Home/Labs/Vault Shamir Quorum
All 280 Labs
INTERACTIVE LAB🏛️

Vault Shamir Unsealing and Auto-Unseal Lab (Interactive)

Reconstruct the master key with k of n custodian shards, or delegate unseal to Cloud KMS. Insert key shards into a sealed Vault, tune the (k,n) threshold, and compare human ceremony time and binomial quorum risk against milliseconds-scale auto-unseal.

Vault Sealed State: Shamir (k, n) Quorum Lab

The AES-256-GCM cryptographic barrier keeps every byte unreadable until k of n custodians reconstruct the master key — or Cloud KMS does it in milliseconds.

VAULT STATE: SEALED (0/3 keys provided)

Shamir splits the master key over GF(2^8) polynomial interpolation: any k shards reconstruct it, k−1 shards leak zero information. Fewer than k keys in RAM means the Raft store is ciphertext noise — even a full disk theft reveals nothing.

Manual ceremony time

~60 min

3 custodians × ~20 min each

P(quorum reachable)

94.2%

binomial: P(≥3 of 5 custodians on-call)

Secrets engines served while unsealed

KV v2 — versioned static secrets + CAS

Database — ephemeral SQL roles, 1h lease, auto-dropped

Transit — Encryption-as-a-Service shrinks PCI scope

PKI — 24h mTLS X.509 certs for the mesh

While sealed, every engine below returns HTTP 503 with X-Vault-Sealed-Response; pods that cannot fetch credentials fail to boot — which is precisely why production runs 5-node integrated-Raft clusters with auto-unseal, not a ceremony-dependent single node.

How It Works Under the Hood

Vault stores everything behind an AES-256-GCM cryptographic barrier, so a booted node is sealed: the Raft files on disk are ciphertext noise until the master key is reconstructed in RAM. Shamir's Secret Sharing splits that key into n shards over a finite field where any k reconstruct it and k-1 reveal nothing, distributing custody across security officers; the price is a roughly-25-minute human ceremony that breaks Kubernetes rolling restarts, and a threshold that is either unilateral-access (k=1) or hostage-to-absence (k=n). Auto-unseal delegates the unwrap to AWS or GCP KMS via the pod's IAM identity, re-sealing in ~120 milliseconds per boot while shifting trust to the cloud HSM. The lab models quorum availability as a binomial and runs each secrets engine behind the unsealed state.

Core Architectural Principles

  • Shards insert one by one; the state machine flips to unsealed exactly at the k-of-n quorum.
  • Custodian availability p turns unsealing into a binomial P(at least k of n reachable) risk.
  • Auto-unseal replaces the ceremony with an IAM-authenticated KMS unwrap in ~120 ms per pod boot.
Interview Round Script

Explain sealed versus unsealed in storage terms: the barrier key lives only in RAM, so disk theft reveals nothing. Recite Shamir as k-of-n with the dual-control rationale (PCI, insider protection), then contrast with production auto-unseal via Cloud KMS because manual ceremony breaks automated restarts. Mention Transit encryption-as-a-service shrinking PCI scope.

Key Trade-Offs

Shamir thresholds remove single-insider root access but add ceremony latency and quorum-availability risk that KMS auto-unseal trades away.

Related Curriculum Chapter

Secrets & Configuration Management: HashiCorp Vault Architecture

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs