Sentinel — quorum detects, majority elects
Sentinels reach ODOWN at quorum agreement but require a strict majority to elect a failover leader, and Sentinel does not stop the partitioned old master from accepting writes — that is the data plane's job.
Replicas hold a copy, but they don't decide on their own when to take over. Sentinel is the small, separate process that watches, votes, and promotes.
Scene 07
Sentinel — quorum detects, majority elects
- Watch
- Try it
- Predict
- Capture
Three Sentinels watch one master and a replica. The master crashes; watch SDOWN turn into ODOWN once quorum agrees, then a vote in epoch 1 elects the leader who promotes the replica.
Highlighted lines are the ones running in the diagram right now.
def tick(self):if not master.responds_within(down_after_ms):self.mark_sdown() # local opinion only# ask peers via SENTINEL is-master-down-by-addrodown_agree_count = 1 + sum(1 for peer in peers if peer.thinks_sdown(master))if odown_agree_count >= quorum:self.status = ODOWN # quorum-agreedself.start_election()
def start_election(self):if self.status != ODOWN:returnself.my_epoch += 1 # fence this roundself.vote_for = self.idbroadcast(VoteRequest(candidate = self.id,epoch = self.my_epoch,))self.tally = collect_votes_from_peers(epoch = self.my_epoch,)
def tally_votes(self):majority = (sentinel_count // 2) + 1 # NOT quorumif max(self.tally.values()) >= majority:winner = argmax(self.tally)promote(replica) # SLAVEOF NO ONEreturnif all_voted_and_no_majority(self.tally):self.state = TIEDretry_in(2 * failover_timeout) # bumps epoch
Where this sits in Build Redis
Scene 07 of 10, in the HA act — Replication and Sentinel — async by design.. SDOWN/ODOWN ladder, epoch-based election, and the operator footgun: quorum ≠ majority.
Up next. Cluster — Sentinel keeps one master and its replicas available. But you still only have one master's worth of write throughput. Cluster is how you get more.
Designs that use this
- URL ShortenerShorten a long URL. Read-heavy. Don't collide.
- Distributed Rate LimiterEnforce a per-key request limit across a fleet of enforcers — accurately, in under a millisecond, without becoming the outage.
- Twitter / X TimelinePush or pull? Both. The canonical fanout problem.
- Uber / Lyft — Match Drivers and RidersMatch a rider to the closest acceptable driver in under 3 s. Geohash, S2, surge.