Introduction
I recently set up a three-node Vault Enterprise HA cluster on OpenShift, using
HCP Vault as the auto-unseal provider via the transit secrets engine. On paper
this is a straightforward combination of well-documented features. In practice,
it was a series of traps — some subtle, some spectacular — that took multiple






