The Master node of a Cryptographic Security Platform Vault cluster must be available to access or create KMIP keys to encrypt or rekey your data. You can determine which node of your cluster is the Master node by logging into the Cryptographic Security Platform Vault Management webGUI, clicking Switch to Appliance Management, and then selecting Cluster > Servers. A yellow star appears before the server name of the node designated as the KMIP database master node. The master is the first node in the cluster list. The other nodes in the cluster are replica nodes.

All KMIP requests are forwarded to the master node for processing. When the master node's database is updated, all replica nodes receive the updates synchronously. When the master node is down, it may take approximately 1 minute before the other nodes start servicing READ requests.

If your Master node is going to be unavailable for a long time, for example, if there is a network outage, you can log into any other node of the cluster and remove the Master node. When you remove the former Master node, the second node in the cluster list will become the Master. Because the new Master node will update or create KMIP keys, which are replicated only to nodes participating in the cluster, we highly recommend that you immediately shut down the removed node VM to prevent communication with external applications. Once the crisis is averted, you can rejoin the former Master to the cluster, but it will no longer be the Master node.

If you have a strong reason to return the former-Master node to be the Master node after it has been rejoined, you would need to log in to the former Master and, one at a time, remove all nodes from the cluster. At that point, the former Master node will become the new Master node. You can then rejoin the removed nodes to the cluster.