When you install Cryptographic Security Platform Vault, the process creates a Cryptographic Security Platform Vault node that can operate singly or be joined with other Cryptographic Security Platform Vault nodes to form an active-active cluster. These nodes can be installed in different geographic locations, but they must be able to communicate with each other, with the Policy Agent installed on the encrypted servers associated with the cluster, and other nodes, for example KMIP, HTSV, or BYOK.

All Cryptographic Security Platform Vault nodes in a cluster share configuration settings, keys, and policy information. Changes made on one node are automatically synced to all nodes in the cluster through an encrypted object store. This provides a failover mechanism in case a Cryptographic Security Platform Vault node becomes unreachable.

The Cryptographic Security Platform Vault nodes constantly exchange heartbeats to verify that every node in the cluster is reachable. If all nodes respond to the heartbeats, the cluster is considered "healthy". If one or more nodes stop responding for a given length of time, the cluster is considered "degraded". If a cluster is degraded, the active Cryptographic Security Platform Vault nodes can still serve requests for keys and policies from the associated Policy Agents, but you cannot make changes to the nodes in the cluster.

The heartbeat interval and status thresholds are user-configurable for the cluster. For details, see Setting Cluster Options.