Vault HA with PVC and Auto-Unseal

On the other hand, that may take time, learning, figuring out whether you can fit within their free tier, and require an internet connection.

Various HashiCorp Learn tutorials include using the transit auto-unseal method - e.g. Vault HA cluster with integrated storage | Vault | HashiCorp Developer - which uses another Vault (which you have to unseal manually, but is small, stable, and hardly ever restarted) to automate the unsealing of a larger, more frequently restarted Vault. The main tutorial for setting that up yourself is Auto-unseal using Transit secrets engine | Vault | HashiCorp Developer .

Which option is actually better for you will depend on your requirements, beyond the level of detail you’ve mentioned here.