X2 coordinates control quorum, metadata replication, and the default protection for new writes. Preview the complete impact, preserve enough eligible nodes, and let the cluster converge before relying on the new target.
01
Automatic mode follows eligible topology
Automatic mode chooses the largest whole-node failure target supported by the current eligible-node count: floor((eligible nodes - 1) / 2). X2 then targets 2 × tolerance + 1 control voters and metadata replicas.
1–2 eligible nodes
0 node failures 1 voter and metadata replica
3–4 eligible nodes
1 node failure 3 voters and metadata replicas
5–6 eligible nodes
2 node failures 5 voters and metadata replicas
7–8 eligible nodes
3 node failures 7 voters and metadata replicas
9–10 eligible nodes
4 node failures 9 voters and metadata replicas
“Eligible” means a node that can participate in the protection topology, not merely a node record that exists in configuration. A joining, unhealthy, drained, or otherwise ineligible node must not be counted as available protection.
02
Know exactly what the setting controls
Automatic mode follows eligible topology as it grows or shrinks. An explicit tolerance remains fixed until an administrator changes it.
Control-plane voter target: 2 × tolerance + 1.
Metadata-replica target: 2 × tolerance + 1.
Default object protection for new writes that inherit the system policy.
No implicit rewrite of existing object payloads or previously committed layouts.
New writes
This includes new objects, new versions, overwrites, and completed multipart uploads. Preview and Apply do not retroactively move existing payloads.
03
Preview first, then apply deliberately
Open Settings → Data Protection → Fault Tolerance.
Choose Automatic or set an explicit whole-node failure tolerance.
Select Preview impact. A successful preflight is not an applied change.
Review current and requested tolerance, target voters, target metadata replicas, affected inherited placement policies, and lower-protection exceptions.
Acknowledge any intentional policy that remains below the system default, then select Apply.
Monitor control, metadata, placement, scanner, and healing convergence before treating the target as available.
04
Placement policies may inherit or override
Policies that inherit the system setting move with the new default for future writes. An explicit placement-policy override may remain different, but a below-system exception must be visible in Preview and explicitly acknowledged.
Do not interpret an exception as increased protection. The effective protection of an object is determined by the policy and layout actually used when that object version is committed.
05
Expect writes to fail safely during insufficient protection
After an upward change, the cluster may need time to add voters, metadata replicas, or placement capacity. If the full requested protection cannot be met, affected new writes are rejected until the requirement can be satisfied.
Readiness, quorum, and placement health are separate signals. Check each required node and the component-specific status; a healthy load-balancer route alone is not proof that the protection change has converged.
06
Keep a recovery plan outside the cluster
Record the applied mode, tolerance, eligible-node count, and preview result.
Verify representative writes and reads through more than one node after convergence.
Monitor scanner and healing work after node or storage changes.
Test restore procedures independently. Fault tolerance, replication, healing, versioning, and Object Lock do not replace backup and recovery.