4 ms·
I'm one of the creators of Vault. I read this back when it was posted and I'd be happy to share my thoughts. I'll note its worth reading through to the last par
by mitchellh 6y ago
I'm one of the creators of Vault. I read this back when it was posted and I'd be happy to share my thoughts. I'll note its worth reading through to the last paragraph and into the comments, the title is a bit bait-y and the article does a better job than the title gives itself credit for.
Broadly speaking, if you're looking at Vault to solve a specific problem X for a specific consumption type Y on a specific platform Z, then it _probably is overkill_ (I wouldn't say "overhyped" :)). i.e. "encrypted key/value via env vars on AWS Lambda". "X via Y on Z." The power of Vault is: multiple use cases, multiple consumption modes, and multiple platforms supported with a single consistent way to do access control, audit logging, operations, etc.
I can't stress that "single consistent way to do access control, audit logging, operations, etc." enough. Multiple security use cases dangling off that consistency is really important as soon as you hit N=2 or N=3 security use cases.
If you need say... encrypted KV and encryption-as-a-service and dynamic just-in-time credentials and a PKI system (certificate), and you need this as files and as env vars, and you need this on Kubernetes and maybe also on EC2, then Vault is -- in my totally biased opinion -- going to blow any other option out of the water.
That's a somewhat complex use case but its something Vault excels at. For simpler use cases, Vault is making more and more sense as we continue to make Vault easier to use. For example, we now provide a Helm chart and official K8S integration so you can run Vault on K8S very easily. And in this mode, developers don't even need to know Vault is there cause their secrets show up as env vars and files just like normal K8S secrets would.
Also, this article is from June 2019 and in 10 short months we've made a ton of progress on simplifying Vault so it gets closer to that "X via Y on Z" use case. Here are some highlights I can think of off the top of my head but there are definitely more, this is just from memory:
* We have integrated storage as an option now, so you don't need separate storage mechanisms.
* Our learn guides went from basically zero to lots of content which makes it much easier to learn how to use Vault: https://learn.hashicorp.com/vault https://learn.hashicorp.com/vault
* We have an official, feature-packed Kubernetes integration to do stuff like secret injection and rotation automatically. We also publish a Helm chart to run Vault on Kubernetes. https://learn.hashicorp.com/vault?track=getting-started-k8s#getting-started-k8s https://learn.hashicorp.com/vault?track=getting-started-k8s#...
We're looking at ways to make running Vault much, much easier. More on that later this year. :)
- NovemberWhiskey 6y ago> We have integrated storage as an option now, so you don't need separate storage mechanisms. Off topic, but seeing as you mentioned it - do you see the integrated Raft storage becoming the preferred solution? Without it, there's (IMHO) a bit of a chicken-and-egg bootstrapping problem between Vault and Consul.
- mitchellh 6y agoYes it will become the preferred solution. We just went GA with it (after a year of testing) in our last release. We’re now recommending this to customers. We’ll continue to provide support for Consul indefinitely and aren’t forcing customers to switch over. (Note “support” above is literal human support. “Support” in terms of enabling that use case will be around indefinitely but planned forever, we’ll always support different storage backends. But for our paying customers, we only support Consul and integrated storage for the sake of providing good service.)
- rad_gruchalski 6y agoVault is awesome. Thank you for creating it. We use it at Klarrio for issuing Kafka client certificates on demand in a multi-tenat DC/OS cluster. It sits right in the core of the platform and it just never fails us.
- deleted 6y ago[deleted]
- polskibus 6y agoWould you mind comparing Vault to Keycloak? https://www.keycloak.org/ https://www.keycloak.org/ I need an equivalent to Windows' Active Directory in Linux world that ideally can also federate with/masquerade as AD. Can Vault be such thing?