#!/usr/bin/env bash # cluster-enable-stonith.sh — enable STONITH fence agent after the fence SSH # key is deployed to both nodes and authorised on the Proxmox host. # # Run from ha-server-1 as root AFTER: # - /etc/pacemaker/fence_pve_ssh exists on both nodes (chmod +x) # (copy from scripts/ha/fence-pve-ssh.py) # - /etc/fence-pve-ssh-key (SSH private key) exists on both nodes # - The corresponding public key is in authorized_keys on PVE_HOST # - VMID_NODE1 / VMID_NODE2 filled in below set -euo pipefail # ── Configuration ───────────────────────────────────────────────────────── NODE1="ha-server-1" NODE2="ha-server-2" VMID_NODE1="" # FILL IN: Proxmox VMID for ha-server-1 VMID_NODE2="" # FILL IN: Proxmox VMID for ha-server-2 PVE_HOST="pve1.sweet.home" PVE_USER="wayne" FENCE_KEY="/etc/fence-pve-ssh-key" FENCE_SCRIPT="/etc/pacemaker/fence_pve_ssh" # ────────────────────────────────────────────────────────────────────────── log() { echo "[stonith-setup] $*"; } die() { echo "[stonith-setup] ERROR: $*" >&2; exit 1; } [[ $(id -u) -eq 0 ]] || die "must run as root" [[ -n "$VMID_NODE1" ]] || die "VMID_NODE1 not set — edit this script" [[ -n "$VMID_NODE2" ]] || die "VMID_NODE2 not set — edit this script" [[ -f "$FENCE_KEY" ]] || die "fence key not found at $FENCE_KEY" [[ -f "$FENCE_SCRIPT" ]] || die "fence script not found at $FENCE_SCRIPT" log "Verifying fence agent can reach ${PVE_HOST}..." ssh -i "$FENCE_KEY" -o BatchMode=yes -o ConnectTimeout=10 \ -o StrictHostKeyChecking=no "${PVE_USER}@${PVE_HOST}" \ "sudo /usr/sbin/qm list" &>/dev/null \ || die "Cannot SSH to ${PVE_USER}@${PVE_HOST} — check authorized_keys and sudo" log "Fence agent SSH connectivity confirmed" log "Creating Pacemaker STONITH resources..." cibadmin --create --scope resources --xml-text " " 2>/dev/null || true cibadmin --create --scope resources --xml-text " " 2>/dev/null || true log "Enabling STONITH and restoring quorum policy..." crm_attribute -t crm_config -n stonith-enabled -v true crm_attribute -t crm_config -n no-quorum-policy -v stop log "DRBD fencing mode must also be updated to resource-only (already the" log "default in cluster-config.nix; confirm with: cat /etc/drbd.d/ha-data.conf)" log "Testing fence agent..." stonith_admin --list-devices && log "Fence devices listed successfully." \ || warn "stonith_admin --list-devices failed — check config" log "STONITH enabled. Cluster is now fully HA."