Vault Shamir Unsealing and Auto-Unseal Lab (Interactive)
Reconstruct the master key with k of n custodian shards, or delegate unseal to Cloud KMS. Insert key shards into a sealed Vault, tune the (k,n) threshold, and compare human ceremony time and binomial quorum risk against milliseconds-scale auto-unseal.
Vault Sealed State: Shamir (k, n) Quorum Lab
The AES-256-GCM cryptographic barrier keeps every byte unreadable until k of n custodians reconstruct the master key — or Cloud KMS does it in milliseconds.
VAULT STATE: SEALED (0/3 keys provided)
Shamir splits the master key over GF(2^8) polynomial interpolation: any k shards reconstruct it, k−1 shards leak zero information. Fewer than k keys in RAM means the Raft store is ciphertext noise — even a full disk theft reveals nothing.
Manual ceremony time
~60 min
3 custodians × ~20 min each
P(quorum reachable)
94.2%
binomial: P(≥3 of 5 custodians on-call)
Secrets engines served while unsealed
KV v2 — versioned static secrets + CAS
Database — ephemeral SQL roles, 1h lease, auto-dropped
Transit — Encryption-as-a-Service shrinks PCI scope
PKI — 24h mTLS X.509 certs for the mesh
While sealed, every engine below returns HTTP 503 with X-Vault-Sealed-Response; pods that cannot fetch credentials fail to boot — which is precisely why production runs 5-node integrated-Raft clusters with auto-unseal, not a ceremony-dependent single node.
How It Works Under the Hood
Vault stores everything behind an AES-256-GCM cryptographic barrier, so a booted node is sealed: the Raft files on disk are ciphertext noise until the master key is reconstructed in RAM. Shamir's Secret Sharing splits that key into n shards over a finite field where any k reconstruct it and k-1 reveal nothing, distributing custody across security officers; the price is a roughly-25-minute human ceremony that breaks Kubernetes rolling restarts, and a threshold that is either unilateral-access (k=1) or hostage-to-absence (k=n). Auto-unseal delegates the unwrap to AWS or GCP KMS via the pod's IAM identity, re-sealing in ~120 milliseconds per boot while shifting trust to the cloud HSM. The lab models quorum availability as a binomial and runs each secrets engine behind the unsealed state.
Core Architectural Principles
- Shards insert one by one; the state machine flips to unsealed exactly at the k-of-n quorum.
- Custodian availability p turns unsealing into a binomial P(at least k of n reachable) risk.
- Auto-unseal replaces the ceremony with an IAM-authenticated KMS unwrap in ~120 ms per pod boot.
Explain sealed versus unsealed in storage terms: the barrier key lives only in RAM, so disk theft reveals nothing. Recite Shamir as k-of-n with the dual-control rationale (PCI, insider protection), then contrast with production auto-unseal via Cloud KMS because manual ceremony breaks automated restarts. Mention Transit encryption-as-a-service shrinking PCI scope.
Shamir thresholds remove single-insider root access but add ceremony latency and quorum-availability risk that KMS auto-unseal trades away.