I’m setting up a HA Vault in AWS with EC2 instances using an ALB as the only entry point.
In the docs I read
Note that only active nodes have active listeners. When a node becomes active it will start cluster listeners, and when it becomes standby it will stop them.
I interpret this as port 8201 being not listening for connections on the standby servers but that’s not the case how you can see in my screenshot
Q1: Is the documentation outdated or I misinterpreted something ?
So not being able to distinguish active from standby by using the availability of port 8201, I ended having the following configuration:
api_addr = "https://vault.uniqueos-stage.[redacted]" cluster_addr = "https://vault.uniqueos-stage.[redacted]:8201"
The Load balancer has 2 Target Groups:
- port 443 -> port 8200 with health check reporting healthy on status 200 and 429
- port 8201 -> port 8201 with health check reporting healthy on status 200
This way the LB will redirect server-to-server communication only to the current active node
Q2: Is this the way one is supposed to be setting it up ?