パート 1: HashiCorp Vault プラットフォーム
レッスン 1: HashiCorp Vault の紹介 - エンタープライズにおけるシークレット管理
HashiCorp Vault とは何ですか?開発履歴 (HashiCorp から CNCF まで)
一元的な秘密管理が必要なのはなぜですか?
Vault アーキテクチャ: ストレージ バックエンド、バリア、シークレット エンジン、認証方法、監査デバイス
Vault と AWS Secrets Manager と Azure Key Vault と Google Secret Manager を比較
ユースケース: 静的シークレット、動的資格情報、サービスとしての暗号化、PKI、SSH
レッスン 2: Vault のインストール - スタンドアロン、Docker、および Kubernetes
Ubuntu/CentOS に Vault をインストールする (パッケージ マネージャー)
Docker および Docker Compose を使用して Vault を実行する
Kubernetes Helm chart deployment
ストレージ バックエンドの構成 (統合ストレージ、ファイル、Consul)
Dev Server vs Production Mode
Vault の初期化 (オペレーター初期化)、シール/シール解除ワークフロー
レッスン 3: Vault CLI、API、Web UI
Vault CLI commands (read, write, list, delete, kv, auth, secrets, policy, operator)
Environment variables (VAULT_ADDR, VAULT_TOKEN, VAULT_NAMESPACE)
Vault HTTP API, cURL examples
SDK clients (Go, Python, Java, Node.js)
Vault Web UI の概要とナビゲーション
レッスン 4: 封印/封印解除、自動封印解除および回復キー
シール/シール解除メカニズムとシャミール秘密共有
Key Shares, Key Threshold, Master Key
Auto-unseal (AWS KMS, Azure Key Vault, GCP Cloud KMS, Transit, HSM)
回復キーとキーの再生成 (オペレーターによるキーの再生成)
キーのローテーションとシールの移行
レッスン 5: トークン、リース、更新
Token types: Service tokens, Batch tokens
Token hierarchy, Orphan tokens, Token accessors
トークンの役割、定期トークン、TTL および最大 TTL
Lease concept, Lease renewal, Lease revocation
Cubbyhole Response Wrapping
パート 2: シークレット エンジン - シークレットの管理
レッスン 6: KV シークレット エンジン - 静的シークレット管理
KV v1 と KV v2 の詳細な比較
Enable/Configure KV Secrets Engine
CRUD operations, versioning, metadata
KV v2 version attribution (Vault 1.21)
Check-and-set (CAS), soft delete, patch operations
レッスン 7: データベース シークレット エンジン - 動的資格情報
Database Secrets Engine concept
接続の構成: PostgreSQL、MySQL、MongoDB、MSSQL
動的ロールと静的ロール
Root credential rotation
Tích hợp với ứng dụng thực tế
レッスン 8: PKI シークレット エンジン - 認証局
ルート CA と中間 CA の作成
Certificate roles, Issue/Sign certificates
CRL, OCSP, Auto-rotation, ACME protocol
PKI certificate counter (Vault 1.21)
cert-manager、Nginx、mTLS との統合
レッスン 9: トランジット シークレット エンジン - サービスとしての暗号化
Encryption/Decryption operations
キーの管理とローテーション
Key types, HMAC, Sign/Verify
Data key generation, Convergent encryption
BYOK およびバッチ操作
レッスン 10: AWS、Azure、GCP、およびクラウド シークレット エンジン
AWS Secrets Engine (IAM, STS AssumeRole)
Azure Secrets Engine (Static roles trong 1.21)
GCP Secrets Engine (Service Account, OAuth2)
Multi-cloud secret management best practices
パート 3: 認証方法 - 認証と認可
レッスン 11: 基本的な認証方法 - トークン、ユーザーパス、AppRole
Token Auth Method, Root tokens
Userpass Auth Method, Password policies
AppRole (RoleID, SecretID, CIDR binding)
Response wrapping cho SecretID
AppRole cho CI/CD pipelines
レッスン 12: LDAP、OIDC、および JWT 認証方法
LDAP Auth Method (Active Directory integration)
OIDC Auth Method (Keycloak, Azure AD, Okta)
JWT Auth Method (GitHub Actions OIDC, GitLab CI)
Bound claims, Claim mappings
レッスン 13: Kubernetes、AWS、およびクラウドの認証方法
Kubernetes Auth Method (Service Account token review)
AWS Auth Method (IAM, EC2)
Azure, GCP Auth Methods
SPIFFE 認証方法 (1.21 の新機能)
Workload identity best practices
レッスン 14: ポリシー - ACL、Sentinel、RBAC
HCL policy syntax, Path-based policies
Capabilities (create, read, update, delete, list, sudo, deny)
Policy templates (identity parameters)
Fine-grained control (allowed_parameters, denied_parameters)
Sentinel policies (Enterprise) — EGP, RGP
レッスン 15: ID シークレット エンジン、エンティティ、および MFA
ID シークレット エンジン、エンティティ、およびエイリアス
Internal Groups vs External Groups
Identity Tokens (OIDC provider)
MFA — TOTP, Duo, Okta, PingID
MFA TOTP self-enrollment (Vault 1.21)
パート 4: 高度なシークレット エンジン
レッスン 16: SSH シークレット エンジンと TOTP
SSH Signed Certificates (CA mode)
SSH One-Time Password (OTP mode)
Host key signing, allowed users/extensions
TOTP Secrets Engine
LDAP Secrets Engine (RACF passphrase support 1.21)
レッスン 17: 変換とトークン化 - データ保護
Transform Secrets Engine (Enterprise)
Format Preserving Encryption (FPE), Masking
Tokenization stores (internal, external)
PCI DSS compliance, PII protection
Transit と Transform — どちらを使用するか
レッスン 18: KMIP、Consul、Nomad Secrets エンジンおよびカスタム プラグイン
KMIP Secrets Engine (Key Management Interoperability Protocol)
Consul および Nomad Secrets エンジン
Vault プラグイン システムとプラグイン カタログ
Developing custom secrets engines/auth methods (Go)
プラグインの多重化とバージョン管理されたプラグイン
パート 5: Vault Agent、プロキシ、および Kubernetes の統合
レッスン 19: Vault Agent と Vault Proxy
Vault Agent: Auto-auth, Template rendering, File sink
Agent caching, Process supervisor
Vault Proxy: API proxy mode, Static secret caching
エージェントとプロキシ — いつどちらを使用するか
Deployment patterns (systemd, Docker sidecar)
レッスン 20: Kubernetes 上の Vault - Helm、Operator、CSI
Helm チャートを使用した Vault のデプロイ (スタンドアロン、HA、外部)
Vault Secrets Operator (VaultAuth, VaultStaticSecret, VaultDynamicSecret)
Vault CSI Provider (SecretProviderClass)
Vault Agent Injector (annotations, templates)
VSO vs CSI vs Agent Injector comparison
パート 6: 実用的なアプリケーションの統合
レッスン 21: Vault と Spring Boot および Node.js の統合
Spring Cloud Vault integration
Database credential rotation trong Java
Node.js とノードボルト、Python hvac
Application patterns: direct API, sidecar, env vars, CSI
秘密ゼロの問題と解決策
レッスン 22: Terraform、Ansible、CI/CD パイプラインを使用した Vault
Terraform Vault Provider (Infrastructure as Code)
Ansible Vault lookup plugin
GitHub Actions OIDC, GitLab CI JWT auth
Jenkins AppRole integration
ArgoCD Vault Plugin, External Secrets Operator
パート 7: 本番、エンタープライズ、運用
レッスン 23: 高可用性、統合ストレージおよび本番環境の強化
Integrated Storage (Raft) cluster setup
Autopilot, Raft snapshots, WAL log store
HA: active/standby/performance standby
Production hardening: TLS, mlock, systemd, security checklist
レッスン 24: Vault Enterprise - ネームスペース、レプリケーション、および DR
Namespaces (multi-tenancy)
Performance Replication, Disaster Recovery
Sentinel policies (EGP/RGP)
Control Groups, Seal Wrap, Entropy Augmentation
ライセンス管理とエンタープライズアップグレード
レッスン 25: 監視、監査ログ、バックアップ/復元、およびトラブルシューティング
Audit Devices (File, Syslog, Socket)
Prometheus metrics, Grafana dashboards
OpenTelemetry tracing
Raft snapshots, Secret recovery (Vault 1.21)
Troubleshooting, vault debug, production runbook