X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/2faca8ec3aa45a0df043050817831e3ea11dda23..455f8d9bfa94ac304fc34ae546bf8ceb5d5bc4cf:/roles/nominatim.rb diff --git a/roles/nominatim.rb b/roles/nominatim.rb index a98fd9f25..8981e500a 100644 --- a/roles/nominatim.rb +++ b/roles/nominatim.rb @@ -1,25 +1,19 @@ name "nominatim" -description "Role applied to all nominatim servers" +description "Role applied to all nominatim servers." default_attributes( :accounts => { :users => { :lonvia => { :status => :administrator }, - :twain => { :status => :administrator }, :nominatim => { :status => :role, - :members => [ :lonvia, :tomh, :twain ] - }, + :members => [:lonvia, :tomh] + } } }, - :apache => { - :mpm => "event", - :timeout => 60, - :keepalive => false, - :event => { - :server_limit => 32, - :max_clients => 1600, - :threads_per_child => 50 + :networking => { + :firewall => { + :http_rate_limit => "s:2/sec:15" } }, :postgresql => { @@ -27,17 +21,20 @@ default_attributes( :defaults => { :max_connections => "450", :synchronous_commit => "off", - :checkpoint_segments => "50", + :checkpoint_segments => "32", :checkpoint_timeout => "10min", :checkpoint_completion_target => "0.9", - :autovacuum_max_workers => "1" + :jit => "off", + :shared_buffers => "2GB", + :autovacuum_max_workers => "1", + :max_parallel_workers_per_gather => "0" } } }, :sysctl => { :postgres => { :comment => "Increase shared memory for postgres", - :parameters => { + :parameters => { "kernel.shmmax" => 26 * 1024 * 1024 * 1024, "kernel.shmall" => 26 * 1024 * 1024 * 1024 / 4096 } @@ -54,14 +51,22 @@ default_attributes( :parameters => { "vm.swappiness" => 10 } + }, + :network_conntrack_time_wait => { + :comment => "Only track completed connections for 30 seconds", + :parameters => { + "net.netfilter.nf_conntrack_tcp_timeout_time_wait" => "30" + } + }, + :network_conntrack_max => { + :comment => "Increase max number of connections tracked", + :parameters => { + "net.netfilter.nf_conntrack_max" => "196608" + } } - }, - :nominatim => { - :enabled => true, - :repository => "git://git.openstreetmap.org/nominatim.git" } ) run_list( - "recipe[nominatim]" + "recipe[nominatim::default]" )