Chuyển đến nội dung chính

Lesson 2: Install Vault - Standalone, Docker and Kubernetes

Instructions for installing Vault 1.21.x on Linux (Ubuntu/CentOS), macOS, Docker Compose and Kubernetes Helm chart. Configure storage backend (Integrated Storage, File, Consul), listener (TCP, TLS), run Vault in Dev Server vs Production Mode. Vault initialization (vault operator init), Seal/Unseal workflow, and Root Token management.

🔒 DevSecOps — Lesson 2 Lesson 2: Installing Vault - Standalone, Docker and Kubernetes

HashiCorp Vault from Basic to Advanced

Part 1: HashiCorp Vault Platform

xdev.asia

1. Install Vault on Linux

Ubuntu/Debian

# Thêm HashiCorp GPG key
wget -O- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg

Thêm repository

echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list

Cài đặt Vault

sudo apt update && sudo apt install vault

Xác nhận cài đặt

vault version

Vault v1.21.x

CentOS/RHEL

# Thêm repository
sudo yum install -y yum-utils
sudo yum-config-manager --add-repo https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo

Cài đặt Vault

sudo yum install vault

vault version

macOS

# Sử dụng Homebrew
brew tap hashicorp/tap
brew install hashicorp/tap/vault

vault version

2. Run Vault Dev Server

Dev Server is development mode, all data is stored in memory, TLS disabled, auto-unsealed:

# Khởi chạy Dev Server
vault server -dev

# Output sẽ hiển thị:
# Unseal Key: ...
# Root Token: hvs.xxxxx

# Trong terminal khác, export environment variables
export VAULT_ADDR='http://127.0.0.1:8200'
export VAULT_TOKEN='hvs.xxxxx'

# Kiểm tra trạng thái
vault status

⚠️ Warning: Dev Server should NEVER be used for production. Data lost when restarting, no TLS, root token used directly.

3. Configuration Production

Vault configuration file (vault.hcl)

# /etc/vault.d/vault.hcl

Storage Backend - Integrated Storage (Raft)

storage "raft" { path = "/opt/vault/data" node_id = "vault-node-1" }

Listener - TCP với TLS

listener "tcp" { address = "0.0.0.0:8200" tls_cert_file = "/opt/vault/tls/vault-cert.pem" tls_key_file = "/opt/vault/tls/vault-key.pem" }

API Address

api_addr = "https://vault.example.com:8200" cluster_addr = "https://vault.example.com:8201"

UI

ui = true

Disable mlock (recommended cho containers)

disable_mlock = true

Telemetry

telemetry { prometheus_retention_time = "30s" disable_hostname = true }

Systemd Service

# /etc/systemd/system/vault.service
[Unit]
Description=HashiCorp Vault
Documentation=https://developer.hashicorp.com/vault/docs
Requires=network-online.target
After=network-online.target
ConditionFileNotEmpty=/etc/vault.d/vault.hcl

[Service] User=vault Group=vault ProtectSystem=full ProtectHome=read-only PrivateTmp=yes PrivateDevices=yes SecureBits=keep-caps AmbientCapabilities=CAP_IPC_LOCK NoNewPrivileges=yes ExecStart=/usr/bin/vault server -config=/etc/vault.d/vault.hcl ExecReload=/bin/kill --signal HUP $MAINPID KillMode=process KillSignal=SIGINT Restart=on-failure RestartSec=5 TimeoutStopSec=30 LimitNOFILE=65536 LimitMEMLOCK=infinity

[Install] WantedBy=multi-user.target

4. Vault with Docker Compose

# docker-compose.yml
services:
  vault:
    image: hashicorp/vault:1.21
    container_name: vault
    restart: unless-stopped
    ports:
      - "8200:8200"
    environment:
      VAULT_ADDR: "http://0.0.0.0:8200"
      VAULT_API_ADDR: "http://0.0.0.0:8200"
    volumes:
      - vault-data:/vault/data
      - ./config:/vault/config
    cap_add:
      - IPC_LOCK
    command: vault server -config=/vault/config/vault.hcl

volumes:
  vault-data:

5. Initialize Vault (Operator Init)

# Khởi tạo Vault lần đầu
vault operator init

# Output:
# Unseal Key 1: xxx
# Unseal Key 2: xxx
# Unseal Key 3: xxx
# Unseal Key 4: xxx
# Unseal Key 5: xxx
# Initial Root Token: hvs.xxxxx

# Unseal Vault (cần 3 trong 5 keys mặc định)
vault operator unseal <key-1>
vault operator unseal <key-2>
vault operator unseal <key-3>

# Custom key shares và threshold
vault operator init -key-shares=3 -key-threshold=2

# Kiểm tra trạng thái
vault status
# Sealed: false
# HA Enabled: true

6. Deploy Vault on Kubernetes using Helm

# Thêm Helm repo
helm repo add hashicorp https://helm.releases.hashicorp.com
helm repo update

# Cài đặt Vault standalone
helm install vault hashicorp/vault \
  --set "server.dev.enabled=false" \
  --set "server.ha.enabled=true" \
  --set "server.ha.replicas=3" \
  --set "server.ha.raft.enabled=true"

# Khởi tạo Vault trong Kubernetes
kubectl exec vault-0 -- vault operator init
kubectl exec vault-0 -- vault operator unseal <key>

7. Summary

In this article you learned how to install Vault on a variety of platforms, from bare metal Linux to Docker and Kubernetes. The important point is to understand the difference between Dev Server (testing only) and Production mode (needs TLS, persistent storage, proper init/unseal). The next article will dive into Vault CLI, API, and Web UI.