When configuring and managing Disaster Recovery (DR) for Tanzu Hub environments, organizations often need clarity on which specific roles have the authorization to trigger a failover.
Specifically, administrators frequently ask if triggering a failover is strictly an Admin-only operation, or if it can be securely delegated to an Organization Group (OrgGroup) Manager. This article serves as a supplementary technique guide to the official documentation on Performing a Failover.
Tanzu Hub
Tanzu Platform for Cloud Foundry (TPCF)
Clarification is required around RBAC rules for failover operations to ensure that delegation of DR responsibilities aligns with the architectural security constraints of the platform.
An OrgGroup Manager is authorized and permitted to trigger a failover. This operation is not restricted exclusively to Administrators.
Allowing OrgGroup Managers to trigger failovers intentionally aligns with the existing permissions they hold within the platform's creation and management flows. Because an OrgGroup Manager already has the foundational permissions to:
Create spaces
Set topology with an active region
Remove regions
It is logically consistent for them to also have the ability to initiate a failover between those regions. Restricting this action solely to Administrators would disrupt the standard operational workflow for OrgGroup Managers.
For step-by-step instructions on executing the failover process, please refer to the official documentation: Perform a Failover.
This article serves as a supplementary technique guide to the official documentation. For complete, step-by-step instructions on executing the failover process, please refer to the official Broadcom documentation: