Corosync Config
Transport Configuration¶
Corosync supports multiple transport protocols, with UDP and TCP being the most common. The choice depends on network latency requirements and infrastructure constraints.
TCP Transport¶
TCP is the default and most widely used transport. Configure it in /etc/corosync/corosync.conf under the totem section:
interface specifies the network interface (e.g., eth0) or CIDR notation for multi-interface setups.
- Ensure all nodes use the same interface value and are reachable via TCP.
UDP Transport¶
UDP offers lower latency but requires a dedicated multicast network. Configure as:
-mcastaddr and mcastport define the multicast address/port.
- Nodes must be on the same subnet and support multicast traffic.
Authentication Configuration¶
Corosync uses cryptographic authentication to prevent unauthorized nodes from joining the cluster. The default auth method is none, but hmac or sha1 is recommended for production environments.
Generating Authentication Keys¶
Run corosync-keygen to create a shared key:
authkey file in /etc/corosync/. Copy this file to all cluster nodes and ensure permissions are set to 600.
Configuring Authentication¶
Update /etc/corosync/corosync.conf:
authkey with the actual path to your key file.
- Ensure the key file is identical across all nodes and has strict permissions.
Node Discovery Configuration¶
Corosync discovers nodes via multicast (preferred) or unicast (explicit IP listing). Multicast simplifies setup but requires a multicast-capable network.
Multicast Discovery¶
Configure multicast in /etc/corosync/corosync.conf:
[totem]
transport: tcp
interface: 192.168.1.0/24
mcastaddr: 239.1.1.1
mcastport: 5405
ringnumber: 0
bindnetaddr: 192.168.1.0
ringnumber defines the multicast ring (use 0 for default).
- bindnetaddr restricts communication to the specified subnet.
Unicast Discovery¶
For unicast, explicitly list all nodes in the nodes section:
Post-Configuration Steps¶
-
Validate Configuration:
This checks for syntax errors and connectivity issues. -
Restart Corosync:
Ensure the service starts without errors: -
Verify Cluster Status: Use
crm_monorpcs statusto confirm nodes are communicating and the cluster is active.
Key takeaways¶
- Transport: Use TCP for reliability or UDP for low-latency multicast networks.
- Authentication: Always enable
hmacorsha1with a sharedauthkeyfile. - Node Discovery: Prefer multicast for simplicity, but use unicast if multicast is unavailable.
- Consistency: Ensure all nodes have identical
corosync.confandauthkeyfiles. - Testing: Validate configurations with
corosync-configureand monitor cluster health post-deployment.