From ca679a93b8183ffef4429d94f3f3d3a2dd8e05a8 Mon Sep 17 00:00:00 2001 From: bradnicholson Date: Fri, 9 Mar 2018 09:35:29 -0500 Subject: [PATCH 01/63] Make deleting recovery.conf optional. (#638) pgBackRest's restore command generates the appropriate recovery.conf based on the parameters you provide to pgBackRest. When calling pgBackRest's restore command via Patroni's custom bootstrap, it deletes that recovery.conf. Specifying the recovery.conf information in the patroni.yml is less than ideal. It prevent's leveraging pgBackRests work to ensure recovery.conf files are properly generated. It also can lead to transient config data in the patroni.yml under certain restore cases, such as a PITR restore of Cluster B to Cluster A, where the restore_commnand in A needs to reference B. The parameter is optional. The default behavior is to delete the recovery.conf. Fixes https://github.com/zalando/patroni/issues/637 --- docs/replica_bootstrap.rst | 4 ++++ patroni/postgresql.py | 3 ++- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/replica_bootstrap.rst b/docs/replica_bootstrap.rst index 77f27e66..2d1da113 100644 --- a/docs/replica_bootstrap.rst +++ b/docs/replica_bootstrap.rst @@ -23,6 +23,7 @@ arguments to them, i.e. the name of the cluster and the path to the data directo method: : command: [param1 [, ...]] + keep_existing_recovery_conf: False recovery_conf: recovery_target_action: promote recovery_target_timeline: latest @@ -47,6 +48,9 @@ If a ``recovery_conf`` block is defined in the same section as the custom bootst ``recovery.conf`` before starting the newly bootstrapped instance. Typically, such recovery.conf should contain at least one of the ``recovery_target_*`` parameters, together with the ``recovery_target_timeline`` set to ``promote``. +If ``keep_existing_recovery_conf`` is defined and set to ``True``, Patroni will not remove the existing ``recovery.conf`` file if it exists. +This is useful when bootstrapping from a backup with tools like pgBackRest that generate the appropriate ``recovery.conf`` for you. + .. note:: Bootstrap methods are neither chained, nor fallen-back to the default one in case the primary one fails diff --git a/patroni/postgresql.py b/patroni/postgresql.py index 742e1017..a4a076d4 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -556,7 +556,8 @@ class Postgresql(object): if 'recovery_conf' in config: self.write_recovery_conf(config['recovery_conf']) - elif os.path.isfile(self._recovery_conf) or os.path.islink(self._recovery_conf): + elif (os.path.isfile(self._recovery_conf) or os.path.islink(self._recovery_conf)) and \ + not config.get('keep_existing_recovery_conf'): os.unlink(self._recovery_conf) return True From 3c05e2e984e164994fa4ddfb379ec5fbe91a9e99 Mon Sep 17 00:00:00 2001 From: Josh Berkus Date: Wed, 4 Apr 2018 04:39:43 -0700 Subject: [PATCH 02/63] Added references to the Slack channel in Readme and in contributing.rst. (#653) --- README.rst | 8 +++++++- docs/CONTRIBUTING.rst | 5 +++++ 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/README.rst b/README.rst index 505bc389..9dd9c16f 100644 --- a/README.rst +++ b/README.rst @@ -29,7 +29,7 @@ For an example of a Docker-based deployment with Patroni, see `Spilo `_, talk by Josh Berkus and Oleksii Kliukin at KubeCon Berlin 2017 +* `Elephants on Automatic: HA Clustered PostgreSQL with Helm `_, talk by Josh Berkus and Oleksii Kliukin at KubeCon Berlin 2017 * `PostgreSQL HA with Kubernetes and Patroni `__, talk by Josh Berkus at KubeCon 2016 (video) * `Feb. 2016 Zalando Tech blog post `__ @@ -41,6 +41,12 @@ Patroni is in active development and accepts contributions. See our `Contributin We report new releases information `here `__. +========= +Community +========= + +There are two places to connect with the Patroni community: `on github `__, via Issues and PRs, and on channel #patroni in the `PostgreSQL Slack `__. If you're using Patroni, or just interested, please join us. + =================================== Technical Requirements/Installation =================================== diff --git a/docs/CONTRIBUTING.rst b/docs/CONTRIBUTING.rst index 09409d8a..f7167b00 100644 --- a/docs/CONTRIBUTING.rst +++ b/docs/CONTRIBUTING.rst @@ -5,6 +5,11 @@ Contributing guidelines Wanna contribute to Patroni? Yay - here is how! +Chatting +-------- + +Just want to chat with other Patroni users? Looking for interactive troubleshooting help? Join us on channel #patroni in the `PostgreSQL Slack `__. + Reporting issues ---------------- From 140618abd2fcd920692cb84d7cc414a6333904e3 Mon Sep 17 00:00:00 2001 From: Don Seiler Date: Wed, 4 Apr 2018 06:40:46 -0500 Subject: [PATCH 03/63] Missing a word (#647) In re Issue #639 --- docs/pause.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/pause.rst b/docs/pause.rst index 325505e6..a33b04b4 100644 --- a/docs/pause.rst +++ b/docs/pause.rst @@ -25,7 +25,7 @@ When Patroni runs in a paused mode, it does not change the state of PostgreSQL, - If there is no leader lock in the cluster, the running master acquires the lock. If there is more than one master node, then the first master to acquire the lock wins. If there are no masters altogether, Patroni does not try to promote any replicas. There is an exception in this rule: if there is no leader lock because the old master has demoted itself due to the manual promotion, then only the candidate node mentioned in the promotion request may take the leader lock. When the new leader lock is granted (i.e. after promoting a replica manually), Patroni makes sure the replicas that were streaming from the previous leader will switch to the new one. -- When Postgres is stopped, Patroni does not try to start it. When Patroni is stopped, it does not to stop Postgres instance it is managing. +- When Postgres is stopped, Patroni does not try to start it. When Patroni is stopped, it does not try to stop the Postgres instance it is managing. User guide ---------- From 8c795ff0cf543b8b196f40ed9aeffd294f987df9 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Wed, 4 Apr 2018 13:45:44 +0200 Subject: [PATCH 04/63] Pass dict object to touch_member instead of json encoded string (#651) DCS implementation will take care about encoding it. Fixes https://github.com/zalando/patroni/issues/642 --- patroni/ctl.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/patroni/ctl.py b/patroni/ctl.py index f8b4b524..7f979861 100644 --- a/patroni/ctl.py +++ b/patroni/ctl.py @@ -786,7 +786,7 @@ def touch_member(config, dcs): 'role': p.role } - return dcs.touch_member(json.dumps(data, separators=(',', ':')), permanent=True) + return dcs.touch_member(data, permanent=True) def set_defaults(config, cluster_name): From e375fac273a75457bb241ade28c1609bf5a7fca2 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Wed, 4 Apr 2018 14:23:53 +0200 Subject: [PATCH 05/63] Treat postgres settings parameter names as case insensitive (#650) Because they are indeed case insensitive. Most of the parameters have snake_case_name, but there are three exceptions from this rule: DateStyle, IntervalStyle and TimeZone. In fact, if you specify timezone = 'some/tzn' it still works, but Patroni wasn't able to find 'timezone' in pg_settings and stripping this parameter out. We will use CaseInsensitiveDict to keep postgresql.parameters. This change affects only "final" configuration. That means if you put some"duplicates" (work_mem vs WORK_MEM) into patroni yaml or into cluster config, it would be resolved only at the last stage and for example you will be able to see both values if you use `patronictl edit-config`. Fixes https://github.com/zalando/patroni/issues/649 --- patroni/config.py | 3 ++- patroni/postgresql.py | 21 ++++++++++----------- 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/patroni/config.py b/patroni/config.py index 5dabe8ec..8a1a5aa8 100644 --- a/patroni/config.py +++ b/patroni/config.py @@ -10,6 +10,7 @@ from copy import deepcopy from patroni.dcs import ClusterConfig from patroni.postgresql import Postgresql from patroni.utils import deep_compare, parse_int, patch_config +from requests.structures import CaseInsensitiveDict logger = logging.getLogger(__name__) @@ -47,7 +48,7 @@ class Config(object): 'postgresql': { 'bin_dir': '', 'use_slots': True, - 'parameters': {p: v[0] for p, v in Postgresql.CMDLINE_OPTIONS.items()} + 'parameters': CaseInsensitiveDict({p: v[0] for p, v in Postgresql.CMDLINE_OPTIONS.items()}) }, 'watchdog': { 'mode': 'automatic', diff --git a/patroni/postgresql.py b/patroni/postgresql.py index a4a076d4..b52b7068 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -15,6 +15,7 @@ from patroni.callback_executor import CallbackExecutor from patroni.exceptions import PostgresConnectionException, PostgresException from patroni.utils import compare_values, parse_bool, parse_int, Retry, RetryFailedError, polling_loop, split_host_port from patroni.postmaster import PostmasterProcess +from requests.structures import CaseInsensitiveDict from six import string_types from six.moves.urllib.parse import quote_plus from threading import current_thread, Lock @@ -86,7 +87,7 @@ class Postgresql(object): # default_value -- some sane default value # check_function -- if the new value is not correct must return `!False` # min_version -- major version of PostgreSQL when parameter was introduced - CMDLINE_OPTIONS = { + CMDLINE_OPTIONS = CaseInsensitiveDict({ 'listen_addresses': (None, lambda _: False, 90100), 'port': (None, lambda _: False, 90100), 'cluster_name': (None, lambda _: False, 90500), @@ -101,7 +102,7 @@ class Postgresql(object): 'max_replication_slots': (10, lambda v: int(v) >= 10, 90400), 'max_worker_processes': (8, lambda v: int(v) >= 8, 90400), 'wal_log_hints': ('on', lambda _: False, 90400) - } + }) _CONFIG_WARNING_HEADER = '# Do not edit this file manually!\n# It will be overwritten by Patroni!\n' @@ -241,11 +242,9 @@ class Postgresql(object): parameters['synchronous_standby_names'] = self._synchronous_standby_names if self._major_version >= 90600 and parameters['wal_level'] == 'hot_standby': parameters['wal_level'] = 'replica' - ret = {k: v for k, v in parameters.items() if not self._major_version or - self._major_version >= self.CMDLINE_OPTIONS.get(k, (0, 1, 90100))[2]} - for k in ('hba_file', 'ident_file'): - if k in ret: - ret[k] = os.path.join(self._config_dir, ret[k]) + ret = CaseInsensitiveDict({k: v for k, v in parameters.items() if not self._major_version or + self._major_version >= self.CMDLINE_OPTIONS.get(k, (0, 1, 90100))[2]}) + ret.update({k: os.path.join(self._config_dir, ret[k]) for k in ('hba_file', 'ident_file') if k in ret}) return ret def resolve_connection_addresses(self): @@ -310,16 +309,16 @@ class Postgresql(object): conf_changed = hba_changed = local_connection_address_changed = pending_restart = False if self.state == 'running': - changes = {p: v for p, v in server_parameters.items() if '.' not in p} - changes.update({p: None for p, v in self._server_parameters.items() if not ('.' in p or p in changes)}) + changes = CaseInsensitiveDict({p: v for p, v in server_parameters.items() if '.' not in p}) + changes.update({p: None for p in self._server_parameters.keys() if not ('.' in p or p in changes)}) if changes: if 'wal_segment_size' not in changes: changes['wal_segment_size'] = '16384kB' # XXX: query can raise an exception for r in self.query("""SELECT name, setting, unit, vartype, context FROM pg_settings - WHERE name IN (""" + ', '.join(['%s'] * len(changes)) + """) - ORDER BY 1 DESC""", *(list(changes.keys()))): + WHERE LOWER(name) IN (""" + ', '.join(['%s'] * len(changes)) + """) + ORDER BY 1 DESC""", *(k.lower() for k in changes.keys())): if r[4] == 'internal': if r[0] == 'wal_segment_size': server_parameters.pop(r[0], None) From 38ad3943082d5e8082192e8d3aa3464b4aefca24 Mon Sep 17 00:00:00 2001 From: Dave Cramer Date: Sun, 15 Apr 2018 19:29:51 -0400 Subject: [PATCH 06/63] Use the word primary in favour of master (#663) Primary is a better alternative. --- docs/replication_modes.rst | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/docs/replication_modes.rst b/docs/replication_modes.rst index 9495bb51..ea404628 100644 --- a/docs/replication_modes.rst +++ b/docs/replication_modes.rst @@ -9,9 +9,9 @@ Patroni uses PostgreSQL streaming replication. For more information about stream Asynchronous mode durability ---------------------------- -In asynchronous mode the cluster is allowed to lose some committed transactions to ensure availability. When master server fails or becomes unavailable for any other reason Patroni will automatically promote a sufficiently healthy standby to master. Any transactions that have not been replicated to that standby remain in a "forked timeline" on the master, and are effectively unrecoverable [1]_. +In asynchronous mode the cluster is allowed to lose some committed transactions to ensure availability. When the primary server fails or becomes unavailable for any other reason Patroni will automatically promote a sufficiently healthy standby to primary. Any transactions that have not been replicated to that standby remain in a "forked timeline" on the primary, and are effectively unrecoverable [1]_. -The amount of transactions that can be lost is controlled via ``maximum_lag_on_failover`` parameter. Because master transaction log position is not sampled in real time, in reality the amount of lost data on failover is worst case bounded by ``maximum_lag_on_failover`` bytes of transaction log plus the amount that is written in the last ``ttl`` seconds (``loop_wait``/2 seconds in the average case). However typical steady state replication delay is well under a second. +The amount of transactions that can be lost is controlled via ``maximum_lag_on_failover`` parameter. Because the primary transaction log position is not sampled in real time, in reality the amount of lost data on failover is worst case bounded by ``maximum_lag_on_failover`` bytes of transaction log plus the amount that is written in the last ``ttl`` seconds (``loop_wait``/2 seconds in the average case). However typical steady state replication delay is well under a second. PostgreSQL synchronous replication ---------------------------------- @@ -29,7 +29,7 @@ To enable a simple synchronous replication test, add the follow lines to the ``p When using PostgreSQL synchronous replication, use at least three Postgres data nodes to ensure write availability if one host fails. -Using PostgreSQL synchronous replication does not guarantee zero lost transactions under all circumstances. When master and standby that is currently acting as synchronous fail simultaneously a third node that might not contain all transactions will be promoted. +Using PostgreSQL synchronous replication does not guarantee zero lost transactions under all circumstances. When the primary and the secondary that is currently acting as a synchronous replica fail simultaneously a third node that might not contain all transactions will be promoted. .. _synchronous_mode: @@ -38,9 +38,9 @@ Synchronous mode For use cases where losing committed transactions is not permissible you can turn on Patronis ``synchronous_mode``. When ``synchronous_mode`` is turned on Patroni will not promote a standby unless it is certain that the standby contains all transactions that may have returned a successful commit status to client [2]_. This means that the system may be unavailable for writes even though some servers are available. System administrators can still use manual failover commmands to promote a standby even if it results in transaction loss. -Turning on ``synchronous_mode`` does not guarantee multi node durability of commits under all circumstances. When no suitable standby is available, master server will still accept writes, but does not guarantee their replication. When the master fails in this mode no standby will be promote. When the host that used to be master comes back it will get promoted automatically, unless system administrator performed a manual failover. This behavior makes synchronous mode usable with 2 node clusters. +Turning on ``synchronous_mode`` does not guarantee multi node durability of commits under all circumstances. When no suitable standby is available, primary server will still accept writes, but does not guarantee their replication. When the primary fails in this mode no standby will be promote. When the host that used to be primary comes back it will get promoted automatically, unless system administrator performed a manual failover. This behavior makes synchronous mode usable with 2 node clusters. -When ``synchronous_mode`` is on and a standby crashes, commits will block until next iteration of Patroni runs and switches master to standalone mode (worst case delay for writes ``ttl`` seconds, average case ``loop_wait``/2 seconds). Manually shutting down or restarting a standby will not cause a commit service interruption. Standby will signal the master to release itself from synchronous standby duties before PostgreSQL shutdown is initiated. +When ``synchronous_mode`` is on and a standby crashes, commits will block until next iteration of Patroni runs and switches the primary to standalone mode (worst case delay for writes ``ttl`` seconds, average case ``loop_wait``/2 seconds). Manually shutting down or restarting a standby will not cause a commit service interruption. Standby will signal the primary to release itself from synchronous standby duties before PostgreSQL shutdown is initiated. You can ensure that a standby never becomes the synchronous standby by setting ``nosync`` tag to true. This is recommended to set for standbys that are behind slow network connections and would cause performance degradation when becoming a synchronous standby. @@ -50,7 +50,7 @@ Synchronous mode can be switched on and off via Patroni REST interface. See :ref Synchronous mode implementation ------------------------------- -When in synchronous mode Patroni maintains synchronization state in the DCS, containing the latest master and current synchronous standby. This state is updated with strict ordering constraints to ensure the following invariants: +When in synchronous mode Patroni maintains synchronization state in the DCS, containing the latest primary and current synchronous standby. This state is updated with strict ordering constraints to ensure the following invariants: - A node must be marked as the latest leader whenever it can accept write transactions. Patroni crashing or PostgreSQL not shutting down can cause violations of this invariant. @@ -63,6 +63,6 @@ Patroni will only ever assign one standby to ``synchronous_standby_names`` becau On each HA loop iteration Patroni re-evaluates synchronous standby choice. If the current synchronous standby is connected and has not requested its synchronous status to be removed it remains picked. Otherwise the cluster member avaiable for sync that is furthest ahead in replication is picked. -.. [1] The data is still there, but recovering it requires a manual recovery effort by data recovery specialists. When Patroni is allowed to rewind with ``use_pg_rewind`` the forked timeline will be automatically erased to rejoin the failed master with the cluster. +.. [1] The data is still there, but recovering it requires a manual recovery effort by data recovery specialists. When Patroni is allowed to rewind with ``use_pg_rewind`` the forked timeline will be automatically erased to rejoin the failed primary with the cluster. .. [2] Clients can change the behavior per transaction using PostgreSQL's ``synchronous_commit`` setting. Transactions with ``synchronous_commit`` values of ``off`` and ``local`` may be lost on fail over, but will not be blocked by replication delays. From 20138af37adafd319905e0e5f0044a6a1ac6b861 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Reinhard=20N=C3=A4gele?= Date: Mon, 16 Apr 2018 15:45:53 +0200 Subject: [PATCH 07/63] Link to official Helm chart (#660) Changes the link from my outdated fork to the official Helm chart which is now up to date. --- docs/kubernetes.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/kubernetes.rst b/docs/kubernetes.rst index b61634a0..fc69c8f9 100644 --- a/docs/kubernetes.rst +++ b/docs/kubernetes.rst @@ -45,7 +45,7 @@ Examples - You can find the full-featured Docker image that can use Persistent Volumes in the `Spilo Project `_. -- There is also a `Helm chart `_ +- There is also a `Helm chart `_ to deploy the Spilo image configured with Patroni running using Kubernetes. - In order to run your database clusters at scale using Patroni and Spilo, take a look at the From 311009015443626da3ce9e8b8ac6208cc01467cd Mon Sep 17 00:00:00 2001 From: Kostiantyn Nemchenko Date: Mon, 16 Apr 2018 16:46:46 +0300 Subject: [PATCH 08/63] Minor corrections to the documentation. (#654) --- docs/ENVIRONMENT.rst | 6 +++--- docs/README.rst | 2 +- docs/SETTINGS.rst | 24 ++++++++++++------------ docs/dynamic_configuration.rst | 6 +++--- docs/replica_bootstrap.rst | 2 +- docs/replication_modes.rst | 8 ++++---- docs/watchdog.rst | 2 +- 7 files changed, 25 insertions(+), 25 deletions(-) diff --git a/docs/ENVIRONMENT.rst b/docs/ENVIRONMENT.rst index 6df2ae38..a1a02148 100644 --- a/docs/ENVIRONMENT.rst +++ b/docs/ENVIRONMENT.rst @@ -31,7 +31,7 @@ Consul - **PATRONI\_CONSUL\_SCHEME**: (optional) **http** or **https**, defaults to **http** - **PATRONI\_CONSUL\_TOKEN**: (optional) ACL token - **PATRONI\_CONSUL\_VERIFY**: (optional) whether to verify the SSL certificate for HTTPS requests -- **PATRONI\_CONSUL\_CACERT**: (optional) The ca certificate. If pressent it will enable validation. +- **PATRONI\_CONSUL\_CACERT**: (optional) The ca certificate. If present it will enable validation. - **PATRONI\_CONSUL\_CERT**: (optional) File with the client certificate - **PATRONI\_CONSUL\_KEY**: (optional) File with the client key. Can be empty if the key is part of certificate. - **PATRONI\_CONSUL\_DC**: (optional) Datacenter to communicate with. By default the datacenter of the host is used. @@ -44,7 +44,7 @@ Etcd - **PATRONI\_ETCD\_URL**: url for the etcd, in format: http(s)://(username:password@)host:port - **PATRONI\_ETCD\_PROXY**: proxy url for the etcd. If you are connecting to the etcd using proxy, use this parameter instead of **PATRONI\_ETCD\_URL** - **PATRONI\_ETCD\_SRV**: Domain to search the SRV record(s) for cluster autodiscovery. -- **PATRONI\_ETCD\_CACERT**: The ca certificate. If pressent it will enable validation. +- **PATRONI\_ETCD\_CACERT**: The ca certificate. If present it will enable validation. - **PATRONI\_ETCD\_CERT**: File with the client certificate - **PATRONI\_ETCD\_KEY**: File with the client key. Can be empty if the key is part of certificate. @@ -63,7 +63,7 @@ Kubernetes - **PATRONI\_KUBERNETES\_ROLE\_LABEL**: (optional) name of the label containing Postgres role (`master` or `replica`). Patroni will set this label on the pod it is running in. Default value is `role`. - **PATRONI\_KUBERNETES\_USE\_ENDPOINTS**: (optional) if set to true, Patroni will use Endpoints instead of ConfigMaps to run leader elections and keep cluster state. - **PATRONI\_KUBERNETES\_POD\_IP**: (optional) IP address of the pod Patroni is running in. This value is required when `PATRONI_KUBERNETES_USE_ENDPOINTS` is enabled and is used to populate the leader endpoint subsets when the pod's PostgreSQL is promoted. -- **PATRONI\_KUBERNETES\_PORTS**: (optional) if the Service object has the name for the port, the same name must appear in the Endpoint object, otherwise service wont work. For example, if your service is defined as ``{Kind: Service, spec: {ports: [{name: postgresql, port: 5432, targetPort: 5432}]}}``, then you have to set ``PATRONI_KUBERNETES_PORTS='{[{"name": "postgresql", "port": 5432}]}'`` and Patroni will use it for updating subsets of the leader Endpoint. This parameter is used only if `PATRONI_KUBERNETES_USE_ENDPOINTS` is set. +- **PATRONI\_KUBERNETES\_PORTS**: (optional) if the Service object has the name for the port, the same name must appear in the Endpoint object, otherwise service won't work. For example, if your service is defined as ``{Kind: Service, spec: {ports: [{name: postgresql, port: 5432, targetPort: 5432}]}}``, then you have to set ``PATRONI_KUBERNETES_PORTS='{[{"name": "postgresql", "port": 5432}]}'`` and Patroni will use it for updating subsets of the leader Endpoint. This parameter is used only if `PATRONI_KUBERNETES_USE_ENDPOINTS` is set. PostgreSQL ---------- diff --git a/docs/README.rst b/docs/README.rst index bd75c168..33efb487 100644 --- a/docs/README.rst +++ b/docs/README.rst @@ -62,7 +62,7 @@ For example, the command in order to install Patroni together with dependencies pip install patroni[etcd,aws] -Note that external tools to call in the replica creation or custom bootstap scripts (i.e. WAL-E) should be installed +Note that external tools to call in the replica creation or custom bootstrap scripts (i.e. WAL-E) should be installed independently of Patroni. diff --git a/docs/SETTINGS.rst b/docs/SETTINGS.rst index e4412d86..009f1357 100644 --- a/docs/SETTINGS.rst +++ b/docs/SETTINGS.rst @@ -18,13 +18,13 @@ Bootstrap configuration - **retry\_timeout**: timeout for DCS and PostgreSQL operation retries. DCS or network issues shorter than this will not cause Patroni to demote the leader. Default value: 10 - **maximum\_lag\_on\_failover**: the maximum bytes a follower may lag to be able to participate in leader election. - **master\_start\_timeout**: the amount of time a master is allowed to recover from failures before failover is triggered. Default is 300 seconds. When set to 0 failover is done immediately after a crash is detected if possible. When using asynchronous replication a failover can cause lost transactions. Best worst case failover time for master failure is: loop\_wait + master\_start\_timeout + loop\_wait, unless master\_start\_timeout is zero, in which case it's just loop\_wait. Set the value according to your durability/availability tradeoff. - - **synchronous\_mode**: turns on synchronous replication mode. In this mode a replica will be chosen as synchronous and only the latest leader and synchronous replica are able to participate in leader election. Synchronous mode makes sure that succesfully committed transactions will not be lost at failover, at the cost of losing availability for writes when Patroni cannot ensure transaction durability. See `replication modes documentation `__ for details. + - **synchronous\_mode**: turns on synchronous replication mode. In this mode a replica will be chosen as synchronous and only the latest leader and synchronous replica are able to participate in leader election. Synchronous mode makes sure that successfully committed transactions will not be lost at failover, at the cost of losing availability for writes when Patroni cannot ensure transaction durability. See :ref:`replication modes documentation ` for details. - **postgresql**: - - **use\_pg\_rewind**:whether or not to use pg_rewind + - **use\_pg\_rewind**: whether or not to use pg_rewind - **use\_slots**: whether or not to use replication_slots. Must be False for PostgreSQL 9.3. You should comment out max_replication_slots before it becomes ineligible for leader status. - **recovery\_conf**: additional configuration settings written to recovery.conf when configuring follower. - **parameters**: list of configuration settings for Postgres. Many of these are required for replication to work. -- **method**: custom script to use for bootstrpapping this cluster. +- **method**: custom script to use for bootstrapping this cluster. See :ref:`custom bootstrap methods documentation ` for details. When ``initdb`` is specified revert to the default ``initdb`` command. ``initdb`` is also triggered when no ``method`` parameter is present in the configuration file. @@ -35,7 +35,7 @@ Bootstrap configuration - **pg\_hba**: list of lines that you should add to pg\_hba.conf. - **- host all all 0.0.0.0/0 md5**. - **- host replication replicator 127.0.0.1/32 md5**: A line like this is required for replication. -- **users**: Some additional users users which needs to be created after initializing new cluster +- **users**: Some additional users which need to be created after initializing new cluster - **admin**: the name of user - **password: zalando**: - **options**: list of options for CREATE USER statement @@ -54,8 +54,8 @@ Most of the parameters are optional, but you have to specify one of the **host** - **port**: (optional) Consul port - **scheme**: (optional) **http** or **https**, defaults to **http** - **token**: (optional) ACL token -- **verify** (optional) whether to verify the SSL certificate for HTTPS requests -- **cacert**: (optional) The ca certificate. If pressent it will enable validation. +- **verify**: (optional) whether to verify the SSL certificate for HTTPS requests +- **cacert**: (optional) The ca certificate. If present it will enable validation. - **cert**: (optional) file with the client certificate - **key**: (optional) file with the client key. Can be empty if the key is part of **cert**. - **dc**: (optional) Datacenter to communicate with. By default the datacenter of the host is used. @@ -73,7 +73,7 @@ Most of the parameters are optional, but you have to specify one of the **host** - **protocol**: (optional) http or https, if not specified http is used. If the **url** or **proxy** is specified - will take protocol from them. - **username**: (optional) username for etcd authentication - **password**: (optional) password for etcd authentication. -- **cacert**: (optional) The ca certificate. If pressent it will enable validation. +- **cacert**: (optional) The ca certificate. If present it will enable validation. - **cert**: (optional) file with the client certificate - **key**: (optional) file with the client key. Can be empty if the key is part of **cert**. @@ -93,7 +93,7 @@ Kubernetes - **role\_label**: (optional) name of the label containing role (master or replica). Patroni will set this label on the pod it runs in. Default value is ``role``. - **use\_endpoints**: (optional) if set to true, Patroni will use Endpoints instead of ConfigMaps to run leader elections and keep cluster state. - **pod\_ip**: (optional) IP address of the pod Patroni is running in. This value is required when `use_endpoints` is enabled and is used to populate the leader endpoint subsets when the pod's PostgreSQL is promoted. -- **ports**: (optional) if the Service object has the name for the port, the same name must appear in the Endpoint object, otherwise service wont work. For example, if your service is defined as ``{Kind: Service, spec: {ports: [{name: postgresql, port: 5432, targetPort: 5432}]}}``, then you have to set ``kubernetes.ports: {[{"name": "postgresql", "port": 5432}]}`` and Patroni will use it for updating subsets of the leader Endpoint. This parameter is used only if `kubernetes.use_endpoints` is set. +- **ports**: (optional) if the Service object has the name for the port, the same name must appear in the Endpoint object, otherwise service won't work. For example, if your service is defined as ``{Kind: Service, spec: {ports: [{name: postgresql, port: 5432, targetPort: 5432}]}}``, then you have to set ``kubernetes.ports: {[{"name": "postgresql", "port": 5432}]}`` and Patroni will use it for updating subsets of the leader Endpoint. This parameter is used only if `kubernetes.use_endpoints` is set. .. _postgresql_settings: @@ -118,12 +118,12 @@ PostgreSQL own config item. See :ref:`custom replica creation methods documentation ` for further explanation. - **data\_dir**: The location of the Postgres data directory, either existing or to be initialized by Patroni. - **config\_dir**: The location of the Postgres configuration directory, defaults to the data directory. Must be writable by Patroni. -- **bin\_dir**: Path to PostgreSQL binaries. (pg_ctl, pg_rewind, pg_basebackup, postgres) The default value is an empty string meaning that PATH environment variable will be used to find the executables. +- **bin\_dir**: Path to PostgreSQL binaries (pg_ctl, pg_rewind, pg_basebackup, postgres). The default value is an empty string meaning that PATH environment variable will be used to find the executables. - **listen**: IP address + port that Postgres listens to; must be accessible from other nodes in the cluster, if you're using streaming replication. Multiple comma-separated addresses are permitted, as long as the port component is appended after to the last one with a colon, i.e. ``listen: 127.0.0.1,127.0.0.2:5432``. Patroni will use the first address from this list to establish local connections to the PostgreSQL node. - **use\_unix\_socket**: specifies that Patroni should prefer to use unix sockets to connect to the cluster. Default value is ``false``. If ``unix_socket_directories`` is definded, Patroni will use first suitable value from it to connect to the cluster and fallback to tcp if nothing is suitable. If ``unix_socket_directories`` is not specified in ``postgresql.parameters``, Patroni will assume that default value should be used and omit ``host`` from connection parameters. - **pgpass**: path to the `.pgpass `__ password file. Patroni creates this file before executing pg\_basebackup, the post_init script and under some other circumstances. The location must be writable by Patroni. - **recovery\_conf**: additional configuration settings written to recovery.conf when configuring follower. -- **custom\_conf** : path to an optional custom ``postgresql.conf`` file, that will be used in place of ``postgresql.base.conf``. The file must exist on all cluster nodes, be readable by PostgreSQL and will be included from its location on the real ``postgresql.conf``. Note that Patroni will not monitor this file for changes, nor backup it. However, its settings can still be overriden by Patroni's own configuration facilities - see `dynamic configuration `__ for details. +- **custom\_conf** : path to an optional custom ``postgresql.conf`` file, that will be used in place of ``postgresql.base.conf``. The file must exist on all cluster nodes, be readable by PostgreSQL and will be included from its location on the real ``postgresql.conf``. Note that Patroni will not monitor this file for changes, nor backup it. However, its settings can still be overridden by Patroni's own configuration facilities - see :ref:`dynamic configuration ` for details. - **parameters**: list of configuration settings for Postgres. Many of these are required for replication to work. - **pg\_hba**: list of lines that Patroni will use to generate ``pg_hba.conf``. This parameter has higher priority than ``bootstrap.pg_hba``. Together with :ref:`dynamic configuration ` it simplifies management of ``pg_hba.conf``. - **- host all all 0.0.0.0/0 md5**. @@ -131,7 +131,7 @@ PostgreSQL - **pg\_ctl\_timeout**: How long should pg_ctl wait when doing ``start``, ``stop`` or ``restart``. Default value is 60 seconds. - **use\_pg\_rewind**: try to use pg\_rewind on the former leader when it joins cluster as a replica. - **remove\_data\_directory\_on\_rewind\_failure**: If this option is enabled, Patroni will remove postgres data directory and recreate replica. Otherwise it will try to follow the new leader. Default value is **false**. -- **replica\_method** for each create_replica_method other than basebackup, you would add a configuration section of the same name. At a minimum, this should include "command" with a full path to the actual script to be executed. Other configuration parameters will be passed along to the script in the form "parameter=value". +- **replica\_method**: for each create_replica_method other than basebackup, you would add a configuration section of the same name. At a minimum, this should include "command" with a full path to the actual script to be executed. Other configuration parameters will be passed along to the script in the form "parameter=value". REST API -------- @@ -151,6 +151,6 @@ ZooKeeper Watchdog -------- -- **mode**: ``off``, ``automatic`` or ``required``. When ``off`` watchdog is disabled. When ``automatic`` watchdog will be used if available, but ignored if it is not. When ``required`` the node will not become a leader unless watchdog can be succesfully enabled. +- **mode**: ``off``, ``automatic`` or ``required``. When ``off`` watchdog is disabled. When ``automatic`` watchdog will be used if available, but ignored if it is not. When ``required`` the node will not become a leader unless watchdog can be successfully enabled. - **device**: Path to watchdog device. Defaults to ``/dev/watchdog``. - **safety_margin**: Number of seconds of safety margin between watchdog triggering and leader key expiration. diff --git a/docs/dynamic_configuration.rst b/docs/dynamic_configuration.rst index 07cdb981..17ef8496 100644 --- a/docs/dynamic_configuration.rst +++ b/docs/dynamic_configuration.rst @@ -16,9 +16,9 @@ Patroni configuration is stored in the DCS (Distributed Configuration Store). Th These options are defined in the configuration file and take precedence over dynamic configuration. patroni.yml could be changed and reload in runtime (without restart of Patroni) by sending SIGHUP to the Patroni process or by performing ``POST /reload`` REST-API request. -- Environment :ref:`configuration ` . +- Environment :ref:`configuration `. It is possible to set/override some of the "Local" configuration parameters with environment variables. - Environment configuration is very useful when you are running in a dynamic environment and you don't know some of the parameters in advance (for example it's not possible to know you external IP address when you are running inside ``docker``). + Environment configuration is very useful when you are running in a dynamic environment and you don't know some of the parameters in advance (for example it's not possible to know your external IP address when you are running inside ``docker``). Some of the PostgreSQL parameters must hold the same values on the master and the replicas. For those, values set either in the local patroni configuration files or via the environment variables take no effect. To alter or set their values one must change the shared configuration in the DCS. Below is the actual list of such parameters together with the default values: @@ -42,7 +42,7 @@ There are some other Postgres parameters controlled by Patroni: - listen_addresses - is set either from ``postgresql.listen`` or from ``PATRONI_POSTGRESQL_LISTEN`` environment variable - port - is set either from ``postgresql.listen`` or from ``PATRONI_POSTGRESQL_LISTEN`` environment variable -- cluster_name - is set either from ``scope`` or from ``PATRRONI_SCOPE`` environment variable +- cluster_name - is set either from ``scope`` or from ``PATRONI_SCOPE`` environment variable - hot_standby: on To be on the safe side parameters from the above lists are not written into ``postgresql.conf``, but passed as a list of arguments to the ``pg_ctl start`` which gives them the highest precedence, even above `ALTER SYSTEM `__ diff --git a/docs/replica_bootstrap.rst b/docs/replica_bootstrap.rst index 2d1da113..233c2c5b 100644 --- a/docs/replica_bootstrap.rst +++ b/docs/replica_bootstrap.rst @@ -3,7 +3,7 @@ Replica imaging and bootstrap Patroni allows customizing creation of a new replica. It also supports defining what happens when the new empty cluster is being bootstrapped. The distinction between two is well defined: Patroni creates replicas only if the ``initialize`` -key is present in Etcd for the cluster. If there is no ``initialize`` key - Patroni calls bootstrap exclusively on the +key is present in DCS for the cluster. If there is no ``initialize`` key - Patroni calls bootstrap exclusively on the first node that takes the initialize key lock. .. _custom_bootstrap: diff --git a/docs/replication_modes.rst b/docs/replication_modes.rst index ea404628..b7d12cda 100644 --- a/docs/replication_modes.rst +++ b/docs/replication_modes.rst @@ -20,7 +20,7 @@ You can use Postgres's `synchronous replication Date: Mon, 16 Apr 2018 17:32:26 +0200 Subject: [PATCH 09/63] Abort start if attaching to running postgres and cluster not initiazlied (#661) Patroni can attach itself to an already running PostgreSQL instance. If that is the first instance "seen" in the given cluster, Patroni for that instance will create the initialize key, grab the leader key and, if the instance is running a replica, promote. Because of this behavior, when a cluster with a master and one or more replicas gets Patroni for each node, it is imperative to start running Patroni on the master node before getting to the replicas. This commit changes such weird behavior and will abort Patroni start if there is no initialize key in DCS and postgres is running as a replica. Closes https://github.com/zalando/patroni/issues/655 --- patroni/ha.py | 12 +++++++++++- tests/test_ha.py | 28 ++++++++++++++++++++-------- 2 files changed, 31 insertions(+), 9 deletions(-) diff --git a/patroni/ha.py b/patroni/ha.py index e4f84b8f..e5058579 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -72,6 +72,10 @@ class Ha(object): # standby. Changes protected by _member_state_lock. self._disable_sync = 0 + # We need following property to avoid shutdown of postgres when join of Patroni to the postgres + # already running as replica was aborted due to cluster not beeing initialized in DCS. + self._join_aborted = False + def is_paused(self): return self.cluster and self.cluster.is_paused() @@ -1079,6 +1083,12 @@ class Ha(object): return self.bootstrap() # new node # "bootstrap", but data directory is not empty elif not self.sysid_valid(self.cluster.initialize) and self.cluster.is_unlocked() and not self.is_paused(): + if not self.state_handler.cb_called and self.state_handler.is_running() \ + and not self.state_handler.is_leader(): + self._join_aborted = True + logger.error('No initialize key in DCS and PostgreSQL is running as replica, aborting start') + logger.error('Please first start Patroni on the node running as master') + sys.exit(1) self.dcs.initialize(create_new=(self.cluster.initialize is None), sysid=self.state_handler.sysid) else: # check if we are allowed to join @@ -1138,7 +1148,7 @@ class Ha(object): if self.is_paused(): logger.info('Leader key is not deleted and Postgresql is not stopped due paused state') self.watchdog.disable() - else: + elif not self._join_aborted: # FIXME: If stop doesn't reach safepoint quickly enough keepalive is triggered. If shutdown checkpoint # takes longer than ttl, then leader key is lost and replication might not have sent out all xlog. # This might not be the desired behavior of users, as a graceful shutdown of the host can mean lost data. diff --git a/tests/test_ha.py b/tests/test_ha.py index 2312ddbe..bdd2ff9f 100644 --- a/tests/test_ha.py +++ b/tests/test_ha.py @@ -16,6 +16,9 @@ from test_etcd import socket_getaddrinfo, etcd_read, etcd_write, requests_get from test_postgresql import psycopg2_connect, MockPostmaster +SYSID = '12345678901' + + def true(*args, **kwargs): return True @@ -45,7 +48,7 @@ def get_cluster_initialized_without_leader(leader=False, failover=None, sync=Non 'scheduled_restart': {'schedule': "2100-01-01 10:53:07.560445+00:00", 'postgres_version': '99.0.0'}}) syncstate = SyncState(0 if sync else None, sync and sync[0], sync and sync[1]) - return get_cluster(True, leader, [m1, m2], failover, syncstate) + return get_cluster(SYSID, leader, [m1, m2], failover, syncstate) def get_cluster_initialized_with_leader(failover=None, sync=None): @@ -120,7 +123,7 @@ def run_async(self, func, args=()): @patch.object(Postgresql, '_cluster_info_state_get', Mock(return_value=3)) @patch.object(Postgresql, 'call_nowait', Mock(return_value=True)) @patch.object(Postgresql, 'data_directory_empty', Mock(return_value=False)) -@patch.object(Postgresql, 'controldata', Mock(return_value={'Database system identifier': '1234567890'})) +@patch.object(Postgresql, 'controldata', Mock(return_value={'Database system identifier': SYSID})) @patch.object(Postgresql, 'sync_replication_slots', Mock()) @patch.object(Postgresql, 'write_pg_hba', Mock()) @patch.object(Postgresql, 'write_pgpass', Mock(return_value={})) @@ -161,7 +164,7 @@ class TestHa(unittest.TestCase): 'name': 'foo', 'retry_timeout': 10}}) self.ha = Ha(MockPatroni(self.p, self.e)) self.ha.old_cluster = self.e.get_cluster() - self.ha.cluster = get_cluster_not_initialized_without_leader() + self.ha.cluster = get_cluster_initialized_without_leader() self.ha.load_cluster_from_dcs = Mock() def test_update_lock(self): @@ -178,7 +181,7 @@ class TestHa(unittest.TestCase): self.assertEquals(self.ha.run_cycle(), 'starting as a secondary') def test_recover_replica_failed(self): - self.p.controldata = lambda: {'Database cluster state': 'in recovery'} + self.p.controldata = lambda: {'Database cluster state': 'in recovery', 'Database system identifier': SYSID} self.p.is_running = false self.p.follow = false self.assertEquals(self.ha.run_cycle(), 'starting as a secondary') @@ -189,14 +192,14 @@ class TestHa(unittest.TestCase): self.p.is_running = false self.p.name = 'leader' self.p.set_role('master') - self.p.controldata = lambda: {'Database cluster state': 'shut down'} + self.p.controldata = lambda: {'Database cluster state': 'shut down', 'Database system identifier': SYSID} self.ha.cluster = get_cluster_initialized_with_leader() self.assertEquals(self.ha.run_cycle(), 'starting as readonly because i had the session lock') @patch.object(Postgresql, 'fix_cluster_state', Mock()) def test_crash_recovery(self): self.p.is_running = false - self.p.controldata = lambda: {'Database cluster state': 'in production'} + self.p.controldata = lambda: {'Database cluster state': 'in production', 'Database system identifier': SYSID} self.assertEquals(self.ha.run_cycle(), 'doing crash recovery in a single user mode') @patch.object(Postgresql, 'rewind_needed_and_possible', Mock(return_value=True)) @@ -208,7 +211,7 @@ class TestHa(unittest.TestCase): @patch.object(Postgresql, 'can_rewind', PropertyMock(return_value=True)) @patch.object(Postgresql, 'fix_cluster_state', Mock()) def test_single_user_after_recover_failed(self): - self.p.controldata = lambda: {'Database cluster state': 'in recovery'} + self.p.controldata = lambda: {'Database cluster state': 'in recovery', 'Database system identifier': SYSID} self.p.is_running = false self.p.follow = false self.assertEquals(self.ha.run_cycle(), 'starting as a secondary') @@ -217,6 +220,7 @@ class TestHa(unittest.TestCase): @patch('sys.exit', return_value=1) @patch('patroni.ha.Ha.sysid_valid', MagicMock(return_value=True)) def test_sysid_no_match(self, exit_mock): + self.p.controldata = lambda: {'Database cluster state': 'in recovery', 'Database system identifier': '123'} self.ha.run_cycle() exit_mock.assert_called_once_with(1) @@ -225,7 +229,7 @@ class TestHa(unittest.TestCase): self.p.is_leader = false self.p.is_healthy = true self.ha.has_lock = true - self.p.controldata = lambda: {'Database cluster state': 'in production'} + self.p.controldata = lambda: {'Database cluster state': 'in production', 'Database system identifier': SYSID} self.assertEquals(self.ha.run_cycle(), 'promoted self to leader because i had the session lock') @patch('psycopg2.connect', psycopg2_connect) @@ -279,6 +283,7 @@ class TestHa(unittest.TestCase): self.assertEquals(self.ha.run_cycle(), 'Not promoting self because watchdog could not be activated') def test_leader_with_lock(self): + self.ha.cluster = get_cluster_not_initialized_without_leader() self.ha.cluster.is_unlocked = false self.ha.has_lock = true self.assertEquals(self.ha.run_cycle(), 'no action. i am the leader with the lock') @@ -896,3 +901,10 @@ class TestHa(unittest.TestCase): self.ha.has_lock = true self.ha.cluster.is_unlocked = false self.assertEquals(self.ha.run_cycle(), 'no action. i am the leader with the lock') + + @patch('sys.exit', return_value=1) + def test_abort_join(self, exit_mock): + self.ha.cluster = get_cluster_not_initialized_without_leader() + self.p.is_leader = false + self.ha.run_cycle() + exit_mock.assert_called_once_with(1) From 84f29caf925ac33bc9120e9d8d8c5f33018b305d Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Mon, 16 Apr 2018 17:45:05 +0200 Subject: [PATCH 10/63] Fix race condition in poll_failover_result (#658) It didn't affect directly neither failover nor switchover, but in some rare cases it was reporting it as a success too early, when the former leader released the lock: `Failed over to "None" instead of "desired-node"` In addition to that this commit improves logs and status messages by differentiating between failover and switchover. --- patroni/api.py | 18 ++++++++++-------- tests/test_api.py | 1 + 2 files changed, 11 insertions(+), 8 deletions(-) diff --git a/patroni/api.py b/patroni/api.py index 865de459..4b7d835b 100644 --- a/patroni/api.py +++ b/patroni/api.py @@ -295,22 +295,23 @@ class RestApiHandler(BaseHTTPRequestHandler): status_code = 503 self._write_response(status_code, data) - def poll_failover_result(self, leader, candidate): + def poll_failover_result(self, leader, candidate, action): timeout = max(10, self.server.patroni.dcs.loop_wait) for _ in range(0, timeout*2): time.sleep(1) try: cluster = self.server.patroni.dcs.get_cluster() - if cluster.leader and cluster.leader.name != leader: + if not cluster.is_unlocked() and cluster.leader.name != leader: if not candidate or candidate == cluster.leader.name: - return 200, 'Successfully failed over to "{0}"'.format(cluster.leader.name) + return 200, 'Successfully {0}ed over to "{1}"'.format(action[:-4], cluster.leader.name) else: - return 200, 'Failed over to "{0}" instead of "{1}"'.format(cluster.leader.name, candidate) + return 200, '{0}ed over to "{1}" instead of "{2}"'.format(action[:-4].title(), + cluster.leader.name, candidate) if not cluster.failover: - return 503, 'Failover failed' + return 503, action.title() + ' failed' except Exception as e: - logger.debug('Exception occured during polling failover result: %s', e) - return 503, 'Failover status unknown' + logger.debug('Exception occured during polling %s result: %s', action, e) + return 503, action.title() + ' status unknown' def is_failover_possible(self, cluster, leader, candidate, action): if leader and (not cluster.leader or cluster.leader.name != leader): @@ -377,7 +378,8 @@ class RestApiHandler(BaseHTTPRequestHandler): data = action.title() + ' scheduled' status_code = 202 else: - status_code, data = self.poll_failover_result(cluster.leader and cluster.leader.name, candidate) + status_code, data = self.poll_failover_result(cluster.leader and cluster.leader.name, + candidate, action) else: data = 'failed to write {0} key into DCS'.format(action) status_code = 503 diff --git a/tests/test_api.py b/tests/test_api.py index 1da83d7d..d4f0d97f 100644 --- a/tests/test_api.py +++ b/tests/test_api.py @@ -339,6 +339,7 @@ class TestRestApiHandler(unittest.TestCase): cluster2 = cluster.copy() cluster2.leader.name = 'postgresql0' + cluster2.is_unlocked.return_value = False dcs.get_cluster.side_effect = [cluster, cluster2] MockRestApiServer(RestApiHandler, request) From 3eeb4ed97922ff1535ffabc49d5a7c35248bfdf8 Mon Sep 17 00:00:00 2001 From: Cody Coons Date: Thu, 26 Apr 2018 10:38:19 -0400 Subject: [PATCH 11/63] Added check for empty subsets (#670) On Kubernetes 1.10.0 I experienced an issue where calls to `patch_or_create` were failing when bootstraping a cluster. The call was failing because `self._leader_observed_subsets` was `None` instead of `[]`. --- patroni/dcs/kubernetes.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/patroni/dcs/kubernetes.py b/patroni/dcs/kubernetes.py index b04f5717..842ec5ea 100644 --- a/patroni/dcs/kubernetes.py +++ b/patroni/dcs/kubernetes.py @@ -161,7 +161,7 @@ class Kubernetes(AbstractDCS): leader = nodes.get(self.leader_path) metadata = leader and leader.metadata self._leader_resource_version = metadata.resource_version if metadata else None - self._leader_observed_subsets = leader.subsets if self.__subsets and leader else [] + self._leader_observed_subsets = leader.subsets if self.__subsets and leader and leader.subsets else [] annotations = metadata and metadata.annotations or {} # get last leader operation From 5296336f4a9bdb38d29dce107d19a67639fb18fe Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Fri, 18 May 2018 11:18:27 +0200 Subject: [PATCH 12/63] BUGFIX: postmaster start can fail if pid from postmaster.pid is alive (#681) Upon start postmaster process performs various safety checks if there is a postmaster.pid file in the data directory. Although Patroni already detected that the running process corresponding to the postmaster.pid is not a postmaster, the new postmaster might fail to start, because it thinks that postmaster.pid is already locked. Important!!! Unlink of postmaster.pid isn't an option in this case, because it has a lot of nasty race conditions. Luckily there is a workaround to this problem, we can pass the pid from postmaster.pid in the `PG_GRANDPARENT_PID` environment variable and postmaster will ignore it. More likely to hit such problem if you run Patroni and postgres in the docker container. --- patroni/postgresql.py | 15 +------- patroni/postmaster.py | 82 +++++++++++++++++++++++++++++----------- tests/test_postgresql.py | 10 ----- tests/test_postmaster.py | 50 ++++++++++++++++-------- 4 files changed, 95 insertions(+), 62 deletions(-) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index b52b7068..f31e4828 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -141,7 +141,6 @@ class Postgresql(object): self._postgresql_base_conf = os.path.join(self._config_dir, self._postgresql_base_conf_name) self._pg_hba_conf = os.path.join(self._config_dir, 'pg_hba.conf') self._recovery_conf = os.path.join(self._data_dir, 'recovery.conf') - self._postmaster_pid = os.path.join(self._data_dir, 'postmaster.pid') self._trigger_file = config.get('recovery_conf', {}).get('trigger_file') or 'promote' self._trigger_file = os.path.abspath(os.path.join(self._data_dir, self._trigger_file)) @@ -732,21 +731,9 @@ class Postgresql(object): return self._postmaster_proc self._postmaster_proc = None - self._postmaster_proc = PostmasterProcess.from_pidfile(self._read_pid_file()) + self._postmaster_proc = PostmasterProcess.from_pidfile(self._data_dir) return self._postmaster_proc - def _read_pid_file(self): - """Reads and parses postmaster.pid from the data directory - - :returns dictionary of values if successful, empty dictionary otherwise - """ - pid_line_names = ['pid', 'data_dir', 'start_time', 'port', 'socket_dir', 'listen_addr', 'shmem_key'] - try: - with open(self._postmaster_pid) as f: - return {name: line.rstrip("\n") for name, line in zip(pid_line_names, f)} - except IOError: - return {} - @property def cb_called(self): return self.__cb_called diff --git a/patroni/postmaster.py b/patroni/postmaster.py index aaec2d44..aa5f3050 100644 --- a/patroni/postmaster.py +++ b/patroni/postmaster.py @@ -17,6 +17,7 @@ STOP_SIGNALS = { class PostmasterProcess(psutil.Process): + def __init__(self, pid): self.is_single_user = False if pid < 0: @@ -24,32 +25,55 @@ class PostmasterProcess(psutil.Process): self.is_single_user = True super(PostmasterProcess, self).__init__(pid) - @classmethod - def from_pidfile(cls, pidfile): - try: - pid = int(pidfile.get('pid', 0)) - if not pid: - return None - except ValueError: - return None + @staticmethod + def _read_postmaster_pidfile(data_dir): + """Reads and parses postmaster.pid from the data directory + :returns dictionary of values if successful, empty dictionary otherwise + """ + pid_line_names = ['pid', 'data_dir', 'start_time', 'port', 'socket_dir', 'listen_addr', 'shmem_key'] try: - proc = cls(pid) - except psutil.NoSuchProcess: - return None + with open(os.path.join(data_dir, 'postmaster.pid')) as f: + return {name: line.rstrip('\n') for name, line in zip(pid_line_names, f)} + except IOError: + return {} + def _is_postmaster_process(self): try: - start_time = int(pidfile.get('start_time', 0)) - if start_time and abs(proc.create_time() - start_time) > 3: - return None + start_time = int(self._postmaster_pid.get('start_time', 0)) + if start_time and abs(self.create_time() - start_time) > 3: + logger.info('Too much difference between %s and %s', self.create_time(), start_time) + return False except ValueError: - logger.warning("Garbage start time value in pid file: %r", pidfile.get('start_time')) + logger.warning('Garbage start time value in pid file: %r', self._postmaster_pid.get('start_time')) # Extra safety check. The process can't be ourselves, our parent or our direct child. - if proc.pid == os.getpid() or proc.pid == os.getppid() or proc.parent() == os.getpid(): - return None + if self.pid == os.getpid() or self.pid == os.getppid() or self.ppid() == os.getpid(): + logger.info('Patroni (pid=%s, ppid=%s), "fake postmaster" (pid=%s, ppid=%s)', + os.getpid(), os.getppid(), self.pid, self.ppid()) + return False - return proc + return True + + @classmethod + def _from_pidfile(cls, data_dir): + postmaster_pid = PostmasterProcess._read_postmaster_pidfile(data_dir) + try: + pid = int(postmaster_pid.get('pid', 0)) + if pid: + proc = cls(pid) + proc._postmaster_pid = postmaster_pid + return proc + except ValueError: + pass + + @staticmethod + def from_pidfile(data_dir): + try: + proc = PostmasterProcess._from_pidfile(data_dir) + return proc if proc and proc._is_postmaster_process() else None + except psutil.NoSuchProcess: + return None @classmethod def from_pid(cls, pid): @@ -100,8 +124,8 @@ class PostmasterProcess(psutil.Process): except psutil.Error: logger.exception('wait_for_user_backends_to_close') - @classmethod - def start(cls, pgcommand, data_dir, conf, options): + @staticmethod + def start(pgcommand, data_dir, conf, options): # Unfortunately `pg_ctl start` does not return postmaster pid to us. Without this information # it is hard to know the current state of postgres startup, so we had to reimplement pg_ctl start # in python. It will start postgres, wait for port to be open and wait until postgres will start @@ -113,10 +137,24 @@ class PostmasterProcess(psutil.Process): # of init process to take care about postmaster. # In order to make everything portable we can't use fork&exec approach here, so we will call # ourselves and pass list of arguments which must be used to start postgres. + env = {p: os.environ[p] for p in ('PATH', 'LC_ALL', 'LANG') if p in os.environ} + try: + proc = PostmasterProcess._from_pidfile(data_dir) + if proc and not proc._is_postmaster_process(): + # Upon start postmaster process performs various safety checks if there is a postmaster.pid + # file in the data directory. Although Patroni already detected that the running process + # corresponding to the postmaster.pid is not a postmaster, the new postmaster might fail + # to start, because it thinks that postmaster.pid is already locked. + # Important!!! Unlink of postmaster.pid isn't an option, because it has a lot of nasty race conditions. + # Luckily there is a workaround to this problem, we can pass the pid from postmaster.pid + # in the `PG_GRANDPARENT_PID` environment variable and postmaster will ignore it. + env['PG_GRANDPARENT_PID'] = str(proc.pid) + except psutil.NoSuchProcess: + pass + proc = call_self(['pg_ctl_start', pgcommand, '-D', data_dir, '--config-file={}'.format(conf)] + options, close_fds=True, - preexec_fn=os.setsid, stdout=subprocess.PIPE, - env={p: os.environ[p] for p in ('PATH', 'LC_ALL', 'LANG') if p in os.environ}) + preexec_fn=os.setsid, stdout=subprocess.PIPE, env=env) pid = int(proc.stdout.readline().strip()) proc.wait() logger.info('postmaster pid=%s', pid) diff --git a/tests/test_postgresql.py b/tests/test_postgresql.py index e6d5a079..b6f4d2d5 100644 --- a/tests/test_postgresql.py +++ b/tests/test_postgresql.py @@ -808,16 +808,6 @@ class TestPostgresql(unittest.TestCase): self.p._state = 'starting' self.assertIsNone(self.p.wait_for_startup()) - def test_read_pid_file(self): - pidfile = os.path.join(self.data_dir, 'postmaster.pid') - if os.path.exists(pidfile): - os.remove(pidfile) - self.assertEquals(self.p._read_pid_file(), {}) - with open(pidfile, 'w') as fd: - fd.write("123\n/foo/bar\n123456789\n5432") - self.assertEquals(self.p._read_pid_file(), {"pid": "123", "data_dir": "/foo/bar", - "start_time": "123456789", "port": "5432"}) - def test_pick_sync_standby(self): cluster = Cluster(True, None, self.leader, 0, [self.me, self.other, self.leadermem], None, SyncState(0, self.me.name, self.leadermem.name), None) diff --git a/tests/test_postmaster.py b/tests/test_postmaster.py index 342f17af..c0aaaa78 100644 --- a/tests/test_postmaster.py +++ b/tests/test_postmaster.py @@ -1,8 +1,9 @@ +import psutil import unittest -from mock import Mock, patch +from mock import Mock, patch, mock_open from patroni.postmaster import PostmasterProcess -import psutil +from six.moves import builtins class TestPostmasterProcess(unittest.TestCase): @@ -13,26 +14,34 @@ class TestPostmasterProcess(unittest.TestCase): @patch('psutil.Process.create_time') @patch('psutil.Process.__init__') - def test_from_pidfile(self, mock_init, mock_create_time): + @patch('patroni.postmaster.PostmasterProcess._read_postmaster_pidfile') + def test_from_pidfile(self, mock_read, mock_init, mock_create_time): mock_init.side_effect = psutil.NoSuchProcess(123) - self.assertEquals(PostmasterProcess.from_pidfile({}), None) - self.assertEquals(PostmasterProcess.from_pidfile({"pid": "foo"}), None) - self.assertEquals(PostmasterProcess.from_pidfile({"pid": "123"}), None) + mock_read.return_value = {} + self.assertIsNone(PostmasterProcess.from_pidfile('')) + mock_read.return_value = {"pid": "foo"} + self.assertIsNone(PostmasterProcess.from_pidfile('')) + mock_read.return_value = {"pid": "123"} + self.assertIsNone(PostmasterProcess.from_pidfile('')) mock_init.side_effect = None with patch.object(psutil.Process, 'pid', 123), \ - patch.object(psutil.Process, 'parent', return_value=124), \ + patch.object(psutil.Process, 'ppid', return_value=124), \ patch('os.getpid', return_value=125) as mock_ospid, \ patch('os.getppid', return_value=126): - self.assertNotEquals(PostmasterProcess.from_pidfile({"pid": "123"}), None) + self.assertIsNotNone(PostmasterProcess.from_pidfile('')) mock_create_time.return_value = 100000 - self.assertEquals(PostmasterProcess.from_pidfile({"pid": "123", "start_time": "200000"}), None) - self.assertNotEquals(PostmasterProcess.from_pidfile({"pid": "123", "start_time": "foobar"}), None) + mock_read.return_value = {"pid": "123", "start_time": "200000"} + self.assertIsNone(PostmasterProcess.from_pidfile('')) + + mock_read.return_value = {"pid": "123", "start_time": "foobar"} + self.assertIsNotNone(PostmasterProcess.from_pidfile('')) mock_ospid.return_value = 123 - self.assertEquals(PostmasterProcess.from_pidfile({"pid": "123", "start_time": "100000"}), None) + mock_read.return_value = {"pid": "123", "start_time": "100000"} + self.assertIsNone(PostmasterProcess.from_pidfile('')) @patch('psutil.Process.__init__') def test_from_pid(self, mock_init): @@ -75,11 +84,20 @@ class TestPostmasterProcess(unittest.TestCase): @patch('subprocess.Popen') @patch.object(PostmasterProcess, 'from_pid') - def test_start(self, mock_frompid, mock_popen): + @patch.object(PostmasterProcess, '_from_pidfile') + def test_start(self, mock_frompidfile, mock_frompid, mock_popen): + mock_frompidfile.return_value._is_postmaster_process.return_value = False mock_frompid.return_value = "proc 123" mock_popen.return_value.stdout.readline.return_value = '123' - self.assertEquals( - PostmasterProcess.start('/bin/true', '/tmp/', '/tmp/test.conf', ['--foo=bar', '--bar=baz']), - "proc 123" - ) + self.assertEquals(PostmasterProcess.start('true', '/tmp', '/tmp/test.conf', []), "proc 123") mock_frompid.assert_called_with(123) + + mock_frompidfile.side_effect = psutil.NoSuchProcess(123) + self.assertEquals(PostmasterProcess.start('true', '/tmp', '/tmp/test.conf', []), "proc 123") + + @patch('psutil.Process.__init__', Mock(side_effect=psutil.NoSuchProcess(123))) + def test_read_postmaster_pidfile(self): + with patch.object(builtins, 'open', Mock(side_effect=IOError)): + self.assertIsNone(PostmasterProcess.from_pidfile('')) + with patch.object(builtins, 'open', mock_open(read_data='123\n')): + self.assertIsNone(PostmasterProcess.from_pidfile('')) From 5ce18a8045bb62f086b58abf1f9572683b275331 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Fri, 18 May 2018 11:18:58 +0200 Subject: [PATCH 13/63] Improve protection of DCS being accidentally wiped (#680) We already have a lot of logic in place to prevent failover in such case and restore all keys, but an accidental removal of `/config` key was effectively switching off pause mode for 1 cycle of HA loop. --- patroni/config.py | 5 ++++- patroni/dcs/__init__.py | 11 ++++++----- patroni/ha.py | 13 ++++++++++--- tests/test_etcd.py | 6 ++++-- 4 files changed, 24 insertions(+), 11 deletions(-) diff --git a/patroni/config.py b/patroni/config.py index 8a1a5aa8..89f1511c 100644 --- a/patroni/config.py +++ b/patroni/config.py @@ -9,7 +9,7 @@ from collections import defaultdict from copy import deepcopy from patroni.dcs import ClusterConfig from patroni.postgresql import Postgresql -from patroni.utils import deep_compare, parse_int, patch_config +from patroni.utils import deep_compare, parse_bool, parse_int, patch_config from requests.structures import CaseInsensitiveDict logger = logging.getLogger(__name__) @@ -88,6 +88,9 @@ class Config(object): def dynamic_configuration(self): return deepcopy(self._dynamic_configuration) + def check_mode(self, mode): + return bool(parse_bool(self._dynamic_configuration.get(mode))) + def _load_config_file(self): """Loads config.yaml from filesystem and applies some values which were set via ENV""" with open(self._config_file) as f: diff --git a/patroni/dcs/__init__.py b/patroni/dcs/__init__.py index 4e450279..346a22b0 100644 --- a/patroni/dcs/__init__.py +++ b/patroni/dcs/__init__.py @@ -11,6 +11,7 @@ import sys from collections import namedtuple from patroni.exceptions import PatroniException +from patroni.utils import parse_bool from random import randint from six.moves.urllib_parse import urlparse, urlunparse, parse_qsl from threading import Event, Lock @@ -349,14 +350,14 @@ class Cluster(namedtuple('Cluster', 'initialize,config,leader,last_leader_operat candidates = [m for m in self.members if m.clonefrom and m.is_running and m.name not in exclude] return candidates[randint(0, len(candidates) - 1)] if candidates else self.leader + def check_mode(self, mode): + return bool(self.config and parse_bool(self.config.data.get(mode))) + def is_paused(self): - return self.config and self.config.data.get('pause', False) or False + return self.check_mode('pause') def is_synchronous_mode(self): - return bool(self.config and self.config.data.get('synchronous_mode')) - - def is_synchronous_mode_strict(self): - return bool(self.config and self.config.data.get('synchronous_mode_strict')) + return self.check_mode('synchronous_mode') @six.add_metaclass(abc.ABCMeta) diff --git a/patroni/ha.py b/patroni/ha.py index e5058579..3e45f5d4 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -76,8 +76,15 @@ class Ha(object): # already running as replica was aborted due to cluster not beeing initialized in DCS. self._join_aborted = False + def check_mode(self, mode): + # Try to protect from the case when DCS was wiped out during pause + if self.cluster and self.cluster.config and self.cluster.config.modify_index: + return self.cluster.check_mode(mode) + else: + return self.patroni.config.check_mode(mode) + def is_paused(self): - return self.cluster and self.cluster.is_paused() + return self.check_mode('pause') def load_cluster_from_dcs(self): cluster = self.dcs.get_cluster() @@ -288,10 +295,10 @@ class Ha(object): return follow_reason def is_synchronous_mode(self): - return bool(self.cluster and self.cluster.is_synchronous_mode()) + return self.check_mode('synchronous_mode') def is_synchronous_mode_strict(self): - return bool(self.cluster and self.cluster.is_synchronous_mode_strict()) + return self.check_mode('synchronous_mode_strict') def process_sync_replication(self): """Process synchronous standby beahvior. diff --git a/tests/test_etcd.py b/tests/test_etcd.py index f6159131..85b925ef 100644 --- a/tests/test_etcd.py +++ b/tests/test_etcd.py @@ -90,7 +90,7 @@ def etcd_read(self, key, **kwargs): raise etcd.EtcdKeyNotFound response = {"action": "get", "node": {"key": "/service/batman5", "dir": True, "nodes": [ - {"key": "/service/batman5/config", "value": '{"foo": "bar"}', + {"key": "/service/batman5/config", "value": '{"synchronous_mode": 0}', "modifiedIndex": 1582, "createdIndex": 1582}, {"key": "/service/batman5/failover", "value": "", "modifiedIndex": 1582, "createdIndex": 1582}, @@ -276,7 +276,9 @@ class TestEtcd(unittest.TestCase): {'hosts': 'foo:4001,bar', 'retry_timeout': 10}) def test_get_cluster(self): - self.assertIsInstance(self.etcd.get_cluster(), Cluster) + cluster = self.etcd.get_cluster() + self.assertIsInstance(cluster, Cluster) + self.assertFalse(cluster.is_synchronous_mode()) self.etcd._base_path = '/service/nocluster' cluster = self.etcd.get_cluster() self.assertIsInstance(cluster, Cluster) From ed479fe585f83c6a96d96bb18770454f8a4dd87e Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Fri, 18 May 2018 11:19:56 +0200 Subject: [PATCH 14/63] Don't demote master if failed to update leader key in pause (#668) Fixes https://github.com/zalando/patroni/issues/659 --- patroni/ha.py | 2 ++ tests/test_ha.py | 8 ++++++++ 2 files changed, 10 insertions(+) diff --git a/patroni/ha.py b/patroni/ha.py index 3e45f5d4..92259b2a 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -771,6 +771,8 @@ class Ha(object): # Either there is no connection to DCS or someone else acquired the lock logger.error('failed to update leader lock') if self.state_handler.is_leader(): + if self.is_paused(): + return 'continue to run as master after failing to update leader lock in DCS' self.demote('immediate-nolock') return 'demoted self because failed to update leader lock in DCS' else: diff --git a/tests/test_ha.py b/tests/test_ha.py index bdd2ff9f..70b4f60f 100644 --- a/tests/test_ha.py +++ b/tests/test_ha.py @@ -623,6 +623,14 @@ class TestHa(unittest.TestCase): self.ha.cluster = get_cluster_initialized_with_leader(Failover(0, '', self.p.name, None)) self.assertEquals(self.ha.run_cycle(), 'PAUSE: waiting to become master after promote...') + def test_failed_to_update_lock_in_pause(self): + self.ha.update_lock = false + self.ha.is_paused = true + self.p.name = 'leader' + self.ha.cluster = get_cluster_initialized_with_leader() + self.assertEquals(self.ha.run_cycle(), + 'PAUSE: continue to run as master after failing to update leader lock in DCS') + def test_postgres_unhealthy_in_pause(self): self.ha.is_paused = true self.p.is_healthy = false From 1043376e6bdcc33d541b28ce14425b53e43b20bf Mon Sep 17 00:00:00 2001 From: Oleksii Kliukin Date: Fri, 18 May 2018 11:48:15 +0200 Subject: [PATCH 15/63] Do not exit when encountering invalid system ID. (#669) Do not exit when the cluster system ID is empty or the one that doesn't pass the validation check. In that case, the cluster most likely needs a reinit; mention it in the result message. Avoid terminating Patroni, as otherwise reinit cannot happen. --- patroni/ha.py | 5 +++++ tests/test_ha.py | 1 - 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/patroni/ha.py b/patroni/ha.py index 92259b2a..0bc3a533 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -1101,6 +1101,11 @@ class Ha(object): self.dcs.initialize(create_new=(self.cluster.initialize is None), sysid=self.state_handler.sysid) else: # check if we are allowed to join + data_sysid = self.state_handler.sysid + if not self.sysid_valid(data_sysid): + # data directory is not empty, but no valid sysid, cluster must be broken, suggest reinit + return "data dir for the cluster is not empty, but system ID is invalid; consider doing reinitalize" + if self.sysid_valid(self.cluster.initialize) and self.cluster.initialize != self.state_handler.sysid: logger.fatal("system ID mismatch, node %s belongs to a different cluster: %s != %s", self.state_handler.name, self.cluster.initialize, self.state_handler.sysid) diff --git a/tests/test_ha.py b/tests/test_ha.py index 70b4f60f..8901f50e 100644 --- a/tests/test_ha.py +++ b/tests/test_ha.py @@ -18,7 +18,6 @@ from test_postgresql import psycopg2_connect, MockPostmaster SYSID = '12345678901' - def true(*args, **kwargs): return True From 4ce539ba1b729e96404d0c28582c77bcf9fc593a Mon Sep 17 00:00:00 2001 From: Oleksii Kliukin Date: Fri, 18 May 2018 12:18:35 +0200 Subject: [PATCH 16/63] Allow options to the basebackup built-in method. (#604) Options should be specified in the basebackup section, which is optional. --- docs/replica_bootstrap.rst | 37 ++++++++++++++++++--- patroni/postgresql.py | 66 +++++++++++++++++++++++++------------- postgres1.yml | 3 ++ tests/test_postgresql.py | 42 ++++++++++++++++++------ 4 files changed, 112 insertions(+), 36 deletions(-) diff --git a/docs/replica_bootstrap.rst b/docs/replica_bootstrap.rst index 233c2c5b..f5359e7b 100644 --- a/docs/replica_bootstrap.rst +++ b/docs/replica_bootstrap.rst @@ -76,13 +76,14 @@ scripts to clone a new replica. Those are configured in the ``postgresql`` confi no_master: 1 envdir: {{WALE_ENV_DIR}} use_iam: 1 + basebackup: + max-rate: '100M' The ``create_replica_method`` defines available replica creation methods and the order of executing them. Patroni will -stop on the first one that returns 0. The basebackup is the built-in method and doesn't require any configuration. The -rest of the methods should define a separate section in the configuration file, listing the command to execute and any -custom parameters that should be passed to that command. All parameters will be passed in a ``--name=value`` format. -Besides user-defined parameters, Patroni supplies a couple of cluster-specific ones: +stop on the first one that returns 0. Each method should define a separate section in the configuration file, listing the command +to execute and any custom parameters that should be passed to that command. All parameters will be passed in a +``--name=value`` format. Besides user-defined parameters, Patroni supplies a couple of cluster-specific ones: --scope Which cluster this replica belongs to @@ -98,4 +99,32 @@ A special ``no_master`` parameter, if defined, allows Patroni to call the replic running master or replicas. In that case, an empty string will be passed in a connection string. This is useful for restoring the formerly running cluster from the binary backup. +A ``basebackup`` method is a special case: it will be used if ``create_replica_method`` is empty, although it is possible +to list it explicitly among the ``create_replica_method`` methods. This method initializes a new replica with the +``pg_basebackup``, the base backup is taken from the master unless there are replicas with ``clonefrom`` tag, in which case one +of such replicas will be used as the origin for pg_basebackup. It works without any configuration; however, it is +possible to specify a ``basebackup`` configuration section. Same rules as with the other method configuration apply, +namely, only long (with --) options should be specified there. Not all parameters make sense, if you override a connection +string or provide an option to created tar-ed or compressed base backups, patroni won't be able to make a replica out +of it. There is no validation performed on the names or values of the parameters passed to the ``basebackup`` section. +You can specify basebackup parameters as either a map (key-value pairs) or a list of elements, where each element +could be either a key-value pair or a single key (for options that does not receive any values, for instance, ``--verbose``). +Consider those 2 examples: + +.. code:: YAML + + postgresql: + basebackup: + max-rate: '100M' + checkpoint: 'fast' + +and + +.. code:: YAML + + postgresql: + basebackup: + - verbose + - max-rate: '100M' + If all replica creation methods fail, Patroni will try again all methods in order during the next event loop cycle. diff --git a/patroni/postgresql.py b/patroni/postgresql.py index f31e4828..fc473f00 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -498,28 +498,44 @@ class Postgresql(object): return not os.path.exists(self._data_dir) or os.listdir(self._data_dir) == [] @staticmethod - def initdb_allowed_option(name): - if name in ['pgdata', 'nosync', 'pwfile', 'sync-only']: - raise Exception('{0} option for initdb is not allowed'.format(name)) - return True + def process_user_options(tool, options, not_allowed_options, error_handler): + user_options = [] - def get_initdb_options(self, config): - options = [] - for o in config: - if isinstance(o, string_types) and self.initdb_allowed_option(o): - options.append('--{0}'.format(o)) - elif isinstance(o, dict): - keys = list(o.keys()) - if len(keys) != 1 or not isinstance(keys[0], string_types) or not self.initdb_allowed_option(keys[0]): - raise Exception('Invalid option: {0}'.format(o)) - options.append('--{0}={1}'.format(keys[0], o[keys[0]])) - else: - raise Exception('Unknown type of initdb option: {0}'.format(o)) - return options + def option_is_allowed(name): + ret = name not in not_allowed_options + if not ret: + error_handler('{0} option for {1} is not allowed'.format(name, tool)) + return ret + + if isinstance(options, dict): + for k, v in options.items(): + if k and v: + user_options.append('--{0}={1}'.format(k, v)) + elif isinstance(options, list): + for opt in options: + if isinstance(opt, string_types) and option_is_allowed(opt): + user_options.append('--{0}'.format(opt)) + elif isinstance(opt, dict): + keys = list(opt.keys()) + if len(keys) != 1 or not isinstance(opt[keys[0]], string_types) or not option_is_allowed(keys[0]): + error_handler('Error when parsing {0} key-value option {1}: only one key-value is allowed' + ' and value should be a string'.format(tool, opt[keys[0]])) + user_options.append('--{0}={1}'.format(keys[0], opt[keys[0]])) + else: + error_handler('Error when parsing {0} option {1}: value should be string value' + ' or a single key-value pair'.format(tool, opt)) + else: + error_handler('{0} options must be list ot dict'.format(tool)) + return user_options def _initdb(self, config): self.set_state('initalizing new cluster') - options = self.get_initdb_options(config.get('initdb') or []) + not_allowed_options = ('pgdata', 'nosync', 'pwfile', 'sync-only', 'version') + + def error_handler(e): + raise Exception(e) + + options = self.process_user_options('initdb', config.get('initdb') or [], not_allowed_options, error_handler) pwfile = None if self._superuser: @@ -659,7 +675,7 @@ class Postgresql(object): break # if the method is basebackup, then use the built-in if replica_method == "basebackup": - ret = self.basebackup(connstring, env) + ret = self.basebackup(connstring, env, self.config.get(replica_method, {})) if ret == 0: logger.info("replica has been created using basebackup") # if basebackup succeeds, exit with success @@ -672,7 +688,7 @@ class Postgresql(object): method_config = {} # user-defined method; check for configuration # not required, actually - if replica_method in self.config: + if self.config.get(replica_method, {}): method_config = self.config[replica_method].copy() # look to see if the user has supplied a full command path # if not, use the method name as the command @@ -1601,23 +1617,27 @@ $$""".format(name, ' '.join(options)), name, password, password) logger.exception('Could not remove data directory %s', self._data_dir) self.move_data_directory() - def basebackup(self, conn_url, env): + def basebackup(self, conn_url, env, options): # creates a replica data dir using pg_basebackup. # this is the default, built-in create_replica_method # tries twice, then returns failure (as 1) # uses "stream" as the xlog-method to avoid sync issues + # supports additional user-supplied options, those are not validated maxfailures = 2 ret = 1 + not_allowed_options = ('pgdata', 'format', 'wal-method', 'xlog-method', 'gzip', + 'version', 'compress', 'dbname', 'host', 'port', 'username', 'password') + user_options = self.process_user_options('basebackup', options, not_allowed_options, logger.error) + for bbfailures in range(0, maxfailures): with self._cancellable_lock: if self._is_cancelled: break if not self.data_directory_empty(): self.remove_data_directory() - try: ret = self.cancellable_subprocess_call([self._pgcommand('pg_basebackup'), '--pgdata=' + self._data_dir, - '-X', 'stream', '--dbname=' + conn_url], env=env) + '-X', 'stream', '--dbname=' + conn_url] + user_options, env=env) if ret == 0: break else: diff --git a/postgres1.yml b/postgres1.yml index 9c1d141b..683bc965 100644 --- a/postgres1.yml +++ b/postgres1.yml @@ -75,6 +75,9 @@ postgresql: password: zalando parameters: unix_socket_directories: '.' + basebackup: + - verbose + - max-rate: 100M tags: nofailover: false noloadbalance: false diff --git a/tests/test_postgresql.py b/tests/test_postgresql.py index b6f4d2d5..7fab3d65 100644 --- a/tests/test_postgresql.py +++ b/tests/test_postgresql.py @@ -210,12 +210,11 @@ class TestPostgresql(unittest.TestCase): def tearDown(self): shutil.rmtree('data') - def test_get_initdb_options(self): - self.assertEquals(self.p.get_initdb_options([{'encoding': 'UTF8'}, 'data-checksums']), - ['--encoding=UTF8', '--data-checksums']) - self.assertRaises(Exception, self.p.get_initdb_options, [{'pgdata': 'bar'}]) - self.assertRaises(Exception, self.p.get_initdb_options, [{'foo': 'bar', 1: 2}]) - self.assertRaises(Exception, self.p.get_initdb_options, [1]) + def test__initdb(self): + self.assertRaises(Exception, self.p.bootstrap, {'initdb': [{'pgdata': 'bar'}]}) + self.assertRaises(Exception, self.p.bootstrap, {'initdb': [{'foo': 'bar', 1: 2}]}) + self.assertRaises(Exception, self.p.bootstrap, {'initdb': [1]}) + self.assertRaises(Exception, self.p.bootstrap, {'initdb': 1}) @patch('os.path.exists', Mock(return_value=True)) @patch('os.unlink', Mock()) @@ -428,6 +427,29 @@ class TestPostgresql(unittest.TestCase): del self.p.config['wale'] self.assertEquals(self.p.create_replica(self.leader), 0) + self.p.config['create_replica_method'] = ['basebackup'] + self.p.config['basebackup'] = [{'max_rate': '100M'}, 'no-sync'] + self.assertEquals(self.p.create_replica(self.leader), 0) + + self.p.config['basebackup'] = [{'max_rate': '100M', 'compress': '9'}] + with mock.patch('patroni.postgresql.logger.error', new_callable=Mock()) as mock_logger: + self.p.create_replica(self.leader) + mock_logger.assert_called_once() + self.assertTrue("only one key-value is allowed and value should be a string" in mock_logger.call_args[0][0], + "not matching {0}".format(mock_logger.call_args[0][0])) + + self.p.config['basebackup'] = [42] + with mock.patch('patroni.postgresql.logger.error', new_callable=Mock()) as mock_logger: + self.p.create_replica(self.leader) + mock_logger.assert_called_once() + self.assertTrue("value should be string value or a single key-value pair" in mock_logger.call_args[0][0], + "not matching {0}".format(mock_logger.call_args[0][0])) + + self.p.config['basebackup'] = {"foo": "bar"} + self.assertEquals(self.p.create_replica(self.leader), 0) + + self.p.config['create_replica_method'] = ['wale', 'basebackup'] + del self.p.config['basebackup'] mock_cancellable_subprocess_call.return_value = 1 self.assertEquals(self.p.create_replica(self.leader), 1) @@ -445,7 +467,7 @@ class TestPostgresql(unittest.TestCase): def test_basebackup(self): self.p.cancel() - self.p.basebackup(None, None) + self.p.basebackup(None, None, {'foo': 'bar'}) @patch.object(Postgresql, 'is_running', Mock(return_value=True)) def test_sync_replication_slots(self): @@ -463,8 +485,10 @@ class TestPostgresql(unittest.TestCase): cluster.members.extend([alias1, alias2]) self.p.sync_replication_slots(cluster) errorlog_mock.assert_called_once() - assert "test-3" in errorlog_mock.call_args[0][1] - assert "test.3" in errorlog_mock.call_args[0][1] + self.assertTrue("test-3" in errorlog_mock.call_args[0][1], + "non matching {0}".format(errorlog_mock.call_args[0][1])) + self.assertTrue("test.3" in errorlog_mock.call_args[0][1], + "non matching {0}".format(errorlog_mock.call_args[0][1])) @patch.object(MockCursor, 'execute', Mock(side_effect=psycopg2.OperationalError)) def test__query(self): From 856552bd6165731c3fe38f15ba5826df9cd5f425 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Fri, 18 May 2018 12:18:49 +0200 Subject: [PATCH 17/63] Sync replication slots and verify sysid after coming out of pause (#678) Fixes https://github.com/zalando/patroni/issues/568 and https://github.com/zalando/patroni/issues/674 --- patroni/ha.py | 6 ++++++ patroni/postgresql.py | 9 +++++++++ tests/test_ha.py | 8 ++++++++ 3 files changed, 23 insertions(+) diff --git a/patroni/ha.py b/patroni/ha.py index 0bc3a533..d8eca50a 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -57,6 +57,7 @@ class Ha(object): self.dcs = patroni.dcs self.cluster = None self.old_cluster = None + self._was_paused = False self._leader_timeline = None self.recovering = False self._post_bootstrap_task = None @@ -1047,6 +1048,11 @@ class Ha(object): if self.is_paused(): self.watchdog.disable() + self._was_paused = True + else: + if self._was_paused: + self.state_handler.schedule_sanity_checks_after_pause() + self._was_paused = False if not self.cluster.has_member(self.state_handler.name): self.touch_member() diff --git a/patroni/postgresql.py b/patroni/postgresql.py index fc473f00..f215283a 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -1848,3 +1848,12 @@ $$""".format(name, ' '.join(options)), name, password, password) with self._cancellable_lock: if self._cancellable is not None and self._cancellable.returncode is None: self._cancellable.kill() + + def schedule_sanity_checks_after_pause(self): + """ + After coming out of pause we have to: + 1. sync replication slots, because it might happen that slots were removed + 2. get new 'Database system identifier' to make sure that it wasn't changed + """ + self._schedule_load_slots = self.use_slots + self._sysid = None diff --git a/tests/test_ha.py b/tests/test_ha.py index 8901f50e..240a85f8 100644 --- a/tests/test_ha.py +++ b/tests/test_ha.py @@ -915,3 +915,11 @@ class TestHa(unittest.TestCase): self.p.is_leader = false self.ha.run_cycle() exit_mock.assert_called_once_with(1) + + def test_after_pause(self): + self.ha.has_lock = true + self.ha.cluster.is_unlocked = false + self.ha.is_paused = true + self.assertEquals(self.ha.run_cycle(), 'PAUSE: no action. i am the leader with the lock') + self.ha.is_paused = false + self.assertEquals(self.ha.run_cycle(), 'no action. i am the leader with the lock') From 041015037e1e08eb7cd5df27d276da946335f86a Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Fri, 18 May 2018 16:32:06 +0200 Subject: [PATCH 18/63] Sync replication slots when we noticed a new postmaster process (#677) Fixes: https://github.com/zalando/patroni/issues/674 --- patroni/postgresql.py | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index f215283a..7a9034aa 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -741,12 +741,15 @@ class Postgresql(object): def is_running(self): """Returns PostmasterProcess if one is running on the data directory or None. If most recently seen process - is running udpates the cached process based on pid file.""" + is running updates the cached process based on pid file.""" if self._postmaster_proc: if self._postmaster_proc.is_running(): return self._postmaster_proc self._postmaster_proc = None + # we noticed that postgres was restarted, force syncing of replication + self._schedule_load_slots = self.use_slots + self._postmaster_proc = PostmasterProcess.from_pidfile(self._data_dir) return self._postmaster_proc @@ -987,7 +990,7 @@ class Postgresql(object): Should only be called when state == 'starting' - :returns: True iff state was changed from 'starting' + :returns: True if state was changed from 'starting' """ ready = self.pg_isready() From 1de7c78c04dab9882f6113815d377e6f3490d5dd Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Tue, 22 May 2018 14:46:19 +0200 Subject: [PATCH 19/63] Release 1.4.4 (#683) bump version and update release notes --- docs/releases.rst | 62 ++++++++++++++++++++++++++++++++++++++++++++++ patroni/version.py | 2 +- 2 files changed, 63 insertions(+), 1 deletion(-) diff --git a/docs/releases.rst b/docs/releases.rst index cba3d2ed..f2d30f58 100644 --- a/docs/releases.rst +++ b/docs/releases.rst @@ -3,6 +3,68 @@ Release notes ============= +Version 1.4.4 +------------- + +**Stability improvements** + +- Fix race condition in poll_failover_result (Alexander Kukushkin) + + It didn't affect directly neither failover nor switchover, but in some rare cases it was reporting success too early, when the former leader released the lock, producing a 'Failed over to "None"' instead of 'Failed over to "desired-node"' message. + +- Treat Postgres parameter names as case insensitive (Alexander) + + Most of the Postgres parameters have snake_case names, but there are three exceptions from this rule: DateStyle, IntervalStyle and TimeZone. Postgres accepts those parameters when written in a different case (e.g. timezone = 'some/tzn'); however, Patroni was unable to find case-insensitive matches of those parameter names in pg_settings and ignored such parameters as a result. + +- Abort start if attaching to running postgres and cluster not initialized (Alexander) + + Patroni can attach itself to an already running Postgres instance. It is imperative to start running Patroni on the master node before getting to the replicas. + +- Fix behavior of patronictl scaffold (Alexander) + + Pass dict object to touch_member instead of json encoded string, DCS implementation will take care of encoding it. + +- Don't demote master if failed to update leader key in pause (Alexander) + + During maintenance a DCS may start failing write requests while continuing to responds to read ones. In that case, Patroni used to put the Postgres master node to a read-only mode after failing to update the leader lock in DCS. + +- Sync replication slots when Patroni notices a new postmaster process (Alexander) + + If Postgres has been restarted, Patroni has to make sure that list of replication slots matches its expectations. + +- Verify sysid and sync replication slots after coming out of pause (Alexander) + + During the `maintenance` mode it may happen that data directory was completely rewritten and therefore we have to make sure that `Database system identifier` still belongs to our cluster and replication slots are in sync with Patroni expectations. + +- Fix a possible failure to start not running Postgres on a data directory with postmaster lock file present (Alexander) + + Detect reuse of PID from the postmaster lock file. More likely to hit such problem if you run Patroni and Postgres in the docker container. + +- Improve protection of DCS being accidentally wiped (Alexander) + + Patroni has a lot of logic in place to prevent failover in such case; it can also restore all keys back; however, until this change an accidental removal of /config key was switching off pause mode for 1 cycle of HA loop. + +- Do not exit when encountering invalid system ID (Oleksii Kliukin) + + Do not exit when the cluster system ID is empty or the one that doesn't pass the validation check. In that case, the cluster most likely needs a reinit; mention it in the result message. Avoid terminating Patroni, as otherwise reinit cannot happen. + +**Compatibility with Kubernetes 1.10+** + +- Added check for empty subsets (Cody Coons) + + Kubernetes 1.10.0+ started returning `Endpoints.subsets` set to `None` instead of `[]`. + +**Bootstrap improvements** + +- Make deleting recovery.conf optional (Brad Nicholson) + + If `bootstrap..keep_existing_recovery_conf` is defined and set to ``True``, Patroni will not remove the existing ``recovery.conf`` file. This is useful when bootstrapping from a backup with tools like pgBackRest that generate the appropriate `recovery.conf` for you. + +- Allow options to the basebackup built-in method (Oleksii) + + It is now possible to supply options to the built-in basebackup method by defining the `basebackup` section in the configuration, similar to how those are defined for custom replica creation methods. The difference is in the format accepted by the `basebackup` section: since pg_basebackup accepts both `--key=value` and `--key` options, the contents of the section could be either a dictionary of key-value pairs, or a list of either one-element dictionaries or just keys (for the options that don't accept values). See :ref:`replica creation method ` section for additional examples. + + Version 1.4.3 ------------- diff --git a/patroni/version.py b/patroni/version.py index 4e7c72a5..9e0feee7 100644 --- a/patroni/version.py +++ b/patroni/version.py @@ -1 +1 @@ -__version__ = '1.4.3' +__version__ = '1.4.4' From e5f25117642478bba6ae50514d948b2056417bc3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Albers?= Date: Mon, 4 Jun 2018 16:36:41 +0200 Subject: [PATCH 20/63] Add WorkingDirectory to systemd sample config. (#686) Otherwise `initdb` fails because it tries to create the data directory in the root directory where the postgres user has no permissions. --- extras/startup-scripts/patroni.service | 2 ++ 1 file changed, 2 insertions(+) diff --git a/extras/startup-scripts/patroni.service b/extras/startup-scripts/patroni.service index 829fb64b..0be8f961 100644 --- a/extras/startup-scripts/patroni.service +++ b/extras/startup-scripts/patroni.service @@ -11,6 +11,8 @@ Type=simple User=postgres Group=postgres +WorkingDirectory=~ + # Where to send early-startup messages from the server # This is normally controlled by the global default set by systemd # StandardOutput=syslog From d037aa8afdf24dbe3f2153bec4cbc23d567828f0 Mon Sep 17 00:00:00 2001 From: erthalion <9erthalion6@gmail.com> Date: Tue, 12 Jun 2018 11:33:13 +0200 Subject: [PATCH 21/63] Rename create_replica_method to create_replica_methods To make it clear that it's actually an array --- docs/SETTINGS.rst | 2 +- docs/replica_bootstrap.rst | 9 +++++---- patroni/postgresql.py | 11 ++++++++--- tests/test_postgresql.py | 31 ++++++++++++++++++++++++++++--- 4 files changed, 42 insertions(+), 11 deletions(-) diff --git a/docs/SETTINGS.rst b/docs/SETTINGS.rst index 009f1357..8e2a7607 100644 --- a/docs/SETTINGS.rst +++ b/docs/SETTINGS.rst @@ -131,7 +131,7 @@ PostgreSQL - **pg\_ctl\_timeout**: How long should pg_ctl wait when doing ``start``, ``stop`` or ``restart``. Default value is 60 seconds. - **use\_pg\_rewind**: try to use pg\_rewind on the former leader when it joins cluster as a replica. - **remove\_data\_directory\_on\_rewind\_failure**: If this option is enabled, Patroni will remove postgres data directory and recreate replica. Otherwise it will try to follow the new leader. Default value is **false**. -- **replica\_method**: for each create_replica_method other than basebackup, you would add a configuration section of the same name. At a minimum, this should include "command" with a full path to the actual script to be executed. Other configuration parameters will be passed along to the script in the form "parameter=value". +- **replica\_method**: for each create_replica_methods other than basebackup, you would add a configuration section of the same name. At a minimum, this should include "command" with a full path to the actual script to be executed. Other configuration parameters will be passed along to the script in the form "parameter=value". REST API -------- diff --git a/docs/replica_bootstrap.rst b/docs/replica_bootstrap.rst index f5359e7b..d5d79155 100644 --- a/docs/replica_bootstrap.rst +++ b/docs/replica_bootstrap.rst @@ -68,7 +68,7 @@ scripts to clone a new replica. Those are configured in the ``postgresql`` confi .. code:: YAML postgresql: - create_replica_method: + create_replica_methods: - wal_e - basebackup wal_e: @@ -80,7 +80,7 @@ scripts to clone a new replica. Those are configured in the ``postgresql`` confi max-rate: '100M' -The ``create_replica_method`` defines available replica creation methods and the order of executing them. Patroni will +The ``create_replica_methods`` defines available replica creation methods and the order of executing them. Patroni will stop on the first one that returns 0. Each method should define a separate section in the configuration file, listing the command to execute and any custom parameters that should be passed to that command. All parameters will be passed in a ``--name=value`` format. Besides user-defined parameters, Patroni supplies a couple of cluster-specific ones: @@ -99,8 +99,9 @@ A special ``no_master`` parameter, if defined, allows Patroni to call the replic running master or replicas. In that case, an empty string will be passed in a connection string. This is useful for restoring the formerly running cluster from the binary backup. -A ``basebackup`` method is a special case: it will be used if ``create_replica_method`` is empty, although it is possible -to list it explicitly among the ``create_replica_method`` methods. This method initializes a new replica with the +A ``basebackup`` method is a special case: it will be used if +``create_replica_methods`` is empty, although it is possible +to list it explicitly among the ``create_replica_methods`` methods. This method initializes a new replica with the ``pg_basebackup``, the base backup is taken from the master unless there are replicas with ``clonefrom`` tag, in which case one of such replicas will be used as the origin for pg_basebackup. It works without any configuration; however, it is possible to specify a ``basebackup`` configuration section. Same rules as with the other method configuration apply, diff --git a/patroni/postgresql.py b/patroni/postgresql.py index 7a9034aa..bc8add0a 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -180,6 +180,11 @@ class Postgresql(object): if self._replace_pg_hba(): self.reload() + @property + def _create_replica_methods(self): + return (self.config.get('create_replica_methods', []) or + self.config.get('create_replica_method', [])) + @property def _configuration_to_save(self): configuration = [os.path.basename(self._postgresql_conf)] @@ -638,7 +643,7 @@ class Postgresql(object): """ go through the replication methods to see if there are ones that does not require a working replication connection. """ - replica_methods = self.config.get('create_replica_method', []) + replica_methods = self._create_replica_methods return any(self.replica_method_can_work_without_replication_connection(method) for method in replica_methods) def create_replica(self, clone_member): @@ -653,7 +658,7 @@ class Postgresql(object): # get list of replica methods from config. # If there is no configuration key, or no value is specified, use basebackup - replica_methods = self.config.get('create_replica_method') or ['basebackup'] + replica_methods = self._create_replica_methods or ['basebackup'] if clone_member and clone_member.conn_url: r = clone_member.conn_kwargs(self._replication) @@ -1622,7 +1627,7 @@ $$""".format(name, ' '.join(options)), name, password, password) def basebackup(self, conn_url, env, options): # creates a replica data dir using pg_basebackup. - # this is the default, built-in create_replica_method + # this is the default, built-in create_replica_methods # tries twice, then returns failure (as 1) # uses "stream" as the xlog-method to avoid sync issues # supports additional user-supplied options, those are not validated diff --git a/tests/test_postgresql.py b/tests/test_postgresql.py index 7fab3d65..80e93f61 100644 --- a/tests/test_postgresql.py +++ b/tests/test_postgresql.py @@ -420,14 +420,14 @@ class TestPostgresql(unittest.TestCase): def test_create_replica(self, mock_cancellable_subprocess_call): self.p.delete_trigger_file = Mock(side_effect=OSError) - self.p.config['create_replica_method'] = ['wale', 'basebackup'] + self.p.config['create_replica_methods'] = ['wale', 'basebackup'] self.p.config['wale'] = {'command': 'foo'} mock_cancellable_subprocess_call.return_value = 0 self.assertEquals(self.p.create_replica(self.leader), 0) del self.p.config['wale'] self.assertEquals(self.p.create_replica(self.leader), 0) - self.p.config['create_replica_method'] = ['basebackup'] + self.p.config['create_replica_methods'] = ['basebackup'] self.p.config['basebackup'] = [{'max_rate': '100M'}, 'no-sync'] self.assertEquals(self.p.create_replica(self.leader), 0) @@ -448,7 +448,7 @@ class TestPostgresql(unittest.TestCase): self.p.config['basebackup'] = {"foo": "bar"} self.assertEquals(self.p.create_replica(self.leader), 0) - self.p.config['create_replica_method'] = ['wale', 'basebackup'] + self.p.config['create_replica_methods'] = ['wale', 'basebackup'] del self.p.config['basebackup'] mock_cancellable_subprocess_call.return_value = 1 self.assertEquals(self.p.create_replica(self.leader), 1) @@ -465,6 +465,31 @@ class TestPostgresql(unittest.TestCase): self.p.cancel() self.assertEquals(self.p.create_replica(self.leader), 1) + @patch('time.sleep', Mock()) + @patch.object(Postgresql, 'cancellable_subprocess_call') + @patch.object(Postgresql, 'remove_data_directory', Mock(return_value=True)) + def test_create_replica_old_format(self, mock_cancellable_subprocess_call): + """ The same test as before but with old 'create_replica_method' + to test backward compatibility + """ + self.p.delete_trigger_file = Mock(side_effect=OSError) + + self.p.config['create_replica_method'] = ['wale', 'basebackup'] + self.p.config['wale'] = {'command': 'foo'} + mock_cancellable_subprocess_call.return_value = 0 + self.assertEquals(self.p.create_replica(self.leader), 0) + del self.p.config['wale'] + self.assertEquals(self.p.create_replica(self.leader), 0) + + self.p.config['create_replica_method'] = ['basebackup'] + self.p.config['basebackup'] = [{'max_rate': '100M'}, 'no-sync'] + self.assertEquals(self.p.create_replica(self.leader), 0) + + self.p.config['create_replica_method'] = ['wale', 'basebackup'] + del self.p.config['basebackup'] + mock_cancellable_subprocess_call.return_value = 1 + self.assertEquals(self.p.create_replica(self.leader), 1) + def test_basebackup(self): self.p.cancel() self.p.basebackup(None, None, {'foo': 'bar'}) From 3d80e49b38faf770e0873dade1e8bd3aee598d1b Mon Sep 17 00:00:00 2001 From: erthalion <9erthalion6@gmail.com> Date: Tue, 12 Jun 2018 13:28:30 +0200 Subject: [PATCH 22/63] Rename also in settings docs --- docs/SETTINGS.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/SETTINGS.rst b/docs/SETTINGS.rst index 8e2a7607..c09826db 100644 --- a/docs/SETTINGS.rst +++ b/docs/SETTINGS.rst @@ -113,7 +113,7 @@ PostgreSQL - **on\_start**: run this script when the cluster starts. - **on\_stop**: run this script when the cluster stops. - **connect\_address**: IP address + port through which Postgres is accessible from other nodes and applications. -- **create\_replica\_method**: an ordered list of the create methods for turning a Patroni node into a new replica. +- **create\_replica\_methods**: an ordered list of the create methods for turning a Patroni node into a new replica. "basebackup" is the default method; other methods are assumed to refer to scripts, each of which is configured as its own config item. See :ref:`custom replica creation methods documentation ` for further explanation. - **data\_dir**: The location of the Postgres data directory, either existing or to be initialized by Patroni. From e405e4e03c2e13f20d4d16c56b99feddf75a004f Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Tue, 12 Jun 2018 14:00:10 +0200 Subject: [PATCH 23/63] Workaround to sporadic unit-test failures (#696) Fixes https://github.com/zalando/patroni/issues/691 --- tests/test_postgresql.py | 8 +++++--- tests/test_wale_restore.py | 27 ++++++++++++++++++++------- 2 files changed, 25 insertions(+), 10 deletions(-) diff --git a/tests/test_postgresql.py b/tests/test_postgresql.py index 7fab3d65..4e6c0f0e 100644 --- a/tests/test_postgresql.py +++ b/tests/test_postgresql.py @@ -14,7 +14,7 @@ from patroni.postgresql import Postgresql, STATE_REJECT, STATE_NO_RESPONSE from patroni.postmaster import PostmasterProcess from patroni.utils import RetryFailedError from six.moves import builtins -from threading import Thread +from threading import Thread, current_thread class MockCursor(object): @@ -790,10 +790,12 @@ class TestPostgresql(unittest.TestCase): def test_wait_for_startup(self): state = {'sleeps': 0, 'num_rejects': 0, 'final_return': 0} + self.__thread_ident = current_thread().ident def increment_sleeps(*args): - print("Sleep") - state['sleeps'] += 1 + if current_thread().ident == self.__thread_ident: + print("Sleep") + state['sleeps'] += 1 def isready_return(*args): ret = 1 if state['sleeps'] < state['num_rejects'] else state['final_return'] diff --git a/tests/test_wale_restore.py b/tests/test_wale_restore.py index 57fb7509..057cfd96 100644 --- a/tests/test_wale_restore.py +++ b/tests/test_wale_restore.py @@ -7,6 +7,7 @@ from patroni.scripts import wale_restore from patroni.scripts.wale_restore import WALERestore, main as _main, get_major_version from six.moves import builtins from test_postgresql import MockConnect, psycopg2_connect +from threading import current_thread wale_output_header = ( @@ -42,6 +43,13 @@ class TestWALERestore(unittest.TestCase): '/etc', 100, 100, 1, 0, WALE_TEST_RETRIES) def test_should_use_s3_to_create_replica(self): + self.__thread_ident = current_thread().ident + sleeps = [0] + + def mock_sleep(*args): + if current_thread().ident == self.__thread_ident: + sleeps[0] += 1 + self.assertTrue(self.wale_restore.should_use_s3_to_create_replica()) with patch.object(MockConnect, 'server_version', PropertyMock(return_value=100000)): self.assertTrue(self.wale_restore.should_use_s3_to_create_replica()) @@ -55,13 +63,11 @@ class TestWALERestore(unittest.TestCase): self.assertFalse(self.wale_restore.should_use_s3_to_create_replica()) - with patch('time.sleep', Mock(return_value=None)) as mock_sleep: + with patch('time.sleep', mock_sleep): self.wale_restore.no_master = 1 - assert self.wale_restore.should_use_s3_to_create_replica() + self.assertTrue(self.wale_restore.should_use_s3_to_create_replica()) # verify retries - mock_sleep.assert_has_calls( - [((wale_restore.RETRY_SLEEP_INTERVAL,),)] * WALE_TEST_RETRIES - ) + self.assertEqual(sleeps[0], WALE_TEST_RETRIES) self.wale_restore.master_connection = '' self.assertTrue(self.wale_restore.should_use_s3_to_create_replica()) @@ -104,13 +110,20 @@ class TestWALERestore(unittest.TestCase): @patch('sys.exit', Mock()) def test_main(self): + self.__thread_ident = current_thread().ident + sleeps = [0] + + def mock_sleep(*args): + if current_thread().ident == self.__thread_ident: + sleeps[0] += 1 + with patch.object(WALERestore, 'run', Mock(return_value=0)): self.assertEqual(_main(), 0) with patch.object(WALERestore, 'run', Mock(return_value=1)), \ - patch('time.sleep', Mock(return_value=None)) as mock_sleep: + patch('time.sleep', mock_sleep): self.assertEqual(_main(), 1) - assert mock_sleep.call_count == WALE_TEST_RETRIES + self.assertTrue(sleeps[0], WALE_TEST_RETRIES) @patch('os.path.isfile', Mock(return_value=True)) def test_get_major_version(self): From aa18f704660d60f3b4a85bd177876f6be469047b Mon Sep 17 00:00:00 2001 From: Chris Fraser Date: Tue, 12 Jun 2018 05:00:48 -0700 Subject: [PATCH 24/63] If set, use LD_LIBRARY_PATH when starting postgres (#698) Fixes #697 --- patroni/postmaster.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/patroni/postmaster.py b/patroni/postmaster.py index aa5f3050..fe46c0e1 100644 --- a/patroni/postmaster.py +++ b/patroni/postmaster.py @@ -137,7 +137,7 @@ class PostmasterProcess(psutil.Process): # of init process to take care about postmaster. # In order to make everything portable we can't use fork&exec approach here, so we will call # ourselves and pass list of arguments which must be used to start postgres. - env = {p: os.environ[p] for p in ('PATH', 'LC_ALL', 'LANG') if p in os.environ} + env = {p: os.environ[p] for p in ('PATH', 'LD_LIBRARY_PATH', 'LC_ALL', 'LANG') if p in os.environ} try: proc = PostmasterProcess._from_pidfile(data_dir) if proc and not proc._is_postmaster_process(): From e939304001dbce26b895a0cc22b72722b14e5ecd Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Tue, 12 Jun 2018 14:04:32 +0200 Subject: [PATCH 25/63] Take and apply some parameters from controldata when starting as replica (#703) * Take and apply some parameters from controldata when starting as replica https://www.postgresql.org/docs/10/static/hot-standby.html#HOT-STANDBY-ADMIN There is set of parameters which value on the replica must be not smaller than on the primary, otherwise replica will refuse to start: * max_connections * max_prepared_transactions * max_locks_per_transaction * max_worker_processes It might happen that values of these parameters in the global configuration are not set high enough, what makes impossible to start a replica without human intervention. Usually it happens when we bootstrap a new cluster from the basebackup. As a solution to this problem we will take values of above parameters from the pg_controldata output and in case if the values in the global configuration are not high enough, apply values taken from pg_controldata and set `pending_restart` flag. --- features/environment.py | 7 ++++++ patroni/postgresql.py | 52 ++++++++++++++++++++++++++++++++-------- tests/test_postgresql.py | 17 +++++++++++++ 3 files changed, 66 insertions(+), 10 deletions(-) diff --git a/features/environment.py b/features/environment.py index 8a729995..376bb45a 100644 --- a/features/environment.py +++ b/features/environment.py @@ -612,6 +612,13 @@ class PatroniPoolController(object): 'method': 'pg_basebackup', 'pg_basebackup': { 'command': self.BACKUP_SCRIPT + ' --walmethod=stream --dbname=' + f.backup_source + }, + 'dcs': { + 'postgresql': { + 'parameters': { + 'max_connections': 101 + } + } } }, 'postgresql': { diff --git a/patroni/postgresql.py b/patroni/postgresql.py index 7a9034aa..6ccfba7f 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -403,7 +403,7 @@ class Postgresql(object): @property def sysid(self): - if not self._sysid: + if not self._sysid and not self.bootstrapping: data = self.controldata() self._sysid = data.get('Database system identifier', "") return self._sysid @@ -818,6 +818,34 @@ class Postgresql(object): logger.warning("Timed out waiting for PostgreSQL to start") return False + def _build_effective_configuration(self): + """It might happen that the current value of one (or more) below parameters stored in + the controldata is higher than the value stored in the global cluster configuration. + + Example: max_connections in global configuration is 100, but in controldata + `Current max_connections setting: 200`. If we try to start postgres with + max_connections=100, it will immediately exit. + As a workaround we will start it with the values from controldata and set `pending_restart` + to true as an indicator that current values of parameters are not matching expectations.""" + + OPTIONS_MAPPING = { + 'max_connections': 'max_connections setting', + 'max_worker_processes': 'max_worker_processes setting', + 'max_prepared_transactions': 'max_prepared_xacts setting', + 'max_locks_per_transaction': 'max_locks_per_xact setting' + } + + data = self.controldata() + effective_configuration = self._server_parameters.copy() + + for name, cname in OPTIONS_MAPPING.items(): + value = parse_int(effective_configuration[name]) + cvalue = parse_int(data[cname]) + if cvalue > value: + effective_configuration[name] = cvalue + self._pending_restart = True + return effective_configuration + def start(self, timeout=None, block_callbacks=False, task=None): """Start PostgreSQL @@ -843,12 +871,13 @@ class Postgresql(object): self.set_state('starting') self._pending_restart = False - self._write_postgresql_conf() + configuration = self._server_parameters if self.role == 'master' else self._build_effective_configuration() + self._write_postgresql_conf(configuration) self.resolve_connection_addresses() self._replace_pg_hba() - options = ['--{0}={1}'.format(p, self._server_parameters[p]) for p in self.CMDLINE_OPTIONS - if p in self._server_parameters and p != 'wal_keep_segments'] + options = ['--{0}={1}'.format(p, configuration[p]) for p in self.CMDLINE_OPTIONS + if p in configuration and p != 'wal_keep_segments'] with self._cancellable_lock: if self._is_cancelled: @@ -1053,7 +1082,7 @@ class Postgresql(object): self.set_state('restart failed ({0})'.format(self.state)) return ret - def _write_postgresql_conf(self): + def _write_postgresql_conf(self, configuration=None): # rename the original configuration if it is necessary if 'custom_conf' not in self.config and not os.path.exists(self._postgresql_base_conf): os.rename(self._postgresql_conf, self._postgresql_base_conf) @@ -1061,7 +1090,7 @@ class Postgresql(object): with open(self._postgresql_conf, 'w') as f: f.write(self._CONFIG_WARNING_HEADER) f.write("include '{0}'\n\n".format(self.config.get('custom_conf') or self._postgresql_base_conf_name)) - for name, value in sorted(self._server_parameters.items()): + for name, value in sorted((configuration or self._server_parameters).items()): if not self._running_custom_bootstrap or name != 'hba_file': f.write("{0} = '{1}'\n".format(name, value)) # when we are doing custom bootstrap we assume that we don't know superuser password @@ -1164,7 +1193,7 @@ class Postgresql(object): """ return the contents of pg_controldata, or non-True value if pg_controldata call failed """ result = {} # Don't try to call pg_controldata during backup restore - if not self.bootstrapping and self._version_file_exists() and self.state != 'creating replica': + if self._version_file_exists() and self.state != 'creating replica': try: data = subprocess.check_output([self._pgcommand('pg_controldata'), self._data_dir], env={'LANG': 'C', 'LC_ALL': 'C', 'PATH': os.environ['PATH']}) @@ -1587,9 +1616,12 @@ $$""".format(name, ' '.join(options)), name, password, password) self.restart() else: self._replace_pg_hba() - self.reload() - time.sleep(1) # give a time to postgres to "reload" configuration files - self.close_connection() # close connection to reconnect with a new password + if self.pending_restart: + self.restart() + else: + self.reload() + time.sleep(1) # give a time to postgres to "reload" configuration files + self.close_connection() # close connection to reconnect with a new password except Exception: logger.exception('post_bootstrap') task.complete(False) diff --git a/tests/test_postgresql.py b/tests/test_postgresql.py index 4e6c0f0e..fdb0c681 100644 --- a/tests/test_postgresql.py +++ b/tests/test_postgresql.py @@ -635,6 +635,12 @@ class TestPostgresql(unittest.TestCase): self.p.post_bootstrap({}, task) self.assertTrue(task.result) + self.p.bootstrap(config) + with patch.object(Postgresql, 'pending_restart', PropertyMock(return_value=True)), \ + patch.object(Postgresql, 'restart', Mock()) as mock_restart: + self.p.post_bootstrap({}, task) + mock_restart.assert_called_once() + self.p.bootstrap(config) self.p.set_state('stopped') self.p.reload_config({'authentication': {'superuser': {'username': 'p', 'password': 'p'}, @@ -971,3 +977,14 @@ class TestPostgresql(unittest.TestCase): self.p.cancel() type(self.p._cancellable).returncode = PropertyMock(side_effect=[None, -15]) self.p.cancel() + + @patch.object(Postgresql, 'get_postgres_role_from_data_directory', Mock(return_value='replica')) + def test__build_effective_configuration(self): + with patch.object(Postgresql, 'controldata', + Mock(return_value={'max_connections setting': '200', + 'max_worker_processes setting': '20', + 'max_prepared_xacts setting': '100', + 'max_locks_per_xact setting': '100'})): + self.p.cancel() + self.assertFalse(self.p.start()) + self.assertTrue(self.p.pending_restart) From 25371478101ca233f52fb407fda2764fb8be0489 Mon Sep 17 00:00:00 2001 From: Henning Jacobs Date: Tue, 12 Jun 2018 14:08:38 +0200 Subject: [PATCH 26/63] #694 handle configuration error (#695) It is possible to change a lot of parameters in runtime (including `restapi.listen`) by updating Patroni config file and sending SIGHUP to Patroni process. If something was misconfigured it was throwing a weird exception and breaking `restapi` thread. This PR improves friendliness of error message and avoids breaking of `restapi`. --- patroni/api.py | 37 ++++++++++++++++++++++++------------- tests/test_api.py | 18 ++++++++++++++---- 2 files changed, 38 insertions(+), 17 deletions(-) diff --git a/patroni/api.py b/patroni/api.py index 4b7d835b..de121b2e 100644 --- a/patroni/api.py +++ b/patroni/api.py @@ -8,7 +8,8 @@ import dateutil.parser import datetime from patroni.postgresql import PostgresConnectionException, PostgresException, Postgresql -from patroni.utils import deep_compare, parse_bool, patch_config, Retry, RetryFailedError, parse_int, tzutc +from patroni.utils import deep_compare, parse_bool, patch_config, Retry, \ + RetryFailedError, parse_int, split_host_port, tzutc from six.moves.BaseHTTPServer import BaseHTTPRequestHandler, HTTPServer from six.moves.socketserver import ThreadingMixIn from threading import Thread @@ -473,6 +474,7 @@ class RestApiServer(ThreadingMixIn, HTTPServer, Thread): def __init__(self, patroni, config): self.patroni = patroni + self.__listen = None self.__initialize(config) self.__set_config_parameters(config) self.daemon = True @@ -507,18 +509,25 @@ class RestApiServer(ThreadingMixIn, HTTPServer, Thread): def __get_ssl_options(config): return {option: config[option] for option in ['certfile', 'keyfile'] if option in config} - def __set_connection_string(self, connect_address): - self.connection_string = '{0}://{1}/patroni'.format(self.__protocol, connect_address or self.__listen) - def __set_config_parameters(self, config): self.__auth_key = base64.b64encode(config['auth'].encode('utf-8')).decode('utf-8') if 'auth' in config else None - self.__set_connection_string(config.get('connect_address')) + self.connection_string = '{0}://{1}/patroni'.format(self.__protocol, + config.get('connect_address') or self.__listen) def __initialize(self, config): - self.__ssl_options = self.__get_ssl_options(config) + try: + host, port = split_host_port(config['listen'], None) + except Exception: + raise ValueError('Invalid "restapi" config: expected : for "listen", but got "{0}"' + .format(config['listen'])) + + if self.__listen is not None: # changing config in runtime + self.shutdown() + self.__listen = config['listen'] - host, port = config['listen'].rsplit(':', 1) - HTTPServer.__init__(self, (host, int(port)), RestApiHandler) + self.__ssl_options = self.__get_ssl_options(config) + + HTTPServer.__init__(self, (host, port), RestApiHandler) Thread.__init__(self, target=self.serve_forever) self._set_fd_cloexec(self.socket) @@ -530,11 +539,13 @@ class RestApiServer(ThreadingMixIn, HTTPServer, Thread): import ssl self.socket = ssl.wrap_socket(self.socket, server_side=True, **self.__ssl_options) self.__protocol = 'https' - self.__set_connection_string(config.get('connect_address')) + return True def reload_config(self, config): - self.__set_config_parameters(config) - if self.__listen != config['listen'] or self.__ssl_options != self.__get_ssl_options(config): - self.shutdown() - self.__initialize(config) + if 'listen' not in config: # changing config in runtime + raise ValueError('Can not find "restapi.listen" config') + + elif (self.__listen != config['listen'] or self.__ssl_options != self.__get_ssl_options(config)) \ + and self.__initialize(config): self.start() + self.__set_config_parameters(config) diff --git a/tests/test_api.py b/tests/test_api.py index d4f0d97f..29bcabb4 100644 --- a/tests/test_api.py +++ b/tests/test_api.py @@ -123,16 +123,14 @@ class MockRequest(object): class MockRestApiServer(RestApiServer): - def __init__(self, Handler, request): + def __init__(self, Handler, request, config=None): self.socket = 0 self.serve_forever = Mock() BaseHTTPServer.HTTPServer.__init__ = Mock() MockRestApiServer._BaseServer__is_shut_down = Mock() MockRestApiServer._BaseServer__shutdown_request = True - config = {'listen': '127.0.0.1:8008', 'auth': 'test:test'} + config = config or {'listen': '127.0.0.1:8008', 'auth': 'test:test', 'certfile': 'dumb'} super(MockRestApiServer, self).__init__(MockPatroni(), config) - config['certfile'] = 'dumb' - self.reload_config(config) Handler(MockRequest(request), ('0.0.0.0', 8080), self) @@ -380,3 +378,15 @@ class TestRestApiHandler(unittest.TestCase): post = 'POST /failover HTTP/1.0' + self._authorization + '\nContent-Length: ' MockRestApiServer(RestApiHandler, post + '14\n\n{"leader":"1"}') MockRestApiServer(RestApiHandler, post + '37\n\n{"candidate":"2","scheduled_at": "1"}') + + +@patch('ssl.wrap_socket', Mock(return_value=0)) +class TestRestApiServer(unittest.TestCase): + + def test_reload_config(self): + bad_config = {'listen': 'foo'} + self.assertRaises(ValueError, MockRestApiServer, None, '', bad_config) + srv = MockRestApiServer(lambda a1, a2, a3: None, '') + self.assertRaises(ValueError, srv.reload_config, bad_config) + self.assertRaises(ValueError, srv.reload_config, {}) + srv.reload_config({'listen': '127.0.0.2:8008'}) From aadd39b0a45daa9cef7119cffbed4370b90693a3 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Tue, 12 Jun 2018 14:09:09 +0200 Subject: [PATCH 27/63] Do crash recovery only when we sure that postgres was running as master (#707) pg_controldata reports in this case: * 'in production' * 'shutting down' * 'in crash recovery' --- patroni/ha.py | 20 +++++--------------- tests/test_ha.py | 11 +---------- 2 files changed, 6 insertions(+), 25 deletions(-) diff --git a/patroni/ha.py b/patroni/ha.py index d8eca50a..f2bf6651 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -201,11 +201,6 @@ class Ha(object): self._async_executor.run_async(self.state_handler.rewind, (self.cluster.leader,)) return True - def _start_crash_recovery(self, msg): - self._async_executor.schedule(msg) - self._async_executor.run_async(self.state_handler.fix_cluster_state) - return msg - def recover(self): # Postgres is not running and we will restart in standby mode. Watchdog is not needed until we promote. self.watchdog.disable() @@ -226,10 +221,12 @@ class Ha(object): timeout = None data = self.state_handler.controldata() - if data.get('Database cluster state') == 'in production' and not self._crash_recovery_executed and \ - (self.cluster.is_unlocked() or self.state_handler.can_rewind): + if data.get('Database cluster state') in ('in production', 'shutting down', 'in crash recovery') and \ + not self._crash_recovery_executed and (self.cluster.is_unlocked() or self.state_handler.can_rewind): self._crash_recovery_executed = True - return self._start_crash_recovery('doing crash recovery in a single user mode') + self._async_executor.schedule('doing crash recovery in a single user mode') + self._async_executor.run_async(self.state_handler.fix_cluster_state) + return self._async_executor.scheduled_action self.load_cluster_from_dcs() @@ -244,13 +241,6 @@ class Ha(object): msg = "starting as a secondary" node_to_follow = self._get_node_to_follow(self.cluster) - # once we already tried to start postgres but failed, single user mode is a rescue in this case - if self.recovering and not self.state_handler.rewind_executed \ - and not self._crash_recovery_executed and self.state_handler.can_rewind \ - and data.get('Database cluster state') not in ('shut down', 'shut down in recovery'): - self.recovering = False - return self._start_crash_recovery('fixing cluster state in a single user mode') - self.recovering = True self._async_executor.schedule('restarting after failure') diff --git a/tests/test_ha.py b/tests/test_ha.py index 240a85f8..7bc170da 100644 --- a/tests/test_ha.py +++ b/tests/test_ha.py @@ -15,9 +15,9 @@ from patroni.utils import tzutc from test_etcd import socket_getaddrinfo, etcd_read, etcd_write, requests_get from test_postgresql import psycopg2_connect, MockPostmaster - SYSID = '12345678901' + def true(*args, **kwargs): return True @@ -207,15 +207,6 @@ class TestHa(unittest.TestCase): self.ha.cluster = get_cluster_initialized_with_leader() self.assertEquals(self.ha.run_cycle(), 'running pg_rewind from leader') - @patch.object(Postgresql, 'can_rewind', PropertyMock(return_value=True)) - @patch.object(Postgresql, 'fix_cluster_state', Mock()) - def test_single_user_after_recover_failed(self): - self.p.controldata = lambda: {'Database cluster state': 'in recovery', 'Database system identifier': SYSID} - self.p.is_running = false - self.p.follow = false - self.assertEquals(self.ha.run_cycle(), 'starting as a secondary') - self.assertEquals(self.ha.run_cycle(), 'fixing cluster state in a single user mode') - @patch('sys.exit', return_value=1) @patch('patroni.ha.Ha.sysid_valid', MagicMock(return_value=True)) def test_sysid_no_match(self, exit_mock): From cbd0a759c0c31bfc6ba57a6659f6037e35448ce1 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Tue, 12 Jun 2018 14:11:00 +0200 Subject: [PATCH 28/63] Relax kubernetes module version (#701) Patroni is proven to work with 2.0.0, 3.0.0 and 6.0.0 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 0a4bb6da..45d5bcde 100644 --- a/requirements.txt +++ b/requirements.txt @@ -13,4 +13,4 @@ tzlocal python-dateutil psutil cdiff -kubernetes==3.0.0 +kubernetes>=2.0.0,<=6.0.0,!=4.0.*,!=5.0.* From 41e5f58f2b9c3d63cc708d72b796c5c98eadb83a Mon Sep 17 00:00:00 2001 From: Oleksii Kliukin Date: Wed, 13 Jun 2018 11:12:22 +0200 Subject: [PATCH 29/63] Describe synchronous_mode_strict (#710) * Describe synchronous_mode_strict Per https://github.com/zalando/patroni/issues/709 --- docs/SETTINGS.rst | 1 + docs/replication_modes.rst | 9 +++++++++ 2 files changed, 10 insertions(+) diff --git a/docs/SETTINGS.rst b/docs/SETTINGS.rst index c09826db..7b9265cd 100644 --- a/docs/SETTINGS.rst +++ b/docs/SETTINGS.rst @@ -19,6 +19,7 @@ Bootstrap configuration - **maximum\_lag\_on\_failover**: the maximum bytes a follower may lag to be able to participate in leader election. - **master\_start\_timeout**: the amount of time a master is allowed to recover from failures before failover is triggered. Default is 300 seconds. When set to 0 failover is done immediately after a crash is detected if possible. When using asynchronous replication a failover can cause lost transactions. Best worst case failover time for master failure is: loop\_wait + master\_start\_timeout + loop\_wait, unless master\_start\_timeout is zero, in which case it's just loop\_wait. Set the value according to your durability/availability tradeoff. - **synchronous\_mode**: turns on synchronous replication mode. In this mode a replica will be chosen as synchronous and only the latest leader and synchronous replica are able to participate in leader election. Synchronous mode makes sure that successfully committed transactions will not be lost at failover, at the cost of losing availability for writes when Patroni cannot ensure transaction durability. See :ref:`replication modes documentation ` for details. + - **synchronous\_mode\_strict**: prevents disabling synchronous replication if no synchronous replicas are available, blocking all client writes to the master. See :ref:`replication modes documentation ` for details. - **postgresql**: - **use\_pg\_rewind**: whether or not to use pg_rewind - **use\_slots**: whether or not to use replication_slots. Must be False for PostgreSQL 9.3. You should comment out max_replication_slots before it becomes ineligible for leader status. diff --git a/docs/replication_modes.rst b/docs/replication_modes.rst index b7d12cda..8bf36d4b 100644 --- a/docs/replication_modes.rst +++ b/docs/replication_modes.rst @@ -42,6 +42,15 @@ Turning on ``synchronous_mode`` does not guarantee multi node durability of comm When ``synchronous_mode`` is on and a standby crashes, commits will block until next iteration of Patroni runs and switches the primary to standalone mode (worst case delay for writes ``ttl`` seconds, average case ``loop_wait``/2 seconds). Manually shutting down or restarting a standby will not cause a commit service interruption. Standby will signal the primary to release itself from synchronous standby duties before PostgreSQL shutdown is initiated. +When it is absolutely necessary to guarantee that each write is stored durably +on at least two nodes, enable ``synchronous_mode_strict`` in addition to the +``synchronous_node``. This parameter prevents Patroni from switching off the +synchronous replication on the primary when no synchronous standby candidates +are available. As a downside, the primary is not be available for writes +(unless the Postgres transaction explicitly turns of ``synchronous_mode``), +blocking all client write requests until at least one synchronous replica comes +up. + You can ensure that a standby never becomes the synchronous standby by setting ``nosync`` tag to true. This is recommended to set for standbys that are behind slow network connections and would cause performance degradation when becoming a synchronous standby. Synchronous mode can be switched on and off via Patroni REST interface. See :ref:`dynamic configuration ` for instructions. From 8a3b78ca7bb2bb6af1fe25921cfb5f08fe38325c Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Thu, 14 Jun 2018 13:17:50 +0200 Subject: [PATCH 30/63] Rest api thread can raise an exception during shutdown (#711) catch it and report --- patroni/__init__.py | 5 ++++- tests/test_patroni.py | 4 ++++ 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/patroni/__init__.py b/patroni/__init__.py index 40801f65..edf6cf10 100644 --- a/patroni/__init__.py +++ b/patroni/__init__.py @@ -129,7 +129,10 @@ class Patroni(object): signal.signal(signal.SIGTERM, self.sigterm_handler) def shutdown(self): - self.api.shutdown() + try: + self.api.shutdown() + except Exception: + logger.exception('Exception during RestApi.shutdown') self.ha.shutdown() diff --git a/tests/test_patroni.py b/tests/test_patroni.py index d4b46589..d3269798 100644 --- a/tests/test_patroni.py +++ b/tests/test_patroni.py @@ -151,3 +151,7 @@ class TestPatroni(unittest.TestCase): self.assertTrue(self.p.nosync) self.p.tags['nosync'] = None self.assertFalse(self.p.nosync) + + def test_shutdown(self): + self.p.api.shutdown = Mock(side_effect=Exception) + self.p.shutdown() From 959f254bfbc3477fc28b6463fa97dfae4a6dbcf3 Mon Sep 17 00:00:00 2001 From: Don Seiler Date: Wed, 20 Jun 2018 03:09:10 -0500 Subject: [PATCH 31/63] Adding patronictl reload functionality to reload from yaml config file (#716) Fixes https://github.com/zalando/patroni/issues/715 --- patroni/ctl.py | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/patroni/ctl.py b/patroni/ctl.py index 7f979861..ccb8309f 100644 --- a/patroni/ctl.py +++ b/patroni/ctl.py @@ -445,6 +445,33 @@ def parse_scheduled(scheduled): return None +@ctl.command('reload', help='Reload cluster member configuration') +@click.argument('cluster_name') +@click.argument('member_names', nargs=-1) +@click.option('--role', '-r', help='Reload only members with this role', default='any', + type=click.Choice(['master', 'replica', 'any'])) +@option_force +@click.pass_obj +def reload(obj, cluster_name, member_names, force, role): + cluster = get_dcs(obj, cluster_name).get_cluster() + + members = get_members(cluster, cluster_name, member_names, role, force, 'reload') + + content = {} + for member in members: + r = request_patroni(member, 'post', 'reload', content, auth_header(obj)) + if r.status_code == 200: + click.echo('No changes to apply on member {0}'.format(member.name)) + elif r.status_code == 202: + click.echo('Reload request received for member {0} and will be processed within {1} seconds'.format( + member.name, cluster.config.data.get('loop_wait')) + ) + else: + click.echo('Failed: reload for member {0}, status code={1}, ({2})'.format( + member.name, r.status_code, r.text) + ) + + @ctl.command('restart', help='Restart cluster member') @click.argument('cluster_name') @click.argument('member_names', nargs=-1) From 4128cba6286a2cd394edbe59c321bf4f555abc66 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Tue, 26 Jun 2018 13:48:16 +0100 Subject: [PATCH 32/63] max_worker_processes parameter was introduced only in 9.4 (#724) exclude it from the list on 9.3 when building effective configuration --- patroni/postgresql.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index e8e240eb..2e6e9b07 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -835,11 +835,13 @@ class Postgresql(object): OPTIONS_MAPPING = { 'max_connections': 'max_connections setting', - 'max_worker_processes': 'max_worker_processes setting', 'max_prepared_transactions': 'max_prepared_xacts setting', 'max_locks_per_transaction': 'max_locks_per_xact setting' } + if self._major_version >= 90400: + OPTIONS_MAPPING['max_worker_processes'] = 'max_worker_processes setting' + data = self.controldata() effective_configuration = self._server_parameters.copy() From 4e8709b26655402235b26085917657765eefb7f2 Mon Sep 17 00:00:00 2001 From: Don Seiler Date: Sat, 30 Jun 2018 16:16:42 -0500 Subject: [PATCH 33/63] Adding reload functionality (#726) This allows the config to be reloaded via `systemctl reload patroni`, sending SIGHUP to the patroni process. Tested on CentOS. --- extras/startup-scripts/patroni.service | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extras/startup-scripts/patroni.service b/extras/startup-scripts/patroni.service index 0be8f961..86a6f723 100644 --- a/extras/startup-scripts/patroni.service +++ b/extras/startup-scripts/patroni.service @@ -19,6 +19,9 @@ WorkingDirectory=~ ExecStart=/bin/patroni /etc/patroni.yml +# Send HUP to reload from patroni.yml +ExecReload=/bin/kill -s HUP $MAINPID + # only kill the patroni process, not it's children, so it will gracefully stop postgres KillMode=process From 50a8114d0bf1c41b27a505de78415bfac5722b24 Mon Sep 17 00:00:00 2001 From: Don Seiler Date: Wed, 4 Jul 2018 03:08:54 -0500 Subject: [PATCH 34/63] Use enforced minimums in postgresX.yml files (#730) Fix the discrepancy for the values of max_wal_senders and max_replication_slots between the sample postgres.yml files and hard-coded defaults in Patroni, bumping the former to 10. Contributed by @dtseiler --- postgres0.yml | 4 ++-- postgres1.yml | 4 ++-- postgres2.yml | 4 ++-- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/postgres0.yml b/postgres0.yml index d5425373..8d7ef60a 100644 --- a/postgres0.yml +++ b/postgres0.yml @@ -31,8 +31,8 @@ bootstrap: # wal_level: hot_standby # hot_standby: "on" # wal_keep_segments: 8 -# max_wal_senders: 5 -# max_replication_slots: 5 +# max_wal_senders: 10 +# max_replication_slots: 10 # wal_log_hints: "on" # archive_mode: "on" # archive_timeout: 1800s diff --git a/postgres1.yml b/postgres1.yml index 683bc965..9178b088 100644 --- a/postgres1.yml +++ b/postgres1.yml @@ -29,8 +29,8 @@ bootstrap: # wal_level: hot_standby # hot_standby: "on" # wal_keep_segments: 8 -# max_wal_senders: 5 -# max_replication_slots: 5 +# max_wal_senders: 10 +# max_replication_slots: 10 # wal_log_hints: "on" # archive_mode: "on" # archive_timeout: 1800s diff --git a/postgres2.yml b/postgres2.yml index b77f5bec..dcefe6f4 100644 --- a/postgres2.yml +++ b/postgres2.yml @@ -29,8 +29,8 @@ bootstrap: # wal_level: hot_standby # hot_standby: "on" # wal_keep_segments: 8 -# max_wal_senders: 5 -# max_replication_slots: 5 +# max_wal_senders: 10 +# max_replication_slots: 10 # wal_log_hints: "on" # archive_mode: "on" # archive_timeout: 1800s From 936a4238fb88ff31e4f4b7e46dd86e305d92072a Mon Sep 17 00:00:00 2001 From: alago197 <38751470+alago197@users.noreply.github.com> Date: Tue, 10 Jul 2018 15:40:53 +0200 Subject: [PATCH 35/63] Update some descriptions for the REST API endpoints (#729) * Update some descriptions for the REST API endpoints By @alago197 --- docs/SETTINGS.rst | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/SETTINGS.rst b/docs/SETTINGS.rst index 7b9265cd..542d8f1d 100644 --- a/docs/SETTINGS.rst +++ b/docs/SETTINGS.rst @@ -136,8 +136,8 @@ PostgreSQL REST API -------- -- **connect\_address**: IP address and port to access the REST API. -- **listen**: IP address and port that Patroni will listen to, to provide health-check information for HAProxy. +- **connect\_address**: IP address (or hostname) and port, to access the Patroni's REST API. It can serve as a endpoint for HTTP health checks (read below about the "listen" REST API parameter), and also for user queries (either directly or via the REST API), as well as for the health checks done by the cluster members during leader elections (for example, to determine whether the master is still running, or if there is a node which has a WAL position that is ahead of the one doing the query; etc.) The connect_address is put in the member key in DCS, making it possible to translate the member name into the address to connect to its REST API. +- **listen**: IP address (or hostname) and port that Patroni will listen to for the REST API - to provide also the same health checks and cluster messaging between the participating nodes, as described above. to provide health-check information for HAProxy (or any other load balancer capable of doing a HTTP "OPTION" or "GET" checks) - **Optional**: - **authentication**: - **username**: Basic-auth username to protect unsafe REST API endpoints. From 3b633abd918a4dd20021d8ec7d77674e3a9304da Mon Sep 17 00:00:00 2001 From: Ants Aasma Date: Tue, 17 Jul 2018 17:46:22 +0300 Subject: [PATCH 36/63] Improve logging when stale postmaster.pid matches running process (#738) Currently the informational message logged is beyond confusing. This improves the logging so there is some indication what this message is about and that it is somewhat normal. Changes by @ants --- patroni/postmaster.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/patroni/postmaster.py b/patroni/postmaster.py index fe46c0e1..d07a62f1 100644 --- a/patroni/postmaster.py +++ b/patroni/postmaster.py @@ -42,7 +42,8 @@ class PostmasterProcess(psutil.Process): try: start_time = int(self._postmaster_pid.get('start_time', 0)) if start_time and abs(self.create_time() - start_time) > 3: - logger.info('Too much difference between %s and %s', self.create_time(), start_time) + logger.info('Process %s is not postmaster, too much difference between PID file start time %s and ' + 'process start time %s', self.pid, self.create_time(), start_time) return False except ValueError: logger.warning('Garbage start time value in pid file: %r', self._postmaster_pid.get('start_time')) @@ -148,6 +149,7 @@ class PostmasterProcess(psutil.Process): # Important!!! Unlink of postmaster.pid isn't an option, because it has a lot of nasty race conditions. # Luckily there is a workaround to this problem, we can pass the pid from postmaster.pid # in the `PG_GRANDPARENT_PID` environment variable and postmaster will ignore it. + logger.info("Telling pg_ctl that it is safe to ignore postmaster.pid for process %s", proc.pid) env['PG_GRANDPARENT_PID'] = str(proc.pid) except psutil.NoSuchProcess: pass From 2356af679bebcb39905a0910fa85f97c75f1f83c Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Mon, 23 Jul 2018 15:56:51 +0300 Subject: [PATCH 37/63] Convert query params from list to dict (#744) Patroni is relying on params to determinte timeout and amount of retries when executing api requests to consul. Starting from v1.1.0 python-consul changed internal API and started using `list` instead of `dict` to pass query parameters. Such change broke "watch" functionality. Fixes https://github.com/zalando/patroni/issues/742 and https://github.com/zalando/patroni/issues/734 --- patroni/dcs/consul.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/patroni/dcs/consul.py b/patroni/dcs/consul.py index 6c319744..bde5542a 100644 --- a/patroni/dcs/consul.py +++ b/patroni/dcs/consul.py @@ -91,6 +91,8 @@ class HTTPClient(object): data = '{' + ttl + '}' else: data = data[:-1] + ', ' + ttl + '}' + if isinstance(params, list): # starting from v1.1.0 python-consul switched from `dict` to `list` for params + params = {k: v for k, v in params} kwargs = {'retries': 0, 'preload_content': False, 'body': data} if method == 'get' and isinstance(params, dict) and 'index' in params: kwargs['timeout'] = (float(params['wait'][:-1]) if 'wait' in params else 300) + 1 From c8f91999881dda96230fbf4c7565c4d77a5d1ea6 Mon Sep 17 00:00:00 2001 From: Tony Sorrentino <4976173+tonys66@users.noreply.github.com> Date: Mon, 23 Jul 2018 07:59:39 -0500 Subject: [PATCH 38/63] Added setting state to "stopped" when a member is stopped in Ha.shutdown (#733) Changes by @tonys66, review by @CyberDem0n --- patroni/ha.py | 1 + 1 file changed, 1 insertion(+) diff --git a/patroni/ha.py b/patroni/ha.py index f2bf6651..0b4f8299 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -1168,6 +1168,7 @@ class Ha(object): if not self.state_handler.is_running(): if self.has_lock(): self.dcs.delete_leader() + self.touch_member() else: # XXX: what about when Patroni is started as the wrong user that has access to the watchdog device # but cannot shut down PostgreSQL. Root would be the obvious example. Would be nice to not kill the From 26466237b99f9d2202bd8ad50ab45cd1781cd9cf Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Mon, 23 Jul 2018 17:41:17 +0300 Subject: [PATCH 39/63] Update docker-compose example to postgres 10 (#737) Some other changes are related to the new version of confd, which now requires specifying etcd url instead of etcd host. --- Dockerfile | 21 +++++++++------------ docker-compose.yml | 8 ++++---- docker/dev_patroni_cluster.sh | 2 +- docker/entrypoint.sh | 10 +++++----- extras/README.md | 2 +- 5 files changed, 20 insertions(+), 23 deletions(-) diff --git a/Dockerfile b/Dockerfile index d412ebd9..897de850 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,45 +1,42 @@ ## This Dockerfile is meant to aid in the building and debugging patroni whilst developing on your local machine ## It has all the necessary components to play/debug with a single node appliance, running etcd -FROM postgres:9.6 +FROM postgres:10 MAINTAINER Alexander Kukushkin RUN export DEBIAN_FRONTEND=noninteractive \ && echo 'APT::Install-Recommends "0";\nAPT::Install-Suggests "0";' > /etc/apt/apt.conf.d/01norecommend \ && apt-get update -y \ && apt-get upgrade -y \ - && apt-get install -y curl jq haproxy python-psycopg2 python-yaml python-requests python-six python-pysocks \ - python-dateutil python-pip python-setuptools python-prettytable python-wheel python-psutil python locales \ + # postgres:10 is based on debian, which has patroni package. We will install all required dependencies + && apt-get install -s patroni | sed -n -e '/^Inst patroni /d' -e 's/^Inst \([^ ]\+\) .*$/\1/p' \ + | xargs apt-get install -y curl jq haproxy locales python3-etcd python3-kazoo \ ## Make sure we have a en_US.UTF-8 locale available && localedef -i en_US -c -f UTF-8 -A /usr/share/locale/locale.alias en_US.UTF-8 \ - && pip install 'python-etcd>=0.4.3,<0.5' click tzlocal cdiff \ - && mkdir -p /home/postgres \ && chown postgres:postgres /home/postgres \ # Clean up - && apt-get remove -y python-pip python-setuptools \ + && apt-get purge -y libpython2.7-stdlib libpython2.7-minimal \ && apt-get autoremove -y \ && apt-get clean -y \ && rm -rf /var/lib/apt/lists/* /root/.cache -ENV ETCDVERSION 3.2.3 +ENV ETCDVERSION 3.2.23 RUN curl -L https://github.com/coreos/etcd/releases/download/v${ETCDVERSION}/etcd-v${ETCDVERSION}-linux-amd64.tar.gz \ | tar xz -C /usr/local/bin --strip=1 --wildcards --no-anchored etcd etcdctl -ENV CONFDVERSION 0.11.0 +ENV CONFDVERSION 0.16.0 RUN curl -L https://github.com/kelseyhightower/confd/releases/download/v${CONFDVERSION}/confd-${CONFDVERSION}-linux-amd64 > /usr/local/bin/confd \ && chmod +x /usr/local/bin/confd ADD patronictl.py patroni.py docker/entrypoint.sh / ADD patroni /patroni/ ADD extras/confd /etc/confd -RUN ln -s /patronictl.py /usr/local/bin/patronictl -### Setting up a simple script that will serve as an entrypoint -RUN mkdir /data/ && touch /pgpass /patroni.yml \ - && chown postgres:postgres -R /patroni/ /data/ /pgpass /patroni.yml /etc/haproxy /var/run/ /var/lib/ /var/log/ +RUN sed -i 's/env python/&3/' patroni*.py && ln -s /patronictl.py /usr/local/bin/patronictl && mkdir /data/ /run/haproxy \ + && touch /pgpass /patroni.yml && chown postgres:postgres -R /patroni/ /data/ /pgpass /patroni.yml /etc/haproxy /var/run/ /var/lib/ /var/log/ EXPOSE 2379 5432 8008 diff --git a/docker-compose.yml b/docker-compose.yml index b6824c91..bff610de 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -15,7 +15,7 @@ dbnode1: - ./patroni:/patroni env_file: docker/patroni-secrets.env environment: - PATRONI_ETCD_HOST: patroni_etcd:2379 + PATRONI_ETCD_URL: http://patroni_etcd:2379 PATRONI_NAME: dbnode1 PATRONI_SCOPE: testcluster @@ -28,7 +28,7 @@ dbnode2: - ./patroni:/patroni env_file: docker/patroni-secrets.env environment: - PATRONI_ETCD_HOST: patroni_etcd:2379 + PATRONI_ETCD_URL: http://patroni_etcd:2379 PATRONI_NAME: dbnode2 PATRONI_SCOPE: testcluster @@ -41,7 +41,7 @@ dbnode3: - ./patroni:/patroni env_file: docker/patroni-secrets.env environment: - PATRONI_ETCD_HOST: patroni_etcd:2379 + PATRONI_ETCD_URL: http://patroni_etcd:2379 PATRONI_NAME: dbnode3 PATRONI_SCOPE: testcluster @@ -53,6 +53,6 @@ haproxy: - "5000:5000" - "5001:5001" environment: - PATRONI_ETCD_HOST: patroni_etcd:2379 + PATRONI_ETCD_URL: http://patroni_etcd:2379 PATRONI_SCOPE: testcluster command: --confd diff --git a/docker/dev_patroni_cluster.sh b/docker/dev_patroni_cluster.sh index 9f21b128..2e21faac 100755 --- a/docker/dev_patroni_cluster.sh +++ b/docker/dev_patroni_cluster.sh @@ -84,7 +84,7 @@ function docker_run() ETCD_CONTAINER="${PATRONI_SCOPE}_etcd" docker_run ${ETCD_CONTAINER} ${DOCKER_IMAGE} --etcd -DOCKER_ARGS="--link=${ETCD_CONTAINER}:${ETCD_CONTAINER} -e PATRONI_SCOPE=${PATRONI_SCOPE} -e PATRONI_ETCD_HOST=${ETCD_CONTAINER}:2379" +DOCKER_ARGS="--link=${ETCD_CONTAINER}:${ETCD_CONTAINER} -e PATRONI_SCOPE=${PATRONI_SCOPE} -e PATRONI_ETCD_URL=http://${ETCD_CONTAINER}:2379" PATRONI_ENV=$(sed 's/#.*//g' docker/patroni-secrets.env | sed -n 's/^PATRONI_.*$/-e &/p' | tr '\n' ' ') PATRONI_VOLUME="-v $(dirname $(dirname $(realpath $0)))/patroni:/patroni" diff --git a/docker/entrypoint.sh b/docker/entrypoint.sh index 0796b70c..1daa9c8b 100755 --- a/docker/entrypoint.sh +++ b/docker/entrypoint.sh @@ -38,10 +38,10 @@ while getopts "$optspec" optchar; do done exec $CONFD zookeeper -node ${PATRONI_ZOOKEEPER_HOSTS} else - while ! curl -s ${PATRONI_ETCD_HOST}/v2/members | jq -r '.members[0].clientURLs[0]' | grep -q http; do + while ! curl -s ${PATRONI_ETCD_URL}/v2/members | jq -r '.members[0].clientURLs[0]' | grep -q http; do sleep 1 done - exec $CONFD etcd -node $PATRONI_ETCD_HOST + exec $CONFD etcd -node $PATRONI_ETCD_URL fi ;; etcd) @@ -74,9 +74,9 @@ while getopts "$optspec" optchar; do done ## We start an etcd -if [[ -z ${PATRONI_ETCD_HOST} && -z ${PATRONI_ZOOKEEPER_HOSTS} ]]; then +if [[ -z ${PATRONI_ETCD_URL} && -z ${PATRONI_ZOOKEEPER_HOSTS} ]]; then etcd $ETCD_ARGS > /var/log/etcd.log 2> /var/log/etcd.err & - export PATRONI_ETCD_HOST="127.0.0.1:2379" + export PATRONI_ETCD_URL="http://127.0.0.1:2379" fi export PATRONI_SCOPE @@ -108,7 +108,7 @@ __EOF__ mkdir -p "$HOME/.config/patroni" [ -h "$HOME/.config/patroni/patronictl.yaml" ] || ln -s /patroni.yml "$HOME/.config/patroni/patronictl.yaml" -[ -z $CHEAT ] && exec python /patroni.py /patroni.yml +[ -z $CHEAT ] && exec python3 /patroni.py /patroni.yml while true; do sleep 60 diff --git a/extras/README.md b/extras/README.md index a4c3d59a..03b7cf1a 100644 --- a/extras/README.md +++ b/extras/README.md @@ -3,7 +3,7 @@ `confd` directory contains haproxy template files for the [confd](https://github.com/kelseyhightower/confd) -- lightweight configuration management tool You need to copy content of `confd` directory into /etcd/confd and run confd service: ```bash -$ confd -prefix=/service/$PATRONI_SCOPE -backend etcd -node $PATRONI_ETCD_HOST -interval=10 +$ confd -prefix=/service/$PATRONI_SCOPE -backend etcd -node $PATRONI_ETCD_URL -interval=10 ``` It will periodically update haproxy.cfg with the actual list of Patroni nodes from `etcd` and "reload" haproxy when it is necessary. From f5927bad70eeff1b5b580c5df8c22d1d2002ba5f Mon Sep 17 00:00:00 2001 From: Don Seiler Date: Mon, 23 Jul 2018 12:31:47 -0500 Subject: [PATCH 40/63] Add EnvironmentFile directive (#746) Add an EnvironmentFile directive to read in a configuration file with environment variables. The "-" prefix means it can proceed if the file doesn't exist. This would allow users to keep sensitive information like the SUPERUSER/REPLICATION passwords in the config file separate from a YAML file that might be deployed from source control. --- extras/startup-scripts/patroni.service | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extras/startup-scripts/patroni.service b/extras/startup-scripts/patroni.service index 86a6f723..153ad2bd 100644 --- a/extras/startup-scripts/patroni.service +++ b/extras/startup-scripts/patroni.service @@ -11,6 +11,9 @@ Type=simple User=postgres Group=postgres +# Read in configuration file if it exists, otherwise proceed +EnvironmentFile=-/etc/patroni_env.conf + WorkingDirectory=~ # Where to send early-startup messages from the server From 00c2e1c2d092c59959d810b4f471f17c7871f4c4 Mon Sep 17 00:00:00 2001 From: Oleksii Kliukin Date: Mon, 23 Jul 2018 19:39:46 +0200 Subject: [PATCH 41/63] Grant delete on endpoints and configmaps in RBAC. (#749) 'patronictl remove' deletes the cluster configuration (stored either in configmaps or endpoints) and cannot be run from the postgres pod w/o 'delete' on those objects being granted to the pod service account. --- kubernetes/patroni_k8s.yaml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/kubernetes/patroni_k8s.yaml b/kubernetes/patroni_k8s.yaml index 71e82350..3fcadeed 100644 --- a/kubernetes/patroni_k8s.yaml +++ b/kubernetes/patroni_k8s.yaml @@ -145,6 +145,8 @@ rules: - patch - update - watch + # delete is required only for 'patronictl remove' + - delete - apiGroups: - "" resources: @@ -157,6 +159,8 @@ rules: - create - list - watch + # delete is required only for for 'patronictl remove' + - delete - apiGroups: - "" resources: From a2c6ed55044911e598ff24b939fcd27e33a64a67 Mon Sep 17 00:00:00 2001 From: Christoph Berg Date: Mon, 23 Jul 2018 20:42:33 +0200 Subject: [PATCH 42/63] async is a keyword in python3.7 (#751) * async is a keyword in python3.7 Setting up patroni (1.4.4-1) ... File "/usr/lib/python3/dist-packages/patroni/ha.py", line 610 'offline': dict(stop='fast', checkpoint=False, release=False, offline=True, async=False), ^ SyntaxError: invalid syntax Fix #750 by replacing dict member "async" with "async_req". * requirements.txt: Update for new kubernetes version compatible with 3.7 --- patroni/ha.py | 10 +++++----- requirements.txt | 2 +- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/patroni/ha.py b/patroni/ha.py index 0b4f8299..eaf16e72 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -597,10 +597,10 @@ class Ha(object): PostgreSQL as quickly as possible without regard for data durability. May only be called synchronously. """ mode_control = { - 'offline': dict(stop='fast', checkpoint=False, release=False, offline=True, async=False), - 'graceful': dict(stop='fast', checkpoint=True, release=True, offline=False, async=False), - 'immediate': dict(stop='immediate', checkpoint=False, release=True, offline=False, async=True), - 'immediate-nolock': dict(stop='immediate', checkpoint=False, release=False, offline=False, async=True), + 'offline': dict(stop='fast', checkpoint=False, release=False, offline=True, async_req=False), + 'graceful': dict(stop='fast', checkpoint=True, release=True, offline=False, async_req=False), + 'immediate': dict(stop='immediate', checkpoint=False, release=True, offline=False, async_req=True), + 'immediate-nolock': dict(stop='immediate', checkpoint=False, release=False, offline=False, async_req=True), }[mode] self.state_handler.trigger_check_diverged_lsn() @@ -620,7 +620,7 @@ class Ha(object): # FIXME: with mode offline called from DCS exception handler and handle_long_action_in_progress # there could be an async action already running, calling follow from here will lead # to racy state handler state updates. - if mode_control['async']: + if mode_control['async_req']: self._async_executor.schedule('starting after demotion') self._async_executor.run_async(self.state_handler.follow, (node_to_follow,)) else: diff --git a/requirements.txt b/requirements.txt index 45d5bcde..5684f0b7 100644 --- a/requirements.txt +++ b/requirements.txt @@ -13,4 +13,4 @@ tzlocal python-dateutil psutil cdiff -kubernetes>=2.0.0,<=6.0.0,!=4.0.*,!=5.0.* +kubernetes>=2.0.0,<=7.0.0,!=4.0.*,!=5.0.* From 2f7c53031c67b11400c46ce1ed34312ad22944a3 Mon Sep 17 00:00:00 2001 From: Henning Jacobs Date: Tue, 24 Jul 2018 10:51:25 +0200 Subject: [PATCH 43/63] Python 3.6 and 3.7 are now supported, too (#752) --- setup.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/setup.py b/setup.py index 2d28ebab..74322f8e 100644 --- a/setup.py +++ b/setup.py @@ -53,6 +53,8 @@ CLASSIFIERS = [ 'Programming Language :: Python :: 2.7', 'Programming Language :: Python :: 3.4', 'Programming Language :: Python :: 3.5', + 'Programming Language :: Python :: 3.6', + 'Programming Language :: Python :: 3.7', 'Programming Language :: Python :: Implementation :: CPython', ] From d47049ce0e70d6ab7689f0e7e43d910e2e72075f Mon Sep 17 00:00:00 2001 From: Oleksii Kliukin Date: Fri, 3 Aug 2018 16:45:33 +0200 Subject: [PATCH 44/63] Fix condition for the replica start due to pg_rewind in paused state. (#754) Avoid starting the replica that had already executed pg_rewind before. Fixes in #753 --- patroni/ha.py | 9 +++++++-- patroni/postgresql.py | 4 ++++ 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/patroni/ha.py b/patroni/ha.py index eaf16e72..f386bb00 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -1113,8 +1113,13 @@ class Ha(object): self.dcs.delete_leader() self.dcs.reset_cluster() return 'removed leader lock because postgres is not running' - elif not (self.state_handler.rewind_executed or - self.state_handler.need_rewind and self.state_handler.can_rewind): + # Normally we don't start Postgres in a paused state. We make an exception for the demoted primary + # that needs to be started after it had been stopped by demote. When there is no need to call rewind + # the demote code follows through to starting Postgres right away, however, in the rewind case + # it returns from demote and reaches this point to start PostgreSQL again after rewind. In that + # case it makes no sense to continue to recover() unless rewind has finished successfully. + elif (self.state_handler.rewind_failed or + not (self.state_handler.need_rewind and self.state_handler.can_rewind)): return 'postgres is not running' # try to start dead postgres diff --git a/patroni/postgresql.py b/patroni/postgresql.py index 2e6e9b07..789f4471 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -1398,6 +1398,10 @@ class Postgresql(object): def rewind_executed(self): return self._rewind_state > REWIND_STATUS.NOT_NEED + @property + def rewind_failed(self): + return self._rewind_state == REWIND_STATUS.FAILED + def follow(self, member, timeout=None): primary_conninfo = self.primary_conninfo(member) change_role = self.role in ('master', 'demoted') From 2fd25560504dfd2d0721cb53f2e3de479cce2f80 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Fri, 3 Aug 2018 16:59:04 +0200 Subject: [PATCH 45/63] Set role to demoted if postgres isn't running and no recovery.conf (#757) In really rare cases it was causing following behavior: ``` 2018-07-31 10:35:30,302 INFO: starting as a secondary 2018-07-31 10:35:30,309 INFO: Lock owner: postgresql0; I am postgresql1 2018-07-31 10:35:30,310 INFO: Demoting master during restarting after failure 2018-07-31 10:35:30,381 INFO: postmaster pid=17709 2018-07-31 10:35:30,386 INFO: lost leader lock during restarting after failure 2018-07-31 10:35:30,388 ERROR: Exception during CHECKPOINT ``` --- patroni/postgresql.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index 789f4471..4462c524 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -179,6 +179,8 @@ class Postgresql(object): self._write_postgresql_conf() # we are "joining" already running postgres if self._replace_pg_hba(): self.reload() + elif self.role == 'master': + self.set_role('demoted') @property def _create_replica_methods(self): From 0c1ae6fbebd888d4f2ab38928c9de9d9efeb97df Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Fri, 3 Aug 2018 17:00:01 +0200 Subject: [PATCH 46/63] Respond 200 to master health-check only if update_lock was successful (#713) If Patroni gets partitioned it starts receiving stale information from DCS. We can't use this information to determine that we have the leader key. Instead, we will record in Ha object the actual state of acquire/update lock and report as a leader only if it was successful. P.S. despite responding with 200 on `GET /master` postgres was still running read-only. --- patroni/api.py | 2 +- patroni/ha.py | 16 +++++++++++++++- tests/test_api.py | 6 +++++- tests/test_patroni.py | 1 + 4 files changed, 22 insertions(+), 3 deletions(-) diff --git a/patroni/api.py b/patroni/api.py index de121b2e..73cdb14c 100644 --- a/patroni/api.py +++ b/patroni/api.py @@ -92,7 +92,7 @@ class RestApiHandler(BaseHTTPRequestHandler): return response.get('role') == 'replica' and not patroni.noloadbalance if cluster: # dcs available - if cluster.leader and cluster.leader.name == patroni.postgresql.name: # is_leader + if patroni.ha.is_leader(): status_code = 200 if 'master' in path else 503 elif 'role' not in response: status_code = 503 diff --git a/patroni/ha.py b/patroni/ha.py index f386bb00..e6a9797d 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -57,6 +57,8 @@ class Ha(object): self.dcs = patroni.dcs self.cluster = None self.old_cluster = None + self._is_leader = False + self._is_leader_lock = RLock() self._was_paused = False self._leader_timeline = None self.recovering = False @@ -87,6 +89,14 @@ class Ha(object): def is_paused(self): return self.check_mode('pause') + def is_leader(self): + with self._is_leader_lock: + return self._is_leader + + def set_is_leader(self, value): + with self._is_leader_lock: + self._is_leader = value + def load_cluster_from_dcs(self): cluster = self.dcs.get_cluster() @@ -98,7 +108,9 @@ class Ha(object): self._leader_timeline = None if cluster.is_unlocked() else cluster.leader.timeline def acquire_lock(self): - return self.dcs.attempt_to_acquire_leader() + ret = self.dcs.attempt_to_acquire_leader() + self.set_is_leader(ret) + return ret def update_lock(self, write_leader_optime=False): last_operation = None @@ -108,6 +120,7 @@ class Ha(object): except Exception: logger.exception('Exception when called state_handler.last_operation()') ret = self.dcs.update_leader(last_operation) + self.set_is_leader(ret) if ret: self.watchdog.keepalive() return ret @@ -981,6 +994,7 @@ class Ha(object): logger.error('Cancelling bootstrap because watchdog activation failed') self.cancel_initialization() self.dcs.take_leader() + self.set_is_leader(True) self.state_handler.call_nowait(ACTION_ON_START) self.load_cluster_from_dcs() return 'initialized a new cluster' diff --git a/tests/test_api.py b/tests/test_api.py index 29bcabb4..ae0f1632 100644 --- a/tests/test_api.py +++ b/tests/test_api.py @@ -51,6 +51,10 @@ class MockHa(object): state_handler = MockPostgresql() watchdog = MockWatchdog() + @staticmethod + def is_leader(): + return False + @staticmethod def reinitialize(_): return 'reinitialize' @@ -152,7 +156,7 @@ class TestRestApiHandler(unittest.TestCase): MockRestApiServer(RestApiHandler, 'GET /synchronous') with patch.object(RestApiHandler, 'get_postgresql_status', Mock(return_value={'role': 'replica'})): MockRestApiServer(RestApiHandler, 'GET /asynchronous') - MockPatroni.dcs.cluster.leader.name = MockPostgresql.name + MockPatroni.ha.is_leader = Mock(return_value=True) MockRestApiServer(RestApiHandler, 'GET /replica') MockPatroni.dcs.cluster = None with patch.object(RestApiHandler, 'get_postgresql_status', Mock(return_value={'role': 'master'})): diff --git a/tests/test_patroni.py b/tests/test_patroni.py index d3269798..71bac6e5 100644 --- a/tests/test_patroni.py +++ b/tests/test_patroni.py @@ -103,6 +103,7 @@ class TestPatroni(unittest.TestCase): @patch('patroni.config.Config.save_cache', Mock()) @patch('patroni.config.Config.reload_local_configuration', Mock(return_value=True)) + @patch('patroni.ha.Ha.is_leader', Mock(return_value=True)) @patch.object(Postgresql, 'state', PropertyMock(return_value='running')) @patch.object(Postgresql, 'data_directory_empty', Mock(return_value=False)) def test_run(self): From 502094ee79bed4b2eead29c88239c6a1cb992b1d Mon Sep 17 00:00:00 2001 From: Don Seiler Date: Fri, 3 Aug 2018 10:00:57 -0500 Subject: [PATCH 47/63] Log config change or not (#731) This adds INFO log messages that clearly state if configuration values were seen as changed by Patroni after SIGHUP/reload and warrant reloading (or if nothing was changed an no reloading is necessary). This ended up being a lot simpler than I had imagined once I found postgresql.py:reload_config(). I add a log line in config.py:reload_local_configuration() since that function will short-circuit the process early if the local config wasn't changed. But the final determination of whether or not values have changed and need reloading is in postgresql.py:reload_config(). --- patroni/config.py | 2 ++ patroni/postgresql.py | 7 +++++++ 2 files changed, 9 insertions(+) diff --git a/patroni/config.py b/patroni/config.py index 89f1511c..ee809f5b 100644 --- a/patroni/config.py +++ b/patroni/config.py @@ -158,6 +158,8 @@ class Config(object): self._local_configuration = configuration self.__effective_configuration = new_configuration return True + else: + logger.info('No configuration items changed, nothing to reload.') except Exception: logger.exception('Exception when reloading local configuration from %s', self.config_file) if dry_run: diff --git a/patroni/postgresql.py b/patroni/postgresql.py index 4462c524..a963330f 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -337,10 +337,12 @@ class Postgresql(object): if new_value is None or not compare_values(r[3], unit, r[1], new_value): if r[4] == 'postmaster': pending_restart = True + logger.info('Changed %s from %s to %s (restart required)', r[0], r[1], new_value) if config.get('use_unix_socket') and r[0] == 'unix_socket_directories'\ or r[0] in ('listen_addresses', 'port'): local_connection_address_changed = True else: + logger.info('Changed %s from %s to %s', r[0], r[1], new_value) conf_changed = True for param in changes: if param in server_parameters: @@ -351,11 +353,13 @@ class Postgresql(object): if not conf_changed: for p, v in server_parameters.items(): if '.' in p and (p not in self._server_parameters or str(v) != str(self._server_parameters[p])): + logger.info('Changed %s from %s to %s', p, self._server_parameters.get(p), v) conf_changed = True break if not conf_changed: for p, v in self._server_parameters.items(): if '.' in p and (p not in server_parameters or str(v) != str(server_parameters[p])): + logger.info('Changed %s from %s to %s', p, v, server_parameters.get(p)) conf_changed = True break @@ -377,7 +381,10 @@ class Postgresql(object): self._replace_pg_hba() if conf_changed or hba_changed: + logger.info('PostgreSQL configuration items changed, reloading configuration.') self.reload() + elif not pending_restart: + logger.info('No PostgreSQL configuration items changed, nothing to reload.') self._is_leader_retry.deadline = self.retry.deadline = config['retry_timeout']/2.0 From 5e7345a2ca90ce1521f46d418aaede53402c5d35 Mon Sep 17 00:00:00 2001 From: Oleksii Kliukin Date: Fri, 3 Aug 2018 17:02:11 +0200 Subject: [PATCH 48/63] Release notes 1.4.5 (#762) bump version update release notes --- docs/releases.rst | 64 ++++++++++++++++++++++++++++++++++++++++++++++ patroni/version.py | 2 +- 2 files changed, 65 insertions(+), 1 deletion(-) diff --git a/docs/releases.rst b/docs/releases.rst index f2d30f58..da9e79e3 100644 --- a/docs/releases.rst +++ b/docs/releases.rst @@ -3,6 +3,70 @@ Release notes ============= +Version 1.4.5 +------------- + +**New features** + +- Improve logging when applying new postgres configuration (Don Seiler) + + Patroni logs changed parameter names and values. + +- Python 3.7 compatibility (Christoph Berg) + + async is a reserved keyword in python3.7 + +- Set state to "stopped" in the DCS when a member is shut down (Tony Sorrentino) + + This shows the member state as "stopped" in "patronictl list" command. + +- Improve the message logged when stale postmaster.pid matches a running process (Ants Aasma) + + The previous one was beyond confusing. + +- Implement patronictl reload functionality (Don Seiler) + + Before that it was only possible to reload configuration by either calling REST API or by sending SIGHUP signal to the Patroni process. + +- Take and apply some parameters from controldata when starting as a replica (Alexander Kukushkin) + + The value of `max_connections` and some other parameters set in the global configuration may be lower than the one actually used by the primary; when this happens, the replica cannot start and should be fixed manually. Patroni takes care of that now by reading and applying the value from `pg_controldata`, starting postgres and setting `pending_restart` flag. + +- If set, use LD_LIBRARY_PATH when starting postgres (Chris Fraser) + + When starting up Postgres, Patroni was passing along PATH, LC_ALL and LANG env vars if they are set. Now it is doing the same with LD_LIBRARY_PATH. It should help if somebody installed PostgreSQL to non-standard place. + +- Rename create_replica_method to create_replica_methods (Dmitry Dolgov) + + To make it clear that it's actually an array. The old name is still supported for backward compatibility. + +**Bug fixes and stability improvements** + +- Fix condition for the replica start due to pg_rewind in paused state (Oleksii Kliukin) + + Avoid starting the replica that had already executed pg_rewind before. + +- Respond 200 to the master health-check only if update_lock has been successful (Alexander) + + Prevent Patroni from reporting itself a master on the former (demoted) master if DCS is partitioned. + +- Fix compatibility with the new consul module (Alexander) + + Starting from v1.1.0 python-consul changed internal API and started using `list` instead of `dict` to pass query parameters. + +- Catch exceptions from Patroni REST API thread during shutdown (Alexander) + + Those uncaught exceptions kept PostgreSQL running at shutdown. + +- Do crash recovery only when Postgres runs as the master (Alexander) + + Require `pg_controldata` to report 'in production' or 'shutting down' or 'in crash recovery'. In all other cases no crash recovery is necessary. + +- Improve handling of configuration errors (Henning Jacobs, Alexander) + + It is possible to change a lot of parameters in runtime (including `restapi.listen`) by updating Patroni config file and sending SIGHUP to Patroni process. This fix eliminates obscure exceptions from the 'restapi' thread when some of the parameters receive invalid values. + + Version 1.4.4 ------------- diff --git a/patroni/version.py b/patroni/version.py index 9e0feee7..5e235ead 100644 --- a/patroni/version.py +++ b/patroni/version.py @@ -1 +1 @@ -__version__ = '1.4.4' +__version__ = '1.4.5' From b282a0f254d69604f4e66218af10c1968eed9953 Mon Sep 17 00:00:00 2001 From: Dmitry Dolgov <9erthalion6@gmail.com> Date: Mon, 13 Aug 2018 14:02:01 +0200 Subject: [PATCH 49/63] Add "cluster_unlocked" field (#764) Add a field to an api to figure out if a master is there from patroni point of view. It can be useful, when you have an alert, based on Auto Scaling Groups, and then ASG decided to shutdown the current master, spin up a new instance but the current master shutdown is stuck. In this situation the current master is no longer a part of ASG, but patroni and Postgres are still alive on the instance, which means a new replica will not be promoted yet - this will lead to a false alert, saying that your cluster doesn't have any master node. --- patroni/api.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/patroni/api.py b/patroni/api.py index 73cdb14c..56cbcc4f 100644 --- a/patroni/api.py +++ b/patroni/api.py @@ -415,6 +415,8 @@ class RestApiHandler(BaseHTTPRequestHandler): def get_postgresql_status(self, retry=False): try: + cluster = self.server.patroni.dcs.cluster + if self.server.patroni.postgresql.state not in ('running', 'restarting', 'starting'): raise RetryFailedError('') stmt = ("WITH replication_info AS (" @@ -439,6 +441,7 @@ class RestApiHandler(BaseHTTPRequestHandler): 'postmaster_start_time': row[0], 'role': 'replica' if row[1] == 0 else 'master', 'server_version': self.server.patroni.postgresql.server_version, + 'cluster_unlocked': bool(not cluster or cluster.is_unlocked()), 'xlog': ({ 'received_location': row[3], 'replayed_location': row[4], @@ -451,7 +454,6 @@ class RestApiHandler(BaseHTTPRequestHandler): if row[1] > 0: result['timeline'] = row[1] else: - cluster = self.server.patroni.dcs.cluster leader_timeline = None if not cluster or cluster.is_unlocked() else cluster.leader.timeline result['timeline'] = self.server.patroni.postgresql.replica_cached_timeline(leader_timeline) From b165183503b581ef129d007f4fb80913457e83e9 Mon Sep 17 00:00:00 2001 From: Oleksii Kliukin Date: Tue, 14 Aug 2018 17:08:08 +0200 Subject: [PATCH 50/63] Reset is_leader status on demote (#777) Make sure demoted cluster member stops responding with code 200 on the /master API call. Issue a new minor release. Fixes https://github.com/zalando/patroni/issues/776 --- docs/releases.rst | 17 +++++++++++++++++ patroni/ha.py | 4 ++++ patroni/version.py | 2 +- 3 files changed, 22 insertions(+), 1 deletion(-) diff --git a/docs/releases.rst b/docs/releases.rst index da9e79e3..5533f6ad 100644 --- a/docs/releases.rst +++ b/docs/releases.rst @@ -3,6 +3,23 @@ Release notes ============= +Version 1.4.6 +------------- + +**Bug fixes and stability improvements** + +This release fixes a critical issue with Patroni API /master endpoint returning 200 for the non-master node. This is a +reporting issue, no actual split-brain, but under certain circumstances clients might be directed to the read-only node. + +- Reset is_leader status on demote (Alexander Kukushkin, Oleksii Kliukin) + + Make sure demoted cluster member stops responding with code 200 on the /master API call. + +- Add new "cluster_unlocked" field to the API output (Dmitry Dolgov) + + This field indicates whether the cluster has the master running. It can be used when it is not possible to query any + other node but one of the replicas. + Version 1.4.5 ------------- diff --git a/patroni/ha.py b/patroni/ha.py index e6a9797d..509b96e1 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -105,6 +105,9 @@ class Ha(object): self.old_cluster = cluster self.cluster = cluster + if self.cluster.is_unlocked() or self.cluster.leader.name != self.state_handler.name: + self.set_is_leader(False) + self._leader_timeline = None if cluster.is_unlocked() else cluster.leader.timeline def acquire_lock(self): @@ -620,6 +623,7 @@ class Ha(object): self.state_handler.stop(mode_control['stop'], checkpoint=mode_control['checkpoint'], on_safepoint=self.watchdog.disable if self.watchdog.is_running else None) self.state_handler.set_role('demoted') + self.set_is_leader(False) if mode_control['release']: self.release_leader_key_voluntarily() diff --git a/patroni/version.py b/patroni/version.py index 5e235ead..adf1ed52 100644 --- a/patroni/version.py +++ b/patroni/version.py @@ -1 +1 @@ -__version__ = '1.4.5' +__version__ = '1.4.6' From 715caaddf3b861354ec2a1d18fb86edd4793e8ad Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Wed, 29 Aug 2018 11:09:35 +0200 Subject: [PATCH 51/63] Remove .zappr.yaml (#795) and switch to github approvals --- .zappr.yaml | 13 ------------- 1 file changed, 13 deletions(-) delete mode 100644 .zappr.yaml diff --git a/.zappr.yaml b/.zappr.yaml deleted file mode 100644 index d87f03fb..00000000 --- a/.zappr.yaml +++ /dev/null @@ -1,13 +0,0 @@ -# for github.com -approvals: - groups: - zalando: - minimum: 2 - from: - orgs: - - "zalando" -# team should be valid team id in team service https://teams.auth.zalando.com/api/teams/:id -X-Zalando-Team: "acid" -# type should be one of [code, doc, config, tools, secrets] -# code will be the default value, if X-Zalando-Type is not found in .zappr.yml -X-Zalando-Type: code From a513a7bb68f53ba92ca7441e50e62474894db999 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Wed, 29 Aug 2018 11:13:18 +0200 Subject: [PATCH 52/63] Improve stability of acceptance tests (#780) last time tests were failing due to postgres/patroni slowness in picking sync standby --- features/basic_replication.feature | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/features/basic_replication.feature b/features/basic_replication.feature index 24d0d28f..bc1f6286 100644 --- a/features/basic_replication.feature +++ b/features/basic_replication.feature @@ -14,12 +14,13 @@ Feature: basic replication Then table foo is present on postgres2 after 20 seconds Scenario: check restart of sync replica - Given I run patronictl.py restart batman postgres2 --force - And "sync" key in DCS has sync_standby=postgres1 after 2 seconds - And I run patronictl.py restart batman postgres1 --force - Then I receive a response returncode 0 - And "sync" key in DCS has sync_standby=postgres2 after 10 seconds - And I sleep for 2 seconds + Given I shut down postgres2 + Then "sync" key in DCS has sync_standby=postgres1 after 5 seconds + When I start postgres2 + And I shut down postgres1 + Then "sync" key in DCS has sync_standby=postgres2 after 10 seconds + When I start postgres1 + And "members/postgres1" key in DCS has state=running after 10 seconds When I issue a GET request to http://127.0.0.1:8010/sync Then I receive a response code 200 When I issue a GET request to http://127.0.0.1:8009/async From 518df2bc4939a8b69e3522b2377a83e694976d45 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Wed, 29 Aug 2018 11:28:46 +0200 Subject: [PATCH 53/63] Search new sync candidate amoung potential and async standbys (#794) In synchronos_mode_strict we put '*' into synchronos_standby_names, what makes one connection 'sync' and other connections 'potential'. The code picking up the correct sync standby didn't consider 'potential' as a good candidate. Fixes: https://github.com/zalando/patroni/issues/789 --- patroni/postgresql.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index a963330f..8498d76e 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -1733,7 +1733,7 @@ $$""".format(name, ' '.join(options)), name, password, password) if sync_state == 'potential' and app_name == current: # Prefer current even if not the best one any more to avoid indecisivness and spurious swaps. return current, False - if sync_state == 'async': + if sync_state in ('async', 'potential'): candidates.append(app_name) if candidates: From 87e9aab04c76744d5dd67c78bd7ef320b2993ed9 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Wed, 29 Aug 2018 11:29:37 +0200 Subject: [PATCH 54/63] Improve tests (#778) * Implement missing unit-tests * Add acceptance tests for ISSUE #776 * Update list of classifiers, keywords and authors --- features/patroni_api.feature | 16 ++++++++++++++++ setup.py | 12 ++++++++---- tests/test_config.py | 1 + tests/test_consul.py | 2 +- tests/test_ctl.py | 16 ++++++++++++++++ tests/test_ha.py | 3 +++ 6 files changed, 45 insertions(+), 5 deletions(-) diff --git a/features/patroni_api.feature b/features/patroni_api.feature index 05eedaf0..107a7199 100644 --- a/features/patroni_api.feature +++ b/features/patroni_api.feature @@ -71,6 +71,14 @@ Scenario: check the switchover via the API in the pause mode And postgres1 role is the primary after 10 seconds And postgres0 role is the secondary after 10 seconds And replication works from postgres1 to postgres0 after 20 seconds + When I issue a GET request to http://127.0.0.1:8008/master + Then I receive a response code 503 + When I issue a GET request to http://127.0.0.1:8008/replica + Then I receive a response code 200 + When I issue a GET request to http://127.0.0.1:8009/master + Then I receive a response code 200 + When I issue a GET request to http://127.0.0.1:8009/replica + Then I receive a response code 503 Scenario: check the scheduled switchover Given I issue a scheduled switchover from postgres1 to postgres0 in 3 seconds @@ -84,6 +92,14 @@ Scenario: check the scheduled switchover And postgres0 role is the primary after 10 seconds And postgres1 role is the secondary after 10 seconds And replication works from postgres0 to postgres1 after 25 seconds + When I issue a GET request to http://127.0.0.1:8008/master + Then I receive a response code 200 + When I issue a GET request to http://127.0.0.1:8008/replica + Then I receive a response code 503 + When I issue a GET request to http://127.0.0.1:8009/master + Then I receive a response code 503 + When I issue a GET request to http://127.0.0.1:8009/replica + Then I receive a response code 200 Scenario: check the scheduled restart Given I issue a PATCH request to http://127.0.0.1:8008/config with {"postgresql": {"parameters": {"superuser_reserved_connections": "6"}}} diff --git a/setup.py b/setup.py index 74322f8e..d81011ef 100644 --- a/setup.py +++ b/setup.py @@ -32,9 +32,10 @@ VERSION = read_version(MAIN_PACKAGE) DESCRIPTION = 'PostgreSQL High-Available orchestrator and CLI' LICENSE = 'The MIT License' URL = 'https://github.com/zalando/patroni' -AUTHOR = 'Alexander Kukushkin, Oleksii Kliukin, Feike Steenbergen' -AUTHOR_EMAIL = 'alexander.kukushkin@zalando.de, oleksii.kliukin@zalando.de, feike.steenbergen@zalando.de' -KEYWORDS = 'etcd governor patroni postgresql postgres ha haproxy confd zookeeper exhibitor consul streaming replication' +AUTHOR = 'Alexander Kukushkin, Dmitrii Dolgov, Oleksii Kliukin' +AUTHOR_EMAIL = 'alexander.kukushkin@zalando.de, dmitrii.dolgov@zalando.de, alexk@hintbits.com' +KEYWORDS = 'etcd governor patroni postgresql postgres ha haproxy confd' +\ + ' zookeeper exhibitor consul streaming replication kubernetes k8s' COVERAGE_XML = True COVERAGE_HTML = False @@ -43,14 +44,17 @@ JUNIT_XML = True # Add here all kinds of additional classifiers as defined under # https://pypi.python.org/pypi?%3Aaction=list_classifiers CLASSIFIERS = [ - 'Development Status :: 4 - Beta', + 'Development Status :: 5 - Production/Stable', 'Environment :: Console', 'Intended Audience :: Developers', 'Intended Audience :: System Administrators', 'License :: OSI Approved :: MIT License', + 'Operating System :: MacOS', 'Operating System :: POSIX :: Linux', + 'Operating System :: POSIX :: BSD :: FreeBSD', 'Programming Language :: Python', 'Programming Language :: Python :: 2.7', + 'Programming Language :: Python :: 3', 'Programming Language :: Python :: 3.4', 'Programming Language :: Python :: 3.5', 'Programming Language :: Python :: 3.6', diff --git a/tests/test_config.py b/tests/test_config.py index 26d64395..3d899e38 100644 --- a/tests/test_config.py +++ b/tests/test_config.py @@ -70,6 +70,7 @@ class TestConfig(unittest.TestCase): self.assertRaises(Exception, config.reload_local_configuration, True) self.assertTrue(config.reload_local_configuration(True)) self.assertTrue(config.reload_local_configuration()) + self.assertIsNone(config.reload_local_configuration()) @patch('tempfile.mkstemp', Mock(return_value=[3000, 'blabla'])) @patch('os.path.exists', Mock(return_value=True)) diff --git a/tests/test_consul.py b/tests/test_consul.py index fad173d2..496caaa2 100644 --- a/tests/test_consul.py +++ b/tests/test_consul.py @@ -62,7 +62,7 @@ class TestHTTPClient(unittest.TestCase): def test_put(self): self.client.put(Mock(), '/v1/session/create') - self.client.put(Mock(), '/v1/session/create', data='{"foo": "bar"}') + self.client.put(Mock(), '/v1/session/create', params=[], data='{"foo": "bar"}') @patch.object(consul.Consul.KV, 'get', kv_get) diff --git a/tests/test_ctl.py b/tests/test_ctl.py index 46987769..12b22770 100644 --- a/tests/test_ctl.py +++ b/tests/test_ctl.py @@ -225,6 +225,22 @@ class TestCtl(unittest.TestCase): result = self.runner.invoke(ctl, ['dsn', 'alpha', '--member', 'dummy']) assert result.exit_code == 1 + @patch('requests.post') + @patch('patroni.ctl.get_dcs') + def test_reload(self, mock_get_dcs, mock_post): + mock_get_dcs.return_value.get_cluster = get_cluster_initialized_with_leader + + result = self.runner.invoke(ctl, ['reload', 'alpha'], input='y') + assert 'Failed: reload for member' in result.output + + mock_post.return_value.status_code = 200 + result = self.runner.invoke(ctl, ['reload', 'alpha'], input='y') + assert 'No changes to apply on member' in result.output + + mock_post.return_value.status_code = 202 + result = self.runner.invoke(ctl, ['reload', 'alpha'], input='y') + assert 'Reload request received for member' in result.output + @patch('requests.post', requests_get) @patch('patroni.ctl.get_dcs') def test_restart_reinit(self, mock_get_dcs): diff --git a/tests/test_ha.py b/tests/test_ha.py index 7bc170da..b5364669 100644 --- a/tests/test_ha.py +++ b/tests/test_ha.py @@ -175,6 +175,9 @@ class TestHa(unittest.TestCase): self.p.replica_cached_timeline = Mock(side_effect=Exception) self.ha.touch_member() + def test_is_leader(self): + self.assertFalse(self.ha.is_leader()) + def test_start_as_replica(self): self.p.is_healthy = false self.assertEquals(self.ha.run_cycle(), 'starting as a secondary') From 5ca5dacaa9b5505ac6fe781f71f93c6761f92ecf Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Wed, 29 Aug 2018 11:30:01 +0200 Subject: [PATCH 55/63] Immediately reserve LSN on upon creation of replication slot (#783) This feature is available starting from 9.6 --- patroni/postgresql.py | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index 8498d76e..aecc8040 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -1560,11 +1560,13 @@ $$""".format(name, ' '.join(options)), name, password, password) if cursor.rowcount != 1: # Either slot doesn't exists or it is still active self._schedule_load_slots = True # schedule load_replication_slots on the next iteration + immediately_reserve = ', true' if self._major_version >= 90600 else '' + # create new slots for slot in slots - set(self._replication_slots): - self._query("""SELECT pg_create_physical_replication_slot(%s) + self._query("""SELECT pg_create_physical_replication_slot(%s{0}) WHERE NOT EXISTS (SELECT 1 FROM pg_replication_slots - WHERE slot_name = %s)""", slot, slot) + WHERE slot_name = %s)""".format(immediately_reserve), slot, slot) self._replication_slots = slots except Exception: From 2b87ae0cd08edca819a9a967d90e707644272a0a Mon Sep 17 00:00:00 2001 From: Jan Mussler Date: Wed, 29 Aug 2018 11:30:51 +0200 Subject: [PATCH 56/63] Add member name to error message. (#792) Analog to success message. --- patroni/ha.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/patroni/ha.py b/patroni/ha.py index 509b96e1..f0707b56 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -455,7 +455,7 @@ class Ha(object): logger.info('Got response from %s %s: %s', member.name, member.api_url, response.content) return _MemberStatus.from_api_response(member, response.json()) except Exception as e: - logger.warning("request failed: GET %s (%s)", member.api_url, e) + logger.warning("Request failed to %s: GET %s (%s)", member.name, member.api_url, e) return _MemberStatus.unknown(member) def fetch_nodes_statuses(self, members): From 90cf930036a9d5249265af15d2b787ec7517cf57 Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Wed, 29 Aug 2018 11:35:22 +0200 Subject: [PATCH 57/63] Refactor REST API health-checks (#779) Make it more readable and easy to understand. Mostly it is needed to implement https://github.com/zalando/patroni/issues/772 --- patroni/api.py | 41 +++++++++++++---------------------------- tests/test_api.py | 1 + 2 files changed, 14 insertions(+), 28 deletions(-) diff --git a/patroni/api.py b/patroni/api.py index 56cbcc4f..d2f52d03 100644 --- a/patroni/api.py +++ b/patroni/api.py @@ -84,35 +84,20 @@ class RestApiHandler(BaseHTTPRequestHandler): patroni = self.server.patroni cluster = patroni.dcs.cluster - def is_synchronous(): - return (cluster.is_synchronous_mode() and cluster.sync - and cluster.sync.sync_standby == patroni.postgresql.name) + replica_status_code = 200 if not patroni.noloadbalance and response.get('role') == 'replica' else 503 + status_code = 503 - def is_balanceable_replica(): - return response.get('role') == 'replica' and not patroni.noloadbalance - - if cluster: # dcs available - if patroni.ha.is_leader(): - status_code = 200 if 'master' in path else 503 - elif 'role' not in response: - status_code = 503 - elif response['role'] == 'master': # running as master but without leader lock!!!! - status_code = 503 - elif path in ('/sync', '/synchronous'): - status_code = 200 if is_balanceable_replica() and is_synchronous() else 503 - elif path in ('/async', '/asynchronous'): - status_code = 200 if is_balanceable_replica() and not is_synchronous() else 503 - elif response['role'] in path: # response['role'] != 'master' - status_code = 503 if patroni.noloadbalance else 200 - else: - status_code = 503 - elif 'role' in response and response['role'] in path: - status_code = 503 if response['role'] != 'master' and patroni.noloadbalance else 200 - elif patroni.ha.restart_scheduled() and patroni.postgresql.role == 'master' and 'master' in path: - # exceptional case for master node when the postgres is being restarted via API - status_code = 200 - else: - status_code = 503 + if 'master' in path: + status_code = 200 if patroni.ha.is_leader() else 503 + elif 'replica' in path: + status_code = replica_status_code + elif cluster: # dcs is available + is_synchronous = cluster.is_synchronous_mode() and cluster.sync \ + and cluster.sync.sync_standby == patroni.postgresql.name + if path in ('/sync', '/synchronous') and is_synchronous: + status_code = replica_status_code + elif path in ('/async', '/asynchronous') and not is_synchronous: + status_code = replica_status_code if write_status_code_only: # when haproxy sends OPTIONS request it reads only status code and nothing more message = self.responses[status_code][0] diff --git a/tests/test_api.py b/tests/test_api.py index ae0f1632..04979151 100644 --- a/tests/test_api.py +++ b/tests/test_api.py @@ -155,6 +155,7 @@ class TestRestApiHandler(unittest.TestCase): with patch.object(RestApiHandler, 'get_postgresql_status', Mock(return_value={'role': 'replica'})): MockRestApiServer(RestApiHandler, 'GET /synchronous') with patch.object(RestApiHandler, 'get_postgresql_status', Mock(return_value={'role': 'replica'})): + MockPatroni.dcs.cluster.sync.sync_standby = '' MockRestApiServer(RestApiHandler, 'GET /asynchronous') MockPatroni.ha.is_leader = Mock(return_value=True) MockRestApiServer(RestApiHandler, 'GET /replica') From 68c0d87d421476279b1e3ead84658f91a65b4d6a Mon Sep 17 00:00:00 2001 From: anikin-aa Date: Wed, 29 Aug 2018 17:06:06 +0300 Subject: [PATCH 58/63] check if output lines of controldata are possible to split (#797) Otherwise it fails with scary stacktrace --- patroni/postgresql.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index aecc8040..84b8963c 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -1216,7 +1216,8 @@ class Postgresql(object): if data: data = data.decode('utf-8').splitlines() # pg_controldata output depends on major verion. Some of parameters are prefixed by 'Current ' - result = {l.split(':')[0].replace('Current ', '', 1): l.split(':', 1)[1].strip() for l in data if l} + result = {l.split(':')[0].replace('Current ', '', 1): l.split(':', 1)[1].strip() for l in data + if l and ':' in l} except subprocess.CalledProcessError: logger.exception("Error when calling pg_controldata") return result From 0e13677880cf0d363163c2235d1cc54288dcbcf1 Mon Sep 17 00:00:00 2001 From: anikin-aa Date: Wed, 29 Aug 2018 17:07:01 +0300 Subject: [PATCH 59/63] exclude members with nofailover tag (#798) Exclude members with nofailover tag from `patronictl switchover/failover` output. Fixes https://github.com/zalando/patroni/issues/769 --- patroni/ctl.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/patroni/ctl.py b/patroni/ctl.py index ccb8309f..5be1fea9 100644 --- a/patroni/ctl.py +++ b/patroni/ctl.py @@ -585,7 +585,8 @@ def _do_failover_or_switchover(obj, action, cluster_name, master, candidate, for if master is not None and cluster.leader and cluster.leader.member.name != master: raise PatroniCtlException('Member {0} is not the leader of cluster {1}'.format(master, cluster_name)) - candidate_names = [str(m.name) for m in cluster.members if m.name != master] + # excluding members with nofailover tag + candidate_names = [str(m.name) for m in cluster.members if m.name != master and not m.nofailover] # We sort the names for consistent output to the client candidate_names.sort() From 0136f252ab79eed49d8740ba997af8f30d67bd85 Mon Sep 17 00:00:00 2001 From: wilfriedroset Date: Wed, 29 Aug 2018 16:08:13 +0200 Subject: [PATCH 60/63] Add patronictl -k/--insecure flag and suport for restapi cert (#790) Fixes https://github.com/zalando/patroni/issues/785 --- docs/SETTINGS.rst | 7 +++++++ patroni/ctl.py | 26 +++++++++++++++++++++++--- postgres0.yml | 5 +++++ postgres1.yml | 5 +++++ postgres2.yml | 5 +++++ tests/test_ctl.py | 7 +++++-- 6 files changed, 50 insertions(+), 5 deletions(-) diff --git a/docs/SETTINGS.rst b/docs/SETTINGS.rst index 542d8f1d..a7c68604 100644 --- a/docs/SETTINGS.rst +++ b/docs/SETTINGS.rst @@ -146,6 +146,13 @@ REST API - **certfile**: Specifies the file with the certificate in the PEM format. If the certfile is not specified or is left empty, the API server will work without SSL. - **keyfile**: Specifies the file with the secret key in the PEM format. +CTL +--- +- **Optional**: + - **insecure**: Allow connections to REST API without verifying SSL certs. + - **cacert**: Specifices the file with the CA_BUNDLE file or directory with certificates of trusted CAs to use while verifying REST API SSL certs. + - **certfile**: Specifies the file with the certificate in the PEM format to use while verifying REST API SSL certs. If not provided patronictl will use the value provided for REST API "certfile" parameter. + ZooKeeper ---------- - **hosts**: list of ZooKeeper cluster members in format: ['host1:port1', 'host2:port2', 'etc...']. diff --git a/patroni/ctl.py b/patroni/ctl.py index 5be1fea9..58d75d1e 100644 --- a/patroni/ctl.py +++ b/patroni/ctl.py @@ -103,15 +103,20 @@ option_watch = click.option('-W', is_flag=True, help='Auto update the screen eve option_force = click.option('--force', is_flag=True, help='Do not ask for confirmation at any point') arg_cluster_name = click.argument('cluster_name', required=False, default=lambda: click.get_current_context().obj.get('scope')) +option_insecure = click.option('-k', '--insecure', is_flag=True, help='Allow connections to SSL sites without certs') @click.group() @click.option('--config-file', '-c', help='Configuration file', default=CONFIG_FILE_PATH) @click.option('--dcs', '-d', help='Use this DCS', envvar='DCS') +@option_insecure @click.pass_context -def ctl(ctx, config_file, dcs): +def ctl(ctx, config_file, dcs, insecure): logging.basicConfig(format='%(asctime)s - %(levelname)s - %(message)s', level=os.environ.get('LOGLEVEL', 'WARNING')) + logging.captureWarnings(True) # Capture eventual SSL warning ctx.obj = load_config(config_file, dcs) + # backward compatibility for configuration file where ctl section is not define + ctx.obj.setdefault('ctl', {})['insecure'] = ctx.obj.get('ctl', {}).get('insecure') or insecure def get_dcs(config, scope): @@ -129,6 +134,7 @@ def auth_header(config): def request_patroni(member, request_type, endpoint, content=None, headers=None): + ctx = click.get_current_context() # the current click context headers = headers or {} url_parts = urlparse(member.api_url) logging.debug(url_parts) @@ -137,8 +143,21 @@ def request_patroni(member, request_type, endpoint, content=None, headers=None): url = '{0}://{1}/{2}'.format(url_parts.scheme, url_parts.netloc, endpoint) + insecure = ctx.obj.get('ctl', {}).get('insecure', False) + # Get certfile if any from several configuration namespace + cert = ctx.obj.get('ctl', {}).get('cacert') or \ + ctx.obj.get('restapi', {}).get('cacert') or \ + ctx.obj.get('restapi', {}).get('certfile') + # In the case we specificaly disable SSL cert verification we don't want to have the warning + if insecure: + verify = False + elif cert: + verify = cert + else: + verify = True return getattr(requests, request_type)(url, headers=headers, - data=json.dumps(content) if content else None, timeout=60) + data=json.dumps(content) if content else None, timeout=60, + verify=verify) def print_output(columns, rows=None, alignment=None, fmt='pretty', header=True, delimiter='\t'): @@ -903,7 +922,8 @@ def toggle_pause(config, cluster_name, paused, wait): for member in members: try: r = request_patroni(member, 'patch', 'config', {'pause': paused or None}, auth_header(config)) - except Exception: + except Exception as err: + logging.warning(str(err)) logging.warning('Member %s is not accessible', member.name) continue diff --git a/postgres0.yml b/postgres0.yml index 8d7ef60a..0f3a1935 100644 --- a/postgres0.yml +++ b/postgres0.yml @@ -11,6 +11,11 @@ restapi: # username: username # password: password +# ctl: +# insecure: false # Allow connections to SSL sites without certs +# certfile: /etc/ssl/certs/ssl-cert-snakeoil.pem +# cacert: /etc/ssl/certs/ssl-cacert-snakeoil.pem + etcd: host: 127.0.0.1:2379 diff --git a/postgres1.yml b/postgres1.yml index 9178b088..1ba9bd54 100644 --- a/postgres1.yml +++ b/postgres1.yml @@ -11,6 +11,11 @@ restapi: # username: username # password: password +# ctl: +# insecure: false # Allow connections to SSL sites without certs +# certfile: /etc/ssl/certs/ssl-cert-snakeoil.pem +# cacert: /etc/ssl/certs/ssl-cacert-snakeoil.pem + etcd: host: 127.0.0.1:2379 diff --git a/postgres2.yml b/postgres2.yml index dcefe6f4..684ec066 100644 --- a/postgres2.yml +++ b/postgres2.yml @@ -11,6 +11,11 @@ restapi: username: username password: password +# ctl: +# insecure: false # Allow connections to SSL sites without certs +# certfile: /etc/ssl/certs/ssl-cert-snakeoil.pem +# cacert: /etc/ssl/certs/ssl-cacert-snakeoil.pem + etcd: host: 127.0.0.1:2379 diff --git a/tests/test_ctl.py b/tests/test_ctl.py index 12b22770..e388d910 100644 --- a/tests/test_ctl.py +++ b/tests/test_ctl.py @@ -345,8 +345,11 @@ class TestCtl(unittest.TestCase): @patch('requests.post', Mock(side_effect=requests.exceptions.ConnectionError('foo'))) def test_request_patroni(self): - member = get_cluster_initialized_with_leader().leader.member - self.assertRaises(requests.exceptions.ConnectionError, request_patroni, member, 'post', 'dummy', {}) + context = {'restapi': {'keyfile': '/etc/patroni/key.pem', 'certfile': 'cert.pem'}} + with patch('click.get_current_context') as mock_context: + mock_context.return_value.obj = context + member = get_cluster_initialized_with_leader().leader.member + self.assertRaises(requests.exceptions.ConnectionError, request_patroni, member, 'post', 'dummy', {}) def test_ctl(self): self.runner.invoke(ctl, ['list']) From 4ca8a6e5066f02f773f4519f54ab7d2d69d2d73c Mon Sep 17 00:00:00 2001 From: Alexander Kukushkin Date: Thu, 6 Sep 2018 08:37:26 +0200 Subject: [PATCH 61/63] Make retries of calls to DCS consistent across implementations (#805) in addition to that do a small refactoring of zookeeper and consul and try to improve the stability of AT --- features/basic_replication.feature | 1 + patroni/__init__.py | 2 +- patroni/dcs/consul.py | 6 +-- patroni/dcs/etcd.py | 2 +- patroni/dcs/kubernetes.py | 2 +- patroni/dcs/zookeeper.py | 74 +++++++++++++----------------- patroni/postgresql.py | 2 +- tests/test_consul.py | 3 +- tests/test_zookeeper.py | 5 +- 9 files changed, 43 insertions(+), 54 deletions(-) diff --git a/features/basic_replication.feature b/features/basic_replication.feature index bc1f6286..8aa112fa 100644 --- a/features/basic_replication.feature +++ b/features/basic_replication.feature @@ -21,6 +21,7 @@ Feature: basic replication Then "sync" key in DCS has sync_standby=postgres2 after 10 seconds When I start postgres1 And "members/postgres1" key in DCS has state=running after 10 seconds + And I sleep for 2 seconds When I issue a GET request to http://127.0.0.1:8010/sync Then I receive a response code 200 When I issue a GET request to http://127.0.0.1:8009/async diff --git a/patroni/__init__.py b/patroni/__init__.py index edf6cf10..ee4c5824 100644 --- a/patroni/__init__.py +++ b/patroni/__init__.py @@ -188,7 +188,7 @@ def main(): if ret == (0, 0): break elif ret[0] != pid: - logging.info('Reaped pid=%s, exit status=%s', *ret) + logger.info('Reaped pid=%s, exit status=%s', *ret) except OSError: pass diff --git a/patroni/dcs/consul.py b/patroni/dcs/consul.py index bde5542a..6bcd3216 100644 --- a/patroni/dcs/consul.py +++ b/patroni/dcs/consul.py @@ -144,7 +144,6 @@ class Consul(AbstractDCS): retry_exceptions=(ConsulInternalError, HTTPException, HTTPError, socket.error, socket.timeout)) - self._my_member_data = {} kwargs = {} if 'url' in config: r = urlparse(config['url']) @@ -318,13 +317,12 @@ class Consul(AbstractDCS): except Exception: return False - if not create_member and member and deep_compare(data, self._my_member_data): + if not create_member and member and deep_compare(data, member.data): return True try: args = {} if permanent else {'acquire': self._session} self._client.kv.put(self.member_path, json.dumps(data, separators=(',', ':')), **args) - self._my_member_data = data return True except Exception: logger.exception('touch_member') @@ -408,7 +406,7 @@ class Consul(AbstractDCS): idx, _ = self._client.kv.get(self.leader_path, index=leader_index, wait=str(timeout) + 's') return str(idx) != str(leader_index) except (ConsulException, HTTPException, HTTPError, socket.error, socket.timeout): - logging.exception('watch') + logger.exception('watch') timeout = end_time - time.time() diff --git a/patroni/dcs/etcd.py b/patroni/dcs/etcd.py index a5809d1c..5d664a72 100644 --- a/patroni/dcs/etcd.py +++ b/patroni/dcs/etcd.py @@ -496,7 +496,7 @@ class Etcd(AbstractDCS): @catch_etcd_errors def touch_member(self, data, ttl=None, permanent=False): data = json.dumps(data, separators=(',', ':')) - return self.retry(self._client.set, self.member_path, data, None if permanent else ttl or self._ttl) + return self._client.set(self.member_path, data, None if permanent else ttl or self._ttl) @catch_etcd_errors def take_leader(self): diff --git a/patroni/dcs/kubernetes.py b/patroni/dcs/kubernetes.py index 842ec5ea..423a77fa 100644 --- a/patroni/dcs/kubernetes.py +++ b/patroni/dcs/kubernetes.py @@ -399,7 +399,7 @@ class Kubernetes(AbstractDCS): except KeyboardInterrupt: raise except Exception: - logging.exception('watch') + logger.exception('watch') timeout = end_time - time.time() diff --git a/patroni/dcs/zookeeper.py b/patroni/dcs/zookeeper.py index df476a4e..315258ae 100644 --- a/patroni/dcs/zookeeper.py +++ b/patroni/dcs/zookeeper.py @@ -59,7 +59,6 @@ class ZooKeeper(AbstractDCS): max_delay=1, max_tries=-1, sleep_func=time.sleep)) self._client.add_listener(self.session_listener) - self._my_member_data = {} self._fetch_cluster = True self._orig_kazoo_connect = self._client._connection._connect @@ -208,45 +207,52 @@ class ZooKeeper(AbstractDCS): self.cluster_watcher(None) raise ZooKeeperError('ZooKeeper in not responding properly') - def _create(self, path, value, **kwargs): + def _create(self, path, value, retry=False, ephemeral=False): try: - self._client.retry(self._client.create, path, value.encode('utf-8'), **kwargs) + if retry: + self._client.retry(self._client.create, path, value, makepath=True, ephemeral=ephemeral) + else: + self._client.create_async(path, value, makepath=True, ephemeral=ephemeral).get(timeout=1) return True except Exception: - return False + logger.exception('Failed to create %s', path) + return False def attempt_to_acquire_leader(self, permanent=False): - ret = self._create(self.leader_path, self._name, makepath=True, ephemeral=not permanent) + ret = self._create(self.leader_path, self._name.encode('utf-8'), retry=True, ephemeral=not permanent) if not ret: logger.info('Could not take out TTL lock') return ret - def __set_failover_or_sync_state_value(self, key, value, index=None): + def _set_or_create(self, key, value, index=None, retry=False, do_not_create_empty=False): + value = value.encode('utf-8') try: - self._client.retry(self._client.set, key, value.encode('utf-8'), version=index or -1) + if retry: + self._client.retry(self._client.set, key, value, version=index or -1) + else: + self._client.set_async(key, value, version=index or -1).get(timeout=1) return True except NoNodeError: - return value == '' or (index is None and self._create(key, value)) + if do_not_create_empty and not value: + return True + elif index is None: + return self._create(key, value, retry) + else: + return False except Exception: - logging.exception('set_failover_value') - return False + logger.exception('Failed to update %s', key) + return False def set_failover_value(self, value, index=None): - return self.__set_failover_or_sync_state_value(self.failover_path, value, index) + return self._set_or_create(self.failover_path, value, index) def set_config_value(self, value, index=None): - try: - self._client.retry(self._client.set, self.config_path, value.encode('utf-8'), version=index or -1) - return True - except NoNodeError: - return index is None and self._create(self.config_path, value) - except Exception: - logging.exception('set_config_value') - return False + return self._set_or_create(self.config_path, value, index, retry=True) def initialize(self, create_new=True, sysid=""): - return self._create(self.initialize_path, sysid, makepath=True) if create_new \ - else self._client.retry(self._client.set, self.initialize_path, sysid.encode("utf-8")) + sysid = sysid.encode('utf-8') + return self._create(self.initialize_path, sysid, retry=True) if create_new \ + else self._client.retry(self._client.set, self.initialize_path, sysid) def touch_member(self, data, ttl=None, permanent=False): cluster = self.cluster @@ -262,13 +268,12 @@ class ZooKeeper(AbstractDCS): member = None if member: - if deep_compare(data, self._my_member_data): + if deep_compare(data, member.data): return True else: try: self._client.create_async(self.member_path, encoded_data, makepath=True, ephemeral=not permanent).get(timeout=1) - self._my_member_data = data return True except Exception as e: if not isinstance(e, NodeExistsError): @@ -276,7 +281,6 @@ class ZooKeeper(AbstractDCS): return False try: self._client.set_async(self.member_path, encoded_data).get(timeout=1) - self._my_member_data = data return True except Exception: logger.exception('touch_member') @@ -286,30 +290,14 @@ class ZooKeeper(AbstractDCS): def take_leader(self): return self.attempt_to_acquire_leader() - def __write_leader_optime_or_history_value(self, key, value): - value = value.encode('utf-8') - try: - self._client.set_async(key, value).get(timeout=1) - return True - except NoNodeError: - try: - self._client.create_async(key, value, makepath=True).get(timeout=1) - return True - except Exception: - logger.exception('Failed to create %s', key) - except Exception: - logger.exception('Failed to update %s', key) - return False - def _write_leader_optime(self, last_operation): - return self.__write_leader_optime_or_history_value(self.leader_optime_path, last_operation) + return self._set_or_create(self.leader_optime_path, last_operation) def _update_leader(self): return True def delete_leader(self): self._client.restart() - self._my_member_data = None return True def _cancel_initialization(self): @@ -330,10 +318,10 @@ class ZooKeeper(AbstractDCS): return True def set_history_value(self, value): - return self.__write_leader_optime_or_history_value(self.history_path, value) + return self._set_or_create(self.history_path, value) def set_sync_state_value(self, value, index=None): - return self.__set_failover_or_sync_state_value(self.sync_path, value, index) + return self._set_or_create(self.sync_path, value, index, retry=True, do_not_create_empty=True) def delete_sync_state(self, index=None): return self.set_sync_state_value("{}", index) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index 84b8963c..b5c305b3 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -945,7 +945,7 @@ class Postgresql(object): return 'is_in_recovery=true' return cur.execute('CHECKPOINT') except psycopg2.Error: - logging.exception('Exception during CHECKPOINT') + logger.exception('Exception during CHECKPOINT') return 'not accessible or not healty' def stop(self, mode='fast', block_callbacks=False, checkpoint=None, on_safepoint=None): diff --git a/tests/test_consul.py b/tests/test_consul.py index 496caaa2..c26ca3c6 100644 --- a/tests/test_consul.py +++ b/tests/test_consul.py @@ -116,7 +116,8 @@ class TestConsul(unittest.TestCase): self.c.touch_member({'balbla': 'blabla'}) self.c.touch_member({'balbla': 'blabla'}) self.c.refresh_session = Mock(return_value=False) - self.c.touch_member({'balbla': 'blabla'}) + self.c.touch_member({'conn_url': 'postgres://replicator:rep-pass@127.0.0.1:5433/postgres', + 'api_url': 'http://127.0.0.1:8009/patroni'}) @patch.object(consul.Consul.KV, 'put', Mock(return_value=False)) def test_take_leader(self): diff --git a/tests/test_zookeeper.py b/tests/test_zookeeper.py index 452fd7df..d8de0680 100644 --- a/tests/test_zookeeper.py +++ b/tests/test_zookeeper.py @@ -156,7 +156,7 @@ class TestZooKeeper(unittest.TestCase): self.zk.set_failover_value('Exception') def test_set_config_value(self): - self.zk.set_config_value('') + self.zk.set_config_value('', 1) self.zk.set_config_value('ok') self.zk.set_config_value('Exception') @@ -179,7 +179,8 @@ class TestZooKeeper(unittest.TestCase): self.zk.touch_member({'retry': 'retry'}) self.zk._fetch_cluster = True self.zk.get_cluster() - self.zk.touch_member({'retry': 'retry'}) + self.zk.touch_member({'conn_url': 'postgres://repuser:rep-pass@localhost:5434/postgres', + 'api_url': 'http://127.0.0.1:8009/patroni'}) def test_take_leader(self): self.zk.take_leader() From dd7c3c349f64391f7310904d061c178376687470 Mon Sep 17 00:00:00 2001 From: Dmitry Dolgov <9erthalion6@gmail.com> Date: Fri, 7 Sep 2018 10:10:56 +0200 Subject: [PATCH 62/63] [WIP] Standby cluster implementation (#679) Implementation of "standby cluster" described in #657. Standby cluster consists of a "standby leader", that replicates from a "remote master" (which is not a part of current patroni cluster and can be anywhere), and cascade replicas, that replicate from the corresponding standby leader. "Standby leader" behaves pretty much like a regular leader, which means that it holds a leader lock in DSC, in case if disappears there will be an election of a new "standby leader". One can define such a cluster using the section "standby_cluster" in patroni config file. This section provides parameters for standby cluster, that will be applied only once during bootstrap and can be changed only through DSC. --- docs/SETTINGS.rst | 8 ++ docs/replica_bootstrap.rst | 32 +++++++ features/basic_replication.feature | 2 +- features/standby_cluster.feature | 16 ++++ features/steps/standby_cluster.py | 78 ++++++++++++++++ patroni/config.py | 34 ++++++- patroni/dcs/__init__.py | 56 ++++++++++- patroni/ha.py | 107 ++++++++++++++++++--- patroni/postgresql.py | 36 ++++++-- postgres0.yml | 4 + tests/test_config.py | 2 +- tests/test_ctl.py | 15 +-- tests/test_ha.py | 144 +++++++++++++++++++++++++++-- tests/test_postgresql.py | 4 +- 14 files changed, 497 insertions(+), 41 deletions(-) create mode 100644 features/standby_cluster.feature create mode 100644 features/steps/standby_cluster.py diff --git a/docs/SETTINGS.rst b/docs/SETTINGS.rst index a7c68604..0ce1ba5b 100644 --- a/docs/SETTINGS.rst +++ b/docs/SETTINGS.rst @@ -25,6 +25,14 @@ Bootstrap configuration - **use\_slots**: whether or not to use replication_slots. Must be False for PostgreSQL 9.3. You should comment out max_replication_slots before it becomes ineligible for leader status. - **recovery\_conf**: additional configuration settings written to recovery.conf when configuring follower. - **parameters**: list of configuration settings for Postgres. Many of these are required for replication to work. + - **standby\_cluster**: if this section is defined, we want to bootstrap a standby cluster. + - **host**: an address of remote master + - **port**: a port of remote master + - **primary\_slot\_name**: which slot on the remote master to use for replication. This parameter is optional, the default value is derived from the instance name (see function `slot_name_from_member_name`). + - **create\_replica\_methods**: an ordered list of methods that can be used to bootstrap standby leader from the remote master, can be different from the list defined in :ref:`postgresql_settings` + - **restore\_command**: command to restore WAL records from the remote master to standby leader, can be different from the list defined in :ref:`postgresql_settings` + - **archive\_cleanup\_command**: cleanup command for standby leader + - **recovery\_min\_apply\_delay**: how long to wait before actually apply WAL records on a standby leader - **method**: custom script to use for bootstrapping this cluster. See :ref:`custom bootstrap methods documentation ` for details. When ``initdb`` is specified revert to the default ``initdb`` command. ``initdb`` is also triggered when no ``method`` diff --git a/docs/replica_bootstrap.rst b/docs/replica_bootstrap.rst index d5d79155..3f832a89 100644 --- a/docs/replica_bootstrap.rst +++ b/docs/replica_bootstrap.rst @@ -129,3 +129,35 @@ and - max-rate: '100M' If all replica creation methods fail, Patroni will try again all methods in order during the next event loop cycle. + +Standby cluster +--------------- + +Another available option is to run a "standby cluster", that contains only of +standby nodes replicating from some remote master. This type of clusters has: + +* "standby leader", that behaves pretty much like a regular cluster leader, + except it replicates from a remote master. + +* cascade replicas, that are replicating from standby leader. + +Standby leader holds and updates a leader lock in DCS. If the leader lock +expires, cascade replicas will perform an election to choose another leader +from the standbys. For the sake of flexibility, you can specify different +methods of creating a replica and recovery WAL records when a cluster is in the +"standby mode", and after it was detached to function as a normal cluster. + +To configure such cluster you need to specify the section ``standby_cluster`` +in a patroni configuration: + +.. code:: YAML + + bootstrap: + dcs: + standby_cluster: + host: 1.2.3.4 + port: 5432 + primary_slot_name: patroni + +Note, that these options will be applied only once during cluster bootstrap, +and the only way to change them afterwards is through DCS. diff --git a/features/basic_replication.feature b/features/basic_replication.feature index 8aa112fa..e0eafc2a 100644 --- a/features/basic_replication.feature +++ b/features/basic_replication.feature @@ -32,7 +32,7 @@ Feature: basic replication Then I receive a response returncode 0 When I sleep for 2 seconds And I shut down postgres0 - And I run patronictl.py resume batman + And I run patronictl.py resume batman Then I receive a response returncode 0 And postgres2 role is the primary after 24 seconds When I issue a PATCH request to http://127.0.0.1:8010/config with {"synchronous_mode": null, "master_start_timeout": 0} diff --git a/features/standby_cluster.feature b/features/standby_cluster.feature new file mode 100644 index 00000000..51127efe --- /dev/null +++ b/features/standby_cluster.feature @@ -0,0 +1,16 @@ +Feature: standby cluster + + Scenario: check replication of a single table in a standby cluster + Given I start postgres0 without slots sync + And I create a replication slot postgres1 on postgres0 + And I start postgres1 in a standby cluster batman1 as a clone of postgres0 + Then postgres1 is a leader of batman1 after 10 seconds + When I add the table foo to postgres0 + Then table foo is present on postgres1 after 20 seconds + When I start postgres2 in a cluster batman1 + Then postgres2 role is the replica after 24 seconds + And table foo is present on postgres2 after 20 seconds + + Scenario: check failover + When I kill postgres1 + Then postgres2 is replicating from postgres0 after 20 seconds diff --git a/features/steps/standby_cluster.py b/features/steps/standby_cluster.py new file mode 100644 index 00000000..6eb8975d --- /dev/null +++ b/features/steps/standby_cluster.py @@ -0,0 +1,78 @@ +import time + +from behave import step + + +select_replication_query = """ +SELECT * FROM pg_catalog.pg_stat_replication +WHERE application_name = '{0}' +""" + +create_replication_slot_query = """ +SELECT pg_create_physical_replication_slot('{0}') +""" + + +@step('I start {name:w} without slots sync') +def start_patroni_without_slots_sync(context, name): + return context.pctl.start(name, custom_config={ + "bootstrap": { + "dcs": { + "postgresql": { + "use_slots": False + } + } + } + }) + + +@step('I start {name:w} in a cluster {cluster_name:w}') +def start_patroni(context, name, cluster_name): + return context.pctl.start(name, custom_config={ + "scope": cluster_name + }) + + +@step('I start {name:w} in a standby cluster {cluster_name:w} as a clone of {name2:w}') +def start_patroni_stanby_cluster(context, name, cluster_name, name2): + port = context.pctl._processes[name2]._connkwargs.get('port') + return context.pctl.start(name, custom_config={ + "scope": cluster_name, + "bootstrap": { + "dcs": { + "standby_cluster": { + "host": "localhost", + "port": port, + "primary_slot_name": "postgres1", + } + } + } + }) + + +@step('{pg_name1:w} is replicating from {pg_name2:w} after {timeout:d} seconds') +def check_replication_status(context, pg_name1, pg_name2, timeout): + bound_time = time.time() + timeout + + while time.time() < bound_time: + cur = context.pctl.query( + pg_name2, + select_replication_query.format(pg_name1), + fail_ok=True + ) + + if cur and len(cur.fetchall()) != 0: + return True + + time.sleep(1) + + return False + + +@step('I create a replication slot {slot_name:w} on {pg_name:w}') +def create_replication_slot(context, slot_name, pg_name): + return context.pctl.query( + pg_name, + create_replication_slot_query.format(slot_name), + fail_ok=True + ) diff --git a/patroni/config.py b/patroni/config.py index ee809f5b..dc8a6045 100644 --- a/patroni/config.py +++ b/patroni/config.py @@ -1,13 +1,14 @@ import json import logging import os +import six import sys import tempfile import yaml from collections import defaultdict from copy import deepcopy -from patroni.dcs import ClusterConfig +from patroni.dcs import ClusterConfig, is_standby_cluster from patroni.postgresql import Postgresql from patroni.utils import deep_compare, parse_bool, parse_int, patch_config from requests.structures import CaseInsensitiveDict @@ -45,6 +46,15 @@ class Config(object): 'master_start_timeout': 300, 'synchronous_mode': False, 'synchronous_mode_strict': False, + 'standby_cluster': { + 'create_replica_methods': '', + 'host': '', + 'port': '', + 'primary_slot_name': '', + 'restore_command': '', + 'archive_cleanup_command': '', + 'recovery_min_apply_delay': '' + }, 'postgresql': { 'bin_dir': '', 'use_slots': True, @@ -88,6 +98,10 @@ class Config(object): def dynamic_configuration(self): return deepcopy(self._dynamic_configuration) + @property + def is_standby_cluster(self): + return is_standby_cluster(self._dynamic_configuration.get('standby_cluster')) + def check_mode(self, mode): return bool(parse_bool(self._dynamic_configuration.get(mode))) @@ -183,6 +197,13 @@ class Config(object): config['postgresql'][name].update(self._process_postgresql_parameters(value)) elif name not in ('connect_address', 'listen', 'data_dir', 'pgpass', 'authentication'): config['postgresql'][name] = deepcopy(value) + elif name == 'standby_cluster': + allowed_keys = self.__DEFAULT_CONFIG['standby_cluster'].keys() + expected = { + k: v for k, v in (value or {}).items() + if (k in allowed_keys and isinstance(v, six.string_types)) + } + config['standby_cluster'].update(expected) elif name in config: # only variables present in __DEFAULT_CONFIG allowed to be overriden from DCS if name in ('synchronous_mode', 'synchronous_mode_strict'): config[name] = value @@ -317,8 +338,15 @@ class Config(object): if 'name' not in config and 'name' in pg_config: config['name'] = pg_config['name'] - pg_config.update({p: config[p] for p in ('name', 'scope', 'retry_timeout', - 'synchronous_mode', 'maximum_lag_on_failover') if p in config}) + updated_fields = ( + 'name', + 'scope', + 'retry_timeout', + 'synchronous_mode', + 'maximum_lag_on_failover' + ) + + pg_config.update({p: config[p] for p in updated_fields if p in config}) return config diff --git a/patroni/dcs/__init__.py b/patroni/dcs/__init__.py index 346a22b0..8d050fd5 100644 --- a/patroni/dcs/__init__.py +++ b/patroni/dcs/__init__.py @@ -108,12 +108,29 @@ class Member(namedtuple('Member', 'index,name,session,data')): @property def conn_url(self): - return self.data.get('conn_url') + conn_url = self.data.get('conn_url') + conn_kwargs = self.data.get('conn_kwargs') + if conn_url: + return conn_url + + if conn_kwargs: + conn_url = 'postgresql://{host}:{port}'.format( + host=conn_kwargs.get('host'), + port=conn_kwargs.get('port'), + ) + self.data['conn_url'] = conn_url + return conn_url def conn_kwargs(self, auth=None): + defaults = { + "host": "", + "port": "", + "database": "" + } ret = self.data.get('conn_kwargs') if ret: - ret = ret.copy() + defaults.update(ret) + ret = defaults else: r = urlparse(self.conn_url) ret = { @@ -159,6 +176,27 @@ class Member(namedtuple('Member', 'index,name,session,data')): return self.state == 'running' +class RemoteMember(Member): + """ Represents a remote master for a standby cluster + """ + def __new__(cls, name, data): + return super(RemoteMember, cls).__new__(cls, None, name, None, data) + + @staticmethod + def allowed_keys(): + return ('primary_slot_name', + 'create_replica_methods', + 'restore_command', + 'archive_cleanup_command', + 'recovery_min_apply_delay') + + def __getattr__(self, name): + if name not in RemoteMember.allowed_keys(): + return + + return self.data.get(name) + + class Leader(namedtuple('Leader', 'index,session,member')): """Immutable object (namedtuple) which represents leader key. @@ -359,6 +397,9 @@ class Cluster(namedtuple('Cluster', 'initialize,config,leader,last_leader_operat def is_synchronous_mode(self): return self.check_mode('synchronous_mode') + def is_standby_cluster(self): + return is_standby_cluster(self.config and self.config.data.get('standby_cluster')) + @six.add_metaclass(abc.ABCMeta) class AbstractDCS(object): @@ -612,3 +653,14 @@ class AbstractDCS(object): self.event.wait(timeout) return self.event.isSet() + + +def is_standby_cluster(config): + """ Check whether or not provided configuration describes a standby cluster. + Config can be both patroni config or cluster.config.data + """ + return isinstance(config, dict) and ( + config.get('host') or + config.get('port') or + config.get('restore_command') + ) diff --git a/patroni/ha.py b/patroni/ha.py index f0707b56..0a712dd7 100644 --- a/patroni/ha.py +++ b/patroni/ha.py @@ -6,6 +6,7 @@ import psycopg2 import requests import sys import time +import uuid from collections import namedtuple from multiprocessing.pool import ThreadPool @@ -13,6 +14,7 @@ from patroni.async_executor import AsyncExecutor, CriticalTask from patroni.exceptions import DCSError, PostgresConnectionException, PatroniException from patroni.postgresql import ACTION_ON_START from patroni.utils import polling_loop, tzutc +from patroni.dcs import RemoteMember from threading import RLock logger = logging.getLogger(__name__) @@ -193,14 +195,24 @@ class Ha(object): self._async_executor.schedule('bootstrap {0}'.format(msg)) self._async_executor.run_async(self.clone, args=(clone_member, msg)) return 'trying to bootstrap {0}'.format(msg) + # no initialize key and node is allowed to be master and has 'bootstrap' section in a configuration file elif self.cluster.initialize is None and not self.patroni.nofailover and 'bootstrap' in self.patroni.config: if self.dcs.initialize(create_new=True): # race for initialization self.state_handler.bootstrapping = True self._post_bootstrap_task = CriticalTask() - self._async_executor.schedule('bootstrap') - self._async_executor.run_async(self.state_handler.bootstrap, args=(self.patroni.config['bootstrap'],)) - return 'trying to bootstrap a new cluster' + + if self.patroni.config.is_standby_cluster: + self._async_executor.schedule('bootstrap_standby_leader') + self._async_executor.run_async(self.bootstrap_standby_leader) + return 'trying to bootstrap a new standby leader' + else: + self._async_executor.schedule('bootstrap') + self._async_executor.run_async( + self.state_handler.bootstrap, + args=(self.patroni.config['bootstrap'],) + ) + return 'trying to bootstrap a new cluster' else: return 'failed to acquire initialize lock' else: @@ -211,6 +223,21 @@ class Ha(object): return 'trying to ' + msg return 'waiting for leader to bootstrap' + def bootstrap_standby_leader(self): + """ If we found 'standby' key in the configuration, we need to bootstrap + not a real master, but a 'standby leader', that will take base backup + from a remote master and start follow it. + """ + patroni_config = self.patroni.config.dynamic_configuration + clone_source = self.get_remote_master(patroni_config) + msg = 'clone from remote master {0}'.format(clone_source.conn_url) + result = self.clone(clone_source, msg) + self._post_bootstrap_task.complete(result) + if result: + self.state_handler.set_role('standby_leader') + + return result + def _handle_rewind(self): if self.state_handler.rewind_needed_and_possible(self.cluster.leader): self._async_executor.schedule('running pg_rewind from ' + self.cluster.leader.name) @@ -266,12 +293,18 @@ class Ha(object): def _get_node_to_follow(self, cluster): # determine the node to follow. If replicatefrom tag is set, # try to follow the node mentioned there, otherwise, follow the leader. - if not self.patroni.replicatefrom or self.patroni.replicatefrom == self.state_handler.name: - node_to_follow = cluster.leader - else: - node_to_follow = cluster.get_member(self.patroni.replicatefrom) + is_leader = self.cluster.leader and self.state_handler.name == self.cluster.leader.name - return node_to_follow if node_to_follow and node_to_follow.name != self.state_handler.name else None + if self.cluster.is_standby_cluster() and is_leader: + node_to_follow = self.get_remote_master(cluster.config.data) + elif self.patroni.replicatefrom and self.patroni.replicatefrom != self.state_handler.name: + node_to_follow = cluster.get_member(self.patroni.replicatefrom) + else: + node_to_follow = cluster.leader + + return (node_to_follow if + node_to_follow and + node_to_follow.name != self.state_handler.name else None) def follow(self, demote_reason, follow_reason, refresh=True): if refresh: @@ -411,6 +444,12 @@ class Ha(object): line.append(cluster_history[line[0]][3]) self.dcs.set_history_value(json.dumps(history, separators=(',', ':'))) + def enforce_follow_remote_master(self, message): + self.state_handler.set_role('standby_leader') + demote_reason = 'cannot be a real master in standby cluster' + + return self.follow(demote_reason, message) + def enforce_master_role(self, message, promote_message): if not self.is_paused() and not self.watchdog.is_running and not self.watchdog.activate(): if self.state_handler.is_leader(): @@ -740,8 +779,18 @@ class Ha(object): logger.info('Cleaning up failover key after acquiring leader lock...') self.dcs.manual_failover('', '') self.load_cluster_from_dcs() - return self.enforce_master_role('acquired session lock as a leader', - 'promoted self to leader by acquiring session lock') + + if self.cluster.is_standby_cluster(): + # standby leader disappeared, and this is a healthiest + # replica, so it should become a new standby leader. + # This imply that we need to start following a remote master + msg = 'promoted self to a standby leader because i had the session lock' + return self.enforce_follow_remote_master(msg) + else: + return self.enforce_master_role( + 'acquired session lock as a leader', + 'promoted self to leader by acquiring session lock' + ) else: return self.follow('demoted self after trying and failing to obtain lock', 'following new leader after trying and failing to obtain lock') @@ -773,8 +822,17 @@ class Ha(object): if msg is not None: return msg - return self.enforce_master_role('no action. i am the leader with the lock', - 'promoted self to leader because i had the session lock') + if self.cluster.is_standby_cluster(): + # in case of standby cluster we don't really need to + # enforce anything, since the leader is not a master. + # So just remind the role. + msg = 'no action. i am the standby leader with the lock' + return self.enforce_follow_remote_master(msg) + else: + return self.enforce_master_role( + 'no action. i am the leader with the lock', + 'promoted self to leader because i had the session lock' + ) else: # Either there is no connection to DCS or someone else acquired the lock logger.error('failed to update leader lock') @@ -1001,6 +1059,7 @@ class Ha(object): self.set_is_leader(True) self.state_handler.call_nowait(ACTION_ON_START) self.load_cluster_from_dcs() + return 'initialized a new cluster' def handle_starting_instance(self): @@ -1215,3 +1274,27 @@ class Ha(object): no "active" leader watch request in progress. This usually happens on the master or if the node is running async action""" self.dcs.event.set() + + def get_remote_master(self, config): + """ In case of standby cluster this will tel us from which remote + master to stream. Config can be both patroni config or + cluster.config.data + """ + config = config or (self.config is not None and self.config.data) + + if config and config.get('standby_cluster'): + cluster_params = config.get('standby_cluster') + unique_name = 'remote_master:{}'.format(uuid.uuid1()) + data = { + 'conn_kwargs': { + "host": cluster_params.get('host'), + "port": cluster_params.get('port'), + }, + 'no_replication_slot': 'primary_slot_name' not in cluster_params, + } + data.update({ + k: v for k, v in cluster_params.items() + if k in RemoteMember.allowed_keys() + }) + + return RemoteMember(unique_name, data) diff --git a/patroni/postgresql.py b/patroni/postgresql.py index b5c305b3..f69a52bb 100644 --- a/patroni/postgresql.py +++ b/patroni/postgresql.py @@ -15,11 +15,13 @@ from patroni.callback_executor import CallbackExecutor from patroni.exceptions import PostgresConnectionException, PostgresException from patroni.utils import compare_values, parse_bool, parse_int, Retry, RetryFailedError, polling_loop, split_host_port from patroni.postmaster import PostmasterProcess +from patroni.dcs import RemoteMember from requests.structures import CaseInsensitiveDict from six import string_types from six.moves.urllib.parse import quote_plus from threading import current_thread, Lock + logger = logging.getLogger(__name__) ACTION_ON_START = "on_start" @@ -665,9 +667,17 @@ class Postgresql(object): self.set_state('creating replica') self._sysid = None - # get list of replica methods from config. - # If there is no configuration key, or no value is specified, use basebackup - replica_methods = self._create_replica_methods or ['basebackup'] + is_remote_master = isinstance(clone_member, RemoteMember) + create_replica_methods = is_remote_master and clone_member.create_replica_methods + + # get list of replica methods either from clone member or from + # the config. If there is no configuration key, or no value is + # specified, use basebackup + replica_methods = ( + create_replica_methods + or self._create_replica_methods + or ['basebackup'] + ) if clone_member and clone_member.conn_url: r = clone_member.conn_kwargs(self._replication) @@ -1413,6 +1423,12 @@ class Postgresql(object): return self._rewind_state == REWIND_STATUS.FAILED def follow(self, member, timeout=None): + is_remote_master = isinstance(member, RemoteMember) + no_replication_slot = is_remote_master and member.no_replication_slot + restore_command = is_remote_master and member.restore_command + min_apply_delay = is_remote_master and member.recovery_min_apply_delay + archive_cleanup = is_remote_master and member.archive_cleanup_command + primary_conninfo = self.primary_conninfo(member) change_role = self.role in ('master', 'demoted') @@ -1420,8 +1436,16 @@ class Postgresql(object): recovery_params.update({'standby_mode': 'on', 'recovery_target_timeline': 'latest'}) if primary_conninfo: recovery_params['primary_conninfo'] = primary_conninfo - if self.use_slots: - recovery_params['primary_slot_name'] = slot_name_from_member_name(self.name) + if self.use_slots and not no_replication_slot: + required_name = is_remote_master and member.data.get('primary_slot_name') + name = required_name or slot_name_from_member_name(self.name) + recovery_params['primary_slot_name'] = name + if restore_command: + recovery_params['restore_command'] = restore_command + if min_apply_delay: + recovery_params['recovery_min_apply_delay'] = min_apply_delay + if archive_cleanup: + recovery_params['archive_cleanup_command'] = archive_cleanup self.write_recovery_conf(recovery_params) @@ -1533,7 +1557,7 @@ $$""".format(name, ' '.join(options)), name, password, password) # the current master, because that member would replicate from elsewhere. We still create the slot if # the replicatefrom destination member is currently not a member of the cluster (fallback to the # master), or if replicatefrom destination member happens to be the current master - if self.role == 'master': + if self.role in ('master', 'standby_leader'): slot_members = [m.name for m in cluster.members if m.name != self.name and (m.replicatefrom is None or m.replicatefrom == self.name or not cluster.has_member(m.replicatefrom))] diff --git a/postgres0.yml b/postgres0.yml index 0f3a1935..5b4cfe56 100644 --- a/postgres0.yml +++ b/postgres0.yml @@ -29,6 +29,10 @@ bootstrap: maximum_lag_on_failover: 1048576 # master_start_timeout: 300 # synchronous_mode: false + #standby_cluster: + #host: 127.0.0.1 + #port: 1111 + #primary_slot_name: patroni postgresql: use_pg_rewind: true # use_slots: true diff --git a/tests/test_config.py b/tests/test_config.py index 3d899e38..a2f661f9 100644 --- a/tests/test_config.py +++ b/tests/test_config.py @@ -23,7 +23,7 @@ class TestConfig(unittest.TestCase): def test_set_dynamic_configuration(self): with patch.object(Config, '_build_effective_configuration', Mock(side_effect=Exception)): self.assertIsNone(self.config.set_dynamic_configuration({'foo': 'bar'})) - self.assertTrue(self.config.set_dynamic_configuration({'synchronous_mode': True})) + self.assertTrue(self.config.set_dynamic_configuration({'synchronous_mode': True, 'standby_cluster': {}})) def test_reload_local_configuration(self): os.environ.update({ diff --git a/tests/test_ctl.py b/tests/test_ctl.py index e388d910..0afea71d 100644 --- a/tests/test_ctl.py +++ b/tests/test_ctl.py @@ -344,12 +344,15 @@ class TestCtl(unittest.TestCase): assert result.exit_code == 0 @patch('requests.post', Mock(side_effect=requests.exceptions.ConnectionError('foo'))) - def test_request_patroni(self): - context = {'restapi': {'keyfile': '/etc/patroni/key.pem', 'certfile': 'cert.pem'}} - with patch('click.get_current_context') as mock_context: - mock_context.return_value.obj = context - member = get_cluster_initialized_with_leader().leader.member - self.assertRaises(requests.exceptions.ConnectionError, request_patroni, member, 'post', 'dummy', {}) + @patch('click.get_current_context') + def test_request_patroni(self, mock_context): + member = get_cluster_initialized_with_leader().leader.member + + mock_context.return_value.obj = {'ctl': {'cacert': 'cert.pem'}} + self.assertRaises(requests.exceptions.ConnectionError, request_patroni, member, 'post', 'dummy', {}) + + mock_context.return_value.obj = {'ctl': {'insecure': True}} + self.assertRaises(requests.exceptions.ConnectionError, request_patroni, member, 'post', 'dummy', {}) def test_ctl(self): self.runner.invoke(ctl, ['list']) diff --git a/tests/test_ha.py b/tests/test_ha.py index b5364669..be9b94ae 100644 --- a/tests/test_ha.py +++ b/tests/test_ha.py @@ -2,8 +2,10 @@ import datetime import etcd import os import unittest +import sys from mock import Mock, MagicMock, PropertyMock, patch +from patroni.async_executor import CriticalTask from patroni.config import Config from patroni.dcs import Cluster, ClusterConfig, Failover, Leader, Member, get_dcs, SyncState, TimelineHistory from patroni.dcs.etcd import Client @@ -26,16 +28,17 @@ def false(*args, **kwargs): return False -def get_cluster(initialize, leader, members, failover, sync): +def get_cluster(initialize, leader, members, failover, sync, cluster_config=None): history = TimelineHistory(1, [(1, 67197376, 'no recovery target specified', datetime.datetime.now().isoformat())]) - return Cluster(initialize, ClusterConfig(1, {1: 2}, 1), leader, 10, members, failover, sync, history) + cluster_config = cluster_config or ClusterConfig(1, {1: 2}, 1) + return Cluster(initialize, cluster_config, leader, 10, members, failover, sync, history) -def get_cluster_not_initialized_without_leader(): - return get_cluster(None, None, [], None, SyncState(None, None, None)) +def get_cluster_not_initialized_without_leader(cluster_config=None): + return get_cluster(None, None, [], None, SyncState(None, None, None), cluster_config) -def get_cluster_initialized_without_leader(leader=False, failover=None, sync=None): +def get_cluster_initialized_without_leader(leader=False, failover=None, sync=None, cluster_config=None): m1 = Member(0, 'leader', 28, {'conn_url': 'postgres://replicator:rep-pass@127.0.0.1:5435/postgres', 'api_url': 'http://127.0.0.1:8008/patroni', 'xlog_location': 4}) leader = Leader(0, 0, m1) if leader else None @@ -47,16 +50,38 @@ def get_cluster_initialized_without_leader(leader=False, failover=None, sync=Non 'scheduled_restart': {'schedule': "2100-01-01 10:53:07.560445+00:00", 'postgres_version': '99.0.0'}}) syncstate = SyncState(0 if sync else None, sync and sync[0], sync and sync[1]) - return get_cluster(SYSID, leader, [m1, m2], failover, syncstate) + return get_cluster(SYSID, leader, [m1, m2], failover, syncstate, cluster_config) def get_cluster_initialized_with_leader(failover=None, sync=None): return get_cluster_initialized_without_leader(leader=True, failover=failover, sync=sync) -def get_cluster_initialized_with_only_leader(failover=None): +def get_cluster_initialized_with_only_leader(failover=None, cluster_config=None): leader = get_cluster_initialized_without_leader(leader=True, failover=failover).leader - return get_cluster(True, leader, [leader], failover, None) + return get_cluster(True, leader, [leader], failover, None, cluster_config) + + +def get_cluster_not_initialized_standby(failover=None, sync=None): + return get_cluster_not_initialized_without_leader( + cluster_config=ClusterConfig(1, { + "standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }}, 1) + ) + + +def get_standby_cluster_initialized_with_only_leader(failover=None, sync=None): + return get_cluster_initialized_with_only_leader( + cluster_config=ClusterConfig(1, { + "standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }}, 1) + ) def get_node_status(reachable=True, in_recovery=True, wal_position=10, nofailover=False, watchdog_failed=False): @@ -97,6 +122,10 @@ zookeeper: hosts: [localhost] port: 8181 """ + # We rely on sys.argv in Config, so it's necessary to reset + # all the extra values that are coming from py.test + sys.argv = sys.argv[:1] + self.config = Config() self.postgresql = p self.dcs = d @@ -182,6 +211,50 @@ class TestHa(unittest.TestCase): self.p.is_healthy = false self.assertEquals(self.ha.run_cycle(), 'starting as a secondary') + @patch('patroni.dcs.etcd.Etcd.initialize', return_value=True) + def test_start_as_standby_leader(self, initialize): + self.p.data_directory_empty = true + self.ha.cluster = get_cluster_not_initialized_standby() + self.ha.cluster.is_unlocked = true + self.ha.patroni.config._dynamic_configuration = {"standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }} + self.assertEquals( + self.ha.run_cycle(), + 'trying to bootstrap a new standby leader' + ) + + @patch.object(Cluster, 'get_clone_member', + Mock(return_value=Member(0, 'test', 1, {'api_url': 'http://127.0.0.1:8011/patroni'}))) + @patch.object(Postgresql, 'create_replica', Mock(return_value=0)) + def test_start_as_cascade_replica_in_standby_cluster(self): + self.p.data_directory_empty = true + self.ha.cluster = get_standby_cluster_initialized_with_only_leader() + self.ha.cluster.is_unlocked = false + self.ha.patroni.config._dynamic_configuration = {"standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }} + self.assertEquals( + self.ha.run_cycle(), + "trying to bootstrap from replica 'test'" + ) + + @patch.object(Postgresql, 'create_replica', Mock(return_value=0)) + def test_bootstrap_standby_leader(self): + self.ha.cluster = get_cluster_not_initialized_standby() + self.ha.cluster.is_unlocked = true + self.ha.patroni.config._dynamic_configuration = {"standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }} + self.ha._post_bootstrap_task = CriticalTask() + self.assertEquals(self.ha.bootstrap_standby_leader(), True) + def test_recover_replica_failed(self): self.p.controldata = lambda: {'Database cluster state': 'in recovery', 'Database system identifier': SYSID} self.p.is_running = false @@ -616,6 +689,61 @@ class TestHa(unittest.TestCase): self.ha.cluster = get_cluster_initialized_with_leader(Failover(0, '', self.p.name, None)) self.assertEquals(self.ha.run_cycle(), 'PAUSE: waiting to become master after promote...') + def test_process_healthy_standby_cluster_as_standby_leader(self): + self.p.is_leader = false + self.p.name = 'leader' + self.ha.patroni.config._dynamic_configuration = {"standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }} + self.ha.cluster = get_standby_cluster_initialized_with_only_leader() + msg = 'no action. i am the standby leader with the lock' + self.assertEquals(self.ha.run_cycle(), msg) + + def test_process_healthy_standby_cluster_as_cascade_replica(self): + self.p.is_leader = false + self.p.name = 'replica' + self.ha.patroni.config._dynamic_configuration = {"standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }} + self.ha.cluster = get_standby_cluster_initialized_with_only_leader() + msg = 'no action. i am a secondary and i am following a leader' + self.assertEquals(self.ha.run_cycle(), msg) + + @patch('patroni.dcs.etcd.Etcd.initialize', return_value=True) + def test_process_unhealthy_standby_cluster_as_standby_leader(self, initialize): + self.p.is_leader = false + self.p.name = 'leader' + self.ha.patroni.config._dynamic_configuration = {"standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }} + self.ha.cluster = get_standby_cluster_initialized_with_only_leader() + self.ha.cluster.is_unlocked = true + self.ha.sysid_valid = true + self.p._sysid = True + msg = 'promoted self to a standby leader because i had the session lock' + self.assertEquals(self.ha.run_cycle(), msg) + + @patch.object(Postgresql, 'rewind_needed_and_possible', Mock(return_value=True)) + @patch('patroni.dcs.etcd.Etcd.initialize', return_value=True) + def test_process_unhealthy_standby_cluster_as_cascade_replica(self, initialize): + self.p.is_leader = false + self.p.name = 'replica' + self.ha.patroni.config._dynamic_configuration = {"standby_cluster": { + "host": "localhost", + "port": 5432, + "primary_slot_name": "", + }} + self.ha.cluster = get_standby_cluster_initialized_with_only_leader() + self.ha.is_unlocked = true + msg = 'running pg_rewind from leader' + self.assertEquals(self.ha.run_cycle(), msg) + def test_failed_to_update_lock_in_pause(self): self.ha.update_lock = false self.ha.is_paused = true diff --git a/tests/test_postgresql.py b/tests/test_postgresql.py index 2c0f2874..4019979c 100644 --- a/tests/test_postgresql.py +++ b/tests/test_postgresql.py @@ -8,7 +8,7 @@ import unittest from mock import Mock, MagicMock, PropertyMock, patch, mock_open from patroni.async_executor import CriticalTask -from patroni.dcs import Cluster, Leader, Member, SyncState +from patroni.dcs import Cluster, Leader, Member, RemoteMember, SyncState from patroni.exceptions import PostgresConnectionException, PostgresException from patroni.postgresql import Postgresql, STATE_REJECT, STATE_NO_RESPONSE from patroni.postmaster import PostmasterProcess @@ -401,7 +401,7 @@ class TestPostgresql(unittest.TestCase): @patch.object(Postgresql, 'is_running', Mock(return_value=False)) @patch.object(Postgresql, 'start', Mock()) def test_follow(self): - self.p.follow(None) + self.p.follow(RemoteMember('123', {'recovery_command': 'foo'})) @patch('subprocess.check_output', Mock(return_value=0, side_effect=pg_controldata_string)) def test_can_rewind(self): From 2e9cb412e4ca07864e4b43e64960476cabd6eabf Mon Sep 17 00:00:00 2001 From: Pavel Kirillov Date: Fri, 7 Sep 2018 16:17:56 +0300 Subject: [PATCH 63/63] Register service in consul (#802) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Đšegister service 'scope_name' with tag 'master' or 'replica' example with scope 'pgsql-pgpi' ```[root@pgpi1 ~]# host -t SRV pgsql-pgpi.service.consul. 127.0.0.1 Using domain server: Name: 127.0.0.1 Address: 127.0.0.1#53 Aliases: pgsql-pgpi.service.consul has SRV record 1 1 5432 pgpi1.node.dc.consul. pgsql-pgpi.service.consul has SRV record 1 1 5432 pgpi2.node.dc.consul. [root@pgpi1 ~]# host -t SRV master.pgsql-pgpi.service.consul. 127.0.0.1 Using domain server: Name: 127.0.0.1 Address: 127.0.0.1#53 Aliases: master.pgsql-pgpi.service.consul has SRV record 1 1 5432 pgpi2.node.dc.consul. [root@pgpi1 ~]# host -t SRV replica.pgsql-pgpi.service.consul. 127.0.0.1 Using domain server: Name: 127.0.0.1 Address: 127.0.0.1#53 Aliases: replica.pgsql-pgpi.service.consul has SRV record 1 1 5432 pgpi1.node.dc.consul.``` Fixes: https://github.com/zalando/patroni/issues/771 --- patroni/dcs/consul.py | 90 ++++++++++++++++++++++++++++++++++++++++++- tests/test_consul.py | 27 +++++++++++-- 2 files changed, 112 insertions(+), 5 deletions(-) diff --git a/patroni/dcs/consul.py b/patroni/dcs/consul.py index 6bcd3216..f65eeb2a 100644 --- a/patroni/dcs/consul.py +++ b/patroni/dcs/consul.py @@ -2,6 +2,7 @@ from __future__ import absolute_import import json import logging import os +import re import socket import ssl import time @@ -12,7 +13,7 @@ from patroni.dcs import AbstractDCS, ClusterConfig, Cluster, Failover, Leader, M from patroni.exceptions import DCSError from patroni.utils import deep_compare, parse_bool, Retry, RetryFailedError, split_host_port from urllib3.exceptions import HTTPError -from six.moves.urllib.parse import urlencode, urlparse +from six.moves.urllib.parse import urlencode, urlparse, quote from six.moves.http_client import HTTPException logger = logging.getLogger(__name__) @@ -133,6 +134,31 @@ def catch_consul_errors(func): return wrapper +def force_if_last_failed(func): + def wrapper(*args, **kwargs): + if wrapper.last_result is False: + kwargs['force'] = True + wrapper.last_result = func(*args, **kwargs) + return wrapper.last_result + + wrapper.last_result = None + return wrapper + + +def service_name_from_scope_name(scope_name): + """Translate scope name to service name which can be used in dns. + + 230 = 253 - len('replica.') - len('.service.consul') + """ + + def replace_char(match): + c = match.group(0) + return '-' if c in '. _' else "u{:04d}".format(ord(c)) + + service_name = re.sub(r'[^a-z0-9\-]', replace_char, scope_name.lower()) + return service_name[0:230] + + class Consul(AbstractDCS): def __init__(self, config): @@ -174,6 +200,13 @@ class Consul(AbstractDCS): self.set_ttl(config.get('ttl') or 30) self._last_session_refresh = 0 self.__session_checks = config.get('checks') + self._register_service = config.get('register_service', False) + if self._register_service: + self._service_name = service_name_from_scope_name(self._scope) + if self._scope != self._service_name: + logger.warning('Using %s as consul service name instead of scope name %s', self._service_name, + self._scope) + self._service_check_interval = config.get('service_check_interval', '5s') if not self._ctl: self.create_session() @@ -323,11 +356,65 @@ class Consul(AbstractDCS): try: args = {} if permanent else {'acquire': self._session} self._client.kv.put(self.member_path, json.dumps(data, separators=(',', ':')), **args) + if self._register_service: + self.update_service(not create_member and member and member.data or {}, data) return True except Exception: logger.exception('touch_member') return False + @catch_consul_errors + def register_service(self, service_name, **kwargs): + logger.info('Register service %s, params %s', service_name, kwargs) + return self._client.agent.service.register(service_name, **kwargs) + + @catch_consul_errors + def deregister_service(self, service_id): + logger.info('Deregister service %s', service_id) + # service_id can contain special characters, but is used as part of uri in deregister request + service_id = quote(service_id) + return self._client.agent.service.deregister(service_id) + + def _update_service(self, data): + service_name = self._service_name + role = data['role'] + state = data['state'] + api_parts = urlparse(data['api_url']) + api_parts = api_parts._replace(path='/{0}'.format(role)) + conn_parts = urlparse(data['conn_url']) + check = base.Check.http(api_parts.geturl(), self._service_check_interval, deregister=self._client.http.ttl * 10) + params = { + 'service_id': '{0}/{1}'.format(self._scope, self._name), + 'address': conn_parts.hostname, + 'port': conn_parts.port, + 'check': check, + 'tags': [role] + } + + if state == 'stopped': + return self.deregister_service(params['service_id']) + + if role in ['master', 'replica']: + if state != 'running': + return + return self.register_service(service_name, **params) + + logger.warning('Could not register service: unknown role type %s', role) + + @force_if_last_failed + def update_service(self, old_data, new_data, force=False): + update = False + + for key in ['role', 'api_url', 'conn_url', 'state']: + if key not in new_data: + logger.warning('Could not register service: not enough params in member data') + return + if old_data.get(key) != new_data[key]: + update = True + + if force or update: + return self._update_service(new_data) + @catch_consul_errors def _do_attempt_to_acquire_leader(self, kwargs): return self.retry(self._client.kv.put, self.leader_path, self._name, **kwargs) @@ -339,6 +426,7 @@ class Consul(AbstractDCS): ret = self._do_attempt_to_acquire_leader({} if permanent else {'acquire': self._session}) if not ret: logger.info('Could not take out TTL lock') + return ret def take_leader(self): diff --git a/tests/test_consul.py b/tests/test_consul.py index c26ca3c6..7f752f18 100644 --- a/tests/test_consul.py +++ b/tests/test_consul.py @@ -74,10 +74,12 @@ class TestConsul(unittest.TestCase): @patch.object(consul.Consul.KV, 'delete', Mock()) def setUp(self): Consul({'ttl': 30, 'scope': 't', 'name': 'p', 'url': 'https://l:1', 'retry_timeout': 10, - 'verify': 'on', 'key': 'foo', 'cert': 'bar', 'cacert': 'buz', 'token': 'asd', 'dc': 'dc1'}) - Consul({'ttl': 30, 'scope': 't', 'name': 'p', 'url': 'https://l:1', 'retry_timeout': 10, - 'verify': 'on', 'cert': 'bar', 'cacert': 'buz'}) - self.c = Consul({'ttl': 30, 'scope': 'test', 'name': 'postgresql1', 'host': 'localhost:1', 'retry_timeout': 10}) + 'verify': 'on', 'key': 'foo', 'cert': 'bar', 'cacert': 'buz', 'token': 'asd', 'dc': 'dc1', + 'register_service': True}) + Consul({'ttl': 30, 'scope': 't_', 'name': 'p', 'url': 'https://l:1', 'retry_timeout': 10, + 'verify': 'on', 'cert': 'bar', 'cacert': 'buz', 'register_service': True}) + self.c = Consul({'ttl': 30, 'scope': 'test', 'name': 'postgresql1', 'host': 'localhost:1', 'retry_timeout': 10, + 'register_service': True}) self.c._base_path = '/service/good' self.c._load_cluster() @@ -111,6 +113,7 @@ class TestConsul(unittest.TestCase): @patch.object(consul.Consul.KV, 'delete', Mock(side_effect=[ConsulException, True, True])) @patch.object(consul.Consul.KV, 'put', Mock(side_effect=[True, ConsulException])) def test_touch_member(self): + self.c._register_service = True self.c.refresh_session = Mock(return_value=True) self.c.touch_member({'balbla': 'blabla'}) self.c.touch_member({'balbla': 'blabla'}) @@ -177,3 +180,19 @@ class TestConsul(unittest.TestCase): @patch.object(consul.Consul.KV, 'put', Mock(return_value=True)) def test_set_history_value(self): self.assertTrue(self.c.set_history_value('{}')) + + @patch.object(consul.Consul.Agent.Service, 'register', Mock(side_effect=(False, True))) + @patch.object(consul.Consul.Agent.Service, 'deregister', Mock(return_value=True)) + def test_update_service(self): + d = {'role': 'replica', 'api_url': 'http://a/t', 'conn_url': 'pg://c:1', 'state': 'running'} + self.assertIsNone(self.c.update_service({}, {})) + self.assertFalse(self.c.update_service({}, d)) + self.assertTrue(self.c.update_service(d, d)) + self.assertIsNone(self.c.update_service(d, d)) + d['state'] = 'stopped' + self.assertTrue(self.c.update_service(d, d, force=True)) + d['state'] = 'unknown' + self.assertIsNone(self.c.update_service({}, d)) + d['state'] = 'running' + d['role'] = 'bla' + self.assertIsNone(self.c.update_service({}, d))