Vault's S3 storage backend needs AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY from vault-minio-creds, previously generated by a helmfile presync hook that no longer exists post-Terraform/helmfile removal. Sourced from the same MINIO_ROOT_USER/PASSWORD already in .env. vault-unseal-keys still missing separately — needs a live 'vault operator init' run, deferred.