Chuyển đến nội dung chính

Bài 1: Giới thiệu HashiCorp Vault - Secret Management trong Enterprise

Tìm hiểu HashiCorp Vault là gì, tại sao cần Secret Management tập trung, kiến trúc Vault (Storage Backend, Barrier, Secrets Engines, Auth Methods, Audit Devices, System Backend), so sánh với AWS Secrets Manager/Azure Key Vault/ Google Secret Manager, và các use cases thực tế. Tổng quan Vault 1.21.x.

🔒 DevSecOps — Bài 1 Bài 1: Giới thiệu HashiCorp Vault - Secret Management trong Enterprise

HashiCorp Vault từ Cơ bản đến Nâng cao

Phần 1: Nền tảng HashiCorp Vault

xdev.asia

1. HashiCorp Vault là gì?

HashiCorp Vault là một giải pháp quản lý bí mật (Secret Management) mã nguồn mở, cung cấp khả năng lưu trữ, truy cập và kiểm soát chặt chẽ các thông tin nhạy cảm như passwords, API keys, certificates, encryption keys và các loại secrets khác. Vault được phát triển bởi HashiCorp và hiện là một trong những công cụ hàng đầu cho việc bảo mật infrastructure.

Vault cung cấp một giao diện thống nhất cho mọi loại secret, đồng thời kiểm soát truy cập chặt chẽ và ghi lại audit log chi tiết cho mọi tương tác.

Lịch sử phát triển

  • 2015: HashiCorp Vault 0.1 ra mắt — quản lý secrets cơ bản

  • 2017: Vault 0.9 — Identity Secrets Engine, Sentinel policies (Enterprise)

  • 2018: Vault 1.0 — Integrated Storage (Raft), Auto-unseal, nhiều cải tiến production

  • 2020: Vault 1.5 — Transform Secrets Engine, UI improvements

  • 2022: Vault 1.12 — ACME protocol cho PKI, Vault Agent improvements

  • 2024: Vault 1.17 — Vault Secrets Operator GA, Event system

  • 2025-2026: Vault 1.21.x — phiên bản hiện tại với SPIFFE auth, MFA TOTP self-enrollment, Static roles cho Azure, Secret Recovery

2. Tại sao cần Secret Management tập trung?

Trong hệ thống enterprise hiện đại, secrets được sử dụng ở khắp nơi:

  • Database credentials cho mỗi microservice

  • API keys để tích hợp với third-party services

  • TLS certificates cho mTLS giữa các services

  • SSH keys cho server access

  • Cloud credentials (AWS IAM, Azure Service Principal, GCP Service Account)

  • Encryption keys cho data at rest

Nếu không có giải pháp tập trung, secrets thường bị:

  • Secret sprawl — secrets nằm rải rác trong config files, environment variables, CI/CD pipelines

  • Thiếu rotation — credentials không bao giờ được thay đổi vì sợ ảnh hưởng hệ thống

  • Thiếu audit — không biết ai truy cập secret nào, khi nào

  • Hardcoded secrets — secrets commit trực tiếp vào source code

  • Over-privileged access — developers có quyền truy cập nhiều hơn cần thiết

3. Kiến trúc HashiCorp Vault

Vault có kiến trúc modular với các thành phần chính:

Storage Backend

Storage Backend chịu trách nhiệm lưu trữ dữ liệu đã mã hóa. Vault không tin tưởng storage backend — tất cả dữ liệu được mã hóa trước khi ghi. Các options bao gồm:

  • Integrated Storage (Raft) — recommended, built-in, HA support

  • Consul — HashiCorp Consul storage backend

  • File — local file system, không hỗ trợ HA

  • In-memory — chỉ cho development

Barrier (Encryption Layer)

Barrier là lớp mã hóa bao quanh Vault. Mọi dữ liệu đi vào hoặc ra khỏi Vault đều được mã hóa bằng AES-256-GCM. Barrier chỉ được "mở" khi Vault ở trạng thái unsealed.

Secrets Engines

Secrets Engines là các components lưu trữ, sinh hoặc mã hóa dữ liệu. Mỗi engine được mount tại một path riêng:

  • KV — lưu trữ key-value pairs (static secrets)

  • Database — sinh dynamic database credentials

  • PKI — Certificate Authority, sinh TLS certificates

  • Transit — Encryption as a Service

  • AWS/Azure/GCP — sinh dynamic cloud credentials

  • SSH — signed SSH certificates hoặc OTP

Auth Methods

Auth Methods xác thực clients và gán identity + policies:

  • Token — xác thực bằng Vault token

  • AppRole — cho machine-to-machine authentication

  • LDAP/OIDC — Human users authentication

  • Kubernetes — Pod-based authentication

  • AWS/Azure/GCP — Cloud workload authentication

  • SPIFFE — SVID-based authentication (mới trong 1.21)

Audit Devices

Audit Devices ghi lại mọi request và response với Vault. Mỗi request được log bất kể authentication hoặc authorization thành công hay thất bại.

4. So sánh Vault với các giải pháp khác

Tính năng HashiCorp Vault AWS Secrets Manager Azure Key Vault GCP Secret Manager
Open Source ✅ (Community Edition) ❌ ❌ ❌
Multi-cloud ✅ ❌ (AWS only) ❌ (Azure only) ❌ (GCP only)
Dynamic Secrets ✅ ⚠️ (hạn chế) ❌ ❌
PKI/CA ✅ ❌ ✅ (hạn chế) ❌
Encryption as a Service ✅ (Transit) ❌ ✅ (hạn chế) ❌
SSH Certificates ✅ ❌ ❌ ❌
On-premises ✅ ❌ ❌ ❌
Plugin Ecosystem ✅ (extensible) ❌ ❌ ❌

5. Các use cases chính của Vault

Static Secrets Management

Lưu trữ, rotate và encrypt arbitrary strings dưới dạng key-value pairs sử dụng KV Secrets Engine. Phù hợp cho API keys, configuration values, database passwords.

Dynamic Credentials

Sinh credentials on-demand với TTL giới hạn cho databases (PostgreSQL, MySQL, MongoDB), cloud providers (AWS IAM, Azure SP, GCP SA), và messaging systems. Credentials tự động bị revoke khi hết hạn.

Encryption as a Service

Sử dụng Transit Secrets Engine để mã hóa/giải mã dữ liệu mà không cần lưu trữ encryption keys trong ứng dụng. Ứng dụng gửi plaintext đến Vault và nhận lại ciphertext.

PKI/Certificate Management

Vault PKI Secrets Engine hoạt động như một Certificate Authority hoàn chỉnh, sinh/sign certificates TLS, quản lý certificate lifecycle, CRL, OCSP và hỗ trợ ACME protocol.

Identity-based Access

Vault kết hợp nhiều identity sources (LDAP, OIDC, Kubernetes, Cloud IAM) thành một entity thống nhất, cho phép quản lý policies nhất quán trên mọi platform.

6. Vault 1.21.x — Điểm mới

  • SPIFFE Authentication — xác thực workloads bằng SVID trong SPIFFE environments

  • MFA TOTP Self-enrollment — users tự đăng ký MFA với QR codes khi login

  • KV v2 Version Attribution — xem ai tạo mỗi version của secret

  • Azure Static Roles — quản lý long-lived Azure credentials

  • Secret Recovery — khôi phục secrets từ snapshots mà không overwrite dữ liệu hiện tại

  • Snowflake Root Rotation — tự động rotate key-pair root credentials cho Snowflake

  • RACF Passphrase Support — hỗ trợ passphrases dài hơn trong LDAP Secrets Engine

  • PKI Certificate Counter — theo dõi số lượng certificates đã issue hàng tháng

7. Tổng kết

HashiCorp Vault là giải pháp secret management toàn diện nhất hiện nay, phù hợp cho cả on-premises và cloud environments. Với plugin ecosystem phong phú, khả năng sinh dynamic credentials, encryption as a service, PKI management và identity-based access, Vault là thành phần không thể thiếu trong kiến trúc Zero Trust hiện đại.

Trong bài tiếp theo, chúng ta sẽ cài đặt Vault trên nhiều platform khác nhau và tìm hiểu quy trình khởi tạo, seal/unseal.