Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tp6ao-000Xn1-Sc for pgsql-admin@arkaria.postgresql.org; Mon, 03 Mar 2025 14:16:26 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1tp6an-008XW5-Kx for pgsql-admin@arkaria.postgresql.org; Mon, 03 Mar 2025 14:16:25 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tp6an-008XVx-9U for pgsql-admin@lists.postgresql.org; Mon, 03 Mar 2025 14:16:25 +0000 Received: from mail-wr1-x429.google.com ([2a00:1450:4864:20::429]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1tp6ag-000iyV-2L for pgsql-admin@postgresql.org; Mon, 03 Mar 2025 14:16:24 +0000 Received: by mail-wr1-x429.google.com with SMTP id ffacd0b85a97d-38f2f391864so2486313f8f.3 for ; Mon, 03 Mar 2025 06:16:18 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1741011377; x=1741616177; darn=postgresql.org; h=user-agent:in-reply-to:content-disposition:mime-version:references :subject:cc:to:from:date:sender:message-id:from:to:cc:subject:date :message-id:reply-to; bh=8rnNzaWyFHThsd1lDSiM4dHOUs772KgiA5LUGSqN5BE=; b=DVBsyPjg3sYy26g14bLnKAF6CZRoUOAd35anNtXPmdci14ipcB8NyKTgxTgc4mbzkl tlvbc05p10/mFTu6UjbQF1m7sAD8LwYhbOU9mDaVdeoHNk5QOrlvWoKDzI1Kgu68EToB PnLX+0CNaXu0SgL/fAK7aOcezEzqVw0Lwz1398GLaV+LcVZ8AZKvpOZJy2Pa/Y+YDDB1 uo2WP/vZTQNtIq1plYo8m7jNw+42Pa/Db9yuEoknsxy4cleRdBP/8qGQ43+a/GiXgfRR sCwUepFmt7CgVO25Y81REIpGA+PbAFpgmar+RNj6YCPSHM/O9phUNDfuAkJ21xMCwIVc WjNQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1741011377; x=1741616177; h=user-agent:in-reply-to:content-disposition:mime-version:references :subject:cc:to:from:date:sender:message-id:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=8rnNzaWyFHThsd1lDSiM4dHOUs772KgiA5LUGSqN5BE=; b=U7jsiAk0Dk6Vq41AoDoFaPBaGR2Cc2hshqx36P1Iyaxap/rTOwlDrQlntvEQu99y3D pszBHdT6AHSYFBlEEr7QPbqZD4vbzAcjRgK86wwMLpCUewvIenPyW8sZv4WQtYciz3AK 8tBOeIWlR7KXfe8pdx7U+l1nEfYJ6DM5kCXnRi8Z9JrwRIcwgEhN//3FoJa6Vvotkmd5 5NctGw/A1yRdWFNtNOds6Y0/qa0v/aGwW2nqRIbTHusLY3AqflV92n/u2vN0y7PwYXEU dhmCND8x4fYKiUoOx37RK5yFs9cdGdDcPtIv6vxSYmcfVZ1AZmrO160I/oOdP8Q+Niz+ Iy7w== X-Forwarded-Encrypted: i=1; AJvYcCUEV0Mz0rnn1nT6KN+fd00XbGrDRKCVSE3xV+sQdG+gZ5gZooBELo41dED4JUl8LpnYioiimKTmfED/4g==@postgresql.org X-Gm-Message-State: AOJu0YyGpU8PXSQObQDCGgJRHpnfWCsnFOYVDcp+HYO8npbAeMeDEdCt ONJaxvX0euSMIHl3kmFLqr1z78FSKLumdldz9sEScid6BOB6NbQiDxl7OQ== X-Gm-Gg: ASbGncsvcK+tlNm3I1h22wR5EFgtF2oHCELSB3wnKZF9Qii4ilwpg2nUI+NaaIzzw2/ haO/+0C0tw9FIRqdYR9TF32tVLMyX77SLXezOm3aCVAnaPihAUtTp0JtZHlS1EmU1rhX3OPMjJ2 BmQQaITR0gz3mYOzBLKVnFnNmjmuE5Nh+PwwPsn8Wu9wDKSEjkfyKi4RGhhJWSFwgWGdMA5Sn8x Y3sY/hwNT243k21GsnK9HFSn7NPAUoaM1RtWFOjfPA+e+6aNNdPGUZSLJSEUwxtfP7bOg7pNSJu cYvn8f2klKcbFcodrNLlgtS43kbxAIPNfc9CO3iptC5FF8Ym2Z6zfZA/OOfzfLxwwad4kSkyTis 9Knau X-Google-Smtp-Source: AGHT+IFFh0Agb2DHCMNPiC6BuuxAD2vYhbvEfrqSG3uHia0eb1gL36IlFupCFjMQ09HuW2BNFJKAbA== X-Received: by 2002:a05:6000:1f88:b0:391:34:4fa9 with SMTP id ffacd0b85a97d-391003450d4mr5430279f8f.0.1741011377310; Mon, 03 Mar 2025 06:16:17 -0800 (PST) Received: from lightning.caipicrew.dd-dns.de ([2001:a61:1023:fa01:30f7:a173:8273:ac3f]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-390e46f580bsm14425055f8f.0.2025.03.03.06.16.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Mar 2025 06:16:16 -0800 (PST) Message-ID: <67c5b9b0.050a0220.324e87.5ae8@mx.google.com> X-Google-Original-Message-ID: <20250303141615.GB8307@caipicrew.dd-dns.de;lightning.caipicrew.dd-dns.de> Sender: Michael Banck Received: from mbanck by lightning.caipicrew.dd-dns.de with local (Exim 4.92) (envelope-from ) id 1tp6ae-0002Al-1b; Mon, 03 Mar 2025 15:16:16 +0100 Date: Mon, 3 Mar 2025 15:16:15 +0100 From: Michael Banck To: kamal deen Cc: Ron Johnson , pgsql-admin Subject: Re: Super user password explicit in patroni yml References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.10.1 (2018-07-13) List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Hi, On Thu, Feb 27, 2025 at 01:30:55AM +0530, kamal deen wrote: > Without .pgpass file patroni can connect to postgres ? Well, I think you could also set the password via environment variables, but I am not sure that is much better form a security point-of-view. As an alternative, if you have unix sockets configured and keep the superuser password empty, Patroni will use a local unix socket connection, i.e. does not require a superuser password to be set. > How patroni service works in this sinario? If you want to use pg_rewind, you will need to configure an additional pg_rewind user (with a password, cause pg_rewind connects remotely) if your superuser has no password. If you add this to a running Patroni cluster, I think Patroni will not GRANT the necessary function execution rights to this pg_rewind user so you will have to do this yourself. This should all be in the Patroni documentation. Michael