LINUXOR.SK ... open source notes ...

Vault - vault.hcl (server configuration)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Vault server configuration, Initialization and Transit auto-unseal

noteThe seal "transit" block held the unseal token inline in the file as built. It is a placeholder here, and the section at the end says what to do instead. Do not copy disable_cache or raw_storage_endpoint without reading that section first.

The one configuration file of the Vault server, as it ran on prod-vault-node1 under Vault 1.14. Every node of every cluster carried the same file; only the values in the two tables below the file changed.

ItemValue
Path on the host/etc/vault.d/vault.hcl
Owner and modevault:vault, 0644
Deployed onall Vault nodes of PROD, NONPROD and COMMON
Shown hereprod-vault-node1
Applied withsystemctl restart vault

The file

hcl
#------------------------------------------------------------------------------
# File: vault.hcl
# Description: Hashicorp Vault configuration
# Author: admin01
# Date: 2023
#
# REF-1: https://developer.hashicorp.com/vault/docs/configuration
# REF-2: https://developer.hashicorp.com/vault/docs/configuration/listener/tcp
# REF-3: https://developer.hashicorp.com/vault/docs/configuration/storage/raft
# REF-4: https://developer.hashicorp.com/vault/docs/configuration/seal/transit
#------------------------------------------------------------------------------

#------------------------------------------------------------------------------
# Basic configuration
#------------------------------------------------------------------------------
# Specifies the identifier for the Vault cluster.
cluster_name = "prod-vault"

# Specifies the address to advertise to other Vault servers in the cluster for
# request forwarding.
cluster_addr  = "https://prod-vault-node1.example.net:8201"

# Specifies the address (full URL) to advertise to other Vault servers in the
# cluster for client redirection.
# With load balancer    - api_addr = FQDN of the LoadBalancer
# Without load balancer - api_addr = FQDN of the Vault node
api_addr      = "https://prod-vault.example.net:8200"

# Enabling GUI
ui = "true"

# Disabling mlock is strongly recommended if using integrated storage due to the
# fact that mlock does not interact well with memory mapped files such as those
# created by BoltDB, which is used by Raft to track state.
disable_mlock = "true"

# Disabling all caches within Vault, including the read cache used by the physical
# storage subsystem.
disable_cache = "true"

# Default and max lease duration for tokens and secrets
max_lease_ttl = "10h"
default_lease_ttl = "10h"

# Enables the sys/raw endpoint which allows the decryption/encryption of raw data
# into and out of the security barrier.
raw_storage_endpoint = "true"

# Disabling using seal wrapping for any value except the master key. If this
# value is toggled, the new behavior will happen lazily (as values are read or written).
# (Vault Enterprise parameter)
disable_sealwrap = "true"

# ?
disable_printable_check = "true"

#------------------------------------------------------------------------------
# Network configuration
#------------------------------------------------------------------------------
# Listener on the loopback interface - for administration purposes only.
listener "tcp" {
  # Specifies the address to bind to for listening.
  address    = "127.0.0.1:8200"

  # Disabling TLS
  tls_disable = "true"
}

# Configuration of the listener on the IP address of the Vault node.
listener "tcp" {
  # Specifies the address to bind to for listening.
  address    = "10.10.1.34:8200"

  # Specifies the address to bind to for cluster server-to-server requests.
  cluster_address = "10.10.1.34:8201"

  # Specifies the path to the certificate for TLS. It requires a PEM-encoded file.
  tls_cert_file      = "/opt/vault/tls/prod-vault-node1.example.net-cert.pem"

  # Specifies the path to the private key for the certificate. It requires a PEM-encoded file.
  # If the key file is encrypted, you will be prompted to enter the passphrase on server startup.
  tls_key_file       = "/opt/vault/tls/prod-vault-node1.example.net-key.pem"

  # PEM-encoded Certificate Authority file used for checking the authenticity of client.
  tls_client_ca_file = "/opt/vault/tls/prod-vault-node1.example.net-ca.pem"

  # Turns off client authentication for this listener.
  tls_disable_client_certs = "true"

  # Min and Max version of the TLS (TLS hardening)
  tls_min_version = "tls13"
  tls_max_version = "tls13"
}

#------------------------------------------------------------------------------
# Storage configuration
#------------------------------------------------------------------------------

storage "raft" {
  # The file system path where all the Vault data gets stored.
  path    = "/data"

  # The identifier for the node in the Raft cluster.
  node_id = "prod-vault-node1.example.net"

  # Enable verification of TLS certificates.
  tls_skip_verify = "false"

  retry_join {
    # The TLS server name to use when connecting with HTTPS. Should match one
    # of the names in the DNS SANs of the remote server certificate.
    leader_tls_servername   = "prod-vault-node1.example.net"

    # Address of a possible leader node.
    leader_api_addr         = "https://prod-vault-node1.example.net:8200"
  }

  retry_join {
    leader_tls_servername   = "prod-vault-node2.example.net"
    leader_api_addr         = "https://prod-vault-node2.example.net:8200"
  }

  retry_join {
    leader_tls_servername   = "prod-vault-node3.example.net"
    leader_api_addr         = "https://prod-vault-node3.example.net:8200"
  }

  retry_join {
    leader_tls_servername   = "prod-vault-node4.example.net"
    leader_api_addr         = "https://prod-vault-node4.example.net:8200"
  }

  retry_join {
    leader_tls_servername   = "prod-vault-node5.example.net"
    leader_api_addr         = "https://prod-vault-node5.example.net:8200"
  }
}

#------------------------------------------------------------------------------
# Seal configuration
#------------------------------------------------------------------------------
seal "transit" {
  # The full address to the Vault cluster.
  address = "https://common-vault.example.net:443"

  # The Vault token to use
  token = "<TRANSIT_UNSEAL_TOKEN>"

  # Disables the automatic renewal of the token in case the lifecycle of the
  # token is managed with some other mechanism outside of Vault, such as Vault
  # Agent.
  disable_renewal = "false"

  # The transit key to use for encryption and decryption.
  key_name = "autounseal-prod-vault"

  # The mount path to the transit secret engine.
  mount_path = "transit/"

  # Enable verification of TLS certificates.
  tls_skip_verify = "false"

  # Set this to true if Vault is migrating from an auto seal configuration.
  disabled = "false"
}

Per-node values

NodeListener addressCertificate filesnode_id
prod-vault-node110.10.1.34prod-vault-node1.example.net-{cert,key,ca}.pemprod-vault-node1.example.net
prod-vault-node210.10.1.35prod-vault-node2.example.net-{cert,key,ca}.pemprod-vault-node2.example.net
prod-vault-node310.10.1.36prod-vault-node3.example.net-{cert,key,ca}.pemprod-vault-node3.example.net
prod-vault-node410.10.1.37prod-vault-node4.example.net-{cert,key,ca}.pemprod-vault-node4.example.net
prod-vault-node510.10.1.38prod-vault-node5.example.net-{cert,key,ca}.pemprod-vault-node5.example.net

Per-environment differences

SettingPRODNONPRODCOMMON
cluster_nameprod-vaultnonprod-vaultcommon-vault
api_addrhttps://prod-vault.example.net:8200https://nonprod-vault.example.net:8200https://common-vault.example.net:8200
Listener network10.10.1.32/2810.20.1.32/2810.30.1.32/28
retry_join blocks553
seal "transit"present, key_name = "autounseal-prod-vault"present, key_name = "autounseal-nonprod-vault"absent: COMMON is unsealed by hand with Shamir key shares

Checked against Vault 2.1

Checked on 2026-10-02 against Vault 2.1.1, the configuration reference and the source at that tag. "Still valid" means the 1.14 file loads unchanged.

SettingStatus in 2.1What to do today
Booleans written as "true"Still valid; the reference now writes bare trueNothing
cluster_name, cluster_addr, api_addrStill validNothing
ui = "true"Still validThe design said the UI would be off; decide and make both agree
disable_mlock = "true"Still valid, and since 1.20 mandatory to set with Integrated Storage: the server refuses to start without itKeep it, and run without swap or with encrypted swap
disable_cache = "true"Still valid, discouraged: it "will very significantly impact performance"Remove it
max_lease_ttl, default_lease_ttlStill validNothing
raw_storage_endpoint = "true"Still valid, a highly privileged endpoint that is off by defaultRemove it; enable only for a specific recovery task
disable_sealwrapParsed, but an Enterprise parameter with no effect hereRemove it
disable_printable_checkParsed by the code, absent from the 2.x referenceNot verified; remove it unless a non-printable secret value requires it
Listener on 127.0.0.1 with tls_disableStill validAnyone with a shell on a node talks to Vault without TLS; prefer the TLS listener and VAULT_CACERT
tls_cert_file, tls_key_file, tls_client_ca_file, tls_disable_client_certsStill validNothing
tls_min_version, tls_max_version = "tls13"Still validNothing
tls_skip_verify inside storage "raft"Never was a parameter of this block; it is silently ignoredRemove the line
retry_join without leader_ca_cert_fileStill valid; the CA fields are optionalThe CA sat in the system trust store. That this is the fallback is implied by the reference, not stated
seal "transit" with an inline tokenStill accepted, strongly discouragedGive the token through the VAULT_TOKEN environment variable, or token = "file:///path", or let Vault Agent manage it and set disable_renewal
Any key written twiceA hard error since 1.21This file has none; check before upgrading older ones

Two things a 1.14 file does not have and a current one should consider: the PROXY protocol settings of the listener, so the audit log shows real client addresses behind a TCP load balancer, and a telemetry block.

← solutionz