3 ms·
Even when going multi-cloud you can employ different strategies. Vault is definitely one of them, but you can also use federation to exchange one cloud's creden
by fishnchips 3y ago
Even when going multi-cloud you can employ different strategies. Vault is definitely one of them, but you can also use federation to exchange one cloud's credentials for another's, giving you the ability to centralize secrets in one of them. You can use a layer of abstraction like GoCloud [0]. You can also build for each cloud separately and decide either not to centralize secrets at all, or build some trivial bespoke tooling to synchronize some of them. I'm not endorsing any of the options, nor am I trying to argue that Vault is never the right choice, I'm just pointing out that Vault isn't the only viable alternative.
https://github.com/google/go-cloud https://github.com/google/go-cloud