Access the Vault UI
- Open your browser and navigate to:
https://<SERVER-IP>:8200 - Accept the self-signed certificate warning.
- Use any 4 of the 7 unseal keys in
/root/.vault_tokensto unseal Vault. - Choose Token as the authentication method and enter the root token from
/root/.vault_tokens
Vault Root Token & Unseal Keys
- Stored at:
/root/.vault_tokens(keep this file safe and private) - Number of unseal keys: 7
- Threshold to unseal: 4
Systemd Service
systemctl status vault
systemctl restart vault
Important Files & Directories
/etc/vault.d→ Vault configuration files (vault.hcl)/opt/vault/data→ Vault storage (file backend)/root/.vault_tokens→ Root token and unseal keys
Next Steps
Use the Vault UI or CLI to create secrets, policies, and authentication methods.
To manage Vault from CLI:
export VAULT_ADDR='https://127.0.0.1:8200'
export VAULT_SKIP_VERIFY=true
vault status