Cluster-Devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Jan Friesse <jfriesse@redhat.com>
To: cluster-devel.redhat.com
Subject: [Cluster-devel] Prototype Fencing Agent for Raritan eRIC G4
Date: Thu, 11 Jun 2009 11:31:55 +0200	[thread overview]
Message-ID: <4A30CF0B.2030203@redhat.com> (raw)
In-Reply-To: <4A30087D.3060901@bobich.net>

Gordan,

Gordan Bobic wrote:
> Subhendu Ghosh wrote:
> 
>> Would it be possible to look at migrating this agent to SSH (more secure)
> 
> I started with the idea of doing it over ssh, but Net::SSH module seemed
> to be a lot less forgiving about the terminal quirkyness. I can have
> another go. There's also the issue of manual intervention being required
> to save the signatures (and where do the known hosts go?).
> 
>> or to SNMP (less screen scraping)?
> 
> Hmm, maybe. I haven't looked into the SNMP capability on the device, but
> it looks like it'll work, and probably be easier to do than SSH.
> 
>> Look at fence_cisco as an example of snmp usage.
> 
> Assuming they speak a compatible dialect, which may not be the case.
> I'll have a look.

We are using fence agents library, which makes writing agents easier
(capable of doing things like command line parsing, implement reboot
operation, ...), shorter and easier to maintain. fence_cisco is good
example (short, tested, ...) HOW to write such agent. Agents are written
in Python, and we are migrating all agents on top of library.

> 
>> Long term maintainability of screen scraping is an issue with firmware
>> changes.
> 
> Tell me about it. I submitted a patch for fence_drac a while back to
> address an issue that seems to have arisen from a firmware update
> inducted pattern match failure.
> 
> Not only that, but I've discovered a bug on the latest eRIC G4 firmware
> - 04.02.00-7153 seems to have broken USB keyboard support (you'd think
> this was important on a remote console device!) and potentially some
> power button press dodgyness. The previous firmware, however -
> 04.02.00-6505, works OK.
> 
>> Also it seems that card has IPMI support. If so, can use test with
>> fence_ipmi?
>> Would remove the need for yet-another-agent ;)
> 
> Sadly, my servers with these cards in them don't have IPMI support. The
> card only proxies it. The card supports direct power/reset button
> control in addition to IPMI, so this is what I'm using. But as you can
> see from the code, it operates only on the power on/off even for a
> reboot because the said servers also don't have a reset connector. I
> wrote this agent because I _needed_ it. :)
> 
> But I'll look into the SNMP way of doing it, it sounds like it might be
> neater. I'll add it as an option since the telnet way is already
> written. What parameter should/can be used to specify such things, that
> is available from a cluster.conf reference?

This question answers you little look to fence_cisco agent (or you can
use fence_ifmib, fence_intel_modular, fence_apc_snmp, ...). In case you
will not understand something, please ask.

> 
> Thanks.
> 
> Gordan
> 

Regards,
  Honza



      reply	other threads:[~2009-06-11  9:31 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-06-09 21:13 [Cluster-devel] Prototype Fencing Agent for Raritan eRIC G4 Gordan Bobic
2009-06-10 18:49 ` Subhendu Ghosh
2009-06-10 19:24   ` Gordan Bobic
2009-06-11  9:31     ` Jan Friesse [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4A30CF0B.2030203@redhat.com \
    --to=jfriesse@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox