Chuyển đến nội dung chính

Lesson 24: Vault Enterprise — Namespaces, Replication and DR

Vault Enterprise features: Namespaces cho multi-tenancy, Performance Replication, Disaster Recovery Replication, Control Groups, MFA enforcement, License management.

🔒 DevSecOps — Lesson 24 Lesson 24: Vault Enterprise — Namespaces, Replication and DR

HashiCorp Vault from Basic to Advanced

Part 7: Production, Enterprise and Operations

xdev.asia

1. Vault Enterprise Overview

Vault Enterprise adds enterprise-grade features for large organizations. These are features NOT included in the OSS version.

FeatureDescriptionTier
NamespacesMulti-tenancy isolationStandard+
Performance ReplicationCross-region read replicasStandard+
DR ReplicationDisaster recovery standby clusterStandard+
Control GroupsMulti-person approval workflowGovernance
Sentinel PoliciesPolicy-as-code frameworkGovernance
Entropy AugmentationExternal entropy sourcesStandard+
Seal WrapFIPS 140-2 complianceStandard+
Transform SEFormat-preserving encryptionADP

2. Namespaces — Multi-Tenancy

Namespaces creates isolated Vault instances within the same cluster. Each namespace has its own auth methods, secrets engines, policies, tokens.

Namespace Hierarchy


root (/)
├── team-platform/
│   ├── secrets engines: kv, pki, database
│   ├── auth methods: kubernetes, approle
│   └── policies: admin, deploy
├── team-backend/
│   ├── dev/
│   │   └── secrets engines: kv
│   ├── staging/
│   │   └── secrets engines: kv, database
│   └── production/
│       └── secrets engines: kv, database, pki
└── team-frontend/
    └── secrets engines: kv

Manage Namespaces

# Tạo namespace
vault namespace create team-platform
vault namespace create team-backend
vault namespace create -namespace=team-backend dev
vault namespace create -namespace=team-backend staging
vault namespace create -namespace=team-backend production

# List namespaces
vault namespace list
vault namespace list -namespace=team-backend

# Thao tác trong namespace
export VAULT_NAMESPACE=team-backend/production

vault secrets enable -path=secret kv-v2
vault secrets enable database
vault auth enable kubernetes

# Hoặc dùng flag
vault kv put -namespace=team-backend/production \
  secret/api-key value="prod-secret-123"

Policies trong Namespace

# Policy cho team admin — quản lý namespace của team
path "team-backend/*" {
  capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}

# Policy cho developer — chỉ đọc trong dev namespace
path "team-backend/dev/secret/data/*" {
  capabilities = ["read", "list"]
}

# Cross-namespace access (root namespace policy)
path "team-backend/production/database/creds/readonly" {
  capabilities = ["read"]
}

3. Performance Replication

Performance Replication allows placing read replicas in multiple regions, reducing read operations latency.


┌──────────────────────────────────────────────────────┐
│                   Architecture                        │
│                                                       │
│  Region: Singapore           Region: Tokyo            │
│  ┌─────────────────┐        ┌─────────────────┐      │
│  │  PRIMARY Cluster │ ─────▶│ SECONDARY Cluster│      │
│  │                  │  Sync │  (Performance)   │      │
│  │  ┌────┐ ┌────┐  │       │  ┌────┐ ┌────┐   │      │
│  │  │ N1 │ │ N2 │  │       │  │ N1 │ │ N2 │   │      │
│  │  └────┘ └────┘  │       │  └────┘ └────┘   │      │
│  │       ┌────┐    │       │       ┌────┐     │      │
│  │       │ N3 │    │       │       │ N3 │     │      │
│  │       └────┘    │       │       └────┘     │      │
│  └─────────────────┘       └─────────────────┘       │
│  Read + Write               Read only                 │
│  (tất cả operations)        (writes → forward primary)│
└──────────────────────────────────────────────────────┘

Performance Replication Settings

# PRIMARY cluster
vault write -f sys/replication/performance/primary/enable

# Tạo secondary token
vault write sys/replication/performance/primary/secondary-token \
  id="tokyo-secondary" \
  ttl="30m"
# → Trả về wrapping_token

# SECONDARY cluster
vault write sys/replication/performance/secondary/enable \
  token=""
# Secondary sẽ reboot và sync từ primary

# Kiểm tra trạng thái
vault read sys/replication/performance/status

Behavior

OperationPrimarySecondary
Read secrets✅ Local✅ Local
Write secrets✅ Local↗️ Forward to primary
Auth/Token✅ Local✅ Local (local tokens)
Policies✅ Manage❌ Synced from primary
Auth methods✅ Manage✅ Local auth methods

4. Disaster Recovery Replication

DR Replication creates a hot standby cluster ready to promote when the primary cluster fails.

Set DR

# PRIMARY cluster
vault write -f sys/replication/dr/primary/enable

# Tạo DR secondary token
vault write sys/replication/dr/primary/secondary-token \
  id="dr-singapore-2"

# DR SECONDARY cluster
vault write sys/replication/dr/secondary/enable \
  token=""

# DR secondary sẽ ở trạng thái standby
# Tất cả requests bị reject (503)

DR Failover

# Trước failover — tạo DR operation token trên PRIMARY
vault operator generate-root -dr-token -init
vault operator generate-root -dr-token \
  -nonce="" ""

# Khi primary down — promote DR secondary
vault write sys/replication/dr/secondary/promote \
  dr_operation_token=""

# DR secondary trở thành primary mới
# Cập nhật DNS/LB trỏ tới cluster mới

5. Control Groups (Governance)

Control Groups require multi-person approval before an operation is executed — multi-person approval.

# Policy với control group
path "secret/data/production/master-key" {
  capabilities = ["read"]
  control_group {
    factor "approver" {
      controlled_capabilities = ["read"]
      identity {
        group_names = ["security-team"]
        approvals   = 2
      }
    }
    ttl = "4h"     # Thời gian chờ approve
    max_ttl = "8h"
  }
}
# User yêu cầu secret → nhận wrapping token thay vì secret
vault kv get secret/production/master-key
# → Trả về wrapping_token (accessor)

# Approver authorize request
vault write sys/control-group/authorize \
  accessor=""

# Sau khi đủ approvals, user unwrap để lấy secret
vault unwrap ""

6. License Management

# Kiểm tra license
vault license get
vault license inspect /path/to/license.hclic

# Vault 1.8+ — license tự động load
# Đặt file license tại một trong:
# 1. VAULT_LICENSE env var
# 2. VAULT_LICENSE_PATH env var
# 3. /etc/vault.d/vault.hclic

7. Summary

  • Namespaces — Multi-tenancy, each team/env manages its own Vault

  • Performance Replication — Cross-region reads, reduced latency

  • DR Replication — Hot standby, fast failover khi primary down

  • Control Groups — Multi-person approval cho sensitive operations

  • Sentinel — Policy-as-code, more complex logic than ACL