From Fedora Project Wiki

High Availability Container Resources


The Container Resources feature allows the HA stack (Pacemaker + Corosync) residing on a host machine to extend management of resources into virtual guest instances (KVM/LXC).


  • Email: <>

Current status

  • Targeted release: Fedora 19
  • Last updated: 1-25-2013
  • Percentage of completion: 60%

Detailed Description

This feature is in response to the growing desire for high availability functionality to be extended outside of the host into virtual guest instances. Pacemaker is currently capable of managing virtual guests, meaning Pacemaker can start/stop/monitor/migrate virtual guests anywhere in the cluster, but Pacemaker has no ability to manage the resources that live within the virtual guests. At the moment these virtual guests are very much a black box to Pacemaker.

The Container Resources feature changes this by giving Pacemaker the ability to reach into the virtual guests and manage resources in the exact same way resources are managed on the host nodes. Ultimately this gives the HA stack the ability to manage resources across all the nodes in cluster as well as any virtual guests that reside within those cluster nodes.

Ha node without container resources.jpg

Ha node w container resources.jpg

Benefit to Fedora

This feature expands our current high availability functionality to span across both physical bare-metal cluster nodes and the virtual environments that reside within those nodes. Without this feature, there is currently no direct approach for achieving this functionality.


Remote-LRMD: Pacemaker's existing LRMD must be modified to allow the client and server to communicate remotely over tcp. TLS will be used with PSK encryption/authentication to secure the connection between the lrmd client and server. A standalone version of the LRMD running a tls backend on a virtual guest will allow the CRMD on a host machine to manage resources within the virtual guest.

Pengine Container Resource Support: Pacemaker's policy engine component needs to be able to understand how to represent and manage container resources. This is as simple as the policy engine understanding that container resources are both a resource and a location other resources can be placed after the container resource has started. The policy engine will contain routing information in the LRMD action specify which LRMD an action should go to and on what node. This will allow the CRMD to route the actions to a remote LRMD instance living on the virtual guest rather than the local LRMD instance living on the host node.

CRMD-Routing: Pacemaker's CRMD component must now be capable of routing lrmd commands to both the local LRMD and remote LRMD instances residing on virtual guests.

How To Test

User Experience


Contingency Plan


Release Notes

Comments and Discussion