Skip to content

Corosync Overview

Corosync is the messaging layer that underpins communication between nodes in a high-availability cluster, forming the foundation of Pacemaker’s coordination framework. It ensures reliable, secure, and efficient message exchange across cluster members, enabling consensus, resource management, and fault detection. Understanding Corosync’s architecture and configuration is critical for building resilient clusters.

Corosync Messaging Layer

The Corosync messaging layer abstracts the underlying network infrastructure, providing a consistent interface for cluster communication. It handles tasks such as message routing, redundancy, and fault tolerance, ensuring that critical cluster data (e.g., resource states, fencing decisions) is delivered reliably even in the face of network partitions or node failures.

Key features include:
- Redundancy: Multiple transport protocols can be configured to ensure communication resilience.
- Security: Corosync supports cryptographic authentication to prevent unauthorized nodes from joining the cluster.

Example: To verify the messaging layer’s status, use:

corosync status

Transport Protocols

Corosync supports multiple transport protocols, each suited to different network environments and requirements:

Protocol Description Use Case
UDP Low-latency, best-effort delivery. Ideal for local networks with minimal packet loss. Small clusters with stable connectivity.
TCP Reliable, ordered delivery. Suitable for WANs or unreliable networks. Clusters with intermittent connectivity.
TLS Encrypted communication over TCP. Ensures data confidentiality and integrity. Secure, public-facing clusters.

To configure the transport protocol, edit /etc/corosync/corosync.conf and set the transport parameter:

transport: udp

Configuration Essentials

The corosync.conf file defines cluster-wide settings, including transport parameters, node definitions, and security policies. Critical configuration elements include:

  • bindnetaddr: Specifies the network interface IP address for communication.
  • cluster_name: Identifies the cluster to other Corosync instances.
  • authentication: Enables cryptographic authentication (e.g., authkey for key-based authentication).

Example corosync.conf snippet:

nodelist {
    node {
        ringid: 0
        nodeid: 1
        name: node1
    }
    node {
        ringid: 0
        nodeid: 2
        name: node2
    }
}
transport: udp
bindnetaddr: 192.168.1.100
cluster_name: mycluster
authentication: on

To generate the authentication key, run:

corosync-keygen

Key takeaways

  • Corosync provides the messaging infrastructure for cluster communication, ensuring reliability and security.
  • Transport protocols (UDP, TCP, TLS) determine how nodes exchange data, with trade-offs between latency and reliability.
  • Proper configuration of corosync.conf is essential for defining cluster behavior, security, and network settings.
  • Regularly validate the Corosync configuration and monitor its status to ensure cluster stability.