My current vault status is as follows, which command should I execute to unseal
root@docker-agent:~# vault status
Key Value
--- -----
Seal Type transit
Recovery Seal Type shamir
Initialized true
Sealed true
Total Recovery Shares 5
Threshold 3
Unseal Progress 0/3
Unseal Nonce n/a
Seal Migration in Progress true
Version 1.15.6
Build Date 2024-02-28T17:07:34Z
Storage Type raft
HA Enabled true
root@docker-agent:~# cat /etc/vault.d/vault.hcl
cluster_addr = "https://12.0.0.40:8201"
api_addr = "https://12.0.0.40:8200"
cluster_name = "Vault-Test"
disable_mlock = true
ui = true
log_level = "INFO"
listener "tcp" {
address = "0.0.0.0:8200"
tls_cert_file = "/root/vault/certs.d/vault-cert.pem"
tls_key_file = "/root/vault/certs.d/vault-key.pem"
tls_client_ca_file = "/root/vault/certs.d/vault-ca.pem"
}
seal "transit" {
address = "http://12.0.0.25:8200"
token = "hvs.CAESIFRGCZQuscJ1AcSILHdDqSiqr1ijU3PguwHDDeco7m3HGh4KHGh2cy5ERTNlNxxxxxxxxxxx"
key_name = "unseal-key"
mount_path = "transit"
}
storage "raft" {
path = "/opt/vault/data"
node_id = "node-1"
retry_join {
leader_tls_servername = "vault.xxxx.com"
leader_api_addr = "https://12.0.0.40:8200"
leader_ca_cert_file = "/root/vault/certs.d/vault-ca.pem"
leader_client_cert_file = "/root/vault/certs.d/vault-cert.pem"
leader_client_key_file = "/root/vault/certs.d/vault-key.pem"
}
}