Meta tags:
description= Configurations
The PostgreSQL node in Chef Automate HA provides configuration options you can use to customize its behavior and meet specific requirements. This guide documents all settings you can patch.;
Headings (most frequently used words):
postgresql, node, config, write, ahead, log, ha, configurations, logging, checkpoints, keep, size, lock, management, max, connections, pg, dump, replication, transport, security, settings, user, archive, full, for, centralized, logs, example,
Text of the page (most frequently used words):
chef (148), the (83), overview (46), and (40), server (40), automate (34), infra (32), install (32), builder (30), postgresql (28), version (28), deployment (28), config (25), for (24), node (24), aws (24), log (23), about (22), configure (22), this (20), habitat (20), supermarket (18), upgrade (18), with (17), settings (16), replication (16), manage (16), api (16), packages (16), prem (16), management (15), users (14), workstation (14), reference (14), community (13), nodes (13), ecdhe (12), client (12), system (12), database (12), recovery (12), license (12), backend (12), 360 (12), managed (12), create (11), wal (11), logs (10), can (10), data (10), default (10), compliance (10), platform (10), backup (10), restore (10), effortless (10), saas (10), started (10), opensearch (10), user (9), security (9), password (9), standby (9), configuration (9), set (9), requirements (9), guide (9), lock (8), gcm (8), key (8), certificate (8), ctl (8), cloud (8), resources (8), prerequisites (8), origin (8), disaster (8), desktop (8), certificates (8), iam (8), page (7), example (7), patch (7), private (7), pg_dump (7), number (7), cluster (7), style (7), add (7), all (6), use (6), write (6), ahead (6), you (6), feedback (6), file (6), path (6), enable (6), name (6), ecdsa (6), rsa (6), enter (6), ssl (6), files (6), that (6), time (6), parameter (6), cookbooks (6), audit (6), migrate (6), inspec (6), cookstyle (6), services (6), package (6), supported (6), troubleshooting (6), update (6), get (6), integrations (6), dashboard (6), applications (6), using (6), enterprise (6), policy (5), terms (5), licensing (5), archive (5), connections (5), size (5), checkpoints (5), table (5), true (5), max_connections (5), section (5), specifies (5), seconds (5), value (5), jobs (5), progress (4), trademarks (4), centralized (4), keep (4), logging (4), contents (4), run (4), toml (4), log_level (4), bastion (4), mnt (4), automate_backups (4), admin (4), aes256 (4), sha384 (4), chacha20 (4), poly1305 (4), aes128 (4), sha256 (4), lag_health_threshold (4), wal_keep_size (4), configures (4), from (4), primary (4), before (4), sets (4), lag (4), during (4), send (4), downloads (4), uninstall (4), organizations (4), groups (4), roles (4), saml (4), ldap (4), resource (4), packs (4), profiles (4), local (4), service (4), download (4), apis (4), upgrades (4), monitor (4), quick (4), start (4), deprecations (4), cops (4), v26 (4), firewalls (4), ports (4), authentication (4), authorization (4), high (4), availability (4), core (4), origins (4), profile (4), minio (4), single (4), cookbook (4), application (4), enrollment (4), setup (4), infrastructure (4), getting (4), migration (4), courier (4), tokens (4), app (4), integration (4), external (4), elasticsearch (4), amazon (4), a2ha (4), premises (4), platforms (4), edition (4), product (3), names (3), are (3), its (3), between (3), last (3), full (3), transport (3), dump (3), max (3), configurations (3), your (3), support (3), was (3), main (3), increase (3), false (3), superuser (3), public (3), root (3), max_replay_lag_before_restart_s (3), min_wal_size (3), max_wal_size (3), max_locks_per_transaction (3), 350 (3), logging_collector (3), log_line_prefix (3), error (3), 5min (3), checkpoint_timeout (3), archiving (3), administrator (3), account (3), allowed (3), controls (3), enables (3), connect (3), custom (3), setting (3), largest (3), than (3), reboot (3), new (3), when (3), running (3), locks (3), objects (3), tables (3), object (3), transaction (3), segments (3), directory (3), zero (3), available (3), usage (3), large (3), docs (3), content (3), herein (2), software (2), corporation (2), one (2), subsidiaries (2), affiliates (2), other (2), rights (2), reserved (2), their (2), respective (2), owners (2), not (2), 2026 (2), how (2), document (2), command (2), below (2), debug1 (2), wal_archive (2), tls_ciphers (2), ssl_key (2), ssl_cert (2), issuer_cert (2), 180 (2), 1600 (2), 80mb (2), 1gb (2), where (2), stores (2), tls (2), off (2), wal_compression (2), waits (2), wal_receiver_timeout (2), wal_sender_timeout (2), max_replication_slots (2), max_wal_senders (2), since (2), replayed (2), replica (2), eligible (2), restart (2), 307200 (2), bytes (2), highest (2), note (2), backups (2), leader (2), same (2), higher (2), otherwise (2), won (2), allow (2), queries (2), each (2), individual (2), doesn (2), them (2), automatic (2), increasing (2), amount (2), needed (2), crash (2), line (2), valid (2), above (2), snippet (2), which (2), values (2), warning (2), github (2), environments (2), bags (2), clients (2), active (2), console (2), legacy (2), azure (2), remediation (2), release (2), notes (2), share (2), what (2), scaffolding (2), variables (2), pattern (2), attributehelper (2), attributedefault (2), useplatformhelpers (2), unnecessaryplatformcasestatement (2), unnecessaryoscheck (2), trueclassfalseclassresourceproperties (2), simplifyplatformmajorversioncheck (2), overlycomplexsupportsdependsmetadata (2), negatingonlyif (2), includerecipewithparentheses (2), immediatenotificationtiming (2), filemode (2), defaultcopyrightcomments (2), copyrightcommentformat (2), commentsentencespacing (2), commentformat (2), chefwhaaat (2), attributekeys (2), invalidlicensestring (2), insecurecookbookurl (2), includeresourceexamples (2), includeresourcedescriptions (2), includepropertydescriptions (2), emptymetadatafield (2), defaultmetadatamaintainer (2), sharing (2), sshprivatekey (2), unlessdefinedrequire (2), requirenethttps (2), legacypowershelloutmethods (2), gemspecrequirerubygems (2), gemspeclicense (2), ruby (2), usecreateifmissing (2), unnecessarynameproperty (2), unnecessarydesiredstate (2), suggestsmetadata (2), stringpropertywithnildefault (2), sensitivepropertyinresource (2), resourcewithnothingaction (2), replacesmetadata (2), recipemetadata (2), providesmetadata (2), propertywithrequiredanddefault (2), propertysplatregex (2), ohaiattributetostring (2), namepropertyisrequired (2), multipleplatformchecks (2), longdescriptionmetadata (2), groupingmetadata (2), doublecompiletime (2), customresourcewithallowedactions (2), conflictsmetadata (2), attributemetadata (2), aptrepositorynotifiesaptupdate (2), aptrepositorydistributiondefault (2), redundantcode (2), zipfileresource (2), windowszipfileusage (2), windowsscresource (2), windowsregistryuac (2), whyrunsupportedtrue (2), useszypperrepo (2), userequirerelative (2), usemultipackageinstalls (2), usecheflanguagesystemdhelper (2), usecheflanguageenvhelpers (2), usecheflanguagecloudhelpers (2), usebuildessentialresource (2), unnecessarymixlibshelloutrequire (2), unnecessarydependschef15 (2), unnecessarydependschef14 (2), sysctlparamresource (2), simplifyaptppasetup (2), shellouttochocolatey (2), shellouthelper (2), sevenziparchiveresource (2), setorreturninresources (2), respondtoresourcename (2), respondtoprovides (2), respondtoinmetadata (2), respondtocompiletime (2), resourcenamefrominitialize (2), resourceforcingcompiletime (2), providesfrominitialize (2), propertywithnameattribute (2), powershellscriptexpandarchive (2), powershellinstallwindowsfeature (2), powershellinstallpackage (2), powershellguardinterpreter (2), osxconfigprofileresource (2), opensslx509resource (2), opensslrsakeyresource (2), noderolesinclude (2), nodeinitpackage (2), minitesthandlerusage (2), macosxuserdefaults (2), libarchivefileresource (2), legacyberksfilesource (2), includingwindowsdefaultrecipe (2), includingohaidefaultrecipe (2), includingmixinshelloutinresources (2), includingaptdefaultrecipe (2), ifprovidesdefaultaction (2), foodcriticcomments (2), executetzutil (2), executesysctl (2), executesleep (2), executescexe (2), executeaptupdate (2), emptyresourceinitializemethod (2), dslincludeinresource (2), dependsonzyppercookbook (2), dependsonwindowsfirewallcookbook (2), dependsontimezonelwrpcookbook (2), dependsonopensslcookbook (2), dependsonlocalecookbook (2), dependsonkernelmodulecookbook (2), dependsonchocolateycookbooks (2), dependsonchefvaultcookbook (2), definitions (2), defineschefspecmatchers (2), defaultactionfrominitialize (2), declareactionclass (2), databaghelpers (2), customresourcewithattributes (2), cronmanageresource (2), crondfileortemplate (2), conditionalusingtest (2), classevalactionclass (2), chefgemnokogiri (2), allowedactionsfrominitialize (2), actionmethodinresource (2), modernize (2), searchforenvironmentsorroles (2), dependschefvault (2), cookbookusessearch (2), cookbookusesroles (2), cookbookusespolicygroups (2), cookbookusesenvironments (2), cookbookusesdatabags (2), chefvaultused (2), berksfile (2), windowsversionhelpers (2), windowstaskchangeaction (2), windowspackageinstallertypestring (2), windowsfeatureservermanagercmd (2), verifypropertyusesfileexpansion (2), useyamldump (2), usesruncommandhelper (2), usesdeprecatedmixins (2), useschefresthelpers (2), userdeprecatedsupportsproperty (2), useinlineresourcesdefined (2), useautomaticresourcename (2), searchusespositionalparameters (2), rubyblockcreateaction (2), ruby27keywordargumentwarnings (2), resourcewithoutunifiedtrue (2), resourceusesupdatedmethod (2), resourceusesproviderbasemethod (2), resourceusesonlyresourcename (2), resourceusesdslnamemethod (2), resourceoverridesprovidesmethod (2), resourceinheritsfromcompatresource (2), requirerecipe (2), powershellcookbookhelpers (2), policyfilecommunitysource (2), poisearchiveusage (2), partialsearchhelperusage (2), partialsearchclassusage (2), nodesetwithoutlevel (2), nodesetunless (2), nodeset (2), nodemethodsinsteadofattributes (2), nodedeepfetch (2), namepropertywithdefaultvalue (2), macosuserdefaultsglobalproperty (2), logresourcenotifications (2), localedeprecatedlcallproperty (2), librarianchefspec (2), legacyyumcookbookrecipes (2), legacynotifysyntax (2), launchddeprecatedhashproperty (2), includingyumdnfcompatrecipe (2), includingxmlrubyrecipe (2), hwrpwithoutunifiedtrue (2), hwrpwithoutprovides (2), foodcritictesting (2), foodcriticfile (2), executerelativecreateswithoutcwd (2), executepathproperty (2), erlcallresource (2), epicfail (2), eolauditmodeusage (2), easyinstallresource (2), deprecatedyumrepositoryproperties (2), deprecatedyumrepositoryactions (2), deprecatedwindowsversioncheck (2), deprecatedsudoactions (2), deprecatedshelloutmethods (2), deprecatedplatformmethods (2), deprecatedchefspecplatform (2), dependsonomnibusupdatercookbook (2), dependsonchefreportingcookbook (2), dependsonchefnginxcookbook (2), delivery (2), cookbooksdependsonself (2), cookbookdependsonpoise (2), cookbookdependsonpartialsearch (2), cookbookdependsoncompatresource (2), chocolateypackageuninstallaction (2), chefwindowsplatformhelper (2), chefsugarhelpers (2), chefspeclegacyrunner (2), chefspeccoveragereport (2), chefshellout (2), chefrewind (2), chefhandlerusessupports (2), chefhandlerrecipe (2), cheffile (2), chefdkgenerators (2), tmppath (2), supportsmustbefloat (2), serviceresource (2), scopedfileexist (2), resourcewithnoneaction (2), resourcesetsnameproperty (2), resourcesetsinternalproperties (2), propertywithouttype (2), powershellscriptdeletefile (2), powershellfileexists (2), opensslpasswordhelpers (2), octalmodeasstring (2), notifiesactionnotsymbol (2), nodenormalunless (2), nodenormal (2), metadatamissingversion (2), metadatamissingname (2), metadatamalformeddepends (2), malformedplatformvalueforplatformhelper (2), macosuserdefaultsinvalidtype (2), lazyinresourceguard (2), lazyevalnodeattributedefaults (2), invalidversionmetadata (2), invalidplatformvalueforplatformhelper (2), invalidplatformvalueforplatformfamilyhelper (2), invalidplatformmetadata (2), invalidplatformincase (2), invalidplatformhelper (2), invalidplatformfamilyincase (2), invalidplatformfamilyhelper (2), invalidnotificationtiming (2), invalidnotificationresource (2), invaliddefaultaction (2), invalidcookbookname (2), incorrectlibraryinjection (2), emptyresourceguard (2), dnfpackageallowdowngrades (2), cookbookusesnodesave (2), conditionalrubyshellout (2), chefapplicationfatal (2), blockguardwithonlystring (2), correctness (2), list (2), v25 (2), tuning (2), failure (2), optional (2), tiered (2), installation (2), airgap (2), capacity (2), planning (2), plan (2), base (2), 2025 (2), refresh (2), strategy (2), bootstrap (2), membership (2), rbac (2), keys (2), rotate (2), certs (2), separate (2), scale (2), frontend (2), artifactory (2), artifact (2), store (2), warm (2), spare (2), env (2), windows_update_settings (2), windows_power_management (2), windows_password_policy (2), windows_ie_esc (2), windows_firewall (2), windows_disk_encryption (2), windows_desktop_winrm_settings (2), windows_desktop_screensaver (2), windows_defender_exclusion (2), windows_defender (2), windows_choco_installer (2), windows_automatic_logout (2), windows_app_management (2), windows_admin_control (2), rescue_account (2), macos_power_management (2), macos_password_policy (2), macos_firewall (2), macos_disk_encryption (2), macos_desktop_screensaver (2), macos_automatic_software_updates (2), macos_automatic_logout (2), macos_app_management (2), macos_admin_control (2), windows (2), macos (2), touch (2), redirect (2), sso (2), opsworks (2), skills (2), administration (2), guides (2), enroll (2), clis (2), non (2), san (2), best (2), practices (2), feature (2), flags (2), cli (2), architecture (2), incident (2), servicenow (2), marketplace (2), runs (2), scan (2), reports (2), eas (2), event (2), feed (2), teams (2), policies (2), actions (2), projects (2), credentials (2), lifecycle (2), feeds (2), notifications (2), cleanup (2), monitoring (2), centralize (2), report (2), ingestion (2), invalid (2), login (2), attempts (2), telemetry (2), session (2), timeout (2), disclosure (2), panel (2), banner (2), collection (2), topics (2), manager (2), machine (2), sudo (2), rds (2), vpc (2), cidr (2), load (2), balancer (2), faqs (2), performance (2), benchmarks (2), rotation (2), self (2), signed (2), view (2), bootstrapping (2), commands (2), verify (2), generation (2), remove (2), place (2), existing (2), efs (2), back (2), storage (2), filesystem (2), customer (2), airgapped (2), tutorial (2), shortcodes (2), front (2), matter (2), reuse (2), hugo (2), procedures (2), headings (2), notices (2), markdown (2), lists (2), linking (2), formatting (2), tools (2), house (2), contribute (2), guidelines (2), contributions (2), commercial (2), script (2), versions (2), accept (2), training (2), blog (2), certain, used, registered, countries, see, appropriate, markings, any, contained, inclusion, does, imply, endorsement, affiliation, sponsorship, copyright, modified, april, cookie, privacy, trademark, site, map, thank, submit, fill, field, improve, ask, contact, still, stuck, yes, helpful, take, tour, know, apply, debug, level, 20480, print_db_statistics, 5432, port, host, whether, case, archived, username, turns, issuer, ciphers, compression, disables, timing, out, response, disconnecting, slots, limits, standbys, health, threshold, 300, just, greater, segment, 300kb, utility, performing, modifications, require, elects, reflects, updated, after, described, documentation, concurrent, must, shared, tracks, max_prepared_transactions, means, most, distinct, average, allocated, transactions, more, long, fit, limit, rows, smallest, past, kept, pg_wal, needs, fetch, streaming, extra, purposes, result, old, servers, depends, location, previous, checkpoint, status, helps, reserve, enough, space, handle, spikes, batch, specify, without, units, treats, megabytes, grow, conf, longest, range, day, five, minutes, collector, background, process, captures, messages, sent, stderr, redirects, into, printf, string, output, beginning, message, levels, records, debug5, debug4, debug3, debug2, info, notice, fatal, panic, please, want, detailed, these, properties, affect, official, provides, options, customize, behavior, meet, specific, documents, menu, search, skip,
Text of the page (random words):
ue_account windows_admin_control windows_app_management windows_automatic_logout windows_choco_installer windows_defender windows_defender_exclusion windows_desktop_screensaver windows_desktop_winrm_settings windows_disk_encryption windows_firewall windows_ie_esc windows_password_policy windows_power_management windows_update_settings chef habitat habitat v 2 1 habitat v 2 0 habitat v 1 6 habitat builder about habitat builder on prem builder about on prem builder install overview system requirements install builder connect your workstation to builder configure overview example builder env config file configure disaster recovery or warm spare use artifactory as a package artifact store configure builder logs scale builder frontend separate backend services manage overview minio postgresql rotate ssl certs upgrade builder origins overview create an origin origin keys origin membership and rbac packages overview bootstrap core packages update packages troubleshooting saas builder about habitat saas builder create an account builder profile origins origin packages builder api supported packages habitat package refresh strategy core base 2025 packages chef infra client chef infra client 19 chef infra client 18 chef infra server overview infra server overview services plan chef infra server prerequisites capacity planning install install chef infra server install high availability airgap tiered installation upgrades upgrade ha cluster license usage configure chef server rb settings chef infra server optional settings chef backend rb settings server firewalls and ports security manage backup and restore backend failure recovery monitor tuning log files users authentication and authorization organizations groups server users reference chef server ctl chef backend ctl chef infra server api firewalls ports chef inspec version 7 1 version 7 0 version 6 8 version 5 24 version 5 23 resource packs chef workstation workstation v26 1 workstation v26 0 workstation v25 cookstyle about cookstyle cookstyle cops list cops chef correctness blockguardwithonlystring chefapplicationfatal conditionalrubyshellout cookbookusesnodesave dnfpackageallowdowngrades emptyresourceguard incorrectlibraryinjection invalidcookbookname invaliddefaultaction invalidnotificationresource invalidnotificationtiming invalidplatformfamilyhelper invalidplatformfamilyincase invalidplatformhelper invalidplatformincase invalidplatformmetadata invalidplatformvalueforplatformfamilyhelper invalidplatformvalueforplatformhelper invalidversionmetadata lazyevalnodeattributedefaults lazyinresourceguard macosuserdefaultsinvalidtype malformedplatformvalueforplatformhelper metadatamalformeddepends metadatamissingname metadatamissingversion nodenormal nodenormalunless notifiesactionnotsymbol octalmodeasstring opensslpasswordhelpers powershellfileexists powershellscriptdeletefile propertywithouttype resourcesetsinternalproperties resourcesetsnameproperty resourcewithnoneaction scopedfileexist serviceresource supportsmustbefloat tmppath chef deprecations chefdkgenerators cheffile chefhandlerrecipe chefhandlerusessupports chefrewind chefshellout chefspeccoveragereport chefspeclegacyrunner chefsugarhelpers chefwindowsplatformhelper chocolateypackageuninstallaction cookbookdependsoncompatresource cookbookdependsonpartialsearch cookbookdependsonpoise cookbooksdependsonself delivery dependsonchefnginxcookbook dependsonchefreportingcookbook dependsonomnibusupdatercookbook deprecatedchefspecplatform deprecatedplatformmethods deprecatedshelloutmethods deprecatedsudoactions deprecatedwindowsversioncheck deprecatedyumrepositoryactions deprecatedyumrepositoryproperties easyinstallresource eolauditmodeusage epicfail erlcallresource executepathproperty executerelativecreateswithoutcwd foodcriticfile foodcritictesting hwrpwithoutprovides hwrpwithoutunifiedtrue includingxmlrubyrecipe includingyumdnfcompatrecipe launchddeprecatedhashproperty legacynotifysyntax legacyyumcookbookrecipes librarianchefspec localedeprecatedlcallproperty logresourcenotifications macosuserdefaultsglobalproperty namepropertywithdefaultvalue nodedeepfetch nodemethodsinsteadofattributes nodeset nodesetunless nodesetwithoutlevel partialsearchclassusage partialsearchhelperusage poisearchiveusage policyfilecommunitysource powershellcookbookhelpers requirerecipe resourceinheritsfromcompatresource resourceoverridesprovidesmethod resourceusesdslnamemethod resourceusesonlyresourcename resourceusesproviderbasemethod resourceusesupdatedmethod resourcewithoutunifiedtrue ruby27keywordargumentwarnings rubyblockcreateaction searchusespositionalparameters useautomaticresourcename useinlineresourcesdefined userdeprecatedsupportsproperty useschefresthelpers usesdeprecatedmixins usesruncommandhelper useyamldump verifypropertyusesfileexpansion windowsfeatureservermanagercmd windowspackageinstallertypestring windowstaskchangeaction windowsversionhelpers chef effortless berksfile chefvaultused cookbookusesdatabags cookbookusesenvironments cookbookusespolicygroups cookbookusesroles cookbookusessearch dependschefvault searchforenvironmentsorroles chef modernize actionmethodinresource allowedactionsfrominitialize chefgemnokogiri classevalactionclass conditionalusingtest crondfileortemplate cronmanageresource customresourcewithattributes databaghelpers declareactionclass defaultactionfrominitialize defineschefspecmatchers definitions dependsonchefvaultcookbook dependsonchocolateycookbooks dependsonkernelmodulecookbook dependsonlocalecookbook dependsonopensslcookbook dependsontimezonelwrpcookbook dependsonwindowsfirewallcookbook dependsonzyppercookbook dslincludeinresource emptyresourceinitializemethod executeaptupdate executescexe executesleep executesysctl executetzutil foodcriticcomments ifprovidesdefaultaction includingaptdefaultrecipe includingmixinshelloutinresources includingohaidefaultrecipe includingwindowsdefaultrecipe legacyberksfilesource libarchivefileresource macosxuserdefaults minitesthandlerusage nodeinitpackage noderolesinclude opensslrsakeyresource opensslx509resource osxconfigprofileresource powershellguardinterpreter powershellinstallpackage powershellinstallwindowsfeature powershellscriptexpandarchive propertywithnameattribute providesfrominitialize resourceforcingcompiletime resourcenamefrominitialize respondtocompiletime respondtoinmetadata respondtoprovides respondtoresourcename setorreturninresources sevenziparchiveresource shellouthelper shellouttochocolatey simplifyaptppasetup sysctlparamresource unnecessarydependschef14 unnecessarydependschef15 unnecessarymixlibshelloutrequire usebuildessentialresource usecheflanguagecloudhelpers usecheflanguageenvhelpers usecheflanguagesystemdhelper usemultipackageinstalls userequirerelative useszypperrepo whyrunsupportedtrue windowsregistryuac windowsscresource windowszipfileusage zipfileresource chef redundantcode aptrepositorydistributiondefault aptrepositorynotifiesaptupdate attributemetadata conflictsmetadata customresourcewithallowedactions doublecompiletime groupingmetadata longdescriptionmetadata multipleplatformchecks namepropertyisrequired ohaiattributetostring propertysplatregex propertywithrequiredanddefault providesmetadata recipemetadata replacesmetadata resourcewithnothingaction sensitivepropertyinresource stringpropertywithnildefault suggestsmetadata unnecessarydesiredstate unnecessarynameproperty usecreateifmissing chef ruby gemspeclicense gemspecrequirerubygems legacypowershelloutmethods requirenethttps unlessdefinedrequire chef security sshprivatekey chef sharing defaultmetadatamaintainer emptymetadatafield includepropertydescriptions includeresourcedescriptions includeresourceexamples insecurecookbookurl invalidlicensestring chef style attributekeys chefwhaaat commentformat commentsentencespacing copyrightcommentformat defaultcopyrightcomments filemode immediatenotificationtiming includerecipewithparentheses negatingonlyif overlycomplexsupportsdependsmetadata simplifyplatformmajorversioncheck trueclassfalseclassresourceproperties unnecessaryoscheck unnecessaryplatformcasestatement useplatformhelpers inspec deprecations attributedefault attributehelper effortless pattern effortless overview quick start effortless audit effortless config variables and config what is scaffolding supermarket about supermarket share cookbooks private supermarket about private supermarket install configure backup and restore monitor log files upgrades reference supermarket ctl supermarket api release notes chef 360 platform chef automate chef backend chef download apis chef habitat chef infra client chef infra server chef inspec chef local license service chef manage chef migrate chef supermarket chef workstation chef compliance chef compliance audit profiles chef compliance remediation chef cloud resource packs aws cloud resources azure cloud resources legacy chef manage about the management console uninstall manage rb chef manage ctl active directory ldap configure saml clients cookbooks data bags environments nodes roles organizations groups users uninstall available on github downloads send feedback support ha postgresql node config table of contents configurations the postgresql node in chef automate ha provides configuration options you can use to customize its behavior and meet specific requirements this guide documents all settings you can patch the detailed document about how these individual properties affect the system is at official postgresql docs patch the below configuration to postgresql nodes please add the values you want to patch to a config toml file and run the chef automate config patch config toml pg from the bastion logging log_level error log_line_prefix t p l 1 user u db d client h r x e logging_collector on in the above snippet log_level controls which message levels the server log records valid values are debug5 debug4 debug3 debug2 debug1 info notice warning error log fatal and panic the default value is warning log_line_prefix is a printf style string output at the beginning of each log line logging_collector enables the logging collector which is a background process that captures log messages sent to stderr and redirects them into log files checkpoints checkpoint_timeout 5min max_wal_size 1gb min_wal_size 80mb in the above snippet checkpoint_timeout sets the longest time between automatic wal checkpoints the valid range is between 30 seconds and one day the default is five minutes 5min increasing this parameter can increase the amount of time needed for crash recovery max_wal_size sets the largest size that wal can grow to during automatic checkpoints the default is 1 gb increasing this parameter can increase the amount of time needed for crash recovery set this parameter in the postgresql conf file or on the server command line min_wal_size helps reserve enough wal space to handle spikes in wal usage for example when running large batch jobs if you specify this value without units postgresql treats it as megabytes the default is 80 mb write ahead log keep size wal_keep_size 1600 wal_keep_size specifies the smallest size of past log file segments kept in the pg_wal directory if a standby server needs to fetch them for streaming replication if wal_keep_size is zero the default the system doesn t keep extra segments for standby purposes as a result the number of old wal segments available to standby servers depends on the location of the previous checkpoint and the status of wal archiving lock management max_locks_per_transaction 64 the shared lock table tracks locks on max_locks_per_transaction max_connections max_prepared_transactions objects for example tables this means the system can lock at most that number of distinct objects at a time this parameter controls the average number of object locks allocated for each transaction individual transactions can lock more objects as long as all transaction locks fit in the lock table this doesn t limit the number of rows that a transaction can lock the default is 64 when running a standby server you must set this parameter to the same or higher value than on the primary server otherwise the standby server won t allow queries max connections max_connections 350 the highest number of concurrent connections to the database server the default for chef automate is 350 connections when running a standby server set this parameter to the same or higher value than on the primary server otherwise the standby server won t allow queries note modifications to max_connections require a reboot of the leader and the cluster elects a new leader during that reboot the configuration reflects the updated max_connections value after the reboot as described in the postgresql documentation pg dump pg_dump enable true path mnt automate_backups postgresql pg_dump this section configures pg_dump a postgresql utility for performing database backups it enables pg_dump and specifies the path where pg_dump stores backups replication replication name replication password replication note lag_health_threshold is in bytes default to 300kb this is just greater than 1 wal segment lag_health_threshold 307200 largest lag time in seconds since log was last replayed before replica is eligible for a restart max_replay_lag_before_restart_s 180 max_wal_senders 10 max_replication_slots 5 wal_sender_timeout 60 wal_receiver_timeout 60 wal_compression off this section configures replication settings name replication name password replication password lag_health_threshold sets the lag health threshold to 307200 bytes 300 kb the highest allowed replication lag max_replay_lag_before_restart_s custom setting largest lag time in seconds since log was last replayed before replica is eligible for a restart max_wal_senders limits the number of standbys that can connect for replication default 10 max_replication_slots sets the number of allowed replication slots default 5 wal_sender_timeout primary waits 60 seconds for standby response before disconnecting wal_receiver_timeout standby waits 60 seconds for data from primary before timing out wal_compression controls compression of wal data off disables it on enables it transport security settings ssl enable true issuer_cert enter root ca ssl_cert enter public key ssl_key enter private key tls_ciphers ecdhe ecdsa aes256 gcm sha384 ecdhe rsa aes256 gcm sha384 ecdhe ecdsa chacha20 poly1305 ecdhe rsa chacha20 poly1305 ecdhe ecdsa aes128 gcm sha256 ecdhe rsa aes128 gcm sha256 this section configures ssl tls settings it turns on ssl and specifies the root ca issuer certificate the public key certificate the private key and the allowed tls ciphers user superuser name admin password admin this section specifies the username and password for the superuser administrator account write ahead log archive wal_archive enable false path mnt automate_backups postgresql archive this section configures wal archiving it specifies whether wal archiving is on false in this case and the path where the system stores archived wal files f...
|