pmxcfs is brilliant. if i ever meet whoever came up with that, im getting you beer (or booch if you dont drink)
anyway, seems like it prevents a rebooted node from trying restart a migrated instance. between that, and the fact that we only have 3 nodes, so if one goes down, it should come up asap, i set the fence action to reboot (action="off" followed by action="on", its an apc pdu). is there a possible failure case where this would be a bad idea? is it common enough to offset the vulnerable time of temporarily only having 2 nodes up?
anyway, seems like it prevents a rebooted node from trying restart a migrated instance. between that, and the fact that we only have 3 nodes, so if one goes down, it should come up asap, i set the fence action to reboot (action="off" followed by action="on", its an apc pdu). is there a possible failure case where this would be a bad idea? is it common enough to offset the vulnerable time of temporarily only having 2 nodes up?