# HashiCorp Vault

> HashiCorp Vault is a secrets manager that stores, generates and encrypts credentials, tokens and keys with fine-grained access control and audit logs.

- Source: https://www.itwonderlab.com/vault/
- Published: 2026-09-27
- Updated: 2026-09-27
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**Vault** keeps secrets out of code and files. Applications authenticate, get a short-lived token and read only the paths their policy allows. It can also create dynamic database or cloud credentials that expire. On AWS the managed alternative is [Secrets Manager](https://www.itwonderlab.com/aws-secrets-manager/).

### Key concepts

- **Secrets engine**: where secrets live, such as `kv` or `database`.
- **Auth method**: how a client proves who it is (token, AppRole, Kubernetes, AWS).
- **Policy**: the paths and capabilities a token has.
- **Seal**: Vault starts sealed and needs unseal keys.

### Learn it

Follow [Install Vault with Docker](https://www.itwonderlab.com/install-vault-docker/) and read [Terraform secrets management](https://www.itwonderlab.com/terraform-secrets-management/).
