Chuyển đến nội dung chính

Lesson 3: Vault CLI, API and Web UI

Get familiar with Vault CLI (vault read, write, list, delete, kv, auth, secrets, policy, operator), Environment variables (VAULT_ADDR, VAULT_TOKEN, VAULT_NAMESPACE), Vault HTTP RESTful API, cURL and SDK clients (Go, Python, Java, Node.js). Vault Web UI overview, navigation and management of secrets through the interface.

🔒 DevSecOps — Lesson 3 Lesson 3: Vault CLI, API and Web UI

HashiCorp Vault from Basic to Advanced

Part 1: HashiCorp Vault Platform

xdev.asia

1. Vault CLI Overview

Vault CLI is the main command line tool for interacting with the Vault server. The CLI uses the same HTTP API that every other client uses, ensuring consistency.

Environment Variables needed

# Địa chỉ Vault server
export VAULT_ADDR='https://vault.example.com:8200'

Token xác thực

export VAULT_TOKEN='hvs.xxxxx'

Namespace (Enterprise)

export VAULT_NAMESPACE='admin/team-a'

Skip TLS verify (chỉ dev)

export VAULT_SKIP_VERIFY=true

CA Certificate

export VAULT_CACERT='/path/to/ca.pem'

Basic CLI commands

# Kiểm tra trạng thái
vault status

Login với các auth methods

vault login # Token-based vault login -method=userpass username=admin vault login -method=oidc

KV operations

vault kv put secret/myapp password="s3cr3t" vault kv get secret/myapp vault kv get -field=password secret/myapp vault kv list secret/ vault kv delete secret/myapp

Secrets engine management

vault secrets enable -path=kv kv-v2 vault secrets list vault secrets disable kv/

Auth method management

vault auth enable userpass vault auth list vault auth disable userpass/

Policy management

vault policy write my-policy policy.hcl vault policy read my-policy vault policy list vault policy delete my-policy

Operator commands

vault operator seal vault operator unseal vault operator raft list-peers vault operator raft snapshot save backup.snap

2. Vault HTTP API

Vault provides a complete RESTful API. All operations can be performed via API:

# Đọc secret
curl -s \
  --header "X-Vault-Token: hvs.xxxxx" \
  https://vault.example.com:8200/v1/secret/data/myapp | jq

# Ghi secret
curl -s \
  --header "X-Vault-Token: hvs.xxxxx" \
  --request POST \
  --data '{"data": {"password": "s3cr3t", "username": "admin"}}' \
  https://vault.example.com:8200/v1/secret/data/myapp

# Liệt kê secrets
curl -s \
  --header "X-Vault-Token: hvs.xxxxx" \
  --request LIST \
  https://vault.example.com:8200/v1/secret/metadata/ | jq

# Health check
curl -s https://vault.example.com:8200/v1/sys/health | jq

3. SDK Clients

Python (hvac)

import hvac

client = hvac.Client(url='https://vault.example.com:8200', token='hvs.xxxxx')

Đọc secret

secret = client.secrets.kv.v2.read_secret_version(path='myapp') print(secret['data']['data']['password'])

Ghi secret

client.secrets.kv.v2.create_or_update_secret( path='myapp', secret=dict(password='new-password', username='admin') )

Go

import (
    "github.com/hashicorp/vault-client-go"
)

client, _ := vault.New( vault.WithAddress("https://vault.example.com:8200"), ) client.SetToken("hvs.xxxxx")

secret, _ := client.Secrets.KvV2Read(ctx, "myapp", vault.WithMountPath("secret"))

4. Vault Web UI

Vault Web UI provides a visual interface enabled by ui = true in the configuration. Access at https://vault.example.com:8200/ui.

Web UI support:

  • Managing Secrets Engines and secrets

  • Manage Auth Methods

  • Policies Management

  • Xem Audit Logs

  • Client Count Dashboard (1.21)

  • Secret Recovery (1.21)

5. Summary

Vault provides three main ways of interaction: CLI, HTTP API, and Web UI. CLI is suitable for development and scripting, API for application integration, Web UI for administrators. The next article will delve into the Seal/Unseal and Auto-unseal mechanisms.