1. HashiCorp Vault là gì?
HashiCorp Vault là một giải pháp quản lý bí mật (Secret Management) mã nguồn mở, cung cấp khả năng lưu trữ, truy cập và kiểm soát chặt chẽ các thông tin nhạy cảm như passwords, API keys, certificates, encryption keys và các loại secrets khác. Vault được phát triển bởi HashiCorp và hiện là một trong những công cụ hàng đầu cho việc bảo mật infrastructure.
Vault cung cấp một giao diện thống nhất cho mọi loại secret, đồng thời kiểm soát truy cập chặt chẽ và ghi lại audit log chi tiết cho mọi tương tác.
Lịch sử phát triển
2015: HashiCorp Vault 0.1 ra mắt — quản lý secrets cơ bản
2017: Vault 0.9 — Identity Secrets Engine, Sentinel policies (Enterprise)
2018: Vault 1.0 — Integrated Storage (Raft), Auto-unseal, nhiều cải tiến production
2020: Vault 1.5 — Transform Secrets Engine, UI improvements
2022: Vault 1.12 — ACME protocol cho PKI, Vault Agent improvements
2024: Vault 1.17 — Vault Secrets Operator GA, Event system
2025-2026: Vault 1.21.x — phiên bản hiện tại với SPIFFE auth, MFA TOTP self-enrollment, Static roles cho Azure, Secret Recovery
2. Tại sao cần Secret Management tập trung?
Trong hệ thống enterprise hiện đại, secrets được sử dụng ở khắp nơi:
Database credentials cho mỗi microservice
API keys để tích hợp với third-party services
TLS certificates cho mTLS giữa các services
SSH keys cho server access
Cloud credentials (AWS IAM, Azure Service Principal, GCP Service Account)
Encryption keys cho data at rest
Nếu không có giải pháp tập trung, secrets thường bị:
Secret sprawl — secrets nằm rải rác trong config files, environment variables, CI/CD pipelines
Thiếu rotation — credentials không bao giờ được thay đổi vì sợ ảnh hưởng hệ thống
Thiếu audit — không biết ai truy cập secret nào, khi nào
Hardcoded secrets — secrets commit trực tiếp vào source code
Over-privileged access — developers có quyền truy cập nhiều hơn cần thiết
3. Kiến trúc HashiCorp Vault
Vault có kiến trúc modular với các thành phần chính:
Storage Backend
Storage Backend chịu trách nhiệm lưu trữ dữ liệu đã mã hóa. Vault không tin tưởng storage backend — tất cả dữ liệu được mã hóa trước khi ghi. Các options bao gồm:
Integrated Storage (Raft) — recommended, built-in, HA support
Consul — HashiCorp Consul storage backend
File — local file system, không hỗ trợ HA
In-memory — chỉ cho development
Barrier (Encryption Layer)
Barrier là lớp mã hóa bao quanh Vault. Mọi dữ liệu đi vào hoặc ra khỏi Vault đều được mã hóa bằng AES-256-GCM. Barrier chỉ được "mở" khi Vault ở trạng thái unsealed.
Secrets Engines
Secrets Engines là các components lưu trữ, sinh hoặc mã hóa dữ liệu. Mỗi engine được mount tại một path riêng:
KV — lưu trữ key-value pairs (static secrets)
Database — sinh dynamic database credentials
PKI — Certificate Authority, sinh TLS certificates
Transit — Encryption as a Service
AWS/Azure/GCP — sinh dynamic cloud credentials
SSH — signed SSH certificates hoặc OTP
Auth Methods
Auth Methods xác thực clients và gán identity + policies:
Token — xác thực bằng Vault token
AppRole — cho machine-to-machine authentication
LDAP/OIDC — Human users authentication
Kubernetes — Pod-based authentication
AWS/Azure/GCP — Cloud workload authentication
SPIFFE — SVID-based authentication (mới trong 1.21)
Audit Devices
Audit Devices ghi lại mọi request và response với Vault. Mỗi request được log bất kể authentication hoặc authorization thành công hay thất bại.
4. So sánh Vault với các giải pháp khác
| Tính năng | HashiCorp Vault | AWS Secrets Manager | Azure Key Vault | GCP Secret Manager |
|---|---|---|---|---|
| Open Source | ✅ (Community Edition) | ❌ | ❌ | ❌ |
| Multi-cloud | ✅ | ❌ (AWS only) | ❌ (Azure only) | ❌ (GCP only) |
| Dynamic Secrets | ✅ | ⚠️ (hạn chế) | ❌ | ❌ |
| PKI/CA | ✅ | ❌ | ✅ (hạn chế) | ❌ |
| Encryption as a Service | ✅ (Transit) | ❌ | ✅ (hạn chế) | ❌ |
| SSH Certificates | ✅ | ❌ | ❌ | ❌ |
| On-premises | ✅ | ❌ | ❌ | ❌ |
| Plugin Ecosystem | ✅ (extensible) | ❌ | ❌ | ❌ |
5. Các use cases chính của Vault
Static Secrets Management
Lưu trữ, rotate và encrypt arbitrary strings dưới dạng key-value pairs sử dụng KV Secrets Engine. Phù hợp cho API keys, configuration values, database passwords.
Dynamic Credentials
Sinh credentials on-demand với TTL giới hạn cho databases (PostgreSQL, MySQL, MongoDB), cloud providers (AWS IAM, Azure SP, GCP SA), và messaging systems. Credentials tự động bị revoke khi hết hạn.
Encryption as a Service
Sử dụng Transit Secrets Engine để mã hóa/giải mã dữ liệu mà không cần lưu trữ encryption keys trong ứng dụng. Ứng dụng gửi plaintext đến Vault và nhận lại ciphertext.
PKI/Certificate Management
Vault PKI Secrets Engine hoạt động như một Certificate Authority hoàn chỉnh, sinh/sign certificates TLS, quản lý certificate lifecycle, CRL, OCSP và hỗ trợ ACME protocol.
Identity-based Access
Vault kết hợp nhiều identity sources (LDAP, OIDC, Kubernetes, Cloud IAM) thành một entity thống nhất, cho phép quản lý policies nhất quán trên mọi platform.
6. Vault 1.21.x — Điểm mới
SPIFFE Authentication — xác thực workloads bằng SVID trong SPIFFE environments
MFA TOTP Self-enrollment — users tự đăng ký MFA với QR codes khi login
KV v2 Version Attribution — xem ai tạo mỗi version của secret
Azure Static Roles — quản lý long-lived Azure credentials
Secret Recovery — khôi phục secrets từ snapshots mà không overwrite dữ liệu hiện tại
Snowflake Root Rotation — tự động rotate key-pair root credentials cho Snowflake
RACF Passphrase Support — hỗ trợ passphrases dài hơn trong LDAP Secrets Engine
PKI Certificate Counter — theo dõi số lượng certificates đã issue hàng tháng
7. Tổng kết
HashiCorp Vault là giải pháp secret management toàn diện nhất hiện nay, phù hợp cho cả on-premises và cloud environments. Với plugin ecosystem phong phú, khả năng sinh dynamic credentials, encryption as a service, PKI management và identity-based access, Vault là thành phần không thể thiếu trong kiến trúc Zero Trust hiện đại.
Trong bài tiếp theo, chúng ta sẽ cài đặt Vault trên nhiều platform khác nhau và tìm hiểu quy trình khởi tạo, seal/unseal.