Chuyển đến nội dung chính

HashiCorp Vault の基本から上級まで

HashiCorp Vault コースは基本から上級まで包括的で、シークレット管理、サービスとしての暗号化、動的資格情報、および ID ベースのセキュリティを習得するのに役立ちます。 Secrets Engine (KV、PKI、Transit、Database、AWS、SSH)、Auth Methods (Token、Userpass、AppRole、LDAP、OIDC、Kubernetes)、ポリシーのインストールと構成から、統合ストレージ (Raft)、高可用性、自動アンシール、Vault Agent、Vault Secrets Operator、エンタープライズ機能 (名前空間、Sentinel、レプリケーション、DR)、モニタリングと運用などの高度なトピックまで操作。 SPIFFE 認証、MFA TOTP 自己登録、KV v2 バージョン アトリビューション、エンタープライズ セキュリティのベスト プラクティスを含む、Vault 1.21.x (最新バージョン 2026) に更新されました。

パート 1: HashiCorp Vault プラットフォーム

レッスン 1: HashiCorp Vault の紹介 - エンタープライズにおけるシークレット管理

  • HashiCorp Vault とは何ですか?開発履歴 (HashiCorp から CNCF まで)

  • 一元的な秘密管理が必要なのはなぜですか?

  • Vault アーキテクチャ: ストレージ バックエンド、バリア、シークレット エンジン、認証方法、監査デバイス

  • Vault と AWS Secrets Manager と Azure Key Vault と Google Secret Manager を比較

  • ユースケース: 静的シークレット、動的資格情報、サービスとしての暗号化、PKI、SSH

レッスン 2: Vault のインストール - スタンドアロン、Docker、および Kubernetes

  • Ubuntu/CentOS に Vault をインストールする (パッケージ マネージャー)

  • Docker および Docker Compose を使用して Vault を実行する

  • Kubernetes Helm chart deployment

  • ストレージ バックエンドの構成 (統合ストレージ、ファイル、Consul)

  • Dev Server vs Production Mode

  • Vault の初期化 (オペレーター初期化)、シール/シール解除ワークフロー

レッスン 3: Vault CLI、API、Web UI

  • Vault CLI commands (read, write, list, delete, kv, auth, secrets, policy, operator)

  • Environment variables (VAULT_ADDR, VAULT_TOKEN, VAULT_NAMESPACE)

  • Vault HTTP API, cURL examples

  • SDK clients (Go, Python, Java, Node.js)

  • Vault Web UI の概要とナビゲーション

レッスン 4: 封印/封印解除、自動封印解除および回復キー

  • シール/シール解除メカニズムとシャミール秘密共有

  • Key Shares, Key Threshold, Master Key

  • Auto-unseal (AWS KMS, Azure Key Vault, GCP Cloud KMS, Transit, HSM)

  • 回復キーとキーの再生成 (オペレーターによるキーの再生成)

  • キーのローテーションとシールの移行

レッスン 5: トークン、リース、更新

  • Token types: Service tokens, Batch tokens

  • Token hierarchy, Orphan tokens, Token accessors

  • トークンの役割、定期トークン、TTL および最大 TTL

  • Lease concept, Lease renewal, Lease revocation

  • Cubbyhole Response Wrapping

パート 2: シークレット エンジン - シークレットの管理

レッスン 6: KV シークレット エンジン - 静的シークレット管理

  • KV v1 と KV v2 の詳細な比較

  • Enable/Configure KV Secrets Engine

  • CRUD operations, versioning, metadata

  • KV v2 version attribution (Vault 1.21)

  • Check-and-set (CAS), soft delete, patch operations

レッスン 7: データベース シークレット エンジン - 動的資格情報

  • Database Secrets Engine concept

  • 接続の構成: PostgreSQL、MySQL、MongoDB、MSSQL

  • 動的ロールと静的ロール

  • Root credential rotation

  • Tích hợp với ứng dụng thực tế

レッスン 8: PKI シークレット エンジン - 認証局

  • ルート CA と中間 CA の作成

  • Certificate roles, Issue/Sign certificates

  • CRL, OCSP, Auto-rotation, ACME protocol

  • PKI certificate counter (Vault 1.21)

  • cert-manager、Nginx、mTLS との統合

レッスン 9: トランジット シークレット エンジン - サービスとしての暗号化

  • Encryption/Decryption operations

  • キーの管理とローテーション

  • Key types, HMAC, Sign/Verify

  • Data key generation, Convergent encryption

  • BYOK およびバッチ操作

レッスン 10: AWS、Azure、GCP、およびクラウド シークレット エンジン

  • AWS Secrets Engine (IAM, STS AssumeRole)

  • Azure Secrets Engine (Static roles trong 1.21)

  • GCP Secrets Engine (Service Account, OAuth2)

  • Multi-cloud secret management best practices

パート 3: 認証方法 - 認証と認可

レッスン 11: 基本的な認証方法 - トークン、ユーザーパス、AppRole

  • Token Auth Method, Root tokens

  • Userpass Auth Method, Password policies

  • AppRole (RoleID, SecretID, CIDR binding)

  • Response wrapping cho SecretID

  • AppRole cho CI/CD pipelines

レッスン 12: LDAP、OIDC、および JWT 認証方法

  • LDAP Auth Method (Active Directory integration)

  • OIDC Auth Method (Keycloak, Azure AD, Okta)

  • JWT Auth Method (GitHub Actions OIDC, GitLab CI)

  • Bound claims, Claim mappings

レッスン 13: Kubernetes、AWS、およびクラウドの認証方法

  • Kubernetes Auth Method (Service Account token review)

  • AWS Auth Method (IAM, EC2)

  • Azure, GCP Auth Methods

  • SPIFFE 認証方法 (1.21 の新機能)

  • Workload identity best practices

レッスン 14: ポリシー - ACL、Sentinel、RBAC

  • HCL policy syntax, Path-based policies

  • Capabilities (create, read, update, delete, list, sudo, deny)

  • Policy templates (identity parameters)

  • Fine-grained control (allowed_parameters, denied_parameters)

  • Sentinel policies (Enterprise) — EGP, RGP

レッスン 15: ID シークレット エンジン、エンティティ、および MFA

  • ID シークレット エンジン、エンティティ、およびエイリアス

  • Internal Groups vs External Groups

  • Identity Tokens (OIDC provider)

  • MFA — TOTP, Duo, Okta, PingID

  • MFA TOTP self-enrollment (Vault 1.21)

パート 4: 高度なシークレット エンジン

レッスン 16: SSH シークレット エンジンと TOTP

  • SSH Signed Certificates (CA mode)

  • SSH One-Time Password (OTP mode)

  • Host key signing, allowed users/extensions

  • TOTP Secrets Engine

  • LDAP Secrets Engine (RACF passphrase support 1.21)

レッスン 17: 変換とトークン化 - データ保護

  • Transform Secrets Engine (Enterprise)

  • Format Preserving Encryption (FPE), Masking

  • Tokenization stores (internal, external)

  • PCI DSS compliance, PII protection

  • Transit と Transform — どちらを使用するか

レッスン 18: KMIP、Consul、Nomad Secrets エンジンおよびカスタム プラグイン

  • KMIP Secrets Engine (Key Management Interoperability Protocol)

  • Consul および Nomad Secrets エンジン

  • Vault プラグイン システムとプラグイン カタログ

  • Developing custom secrets engines/auth methods (Go)

  • プラグインの多重化とバージョン管理されたプラグイン

パート 5: Vault Agent、プロキシ、および Kubernetes の統合

レッスン 19: Vault Agent と Vault Proxy

  • Vault Agent: Auto-auth, Template rendering, File sink

  • Agent caching, Process supervisor

  • Vault Proxy: API proxy mode, Static secret caching

  • エージェントとプロキシ — いつどちらを使用するか

  • Deployment patterns (systemd, Docker sidecar)

レッスン 20: Kubernetes 上の Vault - Helm、Operator、CSI

  • Helm チャートを使用した Vault のデプロイ (スタンドアロン、HA、外部)

  • Vault Secrets Operator (VaultAuth, VaultStaticSecret, VaultDynamicSecret)

  • Vault CSI Provider (SecretProviderClass)

  • Vault Agent Injector (annotations, templates)

  • VSO vs CSI vs Agent Injector comparison

パート 6: 実用的なアプリケーションの統合

レッスン 21: Vault と Spring Boot および Node.js の統合

  • Spring Cloud Vault integration

  • Database credential rotation trong Java

  • Node.js とノードボルト、Python hvac

  • Application patterns: direct API, sidecar, env vars, CSI

  • 秘密ゼロの問題と解決策

レッスン 22: Terraform、Ansible、CI/CD パイプラインを使用した Vault

  • Terraform Vault Provider (Infrastructure as Code)

  • Ansible Vault lookup plugin

  • GitHub Actions OIDC, GitLab CI JWT auth

  • Jenkins AppRole integration

  • ArgoCD Vault Plugin, External Secrets Operator

パート 7: 本番、エンタープライズ、運用

レッスン 23: 高可用性、統合ストレージおよび本番環境の強化

  • Integrated Storage (Raft) cluster setup

  • Autopilot, Raft snapshots, WAL log store

  • HA: active/standby/performance standby

  • Production hardening: TLS, mlock, systemd, security checklist

レッスン 24: Vault Enterprise - ネームスペース、レプリケーション、および DR

  • Namespaces (multi-tenancy)

  • Performance Replication, Disaster Recovery

  • Sentinel policies (EGP/RGP)

  • Control Groups, Seal Wrap, Entropy Augmentation

  • ライセンス管理とエンタープライズアップグレード

レッスン 25: 監視、監査ログ、バックアップ/復元、およびトラブルシューティング

  • Audit Devices (File, Syslog, Socket)

  • Prometheus metrics, Grafana dashboards

  • OpenTelemetry tracing

  • Raft snapshots, Secret recovery (Vault 1.21)

  • Troubleshooting, vault debug, production runbook

パート 1: HashiCorp Vault プラットフォーム

パート 2: Secrets Engine - シークレットの管理

パート 3: 認証方法 - 認証と認可

パート 4: 高度なシークレット エンジン

パート 5: Vault Agent、プロキシ、および Kubernetes の統合

パート 6: 実際のアプリケーションの統合

パート 7: 生産、エンタープライズ、および運用