<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Archives des Installation - dbi Blog</title>
	<atom:link href="https://www.dbi-services.com/blog/tag/installation/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dbi-services.com/blog/tag/installation/</link>
	<description></description>
	<lastBuildDate>Fri, 11 Sep 2026 11:58:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/05/cropped-favicon_512x512px-min-32x32.png</url>
	<title>Archives des Installation - dbi Blog</title>
	<link>https://www.dbi-services.com/blog/tag/installation/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Loosing java remote console full control during ODA Reimage</title>
		<link>https://www.dbi-services.com/blog/loosing-java-remote-console-full-control-during-oda-reimage/</link>
					<comments>https://www.dbi-services.com/blog/loosing-java-remote-console-full-control-during-oda-reimage/#respond</comments>
		
		<dc:creator><![CDATA[Marc Wagner]]></dc:creator>
		<pubDate>Wed, 22 Apr 2026 08:18:39 +0000</pubDate>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[oda]]></category>
		<category><![CDATA[reimage]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=43970</guid>

					<description><![CDATA[<p>Recently I had to patch an ODA at one of our customer from 19.20 to 19.26, going through 19.24. As you are aware of, knowing we go from Oracle Linux 7 (19.20) to Oracle Linux 8 (19.24), we need to patch the ODA using Data Preserving Reprovisioning. This includes a reimage of the nodes&#8230; Data [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/loosing-java-remote-console-full-control-during-oda-reimage/">Loosing java remote console full control during ODA Reimage</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Recently I had to patch an ODA at one of our customer from 19.20 to 19.26, going through 19.24. As you are aware of, knowing we go from Oracle Linux 7 (19.20) to Oracle Linux 8 (19.24), we need to patch the ODA using Data Preserving Reprovisioning. This includes a reimage of the nodes&#8230;</p>



<p class="wp-block-paragraph">Data Preserving Reprovisioning will allow you reprovisioning an already deployed Oracle Database Appliance system keeping the storage and the databases on the appliance, so without any modifications on the information stored in the ASM (storage).  The information of the source system will be saved in a server data archive files. The appliance will then be reimaged with Oracle Database Appliance release iso image and the saved metadata will be used to directly reprovision the system and bring back all the resources such as databases, DB systems, Oracle ASR, and others.</p>



<span id="more-43970"></span>



<p class="wp-block-paragraph">The reimage can only be done using the java remote console, available with the ILOM. Remember that to attach the iso on the java console and use it during the reimage, you need to add it and connect it as described in the next picture.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="549" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connect_reimage-1024x549.png" alt="" class="wp-image-44046" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connect_reimage-1024x549.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connect_reimage-300x161.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connect_reimage-768x412.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connect_reimage.png 1249w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">It is important to see the following red message to ensure that the connection with the iso is made and that it can be used.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="559" height="53" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connect_reimage_2.png" alt="" class="wp-image-44047" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connect_reimage_2.png 559w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connect_reimage_2-300x28.png 300w" sizes="(max-width: 559px) 100vw, 559px" /></figure>



<p class="wp-block-paragraph">The problem is that after a time, during the reimage process, the java remote console lost full control on the node, having as consequence a lost of the iso connection and a failure in the reimage process.</p>



<p class="wp-block-paragraph">This could be seen in the console with the message (View Only) displayed in the bar and the Red Cross on the top of the Computer (screen)/mouse image.</p>



<p class="wp-block-paragraph">Here:</p>



<figure class="wp-block-image size-full"><img decoding="async" width="40" height="34" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console_0.png" alt="" class="wp-image-44050" /></figure>



<p class="wp-block-paragraph">When it should be:</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="35" height="35" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connection_good_0.png" alt="" class="wp-image-44051" /></figure>



<p class="wp-block-paragraph">Here the whole picture showing the connection problem.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="122" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console_1-1024x122.png" alt="" class="wp-image-44053" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console_1-1024x122.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console_1-300x36.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console_1-768x92.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console_1.png 1030w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">And we can see the message : &#8220;Sorry, keyboard and mouse connection has been lost. \nIf storage was being shared it has been lost also&#8221;.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="587" height="92" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console-2.png" alt="" class="wp-image-44054" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console-2.png 587w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/Prob_console-2-300x47.png 300w" sizes="auto, (max-width: 587px) 100vw, 587px" /></figure>



<p class="wp-block-paragraph">When a correct connection would be the following one, having (Full Control) message displayed in the bar, with no lost of keyboard/mouse and storage (iso) connection.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="659" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connection_good-1024x659.png" alt="" class="wp-image-44055" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connection_good-1024x659.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connection_good-300x193.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connection_good-768x495.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/04/connection_good.png 1028w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">After several tries it was always the same problem. After a few minutes, lost of the connection&#8230;</p>



<p class="wp-block-paragraph">I then decided to check the ILOM sessions, connecting to the ILOM through ssh connection.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: [16,20,21]">
login as: root
Keyboard-interactive authentication prompts from server:
| Password:
End of keyboard-interactive prompts from server

Oracle(R) Integrated Lights Out Manager

Version 5.1.1.23 r151958

Copyright (c) 2023, Oracle and/or its affiliates. All rights reserved.

Warning: HTTPS certificate is set to factory default.

Hostname: ODA01-ilo

-&gt; show /SP/sessions

 /SP/sessions
    Targets:
        55342
        55346 (current)

    Properties:

    Commands:
        cd
        delete
        show
</pre>
</br>



<p class="wp-block-paragraph">I found surprising to see so high sessions id. I decided to reset the ILOM. This would of course not restart the node.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: [1,2]">
-&gt; reset /SP
Are you sure you want to reset /SP (y/n)? y
Performing reset on /SP
</pre>
</br>



<p class="wp-block-paragraph">And connected again to the ILOM through ssh to checked the sessions:</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: [1,16,20]">
login as: root
Keyboard-interactive authentication prompts from server:
| Password:
End of keyboard-interactive prompts from server

Oracle(R) Integrated Lights Out Manager

Version 5.1.1.23 r151958

Copyright (c) 2023, Oracle and/or its affiliates. All rights reserved.

Warning: HTTPS certificate is set to factory default.

Hostname: ODA01-ilo

-&gt; show /SP/sessions

 /SP/sessions
    Targets:
        1 (current)

    Properties:

    Commands:
        cd
        delete
        show
</pre>
</br>



<p class="wp-block-paragraph">The sessions id were back to one, and I did not have any lost connection issue any more. I could successfully reimage the ODA to 19.24 version.</p>



<p class="wp-block-paragraph"></p>
<p>L’article <a href="https://www.dbi-services.com/blog/loosing-java-remote-console-full-control-during-oda-reimage/">Loosing java remote console full control during ODA Reimage</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/loosing-java-remote-console-full-control-during-oda-reimage/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Comparing Data When Migrating Databases With GoldenGate Veridata: Installation Guide</title>
		<link>https://www.dbi-services.com/blog/comparing-data-when-migrating-databases-with-goldengate-veridata-installation-guide/</link>
					<comments>https://www.dbi-services.com/blog/comparing-data-when-migrating-databases-with-goldengate-veridata-installation-guide/#respond</comments>
		
		<dc:creator><![CDATA[Julien Delattre]]></dc:creator>
		<pubDate>Mon, 26 Jan 2026 07:44:00 +0000</pubDate>
				<category><![CDATA[GoldenGate]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[23ai]]></category>
		<category><![CDATA[23c]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[MY-013276]]></category>
		<category><![CDATA[Veridata]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=42109</guid>

					<description><![CDATA[<p>More often than not, migrating a database is not much about moving the data but about ensuring that nothing was lost in the process. In all migration projects, a DBA will have to answer the following question: &#8220;Is my target database really identical to the source ?&#8220; This is what Oracle GoldenGate Veridata was made [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/comparing-data-when-migrating-databases-with-goldengate-veridata-installation-guide/">Comparing Data When Migrating Databases With GoldenGate Veridata: Installation Guide</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">More often than not, migrating a database is not much about moving the data but about ensuring that nothing was lost in the process. In all migration projects, a DBA will have to answer the following question: &#8220;<em><strong>Is my target database really identical to the source ?</strong></em>&#8220;</p>



<p class="wp-block-paragraph">This is what <strong>Oracle GoldenGate Veridata</strong> was made for, and before diving into more specific use cases of Veridata in upcoming blog posts, we will see how to install and set up GoldenGate Veridata 23c (not called 23ai, for some reason&#8230;), while answering the most common questions.</p>



<div class="wp-block-yoast-seo-table-of-contents yoast-table-of-contents"><h2>Table of contents</h2><ul><li><a href="#h-can-goldengate-veridata-be-installed-on-the-same-host-as-a-goldengate-hub" data-level="2">Can GoldenGate Veridata be installed on the same host as a GoldenGate hub ?</a></li><li><a href="#h-prerequisites-for-goldengate-veridata-installation" data-level="2">Prerequisites for GoldenGate Veridata installation</a></li><li><a href="#h-installing-goldengate-veridata-with-the-oui-graphic-installation" data-level="2">Installing GoldenGate Veridata with the OUI (graphic installation)</a></li><li><a href="#h-installing-goldengate-veridata-with-the-cli-silent-installation" data-level="2">Installing GoldenGate Veridata with the CLI (silent installation)</a></li><li><a href="#h-accessing-goldengate-veridata-web-ui" data-level="2">Accessing GoldenGate Veridata Web UI</a></li><li><a href="#h-veridata-agent-installation-and-configuration" data-level="2">Veridata Agent Installation and Configuration</a></li><li><a href="#h-appendix" data-level="2">Appendix</a></li></ul></div>



<h2 id="h-can-goldengate-veridata-be-installed-on-the-same-host-as-a-goldengate-hub" class="wp-block-heading">Can GoldenGate Veridata be installed on the same host as a GoldenGate hub ?</h2>



<p class="wp-block-paragraph">This sounds like a very good idea at first sight. You have a GoldenGate hub setup for all your GoldenGate replications, with access to all databases being at both ends of your GoldenGate replications. </p>



<p class="wp-block-paragraph">However, there is no real reason to have both GoldenGate and Veridata on the same host, since they have two very different roles. In addition to this, <strong>Oracle strongly recommends having a host dedicated to Veridata operations</strong>.</p>



<h2 id="h-prerequisites-for-goldengate-veridata-installation" class="wp-block-heading">Prerequisites for GoldenGate Veridata installation</h2>



<h4 id="h-certification-matrix" class="wp-block-heading">Certification Matrix</h4>



<p class="wp-block-paragraph">To make sure you respect the requirements for a Veridata setup, check the official Oracle <a href="https://www.oracle.com/a/ocom/docs/ogg-veridata-23c-cert-matrix.xlsx" target="_blank" rel="noreferrer noopener">certification matrix</a>. <strong>For Veridata 23c, Oracle and Red Hat Linux 8 and 9 are supported</strong>.</p>



<h4 id="h-download-the-latest-patched-complete-installation" class="wp-block-heading">Download the latest patched complete installation</h4>



<p class="wp-block-paragraph">In recent years, Oracle provided patched installations, which saved a lot of time during setup. For Veridata, <strong>I strongly recommend using the latest patch for the installation</strong> instead of patching it later. Indeed, a <strong>new feature</strong> was added <strong>in the configuration assistant</strong>, so please download the installer from <a href="https://support.oracle.com/ic/builder/rt/customer_portal/live/webApps/customer-portal/?page=sptemplate&amp;sptemplate=cp-patches-updates-view-more&amp;cp-patches-updates-view-more=cp-patches-details" target="_blank" rel="noreferrer noopener">patch 38437002</a> (released in November 2025) before continuing.</p>



<p class="wp-block-paragraph">For the installation, we will use the standard <code>oracle</code> user and <code>oinstall</code> group. Unzip the binaries to a stage directory.</p>



<pre class="wp-block-code"><code>&#091;root@vmvdt~] mkdir -p /u01/app/oracle/product
&#091;root@vmvdt ~] mkdir -p /u01/stage
&#091;root@vmvdt ~] unzip -oq p38437002_231000_Linux-x86-64.zip -d /u01/stage
&#091;root@vmvdt ~] chown oracle:oinstall -R /u01</code></pre>



<p class="wp-block-paragraph">Contrary to usual Oracle installations, you will also need to download the <a href="https://www.oracle.com/java/technologies/downloads/" target="_blank" rel="noreferrer noopener">JDK</a>. Oracle <strong>recommends downloading JDK 17 from the archive</strong>, and I&#8217;ve never tried using a newer version, so we will stay with this one.</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~] cd /u01/app/oracle/product
&#091;oracle@vmvdt ~] tar zxvf /u01/stage/jdk-17.0.17_linux-x64_bin.tar.gz</code></pre>



<h2 id="h-installing-goldengate-veridata-with-the-oui-graphic-installation" class="wp-block-heading">Installing GoldenGate Veridata with the OUI (graphic installation)</h2>



<h4 id="h-installing-binaries" class="wp-block-heading">Installing binaries</h4>



<p class="wp-block-paragraph">With the <code>oracle</code> user, run the <code>runInstaller</code> to install Veridata binaries.</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~] /u01/stage/fbo_oggvdt_linux_services_shiphome/Disk1/runInstaller</code></pre>



<p class="wp-block-paragraph">On the first panel, you can decide whether to install only Veridata Server, only Veridata Agent or both. We&#8217;ll choose the latter option here.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="794" height="596" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_1o6_both.png" alt="" class="wp-image-42112" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_1o6_both.png 794w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_1o6_both-300x225.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_1o6_both-768x576.png 768w" sizes="auto, (max-width: 794px) 100vw, 794px" /></figure>



<p class="wp-block-paragraph">You can then pick whether to <strong>install a new MySQL database</strong> or <strong>use an existing one</strong>. As a reminder, <strong>only MySQL is supported for storing metadata</strong>, so you cannot opt for an Oracle database here. To keep things simple, let&#8217;s decide to install a new MySQL database. The installation will be done by the configuration assistant in a later process.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="792" height="597" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_2o6_new.png" alt="" class="wp-image-42115" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_2o6_new.png 792w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_2o6_new-300x226.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_2o6_new-768x579.png 768w" sizes="auto, (max-width: 792px) 100vw, 792px" /></figure>



<p class="wp-block-paragraph">After entering the software location (<code>/u01/app/oracle/product/vdt23</code> in this example), you can click on <em><strong>Next</strong></em> for all the following steps, since no action is required. If it&#8217;s your first Oracle installation on the server, you must give the inventory directory location. You can keep the default <code>/u01/oraInventory</code> if you follow OFA.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="795" height="597" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_3o6-1.png" alt="" class="wp-image-42117" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_3o6-1.png 795w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_3o6-1-300x225.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_3o6-1-768x577.png 768w" sizes="auto, (max-width: 795px) 100vw, 795px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="796" height="597" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_4o6.png" alt="" class="wp-image-42118" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_4o6.png 796w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_4o6-300x225.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_4o6-768x576.png 768w" sizes="auto, (max-width: 796px) 100vw, 796px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="796" height="596" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_5o6.png" alt="" class="wp-image-42119" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_5o6.png 796w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_5o6-300x225.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_install_5o6-768x575.png 768w" sizes="auto, (max-width: 796px) 100vw, 796px" /></figure>



<p class="wp-block-paragraph">The <strong>binaries are installed</strong>, and you can now run the Configuration Assistant.</p>



<h4 id="h-running-the-configuration-assistant" class="wp-block-heading">Running the Configuration Assistant</h4>



<p class="wp-block-paragraph">After installing the binaries, you can run the Configuration Assistant. Make sure <code>JAVA_HOME</code> is declared, and add the binaries to the <code>PATH</code> variable.</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~]$ export JAVA_HOME=/u01/app/oracle/product/jdk-17.0.17
&#091;oracle@vmvdt ~]$ export PATH=$JAVA_HOME/bin:$PATH
&#091;oracle@vmvdt ~]$ /u01/app/oracle/product/vdt23/bin/vdtca.sh</code></pre>



<p class="wp-block-paragraph">First, give a <code>root</code> password and a <code>veridata</code> password. These will be passwords of the <code>root</code> and <code>veridata</code> users for the MySQL instance, not the Web UI !</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="772" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_1o7_sudo_filled-1024x772.png" alt="" class="wp-image-42230" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_1o7_sudo_filled-1024x772.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_1o7_sudo_filled-300x226.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_1o7_sudo_filled-768x579.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_1o7_sudo_filled-1536x1158.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_1o7_sudo_filled.png 1584w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">For now, we&#8217;ll also keep the default recommended memory parameters:</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="795" height="597" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_2o7.png" alt="" class="wp-image-42113" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_2o7.png 795w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_2o7-300x225.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_2o7-768x577.png 768w" sizes="auto, (max-width: 795px) 100vw, 795px" /></figure>



<p class="wp-block-paragraph">After this, choose the Web UI administrator account.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="797" height="599" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_3o7.png" alt="" class="wp-image-42114" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_3o7.png 797w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_3o7-300x225.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_3o7-768x577.png 768w" sizes="auto, (max-width: 797px) 100vw, 797px" /></figure>



<p class="wp-block-paragraph">Then, decide how to <strong>secure your installation</strong>. We will keep things simple here by using self-signed certificates, but you should not use them in production, of course. If you want a port that is not the default 8831, now is the time to specify it.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="796" height="598" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_4o7.png" alt="" class="wp-image-42124" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_4o7.png 796w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_4o7-300x225.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_4o7-768x577.png 768w" sizes="auto, (max-width: 796px) 100vw, 796px" /></figure>



<p class="wp-block-paragraph">A window should pop up, asking you to run a script.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="637" height="396" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_root_script.png" alt="" class="wp-image-42126" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_root_script.png 637w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_root_script-300x186.png 300w" sizes="auto, (max-width: 637px) 100vw, 637px" /></figure>



<p class="wp-block-paragraph">As <code>root</code>, run the MySQL installation script located at <code>$VERIDATA_HOME/script/vdtca/install_configure_mysql.sh</code>, and then click <strong><em>Ok</em></strong>. The rest of the installation will follow. You can find below the output of the MySQL installation script.</p>



<pre class="wp-block-code"><code>&#091;root@vmvdt oracle]# /u01/app/oracle/product/vdt23/script/vdtca/install_configure_mysql.sh
&#091;INFO] Searching in '/u01/app/oracle/product/vdt23/script/vdtca/../..' for a directory matching 'mysql-commercial*'...
&#091;INFO] Found a matching directory: '/u01/app/oracle/product/vdt23/script/vdtca/../../mysql-commercial-8.0.42-linux-glibc2.17-x86_64-minimal'
2025-12-21T09:29:57.376559Z 0 &#091;System] &#091;MY-013169] &#091;Server] /u01/app/oracle/product/vdt23/mysql-commercial-8.0.42-linux-glibc2.17-x86_64-minimal/bin/mysqld (mysqld 8.0.42-commercial) initializing of server in progress as process 50020
2025-12-21T09:29:57.383296Z 1 &#091;System] &#091;MY-013576] &#091;InnoDB] InnoDB initialization has started.
2025-12-21T09:29:58.173524Z 1 &#091;System] &#091;MY-013577] &#091;InnoDB] InnoDB initialization has ended.
2025-12-21T09:29:59.799156Z 6 &#091;Warning] &#091;MY-010453] &#091;Server] root@localhost is created with an empty password ! Please consider switching off the --initialize-insecure option.
&#091;INFO] The Configuration Assistant will set the root user password as what you entered in the next stage of veridata repository creation.
&#091;INFO] MySQL has been installed and started.
&#091;INFO] Please return to the Configuration Assistant and click "OK" to continue.</code></pre>



<p class="wp-block-paragraph">After this, the installation is complete, and the last window displays the URL for the GoldenGate Veridata Web UI:</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="683" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_7o7_url-1024x683.png" alt="" class="wp-image-42127" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_7o7_url-1024x683.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_7o7_url-300x200.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_7o7_url-768x512.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_ca_7o7_url.png 1536w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">You have successfully installed GoldenGate Veridata, and can now <a href="#h-accessing-goldengate-veridata-web-ui">connect to the Web UI</a> !</p>



<h2 id="h-installing-goldengate-veridata-with-the-cli-silent-installation" class="wp-block-heading">Installing GoldenGate Veridata with the CLI (silent installation)</h2>



<h4 id="h-installing-binaries-0" class="wp-block-heading">Installing binaries</h4>



<p class="wp-block-paragraph">To perform a silent installation, let&#8217;s create a <code>vdt.rsp</code> file. As mentioned in the graphic installation chapter, you must decide <strong>what to install</strong>, and <strong>whether to build a new MySQL repository</strong>. This is what the file should look like for a Server/Agent setup with a new repository.</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~]$ cat vdt.rsp
oracle.install.responseFileVersion=/oracle/install/rspfmt_ogginstall_response_schema_v23_1_0
INSTALL_OPTION=SERVERAGENT
IS_NEWREPO=true
SOFTWARE_LOCATION=/u01/app/oracle/product/vdt23
INVENTORY_LOCATION=/u01/oraInventory
UNIX_GROUP_NAME=oinstall</code></pre>



<p class="wp-block-paragraph">Specify <code>INSTALL_OPTION=SERVER</code> for a server-only setup, and <code>AGENT</code> for an agent-only setup.</p>



<p class="wp-block-paragraph">Then, run the installer with the&nbsp;<code>-silent</code>&nbsp;and&nbsp;<code>-responseFile</code>&nbsp;options:</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt stage]$ /u01/stage/fbo_oggvdt_linux_services_shiphome/Disk1/runInstaller -silent -responseFile /home/oracle/vdt.rsp
Starting Oracle Universal Installer...

Checking Temp space: must be greater than 120 MB.   Actual 17959 MB    Passed
Checking swap space: must be greater than 150 MB.   Actual 4095 MB    Passed
Preparing to launch Oracle Universal Installer from /tmp/OraInstall2025-12-21_10-01-20AM. Please wait ...
You can find the log of this install session at:
 /tmp/OraInstall2025-12-21_10-01-20AM/installActions2025-12-21_10-01-20AM.log
The installation of Oracle Veridata Services was successful.
Please check '/u01/oraInventory/logs/silentInstall2025-12-21_10-01-20AM.log' for more details.
Successfully Setup Software.
The log of this install session can be found at:
 /u01/oraInventory/logs/installActions2025-12-21_10-01-20AM.log</code></pre>



<h4 id="h-running-the-configuration-assistant-0" class="wp-block-heading">Running the Configuration Assistant</h4>



<p class="wp-block-paragraph">After this, prepare a <code>vdtca.rsp</code> file with the following content (full file in the <a href="#h-appendix-vdtca-rsp-example">appendix</a> below):</p>



<pre class="wp-block-code"><code>oracle.install.responseFileVersion=/oracle/install/rspfmt_oggca_response_schema_v23_1_0
# SECTION A - GENERAL
DB_TYPE=MYSQL
ORACLE_USER=
ORACLE_PASS=
WALLET_LOC=
SERVICE_NAME=
IS_NEW_MYSQL=true
MYSQL_INSTALL_USER_TYPE=sudo
EXISTING_MYSQL_HOST=
EXISTING_MYSQL_PORT=
EXISTING_MYSQL_USERNAME=
EXISTING_MYSQL_PASSWORD=
NEW_MYSQL_ROOT_USERNAME=root
NEW_MYSQL_ROOT_PASSWORD=root_strong_password
NEW_MYSQL_VERIDATA_USERNAME=veridata
NEW_MYSQL_VERIDATA_PASSWORD=veridata_strong_password
SCHEMA_PREFIX=vdt
MIN_HEAP_SIZE=3g
MAX_HEAP_SIZE=10g
ADMINISTRATOR_USER=veridata
ADMINISTRATOR_PASSWORD=veridata_strong_password
STRONG_PWD_POLICY_ENABLED=true
IS_SSL_ENABLED=true
IS_SELF_SIGNED_CERTIFICATE=true
IS_PEM_FILES=false
CERTIFICATE_LOCATION=
PRIVATE_KEY_LOCATION=
CA_CERTIFICATE_LOCATION=
PRIVATE_KEY_PASSWORD=
VERIDATA_PORT=8831</code></pre>



<p class="wp-block-paragraph">And run the <code>vdtca.sh</code> script in the binary directory. Don&#8217;t forget to set <code>JAVA_HOME</code> and add binaries to the path !</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~]$ export JAVA_HOME=/u01/app/oracle/product/jdk-17.0.17
&#091;oracle@vmvdt ~]$ export PATH=$JAVA_HOME/bin:$PATH
&#091;oracle@vmvdt ~]$ /u01/app/oracle/product/vdt23/bin/vdtca.sh -silent -responseFile /home/oracle/vdtca.rsp</code></pre>



<h2 id="h-accessing-goldengate-veridata-web-ui" class="wp-block-heading">Accessing GoldenGate Veridata Web UI</h2>



<p class="wp-block-paragraph">Before connecting to the URL, <strong>make sure the port is open</strong> (below commands are just examples)</p>



<pre class="wp-block-code"><code>&#091;root@vmvdt ~]# firewall-cmd --list-ports

&#091;root@vmvdt ~]# firewall-cmd --add-port 8831/tcp --permanent
success
&#091;root@vmvdt ~]# firewall-cmd --reload
success
&#091;root@vmvdt ~]# firewall-cmd --list-ports
8831/tcp</code></pre>



<p class="wp-block-paragraph">Then, you can open the following URL, depending on your configuration: <code>https://vmvdt.com:8831/veridata</code></p>



<p class="wp-block-paragraph">Login with the username and password given for the Web UI during the installation process (not the ones from the MySQL installation !)</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="751" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_login_filled-1024x751.png" alt="" class="wp-image-42130" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_login_filled-1024x751.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_login_filled-300x220.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_login_filled-768x563.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_login_filled.png 1192w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">You now have access to the Web UI !</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="605" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_webui-1024x605.png" alt="" class="wp-image-42133" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_webui-1024x605.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_webui-300x177.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_webui-768x454.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_webui-1536x908.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/12/veridata_webui.png 1902w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h2 id="h-veridata-agent-installation-and-configuration" class="wp-block-heading">Veridata Agent Installation and Configuration</h2>



<p class="wp-block-paragraph">Since we opted for the <code>SERVERAGENT</code> option when setting up Veridata, we don&#8217;t need to install the agent separately. If you only installed Veridata server in the first place, run the OUI or the silent installation once more where you want your agent to be, with the <code>AGENT</code> option.</p>



<p class="wp-block-paragraph">Run the <code>agent_script.sh</code> to configure the agent. <strong>Warning: you must select a location that is outside the Veridata home !</strong> I will choose <code>/u01/app/oracle/product/vdt_agent1</code>.</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~]$ export JAVA_HOME=/u01/app/oracle/product/jdk-17.0.17
&#091;oracle@vmvdt ~]$ /u01/app/oracle/product/vdt23/agent/agent_config.sh /u01/app/oracle/product/vdt_agent1
Successfully deployed the agent.</code></pre>



<p class="wp-block-paragraph">Then, configure the agent, by copying the template properties file:</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~]$ cd /u01/app/oracle/product/vdt_agent1
&#091;oracle@vmvdt vdt_agent1]$ cp -p agent.properties.sample agent.properties
&#091;oracle@vmvdt vdt_agent1]$ vim agent.properties</code></pre>



<p class="wp-block-paragraph">Specify the following parameters in the <code>agent.properties</code> file:</p>



<ul class="wp-block-list">
<li><code>server.port=8832</code> : Listening port for the agent.</li>



<li><code>database.url=jdbc:oracle:thin:@hostname:1521:PDB1</code> : Connection string for the database. Example for other databases are given in the sample file.</li>



<li><code>server.jdbcDriver=ojdbc11-23.2.0.0.jar</code> : for an Oracle database</li>



<li><code>server.driversLocation=/u01/app/oracle/product/vdt23/agent/drivers</code> : points to the <code>agent/drivers</code> directory in your Veridata home directory.</li>
</ul>



<p class="wp-block-paragraph">The full list of drivers available is shown below. For other drivers, see the <a href="https://docs.oracle.com/en/middleware/goldengate/veridata/23/gvdug/agent-parameters-connections.html#GUID-1D3374B1-5459-4BBE-843E-78562AFB86BE" target="_blank" rel="noreferrer noopener">documentation</a>.</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~]$ ll /u01/app/oracle/product/vdt23/agent/drivers/
total 44584
-rw-------. 1 oracle oinstall  2487576 Nov  6 03:10 mysql-connector-j-8.3.0.jar
-rw-------. 1 oracle oinstall  7493107 Nov  6 03:10 ojdbc11-23.9.0.25.07.jar
-rw-------. 1 oracle oinstall  1098916 Nov  6 03:10 postgresql-42.7.7.jar
-rw-------. 1 oracle oinstall 19019852 Nov  6 03:10 vddb2-5.1.4.jar
-rw-------. 1 oracle oinstall 13643019 Nov  6 03:10 vdsqlserver-6.0.0.jar
-rw-------. 1 oracle oinstall  1899742 Nov  6 03:10 vdsybase-5.1.4.jar</code></pre>



<p class="wp-block-paragraph">You can finally start the agent:</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt vdt_agent1]$ ./agent.sh start agent.properties</code></pre>



<p class="wp-block-paragraph">For some reason, Oracle didn&#8217;t bother with having a log mentioning the agent is successfully started. To be sure, you can check the <code>java</code> processes.</p>



<pre class="wp-block-code"><code>&#091;oracle@vmvdt ~]$ ps -ef | grep java | grep agent
oracle     56408       1  0 12:47 pts/0    00:00:00 /u01/app/oracle/product/jdk-17.0.17/bin/java -Djava.util.logging.config.class=oracle.core.ojdl.logging.LoggingConfiguration -Doracle.core.ojdl.logging.config.file=/u01/app/oracle/product/vdt_agent1/config/odl.xml -Dhome=/u01/app/oracle/product/vdt23/agent -DagentHome=/u01/app/oracle/product/vdt_agent1 -XX:+UseParallelGC -Xms1024M -Dagent-manifest.jar=/u01/app/oracle/product/vdt23/agent/agent-manifest.jar -jar /u01/app/oracle/product/vdt23/agent/JavaAgent.jar agent.properties</code></pre>



<p class="wp-block-paragraph">You have <strong>successfully installed and configured</strong> GoldenGate Veridata server and agent !</p>



<h2 id="h-appendix" class="wp-block-heading">Appendix</h2>



<h4 id="h-error-my-013276-server-failed-to-set-datadir-to-when-running-install-configure-mysql-sh-as-root" class="wp-block-heading"><code>[ERROR] [MY-013276] [Server] Failed to set datadir to</code> when running <code>install_configure_mysql.sh</code> as <code>root</code></h4>



<p class="wp-block-paragraph">If you stumble on this error when running the <code>install_configure_mysql.sh</code> script as <code>root</code>, it is most probably related to the grants of the directories leading to the Veridata installation directory. Make sure they all have the <code>x</code> (execute) permission; otherwise, the <code>vdtrepouser</code> won&#8217;t be able to access them.</p>



<p class="wp-block-paragraph">And remember, you shouldn&#8217;t install Veridata on a host where other Oracle processes are running !</p>



<h4 id="h-appendix-vdtca-rsp-example" class="wp-block-heading">Appendix : <code>vdtca.rsp</code> example</h4>



<p class="wp-block-paragraph">Here is an example of a response file for the configuration assistant. I included at the end the full file with Oracle annotations:</p>



<pre class="wp-block-code"><code>oracle.install.responseFileVersion=/oracle/install/rspfmt_oggca_response_schema_v23_1_0
# SECTION A - GENERAL
DB_TYPE=MYSQL
ORACLE_USER=
ORACLE_PASS=
WALLET_LOC=
SERVICE_NAME=
IS_NEW_MYSQL=true
MYSQL_INSTALL_USER_TYPE=sudo
EXISTING_MYSQL_HOST=
EXISTING_MYSQL_PORT=
EXISTING_MYSQL_USERNAME=
EXISTING_MYSQL_PASSWORD=
NEW_MYSQL_ROOT_USERNAME=root
NEW_MYSQL_ROOT_PASSWORD=root_strong_password
NEW_MYSQL_VERIDATA_USERNAME=veridata
NEW_MYSQL_VERIDATA_PASSWORD=veridata_strong_password
SCHEMA_PREFIX=vdt
MIN_HEAP_SIZE=3g
MAX_HEAP_SIZE=10g
ADMINISTRATOR_USER=veridata
ADMINISTRATOR_PASSWORD=veridata_strong_password
STRONG_PWD_POLICY_ENABLED=true
IS_SSL_ENABLED=true
IS_SELF_SIGNED_CERTIFICATE=true
IS_PEM_FILES=false
CERTIFICATE_LOCATION=
PRIVATE_KEY_LOCATION=
CA_CERTIFICATE_LOCATION=
PRIVATE_KEY_PASSWORD=
VERIDATA_PORT=8831</code></pre>



<p class="wp-block-paragraph">And the full file:</p>



<pre class="wp-block-code"><code>################################################################################
## Copyright(c) Oracle Corporation 2016, 2022. All rights reserved.           ##
##                                                                            ##
## Specify values for the variables listed below to customize your            ##
## installation.                                                              ##
##                                                                            ##
## Each variable is associated with a comment. The comments can help to       ##
## populate the variables with the appropriate values.                        ##
##                                                                            ##
## IMPORTANT NOTE: This file should be secured to have read permission only   ##
## by the Oracle user or an administrator who owns this configuration to      ##
## protect any sensitive input values.                                        ##
##                                                                            ##
################################################################################

#-------------------------------------------------------------------------------
# Do not change the following system generated value.
#-------------------------------------------------------------------------------
oracle.install.responseFileVersion=/oracle/install/rspfmt_oggca_response_schema_v23_1_0


################################################################################
##                                                                            ##
## Oracle GoldenGate Veridata deployment configuration options and details    ##
##                                                                            ##
################################################################################

#-------------------------------------------------------------------------------
##                                                                            ##
## Instructions to fill out this response file                                ##
## -------------------------------------------                                ##
## Specify an option true or false                                            ##
## Specify true to use the Build-In MySql Repository Database                 ##                                            ##
## Specify false to use an existing MySql database for Repository             ##
##                                                                            ##
##                                                                            ##
#-------------------------------------------------------------------------------

DB_TYPE=MYSQL

#------------------------------------------------------------------------------------------
#
#    This section needs to be filled only if the Parameter DB_TYPE is set to ORACLE
#
#------------------------------------------------------------------------------------------

ORACLE_USER=

ORACLE_PASS=

WALLET_LOC=

SERVICE_NAME=


#--------------------------------------------------------------------------------------
#
#  This section needs to be filled only if the Parameter IS_NEW_MYSQL is set to false                                             #
#
#--------------------------------------------------------------------------------------


IS_NEW_MYSQL=true

MYSQL_INSTALL_USER_TYPE=sudo

EXISTING_MYSQL_HOST=

EXISTING_MYSQL_PORT=

EXISTING_MYSQL_USERNAME=

EXISTING_MYSQL_PASSWORD=

#------------------------------------------------------------------------------------------
#
#    This section needs to be filled only if the Parameter IS_NEW_MYSQL is set to true
#
#------------------------------------------------------------------------------------------

NEW_MYSQL_ROOT_USERNAME=root

NEW_MYSQL_ROOT_PASSWORD=root_strong_password

NEW_MYSQL_VERIDATA_USERNAME=veridata

NEW_MYSQL_VERIDATA_PASSWORD=veridata_strong_password

#------------------------------------------------------------------------------------------
#
#      Specify a prefix for the schema which will be created in the repository database
#
#------------------------------------------------------------------------------------------

SCHEMA_PREFIX=vdt

#--------------------------------------------------------------------------------
#       Specify the Minimum and Maximum Heap Size
#--------------------------------------------------------------------------------

MIN_HEAP_SIZE=3g

MAX_HEAP_SIZE=10g

#-------------------------------------------------------------------------------
# Specify if the admin user should enforce a strong password policy.
#-------------------------------------------------------------------------------

ADMINISTRATOR_USER=veridata

ADMINISTRATOR_PASSWORD=veridata_strong_password

#-------------------------------------------------------------------------------
# Specify if the admin user should enforce a strong password policy.
# Specify true to enable strong password policy management.
#-------------------------------------------------------------------------------
STRONG_PWD_POLICY_ENABLED=true

#-------------------------------------------------------------------------------------------
# Specify an option true or false
# Specify true to enable SSL
# Specify false to disable SSL
#-------------------------------------------------------------------------------------------

IS_SSL_ENABLED=true

#-------------------------------------------------------------------------------------------
# This section needs to be filled only if the parameter IS_SSL_ENABLED is set to true
# Specify an option true or false
#-------------------------------------------------------------------------------------------

IS_SELF_SIGNED_CERTIFICATE=true

IS_PEM_FILES=false

#-------------------------------------------------------------------------------------------
# Specify the certificate location
#-------------------------------------------------------------------------------------------

CERTIFICATE_LOCATION=

PRIVATE_KEY_LOCATION=

CA_CERTIFICATE_LOCATION=

PRIVATE_KEY_PASSWORD=

#-------------------------------------------------------------------------------------------
# The Default Port used by Veridata is 8830. You can also provide your own Custom Port.
# If SSL is enabled, the Defualt Port is 8831. You can also provide your own Custom Port
#-------------------------------------------------------------------------------------------

VERIDATA_PORT=8831
</code></pre>
<p>L’article <a href="https://www.dbi-services.com/blog/comparing-data-when-migrating-databases-with-goldengate-veridata-installation-guide/">Comparing Data When Migrating Databases With GoldenGate Veridata: Installation Guide</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/comparing-data-when-migrating-databases-with-goldengate-veridata-installation-guide/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Securing an Existing Unsecure GoldenGate Installation</title>
		<link>https://www.dbi-services.com/blog/securing-an-existing-unsecure-goldengate-installation/</link>
					<comments>https://www.dbi-services.com/blog/securing-an-existing-unsecure-goldengate-installation/#respond</comments>
		
		<dc:creator><![CDATA[Julien Delattre]]></dc:creator>
		<pubDate>Fri, 07 Nov 2025 07:00:00 +0000</pubDate>
				<category><![CDATA[GoldenGate]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[26ai]]></category>
		<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[ogg]]></category>
		<category><![CDATA[oggca]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[unsecure]]></category>
		<category><![CDATA[unsecured]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=41467</guid>

					<description><![CDATA[<p>You might have an existing unsecure GoldenGate installation that you would like to secure, whether it&#8217;s for security reasons or because you would like to dissociate the installation and its securing process. After searching everywhere in the Oracle documentation for how to proceed, I decided to try, investigate and eventually even asked Oracle directly. Here [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/securing-an-existing-unsecure-goldengate-installation/">Securing an Existing Unsecure GoldenGate Installation</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">You might have an <strong>existing unsecure GoldenGate installation</strong> that you would like to secure, whether it&#8217;s for <strong>security reasons</strong> or because you would like to dissociate the installation and its securing process. After searching everywhere in the Oracle documentation for how to proceed, I decided to try, investigate and eventually even asked Oracle directly. Here is the answer.</p>



<p class="wp-block-paragraph">For a <em>TL;DR</em> version of the answer, please go to the end of the blog, but in the meantime, here was my reasoning.</p>



<h2 id="h-setup-differences-between-a-secure-and-unsecure-goldengate-installation" class="wp-block-heading">Setup differences between a secure and unsecure GoldenGate installation</h2>



<h3 id="h-installation-differences" class="wp-block-heading"><strong>Installation differences</strong></h3>



<p class="wp-block-paragraph">From an <strong><em>installation perspective</em></strong>, the <strong>difference between a secure and unsecure installation is narrow</strong>. I talked earlier about <a href="https://www.dbi-services.com/blog/goldengate-23ai-installation-graphic-and-silent-mode-comparison-for-automation/" target="_blank" rel="noreferrer noopener">graphic and silent GoldenGate installations</a>, and for the silent installation, the following response file parameters are the only one involved in this security aspect:</p>



<pre class="wp-block-code"><code># SECTION C - SERVICE MANAGER
SECURITY_ENABLED=false

# SECTION H - SECURITY
TLS_1_2_ENABLED=false
TLS_1_3_ENABLED=false
FIPS_ENABLED=false
SERVER_CERTIFICATE=
SERVER_CERTIFICATE_KEY_FILE=
SERVER_CA_CERTIFICATES_FILE=
CLIENT_CERTIFICATE=
CLIENT_CERTIFICATE_KEY_FILE=
CLIENT_CA_CERTIFICATES_FILE</code></pre>



<p class="wp-block-paragraph"><code>*_ENABLED</code> parameters are just flags that should be set to true to secure the installation (at least for <code>SECURITY_ENABLED</code> and one TLS parameter), and then you need to provide the certificate files (client and server, three for each).</p>



<p class="wp-block-paragraph">To summarize, there is not much you have to do to configure a <strong>secure</strong> GoldenGate setup. So it shouldn&#8217;t be that difficult to enable these security features after installation: one flag, and a few certificates.</p>



<h3 id="h-configuration-differences" class="wp-block-heading"><strong>Configuration differences</strong></h3>



<p class="wp-block-paragraph">From a <strong><em>configuration perspective</em></strong>, there are not many differences either. Looking at the <code>deploymentConfiguration.dat</code> file for both secure and unsecure service managers, the only difference lies in the <code>ServiceManager.config.securityDetails</code> section. After cleaning what is similar, here are the differences:</p>



<pre class="wp-block-code"><code># Secure installation
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "securityDetails": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "network": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "common": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "fipsEnabled": false,
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; },
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "inbound": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "authMode": "clientOptional_server",
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "cipherSuites": &#091;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "TLS_AES_256_GCM_SHA384",
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "TLS_AES_128_GCM_SHA256",
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "TLS_CHACHA20_POLY1305_SHA256"
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ],
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "protocolVersion": "TLS_ALL"
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; },
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "outbound": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "authMode": "clientOptional_server",
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; },

# Unsecure installation
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "securityDetails": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "network": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "common": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "fipsEnabled": false,
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; },
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "inbound": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "authMode": "clientOptional_server",
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "cipherSuites": "^((?!anon|RC4|NULL|3DES).)*$",
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; },
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "outbound": {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "authMode": "client_server",
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; },</code></pre>



<p class="wp-block-paragraph">Basically, <code>securityDetails.outbound.authMode</code> is set to <code>clientOptional_server</code> on one side, and <code>client_server</code> on the other. And the unsecure configuration has a different <code>securityDetails.inbound.cipherSuites</code> parameter, and a missing <code>securityDetails.protocolVersion</code> parameter.</p>



<p class="wp-block-paragraph">But nothing in the configuration points to the wallet files, located in <code>$OGG_ETC_HOME/ssl</code>. So, how to add them here ?</p>



<h2 id="h-can-you-secure-an-unsecure-goldengate-installation" class="wp-block-heading">Can you secure an unsecure GoldenGate installation ?</h2>



<p class="wp-block-paragraph">When connecting to an unsecure GoldenGate service manager, you still have the ability to <strong>add and manage certificates from the UI</strong>, the same way you would do on a secure installation:</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="722" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/11/image-1024x722.png" alt="Certificates Management tab on an unsecured GoldenGate service manager UI" class="wp-image-41468" style="width:600px" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/11/image-1024x722.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/11/image-300x212.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/11/image-768x541.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/11/image.png 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">It is unfortunate, but just <strong>adding the certificates from the UI doesn&#8217;t make your installation secure</strong>. In fact, even after modifying the <code>deploymentConfiguration.dat</code> files, the last piece missing in the configuration, as described above, it doesn&#8217;t work. You will only end up with a <strong>broken installation</strong>, even when doing the same with all your deployments and restarting everything.</p>



<h3 id="h-is-there-really-no-way-to-secure-an-already-existing-goldengate-installation" class="wp-block-heading">Is there really no way to secure an already existing GoldenGate installation ?</h3>



<p class="wp-block-paragraph">Unfortunately, not at this point. And it was confirmed earlier this week on the <a href="https://community.oracle.com/mosc/discussion/4593112/securing-an-already-existing-unsecured-goldengate-23ai-installation" target="_blank" rel="noreferrer noopener">MOSC forums</a> by <strong>Gopal Gaur</strong>, <em>Senior Principal Software Engineer</em> working on GoldenGate at Oracle.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">You can not convert non secure deployment into secure deployment, you will need a new service manager that supports sever side SSL/TLS.</p>



<p class="wp-block-paragraph">You can not convert non secure deployment into secure deployment at this stage, we have an opened enhancement for this.</p>
</blockquote>



<p class="wp-block-paragraph">To wrap up, bad news: <strong>it is not possible to secure an existing GoldenGate installation</strong>, but good news, <strong>Oracle is apparently working</strong> on it. In the meantime, just <a href="https://www.dbi-services.com/blog/goldengate-23ai-installation-graphic-and-silent-mode-comparison-for-automation/">re-install GoldenGate</a>&#8230;</p>
<p>L’article <a href="https://www.dbi-services.com/blog/securing-an-existing-unsecure-goldengate-installation/">Securing an Existing Unsecure GoldenGate Installation</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/securing-an-existing-unsecure-goldengate-installation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GoldenGate 26ai Installation: Graphic and Silent Mode Comparison for Automation</title>
		<link>https://www.dbi-services.com/blog/goldengate-23ai-installation-graphic-and-silent-mode-comparison-for-automation/</link>
					<comments>https://www.dbi-services.com/blog/goldengate-23ai-installation-graphic-and-silent-mode-comparison-for-automation/#respond</comments>
		
		<dc:creator><![CDATA[Julien Delattre]]></dc:creator>
		<pubDate>Mon, 03 Nov 2025 08:00:00 +0000</pubDate>
				<category><![CDATA[Application integration & Middleware]]></category>
		<category><![CDATA[Database Administration & Monitoring]]></category>
		<category><![CDATA[GoldenGate]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[23ai]]></category>
		<category><![CDATA[automated]]></category>
		<category><![CDATA[Automation]]></category>
		<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[microservices]]></category>
		<category><![CDATA[oggca]]></category>
		<category><![CDATA[Replication]]></category>
		<category><![CDATA[response file]]></category>
		<category><![CDATA[responsefile]]></category>
		<category><![CDATA[service manager]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=40320</guid>

					<description><![CDATA[<p>26ai update: This article was originally written for 23ai. But not much changes when setting up GoldenGate 26ai. Just adapt the responseFileVersion when doing the silent installation, and that&#8217;s it ! As instructed in this other blog, use oracle.install.responseFileVersion=/oracle/install/rspfmt_ogginstall_response_schema_v26_1_0 Automating Oracle installations can sometimes be daunting, given the long list of parameters available. We&#8217;ll compare [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/goldengate-23ai-installation-graphic-and-silent-mode-comparison-for-automation/">GoldenGate 26ai Installation: Graphic and Silent Mode Comparison for Automation</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong><em>26ai update:</em></strong> <em>This article was originally written for 23ai. But not much changes when setting up GoldenGate 26ai. Just adapt the <code>responseFileVersion</code> when doing the silent installation, and that&#8217;s it ! As instructed in this <a href="https://www.dbi-services.com/blog/goldengate-26ai-installation-and-new-administration-features/" target="_blank" rel="noreferrer noopener">other blog</a>, use <code>oracle.install.responseFileVersion=/oracle/install/rspfmt_ogginstall_response_schema_v26_1_0</code></em></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Automating Oracle installations can sometimes be daunting, given the long list of parameters available. We&#8217;ll <strong>compare both graphic and silent installations</strong> of GoldenGate 23ai, focusing on building <strong>minimalist response files for automation</strong> purposes.</p>



<div class="wp-block-yoast-seo-table-of-contents yoast-table-of-contents"><h2>Table of contents</h2><ul><li><a href="#h-prerequisites-for-goldengate-installation" data-level="2">Prerequisites for GoldenGate installation</a></li><li><a href="#h-installing-goldengate-with-the-oui-graphic-installation" data-level="2">Installing GoldenGate with the OUI (graphic installation)</a><ul><li><a href="#h-installing-goldengate-binaries" data-level="3">Installing GoldenGate binaries</a></li><li><a href="#h-installing-the-service-manager-and-the-first-deployment" data-level="3">Installing the Service Manager and the First Deployment</a></li></ul></li><li><a href="#h-installing-goldengate-with-the-cli-silent-installation" data-level="2">Installing GoldenGate with the CLI (silent installation)</a><ul><li><a href="#h-installing-goldengate-binaries-0" data-level="3">Installing GoldenGate binaries</a></li><li><a href="#h-installing-the-service-manager-and-the-first-deployment-0" data-level="3">Installing the Service Manager and the First Deployment</a></li></ul></li><li><a href="#h-adding-or-removing-a-deployment" data-level="2">Adding or Removing a Deployment</a><ul><li><a href="#h-removing-a-deployment" data-level="3">Removing a deployment</a></li></ul></li><li><a href="#h-accessing-the-web-ui" data-level="2">Accessing the Web UI</a></li><li><a href="#h-appendix-oggca-rsp-example" data-level="2">Appendix: oggca.rsp example</a></li></ul></div>



<h2 id="h-prerequisites-for-goldengate-installation" class="wp-block-heading">Prerequisites for GoldenGate installation</h2>



<p class="wp-block-paragraph">You can set up GoldenGate in two different ways:</p>



<ul class="wp-block-list">
<li>From the base archive, available on <a href="https://edelivery.oracle.com/">eDelivery</a> (V1042871-01.zip for Linux x86-64, for instance)</li>



<li>From the patched archive, updated quarterly and available on the Oracle Support. At the time of writing of this blog, GoldenGate 23.9 is the latest version available (23.10, now called 23.26, was announced but not released yet). You can find the <a href="https://support.oracle.com/knowledge/Oracle%20Database%20Products/3093376_1.html" target="_blank" rel="noreferrer noopener">MOS Document 3093376.1</a> on the subject, or <a href="https://support.oracle.com/knowledge/Oracle%20Database%20Products/2193391_1.html" target="_blank" rel="noreferrer noopener">2193391.1</a> for general patching information on GoldenGate. <strong>Patch 38139663 is the completely patched installation</strong> (we will use this one in the blog), while patch 38139662 is the patch-only archive, applied on an existing GoldenGate installation.</li>
</ul>



<p class="wp-block-paragraph">For the purpose of this installation, we will use the <code>oracle-database-preinstall</code> rpm, even if we don&#8217;t need all the things it brings. If you plan on installing GoldenGate on an existing Oracle database server, Oracle recommends using a separate user. We will keep <code>oracle</code> here.</p>



<pre class="wp-block-code"><code>&#091;root@vmogg ~] dnf install -y oracle-database-preinstall-23ai
&#091;root@vmogg ~] mkdir -p /u01/stage
&#091;root@vmogg ~] chown oracle:oinstall -R /u01</code></pre>



<p class="wp-block-paragraph">With the <code>oracle</code> user created through the rpm installation, unzip GoldenGate source file into a stage area:</p>



<pre class="wp-block-code"><code>&#091;root@vmogg ~] su - oracle
&#091;oracle@vmogg ~] cd /u01/stage
&#091;oracle@vmogg stage] unzip -oq p38139663_23902507OGGRU_Linux-x86-64.zip -d /u01/stage/</code></pre>



<h2 id="h-installing-goldengate-with-the-oui-graphic-installation" class="wp-block-heading">Installing GoldenGate with the OUI (graphic installation)</h2>



<h3 id="h-installing-goldengate-binaries" class="wp-block-heading">Installing GoldenGate binaries</h3>



<p class="wp-block-paragraph">Running the graphic installation of GoldenGate is not any different from what you would do with an Oracle database installation.</p>



<p class="wp-block-paragraph">After setting up X11 display (out of the scope of this blog), you should first define the <code>OGG_HOME</code> variable to the location of the GoldenGate installation and then run the installer:</p>



<pre class="wp-block-code"><code>&#091;oracle@vmogg ~]$ export OGG_HOME=/u01/app/oracle/product/ogg23ai
&#091;oracle@vmogg ~]$ /u01/stage/fbo_ggs_Linux_x64_Oracle_services_shiphome/Disk1/runInstaller</code></pre>



<p class="wp-block-paragraph">Bug: depending on the display options you have, you might have a color mismatch on the GoldenGate installation window, most of it appearing black (see this <a href="http://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_black_window.png" target="_blank" rel="noreferrer noopener">image</a>). If this happens, run the following command before launching the installation: <code>export _JAVA_OPTIONS="-Dsun.java2d.xrender=false"</code></p>



<p class="wp-block-paragraph">Just click <em>Next</em> on the first step. Starting from GoldenGate 23ai, <strong>Classic Architecture was desupported</strong>, so you don&#8217;t have to worry anymore about which architecture to choose. The Microservices Architecture is the only choice now.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_1o5.png" alt="" class="wp-image-40326" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_1o5.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_1o5-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_1o5-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">Fill in the software location for your installation of GoldenGate. This will match the <code>OGG_HOME</code> environment variable. If the variable is set prior to launching the <code>runInstaller</code>, the software location is filled automatically.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_2o5.png" alt="" class="wp-image-40327" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_2o5.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_2o5-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_2o5-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph"><em><strong>Step 3</strong></em> is just a summary of the installation. You can save the response file at this stage and use it later to standardize your installations with the silent installation described below. Then, click on <em>Install</em>.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_3o5-1.png" alt="" class="wp-image-40329" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_3o5-1.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_3o5-1-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_3o5-1-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">After a few seconds, the installation is complete, and you can exit the installer.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_4o5.png" alt="" class="wp-image-40330" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_4o5.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_4o5-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_4o5-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">If it&#8217;s your first Oracle-related installation on this server, you might have to run the <code>/u01/app/oraInventory/orainstRoot.sh</code> script as <code>root</code> when prompted to do so.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="576" height="321" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_orainstRoot-1.png" alt="" class="wp-image-40336" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_orainstRoot-1.png 576w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_orainstRoot-1-300x167.png 300w" sizes="auto, (max-width: 576px) 100vw, 576px" /></figure>
</div>


<pre class="wp-block-code"><code>&#091;root@vmogg ~]# /u01/app/oraInventory/orainstRoot.sh
Changing permissions of /u01/app/oraInventory.
Adding read,write permissions for group.
Removing read,write,execute permissions for world.

Changing groupname of /u01/app/oraInventory to oinstall.
The execution of the script is complete.</code></pre>



<p class="wp-block-paragraph">The binary installation is complete.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_5o5.png" alt="" class="wp-image-40331" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_5o5.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_5o5-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/ogg_installation_core_5o5-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph"></p>



<h3 id="h-installing-the-service-manager-and-the-first-deployment" class="wp-block-heading">Installing the Service Manager and the First Deployment</h3>



<p class="wp-block-paragraph">Once the binaries are installed, with the same <code>oracle</code> X11 terminal, run the <code>oggca.sh</code> script located in the <code>$OGG_HOME/bin</code> directory:</p>



<pre class="wp-block-code"><code>&#091;oracle@vmogg ~]$ export OGG_HOME=/u01/app/oracle/product/ogg23ai
&#091;oracle@vmogg ~]$ $OGG_HOME/bin/oggca.sh</code></pre>



<p class="wp-block-paragraph">On the first step (see below), you will have:</p>



<ul class="wp-block-list">
<li><em><strong>Software Home</strong></em>, which contains the GoldenGate binaries, also called <code>$OGG_HOME</code></li>



<li><em><strong>Deployment Home</strong></em>, filled with the location of the <strong>service manager directory</strong> (and not the GoldenGate deployment, thank you Oracle for this one…).</li>



<li><strong><em>Port</em></strong> (default is 7809) of the service manager. This will be the main point of entry for the web UI.</li>



<li><em><strong>Register as a service/system daemon</strong></em>, if you want GoldenGate to be a service on your server.</li>



<li><strong><em>Integrate with XAG</em></strong>, for a GoldenGate RAC installation (out of the scope of this blog).</li>



<li><strong><em>Enable Security</em></strong>, with the associated certificates and key. You can leave this unchecked if you just want to test the GoldenGate installation process.</li>



<li>We leave the rest unchecked.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="http://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_1o7.png" alt="Step 1 out of 7 of GoldenGate graphic installation with oggca.sh" class="wp-image-41096" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_1o7.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_1o7-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_1o7-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">Next, fill in the credentials for the <strong>service manager</strong>. Enabling <strong>Strong Password Policy</strong> will force you to enter a secure password.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="http://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_2o7.png" alt="Step 2 out of 7 of GoldenGate graphic installation with oggca.sh" class="wp-image-41097" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_2o7.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_2o7-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_2o7-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">In previous versions of GoldenGate, you could first set up the service manager and wait before configuring your first deployment. It is now mandatory to set up the first deployment:</p>



<ul class="wp-block-list">
<li><strong><em>Deployment Name</em></strong>: <code>ogg_test_01</code> for this installation. It is not just cosmetic, you will refer to this name for connection, in the <code>adminclient</code> and on the Web UI.</li>



<li><strong><em>Deployment Home</em></strong>: Path to the deployment home. Logs, trail files and configuration will sit there.</li>



<li><strong><em>Ports</em></strong>: Four ports need to be filled here. I would recommend using the default ports for the first deployment (7810, 7811, 7812 and 7813), or ports following the service manager port (7809). For a <a href="#h-adding-or-removing-a-deployment">second deployment</a>, you can continue with the following ports (7814, 7815, 7816, 7817), or keep the same units digit (7820, 7821, 7822, 7823) for a better understanding of your GoldenGate infrastructure.</li>



<li><strong><em>Remote Metrics for the Deployment</em></strong>: out of the scope of this blog, not needed for a basic GoldenGate installation.</li>



<li><strong><em>Security</em></strong>: If you secured your service manager earlier in the previous step, you should secure your deployment here, providing keys and certificates.</li>



<li><strong><em>Replication Options</em></strong>: <code>TNS_ADMIN</code> could already be filled, otherwise just specify its path. GoldenGate will look for TNS entries here. You should also fill in the replication schema name.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="http://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_3o7.png" alt="Step 3 out of 7 of GoldenGate graphic installation with oggca.sh" class="wp-image-41094" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_3o7.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_3o7-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_3o7-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">Later, fill in the <strong>credentials for the deployment</strong>. They can be different from the service manager credentials, or you can check the box to keep the same credentials.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="http://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_4o7.png" alt="Step 4 out of 7 of GoldenGate graphic installation with oggca.sh" class="wp-image-41093" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_4o7.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_4o7-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_4o7-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">In the summary screen, review your configuration, and save the response file for later if required. Click on <strong><em>Finish</em></strong> to start the installation.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="http://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_5o7.png" alt="Step 5 out of 7 of GoldenGate graphic installation with oggca.sh" class="wp-image-41095" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_5o7.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_5o7-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_5o7-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">The installation should take a few seconds:</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="798" height="596" src="http://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_6o7.png" alt="Step 6 out of 7 of GoldenGate graphic installation with oggca.sh" class="wp-image-41098" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_6o7.png 798w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_6o7-300x224.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_installation_oggca_6o7-768x574.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>
</div>


<p class="wp-block-paragraph">That&#8217;s it, you have successfully installed GoldenGate 23ai ! Go to the <a href="#h-accessing-the-web-ui">web UI</a> section for how to connect to your GoldenGate environment.</p>



<h2 id="h-installing-goldengate-with-the-cli-silent-installation" class="wp-block-heading">Installing GoldenGate with the CLI (silent installation)</h2>



<h3 id="h-installing-goldengate-binaries-0" class="wp-block-heading">Installing GoldenGate binaries</h3>



<p class="wp-block-paragraph">To perform the GoldenGate installation process in silent mode, you can either use a response file containing the arguments needed for the installation or give these arguments in the command line.</p>



<p class="wp-block-paragraph">For the GoldenGate binaries installation, create a <code>oggcore_23ai.rsp</code> file, changing <code>SOFTWARE_LOCATION</code>, <code>INVENTORY_LOCATION</code> and <code>UNIX_GROUP_NAME</code> as needed:</p>



<pre class="wp-block-code"><code>&#091;oracle@vmogg ~]$ cat oggcore_23ai.rsp
oracle.install.responseFileVersion=/oracle/install/rspfmt_ogginstall_response_schema_v23_1_0
INSTALL_OPTION=ORA23ai
SOFTWARE_LOCATION=/u01/app/oracle/product/ogg23ai
INVENTORY_LOCATION=/u01/app/oraInventory
UNIX_GROUP_NAME=oinstall</code></pre>



<p class="wp-block-paragraph">Then, run the installer with the <code>-silent</code> and <code>-responseFile</code> options:</p>



<pre class="wp-block-code"><code>&#091;oracle@vmogg ~]$ /u01/stage/fbo_ggs_Linux_x64_Oracle_services_shiphome/Disk1/runInstaller -silent -responseFile /home/oracle/oggcore_23ai.rsp
Starting Oracle Universal Installer...

Checking Temp space: must be greater than 120 MB.   Actual 17094 MB    Passed
Checking swap space: must be greater than 150 MB.   Actual 4095 MB    Passed
Preparing to launch Oracle Universal Installer from /tmp/OraInstall2025-09-24_09-53-23AM. Please wait ...
You can find the log of this install session at:
 /u01/app/oraInventory/logs/installActions2025-09-24_09-53-23AM.log

As a root user, run the following script(s):
	1. /u01/app/oraInventory/orainstRoot.sh



Successfully Setup Software.
The installation of Oracle GoldenGate Services was successful.
Please check '/u01/app/oraInventory/logs/silentInstall2025-09-24_09-53-23AM.log' for more details.</code></pre>



<p class="wp-block-paragraph">Same thing as with the graphic installation: if it&#8217;s the first time you run an Oracle-related installation on this server, run the <code>orainstRoot.sh</code> script as <code>root</code>:</p>



<pre class="wp-block-code"><code>&#091;root@vmogg ~]# /u01/app/oraInventory/orainstRoot.sh
Changing permissions of /u01/app/oraInventory.
Adding read,write permissions for group.
Removing read,write,execute permissions for world.

Changing groupname of /u01/app/oraInventory to oinstall.
The execution of the script is complete.</code></pre>



<p class="wp-block-paragraph"></p>



<h3 id="h-installing-the-service-manager-and-the-first-deployment-0" class="wp-block-heading">Installing the Service Manager and the First Deployment</h3>



<p class="wp-block-paragraph">Once the binaries are installed, run the <code>oggca.sh</code> script with the response file corresponding to the service manager and deployment that you want to create. The content of the response file <code>oggca.rsp</code> should be adapted to your needs, but I integrated a full example in the appendix below.</p>



<pre class="wp-block-code"><code>&#091;oracle@vmogg ~]$ /u01/app/oracle/product/ogg23ai/bin/oggca.sh -silent -responseFile /home/oracle/oggca.rsp

As part of the process of registering Service Manager as a system daemon, the following steps will be performed:
	1- The deployment will be stopped before registering the Service Manager as a daemon.
	2- A new popup window will show the details of the script used to register the Service Manager as a daemon.
	3- After the register script is executed, the Service Manager daemon will be started in the background and the deployment will be automatically restarted.

Click "OK" to continue.

In order to register Service Manager as a system service/daemon, as a "root" user, execute the following script:
	(1). /u01/app/oracle/product/ogg23ai_SM/bin/registerServiceManager.sh

To execute the configuration scripts:
  1.Open a terminal window
  2.Login as "root"
  3.Run the script


Successfully Setup Software.</code></pre>



<p class="wp-block-paragraph">If you asked for the creation of a service, then run the following command as <code>root</code>:</p>



<pre class="wp-block-code"><code>&#091;root@vmogg ~]# /u01/app/oracle/product/ogg23ai_SM/bin/registerServiceManager.sh
Copyright (c) 2017, 2024, Oracle and/or its affiliates. All rights reserved.
----------------------------------------------------
     Oracle GoldenGate Install As Service Script
----------------------------------------------------
OGG_HOME=/u01/app/oracle/product/ogg23ai
OGG_CONF_HOME=/u01/app/oracle/product/ogg23ai_SM/etc/conf
OGG_VAR_HOME=/u01/app/oracle/product/ogg23ai_SM/var
OGG_USER=oracle
Running OracleGoldenGateInstall.sh...
Created symlink /etc/systemd/system/multi-user.target.wants/OracleGoldenGate.service → /etc/systemd/system/OracleGoldenGate.service.
Successfully Setup Software.</code></pre>



<p class="wp-block-paragraph"><strong>Warning:</strong> If you plan on automating a GoldenGate installation and setup, make sure response files can only be read by the <code>oracle</code> user, and clean the response files if you need to keep passwords in plain text inside the file.</p>



<h2 id="h-adding-or-removing-a-deployment" class="wp-block-heading">Adding or Removing a Deployment</h2>



<p class="wp-block-paragraph">To add or remove a deployment to an existing service manager, you can do that graphically with <code>oggca.sh</code>, or in silent mode. In silent mode, I give below a minimal response file example to add a new deployment (removing everything that would be already configured, like service manager properties). Of course, the deployment name, paths, and ports should be different from an existing deployment. And if your deployment is secured, you should fill <code>SECTION H - SECURITY</code> in the same way you did for the first installation, and specify <code>SECURITY_ENABLED=true</code> in <code>SECTION C - SERVICE MANAGER</code>.</p>



<h4 id="h-adding-a-deployment" class="wp-block-heading">Adding a deployment</h4>



<pre class="wp-block-code"><code>oracle.install.responseFileVersion=/oracle/install/rspfmt_oggca_response_schema_v23_1_0

# SECTION A - GENERAL
CONFIGURATION_OPTION=ADD
DEPLOYMENT_NAME=ogg_test_02

# SECTION B - ADMINISTRATOR ACCOUNT
ADMINISTRATOR_USER=ogg
ADMINISTRATOR_PASSWORD=ogg_password
DEPLOYMENT_ADMINISTRATOR_USER=ogg
DEPLOYMENT_ADMINISTRATOR_PASSWORD=ogg_password

# SECTION C - SERVICE MANAGER
HOST_SERVICEMANAGER=your_host
PORT_SERVICEMANAGER=7809
SECURITY_ENABLED=false
STRONG_PWD_POLICY_ENABLED=false

# SECTION E - SOFTWARE HOME
OGG_SOFTWARE_HOME=/u01/app/oracle/product/ogg23ai

# SECTION F - DEPLOYMENT DIRECTORIES
OGG_DEPLOYMENT_HOME=/u01/app/oracle/product/ogg_test_02
OGG_ETC_HOME=/u01/app/oracle/product/ogg_test_02/etc
OGG_CONF_HOME=/u01/app/oracle/product/ogg_test_02/etc/conf
OGG_SSL_HOME=/u01/app/oracle/product/ogg_test_02/etc/ssl
OGG_VAR_HOME=/u01/app/oracle/product/ogg_test_02/var
OGG_DATA_HOME=/u01/app/oracle/product/ogg_test_02/var/lib/data
OGG_ARCHIVE_HOME=/u01/app/oracle/product/ogg_test_02/var/lib/archive

# SECTION G - ENVIRONMENT VARIABLES
ENV_LD_LIBRARY_PATH=${OGG_HOME}/lib/instantclient:${OGG_HOME}/lib
ENV_TNS_ADMIN=/u01/app/oracle/network/admin
ENV_STREAMS_POOL_SIZE=
ENV_USER_VARS=

# SECTION H - SECURITY
TLS_1_2_ENABLED=false
TLS_1_3_ENABLED=false
FIPS_ENABLED=false
SERVER_CERTIFICATE=
SERVER_CERTIFICATE_KEY_FILE=
SERVER_CA_CERTIFICATES_FILE=
CLIENT_CERTIFICATE=
CLIENT_CERTIFICATE_KEY_FILE=
CLIENT_CA_CERTIFICATES_FILE=

# SECTION I - SERVICES
ADMINISTRATION_SERVER_ENABLED=true
PORT_ADMINSRVR=7820
DISTRIBUTION_SERVER_ENABLED=true
PORT_DISTSRVR=7821
NON_SECURE_DISTSRVR_CONNECTS_TO_SECURE_RCVRSRVR=false
RECEIVER_SERVER_ENABLED=true
PORT_RCVRSRVR=7822
METRICS_SERVER_ENABLED=true
METRICS_SERVER_IS_CRITICAL=false
PORT_PMSRVR=7823
PMSRVR_DATASTORE_TYPE=BDB
PMSRVR_DATASTORE_HOME=
ENABLE_DEPLOYMENT_REMOTE_METRICS=false
DEPLOYMENT_REMOTE_METRICS_LISTENING_HOST=
DEPLOYMENT_REMOTE_METRICS_LISTENING_PORT=0

# SECTION J - REPLICATION OPTIONS
OGG_SCHEMA=OGGADMIN</code></pre>



<h3 id="h-removing-a-deployment" class="wp-block-heading">Removing a deployment</h3>



<p class="wp-block-paragraph">Same thing for the removal of an existing deployment, where the minimal response file is even simpler. You just need the deployment name and service manager information.</p>



<pre class="wp-block-code"><code>oracle.install.responseFileVersion=/oracle/install/rspfmt_oggca_response_schema_v23_1_0

# SECTION A - GENERAL
CONFIGURATION_OPTION=REMOVE
DEPLOYMENT_NAME=ogg_test_02

# SECTION B - ADMINISTRATOR ACCOUNT
ADMINISTRATOR_USER=ogg
ADMINISTRATOR_PASSWORD=ogg_password
DEPLOYMENT_ADMINISTRATOR_USER=ogg
DEPLOYMENT_ADMINISTRATOR_PASSWORD=ogg_password

# SECTION C - SERVICE MANAGER
HOST_SERVICEMANAGER=your_host
PORT_SERVICEMANAGER=7809
SECURITY_ENABLED=false

# SECTION H - SECURITY
TLS_1_2_ENABLED=false
TLS_1_3_ENABLED=false
FIPS_ENABLED=false
SERVER_CERTIFICATE=
SERVER_CERTIFICATE_KEY_FILE=
SERVER_CA_CERTIFICATES_FILE=
CLIENT_CERTIFICATE=
CLIENT_CERTIFICATE_KEY_FILE=
CLIENT_CA_CERTIFICATES_FILE=

# SECTION K - REMOVE DEPLOYMENT OPTIONS
REMOVE_DEPLOYMENT_FROM_DISK=true</code></pre>



<h2 id="h-accessing-the-web-ui" class="wp-block-heading">Accessing the Web UI</h2>



<p class="wp-block-paragraph">Whether you installed GoldenGate graphically or silently, you will now be able to connect to the Web UI. Except for the design, it is pretty much the same thing as the Microservices Architecture of GoldenGate 19c and 21c. Connect to the hostname of your GoldenGate installation, on the service manager port: <code>http://hostname:port</code>, or <code>https://hostname:port</code> if the installation is secured.</p>



<p class="wp-block-paragraph">With the example of this blog:</p>



<ul class="wp-block-list">
<li><code>7809</code> — Service manager</li>



<li><code>7810</code> — Administration service of the first deployment you created, for managing extracts and replicats</li>



<li><code>7811</code> — Distribution service, to send trail files to other GoldenGate deployments.</li>



<li><code>7812</code> — Receiver service, to receive trail files.</li>



<li><code>7813</code> — Performance metrics service, for extraction and replication analysis.</li>
</ul>



<p class="wp-block-paragraph">Log in either with the service manager credentials, or with the deployment credentials:</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="986" height="888" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_connection.png" alt="" class="wp-image-41353" style="width:500px;height:auto" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_connection.png 986w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_connection-300x270.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_connection-768x692.png 768w" sizes="auto, (max-width: 986px) 100vw, 986px" /></figure>
</div>


<h4 id="h-service-manager-web-ui" class="wp-block-heading">Service Manager Web UI</h4>



<p class="wp-block-paragraph">The service manager web UI allows you to stop and start deployment services, manage users and certificates. You will hardly ever use it, even less since deployment creation/removal will be done through <code>oggca.sh</code> anyway. If you have many deployments, it can still be useful to log in to these deployments quickly.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="315" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_sm_webui-1024x315.png" alt="" class="wp-image-41354" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_sm_webui-1024x315.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_sm_webui-300x92.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_sm_webui-768x237.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_sm_webui-1536x473.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_sm_webui-2048x631.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<h4 id="h-deployment-web-ui" class="wp-block-heading">Deployment Web UI</h4>



<p class="wp-block-paragraph">The deployment web UI, however, is used throughout the whole lifecycle of your GoldenGate replications. You manage extracts, replicats, distribution paths, and more.</p>



<p class="wp-block-paragraph"><em><strong>NB for the newcomers</strong></em>: you don&#8217;t have to bookmark all the services of a deployment. Once logged in to the administration service of a deployment, you can just jump between services through the UI, by clicking on the services on the top bar.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="499" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_depl-1024x499.png" alt="" class="wp-image-41355" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_depl-1024x499.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_depl-300x146.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_depl-768x375.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_depl-1536x749.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/10/ogg_webui_depl-2048x999.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph">You now have a full GoldenGate 23ai installation, and can start configuring your first replication !</p>



<h2 id="h-appendix-oggca-rsp-example" class="wp-block-heading">Appendix: <code>oggca.rsp</code> example</h2>



<p class="wp-block-paragraph">Here is an example of a response file to create both the service manager and the first deployment of a GoldenGate installation. I included at the end the full file with Oracle annotations.</p>



<pre class="wp-block-code"><code>oracle.install.responseFileVersion=/oracle/install/rspfmt_oggca_response_schema_v23_1_0

# SECTION A - GENERAL
CONFIGURATION_OPTION=ADD
DEPLOYMENT_NAME=ogg_test_01

# SECTION B - ADMINISTRATOR ACCOUNT
ADMINISTRATOR_USER=ogg
ADMINISTRATOR_PASSWORD=ogg_password
DEPLOYMENT_ADMINISTRATOR_USER=ogg
DEPLOYMENT_ADMINISTRATOR_PASSWORD=ogg_password

# SECTION C - SERVICE MANAGER
SERVICEMANAGER_DEPLOYMENT_HOME=/u01/app/oracle/product/ogg23ai_SM
SERVICEMANAGER_ETC_HOME=/u01/app/oracle/product/ogg23ai_SM/etc
SERVICEMANAGER_CONF_HOME=/u01/app/oracle/product/ogg23ai_SM/etc/conf
SERVICEMANAGER_SSL_HOME=/u01/app/oracle/product/ogg23ai_SM/etc/ssl
SERVICEMANAGER_VAR_HOME=/u01/app/oracle/product/ogg23ai_SM/var
SERVICEMANAGER_DATA_HOME=/u01/app/oracle/product/ogg23ai_SM/var/lib/data
SERVICEMANAGER_ARCHIVE_HOME=/u01/app/oracle/product/ogg23ai_SM/var/lib/archive
HOST_SERVICEMANAGER=your_host
PORT_SERVICEMANAGER=7809
SECURITY_ENABLED=false
STRONG_PWD_POLICY_ENABLED=false
CREATE_NEW_SERVICEMANAGER=true
REGISTER_SERVICEMANAGER_AS_A_SERVICE=true
INTEGRATE_SERVICEMANAGER_WITH_XAG=false
EXISTING_SERVICEMANAGER_IS_XAG_ENABLED=false
ENABLE_SERVICE_MANAGER_REMOTE_METRICS=false
SERVICE_MANAGER_REMOTE_METRICS_LISTENING_HOST=
SERVICE_MANAGER_REMOTE_METRICS_LISTENING_PORT=0
PLUGIN_SERVICE_ENABLED=false

# SECTION D - CONFIGURATION SERVICE
CONFIGURATION_SERVICE_ENABLED=false
CONFIGURATION_SERVICE_BACKEND_TYPE=FILESYSTEM
CONFIGURATION_SERVICE_BACKEND_CONNECTION_STRING=
CONFIGURATION_SERVICE_BACKEND_USERNAME=
CONFIGURATION_SERVICE_BACKEND_PASSWORD=
CONFIGURATION_SERVICE_BACKEND_TABLE_NAME=

# SECTION E - SOFTWARE HOME
OGG_SOFTWARE_HOME=/u01/app/oracle/product/ogg23ai

# SECTION F - DEPLOYMENT DIRECTORIES
OGG_DEPLOYMENT_HOME=/u01/app/oracle/product/ogg_test_01
OGG_ETC_HOME=/u01/app/oracle/product/ogg_test_01/etc
OGG_CONF_HOME=/u01/app/oracle/product/ogg_test_01/etc/conf
OGG_SSL_HOME=/u01/app/oracle/product/ogg_test_01/etc/ssl
OGG_VAR_HOME=/u01/app/oracle/product/ogg_test_01/var
OGG_DATA_HOME=/u01/app/oracle/product/ogg_test_01/var/lib/data
OGG_ARCHIVE_HOME=/u01/app/oracle/product/ogg_test_01/var/lib/archive

# SECTION G - ENVIRONMENT VARIABLES
ENV_LD_LIBRARY_PATH=${OGG_HOME}/lib/instantclient:${OGG_HOME}/lib
ENV_TNS_ADMIN=/u01/app/oracle/network/admin
ENV_STREAMS_POOL_SIZE=
ENV_USER_VARS=

# SECTION H - SECURITY
TLS_1_2_ENABLED=false
TLS_1_3_ENABLED=true
FIPS_ENABLED=false
SERVER_CERTIFICATE=
SERVER_CERTIFICATE_KEY_FILE=
SERVER_CA_CERTIFICATES_FILE=
CLIENT_CERTIFICATE=
CLIENT_CERTIFICATE_KEY_FILE=
CLIENT_CA_CERTIFICATES_FILE=

# SECTION I - SERVICES
ADMINISTRATION_SERVER_ENABLED=true
PORT_ADMINSRVR=7810
DISTRIBUTION_SERVER_ENABLED=true
PORT_DISTSRVR=7811
NON_SECURE_DISTSRVR_CONNECTS_TO_SECURE_RCVRSRVR=false
RECEIVER_SERVER_ENABLED=true
PORT_RCVRSRVR=7812
METRICS_SERVER_ENABLED=true
METRICS_SERVER_IS_CRITICAL=false
PORT_PMSRVR=7813
PMSRVR_DATASTORE_TYPE=BDB
PMSRVR_DATASTORE_HOME=
ENABLE_DEPLOYMENT_REMOTE_METRICS=false
DEPLOYMENT_REMOTE_METRICS_LISTENING_HOST=
DEPLOYMENT_REMOTE_METRICS_LISTENING_PORT=0

# SECTION J - REPLICATION OPTIONS
OGG_SCHEMA=OGGADMIN

# SECTION K - REMOVE DEPLOYMENT OPTIONS
REMOVE_DEPLOYMENT_FROM_DISK=</code></pre>



<p class="wp-block-paragraph">Full file :</p>



<pre class="wp-block-code"><code>################################################################################
## Copyright(c) Oracle Corporation 2016, 2024. All rights reserved.           ##
##                                                                            ##
## Specify values for the variables listed below to customize your            ##
## installation.                                                              ##
##                                                                            ##
## Each variable is associated with a comment. The comments can help to       ##
## populate the variables with the appropriate values.                        ##
##                                                                            ##
## IMPORTANT NOTE: This file should be secured to have read permission only   ##
## by the Oracle user or an administrator who owns this configuration to      ##
## protect any sensitive input values.                                        ##
##                                                                            ##
################################################################################

#-------------------------------------------------------------------------------
# Do not change the following system generated value. 
#-------------------------------------------------------------------------------
oracle.install.responseFileVersion=/oracle/install/rspfmt_oggca_response_schema_v23_1_0


################################################################################
##                                                                            ##
## Oracle GoldenGate deployment configuration options and details             ##
##                                                                            ##
################################################################################

################################################################################
##                                                                            ##
## Instructions to fill out this response file                                ##
## -------------------------------------------                                ##
## Fill out section A, B, and C for general deployment information            ##
## Additionally:                                                              ##  
## Fill out sections D, E, F, G, H, I, and J for adding a deployment          ##
## Fill out section K for removing a deployment                               ##
##                                                                            ##
################################################################################

################################################################################
#                                                                              #
#                          SECTION A - GENERAL                                 #
#                                                                              #
################################################################################

#-------------------------------------------------------------------------------
# Specify the configuration option.
# Specify: 
# - ADD    : for adding a new GoldenGate deployment.
# - REMOVE : for removing an existing GoldenGate deployment. 
#-------------------------------------------------------------------------------
CONFIGURATION_OPTION=ADD

#-------------------------------------------------------------------------------
# Specify the name for the new or existing deployment.
#-------------------------------------------------------------------------------
DEPLOYMENT_NAME=ogg_test_01


################################################################################
#                                                                              #
#                       SECTION B - ADMINISTRATOR ACCOUNT                      #
#                                                                              #
# * If creating a new Service Manager, set the Administrator Account username  #
#   and password.                                                              #
#                                                                              #
# * If reusing an existing Service Manager:                                    #
#     * Enter the credentials for the Administrator Account in                 #
#       the existing Service Manager.                                          #
#                                                                              #
################################################################################

#-------------------------------------------------------------------------------
# Specify the administrator account username for the Service Manager.
#-------------------------------------------------------------------------------
ADMINISTRATOR_USER=ogg

#-------------------------------------------------------------------------------
# Specify the administrator account password for the Service Manager.
#-------------------------------------------------------------------------------
ADMINISTRATOR_PASSWORD=ogg_password

#-------------------------------------------------------------------------------
# Optionally, specify a different administrator account username for the deployment,
# or leave blanks to use the same Service Manager administrator credentials.
#-------------------------------------------------------------------------------
DEPLOYMENT_ADMINISTRATOR_USER=ogg

#-------------------------------------------------------------------------------
# If creating a different administrator account username for the deployment, 
# specify the password for it.
#-------------------------------------------------------------------------------
DEPLOYMENT_ADMINISTRATOR_PASSWORD=ogg_password


################################################################################
#                                                                              #
#                       SECTION C - SERVICE MANAGER                            #
#                                                                              #
################################################################################

#-------------------------------------------------------------------------------
# Specify the location for the Service Manager deployment.
# This is only needed if the Service Manager deployment doesn't exist already.
#-------------------------------------------------------------------------------
SERVICEMANAGER_DEPLOYMENT_HOME=/u01/app/oracle/product/ogg23ai_SM

#-------------------------------------------------------------------------------
# Optionally, specify a custom location for the Service Manager deployment ETC_HOME.
#-------------------------------------------------------------------------------
SERVICEMANAGER_ETC_HOME=/u01/app/oracle/product/ogg23ai_SM/etc

#-------------------------------------------------------------------------------
# Optionally, specify a custom location for the Service Manager deployment CONF_HOME.
#-------------------------------------------------------------------------------
SERVICEMANAGER_CONF_HOME=/u01/app/oracle/product/ogg23ai_SM/etc/conf

#-------------------------------------------------------------------------------
# Optionally, specify a custom location for the Service Manager deployment SSL_HOME.
#-------------------------------------------------------------------------------
SERVICEMANAGER_SSL_HOME=/u01/app/oracle/product/ogg23ai_SM/etc/ssl

#-------------------------------------------------------------------------------
# Optionally, specify a custom location for the Service Manager deployment VAR_HOME.
#-------------------------------------------------------------------------------
SERVICEMANAGER_VAR_HOME=/u01/app/oracle/product/ogg23ai_SM/var

#-------------------------------------------------------------------------------
# Optionally, specify a custom location for the Service Manager deployment DATA_HOME.
#-------------------------------------------------------------------------------
SERVICEMANAGER_DATA_HOME=/u01/app/oracle/product/ogg23ai_SM/var/lib/data

#-------------------------------------------------------------------------------
# Optionally, specify a custom location for the Service Manager deployment ARCHIVE_HOME.
#-------------------------------------------------------------------------------
SERVICEMANAGER_ARCHIVE_HOME=/u01/app/oracle/product/ogg23ai_SM/var/lib/archive

#-------------------------------------------------------------------------------
# Specify the host for the Service Manager.
#-------------------------------------------------------------------------------
HOST_SERVICEMANAGER=your_host

#-------------------------------------------------------------------------------
# Specify the port for the Service Manager.
#-------------------------------------------------------------------------------
PORT_SERVICEMANAGER=7809

#-------------------------------------------------------------------------------
# Specify if SSL / TLS is or will be enabled for the deployment.
# Specify true if SSL / TLS is or will be enabled, false otherwise.
#-------------------------------------------------------------------------------
SECURITY_ENABLED=false

#-------------------------------------------------------------------------------
# Specify if the deployment should enforce a strong password policy.
# Specify true to enable strong password policy management.
#-------------------------------------------------------------------------------
STRONG_PWD_POLICY_ENABLED=false

#-------------------------------------------------------------------------------
# Specify if a new Service Manager should be created. 
# Specify true if a new Service Manager should be created, false otherwise.
#
# This option is only needed when CONFIGURATION_OPTION is ADD.
#-------------------------------------------------------------------------------
CREATE_NEW_SERVICEMANAGER=true

#-------------------------------------------------------------------------------
# Specify if Service Manager should be registered as a service/daemon. This option is mutually exclusive with the 'INTEGRATE_SERVICEMANAGER_WITH_XAG' option.
# Specify true if Service Manager should be registered as a service, false otherwise.
#
# This option is only needed when CONFIGURATION_OPTION is ADD.
# This option does not apply to Windows platform.
#-------------------------------------------------------------------------------
REGISTER_SERVICEMANAGER_AS_A_SERVICE=true
#-------------------------------------------------------------------------------
# Specify if Service Manager should be integrated with XAG. This option is mutually exclusive with the 'REGISTER_SERVICEMANAGER_AS_A_SERVICE' option.
# Specify true if Service Manager should be integrated with XAG, false otherwise.
#
# This option is only needed when CONFIGURATION_OPTION is ADD.
# This option is only supported for Oracle databases.
#-------------------------------------------------------------------------------
INTEGRATE_SERVICEMANAGER_WITH_XAG=false

#-------------------------------------------------------------------------------
# If using an existing Service Manager, specify if it is integrated with XAG.
# Specify true if the existing Service Manager is integrated with XAG, false otherwise.
#
# This option is only needed when CONFIGURATION_OPTION is ADD.
# This option is only supported for Oracle databases.
#-------------------------------------------------------------------------------
EXISTING_SERVICEMANAGER_IS_XAG_ENABLED=false

#-------------------------------------------------------------------------------
# Specify if Remote Metrics using StatsD protocol will be enabled for the Service Manager
# Specify true if Remote Metrics for the Service Manager will be enabled, false otherwise
#-------------------------------------------------------------------------------
ENABLE_SERVICE_MANAGER_REMOTE_METRICS=false

#-------------------------------------------------------------------------------
# If Remote Metrics for the Service Manager will be enabled, specify the listening host
#-------------------------------------------------------------------------------
SERVICE_MANAGER_REMOTE_METRICS_LISTENING_HOST=

#-------------------------------------------------------------------------------
# If Remote Metrics for the Service Manager will be enabled, specify the listening port for that server
#-------------------------------------------------------------------------------
SERVICE_MANAGER_REMOTE_METRICS_LISTENING_PORT=0

#-------------------------------------------------------------------------------
# Specify if the Plugin Service for the Service Manager will be enabled.
# Specify true if the Plugin Service will be enabled, false otherwise.
#-------------------------------------------------------------------------------
PLUGIN_SERVICE_ENABLED=false
###############################################################################
#                                                                             #  
#                    SECTION D - CONFIGURATION SERVICE                        #
#                                                                             #
###############################################################################

#-------------------------------------------------------------------------------
# Specify if the Configuration Service will be enabled.
# Specify true if the Configuration Service will be enabled, false otherwise.
#-------------------------------------------------------------------------------
CONFIGURATION_SERVICE_ENABLED=false

#-------------------------------------------------------------------------------
# Specify the Configuration Service backend type.
# Specify:
# - FILESYSTEM
# - ORACLE_DATABASE
#
# This is only needed if the Configuration Service will be enabled
#-------------------------------------------------------------------------------
CONFIGURATION_SERVICE_BACKEND_TYPE=FILESYSTEM

#-------------------------------------------------------------------------------
# Specify the Configuration Service connection string for the database backend
#
# This is only needed if:
#     * The Configuration Service will be enabled
#     * CONFIGURATION_SERVICE_BACKEND_TYPE is ORACLE_DATABASE
#-------------------------------------------------------------------------------
CONFIGURATION_SERVICE_BACKEND_CONNECTION_STRING=

#-------------------------------------------------------------------------------
# Specify the Configuration Service username for the database backend
#
# This is only needed if: 
#     * The Configuration Service will be enabled
#     * CONFIGURATION_SERVICE_BACKEND_TYPE is ORACLE_DATABASE
#-------------------------------------------------------------------------------
CONFIGURATION_SERVICE_BACKEND_USERNAME=

#-------------------------------------------------------------------------------
# Specify the Configuration Service password for the database backend
#
# This is only needed if: 
#     * The Configuration Service will be enabled
#     * CONFIGURATION_SERVICE_BACKEND_TYPE is ORACLE_DATABASE
#-------------------------------------------------------------------------------
CONFIGURATION_SERVICE_BACKEND_PASSWORD=

#-------------------------------------------------------------------------------
# Specify the Configuration Service table name for the database backend
#
# This is only needed if: 
#     * The Configuration Service will be enabled
#     * CONFIGURATION_SERVICE_BACKEND_TYPE is ORACLE_DATABASE
#-------------------------------------------------------------------------------
CONFIGURATION_SERVICE_BACKEND_TABLE_NAME=
###############################################################################
#                                                                             #
#                       SECTION E - SOFTWARE HOME                             #
#                                                                             #
###############################################################################

#-------------------------------------------------------------------------------
# Specify the existing OGG software home location.
#-------------------------------------------------------------------------------
OGG_SOFTWARE_HOME=/u01/app/oracle/product/OGG_23.9.0.25.07


###############################################################################
#                                                                             #
#                       SECTION F - DEPLOYMENT DIRECTORIES                    #
#                                                                             #
###############################################################################

#-------------------------------------------------------------------------------
# Specify the location of the new or existing OGG deployment.
#-------------------------------------------------------------------------------
OGG_DEPLOYMENT_HOME=/u01/app/oracle/product/ogg_test_01

#-------------------------------------------------------------------------------
# Specify the location for OGG_ETC_HOME.
#-------------------------------------------------------------------------------
OGG_ETC_HOME=/u01/app/oracle/product/ogg_test_01/etc

#-------------------------------------------------------------------------------
# Specify the location for OGG_CONF_HOME.
#-------------------------------------------------------------------------------
OGG_CONF_HOME=/u01/app/oracle/product/ogg_test_01/etc/conf

#-------------------------------------------------------------------------------
# Specify the location for OGG_SSL_HOME.
#-------------------------------------------------------------------------------
OGG_SSL_HOME=/u01/app/oracle/product/ogg_test_01/etc/ssl

#-------------------------------------------------------------------------------
# Specify the location for OGG_VAR_HOME.
#-------------------------------------------------------------------------------
OGG_VAR_HOME=/u01/app/oracle/product/ogg_test_01/var

#-------------------------------------------------------------------------------
# Specify the location for OGG_DATA_HOME.
#-------------------------------------------------------------------------------
OGG_DATA_HOME=/u01/app/oracle/product/ogg_test_01/var/lib/data

#-------------------------------------------------------------------------------
# Specify the location for OGG_ARCHIVE_HOME.
#-------------------------------------------------------------------------------
OGG_ARCHIVE_HOME=/u01/app/oracle/product/ogg_test_01/var/lib/archive

###############################################################################
#                                                                             #
#                       SECTION G - ENVIRONMENT VARIABLES                     #
#                                                                             #
###############################################################################

#-------------------------------------------------------------------------------
# Specify the value for the LD_LIBRARY_PATH environment variable.
#-------------------------------------------------------------------------------
ENV_LD_LIBRARY_PATH=${OGG_HOME}/lib/instantclient:${OGG_HOME}/lib

#-------------------------------------------------------------------------------
# Specify the value for the TNS_ADMIN environment variable.
# This environment variable is only for Oracle Databases.
#-------------------------------------------------------------------------------
ENV_TNS_ADMIN=/u01/app/oracle/network/admin

#-------------------------------------------------------------------------------
# This option is only needed when Sharding will be enabled.
# Specify the value for the STREAMS_POOL_SIZE environment variable.
# This environment variable is only for Oracle Databases.
#-------------------------------------------------------------------------------
ENV_STREAMS_POOL_SIZE=

#-------------------------------------------------------------------------------
# Specify any additional environment variables to be set in the deployment.
#-------------------------------------------------------------------------------
ENV_USER_VARS=


###############################################################################
#                                                                             #
#                           SECTION H - SECURITY                              #
#           This section is only needed if Security will be enabled           #
#                                                                             #
###############################################################################

# ------------------------------------------------------------------------------
# If security will be enabled, specify if TLS v1.2 will be enabled.
# Specify true if TLS v1.2 will be enabled, false otherwise.
#-------------------------------------------------------------------------------
TLS_1_2_ENABLED=false

# ------------------------------------------------------------------------------
# If security will be enabled, specify if TLS v1.3 will be enabled. 
# Specify true if TLS v1.3 will be enabled, false otherwise.
#-------------------------------------------------------------------------------
TLS_1_3_ENABLED=true

#-------------------------------------------------------------------------------
# Specify if FIPS will be enabled.
#-------------------------------------------------------------------------------
FIPS_ENABLED=false

#-------------------------------------------------------------------------------
# If SSL / TLS will be enabled, specify the server certificate 
#-------------------------------------------------------------------------------
SERVER_CERTIFICATE=

#-------------------------------------------------------------------------------
# If importing a server certificate, specify the private key file in PKCS#8 format
# The private key file must not be encrypted
#-------------------------------------------------------------------------------
SERVER_CERTIFICATE_KEY_FILE=

#-------------------------------------------------------------------------------
# If importing a server certificate, optionally specify the CA certificates file
#-------------------------------------------------------------------------------
SERVER_CA_CERTIFICATES_FILE=

#-------------------------------------------------------------------------------
# If SSL / TLS will be enabled, optionally specify the client certificate.
#-------------------------------------------------------------------------------
CLIENT_CERTIFICATE=

#-------------------------------------------------------------------------------
# If importing a client certificate, specify the private key file in PKCS#8 format
# The private key file must not be encrypted
#-------------------------------------------------------------------------------
CLIENT_CERTIFICATE_KEY_FILE=

#-------------------------------------------------------------------------------
# If importing a client certificate, optionally specify the CA certificates file
#-------------------------------------------------------------------------------
CLIENT_CA_CERTIFICATES_FILE=


###############################################################################
#                                                                             #
#                           SECTION I - SERVICES                              #
#                                                                             #
###############################################################################

#-------------------------------------------------------------------------------
# Specify if the Administration server will be enabled.
# Specify true if the Administration server will be enabled, false otherwise.
#-------------------------------------------------------------------------------
ADMINISTRATION_SERVER_ENABLED=true

#-------------------------------------------------------------------------------
# Required only if the Administration server will be enabled. 
# Specify the port for Administration Server.
#-------------------------------------------------------------------------------
PORT_ADMINSRVR=7810

#-------------------------------------------------------------------------------
# Specify if the Distribution server will be enabled.
# Specify true if the Distribution server will be enabled, false otherwise.
#-------------------------------------------------------------------------------
DISTRIBUTION_SERVER_ENABLED=true

#-------------------------------------------------------------------------------
# Required only if the Distribution server will be enabled. 
# Specify the port for Distribution Server.
#-------------------------------------------------------------------------------
PORT_DISTSRVR=7811

#-------------------------------------------------------------------------------
# If security is disabled, specify if this non-secure deployment will be used
# to send trail data to a secure deployment.
#-------------------------------------------------------------------------------
NON_SECURE_DISTSRVR_CONNECTS_TO_SECURE_RCVRSRVR=false

#-------------------------------------------------------------------------------
# Specify if the Receiver server will be enabled.
# Specify true if the Receiver server will be enabled, false otherwise.
#-------------------------------------------------------------------------------
RECEIVER_SERVER_ENABLED=true

#-------------------------------------------------------------------------------
# Required only if the Receiver server will be enabled. 
# Specify the port for Receiver Server.
#-------------------------------------------------------------------------------
PORT_RCVRSRVR=7812

#-------------------------------------------------------------------------------
# Specify if Performance Metrics server will be enabled.
# Specify true if Performance Metrics server will be enabled, false otherwise.
#-------------------------------------------------------------------------------
METRICS_SERVER_ENABLED=true
#-------------------------------------------------------------------------------
# Specify if Performance Metrics server is a critical service.
# Specify true if Performance Metrics server is a critical service, false otherwise.
#
# This is optional and only takes effect when Performance Metrics server will be enabled.
# Also, this option should only be set when the Service Manager is integrated with XAG.
# The default value is false.
#
# This option is only supported for Oracle databases.
#-------------------------------------------------------------------------------
METRICS_SERVER_IS_CRITICAL=false

#-------------------------------------------------------------------------------
# Specify the port for Performance Metrics server (TCP).
#
# This option is only needed when Performance Metrics server will be enabled.
#-------------------------------------------------------------------------------
PORT_PMSRVR=7813

#-------------------------------------------------------------------------------
# Specify the DataStore type for Performance Metrics server.
# Valid values are: BDB, LMDB
#
# This option is only needed when Performance Metrics server will be enabled.
#-------------------------------------------------------------------------------
PMSRVR_DATASTORE_TYPE=BDB

#-------------------------------------------------------------------------------
# Specify the DataStore home location for Performance Metrics server.
# This is optional and only takes effect when Performance Metrics server will be enabled.
#-------------------------------------------------------------------------------
PMSRVR_DATASTORE_HOME=

#-------------------------------------------------------------------------------
# Specify if Remote Metrics using StatsD protocol will be enabled for the Deployment
# Specify true if Remote Metrics for the deployment will be enabled, false otherwise
#-------------------------------------------------------------------------------
ENABLE_DEPLOYMENT_REMOTE_METRICS=false

#-------------------------------------------------------------------------------
# If Remote Metrics for the deployment will be enabled, specify the listening host
#-------------------------------------------------------------------------------
DEPLOYMENT_REMOTE_METRICS_LISTENING_HOST=

#-------------------------------------------------------------------------------
# If Remote Metrics for the deployment will be enabled, specify the listening port for that server
#-------------------------------------------------------------------------------
DEPLOYMENT_REMOTE_METRICS_LISTENING_PORT=0


###############################################################################
#                                                                             #
#                       SECTION J - REPLICATION OPTIONS                       #
#                                                                             #
###############################################################################

#-------------------------------------------------------------------------------
# Specify the value for the GoldenGate schema.
#-------------------------------------------------------------------------------
OGG_SCHEMA=OGGADMIN


###############################################################################
#                                                                             #
#                  SECTION K - REMOVE DEPLOYMENT OPTIONS                      #
#                                                                             #
###############################################################################

#-------------------------------------------------------------------------------
# Specify if the deployment files should be removed from disk.
# Specify true if the deployment files should be removed, false otherwise.
#-------------------------------------------------------------------------------
REMOVE_DEPLOYMENT_FROM_DISK=</code></pre>
<p>L’article <a href="https://www.dbi-services.com/blog/goldengate-23ai-installation-graphic-and-silent-mode-comparison-for-automation/">GoldenGate 26ai Installation: Graphic and Silent Mode Comparison for Automation</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/goldengate-23ai-installation-graphic-and-silent-mode-comparison-for-automation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Oracle FMW 14 Installation &#8211; ORA-00439: feature not enabled: Fine-grained access control</title>
		<link>https://www.dbi-services.com/blog/oracle-fmw-14-installation-ora-00439-feature-not-enabled-fine-grained-access-control/</link>
					<comments>https://www.dbi-services.com/blog/oracle-fmw-14-installation-ora-00439-feature-not-enabled-fine-grained-access-control/#respond</comments>
		
		<dc:creator><![CDATA[David Diab]]></dc:creator>
		<pubDate>Tue, 23 Sep 2025 21:29:47 +0000</pubDate>
				<category><![CDATA[Application integration & Middleware]]></category>
		<category><![CDATA[WebLogic]]></category>
		<category><![CDATA[Fusion Middleware]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[Oracle]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=39382</guid>

					<description><![CDATA[<p>This short blog is to share with you an issue we faced at a customer during Oracle Fusion Middleware 14 installation. Introduction and Symptoms An important step in the installation process is the Oracle Fusion Middleware Metadata repository creation using the RCU (Repository Creation Utility) which creates the necessary schemas for the components. But when [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/oracle-fmw-14-installation-ora-00439-feature-not-enabled-fine-grained-access-control/">Oracle FMW 14 Installation &#8211; ORA-00439: feature not enabled: Fine-grained access control</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This short blog is to share with you an issue we faced at a customer during Oracle Fusion Middleware 14 installation.</p>



<span id="more-39382"></span>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="701" height="401" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/1520187287514.jpg" alt="" class="wp-image-40316" style="width:573px;height:auto" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/1520187287514.jpg 701w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/09/1520187287514-300x172.jpg 300w" sizes="auto, (max-width: 701px) 100vw, 701px" /></figure>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading" id="h-introduction-and-symptoms">Introduction and Symptoms</h2>



<p class="wp-block-paragraph">An important step in the installation process is the Oracle Fusion Middleware Metadata repository creation using the RCU (Repository Creation Utility) which creates the necessary schemas for the components.</p>



<p class="wp-block-paragraph"> But when running the Repository Creation Utility (RCU) to load schemas on Oracle Database, schema creation fails with the below errors:</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="635" height="499" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-8.png" alt="" class="wp-image-39385" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-8.png 635w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-8-300x236.png 300w" sizes="auto, (max-width: 635px) 100vw, 635px" /></figure>



<p class="wp-block-paragraph">In fact, the problem is seen as RCU tries to set up VPD stripes. In another world, RCU relies on fine-grained access control (FGAC) to manage schema creation and access within the Oracle database. </p>



<p class="wp-block-paragraph">The ORA-00439 error &#8220;feature not enabled: Fine-grained access control&#8221; in Oracle RCU (Repository Creation Utility) indicates that the database being used for RCU schema creation does not have the <strong>fine-grained access control feature enabled</strong>. This feature is only part of the <strong>Enterprise Edition</strong> of Oracle Database and is not available in Standard Edition!</p>



<p class="wp-block-paragraph">Let&#8217;s check <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="538" height="191" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-7.png" alt="" class="wp-image-39384" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-7.png 538w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-7-300x107.png 300w" sizes="auto, (max-width: 538px) 100vw, 538px" /></figure>



<p class="wp-block-paragraph">So, no way to do it with Standard Edition? No worries, there is a solution <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



<h2 class="wp-block-heading" id="h-solution">Solution</h2>



<p class="wp-block-paragraph">Oracle here is a patch to workaround this issue, so the steps will be:</p>



<ul class="wp-block-list">
<li>Download the patch</li>



<li>Apply the patch</li>



<li>Run the RCU to load the schemas</li>



<li>Continue with Domain configuration</li>
</ul>



<p class="wp-block-paragraph"><strong>Download the patch</strong></p>



<p class="wp-block-paragraph">Go to <a href="https://support.oracle.com/epmos/faces/ui/patch/PatchDetail.jspx?parent=DOCUMENT&amp;sourceId=3083393.1&amp;patchId=37506854" target="_blank" rel="noreferrer noopener">Patch 37506854</a> and download it, then move it to your working folder on the server.</p>



<p class="wp-block-paragraph"><strong>Apply the patch</strong></p>



<p class="wp-block-paragraph">Nothing really special here, apply the patch as any patch <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



<p class="wp-block-paragraph">Unzip the patch downloaded, go inside the folder 37506854, and apply the patch:</p>



<pre class="wp-block-code"><code>&#091;oracle@fmwserver working]$ cd 37506854
&#091;oracle@fmwserver 37506854]$ opatch apply
Oracle Interim Patch Installer version 13.9.4.2.17
Copyright (c) 2025, Oracle Corporation.  All rights reserved.


Oracle Home       : /u01/app/oracle/product/midw
Central Inventory : /u01/app/oracle/oraInventory
   from           : /u01/app/oracle/product/midw//oraInst.loc
OPatch version    : 13.9.4.2.17
OUI version       : 13.9.4.0.0
Log file location : /u01/app/oracle/product/midw/cfgtoollogs/opatch/opatch2025-07-10_11-22-38AM_1.log


OPatch detects the Middleware Home as "/u01/app/oracle/product/midw"

Verifying environment and performing prerequisite checks...
OPatch continues with these patches:   37506854

Do you want to proceed? &#091;y|n]
y
User Responded with: Y
All checks passed.

Please shutdown Oracle instances running out of this ORACLE_HOME on the local system.
(Oracle Home = '/u01/app/oracle/product/midw')


Is the local system ready for patching? &#091;y|n]
y
User Responded with: Y
Backing up files...
Applying interim patch '37506854' to OH '/u01/app/oracle/product/midw'

Patching component oracle.rcu.mds, 14.1.2.0.0...

Patching component oracle.rcu.mds, 14.1.2.0.0...
Patch 37506854 successfully applied.
Log file location: /u01/app/oracle/product/midw/cfgtoollogs/opatch/opatch2025-07-10_11-22-38AM_1.log

OPatch succeeded.</code></pre>



<p class="wp-block-paragraph"><strong>Retry the failed step</strong></p>



<p class="wp-block-paragraph">Now, the RCU should work fine and the domain creation could be done without issue.</p>



<p class="wp-block-paragraph">Have a look on all FMW <a href="https://www.dbi-services.com/blog/tag/oracle-fusion-middleware/" target="_blank" rel="noreferrer noopener">blogs</a>, more blogs to come about FMW 14 to highlight new features!</p>



<p class="wp-block-paragraph">If you have any questions don&#8217;t hesitate, please ask <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



<p class="wp-block-paragraph">Happy to share,</p>



<p class="wp-block-paragraph">David<br></p>
<p>L’article <a href="https://www.dbi-services.com/blog/oracle-fmw-14-installation-ora-00439-feature-not-enabled-fine-grained-access-control/">Oracle FMW 14 Installation &#8211; ORA-00439: feature not enabled: Fine-grained access control</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/oracle-fmw-14-installation-ora-00439-feature-not-enabled-fine-grained-access-control/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Automatisation for Oracle ZDM installation and update</title>
		<link>https://www.dbi-services.com/blog/automatisation-for-oracle-zdm-installation-and-update/</link>
					<comments>https://www.dbi-services.com/blog/automatisation-for-oracle-zdm-installation-and-update/#respond</comments>
		
		<dc:creator><![CDATA[Marc Wagner]]></dc:creator>
		<pubDate>Thu, 31 Jul 2025 06:31:15 +0000</pubDate>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[zdm]]></category>
		<category><![CDATA[zero downtime migration]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=39773</guid>

					<description><![CDATA[<p>Let&#8217;s have a look how we can install and update Oracle Zero Downtime Migration tool, and see how we can automatise it with ansible&#8230; Check ZDM build Let&#8217;s first see how we can check ZDM version using zdm cli. [zdm@zdmhost ~]$ zdmcli -v RHP_PT.ZDM21_LINUX.X64_221207.30 [zdm@zdmhost ~]$ zdmcli -build version: 21.0.0.0.0 full version: 21.4.0.0.0 patch version: [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/automatisation-for-oracle-zdm-installation-and-update/">Automatisation for Oracle ZDM installation and update</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Let&#8217;s have a look how we can install and update Oracle Zero Downtime Migration tool, and see how we can automatise it with ansible&#8230;</p>



<span id="more-39773"></span>



<h3>Check ZDM build</h3>



<p class="wp-block-paragraph">Let&#8217;s first see how we can check ZDM version using zdm cli.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: [1,4]">
[zdm@zdmhost ~]$ zdmcli -v
RHP_PT.ZDM21_LINUX.X64_221207.30

[zdm@zdmhost ~]$ zdmcli -build
version: 21.0.0.0.0
full version: 21.4.0.0.0
patch version: 21.4.5.0.0
label date: 221207.30
ZDM kit build date: Mar 21 2024 22:07:12 UTC
CPAT build version: 24.6.0
[exauser@sva-oelexa501 ~]$
</pre>
</br>



<p class="wp-block-paragraph">Version installed is 21.4, and we would see how to update it to last current version, which is 21.5.</p>



<h3>Manuel installation and update</h3>



<p class="wp-block-paragraph">Manuel installation and update is quite easy as it will be done through the <code>zdminstall.sh</code> script. It will be the option that will highlight if it is a first installation or an update. For a first installation, the option will be <code>setup</code> and for an update it will be <code>update</code>.</p>



<h3>Automatisation of the installation and update of ZDM</h3>



<p class="wp-block-paragraph">The playbook to automatise the installation and the update, in my case named <code>deploy_zdm.yml</code>, is composed of following tasks.</p>



<p class="wp-block-paragraph">We start by defining the playbook and the variable that will be used in the included tasks to install or update to zdm current last version, which is 21.5. The zip file to unarchive will be stored in the <code>../oracle_swfiles</code> directory.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: []">
---
# Playbook for deploying ZDM host
# Marc Wagner - dbi
# Date : 06.10.2023
# 11.06.2025 : stop service + new 21.5 version
- name: Deploy ZDM
  hosts: "zdmhost"
  vars:
    sfw_folder: "../oracle_swfiles"


    zdm_base: "/u01/app/oracle"
    zdm_install_dir: "zdm21.5"
    zdm_download_dir: "/u01/app/zdm_download_dir"
    zdm_archive: "{{ sfw_folder }}/V1045330-01.zip"

    # ZDM update is an in-place process
    zdm_home: "/u01/app/oracle/product/zdm"
  environment:
    HTTP_PROXY: ""
    HTTPS_PROXY: ""

  tasks:

</pre>
</br>



<p class="wp-block-paragraph">Then we will have all the tasks performing the installation.</p>



<p class="wp-block-paragraph">The first one will be used to define the variable for the option provided as extra argument of the ansible playbook. And we will assert that the variable is provided.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: []">
- name: Assert extra-var has been passed as argument to playbook
  ansible.builtin.assert:
    that:
      - deploy_option is defined
    quiet: false
    fail_msg: "Please provide --extra-var deploy_option="
    success_msg: "deploy_option={{ deploy_option }}"
</pre>
</br>



<p class="wp-block-paragraph">The next task will stop ZDM service and will only run if following file exists : <code>/u01/app/oracle/product/zdm/bin/zdmservice</code>.</p>



<p class="wp-block-paragraph">This check is done so the task will only run if ZDM tool is already installed.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: []">
- name: Stop ZDM service
  ansible.builtin.shell: |
    cmd: |
    {{ zdm_home }}/bin/zdmservice stop
  args:
    executable: "/bin/bash"
    removes: "/u01/app/oracle/product/zdm/bin/zdmservice"
</pre>
</br>



<p class="wp-block-paragraph">The next task will install some prerequisite if not already installed.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: []">
- name: Install ZDM software prerequisites
  become: true
  become_user: root
  ansible.builtin.dnf:
    name: "{{ item }}"
  loop:
    - perl
    - expect
    - libaio
    - glibc-devel
    - unzip
    - libnsl
    - ncurses-compat-libs
    - oraclelinux-developer-release-el8
</pre>
</br>



<p class="wp-block-paragraph">The next task will create all needed directories like zdm base, zdm home and the file used to store the installation archive file.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: []">
- name: Create directories for ZDM tool
  become: true
  become_user: root
  ansible.builtin.file:
    path: "{{ item }}"
    state: directory
    owner: exauser
    group: exauser
    mode: '755'
  loop:
    - "{{ zdm_base }}"
    - "{{ zdm_home }}"
    - "{{ zdm_download_dir }}"
</pre>
</br>



<p class="wp-block-paragraph">The next task will unarchive the installation zip file.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: []">
- name: Unarchive ZDM
  ansible.builtin.unarchive:
    src: "{{ zdm_archive }}"
    dest: "{{ zdm_download_dir }}"
</pre>
</br>




<p class="wp-block-paragraph">And the next task will finally installed or update zdm tool according to the option given to the playbook.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: []">
- name: Install or update ZDM
  ansible.builtin.shell:
    cmd: |
      {{ zdm_download_dir }}/{{ zdm_install_dir }}/zdminstall.sh \
        {{ deploy_option }} oraclehome={{ zdm_home }} oraclebase={{ zdm_base }} \
        ziploc={{ zdm_download_dir }}/{{ zdm_install_dir }}/zdm_home.zip -zdm
  args:
    executable: "/bin/bash"
</pre>
</br>



<p class="wp-block-paragraph">And we can finally with the last steps start ZDM service.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: []">
- name: Start ZDM service
  ansible.builtin.shell: |
    cmd: |
    {{ zdm_home }}/bin/zdmservice start
  args:
    executable: "/bin/bash"
</pre>
</br>



<h3>Run the playbook</h3>



<p class="wp-block-paragraph">As prerequisite, let&#8217;s first check that the appropriate ZDM installation zip file is in the expected ansible folder.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: [1]">
[myuser@domain.com@admin-host zdm_ansible]$ ls -ltrh ./oracle_swfiles/
total 874M
-rw-r--r--. 1 myuser@domain.com myuser@domain.com 871M Jun 11 10:12 V1045330-01.zip
[myuser@domain.com@admin-host zdm_ansible]$
</pre>
</br>



<p class="wp-block-paragraph">We can check that the assert task to ensure we put the appropriate &#8211;extra-vars works.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: [1]">
[myuser@domain.com@admin-host zdm_ansible]$ ansible-playbook ./playbooks/deploy_zdm.yml

PLAY [Deploy ZDM] ***********************************************************************************************************************************************************************************************************************************************************************

TASK [Gathering Facts] ******************************************************************************************************************************************************************************************************************************************************************
[WARNING]: Platform linux on host zdmhost is using the discovered Python interpreter at /usr/bin/python3, but future installation of another Python interpreter could change the meaning of that path. See https://docs.ansible.com/ansible-
core/2.15/reference_appendices/interpreter_discovery.html for more information.
ok: [zdmhost]

TASK [Assert extra-var has been passed as argument to playbook] *************************************************************************************************************************************************************************************************************************
fatal: [zdmhost]: FAILED! =&gt; {"msg": "The task includes an option with an undefined variable. The error was: 'deploy_option' is undefined. 'deploy_option' is undefined\n\nThe error appears to be in '/home/nfs/domain.com/myuser/ExaCCGit/zdm_ansible/playbooks/deploy_zdm.yml': line 25, column 7, but may\nbe elsewhere in the file depending on the exact syntax problem.\n\nThe offending line appears to be:\n\n\n    - name: Assert extra-var has been passed as argument to playbook\n      ^ here\n"}

PLAY RECAP ******************************************************************************************************************************************************************************************************************************************************************************
zdmhost              : ok=1    changed=0    unreachable=0    failed=1    skipped=0    rescued=0    ignored=0

[myuser@domain.com@admin-host zdm_ansible]$
</pre>
</br>



<p class="wp-block-paragraph">Then we can run the playbook with the update option.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: [1]">
[myuser@domain.com@admin-host zdm_ansible]$ ansible-playbook ./playbooks/deploy_zdm.yml -e deploy_option="update"

PLAY [Deploy ZDM] ***********************************************************************************************************************************************************************************************************************************************************************

TASK [Gathering Facts] ******************************************************************************************************************************************************************************************************************************************************************
[WARNING]: Platform linux on host zdmhost is using the discovered Python interpreter at /usr/bin/python3, but future installation of another Python interpreter could change the meaning of that path. See https://docs.ansible.com/ansible-
core/2.15/reference_appendices/interpreter_discovery.html for more information.
ok: [zdmhost]

TASK [Assert extra-var has been passed as argument to playbook] *************************************************************************************************************************************************************************************************************************
ok: [zdmhost] =&gt; {
    "changed": false,
    "msg": "deploy_option=update"
}

TASK [Stop ZDM service] *****************************************************************************************************************************************************************************************************************************************************************
changed: [zdmhost]

TASK [Install ZDM software prerequisites] ***********************************************************************************************************************************************************************************************************************************************
ok: [zdmhost] =&gt; (item=perl)
ok: [zdmhost] =&gt; (item=expect)
ok: [zdmhost] =&gt; (item=libaio)
ok: [zdmhost] =&gt; (item=glibc-devel)
ok: [zdmhost] =&gt; (item=unzip)
ok: [zdmhost] =&gt; (item=libnsl)
ok: [zdmhost] =&gt; (item=ncurses-compat-libs)
ok: [zdmhost] =&gt; (item=oraclelinux-developer-release-el8)

TASK [Create directories for ZDM tool] **************************************************************************************************************************************************************************************************************************************************
ok: [zdmhost] =&gt; (item=/u01/app/oracle)
ok: [zdmhost] =&gt; (item=/u01/app/oracle/product/zdm)
ok: [zdmhost] =&gt; (item=/u01/app/zdm_download_dir)

TASK [Unarchive ZDM] ********************************************************************************************************************************************************************************************************************************************************************
ok: [zdmhost]

TASK [Install or update ZDM] ************************************************************************************************************************************************************************************************************************************************************
changed: [zdmhost]

TASK [Start ZDM service] ****************************************************************************************************************************************************************************************************************************************************************
changed: [zdmhost]

PLAY RECAP ******************************************************************************************************************************************************************************************************************************************************************************
zdmhost              : ok=8    changed=3    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0
</pre>
</br>



<h3>Check new ZDM version</h3>



<p class="wp-block-paragraph">And we can check that the new ZDM tool version is 21.5.</p>



<pre class="brush: sql; gutter: true; first-line: 1; highlight: [1,4]">
[zdm@zdmhost ~]$ zdmcli -v
RHP_PT.ZDM21_LINUX.X64_240219.12

[zdm@zdmhost ~]$ zdmcli -build
version: 21.0.0.0.0
full version: 21.5.0.0.0
patch version: N/A
label date: 240219.12
ZDM kit build date: Sep 10 2024 21:59:18 UTC
CPAT build version: 24.6.0
[zdm@zdmhost ~]$
</pre>
</br>



<h3>To wrap up&#8230;</h3>



<p class="wp-block-paragraph">Installing and updating ZDM cli is quite easy, and writing an ansible playbook will help automatising the installation and further update.</p>
<p>L’article <a href="https://www.dbi-services.com/blog/automatisation-for-oracle-zdm-installation-and-update/">Automatisation for Oracle ZDM installation and update</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/automatisation-for-oracle-zdm-installation-and-update/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Easily build a kubernetes cluster with kubeadm</title>
		<link>https://www.dbi-services.com/blog/how-to-build-a-kubernetes-cluster-with-kubeadm/</link>
					<comments>https://www.dbi-services.com/blog/how-to-build-a-kubernetes-cluster-with-kubeadm/#respond</comments>
		
		<dc:creator><![CDATA[Middleware Team]]></dc:creator>
		<pubDate>Mon, 20 Mar 2023 07:00:00 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Cluster]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[kubernetes]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=21430</guid>

					<description><![CDATA[<p>In the upcoming blog posts, I will cover monitoring with Prometheus in a Kubernetes infrastructure. As I started blogging, I decided it would be useful to delve into the design of the k8s infrastructure. This will allow you to approach these blogs better if you wish to reproduce them. Therefore, I will start with the [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/how-to-build-a-kubernetes-cluster-with-kubeadm/">Easily build a kubernetes cluster with kubeadm</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In the upcoming blog posts, I will cover monitoring with Prometheus in a Kubernetes infrastructure. As I started blogging, I decided it would be useful to delve into the design of the k8s infrastructure. <br>This will allow you to approach these blogs better if you wish to reproduce them. </p>



<p class="wp-block-paragraph">Therefore, I will start with the basics and explain step by step how to build a Kubernetes cluster with kubeadm easily.<br>I suggest we start with a relatively simple, if not basic, installation with a cluster including a Master (Control Plane) and two worker nodes. To do this, I will use a Debian distribution, with a rather minimalist sizing with 2 CPUs and 4GB of RAM each.<br></p>



<h3 class="wp-block-heading">Install Packages</h3>



<p class="wp-block-paragraph">1. Login to your master server (Control Plane)</p>



<p class="wp-block-paragraph">2. Create a configuration file <em>containerd</em>, which will contain the necessary packages for the container runtime :</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
cat &lt;&lt;EOF | sudo tee /etc/modules-load.d/containerd.conf
overlay
br_netfilter
EOF
</pre></div>


<p class="wp-block-paragraph">3. Load the overlay and br_netfilter kernel modules:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo modprobe overlay
sudo modprobe br_netfilter
</pre></div>


<p class="wp-block-paragraph">4. Set system configurations for Kubernetes networking:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
cat &lt;&lt;EOF | sudo tee /etc/sysctl.d/k8s.conf 
net.bridge.bridge-nf-call-iptables = 1 
net.ipv4.ip_forward = 1 
net.bridge.bridge-nf-call-ip6tables = 1 
EOF
</pre></div>


<p class="wp-block-paragraph">5. Load sysctl settings from all available configuration files:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo sysctl --system
</pre></div>


<p class="wp-block-paragraph">6. Update the package list and install the &#8220;containerd&#8221; package:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo apt-get update &amp;&amp; sudo apt-get install -y containerd
</pre></div>


<p class="wp-block-paragraph">7. Create the /etc/containerd directory if it doesn&#8217;t exist (we will use it to store the default configuration file for containerd ):</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo mkdir -p /etc/containerd
</pre></div>


<p class="wp-block-paragraph">8. Generate a default config file for containerd and save it to the newly created default file:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo containerd config default | sudo tee /etc/containerd/config.toml
</pre></div>


<p class="wp-block-paragraph">9. Restart containerd to ensure new configuration file usage:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
 sudo systemctl restart containerd
</pre></div>


<p class="wp-block-paragraph">10. Verify that containerd is running:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo systemctl status containerd
</pre></div>


<pre class="wp-block-code"><code>dbinla@dbisbx-master01:~$  sudo systemctl status containerd
● containerd.service - containerd container runtime
     Loaded: loaded (/lib/systemd/system/containerd.service; enabled; vendor preset: enabled)
     Active: active (running) since Mon 2023-01-09 10:28:12 UTC; 22s ago
       Docs: https://containerd.io
    Process: 2013 ExecStartPre=/sbin/modprobe overlay (code=exited, status=0/SUCCESS)
   Main PID: 2014 (containerd)
      Tasks: 8
     Memory: 10.8M
        CPU: 140ms
     CGroup: /system.slice/containerd.service
             └─2014 /usr/bin/containerd

Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.551429182Z" level=info msg=serving... address=/run/containerd/containerd.sock.ttrpc
Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.551607403Z" level=info msg=serving... address=/run/containerd/containerd.sock
Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.551954435Z" level=info msg="containerd successfully booted in 0.051594s"
Jan 09 10:28:12 dbisbx-master01 systemd&#091;1]: Started containerd container runtime.
Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.557282442Z" level=info msg="Start subscribing containerd event"
Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.557379562Z" level=info msg="Start recovering state"
Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.557588184Z" level=info msg="Start event monitor"
Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.557619734Z" level=info msg="Start snapshots syncer"
Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.557634754Z" level=info msg="Start cni network conf syncer"
Jan 09 10:28:12 dbisbx-master01 containerd&#091;2014]: time="2023-01-09T10:28:12.557649394Z" level=info msg="Start streaming server"
dbinla@dbisbx-master01:~$</code></pre>



<p class="wp-block-paragraph">11. Disable swap:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo swapoff -a
</pre></div>


<p class="wp-block-paragraph">12. Update and install dependency packages:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo apt-get update &amp;&amp; sudo apt-get install -y apt-transport-https curl
</pre></div>


<p class="wp-block-paragraph">13. Download and add the Google Cloud public signing key:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
curl -s https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo apt-key add -
</pre></div>


<p class="wp-block-paragraph"><em>Depending on the version of your distribution, you might have a warning about the deprecated command. Therefore you can type instead of:</em></p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo curl -fsSLo /etc/apt/keyrings/kubernetes-archive-keyring.gpg https://packages.cloud.google.com/apt/doc/apt-key.gpg
</pre></div>


<p class="wp-block-paragraph">14. Create a new file called &#8220;/etc/apt/sources.list.d/kubernetes.list&#8221; and add the Kubernetes apt repository to it:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
echo &quot;deb &#x5B;signed-by=/etc/apt/keyrings/kubernetes-archive-keyring.gpg] https://apt.kubernetes.io/ kubernetes-xenial main&quot; | sudo tee /etc/apt/sources.list.d/kubernetes.list
</pre></div>


<p class="wp-block-paragraph">15. Update package listings:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo apt-get update
</pre></div>


<p class="wp-block-paragraph">16. Install specific versions of the kubelet, kubeadm, and kubectl packages :</p>



<pre class="wp-block-code"><code>sudo apt-get install -y kubelet=1.24.0-00 kubeadm=1.24.0-00 kubectl=1.24.0-00</code></pre>



<p class="wp-block-paragraph">17. Mark the kubelet, kubeadm, and kubectl packages as &#8220;held&#8221; to prevent them from being automatically upgraded:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo apt-mark hold kubelet kubeadm kubectl
</pre></div>


<p class="wp-block-paragraph">18. The installation of the packages must be performed on all servers. The entire part 1 must be repeated on the worker nodes.</p>



<h3 class="wp-block-heading">Initialize the Cluster</h3>



<p class="wp-block-paragraph">1. <em>This part had to be done only on the Master server (Control Plane)</em><br>Install specific versions of the kubelet, kubeadm, and kubectl packages. And then initialize the Kubernetes cluster with kubeadm, specifying the pod network CIDR and the Kubernetes version</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
sudo apt-get install -y kubelet=1.24.0-00 kubeadm=1.24.0-00 kubectl=1.24.0-00
sudo kubeadm init --pod-network-cidr 192.168.0.0/16 --kubernetes-version 1.24.0
</pre></div>


<pre class="wp-block-code"><code>dbinla@dbisbx-master01:~$ sudo kubeadm init --pod-network-cidr 192.168.0.0/16 --kubernetes-version 1.24.0
&#091;init] Using Kubernetes version: v1.24.0
&#091;preflight] Running pre-flight checks
&#091;preflight] Pulling images required for setting up a Kubernetes cluster
&#091;preflight] This might take a minute or two, depending on the speed of your internet connection
&#091;preflight] You can also perform this action in beforehand using 'kubeadm config images pull'
&#091;certs] Using certificateDir folder "/etc/kubernetes/pki"
&#091;certs] Generating "ca" certificate and key
&#091;certs] Generating "apiserver" certificate and key
&#091;certs] apiserver serving cert is signed for DNS names &#091;dbisbx-master01 kubernetes kubernetes.default kubernetes.default.svc kubernetes.default.svc.cluster.local] and IPs &#091;10.*.*.* 172.*.*.*]
&#091;certs] Generating "apiserver-kubelet-client" certificate and key
&#091;certs] Generating "front-proxy-ca" certificate and key
&#091;certs] Generating "front-proxy-client" certificate and key
&#091;certs] Generating "etcd/ca" certificate and key
&#091;certs] Generating "etcd/server" certificate and key
&#091;certs] etcd/server serving cert is signed for DNS names &#091;dbisbx-master01 localhost] and IPs &#091;172.*.*.* 127.0.0.1 ::1]
&#091;certs] Generating "etcd/peer" certificate and key
&#091;certs] etcd/peer serving cert is signed for DNS names &#091;dbisbx-master01 localhost] and IPs &#091;172.*.*.* 127.0.0.1 ::1]
&#091;certs] Generating "etcd/healthcheck-client" certificate and key
&#091;certs] Generating "apiserver-etcd-client" certificate and key
&#091;certs] Generating "sa" key and public key
&#091;kubeconfig] Using kubeconfig folder "/etc/kubernetes"
&#091;kubeconfig] Writing "admin.conf" kubeconfig file
&#091;kubeconfig] Writing "kubelet.conf" kubeconfig file
&#091;kubeconfig] Writing "controller-manager.conf" kubeconfig file
&#091;kubeconfig] Writing "scheduler.conf" kubeconfig file
&#091;kubelet-start] Writing kubelet environment file with flags to file "/var/lib/kubelet/kubeadm-flags.env"
&#091;kubelet-start] Writing kubelet configuration to file "/var/lib/kubelet/config.yaml"
&#091;kubelet-start] Starting the kubelet
&#091;control-plane] Using manifest folder "/etc/kubernetes/manifests"
&#091;control-plane] Creating static Pod manifest for "kube-apiserver"
&#091;control-plane] Creating static Pod manifest for "kube-controller-manager"
&#091;control-plane] Creating static Pod manifest for "kube-scheduler"
&#091;etcd] Creating static Pod manifest for local etcd in "/etc/kubernetes/manifests"
&#091;wait-control-plane] Waiting for the kubelet to boot up the control plane as static Pods from directory "/etc/kubernetes/manifests". This can take up to 4m0s
&#091;kubelet-check] Initial timeout of 40s passed.
&#091;apiclient] All control plane components are healthy after 53.186020 seconds
&#091;upload-config] Storing the configuration used in ConfigMap "kubeadm-config" in the "kube-system" Namespace
&#091;kubelet] Creating a ConfigMap "kubelet-config" in namespace kube-system with the configuration for the kubelets in the cluster
&#091;upload-certs] Skipping phase. Please see --upload-certs
&#091;mark-control-plane] Marking the node dbisbx-master01 as control-plane by adding the labels: &#091;node-role.kubernetes.io/control-plane node.kubernetes.io/exclude-from-external-load-balancers]
&#091;mark-control-plane] Marking the node dbisbx-master01 as control-plane by adding the taints &#091;node-role.kubernetes.io/master:NoSchedule node-role.kubernetes.io/control-plane:NoSchedule]
&#091;bootstrap-token] Using token: vnv0kw.xmh*************
&#091;bootstrap-token] Configuring bootstrap tokens, cluster-info ConfigMap, RBAC Roles
&#091;bootstrap-token] Configured RBAC rules to allow Node Bootstrap tokens to get nodes
&#091;bootstrap-token] Configured RBAC rules to allow Node Bootstrap tokens to post CSRs in order for nodes to get long term certificate credentials
&#091;bootstrap-token] Configured RBAC rules to allow the csrapprover controller automatically approve CSRs from a Node Bootstrap Token
&#091;bootstrap-token] Configured RBAC rules to allow certificate rotation for all node client certificates in the cluster
&#091;bootstrap-token] Creating the "cluster-info" ConfigMap in the "kube-public" namespace
&#091;kubelet-finalize] Updating "/etc/kubernetes/kubelet.conf" to point to a rotatable kubelet client certificate and key
&#091;addons] Applied essential addon: CoreDNS
&#091;addons] Applied essential addon: kube-proxy

Your Kubernetes control-plane has initialized successfully!

To start using your cluster, you need to run the following as a regular user:

  mkdir -p $HOME/.kube
  sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
  sudo chown $(id -u):$(id -g) $HOME/.kube/config

Alternatively, if you are the root user, you can run:

  export KUBECONFIG=/etc/kubernetes/admin.conf

You should now deploy a pod network to the cluster.
Run "kubectl apply -f &#091;podnetwork].yaml" with one of the options listed at:
  https:&#047;&#047;kubernetes.io/docs/concepts/cluster-administration/addons/

Then you can join any number of worker nodes by running the following on each as root:

kubeadm join 172.*.*.*:6443 --token vnv0kw.xmh************* \
	--discovery-token-ca-cert-hash sha256:eaec80d623e107619c02f743a726d8e5f6******************************
dbinla@dbisbx-master01:~$</code></pre>



<p class="wp-block-paragraph">2. Once the initialization is done, we have to set the kubectl access. <br>For this aim, let&#8217;s create the <em>.kube</em> folder in our user&#8217;s home directory if it doesn&#8217;t already exist. <br>We will then copy the admin.conf file from /etc/kubernetes to the .kube directory. Finally, we will change the owner of the copied file to the current user.</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
</pre></div>


<p class="wp-block-paragraph">3. Test the access to the cluster.</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
kubectl get nodes
</pre></div>


<pre class="wp-block-code"><code>dbinla@dbisbx-master01:~$ kubectl get nodes
NAME              STATUS     ROLES           AGE   VERSION
dbisbx-master01   NotReady   control-plane   02m   v1.24.0
dbinla@dbisbx-master01:~$</code></pre>



<h3 class="wp-block-heading">Install the Calico Network Add-On</h3>



<p class="wp-block-paragraph">1. On the control plane node, install Calico Networking by creating the necessary custom resource:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.25.0/manifests/custom-resources.yaml
</pre></div>


<p class="wp-block-paragraph"><em>More information on configuration option are available</em> <a href="https://docs.tigera.io/calico/latest/reference/installation/api" target="_blank" rel="noreferrer noopener">here</a></p>



<pre class="wp-block-code"><code>dbinla@dbisbx-master01:~$ kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.25.0/manifests/custom-resources.yaml
poddisruptionbudget.policy/calico-kube-controllers created
serviceaccount/calico-kube-controllers created
serviceaccount/calico-node created
configmap/calico-config created
customresourcedefinition.apiextensions.k8s.io/bgpconfigurations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/bgppeers.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/blockaffinities.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/caliconodestatuses.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/clusterinformations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/felixconfigurations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/globalnetworkpolicies.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/globalnetworksets.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/hostendpoints.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ipamblocks.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ipamconfigs.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ipamhandles.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ippools.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ipreservations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/kubecontrollersconfigurations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/networkpolicies.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/networksets.crd.projectcalico.org created
clusterrole.rbac.authorization.k8s.io/calico-kube-controllers created
clusterrole.rbac.authorization.k8s.io/calico-node created
clusterrolebinding.rbac.authorization.k8s.io/calico-kube-controllers created
clusterrolebinding.rbac.authorization.k8s.io/calico-node created
daemonset.apps/calico-node created
deployment.apps/calico-kube-controllers created
dbinla@dbisbx-master01:~$</code></pre>



<p class="wp-block-paragraph">2. Check the status of the control plane node:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
kubectl get nodes -owide
</pre></div>


<pre class="wp-block-code"><code>dbinla@dbisbx-master01:~$ kubectl get nodes -owide
NAME              STATUS   ROLES           AGE   VERSION   INTERNAL-IP      EXTERNAL-IP   OS-IMAGE             KERNEL-VERSION    CONTAINER-RUNTIME
dbisbx-master01   Ready    control-plane   07m   v1.24.0   172.*.*.*    &lt;none&gt;        Ubuntu 20.04.5 LTS   5.15.0-1027-aws   containerd://1.5.9
</code></pre>



<h3 class="wp-block-heading">Join the worker nodes to k8s cluster</h3>



<p class="wp-block-paragraph">In the chapter &#8220;Cluster Initialization&#8221;, we retrieved the command allowing us to add our workers to the cluster.<br>You can retrieve the command and run it on each worker.<br>In case you didn&#8217;t copy the command, you still have the possibility to display the join command by recreating the token that will allow you to join your nodes.<br>1. From the control plane server, execute the following command.</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: plain; title: ; notranslate">
kubeadm token create --print-join-command
</pre></div>

<div class="wp-block-syntaxhighlighter-code "><pre class="brush: plain; title: ; notranslate">
dbinla@dbisbx-master01:~$ kubeadm token create --print-join-command
kubeadm join 172.31.99.146:6443 --token u871a6.k*************** --discovery-token-ca-cert-hash sha256:eaec80d623e107619c02f743a726*********************************

</pre></div>


<pre class="wp-block-preformatted">2. On the first worker node, execute the previous printed command "kubeadm join &lt;IP:PORT&gt; ..." being root, or running as root user.</pre>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: plain; title: ; notranslate">
sudo kubeadm join 172.*.*.*:6443 --token u871a6.kbzwx2j6jztxyvg3 --discovery-token-ca-cert-hash sha256:eaec80d623e107619c02f743a726*********************************
</pre></div>


<pre class="wp-block-code"><code>dbinla@dbisbx-worker01:~$ sudo kubeadm join 172.*.*.*:6443 --token u871a6.kbzwx2j6jztxyvg3 --discovery-token-ca-cert-hash sha256:eaec80d623e107619c02f743a726*********************************
&#091;preflight] Running pre-flight checks
&#091;preflight] Reading configuration from the cluster...
&#091;preflight] FYI: You can look at this config file with 'kubectl -n kube-system get cm kubeadm-config -o yaml'
&#091;kubelet-start] Writing kubelet configuration to file "/var/lib/kubelet/config.yaml"
&#091;kubelet-start] Writing kubelet environment file with flags to file "/var/lib/kubelet/kubeadm-flags.env"
&#091;kubelet-start] Starting the kubelet
&#091;kubelet-start] Waiting for the kubelet to perform the TLS Bootstrap...

This node has joined the cluster:
* Certificate signing request was sent to apiserver and a response was received.
* The Kubelet was informed of the new secure connection details.

Run 'kubectl get nodes' on the control-plane to see this node join the cluster.

dbinla@dbisbx-worker01:~$</code></pre>



<p class="wp-block-paragraph">All that remains is to check that the node has been added to the cluster; it may take a few minutes for the node to go to the ready status</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: plain; title: ; notranslate">
kubectl get nodes -owide
</pre></div>


<pre class="wp-block-code"><code>dbinla@dbisbx-master01:~$ kubectl get nodes -owide
NAME              STATUS   ROLES           AGE   VERSION   INTERNAL-IP      EXTERNAL-IP   OS-IMAGE             KERNEL-VERSION    CONTAINER-RUNTIME
dbisbx-master01   Ready    control-plane   19m   v1.24.0   172.31.99.146    &lt;none&gt;        Ubuntu 20.04.5 LTS   5.15.0-1027-aws   containerd://1.5.9
dbisbx-worker01   Ready    &lt;none&gt;          05m   v1.24.0   172.31.101.246   &lt;none&gt;        Ubuntu 20.04.5 LTS   5.15.0-1027-aws   containerd://1.5.9
dbisbx-worker02   Ready    &lt;none&gt;          03m   v1.24.0   172.31.96.172    &lt;none&gt;        Ubuntu 20.04.5 LTS   5.15.0-1027-aws   containerd://1.5.9</code></pre>



<p class="wp-block-paragraph">Here we are; we could quickly build a small Kubernetes cluster in less than 20 minutes.</p>
<p>L’article <a href="https://www.dbi-services.com/blog/how-to-build-a-kubernetes-cluster-with-kubeadm/">Easily build a kubernetes cluster with kubeadm</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/how-to-build-a-kubernetes-cluster-with-kubeadm/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to setup a Consul Cluster on RHEL 8, Rocky Linux 8, AlmaLinux 8 part 2</title>
		<link>https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8-part-2/</link>
					<comments>https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8-part-2/#respond</comments>
		
		<dc:creator><![CDATA[Open source Team]]></dc:creator>
		<pubDate>Mon, 02 May 2022 06:49:07 +0000</pubDate>
				<category><![CDATA[Database Administration & Monitoring]]></category>
		<category><![CDATA[PostgreSQL]]></category>
		<category><![CDATA[High availability]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[postgresql]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8-part-2/</guid>

					<description><![CDATA[<p>Within the first part I have described the setup of Consul as replacement for ETCD. Here now the setup ob keepalived, haproxy and patroni. The needed packages I have installed within the first part, so let&#8217;s start with the configuration of keepalived. At first we need to open firewalld for the VRRP Protocol: $ [root@patroni-01 [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8-part-2/">How to setup a Consul Cluster on RHEL 8, Rocky Linux 8, AlmaLinux 8 part 2</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Within the first part I have described the setup of Consul as replacement for ETCD.<br />
Here now the setup ob keepalived, haproxy and patroni.</p>
<p>The needed packages I have installed within the first part, so let&#8217;s start with the configuration of keepalived.</p>
<p>At first we need to open firewalld for the VRRP Protocol:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# firewall-cmd --add-rich-rule='rule protocol value="vrrp" accept' --permanent
$ success
$ [root@patroni-01 ~]# firewall-cmd --reload
$ success
$ [root@patroni-01 ~]#
</pre>
<p>Next part will be the configuration of keepalived:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 /]# cat /etc/keepalived/keepalived.conf
$ vrrp_script haproxy {
$         script "killall -0 haproxy"
$         interval 2
$         weight 2
$ }
$ vrrp_instance VI_1 {
$         state MASTER
$         interface ens160
$         virtual_router_id 51
$         priority 255
$         advert_int 1
$         authentication {
$               auth_type PASS
$               auth_pass new_password
$         }
$         virtual_ipaddress {
$               192.168.198.200/24
$         }
$         track_script {
$         haproxy
$         }
$ }
$ [root@patroni-01 /]#
</pre>
<p>Priority defines the default role, in my case 255 for the master role.</p>
<p>The keepalived.conf for the backup role on patroni-02:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-02 /]# cat /etc/keepalived/keepalived.conf
$ vrrp_script haproxy {
$         script "killall -0 haproxy"
$         interval 2
$         weight 2
$ }
$ vrrp_instance VI_1 {
$         state BACKUP
$         interface ens160
$         virtual_router_id 51
$         priority 254
$         advert_int 1
$         authentication {
$               auth_type PASS
$               auth_pass new_password
$         }
$         virtual_ipaddress {
$               192.168.198.200/24
$         }
$         track_script {
$         haproxy
$         }
$ }
[root@patroni-02 /]#
</pre>
<p>The keepalived.conf for the backup role on patroni-03:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-03 /]# cat /etc/keepalived/keepalived.conf
$ vrrp_script haproxy {
$         script "killall -0 haproxy"
$         interval 2
$         weight 2
$ }
$ vrrp_instance VI_1 {
$         state BACKUP
$         interface ens160
$         virtual_router_id 51
$         priority 254
$         advert_int 1
$         authentication {
$               auth_type PASS
$               auth_pass new_password
$         }
$         virtual_ipaddress {
$               192.168.198.200/24
$         }
$         track_script {
$         haproxy
$         }
$ }
$ [root@patroni-03 /]#
</pre>
<p>Checking status on all three nodes.:<br />
patroni-01 as MASTER:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 /]# journalctl -u keepalived
$ Mar 25 13:04:45 patroni-01.patroni.test Keepalived_vrrp[11468]: (VI_1) Entering MASTER STATE
</pre>
<p>patroni-02 as BACKUP:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ journalctl -u keepalived
$ Mar 25 14:20:18 patroni-02.patroni.test Keepalived_vrrp[1484]: (VI_1) Entering BACKUP STATE
</pre>
<p>patroni-03 as BACKUP:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ journalctl -u keepalived
$ Mar 25 14:21:56 patroni-03.patroni.test Keepalived_vrrp[1465]: (VI_1) Entering BACKUP STATE
</pre>
<p>Next step haproxy.<br />
At first we need to adapt SE Linux for haproxy or switch it off:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 /]#setsebool -P haproxy_connect_any=1
</pre>
<p>haproxy.cfg is the same on all three servers:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 /]# cat /etc/haproxy/haproxy.cfg
$ global
$     maxconn 100
$ 
$ defaults
$     log global
$     mode tcp
$     retries 2
$     timeout client 30m
$     timeout connect 4s
$     timeout server 30m
$     timeout check 5s
$ 
$ listen stats
$     mode http
$     bind *:7000
$     stats enable
$     stats uri /
$     # stats auth haproxy:haproxy
$     # stats refresh 10s
$ 
$ listen PG1
$     bind *:5000
$     option httpchk
$     http-check expect status 200
$     default-server inter 3s fall 3 rise 2 on-marked-down shutdown-sessions
$     server postgresql_192.168.198.132_5432 192.168.198.132:5432 maxconn 100 check port 8008
$     server postgresql_192.168.198.133_5432 192.168.198.133:5432 maxconn 100 check port 8008
$     server postgresql_192.168.198.134_5432 192.168.198.134:5432 maxconn 100 check port 8008
$ [root@patroni-01 /]#
</pre>
<p>Starting and enabling haproxy:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 /]# systemctl start haproxy
$ [root@patroni-01 /]# systemctl enable haproxy
</pre>
<p>Now the interesting part, Patroni.<br />
At first, there is a missing dependancy by installing Patroni out of RPM Pachages, python3-urllib3 is missing:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 pgdata]# dnf install python3-urllib3
$ Last metadata expiration check: 5:18:38 ago on Mon 11 Apr 2022 11:06:33 AM CEST.
$ Dependencies resolved.
$ ==========================================================================================================================================================================================================================================================================================
$  Package                                                                   Architecture                                                     Version                                                                Repository                                                        Size
$ ==========================================================================================================================================================================================================================================================================================
$ Installing:
$  python3-urllib3                                                           noarch                                                           1.24.2-5.el8                                                           baseos                                                           176 k
$ Installing dependencies:
$  python3-pysocks                                                           noarch                                                           1.6.8-3.el8                                                            baseos                                                            33 k
$ 
$ Transaction Summary
$ ==========================================================================================================================================================================================================================================================================================
$ Install  2 Packages
$ 
$ Total download size: 209 k
$ Installed size: 681 k
$ Is this ok [y/N]: y
$ Downloading Packages:
$ (1/2): python3-pysocks-1.6.8-3.el8.noarch.rpm                                                                                                                                                                                                             274 kB/s |  33 kB     00:00
$ (2/2): python3-urllib3-1.24.2-5.el8.noarch.rpm                                                                                                                                                                                                            1.0 MB/s | 176 kB     00:00
$ ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
$ Total                                                                                                                                                                                                                                                     469 kB/s | 209 kB     00:00
$ Running transaction check
$ Transaction check succeeded.
$ Running transaction test
$ Transaction test succeeded.
$ Running transaction
$   Preparing        :                                                                                                                                                                                                                                                                  1/1
$   Installing       : python3-pysocks-1.6.8-3.el8.noarch                                                                                                                                                                                                                               1/2
$   Installing       : python3-urllib3-1.24.2-5.el8.noarch                                                                                                                                                                                                                              2/2
$   Running scriptlet: python3-urllib3-1.24.2-5.el8.noarch                                                                                                                                                                                                                              2/2
$   Verifying        : python3-pysocks-1.6.8-3.el8.noarch                                                                                                                                                                                                                               1/2
$   Verifying        : python3-urllib3-1.24.2-5.el8.noarch                                                                                                                                                                                                                              2/2
$ 
$ Installed:
$   python3-pysocks-1.6.8-3.el8.noarch                                                                                                          python3-urllib3-1.24.2-5.el8.noarch
$ 
$ Complete!
</pre>
<p>Patroni need a information which one of the consul nodes is master at start.<br />
This information comes out of the parameter &#8220;bootstrap&#8221;: true only on the master node at start.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 consul.d]# cat consul.json-dist.hcl
$ {
$     "bootstrap": true,
$     "server": true,
$     "data_dir": "/pgdata/consul",
$     "log_level": "INFO"
$     "disable_update_check": true,
$     "disable_anonymous_signature": true,
$     "advertise_addr": "192.168.198.132",
$     "bind_addr": "192.168.198.132",
$     "bootstrap_expect": 3,
$     "client_addr": "0.0.0.0",
$     "domain": "patroni.test",
$     "enable_script_checks": true,
$     "dns_config": {
$         "enable_truncate": true,
$         "only_passing": true
$     },
$     "enable_syslog": true,
$     "encrypt": "ueX3vI8HI63FR/VE+Yv1T4+x7mrrNIU7F2bDNfPVR9g=",
$     "leave_on_terminate": true,
$     "log_level": "INFO",
$     "rejoin_after_leave": true,
$     "retry_join": [
$         "patroni-01",
$         "patroni-02",
$         "patroni-03"
$     ],
$     "server": true,
$     "start_join": [
$         "patroni-01",
$         "patroni-02",
$         "patroni-03"
$     ],
$     "ui_config.enabled": true
$ }
$ [root@patroni-01 consul.d]#
</pre>
<p>Now Patroni, this is similar to Patroni using etcd.<br />
By using etcd there is a part etcd within the patroni.yml file, this is replaced with a part consul:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 patroni]# cat patroni.yml
$ name: "patroni-01.patroni.test"
$ scope: PG1
$ namespace: /patroni.test/
$ consul:
$   url: http://127.0.0.1:8500
$   register_service: true
$ postgresql:
$   connect_address: "patroni-01.patroni.test:5432"
$   bin_dir: /usr/pgsql-14/bin
$   data_dir: /pgdata/14/data
$   authentication:
$     replication:
$       username: replicator
$       password: replicator
$     superuser:
$       username: postgres
$       password: postgres
$   listen: 192.168.198.132:5432
$ restapi:
$   connect_address: "patroni-01.patroni.test:8008"
$   listen: "patroni-01.patroni.test:8008"
$ bootstrap:
$   dcs:
$     postgresql:
$       use_pg_rewind: true
$       use_slots: true
$       parameters:
$         wal_level: 'hot_standby'
$         hot_standby: "on"
$         wal_keep_segments: 8
$         max_replication_slots: 10
$         wal_log_hints: "on"
$         listen_addresses: '*'
$         port: 5432
$         logging_collector: 'on'
$         log_truncate_on_rotation: 'on'
$         log_filename: 'postgresql-%a.log'
$         log_rotation_age: '1440'
$         log_line_prefix: '%m - %l - %p - %h - %u@%d - %x'
$         log_directory: 'pg_log'
$         log_min_messages: 'WARNING'
$         log_autovacuum_min_duration: '60s'
$         log_min_error_statement: 'NOTICE'
$         log_min_duration_statement: '30s'
$         log_checkpoints: 'on'
$         log_statement: 'ddl'
$         log_lock_waits: 'on'
$         log_temp_files: '0'
$         log_timezone: 'Europe/Zurich'
$         log_connections: 'on'
$         log_disconnections: 'on'
$         log_duration: 'on'
$         client_min_messages: 'WARNING'
$         wal_level: 'replica'
$         hot_standby_feedback: 'on'
$         max_wal_senders: '10'
$         shared_buffers: '1024MB'
$         work_mem: '8MB'
$         effective_cache_size: '3072MB'
$         maintenance_work_mem: '64MB'
$         wal_compression: 'off'
$         max_wal_senders: '20'
$         shared_preload_libraries: 'pg_stat_statements'
$         autovacuum_max_workers: '6'
$         autovacuum_vacuum_scale_factor: '0.1'
$         autovacuum_vacuum_threshold: '50'
$         archive_mode: 'on'
$         archive_command: '/bin/true'
$         wal_log_hints: 'on'
$         ssl: "on"
$         ssl_ciphers: "TLSv1.2:!aNULL:!eNULL"
$         ssl_cert_file: /pgdata/certs/server.crt
$         ssl_key_file: /pgdata/certs/server.key
$   users:
$     app_user:
$       password: "aZ5QrESZ"
$   pg_hba:
$     - local all all  scram-sha-256
$     - hostssl all all 127.0.0.1/32 scram-sha-256
$     - hostssl all all ::1/128 scram-sha-256
$     - hostssl all all ::1/128 scram-sha-256
$     - hostssl all all 0.0.0.0/0 scram-sha-256
$     - hostssl replication replicator patroni-01.patroni.test scram-sha-256
$     - hostssl replication replicator patroni-01.patroni.test scram-sha-256
$     - hostssl replication replicator patroni-01.patroni.test scram-sha-256
$   initdb:
$     - encoding: UTF8
$ [root@patroni-01 patroni]#
</pre>
<p>The only difference within patroni.yml on the three nodes within this example setup is:<br />
name: &#8220;patroni-01.patroni.test&#8221; needs to be adapted to &#8220;patroni-02.patroni.test&#8221; or &#8220;patroni-03.patroni.test&#8221;<br />
Under postgresql:<br />
   connect_address: &#8220;patroni-01.patroni.test:5432&#8221; needs to be adapted to &#8220;patroni-02.patroni.test:5432&#8221; or &#8220;patroni-03.patroni.test:5432&#8221;.<br />
   listen: 192.168.198.132:5432 needs to be adpated to the corosponding IPs 192.168.198.133:5432 or 192.168.198.134:5432.<br />
Under reatapi:<br />
  connect_address: &#8220;patroni-01.patroni.test:8008&#8221; to &#8220;patroni-02.patroni.test:8008&#8221; or &#8220;patroni-02.patroni.test:8008&#8221;.<br />
  listen: &#8220;patroni-01.patroni.test:8008&#8221; to &#8220;patroni-02.patroni.test:8008&#8221; or &#8220;patroni-02.patroni.test:8008&#8221;.</p>
<p>In my exapmle patroni-01 is the consul leader, so here we need to start patroni first to be leader within the patroni cluster.<br />
Means the consul leader will be the patroni leader in any case, also in case of failover.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ postgres@patroni-01: patronictl list
$ + Cluster: PG1 (7358967191570897068) -----------------+---------+----+-----------+
$ | Member                  | Host            | Role    | State   | TL | Lag in MB |
$ +-------------------------+-----------------+---------+---------+----+-----------+
$ | patroni-01.patroni.test | 192.168.198.132 | Leader  | running |  2 |           |
$ | patroni-02.patroni.test | 192.168.198.133 | Replica | running |  2 |         0 |
$ | patroni-03.patroni.test | 192.168.198.134 | Replica | running |  2 |         0 |
$ +-------------------------+-----------------+---------+---------+----+-----------+
</pre>
<p>L’article <a href="https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8-part-2/">How to setup a Consul Cluster on RHEL 8, Rocky Linux 8, AlmaLinux 8 part 2</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8-part-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to setup a Consul Cluster on RHEL 8, Rocky Linux 8, AlmaLinux 8 part 1</title>
		<link>https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8/</link>
					<comments>https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8/#respond</comments>
		
		<dc:creator><![CDATA[Open source Team]]></dc:creator>
		<pubDate>Fri, 04 Mar 2022 14:10:44 +0000</pubDate>
				<category><![CDATA[Database Administration & Monitoring]]></category>
		<category><![CDATA[Operating systems]]></category>
		<category><![CDATA[PostgreSQL]]></category>
		<category><![CDATA[Consul]]></category>
		<category><![CDATA[High availability]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[postgresql]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8/</guid>

					<description><![CDATA[<p>This blog describes the setup of a Consul Cluster on RHEL 8 and clones, it will be the base for a Patroni HA setup using RPM Packages from postgresql.org. Many Patroni setups are using ETCD, but ETCD is not available as RPM out of the box for RHEL 8 and clones, and in many cases [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8/">How to setup a Consul Cluster on RHEL 8, Rocky Linux 8, AlmaLinux 8 part 1</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>This blog describes the setup of a Consul Cluster on RHEL 8 and clones, it will be the base for a Patroni HA setup using RPM Packages from postgresql.org.<br />
Many Patroni setups are using ETCD, but ETCD is not available as RPM out of the box for RHEL 8 and clones, and in many cases using tar files or RPMS from unknown sources are not allowed.</p>
<p>I use OS Rocky Linux 8.5 minimal installation patched before writing this blog.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-01 ~]# cat /etc/os-release
NAME="Rocky Linux"
VERSION="8.5 (Green Obsidian)"
ID="rocky"
ID_LIKE="rhel centos fedora"
VERSION_ID="8.5"
PLATFORM_ID="platform:el8"
PRETTY_NAME="Rocky Linux 8.5 (Green Obsidian)"
ANSI_COLOR="0;32"
CPE_NAME="cpe:/o:rocky:rocky:8:GA"
HOME_URL="https://rockylinux.org/"
BUG_REPORT_URL="https://bugs.rockylinux.org/"
ROCKY_SUPPORT_PRODUCT="Rocky Linux"
ROCKY_SUPPORT_PRODUCT_VERSION="8"
[root@patroni-01 ~]#
</pre>
<p>It will be a three node cluster with the following nodes:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-01 ~]# cat /etc/hosts
127.0.0.1   localhost localhost.localdomain localhost4 localhost4.localdomain4
192.168.198.132 patroni-01.patroni.test patroni-01
192.168.198.133 patroni-02.patroni.test patroni-02
192.168.198.134 patroni-03.patroni.test patroni-03
[root@patroni-01 ~]#
</pre>
<p>The installation RPM for Consul will come from the postgresql.org repository, so we need to disable postgresql from the OS Repository on all three nodes.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# dnf -y module disable postgresql
$ Last metadata expiration check: 1:21:07 ago on Fri 04 Mar 2022 12:53:22 PM CET.
$ Dependencies resolved.
$ ====================================================================================================
$  Package                Architecture          Version                  Repository              Size
$ ====================================================================================================
$ Disabling modules:
$  postgresql
$ 
$ Transaction Summary
$ ====================================================================================================
$ 
$ Complete!
$ [root@patroni-01 ~]#
</pre>
<p>Next step is adding the postgresql.org repository.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm
$ Last metadata expiration check: 1:49:40 ago on Fri 04 Mar 2022 12:53:22 PM CET.
$ pgdg-redhat-repo-latest.noarch.rpm                                                                         13 kB/s |  12 kB     00:00
$ Dependencies resolved.
$ ==========================================================================================================================================
$  Package                               Architecture                Version                        Repository                         Size
$ ==========================================================================================================================================
$ Installing:
$  pgdg-redhat-repo                      noarch                      42.0-23                        @commandline                       12 k
$ 
$ Transaction Summary
$ ==========================================================================================================================================
$ Install  1 Package
$ 
$ Total size: 12 k
$ Installed size: 12 k
$ Is this ok [y/N]: y
$ Downloading Packages:
$ Running transaction check
$ Transaction check succeeded.
$ Running transaction test
$ Transaction test succeeded.
$ Running transaction
$   Preparing        :                                                                                                                  1/1
$   Installing       : pgdg-redhat-repo-42.0-23.noarch                                                                                  1/1
$   Verifying        : pgdg-redhat-repo-42.0-23.noarch                                                                                  1/1
$ 
$ Installed:
$   pgdg-redhat-repo-42.0-23.noarch
$ 
$ Complete!
$ [root@patroni-01 ~]#
</pre>
<p>As written in the beginning, Consul will be part of a Patroni based HA Cluster, so I install all needed packages.<br />
But first I edit the pgdg repo file to enable PostgreSQL 14 only and disable all other versions.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-01 ~]# cat /etc/yum.repos.d/pgdg-redhat-all.repo
#######################################################
# PGDG Red Hat Enterprise Linux / CentOS repositories #
#######################################################

# PGDG Red Hat Enterprise Linux / CentOS stable common repository for all PostgreSQL versions

[pgdg-common]
name=PostgreSQL common RPMs for RHEL/CentOS $releasever - $basearch
baseurl=https://download.postgresql.org/pub/repos/yum/common/redhat/rhel-$releasever-$basearch
enabled=1
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PGDG
repo_gpgcheck = 1

# Red Hat recently breaks compatibility between 8.n and 8.n+1. PGDG repo is
# affected with the LLVM repo. This is a band aid repo for the llvmjit users
# whose installations cannot be updated.

[pgdg-centos8-sysupdates]
name=PostgreSQL Supplementary ucommon RPMs for RHEL/CentOS $releasever - $basearch
baseurl=https://download.postgresql.org/pub/repos/yum/common/pgdg-centos8-sysupdates/redhat/rhel-$releasever-$basearch
enabled=0
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PGDG
repo_gpgcheck = 1

# PGDG Red Hat Enterprise Linux / CentOS stable repositories:

[pgdg14]
name=PostgreSQL 14 for RHEL/CentOS $releasever - $basearch
baseurl=https://download.postgresql.org/pub/repos/yum/14/redhat/rhel-$releasever-$basearch
enabled=1
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PGDG
repo_gpgcheck = 1

[pgdg13]
name=PostgreSQL 13 for RHEL/CentOS $releasever - $basearch
baseurl=https://download.postgresql.org/pub/repos/yum/13/redhat/rhel-$releasever-$basearch
enabled=0
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PGDG
repo_gpgcheck = 1
</pre>
<p>Set enabled to 0 for all other version than the one you want to install, in my case only 14 is enabled.</p>
<p>As preparation for the following operations we need to open ports with firewalld, port 5432 is default PostgreSQL, the others used by consul.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# firewall-cmd --add-port={5432,8300,8301,8302,8400,8500,8600}/tcp --permanent
$ success
$ [root@patroni-01 ~]# firewall-cmd --add-port={8301,8302,8600}/udp --permanent
$ success
$ [root@patroni-01 ~]# firewall-cmd --reload
$ success
$ [root@patroni-01 ~]#
$ </pre>
<p>Now it is time to install Consul, as written in the beginning it will be part of a Patroni Cluster, so I install all needed packages in one step.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# dnf install consul postgresql14 postgresql14-server postgresql14-contrib haproxy keepalived patroni
$ PostgreSQL common RPMs for RHEL/CentOS 8 - x86_64                                           83  B/s | 195  B     00:02
$ PostgreSQL common RPMs for RHEL/CentOS 8 - x86_64                                          1.6 MB/s | 1.7 kB     00:00
$ Importing GPG key 0x442DF0F8:
$  Userid     : "PostgreSQL RPM Building Project "
$  Fingerprint: 68C9 E2B9 1A37 D136 FE74 D176 1F16 D2E1 442D F0F8
$  From       : /etc/pki/rpm-gpg/RPM-GPG-KEY-PGDG
$ Is this ok [y/N]: y
$ PostgreSQL common RPMs for RHEL/CentOS 8 - x86_64                                          186 kB/s | 619 kB     00:03
$ PostgreSQL 14 for RHEL/CentOS 8 - x86_64                                                   129  B/s | 195  B     00:01
$ PostgreSQL 14 for RHEL/CentOS 8 - x86_64                                                   1.6 MB/s | 1.7 kB     00:00
$ Importing GPG key 0x442DF0F8:
$  Userid     : "PostgreSQL RPM Building Project "
$  Fingerprint: 68C9 E2B9 1A37 D136 FE74 D176 1F16 D2E1 442D F0F8
$  From       : /etc/pki/rpm-gpg/RPM-GPG-KEY-PGDG
$ Is this ok [y/N]: y
$ PostgreSQL 14 for RHEL/CentOS 8 - x86_64                                                    74 kB/s | 206 kB     00:02
$ Dependencies resolved.
$ ===========================================================================================================================
$  Package                           Architecture  Version                                          Repository          Size
$ ===========================================================================================================================
$ Installing:
$  consul                            x86_64        1.10.3-1.rhel8                                   pgdg-common         16 M
$  haproxy                           x86_64        1.8.27-2.el8                                     appstream          1.4 M
$  keepalived                        x86_64        2.1.5-6.el8                                      appstream          535 k
$  patroni                           x86_64        2.1.3-1.rhel8                                    pgdg-common        863 k
$  postgresql14                      x86_64        14.2-1PGDG.rhel8                                 pgdg14             1.5 M
$  postgresql14-contrib              x86_64        14.2-1PGDG.rhel8                                 pgdg14             723 k
$  postgresql14-server               x86_64        14.2-1PGDG.rhel8                                 pgdg14             5.7 M
$ Installing dependencies:
$  libicu                            x86_64        60.3-2.el8_1                                     baseos             8.8 M
$  lm_sensors-libs                   x86_64        3.4.0-23.20180522git70f7e08.el8                  baseos              58 k
$  lz4                               x86_64        1.8.3-3.el8_4                                    baseos             102 k
$  mariadb-connector-c               x86_64        3.1.11-2.el8_3                                   appstream          199 k
$  mariadb-connector-c-config        noarch        3.1.11-2.el8_3                                   appstream           14 k
$  net-snmp-agent-libs               x86_64        1:5.8-22.el8                                     appstream          747 k
$  net-snmp-libs                     x86_64        1:5.8-22.el8                                     baseos             826 k
$  perl-Carp                         noarch        1.42-396.el8                                     baseos              29 k
$  perl-Data-Dumper                  x86_64        2.167-399.el8                                    baseos              57 k
$  perl-Digest                       noarch        1.17-395.el8                                     appstream           26 k
$  perl-Digest-MD5                   x86_64        2.55-396.el8                                     appstream           36 k
$  perl-Encode                       x86_64        4:2.97-3.el8                                     baseos             1.5 M
$  perl-Errno                        x86_64        1.28-420.el8                                     baseos              75 k
$  perl-Exporter                     noarch        5.72-396.el8                                     baseos              33 k
$  perl-File-Path                    noarch        2.15-2.el8                                       baseos              37 k
$  perl-File-Temp                    noarch        0.230.600-1.el8                                  baseos              62 k
$  perl-Getopt-Long                  noarch        1:2.50-4.el8                                     baseos              62 k
$  perl-HTTP-Tiny                    noarch        0.074-1.el8                                      baseos              57 k
$  perl-IO                           x86_64        1.38-420.el8                                     baseos             141 k
$  perl-MIME-Base64                  x86_64        3.15-396.el8                                     baseos              30 k
$  perl-Net-SSLeay                   x86_64        1.88-1.module+el8.4.0+512+d4f0fc54               appstream          378 k
$  perl-PathTools                    x86_64        3.74-1.el8                                       baseos              89 k
$  perl-Pod-Escapes                  noarch        1:1.07-395.el8                                   baseos              19 k
$  perl-Pod-Perldoc                  noarch        3.28-396.el8                                     baseos              85 k
$  perl-Pod-Simple                   noarch        1:3.35-395.el8                                   baseos             212 k
$  perl-Pod-Usage                    noarch        4:1.69-395.el8                                   baseos              33 k
$  perl-Scalar-List-Utils            x86_64        3:1.49-2.el8                                     baseos              67 k
$  perl-Socket                       x86_64        4:2.027-3.el8                                    baseos              58 k
$  perl-Storable                     x86_64        1:3.11-3.el8                                     baseos              97 k
$  perl-Term-ANSIColor               noarch        4.06-396.el8                                     baseos              45 k
$  perl-Term-Cap                     noarch        1.17-395.el8                                     baseos              22 k
$  perl-Text-ParseWords              noarch        3.30-395.el8                                     baseos              17 k
$  perl-Text-Tabs+Wrap               noarch        2013.0523-395.el8                                baseos              23 k
$  perl-Time-Local                   noarch        1:1.280-1.el8                                    baseos              32 k
$  perl-URI                          noarch        1.73-3.el8                                       appstream          115 k
$  perl-Unicode-Normalize            x86_64        1.25-396.el8                                     baseos              81 k
$  perl-constant                     noarch        1.33-396.el8                                     baseos              24 k
$  perl-interpreter                  x86_64        4:5.26.3-420.el8                                 baseos             6.3 M
$  perl-libnet                       noarch        3.11-3.el8                                       appstream          120 k
$  perl-libs                         x86_64        4:5.26.3-420.el8                                 baseos             1.6 M
$  perl-macros                       x86_64        4:5.26.3-420.el8                                 baseos              71 k
$  perl-parent                       noarch        1:0.237-1.el8                                    baseos              19 k
$  perl-podlators                    noarch        4.11-1.el8                                       baseos             117 k
$  perl-threads                      x86_64        1:2.21-2.el8                                     baseos              60 k
$  perl-threads-shared               x86_64        1.58-2.el8                                       baseos              47 k
$  postgresql14-libs                 x86_64        14.2-1PGDG.rhel8                                 pgdg14             275 k
$  python3-cdiff                     noarch        1.0-1.rhel8                                      pgdg-common         30 k
$  python3-click                     noarch        6.7-8.el8                                        appstream          130 k
$  python3-pip                       noarch        9.0.3-20.el8.rocky.0                             appstream           19 k
$  python3-prettytable               noarch        0.7.2-14.el8                                     appstream           43 k
$  python3-psutil                    x86_64        5.4.3-11.el8                                     appstream          372 k
$  python3-psycopg2                  x86_64        2.8.6-1.rhel8                                    pgdg-common        178 k
$  python3-pyyaml                    x86_64        3.12-12.el8                                      baseos             192 k
$  python3-setuptools                noarch        39.2.0-6.el8                                     baseos             162 k
$  python3-ydiff                     noarch        1.2-10.rhel8                                     pgdg-common         30 k
$  python36                          x86_64        3.6.8-38.module+el8.5.0+671+195e4563             appstream           18 k
$ Installing weak dependencies:
$  perl-IO-Socket-IP                 noarch        0.39-5.el8                                       appstream           46 k
$  perl-IO-Socket-SSL                noarch        2.066-4.module+el8.4.0+512+d4f0fc54              appstream          297 k
$  perl-Mozilla-CA                   noarch        20160104-7.module+el8.4.0+529+e3b3e624           appstream           14 k
$ Enabling module streams:
$  perl                                            5.26
$  perl-IO-Socket-SSL                              2.066
$  perl-libwww-perl                                6.34
$  python36                                        3.6
$ 
$ Transaction Summary
$ ===========================================================================================================================
$ Install  66 Packages
$ 
$ Total download size: 51 M
$ Installed size: 203 M
$ Is this ok [y/N]:
</pre>
<p>With installation out of the postgresql.org repository also user postgres and group postgres are created.</p>
<p>I want Consul also to run as postgres user, for this we need to adapt User and Group within the service file.<br />
The service file is located at /usr/lib/systemd/system/consul.service.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-01 ~]# cat /usr/lib/systemd/system/consul.service
[Unit]
Description=Consul is a tool for service discovery and configuration. Consul is distributed, highly available, and extremely scalable.
Documentation=http://www.consul.io
After=network-online.target
Wants=network-online.target

[Service]
User=postgres
Group=postgres
EnvironmentFile=-/etc/sysconfig/consul
ExecStart=/usr/bin/consul $CMD_OPTS
ExecReload=/bin/kill -HUP $MAINPID
KillSignal=SIGINT
Restart=on-failure

[Install]
WantedBy=multi-user.target
[root@patroni-01 ~]#
</pre>
<p>Next step is adapting the Consul environment file, I want the Consul data directory within /pgdata.<br />
The environment file is located at /etc/sysconfig/consul.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-01 ~]# cat /etc/sysconfig/consul
CMD_OPTS="agent -config-dir=/etc/consul.d -data-dir=/pgdata/consul"
#GOMAXPROCS=4
[root@patroni-01 ~]#
</pre>
<p>Creating Consul data directory.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# mkdir /pgdata/consul
$ [root@patroni-01 ~]# chown -R postgres:postgres /pgdata/
</pre>
<p>And the Consul key.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# consul keygen
$ 5mSUIrSSXp+usVR1qqM68CD2lnFLaTcg4G48l9zJhqE=
$ [root@patroni-01 ~]#
</pre>
<p>Now it is time to adapt the Consul configuration file on each node.<br />
Node patroni-01:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-01 ~]# cat /etc/consul.d/consul.json-dist.hcl
{
    "server": true,
    "data_dir": "/pgdata/consul",
    "log_level": "INFO"
    "disable_update_check": true,
    "disable_anonymous_signature": true,
    "advertise_addr": "192.168.198.132",
    "bind_addr": "192.168.198.132",
    "bootstrap_expect": 3,
    "client_addr": "0.0.0.0",
    "domain": "patroni.test",
    "enable_script_checks": true,
    "dns_config": {
        "enable_truncate": true,
        "only_passing": true
    },
    "enable_syslog": true,
    "encrypt": "5mSUIrSSXp+usVR1qqM68CD2lnFLaTcg4G48l9zJhqE=",
    "leave_on_terminate": true,
    "log_level": "INFO",
    "rejoin_after_leave": true,
    "retry_join": [
        "patroni-01",
        "patroni-02",
        "patroni-03"
    ],
    "server": true,
    "start_join": [
        "patroni-01",
        "patroni-02",
        "patroni-03"
    ],
    "ui_config.enabled": true
}
[root@patroni-01 ~]#
</pre>
<p>Node patroni-02:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-02 ~]# cat /etc/consul.d/consul.json-dist.hcl
{
    "server": true,
    "data_dir": "/pgdata/consul",
    "log_level": "INFO"
    "disable_update_check": true,
    "disable_anonymous_signature": true,
    "advertise_addr": "192.168.198.133",
    "bind_addr": "192.168.198.133",
    "bootstrap_expect": 3,
    "client_addr": "0.0.0.0",
    "domain": "patroni.test",
    "enable_script_checks": true,
    "dns_config": {
        "enable_truncate": true,
        "only_passing": true
    },
    "enable_syslog": true,
    "encrypt": "5mSUIrSSXp+usVR1qqM68CD2lnFLaTcg4G48l9zJhqE=",
    "leave_on_terminate": true,
    "log_level": "INFO",
    "rejoin_after_leave": true,
    "retry_join": [
        "patroni-01",
        "patroni-02",
        "patroni-03"
    ],
    "server": true,
    "start_join": [
        "patroni-01",
        "patroni-02",
        "patroni-03"
    ],
    "ui_config.enabled": true
}
[root@patroni-02 ~]#
</pre>
<p>Node patroni-03:</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-03 ~]# cat /etc/consul.d/consul.json-dist.hcl
{
    "server": true,
    "data_dir": "/pgdata/consul",
    "log_level": "INFO"
    "disable_update_check": true,
    "disable_anonymous_signature": true,
    "advertise_addr": "192.168.198.134",
    "bind_addr": "192.168.198.134",
    "bootstrap_expect": 3,
    "client_addr": "0.0.0.0",
    "domain": "patroni.test",
    "enable_script_checks": true,
    "dns_config": {
        "enable_truncate": true,
        "only_passing": true
    },
    "enable_syslog": true,
    "encrypt": "5mSUIrSSXp+usVR1qqM68CD2lnFLaTcg4G48l9zJhqE=",
    "leave_on_terminate": true,
    "log_level": "INFO",
    "rejoin_after_leave": true,
    "retry_join": [
        "patroni-01",
        "patroni-02",
        "patroni-03"
    ],
    "server": true,
    "start_join": [
        "patroni-01",
        "patroni-02",
        "patroni-03"
    ],
    "ui_config.enabled": true
}
[root@patroni-03 ~]#
</pre>
<p>And make the files accessable for the postgres user.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# chown -R postgres:postgres /etc/consul.d/
</pre>
<p>Now it is time to start Consul on each node.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# systemctl start consul
</pre>
<p>Checking the status.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
[root@patroni-01 ~]# consul members
$ Node                     Address               Status  Type    Build   Protocol  DC   Segment
$ patroni-01.patroni.test  192.168.198.132:8301  alive   server  1.10.3  2         dc1  
$ patroni-02.patroni.test  192.168.198.133:8301  alive   server  1.10.3  2         dc1  
$ patroni-03.patroni.test  192.168.198.134:8301  alive   server  1.10.3  2         dc1  
$ [root@patroni-01 ~]#
</pre>
<p>Sometimes it happens that Consul autojoin has issues, in this case manual join helps.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ [root@patroni-01 ~]# consul join 192.168.198.132 192.168.198.133 192.168.198.134
$ Successfully joined cluster by contacting 3 nodes.
$ [root@patroni-01 ~]# consul members
$ Node                     Address               Status  Type    Build   Protocol  DC   Segment
$ patroni-01.patroni.test  192.168.198.132:8301  alive   server  1.10.3  2         dc1  
$ patroni-02.patroni.test  192.168.198.133:8301  alive   server  1.10.3  2         dc1  
$ patroni-03.patroni.test  192.168.198.134:8301  alive   server  1.10.3  2         dc1  
$ [root@patroni-01 ~]#
</pre>
<p>That was the first part of a Patroni HA Setup using Consul instead of ETCD.</p>
<p>L’article <a href="https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8/">How to setup a Consul Cluster on RHEL 8, Rocky Linux 8, AlmaLinux 8 part 1</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/how-to-setup-a-consul-cluster-on-rhel-8-rocky-linux-8-almalinux-8/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Updating Password in PostgreSQL from md5 to scram-sha-256</title>
		<link>https://www.dbi-services.com/blog/updating-password-in-postgresql-from-md5-to-scram-sha-256/</link>
					<comments>https://www.dbi-services.com/blog/updating-password-in-postgresql-from-md5-to-scram-sha-256/#respond</comments>
		
		<dc:creator><![CDATA[Open source Team]]></dc:creator>
		<pubDate>Mon, 31 Jan 2022 12:58:53 +0000</pubDate>
				<category><![CDATA[Database Administration & Monitoring]]></category>
		<category><![CDATA[PostgreSQL]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[postgresql]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/updating-password-in-postgresql-from-md5-to-scram-sha-256/</guid>

					<description><![CDATA[<p>Many installations have a history of many major PostgreSQL releases. With PostgreSQL 10 comes scram-sha-256 for hashing passwords, by installing from packages scram-sha-256 is the default setting for new installations since PostgreSQL 13. With this small blog I will describe how to update password from md5 to scram-sha-256. For the installation of PostgreSQL there are [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/updating-password-in-postgresql-from-md5-to-scram-sha-256/">Updating Password in PostgreSQL from md5 to scram-sha-256</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Many installations have a history of many major PostgreSQL releases.<br />
With PostgreSQL 10 comes scram-sha-256 for hashing passwords, by installing from packages scram-sha-256 is the default setting for new installations since PostgreSQL 13.</p>
<p>With this small blog I will describe how to update password from md5 to scram-sha-256.<br />
For the installation of PostgreSQL there are many blogs at dbi or articles from dbi.</p>
<p><a href="https://www.dbi-services.com/blog/handling-postgresql-installation-from-packages-internal-activity/">Blog at dbi-services.com</a><br />
<a href="https://www.heise.de/ratgeber/PostgreSQL-installieren-mit-den-Community-Paketen-4877556.html">Article at heise.de</a></p>
<p>So I will not repeat this steps.</p>
<p>The passwords in PostgreSQL are sotred in the table pg_authid and for this blog i have a user test.</p>
<pre class="brush: sql; gutter: true; first-line: 1">
$ postgres=# select rolpassword from pg_authid where rolname = 'test';
$              rolpassword
$ -------------------------------------
$  md56e4b266b2a0fbaa2c08d61bdefe7ee48
$ (1 row)
$ 
$ postgres=#
</pre>
<p>Visible is that the password is hashed in md5.</p>
<p>Mostly for ip ranges, sometimes also for specified users there is a corosponding entry within pg_hba.conf.</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ # TYPE  DATABASE        USER            ADDRESS                 METHOD
$ host    all             test            127.0.0.1/32            md5
</pre>
<p>At first step we need to switch the parameter password_encryption from md5 to scram-sha-256.</p>
<pre class="brush: sql; gutter: true; first-line: 1">
$ postgres=# alter system set password_encryption = 'scram-sha-256';
$ ALTER SYSTEM
$ postgres=#
</pre>
<p>And activate this change.</p>
<pre class="brush: sql; gutter: true; first-line: 1">
$ postgres=# select pg_reload_conf();
$  pg_reload_conf
$ ----------------
$  t
$ (1 row)
$ 
$ postgres=#
</pre>
<p>But keep the line within pg_hba till all affected passwords are updated.</p>
<p>Updating the passwords to change from md5 to scram-sha-256.</p>
<pre class="brush: sql; gutter: true; first-line: 1">
$ postgres=# alter role test with password 'password';
$ ALTER ROLE
$ postgres=#
</pre>
<p>Check the new hashing.</p>
<pre class="brush: sql; gutter: true; first-line: 1">
$ postgres=# select rolpassword from pg_authid where rolname = 'test';
$                                                               rolpassword
$ ---------------------------------------------------------------------------------------------------------------------------------------
$  SCRAM-SHA-256$4096:OSi8R7U5YM0ejUq982OX/g==$82TTXF0cnuq5puyN1mnpTFsSlkLFPDbP7+3TdxtX0B4=:QCRU75g5bDKONib5s9hwsjJsweeiswkyMBFUG0IF1Ts=
$ (1 row)
$ 
$ postgres=#
</pre>
<p>Now change the entry for this user within pg_hba.conf</p>
<pre class="brush: bash; gutter: true; first-line: 1">
$ # TYPE  DATABASE        USER            ADDRESS                 METHOD
$ host    all             test            127.0.0.1/32            scram-sha-256
</pre>
<p>Reload the configuration of PostgreSQL again.</p>
<pre class="brush: sql; gutter: true; first-line: 1">
$ postgres=# select pg_reload_conf();
$  pg_reload_conf
$ ----------------
$  t
$ (1 row)
$ 
$ postgres=#
</pre>
<p>Now the password encryption change is completed from md5 to scram-sha-256.</p>
<p>In many cases old systems where migrated to a complete new environment, new OS, latest PostgreSQL verion, by using pg_dump and pg_restore.<br />
In this cases all users can be migrated to the new environment by using pg_dumpall -r &gt; users.sql or pg_dumpall &#8211;roles-only &gt; users.sql.<br />
These files can be imported with psql -f users.sql, there will be a error messages that postgres user exits but this can be ignored.<br />
All these imported users will still have the md5 hashed passwords, so it make sense to update these user passwords directly afterwards.</p>
<p>L’article <a href="https://www.dbi-services.com/blog/updating-password-in-postgresql-from-md5-to-scram-sha-256/">Updating Password in PostgreSQL from md5 to scram-sha-256</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/updating-password-in-postgresql-from-md5-to-scram-sha-256/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)

Served from: www.dbi-services.com @ 2026-09-19 08:30:14 by W3 Total Cache
-->