Quorum determines cluster safety
Node count, corosync connectivity and failure domains must be designed so expected failures do not leave the cluster without safe decision-making capability.
Storage architecture changes failure modes
Ceph, shared storage and local replication each create different performance, recovery and operational characteristics.
HA does not replace backup
Automatic restart protects availability from some infrastructure failures; it does not provide historical recovery from corruption, deletion or compromise.
AL Group can assess, design, implement and operate the underlying technology rather than stopping at advice.
Talk to an engineer