After you have deployed a Cryptographic Security Platform Vault node, you cannot change its IP address, hostname, or domain name. In order to work around this restriction, you can do the following:
Deploy a new Cryptographic Security Platform Vault node using the IP address and hostname you want to use and join it with the original node to form a cluster.
For details, see Installation Overview.
- Update any Cluster Node Mappings that you have defined in your environment to use the new node. If you are replacing a standalone node, you must then make sure the new Node Mapping information has been successfully disseminated to all registered VMs before you continue. For more information, see High Availability Between a VM and the CSP Vault Cluster.
If there are any VMs that are registered directly with the old Cryptographic Security Platform Vault node, you need to update the Cryptographic Security Platform Vault list on those VMs or create a Cluster Node Mapping and assign that Node Mapping to the VMs. For details see Updating CSP Vault Node IP Addresses on an Individual VM or Managing the Cluster Node Mapping on a VM.
Tip: We highly recommend that you use a Cluster Node Mapping instead of registering VMs directly with Cryptographic Security Platform Vault to provide more flexibility and high availability between the VM and Cryptographic Security Platform Vault.
- When all VMs have been updated to use the new Cryptographic Security Platform Vault IP address, you can decommission the old Cryptographic Security Platform Vault node as described in Decommissioning a CSP Vault Node or you can simply remove it from the cluster and destroy the VM as described in Removing a CSP Vault Node from a Cluster.