feat(mssql): new availability group wizard (SE-247, part 2) - #201
Merged
Merged
Conversation
Fail Over… on an availability group builds the plan from cluster_type_desc: one FAILOVER (or FORCE_FAILOVER_ALLOW_DATA_LOSS) on the target for WSFC, the documented multi-instance sequence for read-scale (NONE), and a refusal with the pcs/crm commands for Pacemaker (EXTERNAL). The plan is data, shown in full before anything runs, re-read and compared at confirm time, and every picked connection must prove it is the replica it was picked for. The old primary's SET (ROLE = SECONDARY) is retried for up to 30 s: issued the moment the promotion returns it fails while that replica is still resolving, seen against a real read-scale group. IToolUiContext gains OpenConnection so the view can read the primary's state when opened on a secondary (additive, folded into tool API 8).
…s folder New Availability Group… makes the launch instance the primary and picked saved connections the secondaries. A pre-flight over every instance gates the form: nothing is offered that the topology cannot do (one instance, Always On off, mixed versions/collations/editions, missing CONTROL SERVER, endpoints on only some instances), WSFC only when all instances are nodes of one cluster, read-scale never preselected, a basic group on Standard edition, and only databases that can join. Endpoints are created with certificate authentication and the public certificates move as CERTENCODED() -> CREATE CERTIFICATE FROM BINARY, so no file is written on a server and the cross-domain case needs no share. Existing endpoints are reused when every instance has one. Seeding is automatic. The plan runner is shared with the failover tool and gains captured values: a step can read a certificate on one instance for a later step to create on another.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
New Availability Group… on the Availability Groups folder (SE-247, part 2 of 2). The instance the tool was opened on becomes the primary; the user ticks the saved connections that hold the secondaries.
The pre-flight is a gate, not a page
While anything blocks, the dialog shows only the checks and why DataTray cannot fix them from a connection — no form at all. Blocking:
mssql-conf)CONTROL SERVEROnce it passes, the form offers only what can work: WSFC only when every instance is a node of the same Windows cluster; NONE (read-scale) only on 2017+, and never preselected because it is not HA; EXTERNAL never (Pacemaker is not something DataTray configures); automatic failover only under WSFC and only on synchronous replicas; backup preference restricted to
PRIMARYfor a basic group. Ineligible databases are listed with the reason instead of a disabled box (not FULL recovery, no full backup, already in a group, mirrored, read-only, AUTO_CLOSE, not multi-user, or a same-named database already on a secondary, which automatic seeding needs absent).The plan
Per instance, in order, shown in full and rebuilt on every change:
DATABASE_MIRRORINGendpoint on each; then each instance's public certificate read withCERTENCODED()and created on every other oneFROM BINARYwith a login/user andGRANT CONNECT ON ENDPOINT. When every instance already has an endpoint, they are reused untouched.CREATE AVAILABILITY GROUP … SEEDING_MODE = AUTOMATICon the primary.JOIN(JOIN WITH (CLUSTER_TYPE = NONE)for read-scale), thenGRANT CREATE ANY DATABASE.ExecuteAsyncre-reads every instance, re-runs the pre-flight and refuses unless the rebuilt script equals the reviewed one. Generated passwords travel with the choices so the script is byte-identical.Decisions on the ticket's open points
CERTENCODED()→CREATE CERTIFICATE … FROM BINARY(documented since 2012). NoBACKUP CERTIFICATE, no UNC share. Endpoints DataTray creates always use certificates, the one mode that works in a domain, across domains, without one, and on Linux.ApplicationIntentin the connection fields first — see Codebase notes).Shared with #200
The step runner moves to
AgStepRunner(wait steps, retried steps, and now captured values:$(cert:NAME)is filled at run time from an earlier step's query; only that prefix is substituted, and an uncaptured token throws instead of sending empty SQL). The failover tool uses the same runner and script rendering.Verification
DataTray.Tools.MsSqlAdmin.Tests: 140 passed (29 new, on top of feat(mssql): fail over an availability group (SE-247, part 1) #200).DataTray.Core.Tests629,DataTray.App.Tests56. Solution builds with 0 warnings.HEALTHY, databaseSYNCHRONIZEDon both sides, endpointsCERTIFICATE/STARTED;HEALTHY;DataTray.Screenshotsscene (not committed).CLUSTER_TYPE = NONE— the docs do not say, so the wizard currently offers it. Live testing is planned on Rick's Proxmox lab.