My ideas :
Reliability : use several firewalls/routers, with VRRP protocol for example in order to have Active/Passive firewalls.
Security : use dedicated cluster servers with low level hardware in order to avoid lateral attackers moves.
You are...
Nodes shouldn't do any function other than virtualization ( and maybe CEPH storage ).
Thus one or several VMs should do routing / firewalling.
Be careful with your overlapping networks as it can be dangerous (security) and prone to mistakes in...
WARNING : YOU CAN LOOSE DATA, thus backup what you have to before doing this (example : VMs and /etc on each nodes)
In order to FORCE local node operations : pvecm expect 1
Then you will have to pay attention to what you are doing in /etc/pve as...
Yes, and I think that your corosync cluster speak on the management traffic. That's why I said it was expected. In order to avoid this, you should add a second ring for corosync on the other switch network.
Hello. Just to be precise : in case of no quorum, and if HA is unconfigured, then no host is rebooted and no VM is shutdown. You would simply be unallowed to do any modification on state (configuration, VM stop/start and so on).
But if HA is...
Hello. The problem could be located to a kernel crash using bridges. But as seen many times in this forum with small form factor units, it rather comes from the processor. Can you try to :
- re-enable bridges and reproduce the problem
- put a fan...
Adding to MarkusKos comment you might also want to read @UdoB great writeup on using Ceph in small custers:
https://forum.proxmox.com/threads/fabu-can-i-use-ceph-in-a-_very_-small-cluster.159671/
Basically you will need fast network (10Gb/s...
if you have the budget for that hardware, dont waste your time with hard disks, use ssd's. 25G nics (LACP bond) for ceph would be a good idea.
storage/networking will be your main bottleneck here, especially with ceph.
check the official ceph...
It is rather a controversial question.
For me : do not do that. Data and disk integrity will be involved in mid term. In order to avoid this, you will have to tune the installation and the swap and it
will lead to a custom system to maintain.
As...