2.6 vSphere Cluster Services (vCLS) & Retreat Mode
Key Takeaways
vSphere Cluster Services (vCLS), introduced in vSphere 7.0 Update 1, runs small system VMs in each cluster that keep DRS working independently of vCenter's availability.
External vCLS VMs are tiny (1 vCPU, 128 MB of memory, and about 500 MB of storage each) and are managed by the system, not by administrators.
vSphere 8.0 Update 3 introduced Embedded vCLS, based on vSphere Pod technology, which is used automatically once vCenter and a cluster's ESXi hosts run 8.0 Update 3.
Retreat Mode deletes a cluster's vCLS VMs; before vSphere 9.0 this makes DRS non-functional and stops vSphere HA from choosing optimal placement during host failures.
Use Retreat Mode temporarily, for example to unmount a datastore that holds vCLS VMs or when vCLS VMs block an operation such as changing EVC on a vSAN cluster.
2.6 vSphere Cluster Services (vCLS) & Retreat Mode
What vCLS Does
Before vSphere 7.0 Update 1, DRS ran entirely inside vCenter, so a vCenter outage stopped DRS. vSphere Cluster Services (vCLS) moved the cluster-service "quorum" into the cluster itself: small vCLS VMs run on the cluster's hosts, and DRS requires a healthy vCLS to operate. vSphere HA uses DRS for placement recommendations, so vCLS indirectly matters for HA too.
| Property | External vCLS (7.0 U1 to 8.0 U2) | Embedded vCLS (8.0 U3 and later) |
|---|---|---|
| Implementation | Tiny appliance VMs deployed by vCenter | Based on vSphere Pod technology, fully system-managed |
| Size | 1 vCPU, 128 MB memory, about 500 MB storage each | Similarly small |
| Count | Up to three per cluster (fewer on one- or two-host clusters) | A small number per cluster |
| Allowed operations | Should not be powered off, deleted, or edited by users | Only power off and hard stop, for troubleshooting |
| When used | Clusters whose hosts all run ESXi 8.0 U2 or earlier | Automatically, once vCenter is on 8.0 U3 and a host in the cluster runs ESXi 8.0 U3 |
Both types appear in the inventory under a vCLS folder and in the cluster's root resource pool, and both are hidden from the Hosts and Clusters tree by default. Always update vCenter to 8.0 Update 3 before the hosts.
vCLS Health
The vSphere Client reports vCLS as Healthy, Degraded, or Unhealthy. If vCLS VMs are missing (deleted, powered off, failed to deploy, or removed by Retreat Mode), you see a message that DRS functionality was impacted because vSphere Cluster Service VMs are unavailable. While DRS is unhealthy, new VM placement, maintenance mode evacuations, and DRS APIs can fail, and configuring Workload Management (Supervisor) fails.
Retreat Mode (6.1)
Retreat Mode removes vCLS from a cluster: vCenter deletes the cluster's vCLS VMs and stops redeploying them until you exit Retreat Mode.
How to Enable It
- vCenter advanced setting (works in vSphere 7.0 U1 and later): in vCenter > Configure > Advanced Settings, add
config.vcls.clusters.domain-c<number>.enabledwith the valueFalse, wheredomain-c<number>is the cluster's managed object ID from the browser URL. Setting it back toTrueexits Retreat Mode. - vSphere Client: newer vSphere 8 updates expose the same choice under the cluster's Configure > vSphere Cluster Services settings (edit the vCLS mode to Retreat Mode).
Impact (vSphere 7 and 8)
| Service | Impact While in Retreat Mode |
|---|---|
| vSphere DRS | Not functional, even if enabled: no load balancing, and VMs are not migrated automatically when a host enters maintenance mode |
| vSphere HA | Still restarts VMs after a host failure, but does not perform optimal placement, because it relies on DRS recommendations, so VMs may start on a less suitable host |
| vSAN | Cluster service health shows Degraded |
| Supervisor | Workload Management configuration fails |
That is why the official sample question asks what happens during a host failure with Retreat Mode enabled: HA optimal placement is not available. HA itself is not disabled, and neither is EVC.
Use Cases for Retreat Mode
Use Retreat Mode temporarily, when vCLS VMs get in the way:
- Datastore maintenance, such as unmounting or retiring a datastore that holds vCLS VMs. In vSphere 7.0 U3 and later you can also choose which datastores vCLS may use, which often avoids this.
- Changing EVC on a vSAN cluster when powered-on vCLS VMs block the change.
- Host maintenance or a full cluster shutdown when vCLS VMs cannot be moved.
- Troubleshooting vCLS deployment failures, or preparing for a vCenter downgrade.
After the task, exit Retreat Mode so vCenter redeploys the vCLS VMs and DRS recovers. Leaving a cluster in Retreat Mode means running without DRS.
Version note: In vSphere 9.0, vCLS is deprecated, and disabling it no longer affects DRS or HA. The exam targets vSphere 8.0, where the impacts above apply.
Troubleshooting Walkthrough: Datastore Retirement
- Find the cluster's ID. Select the cluster in the vSphere Client; the browser URL contains its managed object ID, such as
domain-c8. - Enter Retreat Mode. On the vCenter object, open Configure > Advanced Settings and add
config.vcls.clusters.domain-c8.enabled = False(or use the vCLS mode setting in newer clients). Within a short time vCenter deletes the cluster's vCLS VMs. The cluster summary then warns that DRS is impacted. - Do the work. Unmount and retire the datastore, or complete the EVC change or maintenance task that the vCLS VMs were blocking.
- Exit Retreat Mode. Set the value back to
True. vCenter redeploys the vCLS VMs on suitable hosts and datastores. - Verify. vCLS health returns to Healthy, DRS recommendations resume, and maintenance mode evacuates VMs again.
Living with vCLS Day to Day
- Leave the VMs alone. Do not rename, power off, move, snapshot, or delete vCLS VMs. vCenter manages them, and manual changes make DRS unhealthy.
- Control placement with policies, not rules. If a vCLS VM must stay away from particular workloads, for example for licensing, use the vCLS anti-affinity compute policy rather than editing the system VMs.
- Exclude them from bulk scripts. Automation that powers off every VM in a cluster should skip the vCLS folder.
- Plan for maintenance. In a one-host or two-host cluster, vCLS VMs may have nowhere to move during maintenance, which is one of the documented reasons to use Retreat Mode briefly.
An administrator enables vSphere Cluster Services (vCLS) Retreat Mode on a three-host vSphere 8 cluster that has HA and DRS enabled. What is the impact if a host fails?
vSphere HA is disabled on the cluster and no VMs are restarted
Enhanced vMotion Compatibility is disabled for the cluster
vSphere HA restarts the VMs, but optimal placement is not available because DRS is not functional
vSphere DRS automatically switches to Partially Automated mode
A storage administrator must unmount and decommission a datastore that currently holds the vCLS VMs for a vSphere 8 cluster. What should the vSphere administrator do?
Power off the vCLS VMs manually and delete their folder
Disable vSphere HA, unmount the datastore, and re-enable HA
Convert the vCLS VMs to templates in a content library
Put the cluster in Retreat Mode (or change the allowed vCLS datastores), complete the datastore work, then exit Retreat Mode
After a cluster was placed in Retreat Mode for troubleshooting and never returned to normal, users report that VMs are no longer rebalanced and a host entering maintenance mode does not evacuate its running VMs. What explains this?
DRS is not functional while vCLS is in Retreat Mode
The cluster's EVC mode was lowered automatically
Storage DRS was disabled on the cluster's datastore cluster
vSphere HA admission control is blocking every migration
Sections you finish are checked off in the contents.