Redis Sentinel Config Generator

Generate sentinel.conf for a monitored primary. Two things decide whether failover works, and only one of them is the quorum: performing a failover also needs a majority of all sentinels to be reachable, which is why two sentinels can never fail over.

The primary
The quorum

Quorum decides how many sentinels must AGREE the primary is down. A majority of sentinels must also be reachable to authorise the failover, which is a separate condition and the one people conflate with quorum.

sentinel.conf

updates as you type

    Examples

    Worked setups you can load into the form above. Each one is a decision the generator makes differently, and the reason it makes it.

    Two sentinels

    Losing one leaves no majority, so failover can never be authorised

    master-name
    mymaster
    sentinels
    2

    An even number

    Four buys nothing over three and makes a split vote possible

    master-name
    mymaster
    sentinels
    4

    Common mistakes

    These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

    1. Running two sentinels

      A majority of two is two, so losing either one makes failover impossible. Two sentinels detect an outage and can do nothing about it.

      Instead:Run three, on three separate hosts.

    2. Lowering the quorum to make failover easier

      The quorum only controls agreement that the primary is down. The majority requirement for performing the failover is separate and cannot be lowered.

      Instead:Add sentinels rather than lowering the quorum.

    3. Pointing clients at the primary's address

      After a promotion the client keeps writing to the old primary, which now rejects writes with READONLY.

      Instead:Use the client library's Sentinel support.

    4. Deploying sentinel.conf from configuration management on every restart

      Sentinel rewrites the file to record the current primary and its peers. Overwriting it discards that state.

      Instead:Template it once, then exclude it.

    The quorum is not the whole story

    Sentinel has two separate thresholds and configuring only the visible one is the usual reason a failover does not happen when it should.

    Quorum decides agreement, majority decides authority

    The quorum is how many sentinels must agree the primary is down. Actually performing the failover additionally requires a majority of ALL configured sentinels to be reachable. Setting a quorum of 1 across two sentinels does not make failover easier: the majority is still 2.

    Two sentinels can never fail over

    Losing one leaves a single sentinel, which is not a majority of two, so no failover can be authorised. Three is the minimum, on three separate hosts, and an even number above that buys nothing over the odd number below it.

    Clients must talk to Sentinel, not to the primary

    Sentinel does not proxy traffic; it tells clients where the primary is. A client configured with the primary's host and port keeps pointing at the old primary after a promotion, and the symptom is writes failing with READONLY.

    down-after-milliseconds is a trade, not a tuning knob

    Too low and an ordinary garbage collection pause triggers a failover nobody wanted. Too high and a real outage lasts longer than it needs to. The right value depends on how long your primary can legitimately stall.

    Sentinel rewrites its own config file

    It records the current primary and the other sentinels it has discovered. Deploying the same file to every host from configuration management will overwrite that state, so exclude it after the first start.

    More redis tools

    Redis Hash Slot Calculator Which of the 16,384 slots does this key land in? Redis Hash Tag Tester Will these keys survive a multi-key command? Redis RESP Protocol Decoder Read what the server actually sent Redis RESP2 vs RESP3 Reply Decoder What the same reply looks like on each protocol Redis Command to RESP Exactly what your client puts on the socket Redis Glob Pattern Tester Redis globs are not shell globs Redis Connection URL Parser The path is the database number Redis Memory Unit Converter 1g and 1gb are not the same number Redis TTL Converter -1 and -2 are not durations Redis Stream ID Parser The first half is a millisecond timestamp redis.conf Validator Will Redis start with this file? Redis Production Config Linter The settings that cause incidents redis.conf to CONFIG SET Which of these can you change without a restart? Redis ACL Rule Decoder What does this user actually get? Redis ACL Validator Find the rule that does nothing Redis INFO Analyzer The numbers INFO does not print Redis SLOWLOG Analyzer What blocked everyone else Redis CLUSTER NODES Parser Read the topology, and find the gap Redis Cluster Slot Distribution Who owns how much, and what is missing Redis Keyspace Notification Flags Why your events never arrive Redis Memory Calculator The encoding decides, not the data Redis Key Count to Memory The fixed cost per key Redis Encoding Threshold Calculator One field more, several times the memory Redis Bitmap Memory Calculator Sized by the highest bit, not the set ones Redis HyperLogLog Calculator 12 KB whether you count a thousand or a billion Redis Cluster Sizing Only 60% of each node is usable Redis RDB and AOF Size Calculator The fork needs memory, not disk Redis Replication Bandwidth Calculator How long the backlog actually covers Redis Connection Pool Calculator More connections is not more throughput Redis Pipeline Calculator It removes round trips, not work Redis Cache Hit Rate Calculator 99% to 90% is ten times the backend load Redis Eviction Policy Simulator volatile- with no TTLs is noeviction Redis Cost Estimator Your rates, so nothing goes stale Redis Config File Generator A redis.conf with the reasons in it Redis ACL Generator A user that can do exactly one job Redis Maxmemory Config Generator The limit, and the headroom it needs Redis Persistence Config Generator How much you can afford to lose Redis Lua Script Generator Atomic, and short enough to stay that way Redis TLS Config Generator Encrypted, and the old port actually closed Redis Cluster Config Generator Three primaries, and the bus port open Redis Docker Compose Generator Local Redis that is not on the internet Redis Client Config Generator Timeouts on both sides, and a sane pool Redis MEMORY STATS Analyzer Which number actually matters Redis Bigkeys Output Analyzer Elements are not bytes Redis CLIENT LIST Analyzer Find the connection hurting you Redis LATENCY Report Analyzer An empty report may mean nothing was recorded Redis Keyspace Prefix Analyzer Which key family is growing Redis SET Command Builder A plain SET clears the TTL Redis ZRANGE Query Builder REV reverses the argument order Redis SCAN Iteration Planner COUNT is a hint, not a page size Redis Key Name Validator Legal is not the same as workable Redis Cluster Compatibility Checker Works now, breaks when you shard

    Elsewhere on the site