1. Kubernetes Auth Method
Kubernetes Auth Method cho phép Pods trên Kubernetes xác thực với Vault bằng Kubernetes Service Account tokens. Đây là phương pháp xác thực tự nhiên nhất cho workloads chạy trên Kubernetes — không cần quản lý secrets riêng.
Kiến trúc
┌───────────────────┐ ┌──────────────┐
│ Pod │ 1. Login với SA │ Vault │
│ (ServiceAccount)│ JWT token │ K8s Auth │
│ │ ─────────────────▶ │ │
│ │ │ │
│ │ 4. Vault Token │ │
│ │ ◀───────────────── │ │
└───────────────────┘ └──────┬───────┘
│
2. TokenReview API
(verify SA token)
│
▼
┌──────────────┐
│ Kubernetes │
│ API Server │
└──────────────┘
Enable và cấu hình
# Enable Kubernetes auth
vault auth enable kubernetes
# Cấu hình — Vault chạy trong Kubernetes
vault write auth/kubernetes/config \
kubernetes_host="https://kubernetes.default.svc:443"
# Cấu hình — Vault chạy ngoài Kubernetes
vault write auth/kubernetes/config \
kubernetes_host="https://k8s-api.company.com:6443" \
kubernetes_ca_cert=@/etc/vault/k8s-ca.pem \
token_reviewer_jwt=@/etc/vault/k8s-reviewer-token
Tạo roles
# Role cho namespace cụ thể
vault write auth/kubernetes/role/webapp \
bound_service_account_names="webapp-sa" \
bound_service_account_namespaces="production" \
token_policies="webapp-policy,db-readonly" \
token_ttl=1h \
token_max_ttl=4h
# Role cho nhiều namespaces
vault write auth/kubernetes/role/monitoring \
bound_service_account_names="prometheus-sa,grafana-sa" \
bound_service_account_namespaces="monitoring,observability" \
token_policies="monitoring-readonly" \
token_ttl=30m
# Role với wildcard (tất cả service accounts trong namespace)
vault write auth/kubernetes/role/dev-all \
bound_service_account_names="*" \
bound_service_account_namespaces="development" \
token_policies="dev-readonly" \
token_ttl=30m
# Alias name source
vault write auth/kubernetes/role/webapp \
bound_service_account_names="webapp-sa" \
bound_service_account_namespaces="production" \
token_policies="webapp-policy" \
alias_name_source="serviceaccount_name"
Login từ Pod
# Service Account token tự động mount tại Pod
SA_TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
# Login
curl -s --request POST \
--data "{\"jwt\": \"${SA_TOKEN}\", \"role\": \"webapp\"}" \
${VAULT_ADDR}/v1/auth/kubernetes/login | jq .
# Hoặc dùng Vault CLI
vault write auth/kubernetes/login \
role=webapp \
jwt=@/var/run/secrets/kubernetes.io/serviceaccount/token
Kubernetes RBAC cho Vault
# Vault cần ClusterRole để verify SA tokens
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: vault-token-reviewer
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: system:auth-delegator
subjects:
- kind: ServiceAccount
name: vault
namespace: vault
2. AWS Auth Method
AWS Auth Method cho phép EC2 instances và Lambda functions xác thực với Vault bằng AWS IAM hoặc EC2 metadata — không cần quản lý secrets thủ công.
Hai loại AWS Auth
| Loại | Cách xác thực | Use case |
|---|---|---|
| IAM Auth | Ký STS GetCallerIdentity | EC2, Lambda, ECS, EKS, bất kỳ AWS workload |
| EC2 Auth | EC2 instance metadata (PKCS7 document) | Chỉ EC2 instances |
AWS IAM Auth
# Enable AWS auth
vault auth enable aws
# Cấu hình AWS credentials cho Vault
vault write auth/aws/config/client \
access_key="AKIAIOSFODNN7EXAMPLE" \
secret_key="wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY" \
iam_server_id_header_value="vault.company.com"
# Tạo IAM role
vault write auth/aws/role/webapp \
auth_type=iam \
bound_iam_principal_arn="arn:aws:iam::123456789012:role/webapp-role" \
token_policies="webapp-policy" \
token_ttl=1h \
token_max_ttl=4h
# Role cho nhiều IAM principals
vault write auth/aws/role/services \
auth_type=iam \
bound_iam_principal_arn='["arn:aws:iam::123456789012:role/service-a","arn:aws:iam::123456789012:role/service-b"]' \
token_policies="services-policy"
# Cross-account (từ AWS account khác)
vault write auth/aws/config/sts/987654321098 \
sts_role="arn:aws:iam::123456789012:role/vault-sts-assume"
vault write auth/aws/role/cross-account \
auth_type=iam \
bound_iam_principal_arn="arn:aws:iam::987654321098:role/external-app" \
token_policies="cross-account-readonly"
Login từ AWS workload
# Từ EC2/Lambda/ECS — CLI
vault login -method=aws role=webapp
# API call
vault write auth/aws/login \
role=webapp \
iam_http_request_method="POST" \
iam_request_url="$(echo -n 'https://sts.amazonaws.com/' | base64)" \
iam_request_body="$(echo -n 'Action=GetCallerIdentity&Version=2011-06-15' | base64)" \
iam_request_headers="..."
3. Azure Auth Method
# Enable Azure auth
vault auth enable azure
# Cấu hình
vault write auth/azure/config \
tenant_id="<tenant-id>" \
resource="https://management.azure.com/" \
client_id="<vault-app-id>" \
client_secret="<vault-app-secret>"
# Tạo role cho VM với Managed Identity
vault write auth/azure/role/webapp \
bound_subscription_ids="<subscription-id>" \
bound_resource_groups="production-rg" \
bound_service_principal_ids="<managed-identity-principal-id>" \
token_policies="webapp-policy" \
token_ttl=1h
4. GCP Auth Method
# Enable GCP auth
vault auth enable gcp
# Cấu hình
vault write auth/gcp/config \
credentials=@/etc/vault/gcp-credentials.json
# IAM auth (Service Account)
vault write auth/gcp/role/webapp \
type="iam" \
bound_service_accounts="[email protected]" \
token_policies="webapp-policy" \
token_ttl=1h
# GCE auth (Compute Engine instances)
vault write auth/gcp/role/gce-instances \
type="gce" \
bound_projects="my-project" \
bound_zones="asia-southeast1-a,asia-southeast1-b" \
bound_labels="env:production,team:platform" \
token_policies="gce-policy"
5. SPIFFE Auth Method (Vault 1.21)
SPIFFE (Secure Production Identity Framework for Everyone) Auth Method là tính năng mới trong Vault 1.21, cho phép workloads xác thực bằng SPIFFE SVID (SPIFFE Verifiable Identity Document).
SPIFFE Concepts
| Thuật ngữ | Mô tả |
|---|---|
| SPIFFE ID | URI dạng spiffe://trust-domain/workload-identifier |
| SVID | Document chứng minh identity (X.509 cert hoặc JWT) |
| SPIRE | SPIFFE Runtime Environment — implementation phổ biến nhất |
| Trust Domain | Domain of trust (ví dụ: company.com) |
# Enable SPIFFE auth (Vault 1.21+)
vault auth enable spiffe
# Cấu hình trust domain
vault write auth/spiffe/config \
spiffe_trust_domain="company.com" \
spiffe_trust_bundle=@/etc/vault/spire-root-ca.pem
# Tạo role
vault write auth/spiffe/role/webapp \
bound_spiffe_ids="spiffe://company.com/ns/production/sa/webapp" \
token_policies="webapp-policy" \
token_ttl=1h
# Wildcard matching
vault write auth/spiffe/role/production-all \
bound_spiffe_id_patterns="spiffe://company.com/ns/production/*" \
token_policies="production-readonly"
6. Workload Identity Best Practices
Chọn Auth Method phù hợp
| Platform | Auth Method | Ghi chú |
|---|---|---|
| Kubernetes | Kubernetes Auth | Tự nhiên nhất cho K8s workloads |
| AWS EC2/Lambda/ECS | AWS IAM Auth | Preferred over EC2 auth |
| Azure VMs/Functions | Azure Auth | Dùng Managed Identity |
| GCP GCE/GKE/Functions | GCP Auth | IAM hoặc GCE type |
| Multi-platform/SPIRE | SPIFFE Auth | Platform-agnostic identity |
| CI/CD (GitHub/GitLab) | JWT Auth | OIDC tokens từ CI platform |
| Legacy/On-prem apps | AppRole | Fallback cho non-cloud workloads |
Least Privilege
Mỗi service/workload có role riêng — không share roles
Bind chặt: specific service account, namespace, project
Token TTL ngắn nhất có thể
Policies granular theo path cụ thể
Multi-cluster Kubernetes
# Mount riêng cho mỗi cluster
vault auth enable -path=k8s-prod kubernetes
vault auth enable -path=k8s-staging kubernetes
# Cấu hình riêng biệt
vault write auth/k8s-prod/config \
kubernetes_host="https://prod-k8s-api:6443" \
kubernetes_ca_cert=@/etc/vault/prod-ca.pem
vault write auth/k8s-staging/config \
kubernetes_host="https://staging-k8s-api:6443" \
kubernetes_ca_cert=@/etc/vault/staging-ca.pem
7. Tổng kết
Kubernetes Auth — standard cho K8s workloads, dùng Service Account token
AWS IAM Auth — preferred cho mọi AWS workloads, không cần static credentials
Azure/GCP Auth — tương tự cho Azure Managed Identity và GCP Service Accounts
SPIFFE Auth (1.21) — platform-agnostic, phù hợp multi-cloud/hybrid
Bài tiếp theo sẽ đi sâu vào Vault Policies — cơ chế kiểm soát quyền truy cập chi tiết với ACL, Sentinel và RBAC.