Replacing vSAN Witness and Reconfiguring Stretched Cluster Fault Domains
search cancel

Replacing vSAN Witness and Reconfiguring Stretched Cluster Fault Domains

book

Article ID: 446196

calendar_today

Updated On:

Products

VMware vSAN

Issue/Introduction

Symptoms:

Users may need to reconfigure a vSAN Stretched Cluster if:

  • Fault domains were initially built with incorrect host assignments (e.g., hosts intended for the Secondary site are assigned to the Preferred site).
  • The vSAN Witness Appliance needs to be replaced due to decommissioning of the hosting hardware or resource optimization.
  • Physical hosts need to be swapped between existing fault domains.

Purpose

This article provides the recommended procedure to replace a vSAN Witness Appliance and reconfigure fault domains to ensure correct site-to-host mapping and object health.

Environment

VMware vSAN 8.X

Resolution

Phase 1: Preparation & Pre-Checks

  1. Deploy New Witness: Download the vSAN Witness Appliance OVA (matching the ESXi build version of your data nodes) and deploy it to a host/cluster outside of the vSAN cluster being protected.
  2. Configure Networking: Set up Management and vSAN VMkernel ports on the new Witness. Ensure L3 connectivity between the Witness and all data nodes.
  3. Add to vCenter: Add the new Witness Appliance to vCenter inventory as a standalone host.
  4. Health Check: Navigate to Cluster > Monitor > vSAN > Skyline Health. Ensure the cluster is 100% healthy with no active resyncs or inaccessible objects.

Phase 2: Disable the Stretched Cluster

  1. Navigate to your vSAN Cluster in the vSphere Client.
  2. Go to Configure > vSAN > Fault Domains.
  3. Click the Disable button for the Stretched Cluster.
  4. Acknowledge the warning. vSAN will remove the current witness and collapse the fault domains into a standard cluster configuration.
  5. Wait for the task to complete. Objects will temporarily show a state of Reduced Availability - No Rebuild, which is expected as witness components are removed.

Phase 3: Reconfigure Stretched Cluster

  1. Under Configure > vSAN > Fault Domains, click Configure Stretched Cluster.
  2. Assign Hosts: Select the correct list of ESXi hosts for the Primary/Preferred site and the Secondary site.
  3. Select Witness: Choose the newly deployed Witness Appliance.
  4. Claim Disks: Claim the cache and capacity disks for the new Witness host.
  5. Review the configuration carefully to ensure site mappings are correct, then click Finish.

Phase 4: Post-Configuration Monitoring

  1. Navigate to Monitor > vSAN > Resyncing Objects. vSAN will begin pushing new witness components to the new appliance.
  2. Once the resync queue reaches zero, perform a final Skyline Health check.
  3. Verify all objects are Compliant and healthy.
  4. Power off and delete the old Witness appliance from inventory.

Impact / Risks

  • Reduced Availability: While the stretched cluster is disabled or reconfiguring, objects lose their witness component. A site failure during this window could lead to data unavailability.
  • Data Migration: If VMs use site-affinity policies (e.g., 'Keep data on Preferred'), swapping hosts between domains will trigger a significant data migration across the inter-site link. Ensure sufficient bandwidth is available.
  • Witness Sizing: Ensure the replacement witness is appropriately sized (Medium/Large) for the object count in the cluster to avoid performance issues during component generation.