Skip to content

Corosync Config

Transport Configuration

Corosync supports multiple transport protocols, with UDP and TCP being the most common. The choice depends on network latency requirements and infrastructure constraints.

TCP Transport

TCP is the default and most widely used transport. Configure it in /etc/corosync/corosync.conf under the totem section:

[totem]
    transport: tcp
    interface: 192.168.1.0/24
- interface specifies the network interface (e.g., eth0) or CIDR notation for multi-interface setups. - Ensure all nodes use the same interface value and are reachable via TCP.

UDP Transport

UDP offers lower latency but requires a dedicated multicast network. Configure as:

[totem]
    transport: udp
    mcastaddr: 239.1.1.1
    mcastport: 5405
    interface: 192.168.1.0/24
- mcastaddr and mcastport define the multicast address/port. - Nodes must be on the same subnet and support multicast traffic.


Authentication Configuration

Corosync uses cryptographic authentication to prevent unauthorized nodes from joining the cluster. The default auth method is none, but hmac or sha1 is recommended for production environments.

Generating Authentication Keys

Run corosync-keygen to create a shared key:

sudo corosync-keygen
This generates a authkey file in /etc/corosync/. Copy this file to all cluster nodes and ensure permissions are set to 600.

Configuring Authentication

Update /etc/corosync/corosync.conf:

[totem]
    transport: tcp
    interface: 192.168.1.0/24
    auth: hmac
    authkey: /etc/corosync/authkey
- Replace authkey with the actual path to your key file. - Ensure the key file is identical across all nodes and has strict permissions.


Node Discovery Configuration

Corosync discovers nodes via multicast (preferred) or unicast (explicit IP listing). Multicast simplifies setup but requires a multicast-capable network.

Multicast Discovery

Configure multicast in /etc/corosync/corosync.conf:

[totem]
    transport: tcp
    interface: 192.168.1.0/24
    mcastaddr: 239.1.1.1
    mcastport: 5405
    ringnumber: 0
    bindnetaddr: 192.168.1.0
- ringnumber defines the multicast ring (use 0 for default). - bindnetaddr restricts communication to the specified subnet.

Unicast Discovery

For unicast, explicitly list all nodes in the nodes section:

[cluster]
    node: node1
    node: node2
    node: node3
- Ensure all nodes are reachable via TCP and have consistent IP addresses.


Post-Configuration Steps

  1. Validate Configuration:

    sudo corosync-configure --verify
    
    This checks for syntax errors and connectivity issues.

  2. Restart Corosync:

    sudo systemctl restart corosync
    
    Ensure the service starts without errors:
    sudo systemctl status corosync
    

  3. Verify Cluster Status: Use crm_mon or pcs status to confirm nodes are communicating and the cluster is active.


Key takeaways

  • Transport: Use TCP for reliability or UDP for low-latency multicast networks.
  • Authentication: Always enable hmac or sha1 with a shared authkey file.
  • Node Discovery: Prefer multicast for simplicity, but use unicast if multicast is unavailable.
  • Consistency: Ensure all nodes have identical corosync.conf and authkey files.
  • Testing: Validate configurations with corosync-configure and monitor cluster health post-deployment.