| Previous | Next |
| ERROR_RESOURCE_NOT_FOUND | ERROR_CANT_EVICT_ACTIVE_NODE |
ERROR_SHUTDOWN_CLUSTER
The cluster is being shut down.
ERROR_SHUTDOWN_CLUSTER is Win32 error 5008 (0x1390) and belongs to Failover clustering cluster-wide shutdown state. For ERROR_SHUTDOWN_CLUSTER, the system description identifies the immediate condition but does not identify the caller, object, policy, device, service instance, or transition that produced it.
Interpret ERROR_SHUTDOWN_CLUSTER at the API boundary that returned it. Capture ERROR_SHUTDOWN_CLUSTER before logging, cleanup, or another Windows call can replace the thread-local last-error value. For ERROR_SHUTDOWN_CLUSTER, compare the recorded inputs with the documented precondition for Failover clustering cluster-wide shutdown state rather than starting with a broad system repair.
Where this result appears
ERROR_SHUTDOWN_CLUSTERcan surface during Failover Cluster management during cluster-wide shutdown state.ERROR_SHUTDOWN_CLUSTERcan surface during Cluster service processing where the cluster service is intentionally shutting down and cannot accept the requested operation.ERROR_SHUTDOWN_CLUSTERcan surface during a role or node transition whose evidence includes shutdown initiator and reason.ERROR_SHUTDOWN_CLUSTERcan surface during automation expected to allow shutdown to complete, then reconnect to the restarted cluster; do not attempt configuration writes during teardown.
Likely causes
- For
ERROR_SHUTDOWN_CLUSTER, the cluster service is intentionally shutting down and cannot accept the requested operation. - For
ERROR_SHUTDOWN_CLUSTER, the management view for cluster-wide shutdown state changed before the request committed. - For
ERROR_SHUTDOWN_CLUSTER, a concurrent cluster transition invalidated node states and quorum state. - For
ERROR_SHUTDOWN_CLUSTER, the caller attempted recovery without first confirming that it could allow shutdown to complete, then reconnect to the restarted cluster; do not attempt configuration writes during teardown.
Diagnostic sequence
Diagnosis of ERROR_SHUTDOWN_CLUSTER starts with the exact request type: read, write, create, transition, validation, cancellation, or administrative action. For ERROR_SHUTDOWN_CLUSTER, identify the object generation and subsystem owner, then decide whether the failure happened before side effects, during a partial transition, or after completion. For ERROR_SHUTDOWN_CLUSTER, this ordering matters in Failover clustering cluster-wide shutdown state because a blind retry can hide stale state or repeat a non-idempotent change.
- For
ERROR_SHUTDOWN_CLUSTER, record shutdown initiator and reason. - For
ERROR_SHUTDOWN_CLUSTER, record node states and quorum state. - For
ERROR_SHUTDOWN_CLUSTER, record active clustered roles and drain status. - For
ERROR_SHUTDOWN_CLUSTER, record cluster log around shutdown start. - For
ERROR_SHUTDOWN_CLUSTER, record UTC timestamp, cluster functional level, and the cluster-wide shutdown state transition generation.
Correlate ERROR_SHUTDOWN_CLUSTER with the owning component’s operational log, the Windows System log, and any subsystem trace. Telemetry for ERROR_SHUTDOWN_CLUSTER should preserve native identifiers such as a path or file ID, handle generation, node or peer identity, policy ID, object version, offset and length, or transaction token. Retain decimal 5008, hexadecimal 0x1390, and the producing API even when a localized message is also shown.
State boundary to prove
The decisive boundary for ERROR_SHUTDOWN_CLUSTER is whether the cluster service is intentionally shutting down and cannot accept the requested operation. Prove or disprove that proposition using shutdown initiator and reason together with node states and quorum state. When observations for ERROR_SHUTDOWN_CLUSTER disagree, preserve both and inspect the transition between them instead of choosing the more convenient value.
A focused validation for ERROR_SHUTDOWN_CLUSTER should recreate the relevant part of this situation: a management agent polls during planned maintenance and receives this code. It suppresses remediation until the cluster returns. The negative case should keep the responsible condition unchanged and confirm error 5008; the recovery case should change only that condition and verify a successful result without an unrecorded side effect.
Suggested diagnostic fields
For error 5008, keep winerr_5008_api, winerr_5008_object, winerr_5008_state_before, winerr_5008_request, winerr_5008_first_status, winerr_5008_verification. These fields distinguish the initial state, requested transition, first status, and verified recovery result.
Handling, retry, and recovery
Allow shutdown to complete, then reconnect to the restarted cluster; do not attempt configuration writes during teardown. For ERROR_SHUTDOWN_CLUSTER, generate a focused cluster log for the failure window and preserve the first error rather than only the final management message.
Retry ERROR_SHUTDOWN_CLUSTER only after evidence shows a change in Failover clustering cluster-wide shutdown state. For ERROR_SHUTDOWN_CLUSTER, initialization, asynchronous completion, recall, or service readiness can justify bounded backoff; malformed metadata, invalid identifiers, policy rejection, unsupported versions, and integrity failures require correction. Before repeating a write or configuration operation after ERROR_SHUTDOWN_CLUSTER, query completion state explicitly.
What to log for support and telemetry
- For
ERROR_SHUTDOWN_CLUSTER, log decimal 5008, hexadecimal0x1390, and the producing API. - For
ERROR_SHUTDOWN_CLUSTER, log the target object and observed Failover clustering cluster-wide shutdown state state. - For
ERROR_SHUTDOWN_CLUSTER, log caller identity, process and thread IDs, machine or node identity, and UTC time. - For
ERROR_SHUTDOWN_CLUSTER, log attempt number, elapsed time, previous result, and any partial side effect. - For
ERROR_SHUTDOWN_CLUSTER, retain the first lower-level or component-specific error before Win32 translation.
Difference from nearby codes
For ERROR_SHUTDOWN_CLUSTER, eRROR_SHUTDOWN_CLUSTER names the cluster-specific boundary for cluster-wide shutdown state; a generic Win32 paraphrase would lose the object and transition context.
Practical example
A management agent polls during planned maintenance and receives this code. It suppresses remediation until the cluster returns.
Developer and administrator guidance
Code that handles ERROR_SHUTDOWN_CLUSTER should keep its Win32 domain visible across exceptions, RPC responses, and JSON or REST wrappers. For ERROR_SHUTDOWN_CLUSTER, administrators should verify the subsystem evidence before changing policy, deleting state, forcing failover, or replacing storage. Recovery is demonstrated only when a test observes 5008, changes the responsible condition, and confirms that the same operation succeeds without hidden data loss.
References
- Microsoft: System Error Codes (4000–5999) — reference for error 5008.
- Microsoft: Failover clustering documentation — reference for error 5008.
- Microsoft: Get-ClusterLog — reference for error 5008.
- Microsoft: Troubleshoot unexpected cluster failover — reference for error 5008.
Looking for a different code? Search another status or error code.