How to Set Up HashiCorp Vault on a VPS: TLS, Policies, and Backups

Updated on Apr 17, 2026
Mathew M
18 MINS READ
Table of Contents
Secrets Management with HashiCorp Vault on VPS

HashiCorp Vault is an enterprise-grade secrets management tool designed to securely store, access, and manage sensitive data such as API keys, passwords, certificates, and encryption keys. This guide intends to teach you a full setup for Secrets Management with HashiCorp Vault on VPS.

Unlike traditional methods, Vault provides centralized secrets management with strong encryption, access control, and audit capabilities.

Key features of HashiCorp Vault include:

  • Centralized Secret Storage: Encrypts secrets at rest and stores them in a backend of your choice.
  • Dynamic secrets: Generates short-lived credentials on demand and can rotate and revoke them automatically.
  • Encryption as a service: Apps encrypt and decrypt without handling encryption keys directly.
  • Access control policies: Use path-based rules to grant fine-grained permissions.
  • Audit logging: Records Vault activity for security reviews and compliance.
  • High availability: Runs in clusters with failover for production reliability.

You can proceed to the following steps to set up HashiCorp Vault on a VPS, including installation, configuration, and secrets management.

If you need a reliable VPS server, you can visit PerLod Hosting, which offers the best plans to deploy HashiCorp Vault secret management.

Prerequisites for Setting Up Secrets Management with HashiCorp Vault on VPS

To set up secrets management with HashiCorp Vault on VPS, you need some requirements. Be sure to meet these prerequisites:

  • A VPS running Ubuntu 22.04 or later.
  • Root or sudo access to the server.
  • At least 2GB RAM and 20GB disk space.
  • SSH access to your VPS.
  • A domain name or IP address for accessing Vault.

If you need a reliable Linux VPS with full sudo access and public networking, PerLod provides the best services for your needs.

Connect to your VPS via SSH and update the system packages with the commands below:

Bash
sudo apt update && sudo apt upgrade -y

Install required dependencies for adding the HashiCorp repository:

Bash
sudo apt install gpg wget curl -y

Once you are done with these, proceed to the following steps to set up Secrets Management with HashiCorp Vault on VPS.

Step 1. Install HashiCorp Vault

To install Vault safely on your VPS, you can use HashiCorp’s official APT repository so the package can be installed and updated through your system’s package manager.

Add the HashiCorp GPG key to verify package authenticity with the command below:

Bash
wget -O- https://apt.releases.hashicorp.com/gpg | gpg --dearmor | sudo tee /usr/share/keyrings/hashicorp-archive-keyring.gpg > /dev/null

Add the HashiCorp repository to your system with the following command:

Bash
echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list

Update the package index and install Vault with the following commands:

Bash
sudo apt updatesudo apt install vault -y

You can verify the installation by checking its version:

Bash
vault --version

Step 2. Create HashiCorp Vault User and Directories

At this point, you need to create a dedicated Vault user and the standard directories Vault needs for data, TLS files, and configuration. This allows Vault to run as a non-root user, separates its files into predictable locations, and applies restrictive permissions.

Create a dedicated system user for Vault with the command below:

Bash
sudo useradd --system --home /etc/vault.d --shell /bin/false vault

Create required directories for Vault data and configuration by using the following commands:

Bash
sudo mkdir -p /opt/vault/datasudo mkdir -p /opt/vault/tlssudo mkdir -p /etc/vault.d

Then, set up the correct ownership and permissions with the following commands:

Bash
sudo chown -R vault:vault /opt/vaultsudo chown -R vault:vault /etc/vault.dsudo chmod 750 /opt/vault/datasudo chmod 750 /etc/vault.d

Step 3. Generate TLS Certificates for Vault Secrets Management

TLS is required to protect Vault traffic in transit, especially on a VPS exposed to the internet. In this step, we want to generate a private key and a self-signed certificate for testing.

For production, replace the self-signed cert with one issued by a trusted CA to avoid errors.

Generate a private key with the following command:

Bash
sudo openssl genrsa -out /opt/vault/tls/vault-key.pem 2048

Create a certificate signing request configuration file with the command below:

Bash
sudo tee /opt/vault/tls/vault-csr.conf > /dev/null << EOF[req]default_bits = 2048prompt = noencrypt_key = nodefault_md = sha256distinguished_name = dnreq_extensions = v3_req [dn]CN = vault.yourdomain.comC = USST = StateL = CityO = OrganizationOU = IT Department [v3_req]basicConstraints = CA:FALSEkeyUsage = nonRepudiation, digitalSignature, keyEnciphermentextendedKeyUsage = serverAuthsubjectAltName = @alt_names [alt_names]DNS.1 = vault.yourdomain.comDNS.2 = localhostIP.1 = YOUR_VPS_IPIP.2 = 127.0.0.1EOF

Note: Replace vault.yourdomain.com with your actual domain and YOUR_VPS_IP with your VPS IP address.

Now use the following command to generate the CSR:

Bash
sudo openssl req -new -key /opt/vault/tls/vault-key.pem -out /opt/vault/tls/vault.csr -config /opt/vault/tls/vault-csr.conf

Create a self-signed certificate, which is valid for 365 days:

Bash
sudo openssl x509 -req -in /opt/vault/tls/vault.csr -signkey /opt/vault/tls/vault-key.pem -out /opt/vault/tls/vault-cert.pem -days 365 -extensions v3_req -extfile /opt/vault/tls/vault-csr.conf

Once you are done, set the correct permissions on the certificate files with the following commands:

Bash
sudo chown vault:vault /opt/vault/tls/*sudo chmod 600 /opt/vault/tls/vault-key.pemsudo chmod 644 /opt/vault/tls/vault-cert.pem

Step 4. Create Vault Configuration File

At this point, you must create the vault.hcl file, which is the main server config that tells Vault where to store data, how to accept client connections, and which addresses it should announce to clients and other Vault nodes.

Bash
sudo tee /etc/vault.d/vault.hcl > /dev/null << EOF# Storage Backend - Raft Integrated Storagestorage "raft" {  path    = "/opt/vault/data"  node_id = "node1"} # TCP Listener with TLSlistener "tcp" {  address       = "0.0.0.0:8200"  tls_cert_file = "/opt/vault/tls/vault-cert.pem"  tls_key_file  = "/opt/vault/tls/vault-key.pem"} # API and Cluster Addressesapi_addr      = "https://YOUR_VPS_IP:8200"cluster_addr  = "https://YOUR_VPS_IP:8201" # Enable UIui = true # Disable memory locking (required for non-root users)disable_mlock = true # Log levellog_level = "Info"EOF

Configuration Explanation:

  • path: Local directory where Raft stores data and snapshots.
  • node_id: Unique identifier for this Vault node in a cluster.
  • address = "0.0.0.0:8200": Binds to all network interfaces on port 8200.
  • tls_cert_file: Path to TLS certificate.
  • tls_key_file: Path to private key for TLS.
  • api_addr: External URL for Vault API, which is used by clients.
  • cluster_addr: Internal address for cluster communication on port 8201.
  • ui = true: Enables the web interface at https://YOUR_VPS_IP:8200/ui.
  • disable_mlock = true: Disables memory locking, required when running as a non-root user; prevents swapping secrets to disk.
  • log_level: Options are Trace, Debug, Info, Warn, Error. Info is recommended for production.

Also, set the correct permissions on the configuration file with the following commands:

Bash
sudo chown vault:vault /etc/vault.d/vault.hclsudo chmod 640 /etc/vault.d/vault.hcl

Step 5. Configure Vault as a System Service

To run Vault reliably in the background and start it automatically after reboots, you can set it up as a systemd service.

To create the systemd service file, run the command below:

Bash
sudo tee /lib/systemd/system/vault.service > /dev/null << 'EOF'[Unit]Description="HashiCorp Vault - A tool for managing secrets"Documentation=https://developer.hashicorp.com/vault/docsConditionFileNotEmpty=/etc/vault.d/vault.hclRequires=network-online.targetAfter=network-online.target [Service]Type=notifyUser=vaultGroup=vaultProtectSystem=fullProtectHome=read-onlyPrivateTmp=yesPrivateDevices=yesSecureBits=keep-capsAmbientCapabilities=CAP_IPC_LOCKCapabilityBoundingSet=CAP_SYSLOG CAP_IPC_LOCKNoNewPrivileges=yesExecStart=/usr/bin/vault server -config=/etc/vault.d/vault.hclExecReload=/bin/kill --signal HUP $MAINPIDKillMode=processKillSignal=SIGINTRestart=on-failureRestartSec=5TimeoutStopSec=30LimitNOFILE=65536LimitMEMLOCK=infinity [Install]WantedBy=multi-user.targetEOF

Set proper permissions on the service file with the following command:

Bash
sudo chmod 644 /lib/systemd/system/vault.service

Reload systemd to recognize the new service:

Bash
sudo systemctl daemon-reload

Enable and start the Vault service with the commands below:

Bash
sudo systemctl enable vaultsudo systemctl start vault

Check the service status that is active and running with the following command:

Bash
sudo systemctl status vault

To check logs and errors, you can use the command below:

Bash
sudo journalctl -u vault -n 50 --no-pager

Step 6. Set Vault CLI Environment Variables

To make the Vault CLI talk to your server without repeating flags on every command, you can set a few environment variables in your shell.

Set up environment variables for interacting with Vault with the commands below:

Bash
export VAULT_ADDR='https://YOUR_VPS_IP:8200'export VAULT_SKIP_VERIFY=1

The VAULT_SKIP_VERIFY=1 skips TLS certificate verification. It is only for self-signed certs in development; do not use it in production with proper certificates.

To make these settings permanent, add them to your shell profile with the commands below:

Bash
echo 'export VAULT_ADDR="https://YOUR_VPS_IP:8200"' | sudo tee -a /etc/profile.d/vault.shecho 'export VAULT_SKIP_VERIFY=1' | sudo tee -a /etc/profile.d/vault.shsudo chmod 644 /etc/profile.d/vault.shsource /etc/profile.d/vault.sh

Check Vault status with the following command:

Bash
vault status

You should see the following output that Vault is sealed and uninitialized:

Bash
Sealed: trueInitialized: false

Step 7. Initialize and Unseal Vault

Vault initialization will create the unseal key shares and the first (root) admin token, which must be captured immediately and stored securely, because Vault will not show them again and losing them can lock you out permanently.

Initialize Vault to generate unseal keys and root token with the command below:

Bash
vault operator init

This command generates 5 unseal keys by default and 1 root token.

Example output:

Bash
Unseal Key 1: 4jYbl2CBIv6SpkKj6Hos9iD32k5RfGkLzlosrrq/JgOmUnseal Key 2: B05G1DRtfYckFV5BbdBvXq0wkK5HFqB9g2jcDmNfTQiSUnseal Key 3: Arig0N9rN9ezkTRo7qTB7gsIZDaonOcc53EHo83F5chAUnseal Key 4: 6DJ26by8OC0YcbMXBZO9wJfRb0cI5LkQpDMfnVSPFTZeUnseal Key 5: GqQ8VYuOzp8l9DdNMiLFSQmm5aDDxQqGIsBjGsjRSSfl Initial Root Token: hvs.6j6aLuAq33GcdLQaHXRgztpM Vault initialized with 5 key shares and a key threshold of 3.

Essential security notes:

  • Save these keys and token securely in multiple locations.
  • Never commit them to version control.
  • At least 3 keys are required to unseal the Vault.
  • The root token has unlimited privileges; use it only for initial setup.
  • Loss of unsealed keys means permanent data loss.

For enhanced security, you can customize the key shares and threshold with the command below:

Bash
vault operator init -key-shares=5 -key-threshold=3

For production environments, consider using PGP encryption for unseal keys:

Bash
vault operator init \  -key-shares=5 \  -key-threshold=3 \  -pgp-keys="keybase:user1,keybase:user2,keybase:user3,keybase:user4,keybase:user5"

After initialization, Vault starts in a sealed state. You must unseal it using at least 3 of the 5 unseal keys with the command below:​

Bash
vault operator unseal

When prompted, enter the first unseal key. Repeat this command two more times with different keys:

Bash
vault operator unseal# Enter second key vault operator unseal# Enter third key

After the third key, check the status:

Bash
vault status

Important note: Vault will seal automatically when:

  • The service is restarted.
  • The server reboots.
  • An explicit seal command is issued.
  • A storage error occurs.

You must unseal the Vault every time it seals.

For production environments, you can implement auto-unseal using cloud KMS or HSM.

Step 8. Vault Authentication with Root Token

At this point, you can log in to Vault using the initial root token created during initialization, so you can perform the first setup tasks like enabling auth methods, creating policies, and configuring secrets engines.

Log in to Vault using the root token with the command below:

Bash
vault login

When prompted, enter your root token.

Alternatively, you can use this command:

Bash
vault login hvs.6j6aLuAq33GcdLQaHXRgztpM

Once authenticated, the token is stored in ~/.vault-token.

Root Token Warnings:

  • Root tokens have unrestricted access to all Vault operations and should only be used for initial configuration.
  • Revoke root token after creating administrative policies.
  • Use the principle of least privilege for all other operations.

Step 9. Enable and Configure Vault Secrets Engines

Secrets engines are how Vault actually stores and serves sensitive data or generates it. In this step, we want to enable the KV v2 secrets engine and then practice the core workflows.

Enable KV Version 2 Secrets Engine:

The KV (Key-Value) v2 engine provides versioned secret storage. To enable it, use the command below:

Bash
vault secrets enable -path=secret kv-v2

Check enabled secrets engines with the command below:

Bash
vault secrets list

Store Secrets:

Now you can store a secret with multiple key-value pairs with the command below:

Bash
vault kv put secret/myapp/database \username="dbuser" \password="SecureP@ssw0rd123" \host="db.example.com" \port="5432"

To store secrets from a file, you can run the command below:

Bash
vault kv put secret/myapp/api @api-credentials.json

Read Secrets:

To read the entire secret, you can use:

Bash
vault kv get secret/myapp/database

Or you can get a specific field only:

Bash
vault kv get -field=password secret/myapp/database

To get the secret in a JSON format, you can use this command:

Bash
vault kv get -format=json secret/myapp/database

Version Management:

To update a secret, you can run:

Bash
vault kv put secret/myapp/database \username="dbuser" \password="NewSecureP@ssw0rd456" \host="db.example.com" \port="5432"

This creates version 2. To read a specific version, you can run:

Bash
vault kv get -version=1 secret/myapp/database

View version history metadata with the command below:

Bash
vault kv metadata get secret/myapp/database

Rollback to the previous version with:

Bash
vault kv rollback -version=1 secret/myapp/database

This creates a new version (version 3) with the same data as version 1.

Delete and Destroy Secrets:

For a soft delete, you can use this command:

Bash
vault kv delete secret/myapp/database

Undelete a soft-deleted secret with the command below:

Bash
vault kv undelete -versions=2 secret/myapp/database

Permanently destroy specific versions with this:

Bash
vault kv destroy -versions=2 secret/myapp/database

Warning: Destroyed versions cannot be recovered.

Delete all versions and metadata with the command below:

Bash
vault kv metadata delete secret/myapp/database

Also, you can list all secrets at a path with this:

Bash
vault kv list secret/myapp

Step 10. Configure Vault Access Policies

Access policies are Vault’s core authorization mechanism, which define exactly who can do what, on which paths, using clear capabilities.

Policy Capabilities include:

  • create: Create new data at a path.
  • read: Read data from a path.
  • update: Update existing data at a path.
  • delete: Delete data at a path.
  • list: List keys at a path.
  • sudo: Gain root-protected access to paths.
  • deny: Explicitly deny access.

Read-Only Policy:

To create a policy file for read-only access, you can use this command:

Bash
tee read-only-policy.hcl > /dev/null << 'EOF'# Read-only access to all secrets under secret/myapp/path "secret/data/myapp/*" {  capabilities = ["read", "list"]} # Allow reading metadatapath "secret/metadata/myapp/*" {  capabilities = ["read", "list"]} # Allow token self-managementpath "auth/token/lookup-self" {  capabilities = ["read"]} path "auth/token/renew-self" {  capabilities = ["update"]}EOF

Then, write the policy to Vault:

Bash
vault policy write read-only read-only-policy.hcl

Admin Policy:

You can create a comprehensive admin policy file with:

Bash
tee admin-policy.hcl > /dev/null << 'EOF'# Read system health checkpath "sys/health" {  capabilities = ["read", "sudo"]} # Manage ACL policiespath "sys/policies/acl/*" {  capabilities = ["create", "read", "update", "delete", "list", "sudo"]} # Manage authentication methodspath "sys/auth/*" {  capabilities = ["create", "read", "update", "delete", "sudo"]} path "auth/*" {  capabilities = ["create", "read", "update", "delete", "list"]} # Manage secrets enginespath "sys/mounts/*" {  capabilities = ["create", "read", "update", "delete", "list", "sudo"]} # List existing secrets enginespath "sys/mounts" {  capabilities = ["read"]} # Manage the Key-Value secrets enginepath "secret/*" {  capabilities = ["create", "read", "update", "delete", "list"]} # Manage audit devicespath "sys/audit/*" {  capabilities = ["create", "read", "update", "delete", "list", "sudo"]} # Read audit device configurationpath "sys/audit" {  capabilities = ["read", "sudo"]}EOF

Write the admin policy to the Vault:

Bash
vault policy write admin admin-policy.hcl

Application Policy:

Create a policy for application access with the command below:

Bash
tee app-policy.hcl > /dev/null << 'EOF'# Application can create, read, update secrets under its pathpath "secret/data/myapp/*" {  capabilities = ["create", "read", "update"]} # Application can list secretspath "secret/metadata/myapp/*" {  capabilities = ["list", "read"]} # Application can manage its own tokenpath "auth/token/renew-self" {  capabilities = ["update"]} path "auth/token/lookup-self" {  capabilities = ["read"]}EOF

Write the policy:

Bash
vault policy write app-policy app-policy.hcl

You can list all policies and read a specific policy with the commands below:

Bash
vault policy listvault policy read admin

Vault can show you what policy is needed for a specific operation. To do this, you can run:

Bash
vault kv get -output-policy secret/myapp/database

Step 11. Configure Vault Authentication Methods

Authentication is how users and applications prove who they are to Vault before any policy rules are applied. In this step, we want to configure a few common auth methods, create credentials, and confirm everything is enabled and working.

Method1. Token Authentication: Tokens are the default authentication method.

To create a token with specific policies, you can run:

Bash
vault token create -policy=read-only -ttl=1h

To create a token with multiple policies, you can use:

Bash
vault token create -policy=read-only -policy=app-policy -ttl=24h

Method 2. UserPass Authentication: You can also use the userpass authentication method by enabling it with the command below:

Bash
vault auth enable userpass

Create a user with policies attached:

Bash
vault write auth/userpass/users/mila \  password="SecurePassword123!" \  policies="read-only,app-policy"

Log in with username and password:

Bash
vault login -method=userpass username=mila

Change a user's password by using the command below:

Bash
vault write auth/userpass/users/mila/password password="NewPassword456!"

Method 3. AppRole Authentication: AppRole is designed for automated workflows and applications.

Enable AppRole authentication with this command:

Bash
vault auth enable approle

Create an AppRole with policies:

Bash
vault write auth/approle/role/my-app \token_policies="app-policy" \token_ttl=1h \token_max_ttl=4h \secret_id_ttl=24h

Get the RoleID like a username:

Bash
vault read auth/approle/role/my-app/role-id

Generate a SecretID like a password:

Bash
vault write -force auth/approle/role/my-app/secret-id

Then, log in with AppRole:

Bash
vault write auth/approle/login \role_id="675a50e7-cfe0-be76-e35f-49ec009731ea" \secret_id="ed0a642f-2acf-c2da-232f-1b21300d5f29"

To view all enabled authentication methods, you can use:

Bash
vault auth list

Step 12. Enable Vault Audit Logging

Audit logging records Vault activity so you can trace who accessed which secrets, when, and from where. It is an essential control for security monitoring and compliance.

File Audit Device: You can enable file-based audit logging by using the commands below:

Bash
sudo mkdir -p /var/log/vaultsudo chown vault:vault /var/log/vaultvault audit enable file file_path=/var/log/vault/audit.log

Then, view audit devices:

Bash
vault audit list

Audit Log Format: Audit logs are written in JSON format, and each entry includes:

  • Request details.
  • Authentication information.
  • Response data.
  • Timestamp and duration.

Example audit log entry:

JSON
{  "time": "2024-12-18T10:45:32.123456Z",  "type": "response",  "auth": {    "client_token": "hmac-sha256:abc123...",    "accessor": "hmac-sha256:xyz789...",    "display_name": "token",    "policies": [      "app-policy",      "default"    ],    "token_policies": [      "app-policy",      "default"    ],    "metadata": null  },  "request": {    "id": "f3d2a1b4-...",    "operation": "read",    "client_token": "hmac-sha256:abc123...",    "client_token_accessor": "hmac-sha256:xyz789...",    "path": "secret/data/myapp/database"  },  "response": {    "data": {      "data": {        "password": "hmac-sha256:def456...",        "username": "hmac-sha256:ghi789..."      }    }  }}

Syslog Audit Device: For integration with centralized logging systems, you can use:

Bash
vault audit enable syslog tag="vault" facility="AUTH"

Socket Audit Device: You can send audit logs to an external service via TCP/UDP socket:

Bash
vault audit enable socket address="10.0.1.5:9090" socket_type="tcp"

Disable Audit Device:

Bash
vault audit disable file/

Warning: In production, always maintain at least one audit device for security compliance.

Audit Log Rotation: You can configure log rotation using logrotate:

Bash
sudo tee /etc/logrotate.d/vault > /dev/null << 'EOF'/var/log/vault/audit.log {    daily    rotate 30    compress    delaycompress    missingok    notifempty    create 0640 vault vault    postrotate        systemctl reload vault > /dev/null 2>&1 || true    endscript}EOF

Step 13. Access Vault Web UI

Vault’s Web UI provides a convenient way to manage secrets and access controls without relying only on the CLI.

From your desired browser, you can access it at:

HTML/XML
https://YOUR_VPS_IP:8200/uiorhttps://vault.yourdomain.com:8200/ui

Once you access the Vault UI, accept the self-signed certificate warning and select an authentication method:

  • Token: Enter root token or any valid token.
  • Username: Enter username and password if userpass is enabled.

Then, sign in to the Vault dashboard.

Note: For full UI functionality, users need appropriate policies. The UI automatically requires access to:

Bash
path "sys/internal/ui/mounts" {  capabilities = ["read"]} path "sys/internal/ui/mounts/*" {  capabilities = ["read"]}

These paths are automatically granted and cannot be modified.

Protect Vault Data: Backup and Recovery Options

In this step, you can learn how to protect Vault data and recover quickly from accidents or server failures using integrated Raft snapshots.

First, take a snapshot of Vault data:

Bash
vault operator raft snapshot save vault-snapshot-$(date +%Y%m%d-%H%M%S).snap

Verify the snapshot with:

Bash
vault operator raft snapshot inspect vault-snapshot-20241218-104530.snap

To restore from a snapshot, stop the Vault service with the command below:

Bash
sudo systemctl stop vault

Then, restore the snapshot:

Bash
vault operator raft snapshot restore -force vault-snapshot-20241218-104530.snap

Start and provide unseal keys with these commands:

Bash
sudo systemctl start vaultvault operator unseal

Also, you can create and use an automated backup script:

Bash
sudo tee /usr/local/bin/vault-backup.sh > /dev/null << 'EOF'#!/bin/bash # ConfigurationBACKUP_DIR="/opt/vault/backups"RETENTION_DAYS=30VAULT_ADDR="https://127.0.0.1:8200"VAULT_TOKEN_FILE="/root/.vault-token" # Create backup directory if it doesn't existmkdir -p "$BACKUP_DIR" # Set Vault addressexport VAULT_ADDR="$VAULT_ADDR"export VAULT_TOKEN=$(cat "$VAULT_TOKEN_FILE") # Create snapshot with timestampTIMESTAMP=$(date +%Y%m%d-%H%M%S)SNAPSHOT_FILE="$BACKUP_DIR/vault-snapshot-$TIMESTAMP.snap" # Take snapshotvault operator raft snapshot save "$SNAPSHOT_FILE" # Compress snapshotgzip "$SNAPSHOT_FILE" # Remove old backupsfind "$BACKUP_DIR" -name "vault-snapshot-*.snap.gz" -type f -mtime +$RETENTION_DAYS -delete echo "Backup completed: $SNAPSHOT_FILE.gz"EOF

Make the script file executable:

Bash
sudo chmod +x /usr/local/bin/vault-backup.sh

Schedule it with cron by using the commands below:

Bash
sudo crontab -e

Add this line:

Bash
0 2 * * * /usr/local/bin/vault-backup.sh >> /var/log/vault/backup.log 2>&1

Here are some backup best practices you can consider:

  • Regular Schedule: Automate backups daily or more frequently based on RPO.
  • Off-site Storage: Store backups in a separate location.
  • Encryption: Encrypt backups at rest and in transit.
  • Testing: Regularly test restore procedures to ensure backups are valid.
  • Retention Policy: Keep multiple generations of backups.
  • Monitoring: Alert on backup failures.
  • Documentation: Document restore procedures in runbooks.

Troubleshooting Common Vault Issues

Troubleshooting helps you quickly identify and fix the most common Vault problems. Here are the most common issues you may face and their solutions:

Issue 1: Vault is sealed after a restart.

The solution is to unseal Vault using 3 unseal keys or implement auto-unseal:

Bash
vault operator unseal

Issue 2: permission denied errors.

You must check the policies attached to your token:

Bash
vault token lookupvault policy read POLICY_NAME

Issue 3: TLS certificate errors.

Verify the certificate paths and permissions:

Bash
sudo ls -la /opt/vault/tls/sudo openssl x509 -in /opt/vault/tls/vault-cert.pem -text -noout

Issue 4: Vault service won't start.

Check logs for errors and fix them:

Bash
sudo journalctl -u vault -n 100 --no-pagersudo systemctl status vault

Issue 5: Cannot connect to Vault.

Verify listener configuration and firewall rules:

Bash
sudo netstat -tlnp | grep 8200sudo ufw status

For performance issues, you can check Vault performance metrics:

Bash
vault read sys/metrics

Monitor storage backend with:

Bash
vault operator raft list-peersvault operator raft autopilot state

Conclusion

At this point, you have learned to set up Secrets Management with HashiCorp Vault on VPS, including secure installation, TLS-enabled access, persistent Raft storage, systemd service management, initialization, unsealing, authentication, policies, secrets engines, auditing, and a basic backup workflow.

We hope you enjoy this guide. Subscribe to our X and Facebook channels to get the latest updates and articles.

For further reading:

VPS backups and disaster recovery strategies

Multi-Tenant VPS Hosting Architecture

Vault is used to securely store and control access to sensitive data and to provide encryption services and dynamic, short-lived credentials.

Vault has an open-source community edition and paid editions with additional enterprise features.

Yes. TLS protects secrets in transit between clients and the Vault API/UI, and it’s considered a baseline requirement for real deployments exposed over networks.