Files
inquiry_robot/deploy/_remote_mysql_pg_intranet_final.ps1
T

249 lines
11 KiB
PowerShell

# Local MySQL skip-grant create inquiry_robot; connect maint via shared-memory protocol.
# Then PG + .env -> 10.206.0.15 intranet.
$ErrorActionPreference = "Continue"
$mysqlBin = "C:\yutongda\tools\mysql-8.0.39-winx64\bin"
$mysql = Join-Path $mysqlBin "mysql.exe"
$mysqld = Join-Path $mysqlBin "mysqld.exe"
$ini = "C:\yutongda\tools\mysql-8.0.39-winx64\my.ini"
$datadir = "C:\yutongda\data\mysql"
$ops = "E:\wwwroot\ops"
$psql = "C:\yutongda\tools\pgsql\bin\psql.exe"
$sec = Get-Content "$ops\inquiry_robot_db_secrets.json" -Raw | ConvertFrom-Json
$mysqlPass = [string]$sec.mysql_password
$pgPass = [string]$sec.pg_password
$intranet = (Get-NetIPAddress -AddressFamily IPv4 | Where-Object { $_.IPAddress -like '10.*' } | Select-Object -First 1 -ExpandProperty IPAddress)
function New-Secret([int]$len = 48) {
$bytes = New-Object byte[] $len
[System.Security.Cryptography.RandomNumberGenerator]::Create().GetBytes($bytes)
return ([Convert]::ToBase64String($bytes) -replace '[+/=]', 'x').Substring(0, [Math]::Min(64, $len))
}
function Mysql-TcpOk([string]$h, [string]$u, [string]$p, [string]$db) {
$args = @("-h$h","-P3306","-u$u","-p$p","--connect-timeout=8","--batch","-N","-e","SELECT 1")
if ($db) { $args = @("-h$h","-P3306","-u$u","-p$p","--connect-timeout=8","--batch","-N",$db,"-e","SELECT 1") }
$out = & $mysql @args 2>&1
$text = ($out | ForEach-Object {"$_"}) -join "`n"
if ($text -match "ERROR") { return $false }
$lines = $out | ForEach-Object {"$_".Trim()} | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" }
return ($lines -contains "1")
}
function Mysql-MemOk() {
$out = & $mysql --protocol=MEMORY -u root --batch -N -e "SELECT 1" 2>&1
$text = ($out | ForEach-Object {"$_"}) -join "`n"
if ($text -match "ERROR") { return $false }
$lines = $out | ForEach-Object {"$_".Trim()} | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" }
return ($lines -contains "1")
}
Write-Output ("intranet=" + $intranet)
# Ensure service up first
if ((Get-Service YTD-MySQL).Status -ne "Running") {
Get-Process mysqld -EA SilentlyContinue | Stop-Process -Force -EA SilentlyContinue
Start-Sleep 2
Start-Service YTD-MySQL
Start-Sleep 5
}
Write-Output ("svc=" + (Get-Service YTD-MySQL).Status)
# Persist root secret first
$rootPass = New-Secret 48
@{ root_password = $rootPass; createdAt = (Get-Date).ToString("o") } | ConvertTo-Json |
Set-Content "$ops\local_mysql_root_secret.json" -Encoding UTF8
Set-Content "$ops\.mysql_root_stash.tmp" -Value $rootPass -Encoding ascii -NoNewline
Write-Output ("root_saved len=" + $rootPass.Length)
$est = @(Get-NetTCPConnection -LocalPort 3306 -State Established -EA SilentlyContinue)
Write-Output ("established=" + $est.Count)
if ($est.Count -gt 0) { Write-Output "REFUSE_ACTIVE_CLIENTS"; exit 4 }
Write-Output "=== stop service ==="
Stop-Service YTD-MySQL -Force
Start-Sleep 3
Get-Process mysqld -EA SilentlyContinue | Stop-Process -Force -EA SilentlyContinue
Start-Sleep 2
Write-Output "=== start maint ==="
$errLog = "$ops\mysql-skip-grant.err"
Remove-Item $errLog -Force -EA SilentlyContinue
# enable shared-memory explicitly
$p = Start-Process -FilePath $mysqld -ArgumentList @(
"--defaults-file=$ini",
"--datadir=$datadir",
"--skip-grant-tables",
"--skip-networking",
"--shared-memory",
"--shared-memory-base-name=MYSQL",
"--log-error=$errLog"
) -PassThru -WindowStyle Hidden
Write-Output ("maint_pid=" + $p.Id)
$ready = $false
for ($i=0; $i -lt 45; $i++) {
Start-Sleep 1
if ($p.HasExited) {
Write-Output "maint_exited"
Get-Content $errLog -Tail 30 -EA SilentlyContinue
break
}
if (Mysql-MemOk) { $ready = $true; break }
}
if (-not $ready) {
# try named pipe
$out = & $mysql --protocol=PIPE -u root --batch -N -e "SELECT 1" 2>&1
Write-Output ("pipe_try=" + (($out | ForEach-Object {"$_"}) -join " "))
if ((($out | Out-String) -match "(?m)^\s*1\s*$") -and (($out | Out-String) -notmatch "ERROR")) { $ready = $true; $script:maintProto = "PIPE" }
}
if (-not $ready) {
Get-Content $errLog -Tail 40 -EA SilentlyContinue
Stop-Process -Id $p.Id -Force -EA SilentlyContinue
Start-Service YTD-MySQL
Write-Output "MAINT_FAIL_RESTARTED_SVC"
exit 5
}
Write-Output "MAINT_READY"
$protoArgs = @("--protocol=MEMORY")
if ($script:maintProto -eq "PIPE") { $protoArgs = @("--protocol=PIPE") }
$sqlPathWin = "$ops\sql\_run_ir_mysql.sql"
$sql = @"
FLUSH PRIVILEGES;
ALTER USER 'root'@'localhost' IDENTIFIED BY '$rootPass';
CREATE USER IF NOT EXISTS 'root'@'127.0.0.1' IDENTIFIED BY '$rootPass';
ALTER USER 'root'@'127.0.0.1' IDENTIFIED BY '$rootPass';
GRANT ALL PRIVILEGES ON *.* TO 'root'@'localhost' WITH GRANT OPTION;
GRANT ALL PRIVILEGES ON *.* TO 'root'@'127.0.0.1' WITH GRANT OPTION;
CREATE DATABASE IF NOT EXISTS ``inquiry_robot`` DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER IF NOT EXISTS 'inquiry_robot'@'%' IDENTIFIED BY '$mysqlPass';
CREATE USER IF NOT EXISTS 'inquiry_robot'@'localhost' IDENTIFIED BY '$mysqlPass';
CREATE USER IF NOT EXISTS 'inquiry_robot'@'127.0.0.1' IDENTIFIED BY '$mysqlPass';
CREATE USER IF NOT EXISTS 'inquiry_robot'@'$intranet' IDENTIFIED BY '$mysqlPass';
ALTER USER 'inquiry_robot'@'%' IDENTIFIED BY '$mysqlPass';
ALTER USER 'inquiry_robot'@'localhost' IDENTIFIED BY '$mysqlPass';
ALTER USER 'inquiry_robot'@'127.0.0.1' IDENTIFIED BY '$mysqlPass';
ALTER USER 'inquiry_robot'@'$intranet' IDENTIFIED BY '$mysqlPass';
GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'%';
GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'localhost';
GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'127.0.0.1';
GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'$intranet';
FLUSH PRIVILEGES;
SELECT 'maint_ok' AS s;
"@
Set-Content $sqlPathWin -Value $sql -Encoding ascii
$sqlPath = $sqlPathWin -replace '\\','/'
$mout = & $mysql @protoArgs -u root -e "source $sqlPath" 2>&1 | Out-String
($mout -split "`r?`n" | Where-Object { $_ -notmatch "password|IDENTIFIED" }) | ForEach-Object { $_ }
if ($mout -notmatch "maint_ok") {
Stop-Process -Id $p.Id -Force -EA SilentlyContinue
Start-Sleep 2
Start-Service YTD-MySQL
Write-Output "SQL_FAIL"
exit 6
}
Write-Output "SQL_OK"
Stop-Process -Id $p.Id -Force -EA SilentlyContinue
Start-Sleep 3
Get-Process mysqld -EA SilentlyContinue | Stop-Process -Force -EA SilentlyContinue
Start-Sleep 2
Start-Service YTD-MySQL
$ok = $false
for ($i=0; $i -lt 40; $i++) {
Start-Sleep 1
if ((Get-Service YTD-MySQL).Status -ne "Running") { continue }
if (Mysql-TcpOk "127.0.0.1" "inquiry_robot" $mysqlPass "inquiry_robot") { $ok = $true; break }
}
Write-Output ("mysql_app_127=" + $ok)
Write-Output ("mysql_root_127=" + (Mysql-TcpOk "127.0.0.1" "root" $rootPass $null))
Write-Output ("mysql_app_intranet=" + (Mysql-TcpOk $intranet "inquiry_robot" $mysqlPass "inquiry_robot"))
Remove-Item $sqlPathWin -Force -EA SilentlyContinue
Remove-Item "$ops\sql\_maint_create_inquiry_robot.sql" -Force -EA SilentlyContinue
if (-not $ok) { Write-Output "MYSQL_SMOKE_FAIL"; exit 7 }
Write-Output "MYSQL_DONE"
# PG section
$ErrorActionPreference = "Continue"
$env:PGPASSWORD = (Get-Content "C:\yutongda\secure\pgpass.txt" -Raw).Trim()
$dd = (& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -tAc "SHOW data_directory;").Trim()
Write-Output ("pg_data=" + $dd)
$pgConf = Join-Path $dd "postgresql.conf"
$pgHba = Join-Path $dd "pg_hba.conf"
$conf = [System.IO.File]::ReadAllText($pgConf)
if ($conf -notmatch "(?m)^\s*listen_addresses\s*=\s*'\*'") {
if ($conf -match "(?m)^\s*#?\s*listen_addresses\s*=") {
$conf = [regex]::Replace($conf, "(?m)^\s*#?\s*listen_addresses\s*=\s*.*$", "listen_addresses = '*'", 1)
} else { $conf += "`r`nlisten_addresses = '*'`r`n" }
[System.IO.File]::WriteAllText($pgConf, $conf)
Write-Output "pg_listen_patched"
}
if (-not ((Get-Content $pgHba) -match "inquiry_robot_runtime")) {
Add-Content $pgHba "host inquiry_robot_runtime inquiry_robot_runtime 10.206.0.0/16 scram-sha-256"
Write-Output "pg_hba_patched"
}
$pgSqlPath = "$ops\sql\_run_ir_pg.sql"
@"
DO `$`$BEGIN
IF NOT EXISTS (SELECT FROM pg_roles WHERE rolname = 'inquiry_robot_runtime') THEN
CREATE ROLE inquiry_robot_runtime LOGIN PASSWORD '$pgPass';
ELSE
ALTER ROLE inquiry_robot_runtime WITH LOGIN PASSWORD '$pgPass';
END IF;
END`$`$;
"@ | Set-Content $pgSqlPath -Encoding ascii
& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -f $pgSqlPath 2>&1 | Out-Null
$has = & $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -tAc "SELECT 1 FROM pg_database WHERE datname='inquiry_robot_runtime'"
if (($has | Out-String) -notmatch "1") {
& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -c "CREATE DATABASE inquiry_robot_runtime OWNER inquiry_robot_runtime;" 2>&1 | Out-Null
}
& $psql -h 127.0.0.1 -p 5432 -U postgres -d inquiry_robot_runtime -c "GRANT ALL ON SCHEMA public TO inquiry_robot_runtime;" 2>&1 | Out-Null
Remove-Item $pgSqlPath -Force -EA SilentlyContinue
$listen = (& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -tAc "SHOW listen_addresses;").Trim()
Write-Output ("listen=" + $listen)
if ($listen -ne "*") {
Get-Service | Where-Object { $_.Name -match 'postgres|pgsql|YTD-PG' } | ForEach-Object {
Write-Output ("restart " + $_.Name)
Restart-Service $_.Name -Force -EA SilentlyContinue
}
Start-Sleep 6
}
& $psql -h 127.0.0.1 -p 5432 -U postgres -d postgres -c "SELECT pg_reload_conf();" 2>&1 | Out-Null
$env:PGPASSWORD = $pgPass
$pg127 = (& $psql -h 127.0.0.1 -p 5432 -U inquiry_robot_runtime -d inquiry_robot_runtime -tAc "SELECT 'pg_ok'" 2>&1 | Out-String).Trim()
$pgNet = (& $psql -h $intranet -p 5432 -U inquiry_robot_runtime -d inquiry_robot_runtime -tAc "SELECT 'pg_ok'" 2>&1 | Out-String).Trim()
Write-Output ("pg127=" + $pg127)
Write-Output ("pgNet=" + $pgNet)
Remove-Item Env:PGPASSWORD -EA SilentlyContinue
# .env
$envPath = "E:\wwwroot\.env"
$jdbc = "jdbc:mysql://${intranet}:3306/inquiry_robot?characterEncoding=UTF-8&useUnicode=true&useSSL=false&allowPublicKeyRetrieval=true&tinyInt1isBit=false&serverTimezone=Asia/Shanghai"
$out = foreach ($line in (Get-Content $envPath)) {
if ($line -match '^MYSQL_HOST=') { "MYSQL_HOST=$intranet" }
elseif ($line -match '^PG_HOST=') { "PG_HOST=$intranet" }
elseif ($line -match '^YTD_MYSQL_URL=') { "YTD_MYSQL_URL=$jdbc" }
elseif ($line -match '^MYSQL_PASSWORD=') { "MYSQL_PASSWORD=$mysqlPass" }
elseif ($line -match '^PG_PASSWORD=') { "PG_PASSWORD=$pgPass" }
else { $line }
}
Set-Content $envPath -Value $out -Encoding UTF8
Copy-Item $envPath "E:\wwwroot\agent\current\.env" -Force -EA SilentlyContinue
@{
mysqlHost = $intranet
pgHost = $intranet
mysqlDb = "inquiry_robot"
pgDb = "inquiry_robot_runtime"
mysqlCreated = $true
pgCreated = ($pg127 -match "pg_ok")
mysqlIntranet = [bool](Mysql-TcpOk $intranet "inquiry_robot" $mysqlPass "inquiry_robot")
pgIntranet = ($pgNet -match "pg_ok")
note = "Interim empty DBs on app-server, connect via intranet 10.206.0.15. Data host 10.206.0.14 still needs DBA for final placement."
updatedAt = (Get-Date).ToString("o")
} | ConvertTo-Json | Set-Content "$ops\data-plane-status.json" -Encoding UTF8
Write-Output "ALL_DONE"