NetApp - Tiebreaker installation on RHEL 7
NetApp Solution · Config document · referenced from MetroCluster switchover and Tiebreaker
The installation and configuration of the NetApp MetroCluster Tiebreaker software as it was run: prerequisites, package, one monitor for the MetroCluster of the other site, AutoSupport through a proxy, and the change from observer mode to online mode.
| Item | Value |
|---|---|
| Shown here for | dc1-a-vcntb001.adm.example.net, in site 1, watching the MetroCluster of site 2 |
| Also applied to | dc2-a-vcntb001.adm.example.net, in site 2, watching the MetroCluster of site 1 |
| Virtual machine | 2 vCPU, 4096 MB memory, 32 GB VirtIO disk, one interface in VLAN 1021, highly available |
| Operating system | Red Hat Enterprise Linux 7.5, installed to the organisation's Linux baseline |
| Product version | MetroCluster Tiebreaker 1.21P2 |
| Applied with | A root shell, then the Tiebreaker CLI |
The command set
# --- Prerequisites, as root ------------------------------------------------- # A tool to make administration easier yum install mc # Java runtime yum install java-1.8.0-openjdk # Database server, started and checked yum install mariadb-server systemctl start mariadb systemctl status mariadb # Secure the database. Answers given: # Enter current password for root (enter for none): <MARIADB_ROOT_PASSWORD> # Set root password? [Y/n] Y # New password: <MARIADB_ROOT_PASSWORD> # Remove anonymous users? [Y/n] Y # Disallow root login remotely? [Y/n] Y # Remove test database and access to it? [Y/n] Y # Reload privilege tables now? [Y/n] Y mysql_secure_installation # --- Tiebreaker package ----------------------------------------------------- # The RPM was downloaded from the NetApp support site into a directory named # after the version, so that a later version gets a directory of its own. cd /opt/netapp/install/1.21P2/ rpm -ivh NetApp-MetroCluster-Tiebreaker-Software-1.21P2-1.x86_64.rpm # Enter MetroCluster Tiebreaker user password: <TIEBREAKER_USER_PASSWORD> # Please enter mysql root password when prompted # Enter password: <MARIADB_ROOT_PASSWORD> # Start the daemon and check that it really started. # It does not start when /tmp is mounted with the noexec flag. systemctl start netapp-metrocluster-tiebreaker-software systemctl status netapp-metrocluster-tiebreaker-software # Start both services with the operating system systemctl enable mariadb systemctl enable netapp-metrocluster-tiebreaker-software # --- Configuration, in the Tiebreaker CLI ----------------------------------- sudo su - netapp-metrocluster-tiebreaker-software-cli # Everything below is typed at the prompt "NetApp MetroCluster Tiebreaker :>" # Add the MetroCluster of site 2. Answers given: # Enter Monitor Name: Metro-Cluster_in_DC2 # Enter Cluster IP Address: 10.12.10.33 (DC2-A-XNAS001) # Enter Cluster Username: admin # Enter Cluster Password: <CLUSTER_ADMIN_PASSWORD> # Enter Peer Cluster IP Address: 10.12.10.34 (DC2-B-XNAS001) # Enter Peer Cluster Username: admin # Enter Peer Cluster Password: <CLUSTER_ADMIN_PASSWORD> # Successfully added monitor to NetApp MetroCluster Tiebreaker software. monitor add wizard # Both clusters and all four nodes must be reachable, with intersite # connectivity available, state normal, and "Observer Mode: true" monitor show -status # AutoSupport through the proxy of the site the Tiebreaker runs in. Answers: # Enter Proxy Server IP address: 10.11.16.113 # Enter Proxy Server port number: 3128 # Enter Proxy Server Username: (empty) # Enter Proxy Server Password: (empty) # Autosupport configuration updated successfully. autosupport configure wizard autosupport show autosupport enable # Send a test message; expected "AutoSupport transmission : success" autosupport invoke # Monitor name and the two cluster addresses configuration show # Leave observer mode: from now on the Tiebreaker starts a switchover by # itself when it detects a site failure. The CLI asks for confirmation. monitor modify -monitor-name Metro-Cluster_in_DC2 -observer-mode false
The Tiebreaker in site 2 differs only in what it watches and which proxy it uses.
| Item | dc1-a-vcntb001 | dc2-a-vcntb001 |
|---|---|---|
| Monitor name | Metro-Cluster_in_DC2 | Metro-Cluster_in_DC1 |
| Cluster address | 10.12.10.33, DC2-A-XNAS001 | 10.11.10.33, DC1-A-XNAS001 |
| Peer cluster address | 10.12.10.34, DC2-B-XNAS001 | 10.11.10.34, DC1-B-XNAS001 |
| AutoSupport proxy | 10.11.16.113, port 3128 | 10.12.16.113, port 3128 |
The notes name the download directory /opt/netapp/install/1.21P/ in the text and /opt/netapp/install/1.21P2/ in the command; the command is what is shown. The monitor logs in to the clusters with the built-in admin account; the notes do not show a dedicated, restricted account for it.
Checked against MetroCluster Tiebreaker 1.7
| As built | Today |
|---|---|
Tiebreaker 1.21P2, installed with rpm -ivh as root | The documented versions are 1.4, 1.5, 1.6, 1.6P1 and 1.7; 1.21 is no longer mentioned. Version 1.7 is installed with sh MetroClusterTiebreakerInstall-1.7, which checks a digest and a code signature and uses a dedicated Unix account; certificates are imported afterwards |
| Red Hat Enterprise Linux 7.5 | 1.7 and 1.6P1 run on RHEL 9.6, 9.5, 9.4, 9.2, 8.10 and 8.8 and on Rocky Linux 9.4 and 8.10. RHEL 7 is supported only by Tiebreaker 1.4 |
| ONTAP 9.1 to 9.3 on the clusters | 1.6, 1.6P1 and 1.7 need ONTAP 9.12.1 or later; 1.5 covers 9.8 to 9.14.1; 1.4 covers 9.1 to 9.9.1 |
yum install java-1.8.0-openjdk, yum install mariadb-server, mysql_secure_installation | From 1.6 on there are no prerequisites: OpenJDK 19.0.2 is bundled and no separate database is installed |
Monitor added with the built-in admin account of each cluster | The documentation creates a dedicated ONTAP user for the Tiebreaker with security login create, for the applications ontapi and ssh |
monitor modify -monitor-name <name> -observer-mode false | Same command, same warning. NetApp lists data-loss scenarios for the active mode and declines responsibility for damages arising from its use |
| One Tiebreaker per MetroCluster, in the other site | Still the model: a third site, one monitor per MetroCluster configuration, up to 15 configurations per Tiebreaker, and a local NTP source of its own, not the one the clusters use |
| Tiebreaker as the third-site witness | ONTAP Mediator, current version 1.12.1, works only with MetroCluster IP. For MetroCluster FC the Tiebreaker remains the only third-site option, and the two must not monitor the same configuration |
The /tmp noexec problem could not be confirmed in a readable NetApp source: the public Tiebreaker documentation does not mention it, and the knowledge-base article "MetroCluster Tiebreaker fails to launch" is behind a login. The proxy syntax of the Tiebreaker's AutoSupport was not re-checked. See the Tiebreaker documentation.