4 ms·
I'll give my biased response, but I hope you can see I'm trying to be fair and honest too. Note I'm one of the founders of HashiCorp and original creators of Va
by mitchellh 7y ago
I'll give my biased response, but I hope you can see I'm trying to be fair and honest too. Note I'm one of the founders of HashiCorp and original creators of Vault.
If your challenge is just storing static secrets (think key/value), Vault is probably overkill for you today. Secrets Manager will work fine, or even a smaller KMS-based solution or something. We're working on making Vault a LOT easier to get started with so this probably won't be true for long, but its probably true today. But it is important to understand the tradeoffs of making these decisions.
The value of Vault is in the fact that it does so much more: dynamic secrets, automatic rotation, certificate management, encryption-as-a-service, etc. And that it integrates with so many systems: log in with AWS IAM, or K8S service principles, or OIDC (Google, GitHub, etc.). And it has a single policy and auditing system to back all this.
Usually Vault becomes VERY beneficial when you're juggling multiple "secret-like" solutions: diff password solution from key management from PKI etc etc OR you want to adopt more modern practices like dynamic credentials OR you want a way to centrally govern secret-like things.
Vault literally scales from solving the needs of a small team (static KV) to being used by some of the Fortune 10 to back their entire corporate secret, PKI, encryption, signing requirements in a centralized way. I think that's kind of neat.
- weitzj 7y agoVault is phenomenal. Do you know by chance whether Vault has a pkcs11 Plug-in? So one can offload certain crypto operations into an HSM? (apart from the masterkey) i.e. I would like to use the PKI from vault but the key of the CA has to live in an HSM.
- Operyl 7y agoWould a trade off be having an intermediary for your CA that vault controls the key for? That seems to be the common configuration I’ve seen at least.
- weitzj 7y agoThis is the configuration I would prefer as well. But for my question I already had an intermediate CA in mind and where to store its key. The rootca is offline
- Daegalus 7y agoWe use Vault Enterprise at my company, and I do a lot of the deployment/adminsitration of vault. The enterprise version supports PKCS11 and external HSM: https://www.vaultproject.io/docs/configuration/seal/pkcs11.html https://www.vaultproject.io/docs/configuration/seal/pkcs11.h... and https://www.vaultproject.io/docs/configuration/entropy-augmentation/index.html https://www.vaultproject.io/docs/configuration/entropy-augme... for reference. https://learn.hashicorp.com/vault/operations/ops-seal-wrap https://learn.hashicorp.com/vault/operations/ops-seal-wrap is a guide linked at the bottom
- weitzj 7y agoThanks. So to fully understand this - if I use seal wrapping with an HSM all secrets in Vault will be wrapped by the HSM and not only the masterkey/autounseal? And even though the rest is then in software (Vault) I still have the same FIPS level as the HSM?
- viralpoetry 7y agothere is an issue to track this one already https://github.com/hashicorp/vault/issues/6991 https://github.com/hashicorp/vault/issues/6991
- silviogutierrez 7y agoGreat description, thank you. My main question is: I use https://github.com/shyiko/kubesec https://github.com/shyiko/kubesec (a fancy sops) for k8s and store my database password, stripe credentials, etc in there. Other than that, I have my GCP account credentials (in 1Password) and my terraform state in... terraform. Is this a use case for Vault to consolidate? I guess I can't see how I would "outgrow" the above setup. Thanks for all the great Hashicorp products! Terraform is incredible.
- weitzj 7y agoThis may be interesting for you - a vault terraform provider using envelope encryption To get secrets from terraform into vault https://medium.com/faun/provisioning-vault-encrypted-secrets-using-terraform-using-sumup-oss-vaulted-and-4aa9721d082c https://medium.com/faun/provisioning-vault-encrypted-secrets...