HashiCorp Vault

· 1 min read · Security · Tool

Vault keeps secrets out of code and files. Applications authenticate, get a short-lived token and read only the paths their policy allows. It can also create dynamic database or cloud credentials that expire. On AWS the managed alternative is Secrets Manager.

Key concepts #

  • Secrets engine: where secrets live, such as kv or database.
  • Auth method: how a client proves who it is (token, AppRole, Kubernetes, AWS).
  • Policy: the paths and capabilities a token has.
  • Seal: Vault starts sealed and needs unseal keys.

Learn it #

Follow Install Vault with Docker and read Terraform secrets management.

#Vault #Security