1. Cài đặt Vault trên Linux
Ubuntu/Debian
# Thêm HashiCorp GPG key wget -O- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpgThêm repository
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
Cài đặt Vault
sudo apt update && sudo apt install vault
Xác nhận cài đặt
vault version
Vault v1.21.x
CentOS/RHEL
# Thêm repository sudo yum install -y yum-utils sudo yum-config-manager --add-repo https://rpm.releases.hashicorp.com/RHEL/hashicorp.repoCài đặt Vault
sudo yum install vault
vault version
macOS
# Sử dụng Homebrew brew tap hashicorp/tap brew install hashicorp/tap/vault
vault version
2. Chạy Vault Dev Server
Dev Server là chế độ development, tất cả dữ liệu lưu trong memory, TLS disabled, auto-unsealed:
# Khởi chạy Dev Server
vault server -dev
# Output sẽ hiển thị:
# Unseal Key: ...
# Root Token: hvs.xxxxx
# Trong terminal khác, export environment variables
export VAULT_ADDR='http://127.0.0.1:8200'
export VAULT_TOKEN='hvs.xxxxx'
# Kiểm tra trạng thái
vault status
⚠️ Cảnh báo: Dev Server KHÔNG BAO GIỜ sử dụng cho production. Dữ liệu mất khi restart, không có TLS, root token dùng trực tiếp.
3. Cấu hình Production
File cấu hình Vault (vault.hcl)
# /etc/vault.d/vault.hclStorage Backend - Integrated Storage (Raft)
storage "raft" { path = "/opt/vault/data" node_id = "vault-node-1" }
Listener - TCP với TLS
listener "tcp" { address = "0.0.0.0:8200" tls_cert_file = "/opt/vault/tls/vault-cert.pem" tls_key_file = "/opt/vault/tls/vault-key.pem" }
API Address
api_addr = "https://vault.example.com:8200" cluster_addr = "https://vault.example.com:8201"
UI
ui = true
Disable mlock (recommended cho containers)
disable_mlock = true
Telemetry
telemetry { prometheus_retention_time = "30s" disable_hostname = true }
Systemd Service
# /etc/systemd/system/vault.service [Unit] Description=HashiCorp Vault Documentation=https://developer.hashicorp.com/vault/docs Requires=network-online.target After=network-online.target ConditionFileNotEmpty=/etc/vault.d/vault.hcl[Service] User=vault Group=vault ProtectSystem=full ProtectHome=read-only PrivateTmp=yes PrivateDevices=yes SecureBits=keep-caps AmbientCapabilities=CAP_IPC_LOCK NoNewPrivileges=yes ExecStart=/usr/bin/vault server -config=/etc/vault.d/vault.hcl ExecReload=/bin/kill --signal HUP $MAINPID KillMode=process KillSignal=SIGINT Restart=on-failure RestartSec=5 TimeoutStopSec=30 LimitNOFILE=65536 LimitMEMLOCK=infinity
[Install] WantedBy=multi-user.target
4. Vault với Docker Compose
# docker-compose.yml
services:
vault:
image: hashicorp/vault:1.21
container_name: vault
restart: unless-stopped
ports:
- "8200:8200"
environment:
VAULT_ADDR: "http://0.0.0.0:8200"
VAULT_API_ADDR: "http://0.0.0.0:8200"
volumes:
- vault-data:/vault/data
- ./config:/vault/config
cap_add:
- IPC_LOCK
command: vault server -config=/vault/config/vault.hcl
volumes:
vault-data:
5. Khởi tạo Vault (Operator Init)
# Khởi tạo Vault lần đầu
vault operator init
# Output:
# Unseal Key 1: xxx
# Unseal Key 2: xxx
# Unseal Key 3: xxx
# Unseal Key 4: xxx
# Unseal Key 5: xxx
# Initial Root Token: hvs.xxxxx
# Unseal Vault (cần 3 trong 5 keys mặc định)
vault operator unseal <key-1>
vault operator unseal <key-2>
vault operator unseal <key-3>
# Custom key shares và threshold
vault operator init -key-shares=3 -key-threshold=2
# Kiểm tra trạng thái
vault status
# Sealed: false
# HA Enabled: true
6. Deploy Vault trên Kubernetes bằng Helm
# Thêm Helm repo
helm repo add hashicorp https://helm.releases.hashicorp.com
helm repo update
# Cài đặt Vault standalone
helm install vault hashicorp/vault \
--set "server.dev.enabled=false" \
--set "server.ha.enabled=true" \
--set "server.ha.replicas=3" \
--set "server.ha.raft.enabled=true"
# Khởi tạo Vault trong Kubernetes
kubectl exec vault-0 -- vault operator init
kubectl exec vault-0 -- vault operator unseal <key>
7. Tổng kết
Trong bài này bạn đã học cách cài đặt Vault trên nhiều platform khác nhau, từ bare metal Linux đến Docker và Kubernetes. Điểm quan trọng là hiểu sự khác biệt giữa Dev Server (chỉ cho testing) và Production mode (cần TLS, persistent storage, proper init/unseal). Bài tiếp theo sẽ đi sâu vào Vault CLI, API và Web UI.