1. What is HashiCorp Vault?
HashiCorp Vault is an open source secret management solution that provides the ability to store, access and tightly control sensitive information such as passwords, API keys, certificates, encryption keys and other secrets. Vault was developed by HashiCorp and is currently one of the leading tools for infrastructure security.
Vault provides a unified interface for all types of secrets, while tightly controlling access and recording detailed audit logs for every interaction.
Development history
2015: HashiCorp Vault 0.1 launched — basic secrets management
2017: Vault 0.9 — Identity Secrets Engine, Sentinel policies (Enterprise)
2018: Vault 1.0 — Integrated Storage (Raft), Auto-unseal, many production improvements
2020: Vault 1.5 — Transform Secrets Engine, UI improvements
2022: Vault 1.12 — ACME protocol cho PKI, Vault Agent improvements
2024: Vault 1.17 — Vault Secrets Operator GA, Event system
2025-2026: Vault 1.21.x — current version with SPIFFE auth, MFA TOTP self-enrollment, Static roles for Azure, Secret Recovery
2. Why is there a need for centralized Secret Management?
In modern enterprise systems, secrets are used everywhere:
Database credentials for each microservice
API keys for integration with third-party services
TLS certificates for mTLS between services
SSH keys cho server access
Cloud credentials (AWS IAM, Azure Service Principal, GCP Service Account)
Encryption keys cho data at rest
Without a centralized solution, secrets are often:
Secret sprawl — secrets scattered in config files, environment variables, CI/CD pipelines
Lack of rotation — credentials should never be changed for fear of affecting the system
Missing audit — don't know who accessed which secret and when
Hardcoded secrets — secrets commit directly to source code
Over-privileged access — developers have more access than necessary
3. HashiCorp Vault Architecture
Vault has a modular architecture with the following main components:
Storage Backend
Storage Backend is responsible for storing encrypted data. Vault is agnostic to the storage backend — all data is encrypted before being written. Options include:
Integrated Storage (Raft) — recommended, built-in, HA support
Consul — HashiCorp Consul storage backend
File — local file system, does not support HA
In-memory — development only
Barrier (Encryption Layer)
Barrier is the encryption layer surrounding Vault. Any data going into or out of the Vault is encrypted with AES-256-GCM. The Barrier is only "opened" when the Vault is in an unsealed state.
Secrets Engines
Secrets Engines are components that store, generate or encode data. Each engine is mounted at a separate path:
KV — stores key-value pairs (static secrets)
Database — sinh dynamic database credentials
PKI — Certificate Authority, sinh TLS certificates
Transit — Encryption as a Service
AWS/Azure/GCP — sinh dynamic cloud credentials
SSH — signed SSH certificates or OTP
Auth Methods
Auth Methods authenticates clients and assigns identities + policies:
Token — authenticate with Vault token
AppRole — cho machine-to-machine authentication
LDAP/OIDC — Human users authentication
Kubernetes — Pod-based authentication
AWS/Azure/GCP — Cloud workload authentication
SPIFFE — SVID-based authentication (new in 1.21)
Audit Devices
Audit Devices records every request and response with Vault. Each request is logged regardless of whether authentication or authorization succeeds or fails.
4. Compare Vault with other solutions
| Feature | HashiCorp Vault | AWS Secrets Manager | Azure Key Vault | GCP Secret Manager |
|---|---|---|---|---|
| Open Source | ✅ (Community Edition) | ❌ | ❌ | ❌ |
| Multi-cloud | ✅ | ❌ (AWS only) | ❌ (Azure only) | ❌ (GCP only) |
| Dynamic Secrets | ✅ | ⚠️ (limited) | ❌ | ❌ |
| PKI/CA | ✅ | ❌ | ✅ (limited) | ❌ |
| Encryption as a Service | ✅ (Transit) | ❌ | ✅ (limited) | ❌ |
| SSH Certificates | ✅ | ❌ | ❌ | ❌ |
| On-premises | ✅ | ❌ | ❌ | ❌ |
| Plugin Ecosystem | ✅ (extensible) | ❌ | ❌ | ❌ |
5. Key use cases of Vault
Static Secrets Management
Store, rotate, and encrypt arbitrary strings as key-value pairs using the KV Secrets Engine. Suitable for API keys, configuration values, database passwords.
Dynamic Credentials
Generates on-demand credentials with limited TTL for databases (PostgreSQL, MySQL, MongoDB), cloud providers (AWS IAM, Azure SP, GCP SA), and messaging systems. Credentials are automatically revoked when they expire.
Encryption as a Service
Use Transit Secrets Engine to encrypt/decrypt data without storing encryption keys in the application. The application sends plaintext to Vault and receives ciphertext back.
PKI/Certificate Management
Vault PKI Secrets Engine acts as a complete Certificate Authority, generating/signing TLS certificates, managing certificate lifecycle, CRL, OCSP and supporting ACME protocol.
Identity-based Access
Vault combines multiple identity sources (LDAP, OIDC, Kubernetes, Cloud IAM) into a unified entity, allowing for consistent policy management across all platforms.
6. Vault 1.21.x — What's new
SPIFFE Authentication — authenticate workloads using SVID in SPIFFE environments
MFA TOTP Self-enrollment — users self-enroll in MFA with QR codes when logging in
KV v2 Version Attribution — see who created each version of secret
Azure Static Roles — manage long-lived Azure credentials
Secret Recovery — restore secrets from snapshots without overwriting existing data
Snowflake Root Rotation — automatically rotate key-pair root credentials for Snowflake
RACF Passphrase Support — supports longer passphrases in LDAP Secrets Engine
PKI Certificate Counter — track the number of certificates issued monthly
7. Summary
HashiCorp Vault is the most comprehensive secret management solution today, suitable for both on-premises and cloud environments. With a rich plugin ecosystem, dynamic credentials generation, encryption as a service, PKI management and identity-based access, Vault is an indispensable component in a modern Zero Trust architecture.
In the next article, we will install Vault on many different platforms and learn the initialization and seal/unseal process.