Linux Software RAID Failure Alert - Troubleshooting Guide

KB 905655 - Linux Software RAID Failure Alert - Troubleshooting Guide

Purpose

This document provides a standardized approach for handling and troubleshooting the Linux Software RAID Failure alert, enabling L1 and L2 engineers to respond quickly, minimize risk, and maintain system stability.

Alert Name

Linux Software RAID Failure

Alert Description

This alert is triggered when a RAID disk failure is detected. It indicates that one or more RAID members have failed, placing the RAID array in a degraded state.

There is an immediate risk if another disk fails before the rebuild is completed.

Severity

P3 – Medium Impact

Possible Causes
  1. Disk hardware failure
  2. RAID member disk missing or disconnected
  3. I/O errors on disk
  4. RAID controller or configuration issues
  5. System-level disk detection issues

L1 Engineer Actions

Step 1 – Log the Alert

  1. Log in to the monitoring system
  2. Review:
    1. Alert summary
    2. Affected host/system

Step 2 – Create Ticket

  1. Create an internal ticket including:
    1. Alert name
    2. Hostname
    3. Timestamp
    4. Initial observations

Step 3 – Escalation (If required)

  1. Inform L2 team immediately
  2. Share alert details and observations

Step 4 – Documentation

  1. After confirmation with L2:
    1. Update Issue Master Sheet/ Issue Tracking Sheet

L2 Engineer Actions

Step 1 – Check RAID Status

cat /proc/mdstat
  1. Look for [UU] → healthy || [U_] or [_U] → degraded (one disk failed)
  2. Identify degraded RAID arrays
  3. Detailed info: sudo mdadm --detail /dev/md0
    1. State → clean, degraded, recovering
    2. Active Devices vs Failed Devices
  4. Note failed or missing disks

Step 2 – Identify Failed Disk

  1. Check which disk dropped:
    1. sudo mdadm --detail /dev/md0 | grep -i faulty
  2. Device name using lsblk  (e.g., /dev/sda, /dev/sdb)
    1. RAID group affected
  3. Cross-check logs:
    1. dmesg | grep -i error

Step 3: Mark Disk as Failed / Remove (if not already)

  1. sudo mdadm --manage /dev/md0 --fail /dev/sdX
  2. Then remove it: sudo mdadm --manage /dev/md0 --remove /dev/sdX

Step 4: Replace the Disk

  1. Physically replace the drive (or attach new one)
  2. Partition it (match existing layout)
  3. Copy partition table: sudo sfdisk -d /dev/sdY | sudo sfdisk /dev/sdX

Step 5: Add New Disk to Array & Monitor

  1. Add disk to array: sudo mdadm --manage /dev/md0 --add /dev/sdX
  2. Monitor the Rebuild: watch cat /proc/mdstat
    1. You will see: recovery = XX% complete

Step 6: Verify after rebuild

  1. Ensure:
    1. No failed devices
    2. State = clean
  2. sudo mdadm --detail /dev/md0

Step 7: Check Configuration Persistence

  1. Make sure RAID config is saved: sudo mdadm --detail --scan | sudo tee -a /etc/mdadm/mdadm.conf
  2. update initramfs: sudo update-initramfs -u

Step 8: Prevent Future Failures

  1. Enable SMART monitoring: sudo smartctl -a /dev/sdX
  2. Schedule regular RAID checks: echo check > /sys/block/md0/md/sync_action

Step 9 – Create OEM Support Ticket

  1. If issue is still persistent raise the concern with OEM
  2. Raise a ticket with hardware OEM
  3. Provide:
    1. RAID status output
    2. Server details
    3. Disk failure information

Resolution

The issue is considered resolved when:
  1. Failed disk is replaced
  2. RAID array is rebuilt successfully
  3. RAID status returns to healthy state
  4. No degraded arrays are present

Escalation

  1. L1 → L2: Immediate escalation after alert validation
  2. L2 → OEM/Vendor: For disk replacement and hardware support