Node Action Availability and Blockers
Use this page when an action is hidden, disabled, rejected after confirmation, or missing from the node action menu.
Node actions are enabled based on the node state, node family, operating system, region, project permissions, attached services, billing state, and current operation status. The portal filters the menu first, and the request is checked again when you confirm the action.
Quick Checklist
Check these items first for any unavailable node action:
| Check | Why it matters |
|---|---|
| Node state | Transitional states such as Creating, Saving, Reinstalling, Upgrading, Powering off, Powering on, Stopping, Undeploying, and Terminating usually allow few or no changes. |
| Lock status | Locked nodes block most mutating actions. Unlock, backup enable/disable, and accidental-protection changes are limited exceptions. |
| Stopped state | Stopped E1 nodes allow only start and delete actions until started again. |
| Recovery Mode | Recovery Mode in progress or enabled can block normal lifecycle, image, snapshot, reinstall, and reboot actions. |
| Disaster Recovery role | DR source or target nodes can have restricted lifecycle, delete, transfer, plan, security, and network actions. DR target nodes allow only security group update where available. |
| Accidental Protection | Delete and reinstall are blocked while Accidental Protection is enabled. |
| Current operation | Wait for running lifecycle, storage, backup, image, snapshot, network, or billing changes to finish before starting another action. |
| Node family or OS | Some actions apply only to Linux, Windows, E1, non-E1 or supported node families. |
| Attached services | VPC, SFS, snapshots, backups, Add-on IPs, security groups, and file storage can affect action availability. |
| Permissions and project | The selected project, user role, location, and resource ownership must match the action. |
If the action was visible but fails after confirmation, refresh the node details page and check whether the node state or attached-resource state changed while the page was open.
DR Target Node Restrictions
When a node is marked as a Disaster Recovery target, MyAccount blocks node actions to protect the replicated target state.
For DR target nodes:
- Lifecycle actions such as start, power off, stop, reboot, reinstall, and delete are not allowed.
- Image, snapshot, backup, plan, storage, monitoring, SSH key, password, recovery, compliance, VPC, IP, and volume actions are not allowed.
- Security group update is the limited exception where the portal allows it.
If an action is disabled on a DR target node, manage the source DR plan or remove the node from the DR target workflow before retrying the node action.
Lifecycle Actions
| Action | Main availability requirements | Common blockers |
|---|---|---|
| Start | Node is Powered off, or an E1 node is Stopped. | Current operation, invalid state, DR restrictions. |
| Power Off | Node is Running. | Lock, Recovery Mode in progress, DR target role, DR source state that does not allow power off, transitional state. |
| Stop | E1-series node in a valid state. | Unsupported node family, invalid state, current operation. |
| Reboot | Node is Running. | Lock, Powered off or Stopped state, Failed/Undeployed/Suspended state, Recovery Mode, DR target role, transitional state. |
| Reinstall | Supported node type and valid node state. | Accidental Protection, lock, Powered off or Stopped state, Recovery Mode, DR role, deleted source saved image, unsupported node type, transitional state. |
| Delete | Node is in a safe deletion state. | Accidental Protection, lock, Recovery Mode, DR role, unsafe or transitional state. |
| Bulk actions | Selected nodes individually satisfy the selected action requirements. | Mixed node states, locks, Recovery Mode, DR role, stopped state, unsupported node family, more than 10 selected nodes. |
Image and Snapshot Actions
| Action | Main availability requirements | Common blockers |
|---|---|---|
| Save Image | Node family supports saved images; the node is in an accepted state. Some flows require the node to be powered off. | Lock, Stopped/Stopping/Deploying/Failed/Undeployed/Upgrading/Suspended state, Recovery Mode, DR target role, attached MS SQL license, unsupported node type. |
| Create Snapshot | Node family and attached storage support snapshots. | Lock, Stopped/Stopping/Deploying/Failed/Undeployed/Upgrading/Suspended state, DR target role, unsupported snapshot path. |
| Snapshot delete | Snapshot is not locked and is not required by another active operation. | Locked snapshot, active storage or root-storage operation, snapshot already deleting. |
| Save image from snapshot | Snapshot and selected image path support the conversion. | Unsupported snapshot type, deleted snapshot, incompatible target image path. |
Existing snapshots can also block some storage or root-storage upgrades until the snapshots are deleted.
Plan, Storage, and Billing Actions
| Action | Main availability requirements | Common blockers |
|---|---|---|
| Upgrade Node Plan | Node is usually Powered off and eligible for the selected target plan. | Lock, Stopped/Stopping/Deploying/Failed/Undeployed/Upgrading state, commitment restrictions, Windows flow restrictions, DR role, snapshots that must be deleted first. |
| Update Node Plan | E1 or other eligible node path with compatible target plans. | Node not in required power state, lock, unsupported node family, spot/private-cloud restrictions, current operation, no compatible plan. |
| Increase Root Storage | Supported E1-series node, Running or Powered off, larger valid size. | Lock, DR role, active snapshots, Recovery Mode, existing disk resize, invalid increment, insufficient free disk space for the upgrade check. |
| Convert to Committed | Eligible on-demand node and billing path. | Lock, Recovery Mode, DR target role, Deploying/Stopping/Failed/Undeployed/Upgrading state, spot or private-cloud node. |
CDP Backup Actions
| Action | Main availability requirements | Common blockers |
|---|---|---|
| Activate CDP Backup | Node supports CDP Backup, backup service is available in the node location, and connectivity validation passes. | DR target role, unsupported node type, invalid backup state, TCP port 1167 not enabled in the attached security group, no backup server currently available to handle the request. |
| Update backup policy | CDP Backup is already active and the selected policy is valid. | Backup service connection issue, backup not active, invalid policy, current backup or restore operation. |
| Deactivate backup | CDP Backup is active for the node. | Backup service connection issue, current backup or restore operation, invalid backup state. |
If CDP Backup activation fails because port 1167 is not enabled, update the node security group to allow inbound custom TCP traffic on port 1167, then retry activation after a few minutes.
If activation fails because no backup server is currently available to handle the request, retry later or contact support. This usually means the backup service is temporarily unavailable for the node location.
Network Actions
| Action | Main availability requirements | Common blockers |
|---|---|---|
| Attach primary public IP | An eligible IP is available in the project/location. | Lock, unsupported node family, invalid state, current operation, IP unavailable, project or location mismatch. |
| Detach primary public IP | Node has no Add-on IPs attached. | Add-on IPs still attached, lock, invalid state, current operation. Detach all Add-on IPs first. |
| Attach Add-on IP | Node already has a primary public IP. | Missing primary public IP, lock, invalid state, current operation, Add-on IP unavailable, project or location mismatch. |
| Detach Add-on IP | Add-on IP is attached to the node. | Lock, invalid state, current operation, IP state changed after page load. |
| Attach or detach IPv6 | Node family, location, and state support IPv6. | Lock, unsupported family or configuration, invalid state, current operation, project/location mismatch. |
| Attach, detach, or move Floating IP | Floating IP and target node are compatible. | Lock, invalid state, current operation, floating IP unavailable, target incompatibility, unsupported family/account/region. |
| Attach VPC | Active compatible VPC, valid node state, and available private IP capacity. | Lock, DR role, transitional state, 3 VPC attachments already present, 2 private IPs already attached from the selected VPC, selected subnet already used twice on the node, subnet full, preferred private IP unavailable or outside the subnet, incompatible location. |
| Detach VPC | VPC is attached and detaching it will not break protected relationships. | Lock, DR role, gateway VPC role, SFS connection, current VPC update in progress, invalid state. |
| Move to Another Project | Node and related resources are transferable. | Lock, Creating/Failed/Upgrading/Terminating state, DR role, attached VPC, more than one security group, associated file storage, transfer-blocking tags or resources, E1/private-cloud restrictions. |
For VPC and subnet configuration details, see Node Network.
Security Actions
| Action | Main availability requirements | Common blockers |
|---|---|---|
| Update SSH keys | Linux node path supports SSH key updates. | Unsupported operating system, lock, invalid state, DR target role, current operation. |
| Change password | Supported node and password path. | Lock, DR target role, invalid state, unsupported OS or access mode. |
| Enable or disable Accidental Protection | Node type and state support the setting. | Creating, Failed, Reinstalling, Upgrading, Stopped, Stopping, DR target role, unsupported older node type. |
| Enable Recovery Mode | Supported non-Windows node is Powered off. | Windows node, FortiGate node, spot node, unsupported node family, node not Powered off, Recovery Mode already enabled or in progress. |
| Disable Recovery Mode | Recovery Mode is enabled or in progress and the node can be returned to normal boot. | Current operation, invalid state, recovery workflow not settled. |
| Enable or disable Security Compliance | Eligible node type, location, network path, and state. | FortiGate node, unsupported location, Creating/Failed/Reinstalling/Upgrading/Stopped/Stopping state, lock, DR target role, unsupported VPC path. |
| Update security group | Security group update is available for the node or associated security group. | Permission issue, invalid security group rule, security group service error. This is the limited action that can remain available for DR target nodes. |
Encryption-Specific Notes
Node encryption is selected only during creation. It cannot be enabled for an existing non-encrypted node and cannot be disabled after launch.
For encrypted nodes, review action availability carefully for Disaster Recovery, snapshots, saved images, backups, and plan changes. If an action is missing, check the encrypted status together with node state, lock status, attached services, and plan eligibility.
What to Do Next
- Refresh the node details page.
- Check the node state and whether another operation is running.
- Check lock, Accidental Protection, Recovery Mode, and Disaster Recovery status.
- Review attached resources such as VPCs, security groups, snapshots, backups, SFS, public IPs, Add-on IPs, and volumes.
- Retry only after the blocking state is resolved.
If the portal still rejects a valid action, contact support with the node name, node ID, project, region, action attempted, and the exact error message.
Related Resources
| Resource | Use it for |
|---|---|
| Node Actions | Understand what each node action does. |
| Node Network | Manage IPs, VPCs, subnets, and private networking. |
| Node Security | Manage SSH keys, security groups, recovery mode, accidental protection, and compliance. |
| Node Images | Understand saved image behavior. |
| Node Snapshots | Understand snapshot behavior. |
| E1 Series Nodes | Review E1-specific Stop, root storage, and plan behavior. |