---
name: vmwaresolutions-hadr
title: High availability and disaster recovery for KMIP for VMware
description: As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
last-updated: 2026-03-05
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmwaresolutions?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# High availability and disaster recovery for KMIP for VMware
{: #kmip-hadr}

As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
{: deprecated}

**End of Marketing**: As of 17 July 2025, new deployments of VMware Regulated Workloads instances are no longer available for new customers. If you are an existing customer, you can still add or delete clusters, add or delete VMware ESXi™ servers or NFS storage, and add or remove services for your existing Regulated Workloads instances. As an existing customer, you can also view or delete your Regulated Workloads instances.
{: note}

## High availability within a region
{: #kmip-hadr-regional}

Within a single region:

* KMIP for VMware and Key Protect are highly available when correctly configured. If any one of the three zones in that region fail entirely, key management continues to be available to your VMware® workloads.
* KMIP for VMware and Hyper Protect Crypto Services (HPCS) are highly available if you deploy two or more crypto units for your HPCS instance. If you do so and any one of the three zones in that region fail entirely, key management continues to be available to your VMware workloads.

## Disaster recovery across regions
{: #kmip-hadr-cross-region}

When you are using VMware vSAN® encryption, each site is protected by its own key provider. If you are using vSAN encryption to protect workloads that you replicate between multiple sites, you must create separate KMIP for VMware instances in each site that is connected to separate Key Protect or HPCS instances in those sites. You must connect your VMware vCenter Server® in each site to the local KMIP for VMware instance as its key provider.

When you are using VMware vSphere® encryption, most VMware replication and migration techniques today (for example, cross-vCenter vMotion and vSphere replication) rely on having a common key manager between the two sites. This topology is not supported by KMIP for VMware. Instead, you must create a separate KMIP for VMware instance in each site that is connected to separate Key Protect or HPCS instances in those sites. You must connect your vCenter Server in each site to the local KMIP for VMware instance as its key provider, and then use a replication technology that supports the attachment and replication of decrypted disks.

Veeam Backup and Replication supports this replication technique. To implement this technique, see the [steps that you must take](https://helpcenter.veeam.com/archive/backup/120/vsphere/encrypted_vms_backup.html){: external} as indicated in the Veeam® documentation.

This technique does not support the replication of virtual machines with a vTPM device.
{: note}

## Related links
{: #kmip-hadr-related}

* [Solution overview](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip-overview&format=markdown)
* [Solution design](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip-design&format=markdown)
* [Implementation and management](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip-implementation&format=markdown)
* [Veeam and encrypted VMs](https://helpcenter.veeam.com/archive/backup/120/vsphere/encrypted_vms_backup.html){: external}