4 ms·
All major clouds have better alternatives to Vault. Vault is mostly for really large companies that want to run things like this by themself. There is no need
by AtNightWeCode 5y ago
All major clouds have better alternatives to Vault. Vault is mostly for really large companies that want to run things like this by themself.
There is no need for service discovery in the cloud in general.
I have also used Nomad a lot. Maybe it is because we always needed the cutting edge features in general, but in general not very good quality. Core features always worked though. People should use Kubernetes instead in most cases.
There is simply no way Terraform and the HCL2 will survive for cloud environments. For other use cases I do not know.
- jordanbeiber 5y ago“People should use Kubernetes instead” is an interesting take considering your first paragraph. :) You’ve perhaps not had to troubleshooting issues in a more advanced k8s setup - that is something that is not “for most people”. Keeping services discoverable, with service health-checks and configuration data at hand in the k/v is not needed in the “cloud”? I guess a lot comes down to how you opt to manage you services… It’s what etc does, but worse (imo), for k8s. My usual work with larger infrastructure spans more than k8s or a single provider, hence consul is a given. To my knowledge no other secrets solution exists that cover all the things vault does, and at the same lets you stay provider agnostic. It integrates well with the major cloud providers though!
- AtNightWeCode 5y agoWhat I am saying is that Kubernetes has become the mainstream tool to use. You have to put up good reasons or custom needs to use something else. A thing I like about Consul is that you can also use it as a KV. Something I lack in the cloud. The Vault in Azure is the Keyvault which is all around terrible but Keyvault in conjunction with how Azure works in general is sufficient to build secure infrastructure.
- nuker 5y ago> You have to put up good reasons or custom needs to use something else. Its bloody too complex was a good enough reason to move off it to ECS.
- fragmede 5y ago> There is no need for service discovery in the cloud in general. That's an interesting take! How do you route requests to the right VM/instance whilst VMs go up/down?
- nuker 5y agoLoadbalancer and AWS ASG that registers/unregisters VMs to loadbalancer. Or AWS ECS that does the same for containers.
- jordanbeiber 5y agoThe thing is that few bigger places run stuff in only aws, for example. Also keeping discovery and configuration separate from the cloud provider makes a hybrid approach feasible - which I believe is relevant. Big cloud pricing is big, depending on circumstances.
- slotrans 5y agoDNS.
- folkrav 5y ago> All major clouds have better alternatives to Vault. Debatable. From my experience, all major clours have alternatives to Vault, but not "better" by any stretch of the imagination.
- slotrans 5y agoAWS Secrets Manager gives me everything I want, for no effort, and costs rounds-down-to-zero. I cannot begin to imagine what Vault could even offer that would tempt me to switch.
- jordanbeiber 5y agoSay you want to increase security by issuing short lived accounts and passwords in a database, and make these accessible on demand for apps needing them. The app instance authenticates using the cloud providers key vault and from here it’s allowed to use a policy claiming tokens granting rights to a specific db role. These tokens are short lived and are automatically renewed. This is just one case - vault have a lot of useful integrations that let you “float above” any cloud: https://www.vaultproject.io/docs/secrets https://www.vaultproject.io/docs/secrets I like to keep my concerns separated. That way we can use any cloud as IaaS and keep the platforming part ourselves. Vault is at the heart of achieving something like this.