{"Entry":{"collection":"guc","key":"recovery_end_command","name":"recovery_end_command","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Write-Ahead Log / Archive Recovery","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"11","status":"added","to":"12"},{"documentation_changed":true,"fields":{},"from":"18","status":"changed","to":"19"}],"content_hash":"8515d40240655188685e981bf2660696cd9c672548db15133d81b5a9fb95291d","context":"","default_changed_in":[],"default_history":[{"from":"12","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Provision archive throughput and capacity for bulk-load WAL peaks. If archiving falls behind, throttle the job and alert; never hide backlog with false success or aggressive cleanup.","oltp":"Manage recovery_end_command as part of the backup/restore protocol: the command or module must be idempotent, fail visibly, and be verified by restoring from the real archive—not merely by exit status.","small":"Enable it only for a defined PITR requirement and use a mature backup tool. Keep rebuildable instances simple, but never install a no-op command that creates the illusion of a backup."},"mechanism":["Sets the shell command that will be executed once at the end of recovery. A configuration reload applies a new value; existing work already in flight is not retroactively changed.","PostgreSQL runs this shell command once when archive recovery finishes or a standby is promoted. %r expands to the last restart-point file name; command failure is logged but must not be treated as a transactional post-promotion hook.","Monitor and change recovery_end_command together with archive_mode, archive_command, archive_library. Validate on the relevant server role and real workload, then use its sighup context to choose session change, reload, or restart; a historical boot default is not the current effective value."],"pitfalls":["Treating the shell command as a transactional promotion hook whose failure rolls recovery back.","Misreading %r and deleting WAL still needed by another recovery consumer.","Using non-idempotent external side effects without accounting for promotion and recovery retries.","Assuming a reload executes the command; it runs once when archive recovery ends.","Embedding credentials or unsafe shell expansion in a command executed by the PostgreSQL service account."],"references":[{"title":"PostgreSQL 19 Beta 4: recovery_end_command","url":"https://www.postgresql.org/docs/19/runtime-config-wal.html#GUC-RECOVERY-END-COMMAND"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["archive_mode","archive_command","archive_library","archive_timeout","archive_cleanup_command","restore_command"],"summary":"recovery_end_command sets the shell command that will be executed once at the end of recovery. It is a sighup setting present in PG12–18; the latest recorded boot default is empty."},"enumvals":[],"first_version":"12","group":"Write-Ahead Log","group_slug":"wal","imported_at":"2026-09-27T17:57:31.860297+08:00","intro_commit":{"authored_at":"2018-11-25T16:31:16+01:00","discussion":["https://www.postgresql.org/message-id/flat/607741529606767@web3g.yandex.ru/"],"hash":"2dedf4d9a899b36d1a8ed29be5efbd1b31a8fe85","subject":"Integrate recovery.conf into postgresql.conf","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=2dedf4d9a899b36d1a8ed29be5efbd1b31a8fe85"},"key":"recovery_end_command","last_version":"20","max_val":"","min_val":"","name":"recovery_end_command","position":321,"present_in":["12","13","14","15","16","17","18","19","20"],"short_desc":"This parameter specifies a shell command that will be executed once only at the end of recovery.","short_desc_zh":"","source_rev":"english-manuals:bf8c29973f1b56197a7d190f3d6a8b0d3c3deb12e730faae8f975e30fc639509","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"recovery_end_command","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"recovery_end_command","SourceRevision":"english-manuals:bf8c29973f1b56197a7d190f3d6a8b0d3c3deb12e730faae8f975e30fc639509","Facts":{"boot_val":"","category":"Write-Ahead Log / Archive Recovery","context":"sighup","description":"This parameter specifies a shell command that will be executed once only at the end of recovery. This parameter is optional. The purpose of the recovery_end_command is to provide a mechanism for cleanup following replication or recovery. Any %r is replaced by the name of the file containing the last valid restart point, like in archive_cleanup_command. If the command returns a nonzero exit status then a warning log message will be written and the database will proceed to start up anyway. An exception is that if the command was terminated by a signal or an error by the shell (such as command not found), the database will not proceed with startup. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-RECOVERY-END-COMMAND","file":"runtime-config-wal.html","lang":"en","sha256":"d2646404a06e8f7ac655204b4f28c049ae8f3fd4f2272db080fcefa2c4af0763","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"recovery_end_command","short_desc":"Sets the shell command that will be executed once at the end of recovery.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-RECOVERY-END-COMMAND","file":"runtime-config-wal.html","lang":"en","sha256":"d2646404a06e8f7ac655204b4f28c049ae8f3fd4f2272db080fcefa2c4af0763","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"recovery_end_command","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"recovery_end_command","Summary":"","BodyHTML":"\u003cp\u003e这个参数指定了一个将只在恢复末尾被执行一次的 shell 命令。这个参数是可选的。\u003ccode\u003erecovery_end_command\u003c/code\u003e的目的是为复制或恢复之后的清除提供一种机制。与\u003ca href=\"/docs/18/runtime-config-wal.html#GUC-ARCHIVE-CLEANUP-COMMAND\" rel=\"nofollow\"\u003earchive_cleanup_command\u003c/a\u003e中相似，任何\u003ccode\u003e%r\u003c/code\u003e会被替换为包含最后一个可用重启点的文件的名称。\u003c/p\u003e\u003cp\u003e如果该命令返回一个非零退出状态，则一个警告日志消息将被写出并且不管怎样该数据库将继续启动。一个例外是如果该命令被一个信号或者 shell 错误（例如命令未找到）中止，该数据库将不会继续启动。\u003c/p\u003e\u003cp\u003e这个参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e文件中或通过服务器命令行进行设置。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"8bc2950d8c56c12109790ba9360bc1dbad475e85b5b49c804d892511c4602e2b","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e这个参数指定了一个将只在恢复末尾被执行一次的 shell 命令。这个参数是可选的。\u003ccode class=\"varname\"\u003erecovery_end_command\u003c/code\u003e的目的是为复制或恢复之后的清除提供一种机制。与\u003ca href=\"/docs/18/runtime-config-wal.html#GUC-ARCHIVE-CLEANUP-COMMAND\"\u003earchive_cleanup_command\u003c/a\u003e中相似，任何\u003ccode class=\"literal\"\u003e%r\u003c/code\u003e会被替换为包含最后一个可用重启点的文件的名称。\u003c/p\u003e\u003cp\u003e如果该命令返回一个非零退出状态，则一个警告日志消息将被写出并且不管怎样该数据库将继续启动。一个例外是如果该命令被一个信号或者 shell 错误（例如命令未找到）中止，该数据库将不会继续启动。\u003c/p\u003e\u003cp\u003e这个参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e文件中或通过服务器命令行进行设置。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["12","13","14","15","16","17","18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
