3 ms·
Note that I work for HashiCorp so I have a clear bias. I tend to shy away from these comments because of that but there is a certain addition I'd like to add he
by mitchellh 9y ago
Note that I work for HashiCorp so I have a clear bias. I tend to shy away from these comments because of that but there is a certain addition I'd like to add here. The other comments around this are good so I won't talk about those.
The surface area of Vault capabilities is much larger than EC2 parameter store and through the lens of our paying customers, most are using Vault for many more of the backends (the most popular probably being PKI).
For pure AWS-based companies, parameter store could provide a fine solution for basic key/value secrets! I don't want to bash at all, I just wanted to make sure for any readers that they don't mistake Vault for purely encrypted K/V.
- ejcx 9y agoBut, if you're using vault for only Secrets Management on AWS you are using a nuclear warhead to destroy an ant-hill. It's quite frankly not a good experience and really challenging to automate running Vault in a modern environment, all something that is very simple with SSM. You note this, but I have 2-3 people reaching out to me per week stuck/struggling with vault, who find chamber/SSM and have solved the problem with 1 day of work.