TeamcenterKnowledge

System Administration > Managing secrets using Teamcenter vault

Installing Teamcenter vault with high availability using HashiCorp Community edition

If your site uses HashiCorp Vault Community edition, you can install Teamcenter vault for distributed environments with high availability to help ensure Teamcenter vault operates without interruption during failures and outages. Installing Teamcenter vault with high availability requires that your environment is set up in Deployment Center as a distributed environment. Install Teamcenter as described in Teamcenter Installation Using Deployment Center, ensuring the following items are configured appropriately in Deployment Center. On the Options tab, check High Availability. Doing so installs three instances of Teamcenter vault. On the Components tab, ensure each machine's HTTPS Config component is properly configured. On the Components tab, select the Teamcenter Secrets Manager (by Hashicorp) component and configure all required parameters, including the following: Ensure each Machine Name value is set to the name of a machine specified by an HTTPS Config component. Verify that Port and Cluster Port values are set to available open ports on each machine. Specify a location in which Teamcenter will store snapshots of vault contents. By default, the Vault Snapshot Location value is set to a location in your Teamcenter installation directory. If necessary, change this value as required for your site. This directory can be a location shared by all vault machines, or each machine can specify a unique directory. To ensure the latest vault contents are available if a restoration is necessary, Siemens Digital Industries Software recommends using a shared location for your vault snapshots. To restore vault snapshots, you must have vault administrator credentials. Review the security statements by Enable Vault Admin User and proceed only if you accept the stated responsibilities. To specify vault administrator credentials, check Enable Vault Admin User and specify a user name and password. See Back up and restore Teamcenter vault data for additional information on working with snapshots. Caution Teamcenter vault administrator credentials are provided for snapshot restoration and diagnostic purposes only. Changing passwords or secrets with tools other than Deployment Center is not supported. Vault secrets are updated when Deployment Center scripts run. This process ensures consistency, traceability, and proper synchronization across your Teamcenter environment. Changing passwords or secrets outside of Deployment Center may cause Teamcenter to become unresponsive and Deployment Center may generate errors with future deployments. On the Components tab, only one Teamcenter vault component can be set as the primary vault instance. When deploying the Deployment Center scripts, deploy the script for the primary vault instance machine before scripts for other machines in the distributed environment.

Source: https://docs.sw.siemens.com/documentation/external/PL20251212545240207/en-US/tc_help/AWAdmin/fhs4814155880506/yol1737238560708/foh9980017197978.html · retrieved Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)