1. Vault Enterprise Overview
Vault Enterprise adds enterprise-grade features for large organizations. These are features NOT included in the OSS version.
| Feature | Description | Tier |
|---|---|---|
| Namespaces | Multi-tenancy isolation | Standard+ |
| Performance Replication | Cross-region read replicas | Standard+ |
| DR Replication | Disaster recovery standby cluster | Standard+ |
| Control Groups | Multi-person approval workflow | Governance |
| Sentinel Policies | Policy-as-code framework | Governance |
| Entropy Augmentation | External entropy sources | Standard+ |
| Seal Wrap | FIPS 140-2 compliance | Standard+ |
| Transform SE | Format-preserving encryption | ADP |
2. Namespaces — Multi-Tenancy
Namespaces creates isolated Vault instances within the same cluster. Each namespace has its own auth methods, secrets engines, policies, tokens.
Namespace Hierarchy
root (/)
├── team-platform/
│ ├── secrets engines: kv, pki, database
│ ├── auth methods: kubernetes, approle
│ └── policies: admin, deploy
├── team-backend/
│ ├── dev/
│ │ └── secrets engines: kv
│ ├── staging/
│ │ └── secrets engines: kv, database
│ └── production/
│ └── secrets engines: kv, database, pki
└── team-frontend/
└── secrets engines: kv
Manage Namespaces
# Tạo namespace
vault namespace create team-platform
vault namespace create team-backend
vault namespace create -namespace=team-backend dev
vault namespace create -namespace=team-backend staging
vault namespace create -namespace=team-backend production
# List namespaces
vault namespace list
vault namespace list -namespace=team-backend
# Thao tác trong namespace
export VAULT_NAMESPACE=team-backend/production
vault secrets enable -path=secret kv-v2
vault secrets enable database
vault auth enable kubernetes
# Hoặc dùng flag
vault kv put -namespace=team-backend/production \
secret/api-key value="prod-secret-123"
Policies trong Namespace
# Policy cho team admin — quản lý namespace của team
path "team-backend/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
# Policy cho developer — chỉ đọc trong dev namespace
path "team-backend/dev/secret/data/*" {
capabilities = ["read", "list"]
}
# Cross-namespace access (root namespace policy)
path "team-backend/production/database/creds/readonly" {
capabilities = ["read"]
}
3. Performance Replication
Performance Replication allows placing read replicas in multiple regions, reducing read operations latency.
┌──────────────────────────────────────────────────────┐
│ Architecture │
│ │
│ Region: Singapore Region: Tokyo │
│ ┌─────────────────┐ ┌─────────────────┐ │
│ │ PRIMARY Cluster │ ─────▶│ SECONDARY Cluster│ │
│ │ │ Sync │ (Performance) │ │
│ │ ┌────┐ ┌────┐ │ │ ┌────┐ ┌────┐ │ │
│ │ │ N1 │ │ N2 │ │ │ │ N1 │ │ N2 │ │ │
│ │ └────┘ └────┘ │ │ └────┘ └────┘ │ │
│ │ ┌────┐ │ │ ┌────┐ │ │
│ │ │ N3 │ │ │ │ N3 │ │ │
│ │ └────┘ │ │ └────┘ │ │
│ └─────────────────┘ └─────────────────┘ │
│ Read + Write Read only │
│ (tất cả operations) (writes → forward primary)│
└──────────────────────────────────────────────────────┘
Performance Replication Settings
# PRIMARY cluster
vault write -f sys/replication/performance/primary/enable
# Tạo secondary token
vault write sys/replication/performance/primary/secondary-token \
id="tokyo-secondary" \
ttl="30m"
# → Trả về wrapping_token
# SECONDARY cluster
vault write sys/replication/performance/secondary/enable \
token=""
# Secondary sẽ reboot và sync từ primary
# Kiểm tra trạng thái
vault read sys/replication/performance/status
Behavior
| Operation | Primary | Secondary |
|---|---|---|
| Read secrets | ✅ Local | ✅ Local |
| Write secrets | ✅ Local | ↗️ Forward to primary |
| Auth/Token | ✅ Local | ✅ Local (local tokens) |
| Policies | ✅ Manage | ❌ Synced from primary |
| Auth methods | ✅ Manage | ✅ Local auth methods |
4. Disaster Recovery Replication
DR Replication creates a hot standby cluster ready to promote when the primary cluster fails.
Set DR
# PRIMARY cluster
vault write -f sys/replication/dr/primary/enable
# Tạo DR secondary token
vault write sys/replication/dr/primary/secondary-token \
id="dr-singapore-2"
# DR SECONDARY cluster
vault write sys/replication/dr/secondary/enable \
token=""
# DR secondary sẽ ở trạng thái standby
# Tất cả requests bị reject (503)
DR Failover
# Trước failover — tạo DR operation token trên PRIMARY
vault operator generate-root -dr-token -init
vault operator generate-root -dr-token \
-nonce="" ""
# Khi primary down — promote DR secondary
vault write sys/replication/dr/secondary/promote \
dr_operation_token=""
# DR secondary trở thành primary mới
# Cập nhật DNS/LB trỏ tới cluster mới
5. Control Groups (Governance)
Control Groups require multi-person approval before an operation is executed — multi-person approval.
# Policy với control group
path "secret/data/production/master-key" {
capabilities = ["read"]
control_group {
factor "approver" {
controlled_capabilities = ["read"]
identity {
group_names = ["security-team"]
approvals = 2
}
}
ttl = "4h" # Thời gian chờ approve
max_ttl = "8h"
}
}
# User yêu cầu secret → nhận wrapping token thay vì secret
vault kv get secret/production/master-key
# → Trả về wrapping_token (accessor)
# Approver authorize request
vault write sys/control-group/authorize \
accessor=""
# Sau khi đủ approvals, user unwrap để lấy secret
vault unwrap ""
6. License Management
# Kiểm tra license
vault license get
vault license inspect /path/to/license.hclic
# Vault 1.8+ — license tự động load
# Đặt file license tại một trong:
# 1. VAULT_LICENSE env var
# 2. VAULT_LICENSE_PATH env var
# 3. /etc/vault.d/vault.hclic
7. Summary
Namespaces — Multi-tenancy, each team/env manages its own Vault
Performance Replication — Cross-region reads, reduced latency
DR Replication — Hot standby, fast failover khi primary down
Control Groups — Multi-person approval cho sensitive operations
Sentinel — Policy-as-code, more complex logic than ACL