跳转到主要内容

pg_circuit

针对危险 SQL 语句提供运行时观察、告警和拦截

概览

扩展包名版本分类许可证语言
pg_circuit0.1.0ADMINApache-2.0C
ID扩展名BinLibLoadCreateTrustReloc模式
5815pg_circuit否是是是否否-

Requires shared_preload_libraries and restart; Community runtime pressure is informational.

版本

类型仓库版本PG 大版本包名依赖
EXTPIGSTY0.1.01817161514pg_circuit-
RPMPIGSTY0.1.01817161514pg_circuit_$v-
DEBPIGSTY0.1.01817161514postgresql-$v-pg-circuit-
OS / PGPG18PG17PG16PG15PG14
el8.x86_64N/AN/A
el8.aarch64N/AN/A
el9.x86_64N/AN/A
el9.aarch64N/AN/A
el10.x86_64N/AN/A
el10.aarch64N/AN/A
d12.x86_64N/AN/A
d12.aarch64
PIGSTY 0.1.0
PIGSTY 0.1.0
PIGSTY 0.1.0
N/AN/A
d13.x86_64
PIGSTY 0.1.0
PIGSTY 0.1.0
PIGSTY 0.1.0
N/AN/A
d13.aarch64
PIGSTY 0.1.0
PIGSTY 0.1.0
PIGSTY 0.1.0
N/AN/A
u22.x86_64
PIGSTY 0.1.0
PIGSTY 0.1.0
PIGSTY 0.1.0
N/AN/A
u22.aarch64
PIGSTY 0.1.0
PIGSTY 0.1.0
PIGSTY 0.1.0
N/AN/A
u24.x86_64
PIGSTY 0.1.0
PIGSTY 0.1.0
PIGSTY 0.1.0
N/AN/A
u24.aarch64
PIGSTY 0.1.0
PIGSTY 0.1.0
PIGSTY 0.1.0
N/AN/A
u26.x86_64N/AN/A
u26.aarch64
PIGSTY 0.1.0
PIGSTY 0.1.0
PIGSTY 0.1.0
N/AN/A

构建

您可以使用 pig build 命令构建 pg_circuit 扩展的 RPM / DEB 包:

pig build pkg pg_circuit         # 构建 RPM / DEB 包

安装

您可以直接安装 pg_circuit 扩展包的预置二进制包,首先确保 PGDG 和 PIGSTY 仓库已经添加并启用:

pig repo add pgsql -u          # 添加仓库并更新缓存

使用 pig 或者是 apt/yum/dnf 安装扩展:

安装
pig install pg_circuit;          # 当前活跃 PG 版本安装
pig
pig ext install -y pg_circuit -v 18  # PG 18
pig ext install -y pg_circuit -v 17  # PG 17
pig ext install -y pg_circuit -v 16  # PG 16
dnf
dnf install -y pg_circuit_18       # PG 18
dnf install -y pg_circuit_17       # PG 17
dnf install -y pg_circuit_16       # PG 16
apt
apt install -y postgresql-18-pg-circuit   # PG 18
apt install -y postgresql-17-pg-circuit   # PG 17
apt install -y postgresql-16-pg-circuit   # PG 16

预加载配置:

shared_preload_libraries = 'pg_circuit';

创建扩展:

CREATE EXTENSION pg_circuit;

用法

来源:

pg_circuit 在 PostgreSQL 16–18 中检查有风险的 DML 和 DDL。社区版可以观察、告警或阻止语句。先将其加入 shared_preload_libraries 并重启 PostgreSQL,再以超级用户创建扩展。

基础保护

shared_preload_libraries = 'pg_circuit'
CREATE EXTENSION pg_circuit;
CREATE TABLE circuit_demo (id integer);
INSERT INTO circuit_demo VALUES (1);
SET pg_circuit.mode = 'enforce';
DELETE FROM circuit_demo; -- blocked
DELETE FROM circuit_demo WHERE id = 1;
SELECT * FROM pg_circuit_status();

配置与诊断

pg_circuit.mode 默认为告警模式;观察模式只计算风险,强制模式阻止评分达到配置阈值的语句。pg_circuit_runtime_state() 报告压力信号,pg_circuit_events() 展示近期事件。

社区版的有效运行模式始终为 NORMAL,压力读数不会自动提升拦截力度。扩展是策略辅助工具,数据保护仍取决于应用事务、授权和备份。启用强制模式前应使用代表性查询检查规则和阈值。

这个页面对您有帮助吗?