Andrew Mercer
on this page

5. Fencing (STONITH)

Do this properly for anything beyond a throwaway lab. Quorum tells the cluster whether it's allowed to act; fencing is what actually guarantees a lost node isn't still holding a resource. no-quorum-policy and stonith-enabled=false are lab shortcuts, not a production configuration.

pcs stonith create node1-fence fence_ipmilan \
    pcmk_host_list=node1 ipaddr=<bmc-ip> login=admin passwd=<pw> lanplus=1
pcs property set stonith-enabled=true

For libvirt/KVM lab clusters, fence_virt/fence_xvm fences guest VMs via the hypervisor instead of IPMI:

# On the KVM HOST (not the cluster VMs):
yum install -y fence-virt fence-virtd fence-virtd-multicast fence-virtd-libvirtd
fence_virtd -c

See https://wiki.clusterlabs.org/wiki/Guest_Fencing for the full setup.

Inspect / manage:

pcs stonith show --full
pcs describe <stonith_agent> [--full]
pcs resource stonith disable <node_name>   # disable fencing for one node only

Lab-only shortcut (never on anything that matters):

pcs property set stonith-enabled=false
pcs property set no-quorum-policy=ignore

no-quorum-policy=ignore was the standard workaround for 2-node Heartbeat/openais clusters that would otherwise lose quorum the instant one node dropped — modern pcs/Corosync 3 clusters should instead use two_node: 1 in corosync.conf (set automatically by pcs cluster setup for 2-node clusters) or, better, a real quorum device (pcs qdevice) plus proper fencing.


← Part 02: Cluster Management · Part 04: Creating Resources →