Vault deployments usually start small, a handful of services pulling secrets. As adoption grows, more systems lean on Vault for authentication, secret retrieval, and certificate issuance, and concurrency climbs with them. We ran a series of benchmarks on Vault Enterprise (self-managed) to see what actually breaks first at scale, not just in theory.

How we tested

All tests ran on a HashiCorp Validated Design deployment on AWS, Vault Enterprise 1.17.3+ent with integrated Raft storage. Load was generated with k6, ramping from 1 virtual user up to 500 for KV workloads, and up to roughly 200 to 300 VUs for SSH and PKI depending on the operation.

What we found

Reads consistently outperformed writes, roughly 2.3x faster, since writes have to commit and replicate across the Raft cluster while reads don't carry that overhead.