Learn to safely demote a primary cluster and promote a DR secondary cluster in HashiCorp Vault with minimal downtime and data integrity.
In this guide, you’ll learn how to safely demote the existing primary cluster in a Vault Disaster Recovery (DR) replication setup and then promote the DR secondary cluster to become the new primary. This procedure ensures minimal downtime and maintains data integrity across clusters.
Vault version 1.9+ installed on both clusters
Network connectivity between primary and secondary
Demoting the primary ensures there is no conflict when promoting the secondary.
Copy
Ask AI
# Verify your tokenvault token lookup# Demote primary to secondaryvault write -f sys/replication/dr/primary/demote
Demoting the primary will briefly interrupt Vault service on that cluster. Ensure maintenance windows and inform your team.
Expected warning:
Copy
Ask AI
WARNING! The following warnings were returned from Vault:* This cluster is being demoted to a replication secondary. Vault will be unavailable for a brief period and will resume service shortly.
WARNING! The following warnings were returned from Vault:* This cluster is being promoted to a replication primary. Vault will be unavailable for a brief period and will resume service shortly.
Node Address State Voter---- ------- ----- -----vault-3 10.1.101.108:8201 leader true
Test secrets engines:
Copy
Ask AI
vault secrets enable aws
Copy
Ask AI
Success! Enabled the aws secrets engine at: aws/
At this point, your DR secondary cluster is fully promoted and ready to operate as the new primary. All write and read operations should now succeed on this cluster.