29 Commits

Author SHA1 Message Date
c5ab63672b Merge pull request #34 from matter-labs/add-more-replication
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
feat: Configure replication from postgres collection
2024-11-20 18:04:24 +01:00
22a1d06ef7 fix lint 2024-11-20 17:59:52 +01:00
655b461ba5 add libpq-dev 2024-11-20 17:55:22 +01:00
45feed1069 add psycopg2 2024-11-20 17:51:20 +01:00
5298e9f87d add psycopg2 2024-11-20 17:48:55 +01:00
576f8eb252 change priv to role_attr_flags 2024-11-20 17:44:12 +01:00
b672d803f0 fixed lint 2024-11-20 17:01:52 +01:00
5e8657ac3b fixed lint 2024-11-20 17:00:14 +01:00
4f1b6a37ab fixed lint 2024-11-20 16:59:27 +01:00
9034dc5fd4 feat: Configure replication from postgres collection 2024-11-20 16:42:58 +01:00
dac0b0cc80 feat: Configure replication from postgres collection 2024-11-20 16:37:33 +01:00
10ea272736 Merge pull request #33 from matter-labs/fix-type-postgres_replication_interface
fix: Rename variable postgres_replication_bind_address
2024-11-20 10:41:23 +01:00
3fa5c8622b fix: Rename variable postgres_replication_bind_address 2024-11-20 10:40:16 +01:00
64198202a5 Merge pull request #32 from matter-labs/fix-typo
fix: Fixed typo in validation step for replication
2024-11-20 10:36:36 +01:00
0d1717f38a fix: Fixed typo in validation step for replication 2024-11-20 10:35:18 +01:00
13ef869339 Merge pull request #31 from matter-labs/add-replication-vars
Some checks are pending
Release / Release (push) Waiting to run
feat: Added optional postgres replication
2024-11-19 16:35:45 +01:00
cfbaed74f0 Added replication flags 2024-11-19 16:28:13 +01:00
6f1e025785 Added replication flags 2024-11-19 16:26:57 +01:00
f347a9173e feat: Added optional postgres replication 2024-11-19 16:12:31 +01:00
2bf98e9273 feat: Added optional postgres replication 2024-11-19 16:11:28 +01:00
dde435ca95 Merge pull request #30 from matter-labs/fix-snapshot-conf
feat: Bump default EN version, fix snapshot recovery config
2024-10-02 17:23:55 +02:00
8d085aa960 dedup 2024-10-02 17:21:47 +02:00
b85a7d5c65 feat: Bump default EN version, fix snapshot recovery config 2024-10-02 17:18:15 +02:00
6a3c8cb263 Merge pull request #28 from matter-labs/ya-zkd-1817-upgrade-external-nodes-on-hetzner5
fix: Route all consensus traffic to the docker port.
2024-08-13 13:57:35 +02:00
ed4feb99bc fix: Route all consensus traffic to the docker port. 2024-08-13 13:56:28 +02:00
605525c7ba Merge pull request #27 from matter-labs/ya-zkd-1817-upgrade-external-nodes-on-hetzner4
feat: Add traefik configuration for consensus TCP port, open it in firewall
2024-08-13 13:36:58 +02:00
5bdeb0fcfa feat: Add traefik configuration for consensus TCP port, open it in
firewall
2024-08-13 13:32:10 +02:00
bf186104d4 Merge pull request #26 from matter-labs/ya-zkd-1817-upgrade-external-nodes-on-hetzner3
fix: Correct path and file names for consensus
2024-08-12 17:33:38 +02:00
493e5ceffc fix: Correct path and file names for consensus 2024-08-12 17:31:25 +02:00
7 changed files with 115 additions and 9 deletions

View File

@ -11,7 +11,7 @@ docker_compose_version: "v2.23.0"
# Versions of External Node and 3rd party components # Versions of External Node and 3rd party components
traefik_version: 2.11 traefik_version: 2.11
postgres_version: 14 postgres_version: 14
external_node_version: 24.16.0 external_node_version: 24.26.0
external_node_raw_docker_tag: "" external_node_raw_docker_tag: ""
vmagent_version: 1.100.1 vmagent_version: 1.100.1
cadvisor_version: 0.47.2 cadvisor_version: 0.47.2
@ -56,6 +56,14 @@ postgres_arguments:
- max_parallel_maintenance_workers=4 - max_parallel_maintenance_workers=4
- -c - -c
- checkpoint_timeout=1800 - checkpoint_timeout=1800
enable_postgres_replication: false
# IP address of the interface replication
postgres_replications_arguments: []
postgres_replica_user_name: ""
postgres_replica_user_password: ""
postgres_replica_auth_method: "scram-sha-256"
postgres_replication_bind_address: ""
postgres_replica_address: ""
# Enable TLS for traefik # Enable TLS for traefik
enable_tls: false enable_tls: false

View File

@ -10,3 +10,6 @@ roles:
collections: collections:
- name: community.general - name: community.general
version: 8.4.0 version: 8.4.0
# Collection for the replication only.
- name: community.postgresql
version: 3.7.0

View File

@ -49,6 +49,23 @@
source: "{{ loadbalancer_ip | mandatory }}" source: "{{ loadbalancer_ip | mandatory }}"
jump: ACCEPT jump: ACCEPT
- name: Allow consensus port traffic from any IP
when: enable_consensus
ansible.builtin.iptables:
chain: INPUT
protocol: tcp
destination_port: "{{ consensus_port }}"
jump: ACCEPT
- name: Allow postgres replication traffic from replica only
when: enable_postgres_replication
ansible.builtin.iptables:
chain: INPUT
protocol: tcp
destination_port: 5432
source: "{{ postgres_replica_address }}"
jump: ACCEPT
- name: Set default policy to DROP - name: Set default policy to DROP
ansible.builtin.iptables: ansible.builtin.iptables:
chain: INPUT chain: INPUT

View File

@ -9,3 +9,7 @@
- name: Prepare configs - name: Prepare configs
ansible.builtin.include_tasks: provision.yml ansible.builtin.include_tasks: provision.yml
- name: Configure replication on main instance
ansible.builtin.include_tasks: replication.yml
when: enable_postgres_replication

View File

@ -32,6 +32,23 @@
- l2_chain_id - l2_chain_id
- l1_chain_id - l1_chain_id
- name: "Verify that required variables for replication is set"
when: enable_postgres_replication
ansible.builtin.assert:
that:
- postgress_replication_required_var != ""
fail_msg: "{{ postgress_replication_required_var }} needs to be set for the role for postgres replication to work"
success_msg: "Required variable for postgres replication {{ postgress_replication_required_var }} isn't empty"
loop_control:
loop_var: postgress_replication_required_var
with_items:
- enable_postgres_replication
- postgres_replication_bind_address
- postgres_replica_address
- postgres_replications_arguments
- postgres_replica_user_name
- postgres_replica_user_password
- name: Check required en vars empty - name: Check required en vars empty
ansible.builtin.fail: ansible.builtin.fail:
msg: "Variable '{{ item }}' is empty" msg: "Variable '{{ item }}' is empty"

42
tasks/replication.yml Normal file
View File

@ -0,0 +1,42 @@
---
- name: Install libpq-dev packages
ansible.builtin.apt:
update_cache: true
name: libpq-dev
- name: Install psycopg2 python package
ansible.builtin.pip:
name: psycopg2
- name: Grant user replication access for replication.
community.postgresql.postgresql_pg_hba:
dest: "{{ storage_directory }}/postgres/pg_hba.conf"
contype: host
users: "{{ postgres_replica_user_name }}"
source: "{{ postgres_replica_address }}/32"
databases: replication
method: "{{ postgres_replica_auth_method }}"
- name: Create postgres replication user
community.postgresql.postgresql_user:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
name: "{{ postgres_replica_user_name }}"
password: "{{ postgres_replica_user_password }}"
role_attr_flags: "REPLICATION"
- name: Create replication slot if doesn't exist
community.postgresql.postgresql_slot:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
slot_name: replica
- name: Reload postgres configuration
community.postgresql.postgresql_query:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
query: "SELECT pg_reload_conf()"

View File

@ -8,10 +8,13 @@ services:
- "--log.level=INFO" - "--log.level=INFO"
- "--providers.docker=true" - "--providers.docker=true"
- "--providers.docker.exposedbydefault=false" - "--providers.docker.exposedbydefault=false"
- "--entrypoints.web.address=:80" - "--entryPoints.web.address=:80"
- "--entrypoints.external_node_health.address=:3080" - "--entryPoints.external_node_health.address=:3080"
{% if enable_consensus %}
- "--entryPoints.external_node_consensus.address=:{{ consensus_port }}"
{% endif %}
{% if enable_tls %} {% if enable_tls %}
- "--entrypoints.websecure.address=:443" - "--entryPoints.websecure.address=:443"
- "--certificatesresolvers.en_resolver.acme.tlschallenge=true" - "--certificatesresolvers.en_resolver.acme.tlschallenge=true"
- "--certificatesresolvers.en_resolver.acme.storage=/letsencrypt/acme.json" - "--certificatesresolvers.en_resolver.acme.storage=/letsencrypt/acme.json"
- "--certificatesresolvers.myresolver.acme.email={{ acme_email }}" - "--certificatesresolvers.myresolver.acme.email={{ acme_email }}"
@ -40,12 +43,21 @@ services:
- ./restore_dump.sh:/docker-entrypoint-initdb.d/restore_dump.sh - ./restore_dump.sh:/docker-entrypoint-initdb.d/restore_dump.sh
env_file: env_file:
- postgres.env - postgres.env
{% if enable_postgres_replication %}
ports:
- "{{ postgres_replication_bind_address }}:5432:5432"
{% endif %}
command: command:
- postgres - postgres
- -c - -c
{% for argument in postgres_arguments %} {% for argument in postgres_arguments %}
- {{ argument }} - {{ argument }}
{% endfor %} {% endfor %}
{% if enable_postgres_replication %}
{% for repl_argument in postgres_replications_arguments %}
- {{ repl_argument }}
{% endfor %}
{% endif %}
external_node: external_node:
{% if not external_node_raw_docker_tag %} {% if not external_node_raw_docker_tag %}
image: "matterlabs/external-node:v{{ external_node_version }}" image: "matterlabs/external-node:v{{ external_node_version }}"
@ -76,6 +88,12 @@ services:
{% if enable_basic_auth %} {% if enable_basic_auth %}
- "traefik.http.routers.external_node_main.middlewares=external_node_auth" - "traefik.http.routers.external_node_main.middlewares=external_node_auth"
- "traefik.http.middlewares.external_node_auth.basicauth.users={{ basic_auth_secret }}" - "traefik.http.middlewares.external_node_auth.basicauth.users={{ basic_auth_secret }}"
{% endif %}
{% if enable_consensus %}
- "traefik.tcp.services.external_node_consensus.loadbalancer.server.port={{ consensus_port }}"
- "traefik.tcp.routers.external_node_consensus.rule=HostSNI(`*`)"
- "traefik.tcp.routers.external_node_consensus.entrypoints=external_node_consensus"
- "traefik.tcp.routers.external_node_consensus.service=external_node_consensus"
{% endif %} {% endif %}
expose: expose:
- {{ rpc_http_port }} - {{ rpc_http_port }}
@ -101,7 +119,7 @@ services:
RUST_LOG: {{ rust_log }} RUST_LOG: {{ rust_log }}
{% if enable_consensus %} {% if enable_consensus %}
EN_CONSENSUS_CONFIG_PATH: /etc/consensus_config.yaml EN_CONSENSUS_CONFIG_PATH: /etc/consensus_config.yaml
EN_CONSENSUS_SECRETS_PATH: /run/secrets/consensus_secrets.yaml EN_CONSENSUS_SECRETS_PATH: /run/secrets/consensus_secrets
{% endif %} {% endif %}
healthcheck: healthcheck:
test: [ "CMD", "curl", "-f", "http://localhost:{{ healthcheck_port }}/health" ] test: [ "CMD", "curl", "-f", "http://localhost:{{ healthcheck_port }}/health" ]
@ -112,15 +130,12 @@ services:
volumes: volumes:
- "{{ storage_directory }}/db:/db" - "{{ storage_directory }}/db:/db"
{% if enable_consensus %} {% if enable_consensus %}
- "consensus_config.yaml:/etc/consensus_config.yaml" - "{{ configuration_directory }}/consensus_config.yaml:/etc/consensus_config.yaml"
{% endif %} {% endif %}
env_file: env_file:
- "external_node.env" - "external_node.env"
- "postgres.env" - "postgres.env"
command: command:
{% if enable_snapshots_recovery %}
- --enable-snapshots-recovery
{% endif %}
{% if enable_consensus %} {% if enable_consensus %}
- --enable-consensus - --enable-consensus
secrets: secrets: