Version5.4.0
Revision11
Size235.1 MB
LicenseGPL-3.0-only
Confinementstrict
Basecore22

Tool to initialize and unseal a Juju-deployed Vault cluster.


Automates the initialization or unsealing of a Juju-deployed Vault cluster.
It handles leader-finding, unsealing all units, and automatically
authorizing the Juju charm.

This tool securely manages credentials by storing the root token and each
unseal key in separate GPG-encrypted files, enabling hardware-backed
security (YubiKey) and separation of duties.

It features a robust 3-tier loading system:
1. Auto-detects keys in the credentials directory.
2. Falls back to prompting for individual file paths.
3. Provides a final fallback for raw, manual key entry.

This snap bundles 'jq', 'vault', and 'gpg'. It requires the 'juju'
command to be installed on the host system.

How to install:

sudo snap install un-seal


then, connect the necessary interfaces:

sudo snap connect un-seal:dot-local-share-juju
sudo snap connect un-seal:gpg-keys
sudo snap connect un-seal:pcscd


Source code: https://github.com/Ankow99/un-seal

Update History

5.2.0 (9)5.4.0 (11)
6 Feb 2026, 22:25 UTC
5.1.0 (8)5.2.0 (9)
6 Feb 2026, 19:57 UTC
5.0.0 (7)5.1.0 (8)
23 Jan 2026, 14:25 UTC
4.0.0 (6)5.0.0 (7)
22 Jan 2026, 15:37 UTC

Published22 Jan 2026, 10:54 UTC

Last updated6 Feb 2026, 22:08 UTC

First seen22 Jan 2026, 10:57 UTC