2 ms·
Great article. I would point out, though, that the disadvantages listed against Secrets as a Service need not apply to Hashicorp's Vault: 1) Single point of f
by jlj7 6y ago
Great article.
I would point out, though, that the disadvantages listed against Secrets as a Service need not apply to Hashicorp's Vault:
1) Single point of failure: Vault Enterprise offers high availability solutions that should be able to mitigate much of this (at a cost, of course).
2) Codebase must be changed: Vault (and Consul) really shine here: Consul Template -- and Envconsul -- can be used to seamlessly integrate legacy code with Vault.
3) System-level access must be protected carefully: Well, this is always true, but Vault gives you more options than many others here as well: based on risk assessments, you can choose to limit the secrets you issue, particularly when you're talking about system-level access. You can have very short TTLs, one-time-use wrappers that limit the exposure of said secrets, etc.
(I don't mean to sound like a shill, BTW. It's just that these points easily jumped to mind, having just certified as a Vault Associate. YMMV. :-) )
- Znafon 6y agoRegarding 1, I don't think you need Enterprise to have HA, I'm pretty sure it comes with Vault OSS. You may be thinking about Vault Disaster Recovery which makes one cluster fail to another one, but HA is in OSS.
- jlj7 6y agoI was thinking of on-call support being a key part of the overall concept of HA, but, yes, good point: much of this risk can be mitigated, even with OSS.
- atonse 6y agoHA is there in OSS now with their raft store. I think you could’ve also done in the past if you used consul for vault’s storage.
- rexarex 6y agoHA has always been in OSS