3 ms·
It does. The solution to this problem is to run Vault in high availability mode[1]. This will have a set of stand-bys that can take over if the leader goes dow
by mitchellh 11y ago
It does.
The solution to this problem is to run Vault in high availability mode[1]. This will have a set of stand-bys that can take over if the leader goes down. The idea is to unseal all the stand bys, and if the leader goes down, the standbys take over, and the sealed one can be unsealed at some other future point.
Security-sensitive things have been an interesting UX challenge for us, but this compromise comes at an expense of UX for a much better security promise. As one of the other comments says around this comment: without this feature there would be no real security for the stored data.
[1]: http://vaultproject.io/docs/concepts/ha.html http://vaultproject.io/docs/concepts/ha.html
- carllerche 11y agoLooks good. The post did not mention HA (that I saw), which caused the confusion.
- odiroot 11y agoWould you also recommend to set the lease duration to something higher in order to allow people to react? This way even if Vault dies during the night (and you don't have pager duty) at least some clients (e.g. your cloud instances) can live through?
- SEJeff 11y agoCan you call mlock in go to prevent any secrets from being paged to disk?
- mitchellh 11y agoWe already do this. And yes, you can (using the "syscall" package).