Update order priority for VSatellites¶
Update order priority allows PKI Administrators to control the sequence in which VSatellites are updated during rolling updates managed by CyberArk Certificate Manager - SaaS. This helps prevent simultaneous updates of critical components within the same high availability group or across environments like development, test, and production.
Features and benefits¶
-
Configurable update priority
Set a numeric update priority between 1 and 100 for each VSatellite. Instances with lower priority values are updated first. The default is 50 for VSatellites that do not have a priority assigned. -
Supports HA and standalone environments
Whether a VSatellite is part of a high availability group or deployed as a single instance, the update priority determines its place in the update sequence. -
Safe and predictable updates
Ensures controlled, rolling updates by updating only one VSatellite at a time. Other instances wait until the active update is complete. -
Flexible update methods
Edit update priority through the user interface or the API, depending on administrative preferences or automation needs. -
Built-in safeguards
Validation prevents values outside the supported range (1–100), and helpful tooltips explain behavior and input expectations.
Audience and use cases¶
This feature is designed for PKI Administrators who manage multiple VSatellites across different environments. It is especially useful in the following scenarios:
- Preventing all members of a high availability group from updating simultaneously.
- Updating VSatellites in lower environments (such as development and test) before production.
Requirements and compatibility¶
You can assign update priority only after the VSatellite is deployed.
Next steps¶
To assign or change an update priority, see Set update order priority for a VSatellite.