "postgres" как пользователь "postgres" (компьютер "srv1": адрес "<IP-Address1>", порт "5433").
SSL-соединение (протокол: TLSv1.3, шифр: TLS_AES_256_GCM_SHA384, сжатие: выкл.)

Какие типы подключений для аутентификации HBA могли быть использованы для данной сессии?