3 ms·
(Disclaimer: founder of HashiCorp, creator of Vault) You hit on a good point. Vault has features to eliminate this security risk, if I’m understanding correctl
by mitchellh 7y ago
(Disclaimer: founder of HashiCorp, creator of Vault)
You hit on a good point. Vault has features to eliminate this security risk, if I’m understanding correctly.
The first feature is dynamic secrets: this generates an ephemeral, leased set of credentials that are unique per client. For a Kubernetes pod, it would get a unique set of DB credentials, for example. These are tied to the service account (used for auth). When the auth expires, so do the credentials (they’re dropped from the DB, and if the DB supports it we also drop connections).
The second feature is root credential rotation. To use the above feature, a user had to at some point “paste” the superuser credentials into Vault. As you pointed out, there’s a risk here. So what Vault can do is _immediately_ rotate that credential so after configuring Vault, it is no longer valid and only Vault knows the real credential. We support this for most database backend, for example.
If you combine these two elements, you get fully ephemeral secrets that are unknown by anyone except the necessary user. There’s a lot more we can talk about, there’s a lot more features we have around this, but this is just the high level point!
- p10jkle 7y agoWe are using your database credential generation features! With thousands of clients, too. Very cool, we'll write a blog post soon. The root credential rotation is genius.
- ekidd 7y ago> The first feature is dynamic secrets: this generates an ephemeral, leased set of credentials that are unique per client. Yes, thank you. This is one of those features that once you've lived with it, you can't imagine going back. Essentially, every secret gets an automatic expiration date in the near future. This has several effects: 1. It teaches people to never hard-code secrets anywhere, because they always expire. So people will follow fairly strict credential-management rules out of sheer laziness. 2. It guarantees that you don't have stale secrets lying around in random corners of your company. So even if somebody does record a secret somewhere they shouldn't, the window of attack may only be a few hours.
- SEJeff 7y agoAs one of your commercial customers, I would give you the feedback that there are a lot of features that get closed (on the github vault issue tracker) with terse and not very user friendly reasons. This is off putting to a lot of people. We've recently been escalating via sales for github issues we see use for and hopefully that gets back to product management. Not everyone is able to do that however.
- mitchellh 7y agoThank you, I heard this feedback this week as well. We’re hiring for a couple roles right now in the Vault team that will be dedicated to community management and process (that will expand more broadly). We hope this helps with this. The feedback from customers definitely gets back to product management, so for your case, that works.