1. Install Vault on Linux
Ubuntu/Debian
# Thêm HashiCorp GPG key wget -O- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpgThêm repository
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
Cài đặt Vault
sudo apt update && sudo apt install vault
Xác nhận cài đặt
vault version
Vault v1.21.x
CentOS/RHEL
# Thêm repository sudo yum install -y yum-utils sudo yum-config-manager --add-repo https://rpm.releases.hashicorp.com/RHEL/hashicorp.repoCài đặt Vault
sudo yum install vault
vault version
macOS
# Sử dụng Homebrew brew tap hashicorp/tap brew install hashicorp/tap/vault
vault version
2. Run Vault Dev Server
Dev Server is development mode, all data is stored in memory, TLS disabled, auto-unsealed:
# Khởi chạy Dev Server
vault server -dev
# Output sẽ hiển thị:
# Unseal Key: ...
# Root Token: hvs.xxxxx
# Trong terminal khác, export environment variables
export VAULT_ADDR='http://127.0.0.1:8200'
export VAULT_TOKEN='hvs.xxxxx'
# Kiểm tra trạng thái
vault status
⚠️ Warning: Dev Server should NEVER be used for production. Data lost when restarting, no TLS, root token used directly.
3. Configuration Production
Vault configuration file (vault.hcl)
# /etc/vault.d/vault.hclStorage Backend - Integrated Storage (Raft)
storage "raft" { path = "/opt/vault/data" node_id = "vault-node-1" }
Listener - TCP với TLS
listener "tcp" { address = "0.0.0.0:8200" tls_cert_file = "/opt/vault/tls/vault-cert.pem" tls_key_file = "/opt/vault/tls/vault-key.pem" }
API Address
api_addr = "https://vault.example.com:8200" cluster_addr = "https://vault.example.com:8201"
UI
ui = true
Disable mlock (recommended cho containers)
disable_mlock = true
Telemetry
telemetry { prometheus_retention_time = "30s" disable_hostname = true }
Systemd Service
# /etc/systemd/system/vault.service [Unit] Description=HashiCorp Vault Documentation=https://developer.hashicorp.com/vault/docs Requires=network-online.target After=network-online.target ConditionFileNotEmpty=/etc/vault.d/vault.hcl[Service] User=vault Group=vault ProtectSystem=full ProtectHome=read-only PrivateTmp=yes PrivateDevices=yes SecureBits=keep-caps AmbientCapabilities=CAP_IPC_LOCK NoNewPrivileges=yes ExecStart=/usr/bin/vault server -config=/etc/vault.d/vault.hcl ExecReload=/bin/kill --signal HUP $MAINPID KillMode=process KillSignal=SIGINT Restart=on-failure RestartSec=5 TimeoutStopSec=30 LimitNOFILE=65536 LimitMEMLOCK=infinity
[Install] WantedBy=multi-user.target
4. Vault with Docker Compose
# docker-compose.yml
services:
vault:
image: hashicorp/vault:1.21
container_name: vault
restart: unless-stopped
ports:
- "8200:8200"
environment:
VAULT_ADDR: "http://0.0.0.0:8200"
VAULT_API_ADDR: "http://0.0.0.0:8200"
volumes:
- vault-data:/vault/data
- ./config:/vault/config
cap_add:
- IPC_LOCK
command: vault server -config=/vault/config/vault.hcl
volumes:
vault-data:
5. Initialize Vault (Operator Init)
# Khởi tạo Vault lần đầu
vault operator init
# Output:
# Unseal Key 1: xxx
# Unseal Key 2: xxx
# Unseal Key 3: xxx
# Unseal Key 4: xxx
# Unseal Key 5: xxx
# Initial Root Token: hvs.xxxxx
# Unseal Vault (cần 3 trong 5 keys mặc định)
vault operator unseal <key-1>
vault operator unseal <key-2>
vault operator unseal <key-3>
# Custom key shares và threshold
vault operator init -key-shares=3 -key-threshold=2
# Kiểm tra trạng thái
vault status
# Sealed: false
# HA Enabled: true
6. Deploy Vault on Kubernetes using Helm
# Thêm Helm repo
helm repo add hashicorp https://helm.releases.hashicorp.com
helm repo update
# Cài đặt Vault standalone
helm install vault hashicorp/vault \
--set "server.dev.enabled=false" \
--set "server.ha.enabled=true" \
--set "server.ha.replicas=3" \
--set "server.ha.raft.enabled=true"
# Khởi tạo Vault trong Kubernetes
kubectl exec vault-0 -- vault operator init
kubectl exec vault-0 -- vault operator unseal <key>
7. Summary
In this article you learned how to install Vault on a variety of platforms, from bare metal Linux to Docker and Kubernetes. The important point is to understand the difference between Dev Server (testing only) and Production mode (needs TLS, persistent storage, proper init/unseal). The next article will dive into Vault CLI, API, and Web UI.