A Vault operator deploys a single Vault server using Integrated Storage (Raft) as the storage backend. After initializing Vault, the operator notices that the server is marked as sealed and cannot serve requests. The operator has the unseal keys but wants to understand the architectural reason why Vault starts sealed after initialization. Which statement best explains why Vault is sealed immediately after initialization?
Initialization creates the master key, which encrypts the barrier, and splits it into unseal keys using Shamir's Secret Sharing. Until a threshold of unseal keys is provided, the master key cannot be reconstructed, so the barrier remains sealed. This design ensures that even if storage is compromised, data stays encrypted. The operator must run vault operator unseal with enough keys to transition to an unsealed state.
Why this answer
Vault's security barrier encrypts all data before it reaches the storage backend. During initialization, Vault generates a master key and splits it into unseal keys. The barrier remains sealed until a threshold of unseal keys is provided to reconstruct the master key.
This ensures that storage alone is insufficient to access secrets. The other options confuse Raft quorum, root token usage, or TLS with the unsealing mechanism.
Exam trap
The trap here is assuming that Raft quorum or root token usage automatically unseals Vault, when unsealing is solely about reconstructing the master key via unseal keys.