Discussion space for Vault and secrets management work.
Vault Deployment And Unseal Runbooks
Vault deployment work should be treated as security infrastructure, not just another stateful service. The runbooks need to cover normal operation and the uncomfortable moments: initialization, sealing, unsealing, leader changes, backup, and recovery. Deployment Baseline Document: storage backend. HA topology. TLS certificates. seal mechanism. audit devices. auth methods. backup and restore path. monitoring and alerting expectations. Vault should not run in production without audit logging and a tested recovery path. ...