mirror of
https://github.com/matter-labs/ansible-en-role.git
synced 2025-12-06 10:59:56 +00:00
Compare commits
20 Commits
v3.10.2
...
c497fc0982
| Author | SHA1 | Date | |
|---|---|---|---|
| c497fc0982 | |||
| 57f3fb74e4 | |||
| aa018348d8 | |||
| b8e3b89cf5 | |||
| d276d7b290 | |||
| 60333c40da | |||
| 2eb2b1f6d4 | |||
| 69777ac4e8 | |||
| 46e2a6e0e4 | |||
| c5ab63672b | |||
| 22a1d06ef7 | |||
| 655b461ba5 | |||
| 45feed1069 | |||
| 5298e9f87d | |||
| 576f8eb252 | |||
| b672d803f0 | |||
| 5e8657ac3b | |||
| 4f1b6a37ab | |||
| 9034dc5fd4 | |||
| dac0b0cc80 |
@ -59,8 +59,14 @@ postgres_arguments:
|
|||||||
enable_postgres_replication: false
|
enable_postgres_replication: false
|
||||||
# IP address of the interface replication
|
# IP address of the interface replication
|
||||||
postgres_replications_arguments: []
|
postgres_replications_arguments: []
|
||||||
|
postgres_replica_user_name: ""
|
||||||
|
postgres_replica_user_password: ""
|
||||||
|
postgres_replica_auth_method: "scram-sha-256"
|
||||||
postgres_replication_bind_address: ""
|
postgres_replication_bind_address: ""
|
||||||
postgres_replica_address: ""
|
postgres_replica_address: ""
|
||||||
|
backup_db_user: ""
|
||||||
|
backup_db_password: ""
|
||||||
|
backup_db_name: ""
|
||||||
|
|
||||||
# Enable TLS for traefik
|
# Enable TLS for traefik
|
||||||
enable_tls: false
|
enable_tls: false
|
||||||
|
|||||||
@ -10,3 +10,6 @@ roles:
|
|||||||
collections:
|
collections:
|
||||||
- name: community.general
|
- name: community.general
|
||||||
version: 8.4.0
|
version: 8.4.0
|
||||||
|
# Collection for the replication only.
|
||||||
|
- name: community.postgresql
|
||||||
|
version: 3.7.0
|
||||||
|
|||||||
@ -9,3 +9,7 @@
|
|||||||
|
|
||||||
- name: Prepare configs
|
- name: Prepare configs
|
||||||
ansible.builtin.include_tasks: provision.yml
|
ansible.builtin.include_tasks: provision.yml
|
||||||
|
|
||||||
|
- name: Configure replication on main instance
|
||||||
|
ansible.builtin.include_tasks: replication.yml
|
||||||
|
when: enable_postgres_replication
|
||||||
|
|||||||
@ -46,6 +46,8 @@
|
|||||||
- postgres_replication_bind_address
|
- postgres_replication_bind_address
|
||||||
- postgres_replica_address
|
- postgres_replica_address
|
||||||
- postgres_replications_arguments
|
- postgres_replications_arguments
|
||||||
|
- postgres_replica_user_name
|
||||||
|
- postgres_replica_user_password
|
||||||
|
|
||||||
- name: Check required en vars empty
|
- name: Check required en vars empty
|
||||||
ansible.builtin.fail:
|
ansible.builtin.fail:
|
||||||
|
|||||||
60
tasks/replication.yml
Normal file
60
tasks/replication.yml
Normal file
@ -0,0 +1,60 @@
|
|||||||
|
---
|
||||||
|
|
||||||
|
- name: Install libpq-dev packages
|
||||||
|
ansible.builtin.apt:
|
||||||
|
update_cache: true
|
||||||
|
name: libpq-dev
|
||||||
|
|
||||||
|
- name: Install psycopg2 python package
|
||||||
|
ansible.builtin.pip:
|
||||||
|
name: psycopg2
|
||||||
|
|
||||||
|
- name: Grant user replication access for replication.
|
||||||
|
community.postgresql.postgresql_pg_hba:
|
||||||
|
dest: "{{ storage_directory }}/postgres/pg_hba.conf"
|
||||||
|
contype: host
|
||||||
|
users: "{{ postgres_replica_user_name }}"
|
||||||
|
source: "{{ postgres_replica_address }}/32"
|
||||||
|
databases: replication
|
||||||
|
method: "{{ postgres_replica_auth_method }}"
|
||||||
|
|
||||||
|
- name: Create postgres replication user
|
||||||
|
community.postgresql.postgresql_user:
|
||||||
|
login_host: "{{ postgres_replication_bind_address }}"
|
||||||
|
login_user: "{{ database_username }}"
|
||||||
|
login_password: "{{ database_password }}"
|
||||||
|
name: "{{ postgres_replica_user_name }}"
|
||||||
|
password: "{{ postgres_replica_user_password }}"
|
||||||
|
role_attr_flags: "REPLICATION"
|
||||||
|
|
||||||
|
- name: Create replication slot if doesn't exist
|
||||||
|
community.postgresql.postgresql_slot:
|
||||||
|
login_host: "{{ postgres_replication_bind_address }}"
|
||||||
|
login_user: "{{ database_username }}"
|
||||||
|
login_password: "{{ database_password }}"
|
||||||
|
slot_name: replica
|
||||||
|
|
||||||
|
- name: Reload postgres configuration
|
||||||
|
community.postgresql.postgresql_query:
|
||||||
|
login_host: "{{ postgres_replication_bind_address }}"
|
||||||
|
login_user: "{{ database_username }}"
|
||||||
|
login_password: "{{ database_password }}"
|
||||||
|
query: "SELECT pg_reload_conf()"
|
||||||
|
|
||||||
|
- name: Create postgres backup user
|
||||||
|
community.postgresql.postgresql_user:
|
||||||
|
login_host: "{{ postgres_replication_bind_address }}"
|
||||||
|
login_user: "{{ database_username }}"
|
||||||
|
login_password: "{{ database_password }}"
|
||||||
|
name: "{{ backup_db_user }}"
|
||||||
|
password: "{{ backup_db_password }}"
|
||||||
|
|
||||||
|
- name: Grant role pg_read_all_data to backup user
|
||||||
|
community.postgresql.postgresql_membership:
|
||||||
|
login_host: "{{ postgres_replication_bind_address }}"
|
||||||
|
login_user: "{{ database_username }}"
|
||||||
|
login_password: "{{ database_password }}"
|
||||||
|
group: pg_read_all_data
|
||||||
|
target_roles:
|
||||||
|
- "{{ backup_db_user }}"
|
||||||
|
state: present
|
||||||
@ -1,9 +1,10 @@
|
|||||||
server_addr: '0.0.0.0:3054'
|
server_addr: '0.0.0.0:3054'
|
||||||
public_addr: '{{ ansible_default_ipv4.address }}:{{ consensus_port }}'
|
public_addr: '{{ ansible_default_ipv4.address }}:{{ consensus_port }}'
|
||||||
max_payload_size: 5000000
|
max_payload_size: 5000000
|
||||||
gossip_dynamic_inbound_limit: 100
|
gossip_dynamic_inbound_limit: 200
|
||||||
gossip_static_outbound:
|
rpc_config:
|
||||||
{% for item in consensus_outbound %}
|
get_block_rate:
|
||||||
- key: {{ item.key }}
|
burst: 5
|
||||||
addr: {{ item.addr }}
|
refresh: # 0.2s
|
||||||
{% endfor %}
|
seconds: 0
|
||||||
|
nanos: 200000000
|
||||||
|
|||||||
@ -44,8 +44,6 @@ services:
|
|||||||
env_file:
|
env_file:
|
||||||
- postgres.env
|
- postgres.env
|
||||||
{% if enable_postgres_replication %}
|
{% if enable_postgres_replication %}
|
||||||
environment:
|
|
||||||
POSTGRES_HOST_AUTH_METHOD: "host replication replicator {{ postgres_replica_address }}/32 md5"
|
|
||||||
ports:
|
ports:
|
||||||
- "{{ postgres_replication_bind_address }}:5432:5432"
|
- "{{ postgres_replication_bind_address }}:5432:5432"
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
Reference in New Issue
Block a user