Choose a Recovery Path

Identify what was lost before making changes. Management access, Management state, and appliance data have different recovery paths.

Expired access leads to reconnection, lost Management to reconstruction, and lost appliance data to full recovery. Individual-node failure requires diagnostics and support. ERS reset is a separate destructive action.
Figure 1. Choose the procedure according to what was lost.
Situation Start here Required material

Management opens, but the appliance is disconnected

Reconnect the appliance. Expired cluster access or a Management restart does not by itself stop the appliance.

The appliance’s artifact bundle and access to its network.

Management or its state disk was lost; the appliance survives

Reconstruct Management and recover its configuration from the surviving appliance.

Fresh Management media and state disk, the artifact bundle, and a reachable appliance.

The Management administrator password was forgotten

Reconstruct Management. The ISO console does not reset Management accounts.

The same inputs as Management reconstruction.

Appliance machines or their data were lost

Recover the appliance from a full backup.

A full backup, matching artifact bundle, matching release bundle, compatible Management, and replacement machines.

One node failed

Check the node’s hypervisor, power, disks, and network; collect diagnostics and contact support before replacement.

Node name and failure time, topology, and retained recovery files. This manual does not define an individual-node replacement procedure.

An update stopped or needs attention

Preserve the recovery set and the displayed update state. See Updates and troubleshooting.

The source recovery set and the exact source and target versions.

ERS must be initialized again on an intact appliance

Review ERS reset. It removes active ERS data and configuration; it is not a backup restore.

Approval to delete the current ERS data and configuration.

Prepare before a Failure

Store completed full backups outside the appliance. Retain the matching artifact and release bundles where they remain available after loss of Management and the appliance. The artifact bundle contains private recovery keys; a full backup alone is insufficient.

Keep a record of the appliance version, node names, application hostname, topology, and external dependencies. External HSM key recovery belongs to the HSM administrator.