Part 1: HashiCorp Vault Platform
Lesson 1: Introducing HashiCorp Vault - Secret Management in Enterprise
What is HashiCorp Vault? Development history (from HashiCorp to CNCF)
Why do we need centralized Secret Management?
Vault Architecture: Storage Backend, Barriers, Secrets Engines, Auth Methods, Audit Devices
Compare Vault vs AWS Secrets Manager vs Azure Key Vault vs Google Secret Manager
Use cases: Static Secrets, Dynamic Credentials, Encryption as a Service, PKI, SSH
Lesson 2: Installing Vault - Standalone, Docker and Kubernetes
Install Vault on Ubuntu/CentOS (package manager)
Run Vault with Docker and Docker Compose
Kubernetes Helm chart deployment
Configure Storage Backend (Integrated Storage, File, Consul)
Dev Server vs Production Mode
Initialize Vault (operator init), Seal/Unseal workflow
Lesson 3: Vault CLI, API and Web UI
Vault CLI commands (read, write, list, delete, kv, auth, secrets, policy, operator)
Environment variables (VAULT_ADDR, VAULT_TOKEN, VAULT_NAMESPACE)
Vault HTTP API, cURL examples
SDK clients (Go, Python, Java, Node.js)
Vault Web UI overview and navigation
Lesson 4: Seal/Unseal, Auto-unseal and Recovery Keys
Seal/Unseal mechanism and Shamir Secret Sharing
Key Shares, Key Threshold, Master Key
Auto-unseal (AWS KMS, Azure Key Vault, GCP Cloud KMS, Transit, HSM)
Recovery Keys and Re-keying (operator rekey)
Key Rotation and Seal Migration
Lesson 5: Tokens, Leases and Renewal
Token types: Service tokens, Batch tokens
Token hierarchy, Orphan tokens, Token accessors
Token roles, Periodic tokens, TTL and Max TTL
Lease concept, Lease renewal, Lease revocation
Cubbyhole Response Wrapping
Part 2: Secrets Engines - Managing Secrets
Lesson 6: KV Secrets Engine - Static Secrets Management
KV v1 vs KV v2 detailed comparison
Enable/Configure KV Secrets Engine
CRUD operations, versioning, metadata
KV v2 version attribution (Vault 1.21)
Check-and-set (CAS), soft delete, patch operations
Lesson 7: Database Secrets Engine - Dynamic Credentials
Database Secrets Engine concept
Configure connections: PostgreSQL, MySQL, MongoDB, MSSQL
Dynamic roles and Static roles
Root credential rotation
Integration with real applications
Lesson 8: PKI Secrets Engine - Certificate Authority
Create Root CA and Intermediate CA
Certificate roles, Issue/Sign certificates
CRL, OCSP, Auto-rotation, ACME protocol
PKI certificate counter (Vault 1.21)
Integration with cert-manager, Nginx, mTLS
Lesson 9: Transit Secrets Engine - Encryption as a Service
Encryption/Decryption operations
Key management and rotation
Key types, HMAC, Sign/Verify
Data key generation, Convergent encryption
BYOK and Batch operations
Lesson 10: AWS, Azure, GCP and Cloud Secrets Engines
AWS Secrets Engine (IAM, STS AssumeRole)
Azure Secrets Engine (Static roles trong 1.21)
GCP Secrets Engine (Service Account, OAuth2)
Multi-cloud secret management best practices
Part 3: Auth Methods - Authentication and Authorization
Lesson 11: Basic Auth Methods - Token, Userpass and AppRole
Token Auth Method, Root tokens
Userpass Auth Method, Password policies
AppRole (RoleID, SecretID, CIDR binding)
Response wrapping cho SecretID
AppRole cho CI/CD pipelines
Lesson 12: LDAP, OIDC and JWT Auth Methods
LDAP Auth Method (Active Directory integration)
OIDC Auth Method (Keycloak, Azure AD, Okta)
JWT Auth Method (GitHub Actions OIDC, GitLab CI)
Bound claims, Claim mappings
Lesson 13: Kubernetes, AWS and Cloud Auth Methods
Kubernetes Auth Method (Service Account token review)
AWS Auth Method (IAM, EC2)
Azure, GCP Auth Methods
SPIFFE Auth Method (new in 1.21)
Workload identity best practices
Lesson 14: Policies - ACL, Sentinel and RBAC
HCL policy syntax, Path-based policies
Capabilities (create, read, update, delete, list, sudo, deny)
Policy templates (identity parameters)
Fine-grained control (allowed_parameters, denied_parameters)
Sentinel policies (Enterprise) — EGP, RGP
Lesson 15: Identity Secrets Engine, Entities and MFA
Identity Secrets Engine, Entities and Aliases
Internal Groups vs External Groups
Identity Tokens (OIDC provider)
MFA — TOTP, Duo, Okta, PingID
MFA TOTP self-enrollment (Vault 1.21)
Part 4: Advanced Secrets Engines
Lesson 16: SSH Secrets Engine and TOTP
SSH Signed Certificates (CA mode)
SSH One-Time Password (OTP mode)
Host key signing, allowed users/extensions
TOTP Secrets Engine
LDAP Secrets Engine (RACF passphrase support 1.21)
Lesson 17: Transform and Tokenization - Data Protection
Transform Secrets Engine (Enterprise)
Format Preserving Encryption (FPE), Masking
Tokenization stores (internal, external)
PCI DSS compliance, PII protection
Transit vs Transform — when to use which one
Lesson 18: KMIP, Consul, Nomad Secrets Engines and Custom Plugins
KMIP Secrets Engine (Key Management Interoperability Protocol)
Consul and Nomad Secrets Engines
Vault Plugin System and plugin catalog
Developing custom secrets engines/auth methods (Go)
Plugin multiplexing and versioned plugins
Part 5: Vault Agent, Proxy and Kubernetes Integration
Lesson 19: Vault Agent and Vault Proxy
Vault Agent: Auto-auth, Template rendering, File sink
Agent caching, Process supervisor
Vault Proxy: API proxy mode, Static secret caching
Agent vs Proxy — when to use which one
Deployment patterns (systemd, Docker sidecar)
Lesson 20: Vault on Kubernetes - Helm, Operator and CSI
Deploy Vault using Helm chart (Standalone, HA, External)
Vault Secrets Operator (VaultAuth, VaultStaticSecret, VaultDynamicSecret)
Vault CSI Provider (SecretProviderClass)
Vault Agent Injector (annotations, templates)
VSO vs CSI vs Agent Injector comparison
Part 6: Integrating practical applications
Lesson 21: Integrating Vault with Spring Boot and Node.js
Spring Cloud Vault integration
Database credential rotation trong Java
Node.js with node-vault, Python hvac
Application patterns: direct API, sidecar, env vars, CSI
Secret zero problem and solution
Lesson 22: Vault with Terraform, Ansible and CI/CD Pipelines
Terraform Vault Provider (Infrastructure as Code)
Ansible Vault lookup plugin
GitHub Actions OIDC, GitLab CI JWT auth
Jenkins AppRole integration
ArgoCD Vault Plugin, External Secrets Operator
Part 7: Production, Enterprise and Operations
Lesson 23: High Availability, Integrated Storage and Production Hardening
Integrated Storage (Raft) cluster setup
Autopilot, Raft snapshots, WAL log store
HA: active/standby/performance standby
Production hardening: TLS, mlock, systemd, security checklist
Lesson 24: Vault Enterprise - Namespaces, Replication and DR
Namespaces (multi-tenancy)
Performance Replication, Disaster Recovery
Sentinel policies (EGP/RGP)
Control Groups, Seal Wrap, Entropy Augmentation
License management and Enterprise upgrades
Lesson 25: Monitoring, Audit Logging, Backup/Restore and Troubleshooting
Audit Devices (File, Syslog, Socket)
Prometheus metrics, Grafana dashboards
OpenTelemetry tracing
Raft snapshots, Secret recovery (Vault 1.21)
Troubleshooting, vault debug, production runbook