Re: [ClusterLabs] resources cluster stoped with one node

2024-03-21 Thread Tomas Jelinek
Dne 20. 03. 24 v 23:56 Ken Gaillot napsal(a): On Wed, 2024-03-20 at 23:29 +0100, mierdatutis mi wrote: HI, I've configured a cluster of two nodes. When I start one node only I see that the resources won't start. Hi, In a two-node cluster, it is not safe to start resources until the nodes

Re: [ClusterLabs] Upgrade to OLE8 + Pacemaker

2023-10-03 Thread Tomas Jelinek
Dne 03. 10. 23 v 16:24 Jibrail, Qusay (GfK) via Users napsal(a): Hi Reid, Thank you for the answer. So my plan will be: * pcs config backup  /root/"Server Name" * create a backup of /etc/corosync/ * create a backup of /etc/postfix * pcs cluster stop “server3” àjust to do the failover

Re: [ClusterLabs] last man - issue

2023-07-25 Thread Tomas Jelinek
Lejeczek, Thanks for raising this. We'll improve the error message to make it clear that the cluster needs to be stopped in order to proceed. Tomas Dne 24. 07. 23 v 14:22 Michal Pospíšil (he / him) napsal(a): Hello all, One more useful link that I forgot to include in my original reply -

[ClusterLabs] pcs 0.11.6 released

2023-06-21 Thread Tomas Jelinek
, i.e. `pcs resource clone myResource name=value` is deprecated by `pcs resource clone myResource meta name=value` ([rhbz#2168155], [ghpull#648]) Thanks / congratulations to everyone who contributed to this release, including lixin, Michal Pospisil, Miroslav Lisik, Ondrej Mular and Tomas Jelinek

[ClusterLabs] pcs 0.10.17 released

2023-06-20 Thread Tomas Jelinek
-strategy` is not set appropriately) ([rhbz#2112259]) Thanks / congratulations to everyone who contributed to this release, including Michal Pospisil, Miroslav Lisik and Tomas Jelinek. Cheers, Tomas [rhbz#2112259]: https://bugzilla.redhat.com/show_bug.cgi?id=2112259 [rhbz#2166289]: https

Re: [ClusterLabs] Change hacluster password

2023-06-14 Thread Tomas Jelinek
Hi Jérôme, Assuming you are asking about changing 'hacluster' password and its impact to pcs authentication, the answer is that there is no impact and you don't need to re-authenticate your nodes. If you have no tokens or known-hosts in /var/lib/pcsd, then your nodes are not authenticated to

Re: [ClusterLabs] pcs property maintenance mode --wait not supported

2023-06-02 Thread Tomas Jelinek
Dne 02. 06. 23 v 3:33 Reid Wahl napsal(a): On Thu, Jun 1, 2023 at 6:38 AM S Sathish S via Users wrote: Hi Team, The ‘--wait’ option is not supported in pcs property maintenance mode which is working earlier in pcs-0.9.x version. To understand may I know, why --wait option got removed.

Re: [ClusterLabs] HSTS Missing From HTTPS Server on pcs daemon

2023-04-06 Thread Tomas Jelinek
Hi S Sathish S, New pcs-0.10.16 version containing the fix for this issue has just been released upstream. Regards, Tomas Dne 04. 04. 23 v 19:14 S Sathish S napsal(a): Hi Tomas/Team, In our case PCS WEB UI us disabled while accessing PCS WEB UI URL we are getting 404 response, As you

[ClusterLabs] pcs 0.10.16 released

2023-04-06 Thread Tomas Jelinek
any agents do not work with it properly. Use flag '--agent-validation' to enable it in supported commands. ([rhbz#2159455]) Thanks / congratulations to everyone who contributed to this release, including lixin, Lucas Kanashiro, Mamoru TASAKA, Michal Pospisil, Miroslav Lisik, Ondrej Mular, Tom

Re: [ClusterLabs] HSTS Missing From HTTPS Server on pcs daemon

2023-04-04 Thread Tomas Jelinek
Hi S Sathish S, pcs is sending Strict-Transport-Security header since version pcs-0.9.168. There were further fixes in pcs-0.10 branch which you can find in pcs changelog [1]: * in pcs-0.10.5: Added missing Strict-Transport-Security headers to redirects * in pcs-0.10.14: Set

[ClusterLabs] pcs 0.11.5 released

2023-03-02 Thread Tomas Jelinek
]) Thanks / congratulations to everyone who contributed to this release, including lixin, Lucas Kanashiro, Mamoru TASAKA, Michal Pospisil, Miroslav Lisik, Ondrej Mular, Tomas Jelinek and wangluwei. Cheers, Tomas [ghissue#604]: https://github.com/ClusterLabs/pcs/issues/604 [ghpull#559]: https://github.com

Re: [ClusterLabs] Fix for CVE-2022-30123 and CVE-2019-11358

2023-01-31 Thread Tomas Jelinek
Hi A Gunasekar, These CVEs are fixed in pcs-0.10.9 and newer and pcs-0.11.1 and newer (the 0.11 branch was never affected). Regards, Tomas Dne 27. 01. 23 v 9:01 A Gunasekar via Users napsal(a): Hi Tomas/Team, It would be great if you share in which latest cluster lab version the fixed

Re: [ClusterLabs] Fix for CVE-2022-30123 and CVE-2019-11358

2023-01-23 Thread Tomas Jelinek
Hi A Gunasekar, The pcs-0.9 branch is unsupported and no longer maintained since 2021-04-16. There will be no further releases and commits in that branch. Pcs-0.9 only works with Pacemaker 1.x and Corosync 2.x and those have been unsupported for quite some time as well. I recommend updating

Re: [ClusterLabs] multiple resources - pgsqlms - and IP(s)

2023-01-04 Thread Tomas Jelinek
Dne 04. 01. 23 v 8:29 Reid Wahl napsal(a): On Tue, Jan 3, 2023 at 10:53 PM lejeczek via Users wrote: On 03/01/2023 21:44, Ken Gaillot wrote: On Tue, 2023-01-03 at 18:18 +0100, lejeczek via Users wrote: On 03/01/2023 17:03, Jehan-Guillaume de Rorthais wrote: Hi, On Tue, 3 Jan 2023

Re: [ClusterLabs] Fix for CVE-2022-30123 and CVE-2019-11358

2023-01-02 Thread Tomas Jelinek
Hi A Gunasekar, As far as I can see, updated pcs packages pcs-0.9.169-3.el7_9.3 which fix the mentioned CVEs were released on 2022-11-02. Regards, Tomas Dne 21. 12. 22 v 14:28 A Gunasekar via Users napsal(a): Hi Team, Please be informed, we have got notified from our security tool that

Re: [ClusterLabs] PCS WEB UI is not reachable via inside/outside of the server getting "404 Page Not Found" Error

2022-12-15 Thread Tomas Jelinek
Hi S Sathish, It looks like you have disabled the web UI by putting 'PCSD_DISABLE_GUI=true' into pcsd config file ('/etc/default/pcsd' or '/etc/sysconfig/pcsd', depending on your Linux distribution). The 'pcsd.conf' file is not present in pcs-0.10 and pcs-0.11, that is expected. Regards,

[ClusterLabs] pcs 0.11.4 released

2022-11-29 Thread Tomas Jelinek
#2019464]) - `pcs property set/unset` forbid manipulation of specific cluster properties ([rhbz#1620043]) Thanks / congratulations to everyone who contributed to this release, including Fabio M. Di Nitto, Ivan Devat, lixin, Lucas Kanashiro, Michal Pospisil, Miroslav Lisik, Ondrej Mular and Tomas

[ClusterLabs] pcs 0.10.15 released

2022-11-29 Thread Tomas Jelinek
, lixin, Michal Pospisil, Miroslav Lisik, Ondrej Mular and Tomas Jelinek. Cheers, Tomas [rhbz#1791670]: https://bugzilla.redhat.com/show_bug.cgi?id=1791670 [rhbz#1816852]: https://bugzilla.redhat.com/show_bug.cgi?id=1816852 [rhbz#1918527]: https://bugzilla.redhat.com/show_bug.cgi?id=1918527 [rhbz

Re: [ClusterLabs] Pacemaker question

2022-10-05 Thread Tomas Jelinek
Hi, If you are using pcs to setup your cluster, then the answer is no. I'm not sure about crm shell / hawk. Once you have a cluster, you can use users other than hacluster as Ken pointed out. Regards, Tomas Dne 04. 10. 22 v 16:06 Ken Gaillot napsal(a): Yes, see ACLs:

Re: [ClusterLabs] Corosync over dedicated interface?

2022-10-03 Thread Tomas Jelinek
Dne 28. 09. 22 v 18:22 Jehan-Guillaume de Rorthais via Users napsal(a): Hi, A small addendum below. On Wed, 28 Sep 2022 11:42:53 -0400 "Kevin P. Fleming" wrote: On Wed, Sep 28, 2022 at 11:37 AM Dave Withheld wrote: Is it possible to get corosync to use the private network and stop trying

[ClusterLabs] pcs 0.11.3.1 released

2022-09-14 Thread Tomas Jelinek
I am happy to announce the latest release of pcs, version 0.11.3.1. Source code is available at: https://github.com/ClusterLabs/pcs/archive/v0.11.3.1.tar.gz or https://github.com/ClusterLabs/pcs/archive/v0.11.3.1.zip This version fixes a high severity security issue CVE-2022-2735. Complete

[ClusterLabs] pcs 0.10.14.1 released

2022-09-14 Thread Tomas Jelinek
I am happy to announce the latest release of pcs, version 0.10.14.1. Source code is available at: https://github.com/ClusterLabs/pcs/archive/v0.10.14.1.tar.gz or https://github.com/ClusterLabs/pcs/archive/v0.10.14.1.zip This version fixes a high severity security issue CVE-2022-2735. Complete

Re: [ClusterLabs] Fix for CVE-2022-2735 in pcs 0.9 version

2022-09-12 Thread Tomas Jelinek
Hi, As far as I know, pcs-0.9.x isn't affected by CVE-2022-2735. Therefore, no fix for it is planned. Could you explain why you think it is affected? Both main (pcs-0.11) and pcs-0.10 upstream branches do contain the fix. We are working on releasing new versions. In the meantime, you may use

Re: [ClusterLabs] node1 and node2 communication time question

2022-08-09 Thread Tomas Jelinek
Hi, It seems that you are using pcs 0.9.x. That is an old and unmaintained version. I really recommend updating it. I can see that you disabled stonith. This is really a bad practice. Cluster cannot and will not function properly without working stonith. What makes you think nodes are

Re: [ClusterLabs] Cannot add a node with pcs

2022-08-02 Thread Tomas Jelinek
the cluster tries to do? Have you got any other suggestions what to check? Best regards, Piotr On 12.07.2022 12:50, Tomas Jelinek wrote: Hi Piotr, Based on 'pcs cluster node add n2' and 'pcs config' outputs, pcs added the node to your cluster successfully, that is corosync config has been

Re: [ClusterLabs] Cannot add a node with pcs

2022-07-12 Thread Tomas Jelinek
Hi Piotr, Based on 'pcs cluster node add n2' and 'pcs config' outputs, pcs added the node to your cluster successfully, that is corosync config has been modified, distributed and loaded. It looks like the problem is with pacemaker. This is a wild guess, but maybe pacemaker wants to fence

[ClusterLabs] pcs 0.11.3 released

2022-06-24 Thread Tomas Jelinek
([rhbz#2059177]) Thanks / congratulations to everyone who contributed to this release, including Alessandro Barbieri, Ivan Devat, lixin, Michal Pospisil, Miroslav Lisik, Ondrej Mular, Tomas Jelinek and ysf. Cheers, Tomas [ghpull#509]: https://github.com/ClusterLabs/pcs/pull/509 [rhbz#2024522

[ClusterLabs] pcs 0.10.14 released

2022-06-24 Thread Tomas Jelinek
to this release, including Alessandro Barbieri, Ivan Devat, lixin, Michal Pospisil, Miroslav Lisik, Ondrej Mular, Tomas Jelinek and ysf. Cheers, Tomas [ghpull#509]: https://github.com/ClusterLabs/pcs/pull/509 [rhbz#1730232]: https://bugzilla.redhat.com/show_bug.cgi?id=1730232 [rhbz#1786964

Re: [ClusterLabs] No node name in corosync-cmapctl output

2022-05-31 Thread Tomas Jelinek
Dne 31. 05. 22 v 15:34 Jan Friesse napsal(a): Hi, On 31/05/2022 15:16, Andreas Hasenack wrote: Hi, corosync 3.1.6 pacemaker 2.1.2 crmsh 4.3.1 TL;DR I only seem to get a "name" attribute in the "corosync-cmapctl | grep nodelist" output if I set an explicit name in corosync.conf's nodelist. If

Re: [ClusterLabs] Can a two node cluster start resources if only one node is booted?

2022-04-22 Thread Tomas Jelinek
Dne 21. 04. 22 v 17:26 john tillman napsal(a): Dne 20. 04. 22 v 20:21 john tillman napsal(a): On 20.04.2022 19:53, john tillman wrote: I have a two node cluster that won't start any resources if only one node is booted; the pacemaker service does not start. Once the second node boots up, the

Re: [ClusterLabs] Can a two node cluster start resources if only one node is booted?

2022-04-21 Thread Tomas Jelinek
Dne 20. 04. 22 v 20:21 john tillman napsal(a): On 20.04.2022 19:53, john tillman wrote: I have a two node cluster that won't start any resources if only one node is booted; the pacemaker service does not start. Once the second node boots up, the first node will start pacemaker and the

Re: [ClusterLabs] pcs cluster auth with a key instead of password #179

2022-03-30 Thread Tomas Jelinek
Hi, This issue is not planned to be worked on in the near future. It is still on our todo list. However, as of now, I cannot give you any estimate of when the feature would land in pcs. In any case, pcs-0.9 is no longer maintained and therefore the feature will not be added there.

[ClusterLabs] pcs 0.10.12 released

2022-03-24 Thread Tomas Jelinek
`) is missing ([rhbz#1791670], [ghpull#411], [ghissue#225]) Thanks / congratulations to everyone who contributed to this release, including Hideo Yamauchi, Ivan Devat, Michal Pospisil, Miroslav Lisik, Ondrej Mular, Tomas Jelinek and vivi. Cheers, Tomas [ghissue#225]: https://github.com/ClusterLabs/pcs

[ClusterLabs] pcs 0.11.2 released

2022-03-24 Thread Tomas Jelinek
contributed to this release, including Fabio M. Di Nitto, Miroslav Lisik, Ondrej Mular, Tomas Jelinek and Valentin Vidić. Cheers, Tomas [ghissue#441]: https://github.com/ClusterLabs/pcs/issues/441 [ghpull#431]: https://github.com/ClusterLabs/pcs/pull/431 [rhbz#1301204]: https://bugzilla.redhat.com

[ClusterLabs] pcs 0.10.13 released

2022-03-24 Thread Tomas Jelinek
` command ([rhbz#1990784]) - Pcs no longer creates Pacemaker-1.x CIB when `-f` is used, so running `pcs cluster cib-upgrade` manually is not needed ([rhbz#2022463]) Thanks / congratulations to everyone who contributed to this release, including Miroslav Lisik, Ondrej Mular, Tomas Jelinek

[ClusterLabs] pcs 0.11.1 released

2022-03-24 Thread Tomas Jelinek
cluding Hideo Yamauchi, Ivan Devat, Michal Pospisil, Michele Baldessari, Miroslav Lisik, Ondrej Mular, Tomas Jelinek and vivi. Cheers, Tomas [ghissue#225]: https://github.com/ClusterLabs/pcs/issues/225 [ghpull#370]: https://github.com/ClusterLabs/pcs/pull/370 [ghpull#411]: https

Re: [ClusterLabs] PAF with postgresql 13?

2022-03-09 Thread Tomas Jelinek
Dne 08. 03. 22 v 23:08 Ken Gaillot napsal(a): On Tue, 2022-03-08 at 17:20 +0100, Jehan-Guillaume de Rorthais wrote: Hi, Sorry, your mail was really hard to read on my side, but I think I understood and try to answer bellow. On Tue, 8 Mar 2022 11:45:30 + lejeczek via Users wrote: On

Re: [ClusterLabs] Removing a resource without stopping it

2022-01-31 Thread Tomas Jelinek
Hi, The output you posted actually shows the procedure you followed works. Orphan resources are running resources which have no configuration stored in CIB. Usually, they are stopped shortly after they are removed from CIB. If you set stop-orphan-resources to false, pacemaker won't stop

Re: [ClusterLabs] pcs stonith update problems

2021-11-30 Thread Tomas Jelinek
Dne 21. 07. 21 v 19:06 Digimer napsal(a): On 2021-07-21 8:19 a.m., Tomas Jelinek wrote: Dne 16. 07. 21 v 16:30 Digimer napsal(a): On 2021-07-16 9:26 a.m., Tomas Jelinek wrote: Dne 16. 07. 21 v 6:35 Andrei Borzenkov napsal(a): On 16.07.2021 01:02, Digimer wrote: Hi all,     I've got

[ClusterLabs] pcs 0.10.11 released

2021-10-06 Thread Tomas Jelinek
for new role names introduced in pacemaker 2.1 ([rhbz#1885293]) ### Fixed - Traceback in some cases when --wait without timeout is used Thanks / congratulations to everyone who contributed to this release, including Michal Pospisil, Miroslav Lisik, Ondrej Mular and Tomas Jelinek. Cheers, Tomas

Re: [ClusterLabs] pcs stonith update problems

2021-07-21 Thread Tomas Jelinek
Dne 16. 07. 21 v 16:30 Digimer napsal(a): On 2021-07-16 9:26 a.m., Tomas Jelinek wrote: Dne 16. 07. 21 v 6:35 Andrei Borzenkov napsal(a): On 16.07.2021 01:02, Digimer wrote: Hi all,    I've got a predicament... I want to update a stonith resource to remove an argument. Specifically, when

Re: [ClusterLabs] pcs stonith update problems

2021-07-16 Thread Tomas Jelinek
Dne 16. 07. 21 v 6:35 Andrei Borzenkov napsal(a): On 16.07.2021 01:02, Digimer wrote: Hi all, I've got a predicament... I want to update a stonith resource to remove an argument. Specifically, when resource move nodes, I want to change the stonith delay to favour the new host. This involves

Re: [ClusterLabs] pcs update resource command not working

2021-07-13 Thread Tomas Jelinek
Dne 09. 07. 21 v 7:29 S Sathish S napsal(a): Hi Team, we have find the cause of this problem as per below changelog pcs resource update command doesn’t support empty meta_attributes anymore. https://github.com/ClusterLabs/pcs/blob/0.9.169/CHANGELOG.md pcs resource update does not create an

Re: [ClusterLabs] Quorum when reducing cluster from 3 nodes to 2 nodes

2021-06-01 Thread Tomas Jelinek
reported. Regards, Tomas Dne 31. 05. 21 v 20:55 Hayden,Robert napsal(a): -Original Message- From: Users On Behalf Of Tomas Jelinek Sent: Monday, May 31, 2021 6:29 AM To: users@clusterlabs.org Subject: Re: [ClusterLabs] Quorum when reducing cluster from 3 nodes to 2 nodes Hi Robert

Re: [ClusterLabs] Quorum when reducing cluster from 3 nodes to 2 nodes

2021-05-31 Thread Tomas Jelinek
Hi Robert, Can you share your /etc/corosync/corosync.conf file? Also check if it's the same on all nodes. Dne 26. 05. 21 v 17:48 Hayden,Robert napsal(a): I had a SysAdmin reduce the number of nodes in a OL 7.9 cluster from three nodes to two nodes. From internal testing, I found the

Re: [ClusterLabs] 2 node mariadb-cluster - constraint-problems ?

2021-05-18 Thread Tomas Jelinek
Dne 18. 05. 21 v 14:55 fatcha...@gmx.de napsal(a): Gesendet: Dienstag, 18. Mai 2021 um 14:49 Uhr Von: fatcha...@gmx.de An: users@clusterlabs.org Betreff: Re: [ClusterLabs] 2 node mariadb-cluster - constraint-problems ? Hi Andrei,Hi everybody, ... and it works great Thanks for the hint.

Re: [ClusterLabs] multi-state constraints

2021-05-13 Thread Tomas Jelinek
Dne 11. 05. 21 v 20:22 Alastair Basden napsal(a): Single location constraint may have multiple rules, I would assume pcs supports it. It is certainly supported by crmsh. Yes, it is supported by pcs. First, create a location rule constraint with 'pcs constraint location ... rule'. Then you can

Re: [ClusterLabs] multi-state constraints

2021-05-11 Thread Tomas Jelinek
Hi, Dne 11. 05. 21 v 17:31 Andrei Borzenkov napsal(a): On 11.05.2021 18:20, Alastair Basden wrote: Hi, So, I think the following would do it: pcs constraint location resourceClone rule role=master score=100 uname eq node1 pcs constraint location resourceClone rule role=master score=50 uname

Re: [ClusterLabs] Stopping the last node with pcs

2021-04-29 Thread Tomas Jelinek
Hi, sorry for the late answer and thanks everyone who already responded. This feature was implemented a long time ago based on https://bugzilla.redhat.com/show_bug.cgi?id=1180506 The request was: pcs cluster stop -> this operation should verify if removing a node from the cluster will cause

[ClusterLabs] pcs 0.9.170 released

2021-04-16 Thread Tomas Jelinek
]) Thanks / congratulations to everyone who contributed to this release, including Ondrej Mular and Tomas Jelinek. Cheers, Tomas [ghissue#261]: https://github.com/ClusterLabs/pcs/issues/261 [rhbz#1387358]: https://bugzilla.redhat.com/show_bug.cgi?id=1387358 [rhbz#1824206]: https

Re: [ClusterLabs] best practice for scripting

2021-04-13 Thread Tomas Jelinek
Hi, You can use 'pcs cluster cib' for pacemaker configuration and 'pcs cluster status xml' for pacemaker status. Both commands basically just pass xml obtained from pacemaker, though. As far as I know, corosync also provides parsable output, take a look at corosync-cmapctl. I'm not sure

Re: [ClusterLabs] WebSite_start_0 on node2 'error' (1): call=6, status='complete', exitreason='Failed to access httpd status page.'

2021-03-29 Thread Tomas Jelinek
. Then, if a node disconnected then how it could back to the cluster chain? On Monday, March 29, 2021, 06:13:09 PM GMT+4:30, Tomas Jelinek wrote: Hi Jason, Regarding point 3: Most pcs commands operate on the local node. If you stop a cluster on a node, pcs is unable to connect to cluster

Re: [ClusterLabs] WebSite_start_0 on node2 'error' (1): call=6, status='complete', exitreason='Failed to access httpd status page.'

2021-03-29 Thread Tomas Jelinek
Hi Jason, Regarding point 3: Most pcs commands operate on the local node. If you stop a cluster on a node, pcs is unable to connect to cluster daemons on the node (since they are not running) and prints an error message denoting that. This is expected behavior. Regards, Tomas Dne 27. 03.

Re: [ClusterLabs] pacemaker-2.0.x version support on “RHEL 7” OS

2021-03-12 Thread Tomas Jelinek
Hi Sathish, Sorry, I don't know how to get ruby 2.2.0 for RHEL 7. The types of support have been explained by Ken. It has already been said that pcs-0.10 is not supported on RHEL 7. I would recommend to either downgrade to pacemaker 1.x and pcs-0.9, as suggested by Ken, or upgrade your

Re: [ClusterLabs] pacemaker-2.0.x version support on “RHEL 7” OS

2021-03-10 Thread Tomas Jelinek
Hi, The same principles apply to both pcs and pacemaker (and most probably the whole cluster stack). Red Hat only supports the packages it provides, which is pcs-0.9 series in RHEL 7. Even if you manage to install ruby 2.2.0+ and python 3.6+ on RHEL 7 hosts and build and run pcs-0.10 on

Re: [ClusterLabs] pcs resource disable/enable is taking longer time in 32 node cluster setup for all components up and running.

2021-03-08 Thread Tomas Jelinek
Hi, What method are you using to stop all resources? If you run 'pcs resource disable ' in a loop, then it may take time for 300+ resources. By doing it this way, you run pacemaker scheduler for stopping each resource individually. If you want to stop all resources, just run 'pcs property

Re: [ClusterLabs] Updating CIB Question Update does not conform to the configured schema

2021-02-22 Thread Tomas Jelinek
Hi, It seems to me that you defined "virtualip-instance_attributes-secondary_ip_address" id twice. That is not allowed, IDs must be unique. Also note that multiple instance attributes with rules are not supported by pcs. Your CIB will work in general, just don't use pcs to update your

Re: [ClusterLabs] @ - unsupported char - bug or something to improve upon?

2021-02-22 Thread Tomas Jelinek
Hi all, The error message comes from pcs. Pacemaker doesn't allow '@' to be used in a resource name. The name is an XML ID and those cannot contain '@' (and some other) characters. If pcs allowed '@' in the resource name, pacemaker would reject such a CIB. As long as this is the case,

Re: [ClusterLabs] Old pcs-0.9.167/0.9.168/0.9.169 package with newer corosync-3.1 and pacemaker-2.1 on RHEL 7.7

2021-02-08 Thread Tomas Jelinek
Hi, There are significant changes between corosync 2.x and 3.x and similarly between pacemaker 1.x and 2.x. To cover those and support the new versions, we created pcs-0.10 branch. The old versions are supported by pcs-0.9 branch. RHEL 7 ships corosync 2.x and pacemaker 1.x, so we build

Re: [ClusterLabs] pacemaker 2.0.5 version pcs status resources command is not working

2021-02-04 Thread Tomas Jelinek
Hi, pcs-0.9 does not support pacemaker => 2.0.0. You can go with pcs-0.9 + corosync < 3 + pacemaker 1.x OR pcs-0.10 + corosync 3.x + pacemaker 2.x. Combination of corosync 2 + pacemaker 2 is not supported in any pcs version, even though it may work to some degree. Regards, Tomas Dne 03.

[ClusterLabs] pcs 0.10.8 released

2021-02-02 Thread Tomas Jelinek
([rhbz#1851335]) - Entering values starting with '-' (negative numbers) without '--' on command line is now deprecated ([rhbz#1869399]) Thanks / congratulations to everyone who contributed to this release, including Fabio M. Di Nitto, Ivan Devat, Miroslav Lisik, Ondrej Mular and Tomas Jelinek

Re: [ClusterLabs] Stopping all nodes causes servers to migrate

2021-01-26 Thread Tomas Jelinek
Dne 25. 01. 21 v 17:01 Ken Gaillot napsal(a): On Mon, 2021-01-25 at 09:51 +0100, Jehan-Guillaume de Rorthais wrote: Hi Digimer, On Sun, 24 Jan 2021 15:31:22 -0500 Digimer wrote: [...] I had a test server (srv01-test) running on node 1 (el8-a01n01), and on node 2 (el8-a01n02) I ran 'pcs

Re: [ClusterLabs] Stopping a server failed and fenced, despite disabling stop timeout

2021-01-19 Thread Tomas Jelinek
Dne 18. 01. 21 v 20:08 Digimer napsal(a): On 2021-01-18 4:49 a.m., Tomas Jelinek wrote: Hi Digimer, Regarding pcs behavior: When deleting a resource, pcs first sets its target-role to Stopped, pushes the change into pacemaker and waits for the resource to stop. Once the resource stops, pcs

Re: [ClusterLabs] Stopping a server failed and fenced, despite disabling stop timeout

2021-01-18 Thread Tomas Jelinek
Hi Digimer, Regarding pcs behavior: When deleting a resource, pcs first sets its target-role to Stopped, pushes the change into pacemaker and waits for the resource to stop. Once the resource stops, pcs removes the resource from CIB. If pcs simply removed the resource from CIB without

Re: [ClusterLabs] Q: Starting from pcs-0.10.6-4.el8, logs of pcsd are now output to syslog

2021-01-08 Thread Tomas Jelinek
On Fri, Jan 8, 2021 at 1:49 AM Tomas Jelinek wrote: Hi, It took us some time to figure this out, sorry about that. The behavior you see is not intended, it is a bug. The bug originates in commit 966959ac54d80c4cdeeb0fac40dc7ea60c1a0a82, more specifically in this line in pcs/run.py: from

Re: [ClusterLabs] Q: Starting from pcs-0.10.6-4.el8, logs of pcsd are now output to syslog

2021-01-07 Thread Tomas Jelinek
Hi, It took us some time to figure this out, sorry about that. The behavior you see is not intended, it is a bug. The bug originates in commit 966959ac54d80c4cdeeb0fac40dc7ea60c1a0a82, more specifically in this line in pcs/run.py: from pcs.app import main as cli The pcs/app.py file is

Re: [ClusterLabs] Can't have 2 nodes as master with galera resource agent

2020-12-11 Thread Tomas Jelinek
Dne 11. 12. 20 v 15:10 Andrei Borzenkov napsal(a): 11.12.2020 16:13, Raphael Laguerre пишет: Hello, I'm trying to setup a 2 nodes cluster with 2 galera instances. I use the ocf:heartbeat:galera resource agent, however, after I create the resource, only one node appears to be in master role,

Re: [ClusterLabs] Unable to connect to node , no token available

2020-11-06 Thread Tomas Jelinek
Hi Raffaele, Several bugs related to node authentication have been fixed in between Debian 9 and Debian 10 version of pcs. I think you were hitting one of those. Regards, Tomas Dne 02. 11. 20 v 11:06 Raffaele Pantaleoni napsal(a): Hi, I have solved the issue, well...not really though. I

Re: [ClusterLabs] Unable to connect to node , no token available

2020-10-29 Thread Tomas Jelinek
Hi Raffaele, We'll need to know more details: * What is your pcs version? * Which node is used to access web UI? * Which node is the log from? The part of pcsd log you provided doesn't seem to cover the issue you are experiencing. If the node is not authenticated, which seems to be the case

Re: [ClusterLabs] Adding a node to an active cluster

2020-10-29 Thread Tomas Jelinek
Hi Jiagi, Yes, 'pcs cluster node add' can add a node to a cluster which is already running resources. Regards, Tomas Dne 28. 10. 20 v 22:09 Strahil Nikolov napsal(a): pcsd is another layer ontop of the crmd and thus , you need to use the pcs commands to manage the cluster (otherwise the

Re: [ClusterLabs] Adding a node to an active cluster

2020-10-22 Thread Tomas Jelinek
Hi, Have you reloaded corosync configuration after modifying corosync.conf? I don't see it in your procedure. Modifying the config file has no effect until you reload it with 'corosync-cfgtool -R'. It should not be needed to modify CIB and add the new node manually. If everything is done

[ClusterLabs] pcs 0.10.7 released

2020-10-02 Thread Tomas Jelinek
including Ivan Devat, Miroslav Lisik, Ondrej Mular, Reid Wahl and Tomas Jelinek. Cheers, Tomas [ghissue#241]: https://github.com/ClusterLabs/pcs/issues/241 [rhbz#1222691]: https://bugzilla.redhat.com/show_bug.cgi?id=1222691 [rhbz#1741056]: https://bugzilla.redhat.com/show_bug.cgi?id=1741056 [

Re: [ClusterLabs] Antw: [EXT] Re: Format of '--lifetime' in 'pcs resource move'

2020-08-25 Thread Tomas Jelinek
Hi all, The lifetime value is indeed expected to be ISO 8601 duration. I updated pcs documentation to clarify that: https://github.com/ClusterLabs/pcs/commit/1e9650a8fd5b8a0a22911ddca1010de582684971 Please note constraints are not removed from CIB when their lifetime expires. They are

Re: [ClusterLabs] How to specify which IP pcs should use?

2020-08-11 Thread Tomas Jelinek
Hi Mariusz, You haven't mention pcs version you are running. Based on you mentioning running Pacemaker 2, I suppose you are running pcs 0.10.x. The text bellow applies to pcs 0.10.x. Pcs doesn't depend on or use corosync.conf when connecting to other nodes. The reason is pcs must be able to

Re: [ClusterLabs] unable to start corosync

2020-07-02 Thread Tomas Jelinek
Hello, It's really hard to tell without any further info. Have you run any other pcs commands before running "cluster start"? Can you share your /etc/corosync/corosync.conf file and logs /var/log/pacemaker/pacemaker.log ? Regards, Tomas Dne 01. 07. 20 v 13:47 Филипп Линецкий napsal(a):

Re: [ClusterLabs] JQuery 1.2 < 3.5.0 Multiple XSS Vulnerability on PCS module

2020-07-02 Thread Tomas Jelinek
Hello, See my response in the "jquery in pcs package" thread. Let's continue the discussion there. Regards, Tomas Dne 01. 07. 20 v 15:35 S Sathish S napsal(a): Hi Team, We are getting below vulnerable alert while using pcs module , can we know mitigation plan or any corrective action

Re: [ClusterLabs] jquery in pcs package

2020-07-02 Thread Tomas Jelinek
Hello, Pcs team understand your concerns about jQuery bundled in pcs / pcsd. Unfortunately, it is not possible to upgrade this jQuery library to a newer version right now. We are, however, very well aware this is a problem. We have been working on a new version of the web UI which will be

Re: [ClusterLabs] custom cluster module

2020-06-16 Thread Tomas Jelinek
This error comes from pcs. It means: Your resource's metadata define an option named 'binfile' and the resource cannot run when this option is not specified. (This is done by in metadata.) Moreover, you tried to create the resource without specifying a value for the 'binfile' option. So

Re: [ClusterLabs] Missing or Permissive Content-Security-Policy frameancestors HTTP Response Header in pcsd

2020-05-22 Thread Tomas Jelinek
Hi, We added sending the Content-Security-Policy in commits: https://github.com/ClusterLabs/pcs/commit/d76924fda6574cdcdac4fc75f433dd58ae48cb2e and https://github.com/ClusterLabs/pcs/commit/76aa72a67d2f89c3f725a6e9187631c270e5bb0c Regards, Tomas Dne 19. 05. 20 v 10:06 Tomas Jelinek napsal

Re: [ClusterLabs] Missing or Permissive Content-Security-Policy frameancestors HTTP Response Header in pcsd

2020-05-19 Thread Tomas Jelinek
Hi, Even if you disable the pcsd GUI, the daemon is still running and listening on port 2224. It is needed for pcs to be able to communicate with and manage cluster nodes. The fact the page is accessible is expected. What pcs version are you running? Regards, Tomas Dne 18. 05. 20 v 9:25

Re: [ClusterLabs] Off-line build-time cluster configuration

2020-04-24 Thread Tomas Jelinek
built unofficial packages, they are not guaranteed to work flawlessly. Regards, Tomas Dne 16. 04. 20 v 14:00 Tomas Jelinek napsal(a): Hi Craig, Currently, there is no support in RHEL8 for an equivalent of the --local option of the 'pcs cluster setup' command from RHEL7. We were focusing

Re: [ClusterLabs] Off-line build-time cluster configuration

2020-04-16 Thread Tomas Jelinek
Hi Craig, Currently, there is no support in RHEL8 for an equivalent of the --local option of the 'pcs cluster setup' command from RHEL7. We were focusing higher priority tasks related to supporting the new major version of corosync and knet. As a part of this, the 'pcs cluster setup' command

[ClusterLabs] pcs 0.9.169 released

2020-04-14 Thread Tomas Jelinek
resources for `pcs (resource | stonith) (cleanup | refresh)` ([rhbz#1759269]) ### Changed - Pcsd no longer sends Server HTTP header ([rhbz#1765606]) Thanks / congratulations to everyone who contributed to this release, including Ivan Devat, Ondrej Mular and Tomas Jelinek. Cheers, Tomas [rhbz

Re: [ClusterLabs] Integrate external alerts with pcs cluster

2020-04-14 Thread Tomas Jelinek
Hi Ajay, Dne 11. 04. 20 v 13:04 Ajay Srivastava napsal(a): Hi, In my environment I have a pacemaker cluster running which has various software services as resource agents. These services have dependency on some hardware components. There is a service which monitors the hardware and sends

Re: [ClusterLabs] pcs cluster auth succeeds but pcs cluster setup failed with"error checking node availability: Unable to authenticate ..."

2020-03-09 Thread Tomas Jelinek
Hi Ken, It looks like you are hitting this bug: https://bugs.launchpad.net/ubuntu/+source/pcs/+bug/1640923 Try removing /etc/corosync/corosync.conf on both your nodes and run the commands again. More info regarding the bug: https://bugzilla.redhat.com/show_bug.cgi?id=1517333

Re: [ClusterLabs] pacemaker certificate is not generated with SubjectAlternativeName

2020-03-02 Thread Tomas Jelinek
Dne 28. 02. 20 v 8:06 S Sathish S napsal(a): Hi Team, We have found that the Pacemaker certificate is not generated with SubjectAlternativeName. You are right, SubjectAlternativeName is not specified. Minor correction though, it's pcsd certificate, not pacemaker. Please find the general

Re: [ClusterLabs] PCS cluster auth fails

2020-02-07 Thread Tomas Jelinek
Hi, I haven't seen such a traceback before. It looks like there are pcsd files missing (/usr/lib/pcsd/vendor/bundle/ruby/gems/rack-1.6.10/lib/rack/multipart/parser.rb). Is this the case? If so, can you try reinstalling pcs packages on your nodes? Regards, Tomas Dne 07. 02. 20 v 7:39

[ClusterLabs] pcs 0.10.4 released

2019-11-28 Thread Tomas Jelinek
are present in the corosync.conf file ([rhbz#1741586]) Thanks / congratulations to everyone who contributed to this release, including Ivan Devat, Michal Pospisil, Miroslav Lisik, Ondrej Mular and Tomas Jelinek. Cheers, Tomas [rhbz#1442116]: https://bugzilla.redhat.com/show_bug.cgi?id=1442116 [rhbz

Re: [ClusterLabs] "pcs resource show --full" equivalent

2019-10-29 Thread Tomas Jelinek
Hi, The command has been deprecated. It still works with the most recent pcs: $ pcs resource show --full Warning: This command is deprecated and will be removed. Please use 'pcs resource config' instead. Resource: d3 (class=ocf provider=pacemaker type=Dummy) Operations: migrate_from

Re: [ClusterLabs] Q: The effect of using "default" attribute in RA metadata

2019-09-05 Thread Tomas Jelinek
Dne 03. 09. 19 v 11:27 Ulrich Windl napsal(a): Hi! Reading the RA API metadata specification, there is a "default" attribute for "parameter". I wonder what the effect of specifying a default is: Is it purely documentation (and the RA has to take care it uses the same default value as in the

Re: [ClusterLabs] Command to show location constraints?

2019-08-28 Thread Tomas Jelinek
Dne 28. 08. 19 v 6:07 Andrei Borzenkov napsal(a): 27.08.2019 18:24, Casey & Gina пишет: Hi, I'm looking for a way to show just location constraints, if they exist, for a cluster. I'm looking for the same data shown in the output of `pcs config` under the "Location Constraints:" header, but

[ClusterLabs] pcs 0.10.3 released

2019-08-26 Thread Tomas Jelinek
- Command `pcs resource bundle reset` no longer accepts the container type ([rhbz#1657166]) Thanks / congratulations to everyone who contributed to this release, including Ivan Devat, Michal Pospisil, Ondrej Mular and Tomas Jelinek. Cheers, Tomas [ghissue#206]: https://github.com/ClusterLabs/pcs

[ClusterLabs] pcs 0.9.168 released

2019-08-13 Thread Tomas Jelinek
ions to everyone who contributed to this release, including Ivan Devat, Ondrej Mular and Tomas Jelinek Cheers, Tomas [rhbz#1466088]: https://bugzilla.redhat.com/show_bug.cgi?id=1466088 [rhbz#1500012]: https://bugzilla.redhat.com/show_bug.cgi?id=1500012 [rhbz#1551663]: https://bugzilla.redhat.com/show_bug.

Re: [ClusterLabs] Adding HAProxy as a Resource

2019-07-25 Thread Tomas Jelinek
is available for haproxy but the pcs resource standard command does not list systemd standard . Also I am not using the pacemaker packages from redhat. I am using the packages downloaded from clusterlabs. With Regards Somanath Thilak J -Original Message- From: Tomas Jelinek Sent

Re: [ClusterLabs] Adding HAProxy as a Resource

2019-07-15 Thread Tomas Jelinek
Hi, Do you have a systemd unit file for haproxy installed? Does 'crm_resource --list-standards' print 'systemd'? Does 'crm_resource --list-agents systemd' print 'haproxy'? Note that when you use full agent name (that is including : ) it is case sensitive in pcs. Regards, Tomas Dne 11. 07.

Re: [ClusterLabs] [EXTERNAL] What's the best practice to scale-out/increase the cluster size?

2019-07-15 Thread Tomas Jelinek
Dne 11. 07. 19 v 16:01 Michael Powell napsal(a): Thanks again for the feedback. As a novice to Pacemaker, I am learning a great deal and have a great deal more to learn. I'm afraid I was not precise in my choice of the term "stand-alone". As you point out, our situation is really case b)

Re: [ClusterLabs] "node is unclean" leads to gratuitous reboot

2019-07-15 Thread Tomas Jelinek
Dne 09. 07. 19 v 14:54 Michael Powell napsal(a): ... Here’s the configuration, from the first node – [root@mgraid-16201289RN00023-0 bin]# pcs config Cluster Name: Corosync Nodes: mgraid-16201289RN00023-0 mgraid-16201289RN00023-1 Pacemaker Nodes: mgraid-16201289RN00023-0

Re: [ClusterLabs] PCSD - High Memory Usage

2019-06-27 Thread Tomas Jelinek
Hi, We (pcs developers) do not have any statistics regarding pcsd memory consumption on a cluster with that many nodes and resources. So I cannot confirm if this is normal or not. That being said, it seems to me the memory usage is higher than it should be. Over the time, there has been

[ClusterLabs] pcs 0.10.2 released

2019-06-13 Thread Tomas Jelinek
`pcs resource show`, removed in pcs-0.10.1, has been readded as deprecated to ease transition to its replacements. It will be removed again in future. [rhbz#1661059] Thanks / congratulations to everyone who contributed to this release, including Ivan Devat, Ondrej Mular, Tomas Jelinek and V

Re: [ClusterLabs] Antw: Re: Question on permissions for pcsd ghost files

2019-04-23 Thread Tomas Jelinek
Dne 23. 04. 19 v 13:26 Ulrich Windl napsal(a): Tomas Jelinek schrieb am 23.04.2019 um 12:36 in Nachricht : The files are listed as ghost files in order to let rpm know they belong to pcs but are not distributed in rpm packages. Those files are created by pcsd in runtime. I guess the 000

  1   2   >