Cluster actions

This article describes the actions available for the ADB ES cluster in the ADCM UI.

Overview

You can find cluster actions on the Clusters page.

The Clusters page
The Clusters page

Refer to ADCM documentation for an overview of the Clusters page and common actions.

The Actions column shows icons for managing the cluster:

  • The Actions icon The Actions icon — opens the drop-down list that offers actions to manage the cluster.

    Open a list of available cluster actions
    Open a list of available cluster actions
  • The Upgrade icon — indicates whether a new version of a bundle is available and allows you to upgrade the cluster.

  • The Delete icon — deletes information about the cluster from ADCM (it does not remove ADB ES or make any changes to hosts that belong to the cluster).

IMPORTANT

When upgrading ADB ES, follow the order:

  1. Upgrade an ADB ES cluster.

  2. Upgrade agents on the ADB side (see the Reinstall service action for ADBC agents and ADBM agents).

A set of cluster actions (available after clicking The Actions icon The Actions icon) depends on the current ADB ES cluster status.

Available actions depending on the ADB ES status
Status Condition Available actions

created

The ADB ES cluster was created via ADCM, but not installed yet

installed

The ADB ES cluster was successfully installed via ADCM

ready to upgrade

The ADB ES cluster has been prepared for upgrade. The cluster gets this status after you click The Upgrade icon and before you run the Upgrade cluster action

For information on the Precheck and Install actions, see Install a cluster. The actions for an installed cluster are described below.

Check

The Check action verifies that all hosts, components, and services are configured according to the ADB ES cluster requirements (similarly to what the Precheck action does). Additionally, it checks the status of each ADB ES service.

Reconfigure Vault integration

The Reconfigure Vault integration action is used to apply changes to the Vault configuration parameters. These parameters are available on the Configuration tab of the cluster page and allow you to store secrets of ADB ES services in HashiCorp Vault.

IMPORTANT
  • The Vault configuration switcher can be enabled and Vault can be configured only after the cluster is installed. While the cluster is in the created state, this section cannot be modified.

  • Before editing Vault integration parameters, ensure that Vault is installed and configured.

  • Each time you edit and save parameters in the Vault configuration section, run the cluster action Reconfigure Vault integration.

  • Currently, Vault can be used to store authentication parameters of ADB Control and ADBM.

  • If you need to store credentials for the ADB Control Query DB and Metrics DB in Vault, set up these databases as external.

Manage SSL

Configures and enables SSL for the entire ADB ES cluster. In the window that opens, select SSL configuration to enable SSL and configure the parameters described below.

IMPORTANT

After you enable or disable SSL in ADB ES, run the Reconfigure and restart action of the ADBC agents and ADBM agents services in the corresponding ADB clusters integrated with the current ADB ES cluster.

Parameter Description

Verify system endpoints' certificates

Enables verification of system endpoint certificates. When using this option with self-signed certificates, make sure that you added the root and intermediate CA certificates to the OS trusted root certificate stores. In order to use the Verify system endpoints' certificates option with your own certificates, for proper verification, add the ADB Control IP address to the CN field of the san.cnf file (SAN) and exclude DNS from the alt_names section (leave only the IP address)

Postgres server certificate path

Path to the PostgreSQL certificate file (in PEM format). Required file permissions: 640, owner and group: postgres:postgres. The field is only available for the internal type of the Database service

Postgres server private key path

Path to the PostgreSQL private key file (in PEM format). Required file permissions: 600, owner and group: postgres:postgres. The field is only available for the internal type of the Database service

clickhouse ca certificate path

Path to the root CA certificate for ClickHouse (in PEM format). Required file permissions: 640, owner and group: clickhouse:clickhouse. The field is only available for the internal type of the Clickhouse service

clickhouse server certificate path

Path to the ClickHouse server certificate file (in PEM format). Required file permissions: 640, owner and group: clickhouse:clickhouse. The field is only available for the internal type of the Clickhouse service

clickhouse server private key path

Path to the ClickHouse server private key file (in PEM format). Required file permissions: 600, owner and group: clickhouse:clickhouse. The field is only available for the internal type of the Clickhouse service

Server truststore path

Path to the truststore for server-side Java components: ADB Control, ADBM, and AD Eureka. Format: PKCS #12. Required owner and group: adcc:adbes.

If ADBM is installed on a separate host, the required owner and group of its truststore file are adbm:adbes.

Server truststore password

Password that was set for the server truststore specified in Server truststore path

Server keystore path

Path to the keystore for server-side Java components: ADB Control, ADBM, and AD Eureka. Format: PKCS #12. Required owner and group: adcc:adbes.

If ADBM is installed on a separate host, the required owner and group of its keystore file are adbm:adbes.

Server keystore password

Password that was set for the server keystore specified in Server keystore path

Agent truststore path

Path to the truststore for ADBC/ADBM agents (on the ADB hosts). Format: PKCS #12. Required owner and group: gpadmin:gpadmin

Agent truststore password

Password that was set for the agents truststore specified in Agent truststore path

Agents keystore path

Path to the keystore for agents. Format: PKCS #12. Required owner and group: gpadmin:gpadmin

Agents keystore password

Password that was set for the agents keystore specified in Agents keystore path

NOTE

During ADB ES installation, the bundle automatically creates the adbes group on each ADB ES host and adds the adcc and adbm users to it. The default group identifier is 3033, which can be changed using the ADB ES group GID parameter in the cluster configuration.

The Manage SSL window
The Manage SSL window

Certificate requirements

When creating certificates, the requirements are as follows:

  • If ADB Control, ADBM, and AD Eureka are installed on separate hosts, the absolute paths to the keystore and truststore files must be identical on all hosts. You then specify these paths in Server keystore path and Server truststore path.

  • The file owners (listed above) must have read access to every directory in the path to the truststore and keystore files.

  • The Manage SSL cluster action doesn’t apply to external databases. If you use them, import their certificates to the truststore specified in Server truststore path.

Check results

If the Manage SSL action completed successfully, the ADB ES components start interacting over SSL. The web servers will require TLS, so to access the web interfaces of the services, use https while entering their addresses:

  • ADB Control: https://<ADB Control UI IP address>:8890

  • AD Eureka: https://<AD Eureka IP address>:8761

  • Clickhouse: https://<Clickhouse IP address>:8443 (when SSL is disabled, the 8123 port is used instead)

You can also check that TLS is used in PostgreSQL. For example, for internal ADPG databases, connect to adcc or adbm:

$ sudo su - postgres
$ psql -p 5433 -d adcc

As a result, the TLS version is shown indicating that encrypted connections are used between the database and clients:

psql (16.3)
SSL connection (protocol: TLSv1.3, cipher: TLS_AES_256_GCM_SHA384, compression: off)
Type "help" for help.

adcc=#

Reinstall

The Reinstall action reinstalls the ADB ES cluster.

Reinstall statuschecker

The Reinstall statuschecker action reconfigures and restarts the statuschecker for all cluster services. Use this action when migrating a cluster to a new ADCM server.

Start

The Start action starts all services in the ADB ES cluster.

After you select the action, a dialog box opens where you can set the value for the Apply services configs from ADCM option. Enable this option to apply all changes made in the configurations of the services. Otherwise, the services will just start without applying the changes.

The Start window
The Start window

Stop

Stops all services of the ADB ES cluster.

Upgrade

Refer to the Upgrade ADB ES page.

Found a mistake? Seleсt text and press Ctrl+Enter to report it