This post and the next one wrap up the Vault series, and they are where I pay back a debt. Way back in the bootstrap post I looked at the docker setup and said I would want TLS on something “real”, but that it was “a level of faff i’m not up for today”. Well, it is today. We have spent a lot of posts putting things into Vault (primitives, python, ansible, PKI, audit, transit), all of it over plain HTTP, which is a bit embarrassing for a secrets store.