The article how references the Transit Engine node (Vault 1) as a single instance. Is it possible to deploy this in HA, i.e. 2 (or multiple) instances of the Transit Engine and is there documentation that describes how to achieve this?
We would want to avoid a situation where the Transit Engine node goes down and the Vault instance that needs unsealing is unable to as a result.
Yes you can make your transit unseal cluster an HA cluster, however … there is no point and it would be a waste of resources, but technically there is nothing stopping you from doing so.
It’s a comparison of cost vs. use vs. how reliant a system has to be. There is no technical reason not to do a full cluster. If you’re overflowing with money and machines and the SRE time to monitor and keep the system to update with security and vendor patches then go ahead and do a 3 node cluster.
I agree with Aram here - running a single node transit just for unsealing (which you then have to manually unseal, or autounseal - which if that cluster can auto unseal - just do that for your primary business-centric cluster) should be a last resort.