This guide explains how to configure Disaster Recovery replication between two Vault Enterprise clusters.
In this guide, you’ll configure Disaster Recovery (DR) replication across two Vault Enterprise clusters. We assume both single-node clusters are already initialized, unsealed, and you’re logged in as root:
Primary (10.1.101.199, tan background)
Secondary (10.1.101.108, white background)
DR replication requires Vault Enterprise; it is not supported in the open-source edition.
ec2-user@ip-10-1-101-199 vault]$ vault write -force sys/replication/dr/primary/enableWARNING! The following warnings were returned from Vault:* This cluster is being enabled as a primary for replication. Vault will be unavailable for a brief period and will resume service shortly.
Enabling primary DR replication causes a short downtime. Plan accordingly for production environments.
Switch to the secondary (10.1.101.108) and join it to the primary:
Copy
Ask AI
[root@ip-10-1-101-108 vault]# vault write -f sys/replication/dr/secondary/enable token=<WRAPPING_TOKEN>WARNING! The following warnings were returned from Vault:* Vault has successfully found secondary information; it may take a while to perform setup tasks. Vault will be unavailable until these tasks and initial sync complete.
Enabling DR on a secondary will wipe any existing data. Be sure this node is dedicated for DR replication.