High Availability PostgreSQL howto

Source: Internet
Author: User
Tags failover

Introduction:
This note describes ways to implement high availibility (HA) for PostgreSQL. HA gives the ability to transparently fail-over database connections to an alternative system in the event of some sort of failure of the primary system.

Overview:
The HA-PostgreSQL system works the following way: the HA cluster consists of two machines running heartbeat that use both a serial port and a second network interface to provide the Failover heartbeat. the primary system keeps the secondary system database files synchronized by periodic callto a script that runs rsync.

The heartbeat software provides ha in the form of a hot standby 2-node cluster. in the event of a failure of the primary database system, the heartbeat software causes the secondary to take over. any database changes that may have occurred between the last synchronization and the failure will be lost, so this synchronization must be done relatively frequently. the synchronization is done with the same network interface that is also doing the heartbeat in order to reduce the volume of traffic on the primary network.

Setting up ha-PostgreSQL
Install HEARTBEAT (http://linux-ha.org/) and get it running properly on the two systems. the installation shoshould use both a serial connection and a secondary network interface (connected via a cross-over cable) to implement the heartbeat. in what follows, I will assume that the secondary network interface is eth1 on both systems and that 10.0.0.1 (HB-Castor) is the primary system (Castor) and 10.0.0.2 (HB-Pollux) is the secondary system (Pollux ).

Configure and install PostgreSQL (http://www.postgresql.org/) on both systems. you shoshould use the same version of PostgreSQL and the same configuration options for both systems. it will also be less confusing to use the same path, UID and GID settings for both machines. in what follows, I will assume that the PostgreSQL datafile directory, pgdata, is/home/pgsql on both systems.
Test PostgreSQL, individually on each system. When you are satisfied that it is running properly then bring it down on both sides. On the secondary, clear out the datafile directory:

CD/home/pgsql/base; RM-RF *

Next decide upon a synchronization scheme for the servers. This is tricky because PostgreSQL may have cached some of its recent actions in memory and not written them to disk yet.
There are at least three synchronization methods that can be used:

Use pg_dump/pg_dumpall. this will assure consistant replication even if the database is being used concurrently. the problem with this approach is that there is no way to May incremental backups so that there can be a needlessly large volume of traffic between the servers if the databases are large. using pg_dump will require iterating the synchronization over all the individual databases on the server but can handle large binary objects. using pg_dumpall will handle the entire collection of databases but it cannot handle large binary objects.

Use rsync. this method will keep the volume of data being moved between the servers down. the problem is that since this method works with the data files, its not supposed to work. I have found that in practice, for large databases with low transaction volumes, that it can work. if you have large databases with a low insert/update rates, you might want to experiment with this approach to see if it works for you. rsync setup details.

Use rserv. recent PostgreSQL versions (after 7.0) contain a package in the contrib section called rserv. this is a toolset for replicating a master database to a slave database. using rserv will require iterating the synchronization over all the individual databases on the server. it also requires your database tables to contain a column that can be monitored for updates in order for it to detect what to synchronize (I do not yet know what it does if you add/delete row to/from a table ). I have not yet tried doing this for handling failovers, for example it has a Master/Slave concept, but in a Failover situation the roles get reversed, how rserv will work under this situation I still need to test. I will report here once I have (or you can let me know what you did if you have done it this way ).

Test the transfer.
We can now test the primary-to-secondary transfer with one of the following on the appropriate system:

Method Command run from
Pg_dump-B-H 10.0.0.1 (dbname)>/tmp/db.tar; pg_restore-c-d (dbname)/tmp/db.tar; RM/tmp/db.tar secondary
Pg_dumpall-H 10.0.0.1>/tmp/DB. Dump; pg_restore-F/tmp/DB. Dump template1; RM/tmp/DB. Dump secondary
Rsync/usr/bin/rsync-AUV -- delete/home/pgsql/10.0.0.2: PostgreSQL/primary
Rserv

You shoshould now see a copy of all the other s files on the secondary system in/home/pgsql

If the primary-to-secondary transfer is working, we next need to test the secondary-to-Primary transfer.
First, temporarily move the database directory Out Of The Way (we will keep it, just in case) on the primary.

 

MV/home/pgsql/base. tmp
Mkdir/home/pgsql/base
Chown Postgres: Postgres/home/pgsql/base
Chmod 700/home/pgsql/base

Then try the transfer from the secondary by going to the opposite system from the previous test and typing:

Method Command run from
Pg_dump-B-H 10.0.0.2 (dbname)>/tmp/db.tar; pg_restore-c-d (dbname)/tmp/db.tar; RM/tmp/db.tar primary
Pg_dumpall-H 10.0.0.2>/tmp/DB. Dump; pg_restore-F/tmp/DB. Dump template1; RM/tmp/DB. Dump primary
Rsync/usr/bin/rsync-auq -- delete/home/pgsql/10.0.0.1: PostgreSQL/secondary
Rserv

You shoshould now have a copy of the files in/home/pgsql/base on the primary. If so, you can get rid of the temporary copy:
Rm-RF/home/pgsql/base. tmp

The data is transferred between systems by periodically calling a script, db_sync, which does the update:

The Rsync version:

#! /Bin/sh
# Db_sync sync the DB with Failover copy
# Rsync version

# The Hb interface of the other side
RHost = "HB-Pollux"
Lockfile = "/var/lock/subsys/db_sync"

Master = '/sbin/ifconfig | grep "eth0: 0" | WC-l'

If [$ master-EQ "0"]; then
# This side not the master
Exit 0
Fi

# This side is the master

If [-F $ lockfile]; then
# Have not finished since the last time this script was invoked
Logger-P daemon. Notice-T db_sync "locked, sync already active"
Exit 0
Fi

Touch $ lockfile
Logger-P daemon. Notice-T db_sync "syncing database with $ rHost"
Sync
/Usr/bin/rsync-auq -- delete-after/home/pgsql/$ rHost: PostgreSQL/
Rm-F $ lockfile

Exit 0

 

The pg_dumpall version:

#! /Bin/sh
# Db_sync sync the DB with Failover copy
# Pg_dumpall version
# The pg_dump version is a simple modification of this version

# The Hb interface of the other side
RHost = "HB-Pollux"
Lockfile = "/var/lock/subsys/db_sync"

Master = '/sbin/ifconfig | grep "eth0: 0" | WC-l'

If [$ master-EQ "1"]; then
# This side not the slave
Exit 0
Fi

# This side is the slave

If [-F $ lockfile]; then
# Have not finished since the last time this script was invoked
Logger-P daemon. Notice-T db_sync "locked, sync already active"
Exit 0
Fi

Touch $ lockfile
Logger-P daemon. Notice-T db_sync "syncing database with $ rHost"
Pg_dumpall-u Postgres-h $ rHost>/tmp/DB. Dump $
Pg_restore-u Postgres-F/tmp/DB. Dump $ template1
Rm-F $ lockfile/tmp/DB. Dump $

Exit 0

This script assumes that eth0: 0 is the HA interface of your cluster. A copy of this script is on both systems (with rHost set appropriately ). it shoshould be called periodically by Cron, e.g.
, 20, 25, 30, 35, 40, 45, 50, 55 ***/usr/local/sbin/db_sync
In roots crontab file, wocould cause it to be invoked every 5 minutes. the frequency of this update involves a trade-off. the more often the update is done then the finer the granularity of the mirror copy of the database is, and so there will be less of a data loss when switching over to the secondary. if the synchronization is done too often, then there may be a large volume of network traffic and its possible that the synchronization has not completed when it is time do start another. the script above handles the second case (if you see locked, sync already active messages in the system logs, then you know that there is too much data to transfer in the alloted time ).

Edit the snapshot s init file so that on startup it will do an "pull" from the opposite system.
If using rsync, use the command (on Castor ).
Rsync-auq -- delete-after HB-POLLUX: PostgreSQL // home/pgsql/
And then start PostgreSQL like normal.
If using the other methods, invoke the db_sync script immediately after PostgreSQL starts up.
This is done so that the primary has a fresh copy of the database in the event that it was down long enough that the secondary copy has substantially changed. for the secondary, it provides the chance to get anything that is new before it takes over. doing this makes the periodic updates less critical, since that version of the database is only going to be used if the opposite system is unreachable.

Configure heartbeat to manage PostgreSQL from the haresources file, e.g.
Dbserver.mydomain.com 192.168.1.110 PostgreSQL
And restart heartbeat.
Now PostgreSQL connections to dbserver.mydomain.com will go to Castor if its up and to Pollux if its not.

This setup provides basic high availability for PostgreSQL. it cannot handle problems that will happen to connections that are active during the Failover; these will just fail. one shoshould be maid of this kind of problem when doing transactions with a Commit (I. e. the transaction is set up, a Failover happens, and then the commit is executed ).

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.