Prerequisites for Enabling vSphere Lifecycle Manager Live Patching for ESXi Hosts
search cancel

Prerequisites for Enabling vSphere Lifecycle Manager Live Patching for ESXi Hosts

book

Article ID: 419942

calendar_today

Updated On:

Products

VMware vCenter Server VMware vSphere ESX 8.x

Issue/Introduction

  • The Live Patch feature applies security patches and urgent bug fixes to ESXi hosts in a cluster managed by a vSphere Lifecycle Manager (vLCM) image. This feature causes minimal disruption to running workloads, as it does not require virtual machines to be placed in maintenance mode or rebooted.

  • By default, the Live Patch feature is disabled. vSphere Lifecycle Manager remediation settings must be configured at either the global or cluster level to activate it.

Environment

  • vCenter Server 8.0 Update 3

  • ESXi host 8.0 Update 3

Resolution

To enable Live Patching, ensure your environment meets the following requirements:

  • Version Compatibility: Both vCenter Server and all ESXi hosts in the cluster must run version 8.0 Update 3 or later.

  • Management Mode: Use the Live Patch functionality only for clusters managed by a vSphere Lifecycle Manager single image.

  • Host Support: All hosts in the cluster must support Live Patch functionality. Remediation is blocked if you attempt a live patch on hosts that require maintenance mode.

  • Patch Eligibility: The target host must be eligible for the specific live patch release of the VMware base image. The vSphere Lifecycle Manager image depot provides compatibility information for ESXi host image versions.

  • Hardware Compatibility: Live Patch is incompatible with systems configured with TPM devices or systems using DPUs via vSphere Distributed Services Engine.

    Note: Live Patch for systems with TPM devices are compatible starting vSphere 9.1. Refer: Configuring vSphere Lifecycle Manager for Live Patches

  • Virtual Machine Requirements: Virtual machines that do not support the Fast Suspend and Resume (FSR) mechanism must be migrated or power-cycled to apply hardware changes. Incompatible configurations include:

    • Fault Tolerance (FT) configured VMs.
    • DirectPath I/O (Passthrough) VMs.
    • vSphere pods.
    • Shared-Disk Clustering (e.g., Microsoft SQL Server VMs in FCI).

Note: These configurations trigger compliance warnings but do not block operations.

  • vSphere DRS: Enable vSphere DRS on the cluster before initiating a live patch.

  • Remediation Settings: Deactivate the parallel remediation setting. Live patches must be installed sequentially on hosts within the cluster.

For detailed steps on editing these settings, refer to the How to Configure the vSphere Lifecycle Manager Remediation Settings.

Additional Information

Refer to Configuring vSphere Lifecycle Manager for Live Patches for more details.