Introducing pg_auto_failover
citusdata.com
citusdata.com
Edit: After looking at the architecture page, it seems that the monitor would ask the failed node kill itself? That is polite but wouldn’t work if monitor is partitioned with the standby nodes. Does this expect the primary will self-suicide if it cannot connect to the monitor? Such an approach could be problematic if the keeper process is hung but pg itself is still running. Would love clarification.