5 # Copyright:: 2011, OpenStreetMap Foundation
7 # Licensed under the Apache License, Version 2.0 (the "License");
8 # you may not use this file except in compliance with the License.
9 # You may obtain a copy of the License at
11 # https://www.apache.org/licenses/LICENSE-2.0
13 # Unless required by applicable law or agreed to in writing, software
14 # distributed under the License is distributed on an "AS IS" BASIS,
15 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 # See the License for the specific language governing permissions and
17 # limitations under the License.
20 include_recipe "db::base"
22 passwords = data_bag_item("db", "passwords")
24 postgresql_user "tomh" do
25 cluster node[:db][:cluster]
29 postgresql_user "matt" do
30 cluster node[:db][:cluster]
34 postgresql_user "openstreetmap" do
35 cluster node[:db][:cluster]
36 password passwords["openstreetmap"]
39 postgresql_user "rails" do
40 cluster node[:db][:cluster]
41 password passwords["rails"]
44 postgresql_user "cgimap" do
45 cluster node[:db][:cluster]
46 password passwords["cgimap"]
49 postgresql_user "planetdump" do
50 cluster node[:db][:cluster]
51 password passwords["planetdump"]
54 postgresql_user "planetdiff" do
55 cluster node[:db][:cluster]
56 password passwords["planetdiff"]
60 postgresql_user "backup" do
61 cluster node[:db][:cluster]
62 password passwords["backup"]
65 postgresql_user "munin" do
66 cluster node[:db][:cluster]
67 password passwords["munin"]
70 postgresql_user "replication" do
71 cluster node[:db][:cluster]
72 password passwords["replication"]
76 postgresql_database "openstreetmap" do
77 cluster node[:db][:cluster]
81 postgresql_extension "btree_gist" do
82 cluster node[:db][:cluster]
83 database "openstreetmap"
84 only_if { node[:postgresql][:clusters][node[:db][:cluster]] && node[:postgresql][:clusters][node[:db][:cluster]][:version] >= 9.0 }
87 CGIMAP_PERMISSIONS = {
88 "changeset_comments" => [:select],
89 "changeset_tags" => [:select],
90 "changesets" => [:select, :update],
91 "client_applications" => [:select],
92 "current_node_tags" => [:select, :insert, :delete],
93 "current_nodes" => [:select, :insert, :update],
94 "current_nodes_id_seq" => [:update],
95 "current_relation_members" => [:select, :insert, :delete],
96 "current_relation_tags" => [:select, :insert, :delete],
97 "current_relations" => [:select, :insert, :update],
98 "current_relations_id_seq" => [:update],
99 "current_way_nodes" => [:select, :insert, :delete],
100 "current_way_tags" => [:select, :insert, :delete],
101 "current_ways" => [:select, :insert, :update],
102 "current_ways_id_seq" => [:update],
103 "node_tags" => [:select, :insert],
104 "nodes" => [:select, :insert],
105 "oauth_access_grants" => [:select],
106 "oauth_access_tokens" => [:select],
107 "oauth_applications" => [:select],
108 "oauth_nonces" => [:select, :insert],
109 "oauth_nonces_id_seq" => [:update],
110 "oauth_tokens" => [:select],
111 "relation_members" => [:select, :insert],
112 "relation_tags" => [:select, :insert],
113 "relations" => [:select, :insert],
114 "user_blocks" => [:select],
115 "user_roles" => [:select],
116 "users" => [:select],
117 "way_nodes" => [:select, :insert],
118 "way_tags" => [:select, :insert],
119 "ways" => [:select, :insert]
122 PLANETDUMP_PERMISSIONS = {
123 "note_comments" => :select,
128 PLANETDIFF_PERMISSIONS = {
129 "changeset_comments" => :select,
130 "changeset_tags" => :select,
131 "changesets" => :select,
132 "node_tags" => :select,
134 "relation_members" => :select,
135 "relation_tags" => :select,
136 "relations" => :select,
138 "way_nodes" => :select,
139 "way_tags" => :select,
143 PROMETHEUS_PERMISSIONS = {
144 "delayed_jobs" => :select
149 active_storage_attachments
151 active_storage_variant_records
156 changesets_subscribers
160 current_relation_members
161 current_relation_tags
169 diary_entry_subscriptions
186 oauth_openid_requests
203 postgresql_table table do
204 cluster node[:db][:cluster]
205 database "openstreetmap"
206 owner "openstreetmap"
207 permissions "openstreetmap" => [:all],
208 "rails" => [:select, :insert, :update, :delete],
209 "cgimap" => CGIMAP_PERMISSIONS[table],
210 "planetdump" => PLANETDUMP_PERMISSIONS[table],
211 "planetdiff" => PLANETDIFF_PERMISSIONS[table],
212 "prometheus" => PROMETHEUS_PERMISSIONS[table],
213 "backup" => [:select]
219 active_storage_attachments_id_seq
220 active_storage_blobs_id_seq
221 active_storage_variant_records_id_seq
222 changeset_comments_id_seq
224 client_applications_id_seq
226 current_relations_id_seq
229 diary_comments_id_seq
234 issue_comments_id_seq
239 oauth_access_grants_id_seq
240 oauth_access_tokens_id_seq
241 oauth_applications_id_seq
243 oauth_openid_requests_id_seq
252 postgresql_sequence sequence do
253 cluster node[:db][:cluster]
254 database "openstreetmap"
255 owner "openstreetmap"
256 permissions "openstreetmap" => [:all],
258 "cgimap" => CGIMAP_PERMISSIONS[sequence],
259 "backup" => [:select]
263 cookbook_file "/usr/local/share/monthly-reindex.sql" do
269 systemd_service "monthly-reindex" do
270 description "Monthly database reindex"
271 exec_start "/usr/bin/psql -f /usr/local/share/monthly-reindex.sql openstreetmap"
274 restrict_address_families "AF_UNIX"
277 systemd_timer "monthly-reindex" do
278 description "Monthly database reindex"
279 on_calendar "Sun *-*-1..7 02:00"
282 service "monthly-reindex.timer" do
283 action [:enable, :start]
286 cookbook_file "/usr/local/share/yearly-reindex.sql" do
292 systemd_service "yearly-reindex" do
293 description "Yearly database reindex"
294 exec_start "/usr/bin/psql -f /usr/local/share/yearly-reindex.sql openstreetmap"
297 restrict_address_families "AF_UNIX"
300 systemd_timer "yearly-reindex" do
301 description "Yearly database reindex"
302 on_calendar "Fri *-1-8..14 02:00"
305 service "yearly-reindex.timer" do
306 action [:enable, :start]
309 template "/etc/prometheus/exporters/sql_rails.collector.yml" do
310 source "sql_rails.yml.erb"