Corosync Overview
Corosync is the messaging layer that underpins communication between nodes in a high-availability cluster, forming the foundation of Pacemaker’s coordination framework. It ensures reliable, secure, and efficient message exchange across cluster members, enabling consensus, resource management, and fault detection. Understanding Corosync’s architecture and configuration is critical for building resilient clusters.
Corosync Messaging Layer¶
The Corosync messaging layer abstracts the underlying network infrastructure, providing a consistent interface for cluster communication. It handles tasks such as message routing, redundancy, and fault tolerance, ensuring that critical cluster data (e.g., resource states, fencing decisions) is delivered reliably even in the face of network partitions or node failures.
Key features include:
- Redundancy: Multiple transport protocols can be configured to ensure communication resilience.
- Security: Corosync supports cryptographic authentication to prevent unauthorized nodes from joining the cluster.
Example: To verify the messaging layer’s status, use:
Transport Protocols¶
Corosync supports multiple transport protocols, each suited to different network environments and requirements:
| Protocol | Description | Use Case |
|---|---|---|
| UDP | Low-latency, best-effort delivery. Ideal for local networks with minimal packet loss. | Small clusters with stable connectivity. |
| TCP | Reliable, ordered delivery. Suitable for WANs or unreliable networks. | Clusters with intermittent connectivity. |
| TLS | Encrypted communication over TCP. Ensures data confidentiality and integrity. | Secure, public-facing clusters. |
To configure the transport protocol, edit /etc/corosync/corosync.conf and set the transport parameter:
Configuration Essentials¶
The corosync.conf file defines cluster-wide settings, including transport parameters, node definitions, and security policies. Critical configuration elements include:
bindnetaddr: Specifies the network interface IP address for communication.cluster_name: Identifies the cluster to other Corosync instances.authentication: Enables cryptographic authentication (e.g.,authkeyfor key-based authentication).
Example corosync.conf snippet:
nodelist {
node {
ringid: 0
nodeid: 1
name: node1
}
node {
ringid: 0
nodeid: 2
name: node2
}
}
transport: udp
bindnetaddr: 192.168.1.100
cluster_name: mycluster
authentication: on
To generate the authentication key, run:
Key takeaways¶
- Corosync provides the messaging infrastructure for cluster communication, ensuring reliability and security.
- Transport protocols (UDP, TCP, TLS) determine how nodes exchange data, with trade-offs between latency and reliability.
- Proper configuration of
corosync.confis essential for defining cluster behavior, security, and network settings. - Regularly validate the Corosync configuration and monitor its status to ensure cluster stability.