Thanks, LucD
Yup. Full KMS cluster in place, vm encryption has been working great, but recently, not all esx hosts are automatically entering safe mode to receive encrypted vms via vmotion/poweron.
I've opened a ticket with vmware support to investigate.