Well the idea is to automate system administration while letting the administrator be the commander in chief :)

Setting up disaster recovery sites is difficult and errorprone.

DR site is not a supported scenario so far. There's so much more we need
to get right until then ...
You are right. And why is this - basically because it is REALLY hard to reliably tell the current status the nodes (as it really is and not as the cluster sees it, split brain etc.). This is due to the really unreliable heartbeat infrastructure in DR / Split Site / Wan environments, isn't is ? Well with a manually confirming administrator your have a reliable source of information. the admin can contact other departments prior to doing the failover and ask for the real status of the data center. That's better than any cluster can eventually get.

Robert

_______________________________________________
Pacemaker mailing list
[email protected]
http://list.clusterlabs.org/mailman/listinfo/pacemaker

Reply via email to