LINUXOR.SK ... open source notes ...

Vault - autounseal-prod-vault.hcl (Transit unseal)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Initialization and Transit auto-unseal, Authentication and policies

The policy that lives on the COMMON cluster and is attached to the token the PROD cluster uses to unseal itself. NONPROD has the same policy with nonprod in the two paths.

ItemValue
Path on the host/etc/vault.d/policy/autounseal-prod-vault.hcl
Policy name in Vaultautounseal-prod-vault
Loaded onCOMMON only
Used bythe token in the seal "transit" block of every PROD node
Twinautounseal-nonprod-vault, paths transit/encrypt/autounseal-nonprod-vault and transit/decrypt/autounseal-nonprod-vault

The file

hcl
############################################################################
# AUTOUNSEAL POLICY - PROD Vault cluster
############################################################################
# The only thing the token of the PROD cluster may do on the COMMON cluster:
# encrypt and decrypt with its own transit key.

path "transit/encrypt/autounseal-prod-vault" {
   capabilities = [ "update" ]
}

path "transit/decrypt/autounseal-prod-vault" {
   capabilities = [ "update" ]
}

Checked against Vault 2.1

This is still exactly the policy the Transit seal documentation shows: update on <mount>/encrypt/<key> and <mount>/decrypt/<key>, nothing else. See Transit seal, authentication.

What changed is the advice about the token that carries it. The documentation recommends an orphan, periodic token without an explicit maximum lifetime, renewed by the cluster that uses it. As built, the token had a fixed lifetime of three years and no renewal that could extend it; see Initialization and Transit auto-unseal.

← solutionz