Chuyển đến nội dung chính

HashiCorp Vault from Basic to Advanced

The HashiCorp Vault course is comprehensive from basic to advanced, helping you master Secret Management, Encryption as a Service, Dynamic Credentials and Identity-based Security. From installing and configuring Secrets Engines (KV, PKI, Transit, Database, AWS, SSH), Auth Methods (Token, Userpass, AppRole, LDAP, OIDC, Kubernetes), Policies, to advanced topics such as Integrated Storage (Raft), High Availability, Auto-unseal, Vault Agent, Vault Secrets Operator, Enterprise features (Namespaces, Sentinel, Replication, DR), monitoring and production operations. Updated to Vault 1.21.x (latest version 2026), including SPIFFE auth, MFA TOTP self-enrollment, KV v2 version attribution and enterprise security best practices.

Part 1: HashiCorp Vault Platform

Lesson 1: Introducing HashiCorp Vault - Secret Management in Enterprise

  • What is HashiCorp Vault? Development history (from HashiCorp to CNCF)

  • Why do we need centralized Secret Management?

  • Vault Architecture: Storage Backend, Barriers, Secrets Engines, Auth Methods, Audit Devices

  • Compare Vault vs AWS Secrets Manager vs Azure Key Vault vs Google Secret Manager

  • Use cases: Static Secrets, Dynamic Credentials, Encryption as a Service, PKI, SSH

Lesson 2: Installing Vault - Standalone, Docker and Kubernetes

  • Install Vault on Ubuntu/CentOS (package manager)

  • Run Vault with Docker and Docker Compose

  • Kubernetes Helm chart deployment

  • Configure Storage Backend (Integrated Storage, File, Consul)

  • Dev Server vs Production Mode

  • Initialize Vault (operator init), Seal/Unseal workflow

Lesson 3: Vault CLI, API and Web UI

  • Vault CLI commands (read, write, list, delete, kv, auth, secrets, policy, operator)

  • Environment variables (VAULT_ADDR, VAULT_TOKEN, VAULT_NAMESPACE)

  • Vault HTTP API, cURL examples

  • SDK clients (Go, Python, Java, Node.js)

  • Vault Web UI overview and navigation

Lesson 4: Seal/Unseal, Auto-unseal and Recovery Keys

  • Seal/Unseal mechanism and Shamir Secret Sharing

  • Key Shares, Key Threshold, Master Key

  • Auto-unseal (AWS KMS, Azure Key Vault, GCP Cloud KMS, Transit, HSM)

  • Recovery Keys and Re-keying (operator rekey)

  • Key Rotation and Seal Migration

Lesson 5: Tokens, Leases and Renewal

  • Token types: Service tokens, Batch tokens

  • Token hierarchy, Orphan tokens, Token accessors

  • Token roles, Periodic tokens, TTL and Max TTL

  • Lease concept, Lease renewal, Lease revocation

  • Cubbyhole Response Wrapping

Part 2: Secrets Engines - Managing Secrets

Lesson 6: KV Secrets Engine - Static Secrets Management

  • KV v1 vs KV v2 detailed comparison

  • Enable/Configure KV Secrets Engine

  • CRUD operations, versioning, metadata

  • KV v2 version attribution (Vault 1.21)

  • Check-and-set (CAS), soft delete, patch operations

Lesson 7: Database Secrets Engine - Dynamic Credentials

  • Database Secrets Engine concept

  • Configure connections: PostgreSQL, MySQL, MongoDB, MSSQL

  • Dynamic roles and Static roles

  • Root credential rotation

  • Integration with real applications

Lesson 8: PKI Secrets Engine - Certificate Authority

  • Create Root CA and Intermediate CA

  • Certificate roles, Issue/Sign certificates

  • CRL, OCSP, Auto-rotation, ACME protocol

  • PKI certificate counter (Vault 1.21)

  • Integration with cert-manager, Nginx, mTLS

Lesson 9: Transit Secrets Engine - Encryption as a Service

  • Encryption/Decryption operations

  • Key management and rotation

  • Key types, HMAC, Sign/Verify

  • Data key generation, Convergent encryption

  • BYOK and Batch operations

Lesson 10: AWS, Azure, GCP and Cloud Secrets Engines

  • AWS Secrets Engine (IAM, STS AssumeRole)

  • Azure Secrets Engine (Static roles trong 1.21)

  • GCP Secrets Engine (Service Account, OAuth2)

  • Multi-cloud secret management best practices

Part 3: Auth Methods - Authentication and Authorization

Lesson 11: Basic Auth Methods - Token, Userpass and AppRole

  • Token Auth Method, Root tokens

  • Userpass Auth Method, Password policies

  • AppRole (RoleID, SecretID, CIDR binding)

  • Response wrapping cho SecretID

  • AppRole cho CI/CD pipelines

Lesson 12: LDAP, OIDC and JWT Auth Methods

  • LDAP Auth Method (Active Directory integration)

  • OIDC Auth Method (Keycloak, Azure AD, Okta)

  • JWT Auth Method (GitHub Actions OIDC, GitLab CI)

  • Bound claims, Claim mappings

Lesson 13: Kubernetes, AWS and Cloud Auth Methods

  • Kubernetes Auth Method (Service Account token review)

  • AWS Auth Method (IAM, EC2)

  • Azure, GCP Auth Methods

  • SPIFFE Auth Method (new in 1.21)

  • Workload identity best practices

Lesson 14: Policies - ACL, Sentinel and RBAC

  • HCL policy syntax, Path-based policies

  • Capabilities (create, read, update, delete, list, sudo, deny)

  • Policy templates (identity parameters)

  • Fine-grained control (allowed_parameters, denied_parameters)

  • Sentinel policies (Enterprise) — EGP, RGP

Lesson 15: Identity Secrets Engine, Entities and MFA

  • Identity Secrets Engine, Entities and Aliases

  • Internal Groups vs External Groups

  • Identity Tokens (OIDC provider)

  • MFA — TOTP, Duo, Okta, PingID

  • MFA TOTP self-enrollment (Vault 1.21)

Part 4: Advanced Secrets Engines

Lesson 16: SSH Secrets Engine and TOTP

  • SSH Signed Certificates (CA mode)

  • SSH One-Time Password (OTP mode)

  • Host key signing, allowed users/extensions

  • TOTP Secrets Engine

  • LDAP Secrets Engine (RACF passphrase support 1.21)

Lesson 17: Transform and Tokenization - Data Protection

  • Transform Secrets Engine (Enterprise)

  • Format Preserving Encryption (FPE), Masking

  • Tokenization stores (internal, external)

  • PCI DSS compliance, PII protection

  • Transit vs Transform — when to use which one

Lesson 18: KMIP, Consul, Nomad Secrets Engines and Custom Plugins

  • KMIP Secrets Engine (Key Management Interoperability Protocol)

  • Consul and Nomad Secrets Engines

  • Vault Plugin System and plugin catalog

  • Developing custom secrets engines/auth methods (Go)

  • Plugin multiplexing and versioned plugins

Part 5: Vault Agent, Proxy and Kubernetes Integration

Lesson 19: Vault Agent and Vault Proxy

  • Vault Agent: Auto-auth, Template rendering, File sink

  • Agent caching, Process supervisor

  • Vault Proxy: API proxy mode, Static secret caching

  • Agent vs Proxy — when to use which one

  • Deployment patterns (systemd, Docker sidecar)

Lesson 20: Vault on Kubernetes - Helm, Operator and CSI

  • Deploy Vault using Helm chart (Standalone, HA, External)

  • Vault Secrets Operator (VaultAuth, VaultStaticSecret, VaultDynamicSecret)

  • Vault CSI Provider (SecretProviderClass)

  • Vault Agent Injector (annotations, templates)

  • VSO vs CSI vs Agent Injector comparison

Part 6: Integrating practical applications

Lesson 21: Integrating Vault with Spring Boot and Node.js

  • Spring Cloud Vault integration

  • Database credential rotation trong Java

  • Node.js with node-vault, Python hvac

  • Application patterns: direct API, sidecar, env vars, CSI

  • Secret zero problem and solution

Lesson 22: Vault with Terraform, Ansible and CI/CD Pipelines

  • Terraform Vault Provider (Infrastructure as Code)

  • Ansible Vault lookup plugin

  • GitHub Actions OIDC, GitLab CI JWT auth

  • Jenkins AppRole integration

  • ArgoCD Vault Plugin, External Secrets Operator

Part 7: Production, Enterprise and Operations

Lesson 23: High Availability, Integrated Storage and Production Hardening

  • Integrated Storage (Raft) cluster setup

  • Autopilot, Raft snapshots, WAL log store

  • HA: active/standby/performance standby

  • Production hardening: TLS, mlock, systemd, security checklist

Lesson 24: Vault Enterprise - Namespaces, Replication and DR

  • Namespaces (multi-tenancy)

  • Performance Replication, Disaster Recovery

  • Sentinel policies (EGP/RGP)

  • Control Groups, Seal Wrap, Entropy Augmentation

  • License management and Enterprise upgrades

Lesson 25: Monitoring, Audit Logging, Backup/Restore and Troubleshooting

  • Audit Devices (File, Syslog, Socket)

  • Prometheus metrics, Grafana dashboards

  • OpenTelemetry tracing

  • Raft snapshots, Secret recovery (Vault 1.21)

  • Troubleshooting, vault debug, production runbook

Part 1: HashiCorp Vault Platform

Part 2: Secrets Engines - Managing Secrets

Part 3: Auth Methods - Authentication and Authorization

Part 4: Advanced Secrets Engines

Part 5: Vault Agent, Proxy and Kubernetes Integration

Part 6: Integrating practical applications

Part 7: Production, Enterprise and Operations