I wonder what is this database, and why it is hard to fall-over automatically.
> primary failover briefly improved performance but did not fully mitigate, we've throttled inbound traffic and are investigating upstream Vitess issues
RDBMS integrity basically requires that one master server is responsible for the whole data set and other servers may replicate from it. And it usually doesn't wait for a quorum of replicas, just for one, because the design is to recover from a hardware failure, not a network partition, although that could be fixed at the cost of increased latency.
This can be implemented in front of any RDBMS as a separate layer. Traditionally they weren't designed for quorum-sensing since it hadn't been invented yet. I'd be surprised if something like pgbouncer couldn't do it.