4 ms·
Hey everyone - sorry for the delayed reply, I've been on a plane. Seth from Google here, the same Seth in the byline of the blog post. We are very excited to b
by sethvargo 7y ago
Hey everyone - sorry for the delayed reply, I've been on a plane. Seth from Google here, the same Seth in the byline of the blog post.
We are very excited to bring Secret Manager to the market. Let us know if you have any questions!
- devy 7y agoHi Seth! I wonder how is GCP Secrets Manager comparing to Hashicorp Vault? Is GCP SM implemented in Hashicorp Vault (or Berglas) behind the scene? If not, what are the differences in terms of feature set?
- dannyrosen 7y agoHey Seth, I know there's been _quite_ the effort under the hood to make this product a reality and am curious if you would be open to writing a bit about lessons learned to help others learn about the research & development process.
- sethvargo 7y agoSure - in short, we partnered with multiple customers in designing and building this service. Let me check with my team and see what we _can_ talk about :)
- deleted 7y ago[deleted]
- andrewdb 7y agoYour vault-on-gke[0] repo is solid. For greenfield GKE projects starting now, would you recommend Secret Manager or vault-on-gke? 0: https://github.com/sethvargo/vault-on-gke https://github.com/sethvargo/vault-on-gke
- sethvargo 7y agoThanks :). I'm waiting on Terraform support for Secret Manager[0], then I'll update the configurations to use that for storing the initial root token and certificates. Vault works great on GCP, and it's used by hundreds of enterprises who want brokered identity management across clouds, dynamic secrets, and an open core model that fits their business. However, we kept hearing that sometimes Vault was complex for some small problems. If you're not using its advanced functionality, Vault is incredibly cost prohibitive. It doesn't run well in a serverless environment, so you have to pay for VMs 24/7 even when secrets aren't being accessed. We continue to contribute to Vault and build deeper Vault integrations into GCP - that's not changing. Secret Manager provides choice. Just like there's certain scenarios where you'd prefer a NoSQL database over a relational one, there are scenarios where you'd prefer Secret Manager over Vault and vice versa. Since this question and "Secret Manager vs Cloud KMS" keep coming up as questions, I'm going to work with our team to put together something in the documentation. [0]: https://github.com/terraform-providers/terraform-provider-google/issues/5168 https://github.com/terraform-providers/terraform-provider-go...