feat(cluster): PG Logical Replication + VIP/Keepalived + config_hash sync (v1.2.1–1.2.2)
- PG Logical Replication: edgeguard_shared PUBLICATION auf Primary, edgeguard_sub SUBSCRIPTION auf Secondary. Nur geteilte Config-Tabellen werden repliziert; node-eigene Daten (network_interfaces, ip_addresses, static_routes, cluster_settings, dns_settings, ntp_settings) bleiben lokal — OPNsense-Muster. - cluster-init-replication: Erstellt PUBLICATION, Rolle + pg_hba-Einträge (logical + replication), WAL-Level auf logical. - cluster-setup-standby: Erstellt SUBSCRIPTION (copy_data=true), pollt pg_subscription_rel bis alle Tabellen sync = 'r', rendert dann Configs. - promote: manueller Failover via pg_promote() + touch recovery.signal. - VIP/Keepalived: cluster_settings-Tabelle (vip_address, vip_interface, vrrp_router_id), /cluster/vip-settings API, Keepalived-Config-Generator mit VRRP + check_script + notify-Skripten in /usr/lib/edgeguard/scripts/. - config_hash sync: Secondary pusht alle 5 Min seinen Hash via mTLS an Primary (PushSelfToPrimary). Heartbeat schreibt nur LOCAL, daher ohne aktiven Push wäre Primary-Sicht des Secondary-Hash stale gewesen. - runSecondaryConfigRender: Goroutine auf Secondary rendert HAProxy+nftables neu wenn config_hash sich ändert (Logical-Replication-Nachzügler). - confighash: node-spezifische Tabellen aus hashSpec entfernt. - postinst: Keepalived-Skripte installieren, sudoers für keepalived. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -78,6 +78,14 @@ build_api() {
|
||||
install -m 0644 "$REPO_ROOT/deploy/systemd/haproxy-edgeguard.conf" \
|
||||
"$build_dir/etc/edgeguard/systemd/"
|
||||
|
||||
# Keepalived notify-scripts → /usr/lib/edgeguard/
|
||||
# postinst setzt chmod 0755 nach der Installation.
|
||||
mkdir -p "$build_dir/usr/lib/edgeguard"
|
||||
for script in keepalived-check.sh keepalived-master.sh keepalived-backup.sh; do
|
||||
install -m 0755 "$REPO_ROOT/packaging/scripts/$script" \
|
||||
"$build_dir/usr/lib/edgeguard/$script"
|
||||
done
|
||||
|
||||
# Installed-Size in KB (rounded up)
|
||||
local size
|
||||
size="$(du -sk "$build_dir" | awk '{print $1}')"
|
||||
|
||||
Reference in New Issue
Block a user