Skip to main content

Management server failover (WSFC)

Upgrade the cluster nodes

Last Updated: 2 minute read

Start with the inactive nodes to keep the Management Server running while you upgrade each node. A system downtime will occur while you upgrade the final node.

  1. In Failover Cluster Manager, under Nodes, pause an inactive node that is part of the XProtect management server failover cluster) by selecting Drain Roles.

  2. On the paused node: start the XProtect installer and follow the regular upgrade procedure to upgrade the Management Server and API Gateway components:

    • Run the installer.

    • Select Let the installer create or upgrade the database.

      This allows for potential upgrades to the database structure while preserving your existing data.

    • Point the installer to the cloned database.

  3. Repeat steps 1–2 until only the active node remains.

  4. Pause the last node running the old XProtect version.

    Note

    The system downtime begins.

  5. Upgrade the last node using the same process. The final node must also point to the cloned database.

  6. While the last node is upgrading, resume one upgraded node by selecting Fail Roles Back.

  7. On the resumed node: open Server Configurator and update the registration to use the cluster role address instead of the local hostname.

  8. Stop the Management Server service.

  9. Pause the current node after the next node is resumed.

  10. Repeat steps 7–9 for all upgraded nodes, but the last. For the final node, once the installation of the new XProtect version completes, skip step 9.

  11. Restore encryption (if applicable).

  12. Resume all nodes.

  13. In Failover Cluster Manager, right-click the role and select Move > Best Possible Node.

    This also verifies that the upgrade was successful by confirming that Management Server starts correctly on another node.

    Note

    The system downtime ends and normal operation resumes.

After you have upgraded all cluster nodes, upgrade the remaining XProtect components that are not part of the Management Server failover cluster.