Move secret engine mounts between Vaults


We want to merge two of our Vaults. Is it possible to migrate complete secret engine mounts to another Vault including sensitive data such as transit and PKI keys?

Andrej van der Zee

While you can backup and restore a Vault cluster, you cannot merge the content of two separate Vault clusters. This has to do with that the two Vault clusters have their own encryption key.
You can however make a migration script yourself that executes the two commands. The data of the two secret engine mounts will however not exactly be the same, except static metadata and configuration.

