Chuyển đến nội dung chính

Lesson 1: Introducing HashiCorp Vault - Secret Management in Enterprise

Learn what HashiCorp Vault is, why centralized Secret Management is needed, Vault architecture (Storage Backend, Barrier, Secrets Engines, Auth Methods, Audit Devices, System Backend), comparison with AWS Secrets Manager/Azure Key Vault/Google Secret Manager, and real-life use cases. Vault 1.21.x Overview.

🔒 DevSecOps — Lesson 1 Lesson 1: Introducing HashiCorp Vault - Secret Management trong Enterprise

HashiCorp Vault from Basic to Advanced

Part 1: HashiCorp Vault Platform

xdev.asia

1. What is HashiCorp Vault?

HashiCorp Vault is an open source secret management solution that provides the ability to store, access and tightly control sensitive information such as passwords, API keys, certificates, encryption keys and other secrets. Vault was developed by HashiCorp and is currently one of the leading tools for infrastructure security.

Vault provides a unified interface for all types of secrets, while tightly controlling access and recording detailed audit logs for every interaction.

Development history

  • 2015: HashiCorp Vault 0.1 launched — basic secrets management

  • 2017: Vault 0.9 — Identity Secrets Engine, Sentinel policies (Enterprise)

  • 2018: Vault 1.0 — Integrated Storage (Raft), Auto-unseal, many production improvements

  • 2020: Vault 1.5 — Transform Secrets Engine, UI improvements

  • 2022: Vault 1.12 — ACME protocol cho PKI, Vault Agent improvements

  • 2024: Vault 1.17 — Vault Secrets Operator GA, Event system

  • 2025-2026: Vault 1.21.x — current version with SPIFFE auth, MFA TOTP self-enrollment, Static roles for Azure, Secret Recovery

2. Why is there a need for centralized Secret Management?

In modern enterprise systems, secrets are used everywhere:

  • Database credentials for each microservice

  • API keys for integration with third-party services

  • TLS certificates for mTLS between services

  • SSH keys cho server access

  • Cloud credentials (AWS IAM, Azure Service Principal, GCP Service Account)

  • Encryption keys cho data at rest

Without a centralized solution, secrets are often:

  • Secret sprawl — secrets scattered in config files, environment variables, CI/CD pipelines

  • Lack of rotation — credentials should never be changed for fear of affecting the system

  • Missing audit — don't know who accessed which secret and when

  • Hardcoded secrets — secrets commit directly to source code

  • Over-privileged access — developers have more access than necessary

3. HashiCorp Vault Architecture

Vault has a modular architecture with the following main components:

Storage Backend

Storage Backend is responsible for storing encrypted data. Vault is agnostic to the storage backend — all data is encrypted before being written. Options include:

  • Integrated Storage (Raft) — recommended, built-in, HA support

  • Consul — HashiCorp Consul storage backend

  • File — local file system, does not support HA

  • In-memory — development only

Barrier (Encryption Layer)

Barrier is the encryption layer surrounding Vault. Any data going into or out of the Vault is encrypted with AES-256-GCM. The Barrier is only "opened" when the Vault is in an unsealed state.

Secrets Engines

Secrets Engines are components that store, generate or encode data. Each engine is mounted at a separate path:

  • KV — stores key-value pairs (static secrets)

  • Database — sinh dynamic database credentials

  • PKI — Certificate Authority, sinh TLS certificates

  • Transit — Encryption as a Service

  • AWS/Azure/GCP — sinh dynamic cloud credentials

  • SSH — signed SSH certificates or OTP

Auth Methods

Auth Methods authenticates clients and assigns identities + policies:

  • Token — authenticate with Vault token

  • AppRole — cho machine-to-machine authentication

  • LDAP/OIDC — Human users authentication

  • Kubernetes — Pod-based authentication

  • AWS/Azure/GCP — Cloud workload authentication

  • SPIFFE — SVID-based authentication (new in 1.21)

Audit Devices

Audit Devices records every request and response with Vault. Each request is logged regardless of whether authentication or authorization succeeds or fails.

4. Compare Vault with other solutions

Feature HashiCorp Vault AWS Secrets Manager Azure Key Vault GCP Secret Manager
Open Source ✅ (Community Edition) ❌ ❌ ❌
Multi-cloud ✅ ❌ (AWS only) ❌ (Azure only) ❌ (GCP only)
Dynamic Secrets ✅ ⚠️ (limited) ❌ ❌
PKI/CA ✅ ❌ ✅ (limited) ❌
Encryption as a Service ✅ (Transit) ❌ ✅ (limited) ❌
SSH Certificates ✅ ❌ ❌ ❌
On-premises ✅ ❌ ❌ ❌
Plugin Ecosystem ✅ (extensible) ❌ ❌ ❌

5. Key use cases of Vault

Static Secrets Management

Store, rotate, and encrypt arbitrary strings as key-value pairs using the KV Secrets Engine. Suitable for API keys, configuration values, database passwords.

Dynamic Credentials

Generates on-demand credentials with limited TTL for databases (PostgreSQL, MySQL, MongoDB), cloud providers (AWS IAM, Azure SP, GCP SA), and messaging systems. Credentials are automatically revoked when they expire.

Encryption as a Service

Use Transit Secrets Engine to encrypt/decrypt data without storing encryption keys in the application. The application sends plaintext to Vault and receives ciphertext back.

PKI/Certificate Management

Vault PKI Secrets Engine acts as a complete Certificate Authority, generating/signing TLS certificates, managing certificate lifecycle, CRL, OCSP and supporting ACME protocol.

Identity-based Access

Vault combines multiple identity sources (LDAP, OIDC, Kubernetes, Cloud IAM) into a unified entity, allowing for consistent policy management across all platforms.

6. Vault 1.21.x — What's new

  • SPIFFE Authentication — authenticate workloads using SVID in SPIFFE environments

  • MFA TOTP Self-enrollment — users self-enroll in MFA with QR codes when logging in

  • KV v2 Version Attribution — see who created each version of secret

  • Azure Static Roles — manage long-lived Azure credentials

  • Secret Recovery — restore secrets from snapshots without overwriting existing data

  • Snowflake Root Rotation — automatically rotate key-pair root credentials for Snowflake

  • RACF Passphrase Support — supports longer passphrases in LDAP Secrets Engine

  • PKI Certificate Counter — track the number of certificates issued monthly

7. Summary

HashiCorp Vault is the most comprehensive secret management solution today, suitable for both on-premises and cloud environments. With a rich plugin ecosystem, dynamic credentials generation, encryption as a service, PKI management and identity-based access, Vault is an indispensable component in a modern Zero Trust architecture.

In the next article, we will install Vault on many different platforms and learn the initialization and seal/unseal process.