A virtual machine on vSAN is a set of objects: its namespace, its VMDKs, its swap, its snapshots. Each object is laid out as components according to its storage policy, mirrored across hosts for RAID-1, erasure-coded across four or six for RAID-5 and RAID-6, with witness components to break ties. A disk group on each host is one cache device and up to seven capacity devices, and a component lives on a capacity device in one disk group. When a device fails, every component on it is Degraded; when a host goes away, every component on it is Absent; a component that was absent and is back but behind the others is Active – Stale.
The health states follow. An object with enough components to satisfy its policy is healthy. One with a component absent is Reduced availability with no rebuild – delay timer, because vSAN waits before rebuilding an absent component in case the host returns; Broadcom's KB 327031 states the default is sixty minutes and names the setting VSAN.ClomRepairDelay, and from vSAN 6.7 U1 the same thing is set cluster-wide as the Object Repair Timer. When the timer expires the rebuild starts and the state becomes Reduced availability – active rebuild. An object with a degraded component rebuilds at once. And an object that has lost more components than its policy tolerates, two hosts in an FTT=1 cluster, a disk group and a witness, is Inaccessible: Broadcom's KB 326929 defines it as having suffered more failures, permanent or temporary, than it was configured to tolerate.
Inaccessible is where the bench starts. The components still exist on the capacity devices of the failed disk groups, in vSAN's on-disk format, and the objects are reassembled from them. Every device in every affected disk group is imaged, including the cache device, and the components read from the images with their metadata; the object is rebuilt from the components that are current, with stale ones used only where nothing else holds the block; the VMDK is extracted and its guest file system opened. The rebuild vSAN would have run reads the survivors under load and writes to whatever capacity is left, which on a cluster that has already lost two hosts is the wrong order.