Static Auto-Unseal Is a Temporary Root of Trust, Not HA
The same-host seal service removes manual unseal entry, but its static key remains a temporary bootstrap root of trust on the same failure domain.
The same-host seal service removes manual unseal entry, but its static key remains a temporary bootstrap root of trust on the same failure domain.
The server needs its TLS private key to operate, while the CA private key is more powerful and should remain off-host.