Vault - autounseal-prod-vault.hcl (Transit unseal)
Vault Solution · Config document · referenced from Initialization and Transit auto-unseal, Authentication and policies
The policy that lives on the COMMON cluster and is attached to the token the PROD cluster uses to unseal itself. NONPROD has the same policy with nonprod in the two paths.
| Item | Value |
|---|---|
| Path on the host | /etc/vault.d/policy/autounseal-prod-vault.hcl |
| Policy name in Vault | autounseal-prod-vault |
| Loaded on | COMMON only |
| Used by | the token in the seal "transit" block of every PROD node |
| Twin | autounseal-nonprod-vault, paths transit/encrypt/autounseal-nonprod-vault and transit/decrypt/autounseal-nonprod-vault |
The file
############################################################################ # AUTOUNSEAL POLICY - PROD Vault cluster ############################################################################ # The only thing the token of the PROD cluster may do on the COMMON cluster: # encrypt and decrypt with its own transit key. path "transit/encrypt/autounseal-prod-vault" { capabilities = [ "update" ] } path "transit/decrypt/autounseal-prod-vault" { capabilities = [ "update" ] }
Checked against Vault 2.1
This is still exactly the policy the Transit seal documentation shows: update on <mount>/encrypt/<key> and <mount>/decrypt/<key>, nothing else. See Transit seal, authentication.
What changed is the advice about the token that carries it. The documentation recommends an orphan, periodic token without an explicit maximum lifetime, renewed by the cluster that uses it. As built, the token had a fixed lifetime of three years and no renewal that could extend it; see Initialization and Transit auto-unseal.