On Thu, Jul 01, 2010 at 04:47:16PM +0100, Luca Bigliardi wrote:
> On Thu, Jul 1, 2010 at 3:58 PM, Iustin Pop <[email protected]> wrote:
> 
> Hi!
> 
> > I understand your point, but I'm not sure if this is a good idea. The
> > temporary failure could be hiding the fact that the node might be
> > healthy and have the wrong helper, etc.
> 
> True
> 
> > I would rather say:
> > - any failure aborts the operation: per the other code, broken nodes
> >  should be offlined anyway (and yes, you need to skip an offline node)
> > - optionally, failures could be forced via the --force flag
> 
> Ok for a stricter check, but are you sure that it's a good idea to introduce
> a force option to modify cluster configuration?
> If the force flag is used just in a few places then it's not so
> intuitive for the users.
> On the other hand if it's used to override all the checks then things might 
> get
> very inconsistent (I agree to say that it's users fault to use --force without
> realizing the consequences very well, but still...).

That's why I said "optionally" - let's leave it out for now…

iustin

Reply via email to