---
title: DIY Vault Backup
description: Introduction Hashicorp’s Vault is the industry standard for secrets management. In version 1.4 of Vault, the integrated storage backend supplied by Raft was promoted from beta to general availability. This Raft integrated storage backend has replaced Consul as the default…
image: https://shadow-soft.com/hubfs/Imported_Blog_Media/1200x628-HashiCorp-S-S-2-4.png
---

[Skip to content](https://shadow-soft.com/content/diy-vault-backup#main-content)

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

[![](https://shadow-soft.com/hs-fs/hubfs/Shadow-Soft-Logo-1.png?width=1878&height=431&name=Shadow-Soft-Logo-1.png)](https://shadow-soft.com)

- What We Do
  
   Expertise 
  
    - [Modern Infrastructure](https://shadow-soft.com/expertise/modern-infrastructure)
    - [Automation](https://shadow-soft.com/expertise/automation)
    - [Observability & Monitoring](https://shadow-soft.com/expertise/observability-monitoring)
    - [Cloud Engineering](https://shadow-soft.com/expertise/cloud-engineering)
    - [Security & Compliance](https://shadow-soft.com/expertise/security-compliance)
    - [AI Infrastructure](https://shadow-soft.com/expertise/ai-infrastructure)
  
  
   Technologies 
  
    - [Red Hat OpenShift](https://shadow-soft.com/expertise/openshift)
    - [Kubernetes](https://shadow-soft.com/expertise/kubernetes)
    - [Red Hat Ansible](https://shadow-soft.com/expertise/ansible)
    - [HashiCorp Terraform](https://shadow-soft.com/hashicorp-terraform-consulting)
    - [Dynatrace](https://shadow-soft.com/expertise/dynatrace)
    - [Icinga](https://shadow-soft.com/icinga)
  
  
  Solutions
  
  [**VMware to Red Hat Migration**](https://shadow-soft.com/solutions/vmware-migration-program)  
  Need a strategic path forward as VMware licensing costs rise?
  
  [**IT Operations Automation**](https://shadow-soft.com/solutions/it-operations-automation-program)  
  Transform IT operations into a resilient, cost-efficient foundation
  
  [**Unified Observability**](https://shadow-soft.com/solutions/unified-observability-program)  
  Stop firefighting with 6+ monitoring tools that don't talk to each other.<https://shadow-soft.com/services/embedded-staffing-services>
- Who We Serve
  
    - [Enterprises](https://shadow-soft.com/solutions/enterprises)
    - [Software Companies](https://shadow-soft.com/solutions/software-vendors)
    - [IT Solution Providers](https://shadow-soft.com/solutions/it-solution-providers)
- Resources
  
    - [Client Stories](https://shadow-soft.com/client-stories)
    - [Insights](https://shadow-soft.com/content-hub)
    - [Events](https://shadow-soft.com/events)
    - [Platform Pulse Newsletter](https://shadow-soft.com/platform-pulse)
    - [Academy](https://shadow-soft.com/academy-home)
- About
  
    - [About Shadow-Soft](https://shadow-soft.com/about)
    - [Partners](https://shadow-soft.com/partners)
    - [Careers](https://shadow-soft.com/careers)
    - [Newsroom](https://shadow-soft.com/newsroom)
    - [Contact](https://shadow-soft.com/contact)

[Let's Talk](https://shadow-soft.com/contact)

![Search icon](https://5018647.fs1.hubspotusercontent-na1.net/hubfs/5018647/Design/Icons/Font%20Awesome/search.svg)

[Let's Talk](https://shadow-soft.com/contact)

[All posts](https://shadow-soft.com/content/all)

 May 19, 2022

# DIY Vault Backup

    Shadow-Soft Team  ·   3 minute read

## Introduction

Hashicorp’s Vault is the industry standard for secrets management. In version 1.4 of Vault, the integrated storage backend supplied by Raft was promoted from beta to general availability. This Raft integrated storage backend has replaced Consul as the default and most popular choice for Vault storage.

Unless you are only using Vault in a development/sandbox lifecycle environment, then you have a disaster recovery and failover plan for Vault. Thankfully, the intrinsic clustering provided by the Raft gossip protocol ensures data replication within a cluster. However, you also will want to backup the Vault data external to the cluster to be safe.

Vault Enterprise ships with a fantastic tool for automated Raft backups. However, with some light knowledge of the Vault API, you can also create an automated Vault Raft backup tool yourself. In this article we will introduce an implementation satisfying the minimal functionality for creating your own automated backup software tool for Vault with the Raft storage backend.

## Prerequsities

### Environment

A local filesystem should exist with permissions and storage capable of writing a Raft snapshot. For the example shipping and storage, authentication and authorization should exist in AWS for listing, reading, and writing objects to a S3 bucket. It also requires a S3 bucket capable of storing the backup snapshot.

### Vault

This implementation is primarily tested against Vault 1.8 and 1.9, but should also work with other minor release versions of 1.4 and later. A Vault server cluster with Raft integrated storage should exist and enable connections. Authentication and authorization is required for the Raft backup capability. A simple Vault policy for the authorization appears like:

```
path "sys/storage/raft/snapshot" {
  capabilities = ["read"]
}
```

### Golang

This implementation requires Golang version 1.16 or later. The Go module file also requires `github.com/hashicorp/vault/api v1.3.1` or later, and an optional `github.com/aws/aws-sdk-go v1.42.11` or later if you are integrating with AWS for the example shipping and storage.

## Vault Raft Backup

We will assume that we have an authenticated and authorized client. You may need to consult the Vault documentation for basic authentication engine configuration, and basic policy attaching for authorization. A detailed reference for client initialization in Golang can be found in the previous article titled [Custom Vault Integrations: Go](https://shadow-soft.com/custom-vault-integrations-go/).

We can use the following function to create a backup Raft snapshot and store it on the local filesystem.

```
// vault raft snapshot creation
func vaultRaftSnapshot(client *vault.Client, snapshotPath string) (*os.File, error) {
    // prepare snapshot file
    snapshotFile, err := os.OpenFile(snapshotPath, os.O_CREATE|os.O_WRONLY|os.O_TRUNC, 0o644)
    if err != nil {
        fmt.Println("snapshot file at " + snapshotPath + " could not be created")
        fmt.Println(err)
        return nil, err
    }

    // defer snapshot close
    defer snapshotFileClose(snapshotFile)

    // execute raft snapshot
    err = client.Sys().RaftSnapshot(snapshotFile)
    if err != nil {
        snapshotFile.Close()
        fmt.Println("Vault Raft snapshot invocation failed")
        fmt.Println(err)
        return nil, err
    }

    return snapshotFile, nil
}

// close snapshot file
func snapshotFileClose(snapshotFile *os.File) {
    // close file
    err := snapshotFile.Close()
    if err != nil {
        fmt.Println("Vault raft snapshot file failed to close")
        log.Fatalln(err)
    }
}
```

This function returns a pointer to the file where the Raft backup snapshot is stored on the local filesystem. Please note that the file must be re-opened if you want to ship it to be stored somewhere else. Alternatively, the file close could be deferred until after the backup is shipped.

## Backup Shipping and Storage

Now we have a Vault Raft snapshot ready to be shipped and stored somewhere else if so desired. As an example, we will explore shipping to and storing in a S3 bucket. We need to re-open the snapshot file before shipping, but otherwise this code follows the common pattern for uploading a file to S3.

```
// snapshot upload to s3
func snapshotS3Upload(config *AWSConfig, snapshotPath string) (*s3manager.UploadOutput, error) {
    // open snapshot and defer closing
    snapshotFile, err := os.Open(snapshotPath)
    if err != nil {
        fmt.Printf("Failed to open snapshot file %q: %v", snapshotPath, err)
        return nil, err
    }
    defer snapshotFileClose(snapshotFile)

    // aws session
    awsSession := session.Must(session.NewSession(&aws.Config{
        Region: aws.String(config.s3Region),
    }))

    // initialize an uploader with the session and default options
    uploader := s3manager.NewUploader(awsSession)

    // determine vault backup base for s3 key
    snapshotPathBase := filepath.Base(snapshotPath)

    // upload the snapshot to the s3bucket at specified key
    uploadResult, err := uploader.Upload(&s3manager.UploadInput{
        Bucket: aws.String(config.s3Bucket),
        Key:    aws.String(config.s3Prefix + "-" + snapshotPathBase),
        Body:   snapshotFile,
    })
    if err != nil {
        fmt.Println("Vault backup failed to upload to S3 bucket " + config.s3Bucket)
        fmt.Println(err)
        return nil, err
    }

    return uploadResult, nil
}
```

Now we have code to ship and store the Vault Raft backup snapshots in a dedicated S3 bucket. Since the S3 bucket could begin to grow quite large with these backups, it would be recommended to cleanup the S3 bucket with a lifecycle policy. It would not be a good idea to incorporate that functionality into this tool, because then an entire scheduler would need to be coded and integrated also.

## Conclusion

Now you have the core code functionality for a software tool to create backup Vault Raft snapshots, and ship them to a dedicated external storage solution. It is now possible to expand and extend this implementation for more functionality. It is also easy to wrap this software tool inside your choice of automation tool to ensure scheduled customized backups. While this solution is not on par with the tooling in Vault Enterprise, it does provide a solid homegrown solution if you need one.

If your organization is interested in extensions, custom tooling, and custom integrations with Vault and other secrets management tools, then [contact Shadow-Soft.](https://shadow-soft.com/contact)

 

Share: [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://shadow-soft.com/content/diy-vault-backup) [twitter icon](https://twitter.com/intent/tweet?url=https://shadow-soft.com/content/diy-vault-backup) [envelope icon](mailto:?body=https://shadow-soft.com/content/diy-vault-backup)

## Is Your Platform Ready for What's Next?

Get unfiltered perspectives on modern platforms, automation, and observability. The Platform Pulse newsletter delivers actionable insights to help you build with confidence.

[Get the insights](https://shadow-soft.com/content/diy-vault-backup#popform_hero)

### Subscribe to Platform Pulse

 One email per month. Unfiltered perspectives on modern platforms, automation, and observability.

[![](https://shadow-soft.com/hs-fs/hubfs/Shadow-Soft-Logo-1.png?width=1878&height=431&name=Shadow-Soft-Logo-1.png)](https://shadow-soft.com)

Shadow-Soft is a Red Hat Specialized Partner and Dynatrace Premier Partner helping mid-to-large enterprises modernize infrastructure through Kubernetes platforms, VMware to OpenShift Virtualization migrations, infrastructure automation, and observability solutions. Headquartered in Atlanta and serving enterprises nationwide.

**Address:** 4501 North Point Pkwy, Suite 110

Alpharetta, GA 30022 USA

🔔 [Subscribe to Platform Pulse Newsletter](https://shadow-soft.com/platform-pulse)

[linkedin-in icon](https://www.linkedin.com/company/shadow-soft/) [Follow us on Facebook](https://www.youtube.com/c/Shadow-soft)

**Company**

<https://shadow-soft.com/about>

 

[About](https://shadow-soft.com/about)

[Contact](https://shadow-soft.com/contact)

[Careers](https://shadow-soft.com/careers)

[Content Hub](https://shadow-soft.com/content-hub)

[Case Studies](https://shadow-soft.com/client-stories)

[Icinga Support](https://shadow-soft.com/icinga)

[Privacy Policy](https://shadow-soft.com/privacy)

**Services**

<https://shadow-soft.com/solutions/it-automation>

[VMware to OpenShift Migration](https://shadow-soft.com/solutions/vmware-red-hat-openshift-virtualization-migration)

[Red Hat Consulting](https://shadow-soft.com/expertise/red-hat)<https://shadow-soft.com/solutions/it-automation><https://shadow-soft.com/expertise/ansible><https://shadow-soft.com/expertise/openshift>

[OpenShift Consulting](https://shadow-soft.com/expertise/openshift)<https://shadow-soft.com/expertise/ansible>

[Kubernetes Consulting](https://shadow-soft.com/expertise/kubernetes)

[Ansible Consulting](https://shadow-soft.com/expertise/ansible)

[Observability Consulting](https://shadow-soft.com/expertise/observability-monitoring)

[Dynatrace Consulting](https://shadow-soft.com/expertise/dynatrace)

[HashiCorp Terraform Consulting](https://shadow-soft.com/hashicorp-terraform-consulting)

**Solutions**

<https://shadow-soft.com/solutions/it-automation>

<https://shadow-soft.com/solutions/it-automation>[VMware Alternative](https://shadow-soft.com/solutions/vmware-migration-program)  
<https://shadow-soft.com/expertise/ansible>

[Automate IT Operations](https://shadow-soft.com/solutions/it-operations-automation-program)

[Unified Observability](https://shadow-soft.com/solutions/unified-observability-program)

 

**Workshops**

[VMware Migration Workshop](https://shadow-soft.com/vmware-migration-workshop)

[Observability Workshop](https://shadow-soft.com/observability-tool-sprawl-assessment)

[Automation Strategy Workshop](https://shadow-soft.com/automation-strategy-workshop)

 

Copyright © 2026, Shadow-Soft

![](https://www.facebook.com/tr?id=433738280336898&ev=PageView&noscript=1)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Shadow-Soft Team",
    "url" : "https://shadow-soft.com/content/author/shadow-soft-team"
  },
  "dateModified" : "2024-08-28T15:37:43.856Z",
  "datePublished" : "2022-05-19T15:27:53.000Z",
  "headline" : "DIY Vault Backup",
  "image" : [ "https://shadow-soft.com/hubfs/Imported_Blog_Media/1200x628-HashiCorp-S-S-2-4.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://shadow-soft.com/content/diy-vault-backup",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://shadow-soft.com/hubfs/Shadow-Soft-Logo-1.png"
    }
  }
}
```