Introduction

I recently set up a three-node Vault Enterprise HA cluster on OpenShift, using

HCP Vault as the auto-unseal provider via the transit secrets engine. On paper

this is a straightforward combination of well-documented features. In practice,

it was a series of traps — some subtle, some spectacular — that took multiple