Loading
View Categories

How do I set up an SFTP cluster with load balancing and failover? 

Before you start 

Setting up a ProVide Cluster takes about an hour for a basic two-node configuration, longer if you are also adding gateways and configuring TLS between nodes. The order matters: install ProVide on the nodes first, build the cluster, then add the gateways in front. 

You will need: 

  • At least 2 servers for ProVide nodes (Windows). Physical, virtual, or cloud based. 
  • A Maxi license per server or Mega license 
  • A Cluster license that covers the number of nodes, or a Cluster Unlimited license. 
  • For the recommended setup: 1 or 2 additional servers for Gateways (Windows or Linux), and matching Gateway licenses. 
  • Network connectivity between the nodes on the cluster port (default 3145), and outbound connectivity from each node to the Gateway control port (1280). 

For background on what each level provides and when you need it, see [What is high availability clustering in ProVide Server?]

Install ProVide on each node  #

On each server that will act as a ProVide node: 

  1. Run the ProVide Windows installer. 
  2. Activate your server license (Maxi or Mega) and the Cluster license. 
  3. Start ProVide as a service. 

This is the same installation you would do for a standalone ProVide Server. The cluster behaviour is configured in the next step. 

Create or join the cluster  #

The cluster is created on one node and joined by the others. 

On the first node: 

  1. Sign in to the ProVide admin interface. 
  2. Open Cluster Configuration. 
  3. Select Create a New Cluster. 
  4. Enter a unique node name, an administrator name, and let the system generate a join password. 
  5. Save. 

On each additional node: 

  1. Open Cluster Configuration in the admin interface. 
  2. Select Join an Existing Cluster. 
  3. Enter the address of the first node, the administrator’s name, and the join password. 
  4. If the nodes communicate over an untrusted network, enable TLS for cluster communication. 
  5. Save. 

Synchronization of users, groups, permissions, certificates, and settings starts automatically. New configuration changes made on any node propagate to the others within seconds. 

Note: If a node has been offline for a period, it catches up automatically when it reconnects. Deletions propagate safely, so removing a user on one node removes the user across the cluster even if a peer was unreachable at the time. 

Install one or two Gateways  #

The Gateway is a separate component that runs on its own server. For real high availability, install two Gateways, ideally in separate data centre’s or with separate infrastructure providers. 

On Windows: Run ProVide Gateway Setup.exe on the server that will receive external traffic. The service installs and starts automatically. 

On Linux: Run install-providegateway.sh on the target server. The script detects the init system (systemd, OpenRC, SysVInit, runit, or s6) and configures the service accordingly. 

For two Gateway setups, repeat the installation on a second server. 

Connect the Gateways to the cluster  #

The Gateways need to know about the cluster, and the cluster needs to know about the Gateways. 

  1. In the ProVide admin interface, open Gateway Configuration. 
  2. Add each Gateway’s address. 
  3. Configure which services (HTTPS, SFTP) should be routed through the Gateways and on which public ports. 
  4. Verify that the Gateways show as connected in the admin interface. 
  5. Test access from an external client through the Gateway addresses. 

Each node opens an outbound connection to each Gateway on the control port. The control channel is TLS-protected and authenticated with mutual HMAC. Actual client traffic is bridged directly between the client and the selected node. 

At this point you have a working cluster with load balancing and failover. Connections are distributed based on real-time node load, health status, and sticky sessions for HTTPS. 

Enable rolling updates  #

  1. If you have two Gateways, you can enable rolling updates to keep the service available during version upgrades. 
  2. In ProVide’s update settings, enable Rolling Updates and Rolling Gateway Updates. 
  3. Optionally set a maintenance window (default 00:00–04:00) during which updates are allowed.
  4. Save. 

ProVide will now handle future updates automatically, with no service interruption and no administrator intervention required. 

For the full mechanics of how rolling updates work, see [How do rolling updates work for zero-downtime SFTP server maintenance?]

YOUR CART

CUSTOMERS ALSO ADD

HAVE A COUPON?
ORDER SUMMARY
We'll send a tailored quote to your inbox.

The invoice will be e-mailed once your order is confirmed.

ProVide Server

Your cart is empty

maxi_provideserver

Choose your version of ProVide Server to download

For the ultimate experience of ProVide’s features and functions,
we recommend choosing the MAXI License.

Follow the 3 easy steps below to install ProVide Server
  1. Download the version you need using the buttons below.
  2. Get a free MAXI trial license by clicking the “Get Maxi Trial License” button and enter your email. The license key will be sent to your email.
  3. Activate the license key by following this simple step-by-step-guide.

Free Trial

Get
ProVide Software