Consensus witness node
Clusters with an even number of voters cannot break a tie by themselves, and clusters in one datacentre cannot survive losing it. This node participates in elections as a non-storing member, so a quorum survives the loss of any single site.
| Cluster | Last heartbeat | Lease | Term | Role |
|---|---|---|---|---|
| atlas-euPrimary ledger, 3 voters | 4 s ago | 4 471 | arbiter | |
| ledger-fraTransaction log, 4 voters | 6 s ago | 8 830 | arbiter | |
| meridianConfiguration store, 3 voters | 5 s ago | 1 204 | arbiter | |
| parcel-nlRouting table, 2 voters | 9 s ago | 19 077 | tie-break | |
| vaultlineKey custody, 5 voters | 5 s ago | 612 | arbiter | |
| stillwaterArchive index, 3 voters | 12 s ago | 88 | standby |
A cluster registers once and receives a member identifier. From then on the witness answers votes for that cluster and nothing else; there is no shared identity between registrations.
The node never receives, stores or forwards replica data. It sees member identifiers, terms and log indices, which is the minimum required to decide an election honestly.
Requests from unregistered clusters are refused rather than answered with a neutral vote, because a neutral vote is indistinguishable from a partition to the caller.