249 lines
11 KiB
PowerShell
249 lines
11 KiB
PowerShell
# Local MySQL skip-grant create inquiry_robot; connect maint via shared-memory protocol.
|
|
# Then PG + .env -> 10.206.0.15 intranet.
|
|
$ErrorActionPreference = "Continue"
|
|
$mysqlBin = "C:\yutongda\tools\mysql-8.0.39-winx64\bin"
|
|
$mysql = Join-Path $mysqlBin "mysql.exe"
|
|
$mysqld = Join-Path $mysqlBin "mysqld.exe"
|
|
$ini = "C:\yutongda\tools\mysql-8.0.39-winx64\my.ini"
|
|
$datadir = "C:\yutongda\data\mysql"
|
|
$ops = "E:\wwwroot\ops"
|
|
$psql = "C:\yutongda\tools\pgsql\bin\psql.exe"
|
|
$sec = Get-Content "$ops\inquiry_robot_db_secrets.json" -Raw | ConvertFrom-Json
|
|
$mysqlPass = [string]$sec.mysql_password
|
|
$pgPass = [string]$sec.pg_password
|
|
$intranet = (Get-NetIPAddress -AddressFamily IPv4 | Where-Object { $_.IPAddress -like '10.*' } | Select-Object -First 1 -ExpandProperty IPAddress)
|
|
|
|
function New-Secret([int]$len = 48) {
|
|
$bytes = New-Object byte[] $len
|
|
[System.Security.Cryptography.RandomNumberGenerator]::Create().GetBytes($bytes)
|
|
return ([Convert]::ToBase64String($bytes) -replace '[+/=]', 'x').Substring(0, [Math]::Min(64, $len))
|
|
}
|
|
|
|
function Mysql-TcpOk([string]$h, [string]$u, [string]$p, [string]$db) {
|
|
$args = @("-h$h","-P3306","-u$u","-p$p","--connect-timeout=8","--batch","-N","-e","SELECT 1")
|
|
if ($db) { $args = @("-h$h","-P3306","-u$u","-p$p","--connect-timeout=8","--batch","-N",$db,"-e","SELECT 1") }
|
|
$out = & $mysql @args 2>&1
|
|
$text = ($out | ForEach-Object {"$_"}) -join "`n"
|
|
if ($text -match "ERROR") { return $false }
|
|
$lines = $out | ForEach-Object {"$_".Trim()} | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" }
|
|
return ($lines -contains "1")
|
|
}
|
|
|
|
function Mysql-MemOk() {
|
|
$out = & $mysql --protocol=MEMORY -u root --batch -N -e "SELECT 1" 2>&1
|
|
$text = ($out | ForEach-Object {"$_"}) -join "`n"
|
|
if ($text -match "ERROR") { return $false }
|
|
$lines = $out | ForEach-Object {"$_".Trim()} | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" }
|
|
return ($lines -contains "1")
|
|
}
|
|
|
|
Write-Output ("intranet=" + $intranet)
|
|
|
|
# Ensure service up first
|
|
if ((Get-Service YTD-MySQL).Status -ne "Running") {
|
|
Get-Process mysqld -EA SilentlyContinue | Stop-Process -Force -EA SilentlyContinue
|
|
Start-Sleep 2
|
|
Start-Service YTD-MySQL
|
|
Start-Sleep 5
|
|
}
|
|
Write-Output ("svc=" + (Get-Service YTD-MySQL).Status)
|
|
|
|
# Persist root secret first
|
|
$rootPass = New-Secret 48
|
|
@{ root_password = $rootPass; createdAt = (Get-Date).ToString("o") } | ConvertTo-Json |
|
|
Set-Content "$ops\local_mysql_root_secret.json" -Encoding UTF8
|
|
Set-Content "$ops\.mysql_root_stash.tmp" -Value $rootPass -Encoding ascii -NoNewline
|
|
Write-Output ("root_saved len=" + $rootPass.Length)
|
|
|
|
$est = @(Get-NetTCPConnection -LocalPort 3306 -State Established -EA SilentlyContinue)
|
|
Write-Output ("established=" + $est.Count)
|
|
if ($est.Count -gt 0) { Write-Output "REFUSE_ACTIVE_CLIENTS"; exit 4 }
|
|
|
|
Write-Output "=== stop service ==="
|
|
Stop-Service YTD-MySQL -Force
|
|
Start-Sleep 3
|
|
Get-Process mysqld -EA SilentlyContinue | Stop-Process -Force -EA SilentlyContinue
|
|
Start-Sleep 2
|
|
|
|
Write-Output "=== start maint ==="
|
|
$errLog = "$ops\mysql-skip-grant.err"
|
|
Remove-Item $errLog -Force -EA SilentlyContinue
|
|
# enable shared-memory explicitly
|
|
$p = Start-Process -FilePath $mysqld -ArgumentList @(
|
|
"--defaults-file=$ini",
|
|
"--datadir=$datadir",
|
|
"--skip-grant-tables",
|
|
"--skip-networking",
|
|
"--shared-memory",
|
|
"--shared-memory-base-name=MYSQL",
|
|
"--log-error=$errLog"
|
|
) -PassThru -WindowStyle Hidden
|
|
Write-Output ("maint_pid=" + $p.Id)
|
|
|
|
$ready = $false
|
|
for ($i=0; $i -lt 45; $i++) {
|
|
Start-Sleep 1
|
|
if ($p.HasExited) {
|
|
Write-Output "maint_exited"
|
|
Get-Content $errLog -Tail 30 -EA SilentlyContinue
|
|
break
|
|
}
|
|
if (Mysql-MemOk) { $ready = $true; break }
|
|
}
|
|
if (-not $ready) {
|
|
# try named pipe
|
|
$out = & $mysql --protocol=PIPE -u root --batch -N -e "SELECT 1" 2>&1
|
|
Write-Output ("pipe_try=" + (($out | ForEach-Object {"$_"}) -join " "))
|
|
if ((($out | Out-String) -match "(?m)^\s*1\s*$") -and (($out | Out-String) -notmatch "ERROR")) { $ready = $true; $script:maintProto = "PIPE" }
|
|
}
|
|
if (-not $ready) {
|
|
Get-Content $errLog -Tail 40 -EA SilentlyContinue
|
|
Stop-Process -Id $p.Id -Force -EA SilentlyContinue
|
|
Start-Service YTD-MySQL
|
|
Write-Output "MAINT_FAIL_RESTARTED_SVC"
|
|
exit 5
|
|
}
|
|
Write-Output "MAINT_READY"
|
|
|
|
$protoArgs = @("--protocol=MEMORY")
|
|
if ($script:maintProto -eq "PIPE") { $protoArgs = @("--protocol=PIPE") }
|
|
|
|
$sqlPathWin = "$ops\sql\_run_ir_mysql.sql"
|
|
$sql = @"
|
|
FLUSH PRIVILEGES;
|
|
ALTER USER 'root'@'localhost' IDENTIFIED BY '$rootPass';
|
|
CREATE USER IF NOT EXISTS 'root'@'127.0.0.1' IDENTIFIED BY '$rootPass';
|
|
ALTER USER 'root'@'127.0.0.1' IDENTIFIED BY '$rootPass';
|
|
GRANT ALL PRIVILEGES ON *.* TO 'root'@'localhost' WITH GRANT OPTION;
|
|
GRANT ALL PRIVILEGES ON *.* TO 'root'@'127.0.0.1' WITH GRANT OPTION;
|
|
CREATE DATABASE IF NOT EXISTS ``inquiry_robot`` DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
|
|
CREATE USER IF NOT EXISTS 'inquiry_robot'@'%' IDENTIFIED BY '$mysqlPass';
|
|
CREATE USER IF NOT EXISTS 'inquiry_robot'@'localhost' IDENTIFIED BY '$mysqlPass';
|
|
CREATE USER IF NOT EXISTS 'inquiry_robot'@'127.0.0.1' IDENTIFIED BY '$mysqlPass';
|
|
CREATE USER IF NOT EXISTS 'inquiry_robot'@'$intranet' IDENTIFIED BY '$mysqlPass';
|
|
ALTER USER 'inquiry_robot'@'%' IDENTIFIED BY '$mysqlPass';
|
|
ALTER USER 'inquiry_robot'@'localhost' IDENTIFIED BY '$mysqlPass';
|
|
ALTER USER 'inquiry_robot'@'127.0.0.1' IDENTIFIED BY '$mysqlPass';
|
|
ALTER USER 'inquiry_robot'@'$intranet' IDENTIFIED BY '$mysqlPass';
|
|
GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'%';
|
|
GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'localhost';
|
|
GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'127.0.0.1';
|
|
GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'$intranet';
|
|
FLUSH PRIVILEGES;
|
|
SELECT 'maint_ok' AS s;
|
|
"@
|
|
Set-Content $sqlPathWin -Value $sql -Encoding ascii
|
|
$sqlPath = $sqlPathWin -replace '\\','/'
|
|
$mout = & $mysql @protoArgs -u root -e "source $sqlPath" 2>&1 | Out-String
|
|
($mout -split "`r?`n" | Where-Object { $_ -notmatch "password|IDENTIFIED" }) | ForEach-Object { $_ }
|
|
if ($mout -notmatch "maint_ok") {
|
|
Stop-Process -Id $p.Id -Force -EA SilentlyContinue
|
|
Start-Sleep 2
|
|
Start-Service YTD-MySQL
|
|
Write-Output "SQL_FAIL"
|
|
exit 6
|
|
}
|
|
Write-Output "SQL_OK"
|
|
|
|
Stop-Process -Id $p.Id -Force -EA SilentlyContinue
|
|
Start-Sleep 3
|
|
Get-Process mysqld -EA SilentlyContinue | Stop-Process -Force -EA SilentlyContinue
|
|
Start-Sleep 2
|
|
Start-Service YTD-MySQL
|
|
$ok = $false
|
|
for ($i=0; $i -lt 40; $i++) {
|
|
Start-Sleep 1
|
|
if ((Get-Service YTD-MySQL).Status -ne "Running") { continue }
|
|
if (Mysql-TcpOk "127.0.0.1" "inquiry_robot" $mysqlPass "inquiry_robot") { $ok = $true; break }
|
|
}
|
|
Write-Output ("mysql_app_127=" + $ok)
|
|
Write-Output ("mysql_root_127=" + (Mysql-TcpOk "127.0.0.1" "root" $rootPass $null))
|
|
Write-Output ("mysql_app_intranet=" + (Mysql-TcpOk $intranet "inquiry_robot" $mysqlPass "inquiry_robot"))
|
|
Remove-Item $sqlPathWin -Force -EA SilentlyContinue
|
|
Remove-Item "$ops\sql\_maint_create_inquiry_robot.sql" -Force -EA SilentlyContinue
|
|
if (-not $ok) { Write-Output "MYSQL_SMOKE_FAIL"; exit 7 }
|
|
Write-Output "MYSQL_DONE"
|
|
|
|
# PG section
|
|
$ErrorActionPreference = "Continue"
|
|
$env:PGPASSWORD = (Get-Content "C:\yutongda\secure\pgpass.txt" -Raw).Trim()
|
|
$dd = (& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -tAc "SHOW data_directory;").Trim()
|
|
Write-Output ("pg_data=" + $dd)
|
|
$pgConf = Join-Path $dd "postgresql.conf"
|
|
$pgHba = Join-Path $dd "pg_hba.conf"
|
|
$conf = [System.IO.File]::ReadAllText($pgConf)
|
|
if ($conf -notmatch "(?m)^\s*listen_addresses\s*=\s*'\*'") {
|
|
if ($conf -match "(?m)^\s*#?\s*listen_addresses\s*=") {
|
|
$conf = [regex]::Replace($conf, "(?m)^\s*#?\s*listen_addresses\s*=\s*.*$", "listen_addresses = '*'", 1)
|
|
} else { $conf += "`r`nlisten_addresses = '*'`r`n" }
|
|
[System.IO.File]::WriteAllText($pgConf, $conf)
|
|
Write-Output "pg_listen_patched"
|
|
}
|
|
if (-not ((Get-Content $pgHba) -match "inquiry_robot_runtime")) {
|
|
Add-Content $pgHba "host inquiry_robot_runtime inquiry_robot_runtime 10.206.0.0/16 scram-sha-256"
|
|
Write-Output "pg_hba_patched"
|
|
}
|
|
$pgSqlPath = "$ops\sql\_run_ir_pg.sql"
|
|
@"
|
|
DO `$`$BEGIN
|
|
IF NOT EXISTS (SELECT FROM pg_roles WHERE rolname = 'inquiry_robot_runtime') THEN
|
|
CREATE ROLE inquiry_robot_runtime LOGIN PASSWORD '$pgPass';
|
|
ELSE
|
|
ALTER ROLE inquiry_robot_runtime WITH LOGIN PASSWORD '$pgPass';
|
|
END IF;
|
|
END`$`$;
|
|
"@ | Set-Content $pgSqlPath -Encoding ascii
|
|
& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -f $pgSqlPath 2>&1 | Out-Null
|
|
$has = & $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -tAc "SELECT 1 FROM pg_database WHERE datname='inquiry_robot_runtime'"
|
|
if (($has | Out-String) -notmatch "1") {
|
|
& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -c "CREATE DATABASE inquiry_robot_runtime OWNER inquiry_robot_runtime;" 2>&1 | Out-Null
|
|
}
|
|
& $psql -h 127.0.0.1 -p 5432 -U postgres -d inquiry_robot_runtime -c "GRANT ALL ON SCHEMA public TO inquiry_robot_runtime;" 2>&1 | Out-Null
|
|
Remove-Item $pgSqlPath -Force -EA SilentlyContinue
|
|
|
|
$listen = (& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -tAc "SHOW listen_addresses;").Trim()
|
|
Write-Output ("listen=" + $listen)
|
|
if ($listen -ne "*") {
|
|
Get-Service | Where-Object { $_.Name -match 'postgres|pgsql|YTD-PG' } | ForEach-Object {
|
|
Write-Output ("restart " + $_.Name)
|
|
Restart-Service $_.Name -Force -EA SilentlyContinue
|
|
}
|
|
Start-Sleep 6
|
|
}
|
|
& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -c "SELECT pg_reload_conf();" 2>&1 | Out-Null
|
|
$env:PGPASSWORD = $pgPass
|
|
$pg127 = (& $psql -h 127.0.0.1 -p 5432 -U inquiry_robot_runtime -d inquiry_robot_runtime -tAc "SELECT 'pg_ok'" 2>&1 | Out-String).Trim()
|
|
$pgNet = (& $psql -h $intranet -p 5432 -U inquiry_robot_runtime -d inquiry_robot_runtime -tAc "SELECT 'pg_ok'" 2>&1 | Out-String).Trim()
|
|
Write-Output ("pg127=" + $pg127)
|
|
Write-Output ("pgNet=" + $pgNet)
|
|
Remove-Item Env:PGPASSWORD -EA SilentlyContinue
|
|
|
|
# .env
|
|
$envPath = "E:\wwwroot\.env"
|
|
$jdbc = "jdbc:mysql://${intranet}:3306/inquiry_robot?characterEncoding=UTF-8&useUnicode=true&useSSL=false&allowPublicKeyRetrieval=true&tinyInt1isBit=false&serverTimezone=Asia/Shanghai"
|
|
$out = foreach ($line in (Get-Content $envPath)) {
|
|
if ($line -match '^MYSQL_HOST=') { "MYSQL_HOST=$intranet" }
|
|
elseif ($line -match '^PG_HOST=') { "PG_HOST=$intranet" }
|
|
elseif ($line -match '^YTD_MYSQL_URL=') { "YTD_MYSQL_URL=$jdbc" }
|
|
elseif ($line -match '^MYSQL_PASSWORD=') { "MYSQL_PASSWORD=$mysqlPass" }
|
|
elseif ($line -match '^PG_PASSWORD=') { "PG_PASSWORD=$pgPass" }
|
|
else { $line }
|
|
}
|
|
Set-Content $envPath -Value $out -Encoding UTF8
|
|
Copy-Item $envPath "E:\wwwroot\agent\current\.env" -Force -EA SilentlyContinue
|
|
|
|
@{
|
|
mysqlHost = $intranet
|
|
pgHost = $intranet
|
|
mysqlDb = "inquiry_robot"
|
|
pgDb = "inquiry_robot_runtime"
|
|
mysqlCreated = $true
|
|
pgCreated = ($pg127 -match "pg_ok")
|
|
mysqlIntranet = [bool](Mysql-TcpOk $intranet "inquiry_robot" $mysqlPass "inquiry_robot")
|
|
pgIntranet = ($pgNet -match "pg_ok")
|
|
note = "Interim empty DBs on app-server, connect via intranet 10.206.0.15. Data host 10.206.0.14 still needs DBA for final placement."
|
|
updatedAt = (Get-Date).ToString("o")
|
|
} | ConvertTo-Json | Set-Content "$ops\data-plane-status.json" -Encoding UTF8
|
|
|
|
Write-Output "ALL_DONE"
|