Vault - vault.hcl (server configuration)
Vault Solution · Config document · referenced from Vault server configuration, Initialization and Transit auto-unseal
noteThe
seal "transit" block held the unseal token inline in the file as built. It is a placeholder here, and the section at the end says what to do instead. Do not copy disable_cache or raw_storage_endpoint without reading that section first.The one configuration file of the Vault server, as it ran on prod-vault-node1 under Vault 1.14. Every node of every cluster carried the same file; only the values in the two tables below the file changed.
| Item | Value |
|---|---|
| Path on the host | /etc/vault.d/vault.hcl |
| Owner and mode | vault:vault, 0644 |
| Deployed on | all Vault nodes of PROD, NONPROD and COMMON |
| Shown here | prod-vault-node1 |
| Applied with | systemctl restart vault |
The file
#------------------------------------------------------------------------------ # File: vault.hcl # Description: Hashicorp Vault configuration # Author: admin01 # Date: 2023 # # REF-1: https://developer.hashicorp.com/vault/docs/configuration # REF-2: https://developer.hashicorp.com/vault/docs/configuration/listener/tcp # REF-3: https://developer.hashicorp.com/vault/docs/configuration/storage/raft # REF-4: https://developer.hashicorp.com/vault/docs/configuration/seal/transit #------------------------------------------------------------------------------ #------------------------------------------------------------------------------ # Basic configuration #------------------------------------------------------------------------------ # Specifies the identifier for the Vault cluster. cluster_name = "prod-vault" # Specifies the address to advertise to other Vault servers in the cluster for # request forwarding. cluster_addr = "https://prod-vault-node1.example.net:8201" # Specifies the address (full URL) to advertise to other Vault servers in the # cluster for client redirection. # With load balancer - api_addr = FQDN of the LoadBalancer # Without load balancer - api_addr = FQDN of the Vault node api_addr = "https://prod-vault.example.net:8200" # Enabling GUI ui = "true" # Disabling mlock is strongly recommended if using integrated storage due to the # fact that mlock does not interact well with memory mapped files such as those # created by BoltDB, which is used by Raft to track state. disable_mlock = "true" # Disabling all caches within Vault, including the read cache used by the physical # storage subsystem. disable_cache = "true" # Default and max lease duration for tokens and secrets max_lease_ttl = "10h" default_lease_ttl = "10h" # Enables the sys/raw endpoint which allows the decryption/encryption of raw data # into and out of the security barrier. raw_storage_endpoint = "true" # Disabling using seal wrapping for any value except the master key. If this # value is toggled, the new behavior will happen lazily (as values are read or written). # (Vault Enterprise parameter) disable_sealwrap = "true" # ? disable_printable_check = "true" #------------------------------------------------------------------------------ # Network configuration #------------------------------------------------------------------------------ # Listener on the loopback interface - for administration purposes only. listener "tcp" { # Specifies the address to bind to for listening. address = "127.0.0.1:8200" # Disabling TLS tls_disable = "true" } # Configuration of the listener on the IP address of the Vault node. listener "tcp" { # Specifies the address to bind to for listening. address = "10.10.1.34:8200" # Specifies the address to bind to for cluster server-to-server requests. cluster_address = "10.10.1.34:8201" # Specifies the path to the certificate for TLS. It requires a PEM-encoded file. tls_cert_file = "/opt/vault/tls/prod-vault-node1.example.net-cert.pem" # Specifies the path to the private key for the certificate. It requires a PEM-encoded file. # If the key file is encrypted, you will be prompted to enter the passphrase on server startup. tls_key_file = "/opt/vault/tls/prod-vault-node1.example.net-key.pem" # PEM-encoded Certificate Authority file used for checking the authenticity of client. tls_client_ca_file = "/opt/vault/tls/prod-vault-node1.example.net-ca.pem" # Turns off client authentication for this listener. tls_disable_client_certs = "true" # Min and Max version of the TLS (TLS hardening) tls_min_version = "tls13" tls_max_version = "tls13" } #------------------------------------------------------------------------------ # Storage configuration #------------------------------------------------------------------------------ storage "raft" { # The file system path where all the Vault data gets stored. path = "/data" # The identifier for the node in the Raft cluster. node_id = "prod-vault-node1.example.net" # Enable verification of TLS certificates. tls_skip_verify = "false" retry_join { # The TLS server name to use when connecting with HTTPS. Should match one # of the names in the DNS SANs of the remote server certificate. leader_tls_servername = "prod-vault-node1.example.net" # Address of a possible leader node. leader_api_addr = "https://prod-vault-node1.example.net:8200" } retry_join { leader_tls_servername = "prod-vault-node2.example.net" leader_api_addr = "https://prod-vault-node2.example.net:8200" } retry_join { leader_tls_servername = "prod-vault-node3.example.net" leader_api_addr = "https://prod-vault-node3.example.net:8200" } retry_join { leader_tls_servername = "prod-vault-node4.example.net" leader_api_addr = "https://prod-vault-node4.example.net:8200" } retry_join { leader_tls_servername = "prod-vault-node5.example.net" leader_api_addr = "https://prod-vault-node5.example.net:8200" } } #------------------------------------------------------------------------------ # Seal configuration #------------------------------------------------------------------------------ seal "transit" { # The full address to the Vault cluster. address = "https://common-vault.example.net:443" # The Vault token to use token = "<TRANSIT_UNSEAL_TOKEN>" # Disables the automatic renewal of the token in case the lifecycle of the # token is managed with some other mechanism outside of Vault, such as Vault # Agent. disable_renewal = "false" # The transit key to use for encryption and decryption. key_name = "autounseal-prod-vault" # The mount path to the transit secret engine. mount_path = "transit/" # Enable verification of TLS certificates. tls_skip_verify = "false" # Set this to true if Vault is migrating from an auto seal configuration. disabled = "false" }
Per-node values
| Node | Listener address | Certificate files | node_id |
|---|---|---|---|
prod-vault-node1 | 10.10.1.34 | prod-vault-node1.example.net-{cert,key,ca}.pem | prod-vault-node1.example.net |
prod-vault-node2 | 10.10.1.35 | prod-vault-node2.example.net-{cert,key,ca}.pem | prod-vault-node2.example.net |
prod-vault-node3 | 10.10.1.36 | prod-vault-node3.example.net-{cert,key,ca}.pem | prod-vault-node3.example.net |
prod-vault-node4 | 10.10.1.37 | prod-vault-node4.example.net-{cert,key,ca}.pem | prod-vault-node4.example.net |
prod-vault-node5 | 10.10.1.38 | prod-vault-node5.example.net-{cert,key,ca}.pem | prod-vault-node5.example.net |
Per-environment differences
| Setting | PROD | NONPROD | COMMON |
|---|---|---|---|
cluster_name | prod-vault | nonprod-vault | common-vault |
api_addr | https://prod-vault.example.net:8200 | https://nonprod-vault.example.net:8200 | https://common-vault.example.net:8200 |
| Listener network | 10.10.1.32/28 | 10.20.1.32/28 | 10.30.1.32/28 |
retry_join blocks | 5 | 5 | 3 |
seal "transit" | present, key_name = "autounseal-prod-vault" | present, key_name = "autounseal-nonprod-vault" | absent: COMMON is unsealed by hand with Shamir key shares |
Checked against Vault 2.1
Checked on 2026-10-02 against Vault 2.1.1, the configuration reference and the source at that tag. "Still valid" means the 1.14 file loads unchanged.
| Setting | Status in 2.1 | What to do today |
|---|---|---|
Booleans written as "true" | Still valid; the reference now writes bare true | Nothing |
cluster_name, cluster_addr, api_addr | Still valid | Nothing |
ui = "true" | Still valid | The design said the UI would be off; decide and make both agree |
disable_mlock = "true" | Still valid, and since 1.20 mandatory to set with Integrated Storage: the server refuses to start without it | Keep it, and run without swap or with encrypted swap |
disable_cache = "true" | Still valid, discouraged: it "will very significantly impact performance" | Remove it |
max_lease_ttl, default_lease_ttl | Still valid | Nothing |
raw_storage_endpoint = "true" | Still valid, a highly privileged endpoint that is off by default | Remove it; enable only for a specific recovery task |
disable_sealwrap | Parsed, but an Enterprise parameter with no effect here | Remove it |
disable_printable_check | Parsed by the code, absent from the 2.x reference | Not verified; remove it unless a non-printable secret value requires it |
Listener on 127.0.0.1 with tls_disable | Still valid | Anyone with a shell on a node talks to Vault without TLS; prefer the TLS listener and VAULT_CACERT |
tls_cert_file, tls_key_file, tls_client_ca_file, tls_disable_client_certs | Still valid | Nothing |
tls_min_version, tls_max_version = "tls13" | Still valid | Nothing |
tls_skip_verify inside storage "raft" | Never was a parameter of this block; it is silently ignored | Remove the line |
retry_join without leader_ca_cert_file | Still valid; the CA fields are optional | The CA sat in the system trust store. That this is the fallback is implied by the reference, not stated |
seal "transit" with an inline token | Still accepted, strongly discouraged | Give the token through the VAULT_TOKEN environment variable, or token = "file:///path", or let Vault Agent manage it and set disable_renewal |
| Any key written twice | A hard error since 1.21 | This file has none; check before upgrading older ones |
Two things a 1.14 file does not have and a current one should consider: the PROXY protocol settings of the listener, so the audit log shows real client addresses behind a TCP load balancer, and a telemetry block.