Vault stores it's own encryption key in it's own storage backend. The root key created during the Unseal step is the key to decrypt that key and not known to Vault or kept in the Storage Backend by design.
https://developer.hashicorp.com/vault/docs/concepts/seal#why
Vault stores the encrypted master key (and all its data) within its own storage backend, that is to say it does not store anything on the transit vault cluster but just uses it to decrypt the key.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
daz_rekka
10 months, 1 week agoad873cf
11 months ago