EMBEDDED CONSENSUS ENGINE SEAPILOT HA

7-Second Failover. Zero Data Loss. Any Infrastructure.

SeaPilot HA is an embedded consensus engine for MariaDB and MySQL that delivers five-nines availability without proxy dependencies, infrastructure vendor lock-in, or operational complexity.

Kubernetes, bare metal, any cloud — same binary, same failover logic.
Request a Demo View Documentation ↓
test-failover.sh
LIVE CONSENSUS BENCHMARK
$ ./testing/v3/test-failover.sh
[00:00] Starting continuous writes at 5 req/s...
[00:05] Write #25 committed on mariadb-0 (PRIMARY)
[00:06] ✗ Killing primary node mariadb-0...
[00:06] mariadb-0 terminated
[00:07] Raft heartbeat timeout detected on mariadb-1
[00:08] Election started — mariadb-1 requesting votes
[00:08] mariadb-2 voted for mariadb-1
[00:09] ✓ mariadb-1 elected leader (term 2)
[00:10] mariadb-1 promoted to PRIMARY
[00:11] SET GLOBAL read_only = 0
[00:13] Write #26 committed on mariadb-1 (PRIMARY)
[RESULT] Failover completed in 7.2 seconds
[RESULT] Rows lost: 0
[RESULT] Writes resumed: ✓
THE OPERATIONAL PROBLEM

Your Database Failover is Too Slow

60–120s SLOW FAILOVERS

High Latency Failovers

Average RDS Multi-AZ failover time ranges from 60 to 120 seconds. Every second of outage costs lost transactions, broken user sessions, and cascading microservice failures.

EXTERNAL DEPENDENCIES

Operational Complexity

Orchestrator, MaxScale, VTOrc — separate infrastructure components to deploy, patch, monitor, and keep alive. Who monitors the monitors when they crash?

VENDOR LOCK-IN

Cloud Provider Lock-in

Aurora only runs on AWS. Galera requires strict network configurations. Cloud-managed databases lock your architecture into a single provider.

7s
RTO
(measured)
0
RPO
(rows lost)
45
Failovers/yr
at five nines
1
Binary per node
no proxy, no external deps

* Measured on a 3-node MariaDB 11.8 cluster running on Kind. Continuous writes at 5 req/s during failover. Full test reproducible from our public repository.

FAILOVER MECHANISM

How It Works

Three steps. Seven seconds. Zero human intervention.

STEP 1 • DETECT

Raft Heartbeat Timeout

Raft heartbeat fails (1s interval, 3s timeout). Peer nodes instantly flag primary unresponsiveness.

[node-0]---X---[node-1]
           | timeout
STEP 2 • ELECT

Consensus Majority Vote

Consensus vote finishes in milliseconds across majority quorum nodes.

[node-1] <-- vote -- [node-2]
[node-1] = new leader
STEP 3 • PROMOTE

Primary Promotion

New primary accepts writes immediately, update labels, and clears read_only flags.

[node-1] = PRIMARY
SET read_only = 0 | IO=Yes SQL=Yes

No external monitor. No proxy in the data path. No DNS propagation delay.
The agents detect, decide, and act — all within the same 7 seconds.

CLUSTER TOPOLOGY

Architecture Overview

Pod mariadb-0 PRIMARY
🔹 MariaDB :3306
🔹 SeaPilot :8080
🔹 Raft :7000
🔹 BoltDB local
🔹 MariaBackup :9998
Pod mariadb-1 REPLICA
🔹 MariaDB :3306
🔹 SeaPilot :8080
🔹 Raft :7000
🔹 BoltDB local
🔹 MariaBackup :9998
Pod mariadb-2 REPLICA
🔹 MariaDB :3306
🔹 SeaPilot :8080
🔹 Raft :7000
🔹 BoltDB local
🔹 MariaBackup :9998
Raft TCP :7000: Peer-to-peer consensus channel connecting nodes directly.
Single Binary: No JVM overhead, no proxy in data path, no external state store.
No etcd / ZooKeeper: Raft consensus runs embedded inside each agent.
BoltDB Persistence: Single file embedded store, not another database to manage.
CAPABILITIES

Key Features

Embedded Raft Consensus

Leader election and failover decisions happen inside the agent. No external coordinator to deploy or maintain. Tolerates N/2 node failures effortlessly.

Zero-RPO Failover

GTID-based replication ensures every committed transaction reaches the new primary. Measured zero data loss under continuous write load.

Auto-Rebuild

Ex-primary nodes automatically rejoin as replicas. Three recovery paths: GTID rejoin, stream rebuild from donor, or backup restore from S3.

Partition Safety

Isolated primaries detect quorum loss and demote to read-only within the configured grace period. Prevents split-brain writes.

Backup Integration

MariaBackup and XtraBackup for physical full backups, binlog archiving to S3/MinIO. Scheduled backups, point-in-time recovery, and automatic restore on rebuild.

Multi-Platform

Kubernetes, Docker, bare metal, any cloud. ProxySQL, HAProxy, K8s labels, VIP, or DNS-based routing. Built for MariaDB and MySQL.

ENGINEERING EXCELLENCE

Production-Grade Reliability & Security

Security

  • 🔒 Mutual TLS for Raft inter-node communication
  • 🔒 Bearer token authentication for HTTP API
  • 🔒 Exempt paths for health probes and metrics (K8s compatible)
  • 🔒 All credentials injected via environment variables / K8s Secrets

Observability

  • 📊 Prometheus metrics on every node (/metrics)
  • 📊 Pre-built Grafana dashboard (20 panels)
  • 📊 OpenAPI 3.1 specification for all 22 API endpoints
  • 📊 Structured JSON logging with configurable levels

Operations

  • ⚙️ Helm chart with full value parameterization
  • ⚙️ Graceful shutdown (SIGTERM handling, HTTP drain, Raft leave)
  • ⚙️ Maintenance CLI for manual failover, rejoin, and status
  • ⚙️ Rolling upgrades without downtime

Reliability

  • 🛡️ Five-nines failover resilience (45 events/year within budget)
  • 🛡️ Automatic detection of replication divergence with rebuild trigger
  • 🛡️ Configurable cooldowns to prevent recovery storms
  • 🛡️ Primary Lease Renew (PLR) as secondary failure detection
DEPLOYMENT OPTIONS

Deploy Anywhere

RECOMMENDED

Kubernetes

Helm chart with StatefulSet, Operator for label management, MariaBackup sidecar, MinIO for dev/test. Production-ready with PDB, RBAC, and NetworkPolicy.

DEV & SMALL DEPLOYMENTS

Docker / Docker Compose

For development and small deployments. SeaPilot wrapper manages PID 1, MariaDB lifecycle, and signal forwarding seamlessly.

PHYSICAL & VIRTUAL MACHINES

Bare Metal / VM

systemd unit files, VIP-based routing, IPMI/BMC hard fencing. Full platform driver for non-containerized enterprise environments.

Experience 7-Second Failover on Your Cluster

Schedule a live technical benchmark demo or request access to the SeaPilot repository.

Request a Demo Explore Galera HA Architecture