maintenance VAULT: Cutover to new cluster - changes made after 10:00 AM ET will need re-applying
What's happening
We're moving HashiCorp Vault to a new cluster on Monday 21 September, 10:00–11:00 AM Eastern (14:00–15:00 UTC).
The address is not changing. https://vault.nasuni.dev works exactly as it does today, and no client configuration needs to change.
Important: data written after 10:00 AM Eastern will not carry over
We take a point-in-time snapshot of Vault at 10:00 AM Eastern and restore it onto the new cluster. Anything written after that moment lands on the old cluster and will be lost when we switch over.
If you write a secret, rotate a credential, or change a policy between 10:00 and 11:00 AM Eastern, you will need to do it again once the cutover is complete.
Reading secrets is unaffected — everything stored before 10:00 AM stays readable throughout.
What we're asking
- Don't write to Vault between 10:00 and 11:00 AM Eastern. Move planned secret changes, policy updates and credential rotations outside the window.
- Pause automation that writes to Vault for the hour where you can — CI jobs, deployment pipelines, certificate renewals.
- If a write genuinely can't wait, make a note of it and re-apply it after we confirm completion.
What to expect
- A short interruption while traffic moves to the new cluster. Clients using
vault.nasuni.devreconnect on their own. - The full hour is booked for verification; the actual switch is much quicker than that.
Why we're doing this
The current cluster runs a version of Vault that's past end of support, and its storage can't keep up with large deployments — that's the cause of the intermittent Vault timeouts during big rollouts. The replacement has roughly 40x the write headroom, and we've load tested it at 7,000 machines authenticating in about 8 seconds.
Questions
Contact IT Infrastructure.