22 Commits

Author SHA1 Message Date
4bd3805af1 Merge pull request #38 from matter-labs/docs
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
chore(docs): Update link to EN mainnet DB backup
2024-12-16 17:45:26 +07:00
8006ed9328 chore(docs): Update link to EN mainnet backup 2024-12-16 17:38:02 +07:00
c497fc0982 Merge pull request #37 from matter-labs/yorik-patch-1
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
feat: Fake PR to force release
2024-12-04 15:49:30 +01:00
57f3fb74e4 feat: Fake PR to force release 2024-12-04 15:47:39 +01:00
aa018348d8 Merge pull request #36 from matter-labs/gprusak-rate-limit
feat(consensus): bumped inbound connections limit
2024-12-04 15:04:28 +01:00
b8e3b89cf5 bumped inbound connections limit 2024-12-03 17:47:46 +01:00
d276d7b290 Merge pull request #35 from matter-labs/backup-user
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
feat: Added user with backup permissions only
2024-11-27 15:45:36 +01:00
60333c40da feat: Added user with backup permissions only 2024-11-27 15:24:20 +01:00
2eb2b1f6d4 feat: Added user with backup permissions only 2024-11-27 15:12:12 +01:00
69777ac4e8 feat: Added user with backup permissions only 2024-11-27 15:08:46 +01:00
46e2a6e0e4 feat: Added user with backup permissions only 2024-11-27 14:51:33 +01:00
c5ab63672b Merge pull request #34 from matter-labs/add-more-replication
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
feat: Configure replication from postgres collection
2024-11-20 18:04:24 +01:00
22a1d06ef7 fix lint 2024-11-20 17:59:52 +01:00
655b461ba5 add libpq-dev 2024-11-20 17:55:22 +01:00
45feed1069 add psycopg2 2024-11-20 17:51:20 +01:00
5298e9f87d add psycopg2 2024-11-20 17:48:55 +01:00
576f8eb252 change priv to role_attr_flags 2024-11-20 17:44:12 +01:00
b672d803f0 fixed lint 2024-11-20 17:01:52 +01:00
5e8657ac3b fixed lint 2024-11-20 17:00:14 +01:00
4f1b6a37ab fixed lint 2024-11-20 16:59:27 +01:00
9034dc5fd4 feat: Configure replication from postgres collection 2024-11-20 16:42:58 +01:00
dac0b0cc80 feat: Configure replication from postgres collection 2024-11-20 16:37:33 +01:00
8 changed files with 84 additions and 10 deletions

View File

@ -99,10 +99,10 @@ Basic auth secret can be generated by `htpasswd` and `sed` for interpolation:
2. Prepare the latest database backup on your host. you can download it from our public GCS buckets: 2. Prepare the latest database backup on your host. you can download it from our public GCS buckets:
Skip this step if you are recovering from a snapshot! Skip this step if you are recovering from a snapshot!
* [Era Mainnet latest dump](https://storage.googleapis.com/zksync-era-mainnet-external-node-backups/external_node_latest.pgdump) * [Era Mainnet latest dump](https://en-backups.matterlabs.dev/)
* [Era Sepolia Testnet latest dump](https://storage.googleapis.com/zksync-era-testnet-sepolia-external-node-backups/external_node_latest.pgdump) * [Era Sepolia Testnet latest dump](https://storage.googleapis.com/zksync-era-testnet-sepolia-external-node-backups/external_node_latest.pgdump)
Downloaded dump file should be placed into `{{ storage_directory }}/pg_backups` directory (`/usr/src/en/pg_backups` by default) Downloaded dump, if needed, should be unarchived and named `external_node_latest.pgdump`. File should be placed into `{{ storage_directory }}/pg_backups` directory (`/usr/src/en/pg_backups` by default).
3. **OPTIONAL**: If you already have running node, you can copy its tree and state directory to a new host's `{{ storage_directory }}/db`. (`/usr/src/en/db` by default) 3. **OPTIONAL**: If you already have running node, you can copy its tree and state directory to a new host's `{{ storage_directory }}/db`. (`/usr/src/en/db` by default)
Skip this step if you are recovering from a snapshot! Skip this step if you are recovering from a snapshot!

View File

@ -59,8 +59,14 @@ postgres_arguments:
enable_postgres_replication: false enable_postgres_replication: false
# IP address of the interface replication # IP address of the interface replication
postgres_replications_arguments: [] postgres_replications_arguments: []
postgres_replica_user_name: ""
postgres_replica_user_password: ""
postgres_replica_auth_method: "scram-sha-256"
postgres_replication_bind_address: "" postgres_replication_bind_address: ""
postgres_replica_address: "" postgres_replica_address: ""
backup_db_user: ""
backup_db_password: ""
backup_db_name: ""
# Enable TLS for traefik # Enable TLS for traefik
enable_tls: false enable_tls: false

View File

@ -10,3 +10,6 @@ roles:
collections: collections:
- name: community.general - name: community.general
version: 8.4.0 version: 8.4.0
# Collection for the replication only.
- name: community.postgresql
version: 3.7.0

View File

@ -9,3 +9,7 @@
- name: Prepare configs - name: Prepare configs
ansible.builtin.include_tasks: provision.yml ansible.builtin.include_tasks: provision.yml
- name: Configure replication on main instance
ansible.builtin.include_tasks: replication.yml
when: enable_postgres_replication

View File

@ -46,6 +46,8 @@
- postgres_replication_bind_address - postgres_replication_bind_address
- postgres_replica_address - postgres_replica_address
- postgres_replications_arguments - postgres_replications_arguments
- postgres_replica_user_name
- postgres_replica_user_password
- name: Check required en vars empty - name: Check required en vars empty
ansible.builtin.fail: ansible.builtin.fail:

60
tasks/replication.yml Normal file
View File

@ -0,0 +1,60 @@
---
- name: Install libpq-dev packages
ansible.builtin.apt:
update_cache: true
name: libpq-dev
- name: Install psycopg2 python package
ansible.builtin.pip:
name: psycopg2
- name: Grant user replication access for replication.
community.postgresql.postgresql_pg_hba:
dest: "{{ storage_directory }}/postgres/pg_hba.conf"
contype: host
users: "{{ postgres_replica_user_name }}"
source: "{{ postgres_replica_address }}/32"
databases: replication
method: "{{ postgres_replica_auth_method }}"
- name: Create postgres replication user
community.postgresql.postgresql_user:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
name: "{{ postgres_replica_user_name }}"
password: "{{ postgres_replica_user_password }}"
role_attr_flags: "REPLICATION"
- name: Create replication slot if doesn't exist
community.postgresql.postgresql_slot:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
slot_name: replica
- name: Reload postgres configuration
community.postgresql.postgresql_query:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
query: "SELECT pg_reload_conf()"
- name: Create postgres backup user
community.postgresql.postgresql_user:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
name: "{{ backup_db_user }}"
password: "{{ backup_db_password }}"
- name: Grant role pg_read_all_data to backup user
community.postgresql.postgresql_membership:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
group: pg_read_all_data
target_roles:
- "{{ backup_db_user }}"
state: present

View File

@ -1,9 +1,10 @@
server_addr: '0.0.0.0:3054' server_addr: '0.0.0.0:3054'
public_addr: '{{ ansible_default_ipv4.address }}:{{ consensus_port }}' public_addr: '{{ ansible_default_ipv4.address }}:{{ consensus_port }}'
max_payload_size: 5000000 max_payload_size: 5000000
gossip_dynamic_inbound_limit: 100 gossip_dynamic_inbound_limit: 200
gossip_static_outbound: rpc_config:
{% for item in consensus_outbound %} get_block_rate:
- key: {{ item.key }} burst: 5
addr: {{ item.addr }} refresh: # 0.2s
{% endfor %} seconds: 0
nanos: 200000000

View File

@ -44,8 +44,6 @@ services:
env_file: env_file:
- postgres.env - postgres.env
{% if enable_postgres_replication %} {% if enable_postgres_replication %}
environment:
POSTGRES_HOST_AUTH_METHOD: "host replication replicator {{ postgres_replica_address }}/32 md5"
ports: ports:
- "{{ postgres_replication_bind_address }}:5432:5432" - "{{ postgres_replication_bind_address }}:5432:5432"
{% endif %} {% endif %}