Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 6e7800721f | |||
| fe30792dbf | |||
| 0483f61904 | |||
| ac5a23350d | |||
| 5870da6249 | |||
| 5bf84b3719 | |||
| c55e4199e8 |
@@ -5,7 +5,7 @@
|
|||||||
#-------------------------------------------------------------------------------
|
#-------------------------------------------------------------------------------
|
||||||
|
|
||||||
# Change pg_hba location
|
# Change pg_hba location
|
||||||
hba_file = "/etc/postgres/pg_hba.conf"
|
hba_file = '/etc/postgres/pg_hba.conf'
|
||||||
|
|
||||||
|
|
||||||
#-------------------------------------------------------------------------------
|
#-------------------------------------------------------------------------------
|
||||||
@@ -16,7 +16,10 @@ hba_file = "/etc/postgres/pg_hba.conf"
|
|||||||
|
|
||||||
# Empty listen addresses to disable listening via TCP/IP
|
# Empty listen addresses to disable listening via TCP/IP
|
||||||
# because we want only uni socket connections
|
# because we want only uni socket connections
|
||||||
listen_addresses = ""
|
listen_addresses = ''
|
||||||
|
|
||||||
|
# Forbide access to users not in group postgres
|
||||||
|
unix_socket_permissions = 0770
|
||||||
|
|
||||||
|
|
||||||
#-------------------------------------------------------------------------------
|
#-------------------------------------------------------------------------------
|
||||||
@@ -26,4 +29,4 @@ listen_addresses = ""
|
|||||||
#-------------------------------------------------------------------------------
|
#-------------------------------------------------------------------------------
|
||||||
|
|
||||||
# Redirect logs to stderr to be managed by journald
|
# Redirect logs to stderr to be managed by journald
|
||||||
log_destination = "stderr"
|
log_destination = 'stderr'
|
||||||
|
|||||||
@@ -22,25 +22,32 @@ Install the database management system called postgresql with a predefined confi
|
|||||||
%make_install
|
%make_install
|
||||||
|
|
||||||
%post
|
%post
|
||||||
|
# Create sock directory if not existing
|
||||||
|
mkdir --parents --mode 755 "%{_rundir}/postgresql"
|
||||||
|
chown postgres:postgres "%{_rundir}/postgresql"
|
||||||
|
|
||||||
|
# Restart services
|
||||||
|
systemctl daemon-reload
|
||||||
|
systemctl reenable postgresql.service
|
||||||
|
systemctl restart postgresql.service
|
||||||
|
|
||||||
# Create databases and users from DB_USERS variable (separator is ",") if not existing
|
# Create databases and users from DB_USERS variable (separator is ",") if not existing
|
||||||
IFS="," read -ra users <<< "$DB_USERS";
|
IFS="," read -ra users <<< "$DB_USERS";
|
||||||
for user in "${users[@]}"; do
|
for user in "${users[@]}"; do
|
||||||
if ! runuser --user=postgres -- psql --quiet --tuples-only --command='\du' | grep --invert-match postgres | grep --quiet "$user"; then
|
usermod --append --groups postgres "$user";
|
||||||
|
if ! runuser --user=postgres -- psql --quiet --tuples-only --command='\du' | grep --quiet "$user"; then
|
||||||
runuser --user=postgres -- createuser "$user"
|
runuser --user=postgres -- createuser "$user"
|
||||||
runuser --user=postgres -- createdb --owner="$user" "$user"
|
runuser --user=postgres -- createdb --owner="$user" "$user"
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|
||||||
# Restart services
|
|
||||||
systemctl daemon-reload
|
|
||||||
systemctl reenable --now postgresql.service
|
|
||||||
|
|
||||||
%files
|
%files
|
||||||
%attr(755, root, root) %{_sysconfdir}/postgres
|
%dir %attr(755, root, root) %{_sysconfdir}/postgres
|
||||||
%attr(644, root, root) %{_sysconfdir}/postgres/postgresql.conf
|
%attr(644, root, root) %{_sysconfdir}/postgres/postgresql.conf
|
||||||
%attr(644, root, root) %{_sysconfdir}/postgres/pg_hba.conf
|
%attr(644, root, root) %{_sysconfdir}/postgres/pg_hba.conf
|
||||||
|
|
||||||
|
%dir %attr(755, root, root) %{_unitdir}/postgresql.service.d
|
||||||
%attr(644, root, root) %{_unitdir}/postgresql.service.d/postgres.conf
|
%attr(644, root, root) %{_unitdir}/postgresql.service.d/postgres.conf
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
%autochangelog
|
%autochangelog
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user