Chuyển đến nội dung chính

Lesson 13: Kubernetes, AWS and Cloud Auth Methods

Kubernetes Auth Method (Service Account token review, bound namespaces, bound service accounts), AWS Auth Method (IAM auth, EC2 auth, cross-account), Azure Auth Method, GCP Auth Method, SPIFFE Auth Method (new in 1.21), best practices for workload identity.

🔒 DevSecOps — Lesson 13 Lesson 13: Kubernetes, AWS and Cloud Auth Methods

HashiCorp Vault from Basic to Advanced

Part 3: Auth Methods - Authentication and Authorization

xdev.asia

1. Kubernetes Auth Method

Kubernetes Auth Method allows Pods on Kubernetes to authenticate to Vault using Kubernetes Service Account tokens. This is the most natural authentication method for workloads running on Kubernetes — no need to manage separate secrets.

Architecture

┌───────────────────┐                    ┌──────────────┐
│   Pod             │  1. Login với SA   │    Vault     │
│   (ServiceAccount)│     JWT token      │  K8s Auth    │
│                   │ ─────────────────▶ │              │
│                   │                    │              │
│                   │  4. Vault Token    │              │
│                   │ ◀───────────────── │              │
└───────────────────┘                    └──────┬───────┘
                                                │
                                       2. TokenReview API
                                          (verify SA token)
                                                │
                                                ▼
                                         ┌──────────────┐
                                         │  Kubernetes  │
                                         │  API Server  │
                                         └──────────────┘

Enable and configure

# Enable Kubernetes auth
vault auth enable kubernetes

# Cấu hình — Vault chạy trong Kubernetes
vault write auth/kubernetes/config \
  kubernetes_host="https://kubernetes.default.svc:443"

# Cấu hình — Vault chạy ngoài Kubernetes
vault write auth/kubernetes/config \
  kubernetes_host="https://k8s-api.company.com:6443" \
  kubernetes_ca_cert=@/etc/vault/k8s-ca.pem \
  token_reviewer_jwt=@/etc/vault/k8s-reviewer-token

Create roles

# Role cho namespace cụ thể
vault write auth/kubernetes/role/webapp \
  bound_service_account_names="webapp-sa" \
  bound_service_account_namespaces="production" \
  token_policies="webapp-policy,db-readonly" \
  token_ttl=1h \
  token_max_ttl=4h

# Role cho nhiều namespaces
vault write auth/kubernetes/role/monitoring \
  bound_service_account_names="prometheus-sa,grafana-sa" \
  bound_service_account_namespaces="monitoring,observability" \
  token_policies="monitoring-readonly" \
  token_ttl=30m

# Role với wildcard (tất cả service accounts trong namespace)
vault write auth/kubernetes/role/dev-all \
  bound_service_account_names="*" \
  bound_service_account_namespaces="development" \
  token_policies="dev-readonly" \
  token_ttl=30m

# Alias name source
vault write auth/kubernetes/role/webapp \
  bound_service_account_names="webapp-sa" \
  bound_service_account_namespaces="production" \
  token_policies="webapp-policy" \
  alias_name_source="serviceaccount_name"

Login from Pod

# Service Account token tự động mount tại Pod
SA_TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)

# Login
curl -s --request POST \
  --data "{\"jwt\": \"${SA_TOKEN}\", \"role\": \"webapp\"}" \
  ${VAULT_ADDR}/v1/auth/kubernetes/login | jq .

# Hoặc dùng Vault CLI
vault write auth/kubernetes/login \
  role=webapp \
  jwt=@/var/run/secrets/kubernetes.io/serviceaccount/token

Kubernetes RBAC cho Vault

# Vault cần ClusterRole để verify SA tokens
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: vault-token-reviewer
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: system:auth-delegator
subjects:
  - kind: ServiceAccount
    name: vault
    namespace: vault

2. AWS Auth Method

AWS Auth Method allows EC2 instances and Lambda functions to authenticate to Vault using AWS IAM or EC2 metadata — no need to manually manage secrets.

Two types of AWS Auth

TypeAuthentication methodUse case
IAM AuthSign STS GetCallerIdentityEC2, Lambda, ECS, EKS, any AWS workload
EC2 AuthEC2 instance metadata (PKCS7 document)EC2 instances only

AWS IAM Auth

# Enable AWS auth
vault auth enable aws

# Cấu hình AWS credentials cho Vault
vault write auth/aws/config/client \
  access_key="AKIAIOSFODNN7EXAMPLE" \
  secret_key="wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY" \
  iam_server_id_header_value="vault.company.com"

# Tạo IAM role
vault write auth/aws/role/webapp \
  auth_type=iam \
  bound_iam_principal_arn="arn:aws:iam::123456789012:role/webapp-role" \
  token_policies="webapp-policy" \
  token_ttl=1h \
  token_max_ttl=4h

# Role cho nhiều IAM principals
vault write auth/aws/role/services \
  auth_type=iam \
  bound_iam_principal_arn='["arn:aws:iam::123456789012:role/service-a","arn:aws:iam::123456789012:role/service-b"]' \
  token_policies="services-policy"

# Cross-account (từ AWS account khác)
vault write auth/aws/config/sts/987654321098 \
  sts_role="arn:aws:iam::123456789012:role/vault-sts-assume"

vault write auth/aws/role/cross-account \
  auth_type=iam \
  bound_iam_principal_arn="arn:aws:iam::987654321098:role/external-app" \
  token_policies="cross-account-readonly"

Login from AWS workload

# Từ EC2/Lambda/ECS — CLI
vault login -method=aws role=webapp

# API call
vault write auth/aws/login \
  role=webapp \
  iam_http_request_method="POST" \
  iam_request_url="$(echo -n 'https://sts.amazonaws.com/' | base64)" \
  iam_request_body="$(echo -n 'Action=GetCallerIdentity&Version=2011-06-15' | base64)" \
  iam_request_headers="..."

3. Azure Auth Method

# Enable Azure auth
vault auth enable azure

# Cấu hình
vault write auth/azure/config \
  tenant_id="<tenant-id>" \
  resource="https://management.azure.com/" \
  client_id="<vault-app-id>" \
  client_secret="<vault-app-secret>"

# Tạo role cho VM với Managed Identity
vault write auth/azure/role/webapp \
  bound_subscription_ids="<subscription-id>" \
  bound_resource_groups="production-rg" \
  bound_service_principal_ids="<managed-identity-principal-id>" \
  token_policies="webapp-policy" \
  token_ttl=1h

4. GCP Auth Method

# Enable GCP auth
vault auth enable gcp

# Cấu hình
vault write auth/gcp/config \
  credentials=@/etc/vault/gcp-credentials.json

# IAM auth (Service Account)
vault write auth/gcp/role/webapp \
  type="iam" \
  bound_service_accounts="[email protected]" \
  token_policies="webapp-policy" \
  token_ttl=1h

# GCE auth (Compute Engine instances)
vault write auth/gcp/role/gce-instances \
  type="gce" \
  bound_projects="my-project" \
  bound_zones="asia-southeast1-a,asia-southeast1-b" \
  bound_labels="env:production,team:platform" \
  token_policies="gce-policy"

5. SPIFFE Auth Method (Vault 1.21)

SPIFFE (Secure Production Identity Framework for Everyone) Auth Method is a new feature in Vault 1.21, allowing workloads to authenticate using SPIFFE SVID (SPIFFE Verifiable Identity Document).

SPIFFE Concepts

TermDescription
SPIFFE IDURI of the form spiffe://trust-domain/workload-identifier
SVIDDocument proving identity (X.509 cert or JWT)
SPIRESPIFFE Runtime Environment — most popular implementation
Trust DomainDomain of trust (for example: company.com)
# Enable SPIFFE auth (Vault 1.21+)
vault auth enable spiffe

# Cấu hình trust domain
vault write auth/spiffe/config \
  spiffe_trust_domain="company.com" \
  spiffe_trust_bundle=@/etc/vault/spire-root-ca.pem

# Tạo role
vault write auth/spiffe/role/webapp \
  bound_spiffe_ids="spiffe://company.com/ns/production/sa/webapp" \
  token_policies="webapp-policy" \
  token_ttl=1h

# Wildcard matching
vault write auth/spiffe/role/production-all \
  bound_spiffe_id_patterns="spiffe://company.com/ns/production/*" \
  token_policies="production-readonly"

6. Workload Identity Best Practices

Choose the appropriate Auth Method

PlatformAuth MethodNote
KubernetesKubernetes AuthMost natural for K8s workloads
AWS EC2/Lambda/ECSAWS IAM AuthPreferred over EC2 auth
Azure VMs/FunctionsAzure AuthUse Managed Identity
GCP GCE/GKE/FunctionsGCP AuthIAM or GCE type
Multi-platform/SPIRESPIFFE AuthPlatform-agnostic identity
CI/CD (GitHub/GitLab)JWT AuthOIDC tokens from CI platform
Legacy/On-prem appsAppRoleFallback cho non-cloud workloads

Least Privilege

  • Each service/workload has its own role — no shared roles

  • Tight binding: specific service account, namespace, project

  • Shortest possible Token TTL

  • Policies granular according to specific path

Multi-cluster Kubernetes

# Mount riêng cho mỗi cluster
vault auth enable -path=k8s-prod kubernetes
vault auth enable -path=k8s-staging kubernetes

# Cấu hình riêng biệt
vault write auth/k8s-prod/config \
  kubernetes_host="https://prod-k8s-api:6443" \
  kubernetes_ca_cert=@/etc/vault/prod-ca.pem

vault write auth/k8s-staging/config \
  kubernetes_host="https://staging-k8s-api:6443" \
  kubernetes_ca_cert=@/etc/vault/staging-ca.pem

7. Summary

  • Kubernetes Auth — standard for K8s workloads, uses Service Account token

  • AWS IAM Auth — preferred for all AWS workloads, no static credentials needed

  • Azure/GCP Auth — same for Azure Managed Identity and GCP Service Accounts

  • SPIFFE Auth (1.21) — platform-agnostic, multi-cloud/hybrid compatible

The next article will delve into Vault Policies — detailed access control mechanisms with ACLs, Sentinel and RBAC.