Chuyển đến nội dung chính
Cơ bản

HashiCorp Vault từ Cơ bản đến Nâng cao

Khóa học HashiCorp Vault toàn diện từ cơ bản đến nâng cao, giúp bạn làm chủ Secret Management, Encryption as a Service, Dynamic Credentials và Identity-based Security. Từ cài đặt, cấu hình Secrets Engines (KV, PKI, Transit, Database, AWS, SSH), Auth Methods (Token, Userpass, AppRole, LDAP, OIDC, Kubernetes), Policies, đến các chủ đề nâng cao như Integrated Storage (Raft), High Availability, Auto-unseal, Vault Agent, Vault Secrets Operator, Enterprise features (Namespaces, Sentinel, Replication, DR), monitoring và vận hành production. Cập nhật theo Vault 1.21.x (phiên bản mới nhất 2026), bao gồm SPIFFE auth, MFA TOTP self-enrollment, KV v2 version attribution và các best practices bảo mật enterprise.

DUY TRANDuy Tran
25 bài học
80 giờ
HashiCorp Vault từ Cơ bản đến Nâng cao

Nội dung series

7 phần · 25 bài học

5.Phần 5: Vault Agent, Proxy và Kubernetes Integration

2 bài

Phần 1: Nền tảng HashiCorp Vault

Bài 1: Giới thiệu HashiCorp Vault - Secret Management trong Enterprise

  • HashiCorp Vault là gì? Lịch sử phát triển (từ HashiCorp đến CNCF)

  • Tại sao cần Secret Management tập trung?

  • Kiến trúc Vault: Storage Backend, Barrier, Secrets Engines, Auth Methods, Audit Devices

  • So sánh Vault vs AWS Secrets Manager vs Azure Key Vault vs Google Secret Manager

  • Các use cases: Static Secrets, Dynamic Credentials, Encryption as a Service, PKI, SSH

Bài 2: Cài đặt Vault - Standalone, Docker và Kubernetes

  • Cài đặt Vault trên Ubuntu/CentOS (package manager)

  • Chạy Vault với Docker và Docker Compose

  • Kubernetes Helm chart deployment

  • Cấu hình Storage Backend (Integrated Storage, File, Consul)

  • Dev Server vs Production Mode

  • Khởi tạo Vault (operator init), Seal/Unseal workflow

Bài 3: Vault CLI, API và Web UI

  • Vault CLI commands (read, write, list, delete, kv, auth, secrets, policy, operator)

  • Environment variables (VAULT_ADDR, VAULT_TOKEN, VAULT_NAMESPACE)

  • Vault HTTP API, cURL examples

  • SDK clients (Go, Python, Java, Node.js)

  • Vault Web UI overview và navigation

Bài 4: Seal/Unseal, Auto-unseal và Recovery Keys

  • Seal/Unseal mechanism và Shamir Secret Sharing

  • Key Shares, Key Threshold, Master Key

  • Auto-unseal (AWS KMS, Azure Key Vault, GCP Cloud KMS, Transit, HSM)

  • Recovery Keys và Re-keying (operator rekey)

  • Key Rotation và Seal Migration

Bài 5: Tokens, Leases và Renewal

  • Token types: Service tokens, Batch tokens

  • Token hierarchy, Orphan tokens, Token accessors

  • Token roles, Periodic tokens, TTL và Max TTL

  • Lease concept, Lease renewal, Lease revocation

  • Cubbyhole Response Wrapping

Phần 2: Secrets Engines - Quản lý Bí mật

Bài 6: KV Secrets Engine - Static Secrets Management

  • KV v1 vs KV v2 so sánh chi tiết

  • Enable/Configure KV Secrets Engine

  • CRUD operations, versioning, metadata

  • KV v2 version attribution (Vault 1.21)

  • Check-and-set (CAS), soft delete, patch operations

Bài 7: Database Secrets Engine - Dynamic Credentials

  • Database Secrets Engine concept

  • Cấu hình connections: PostgreSQL, MySQL, MongoDB, MSSQL

  • Dynamic roles và Static roles

  • Root credential rotation

  • Tích hợp với ứng dụng thực tế

Bài 8: PKI Secrets Engine - Certificate Authority

  • Tạo Root CA và Intermediate CA

  • Certificate roles, Issue/Sign certificates

  • CRL, OCSP, Auto-rotation, ACME protocol

  • PKI certificate counter (Vault 1.21)

  • Tích hợp với cert-manager, Nginx, mTLS

Bài 9: Transit Secrets Engine - Encryption as a Service

  • Encryption/Decryption operations

  • Key management và rotation

  • Key types, HMAC, Sign/Verify

  • Data key generation, Convergent encryption

  • BYOK và Batch operations

Bài 10: AWS, Azure, GCP và Cloud Secrets Engines

  • AWS Secrets Engine (IAM, STS AssumeRole)

  • Azure Secrets Engine (Static roles trong 1.21)

  • GCP Secrets Engine (Service Account, OAuth2)

  • Multi-cloud secret management best practices

Phần 3: Auth Methods - Xác thực và Ủy quyền

Bài 11: Auth Methods cơ bản - Token, Userpass và AppRole

  • Token Auth Method, Root tokens

  • Userpass Auth Method, Password policies

  • AppRole (RoleID, SecretID, CIDR binding)

  • Response wrapping cho SecretID

  • AppRole cho CI/CD pipelines

Bài 12: LDAP, OIDC và JWT Auth Methods

  • LDAP Auth Method (Active Directory integration)

  • OIDC Auth Method (Keycloak, Azure AD, Okta)

  • JWT Auth Method (GitHub Actions OIDC, GitLab CI)

  • Bound claims, Claim mappings

Bài 13: Kubernetes, AWS và Cloud Auth Methods

  • Kubernetes Auth Method (Service Account token review)

  • AWS Auth Method (IAM, EC2)

  • Azure, GCP Auth Methods

  • SPIFFE Auth Method (mới trong 1.21)

  • Workload identity best practices

Bài 14: Policies - ACL, Sentinel và RBAC

  • HCL policy syntax, Path-based policies

  • Capabilities (create, read, update, delete, list, sudo, deny)

  • Policy templates (identity parameters)

  • Fine-grained control (allowed_parameters, denied_parameters)

  • Sentinel policies (Enterprise) — EGP, RGP

Bài 15: Identity Secrets Engine, Entities và MFA

  • Identity Secrets Engine, Entities và Aliases

  • Internal Groups vs External Groups

  • Identity Tokens (OIDC provider)

  • MFA — TOTP, Duo, Okta, PingID

  • MFA TOTP self-enrollment (Vault 1.21)

Phần 4: Secrets Engines nâng cao

Bài 16: SSH Secrets Engine và TOTP

  • SSH Signed Certificates (CA mode)

  • SSH One-Time Password (OTP mode)

  • Host key signing, allowed users/extensions

  • TOTP Secrets Engine

  • LDAP Secrets Engine (RACF passphrase support 1.21)

Bài 17: Transform và Tokenization - Data Protection

  • Transform Secrets Engine (Enterprise)

  • Format Preserving Encryption (FPE), Masking

  • Tokenization stores (internal, external)

  • PCI DSS compliance, PII protection

  • Transit vs Transform — khi nào dùng cái nào

Bài 18: KMIP, Consul, Nomad Secrets Engines và Custom Plugins

  • KMIP Secrets Engine (Key Management Interoperability Protocol)

  • Consul và Nomad Secrets Engines

  • Vault Plugin System và plugin catalog

  • Developing custom secrets engines/auth methods (Go)

  • Plugin multiplexing và versioned plugins

Phần 5: Vault Agent, Proxy và Kubernetes Integration

Bài 19: Vault Agent và Vault Proxy

  • Vault Agent: Auto-auth, Template rendering, File sink

  • Agent caching, Process supervisor

  • Vault Proxy: API proxy mode, Static secret caching

  • Agent vs Proxy — khi nào dùng cái nào

  • Deployment patterns (systemd, Docker sidecar)

Bài 20: Vault trên Kubernetes - Helm, Operator và CSI

  • Deploy Vault bằng Helm chart (Standalone, HA, External)

  • Vault Secrets Operator (VaultAuth, VaultStaticSecret, VaultDynamicSecret)

  • Vault CSI Provider (SecretProviderClass)

  • Vault Agent Injector (annotations, templates)

  • VSO vs CSI vs Agent Injector comparison

Phần 6: Tích hợp ứng dụng thực tế

Bài 21: Tích hợp Vault với Spring Boot và Node.js

  • Spring Cloud Vault integration

  • Database credential rotation trong Java

  • Node.js với node-vault, Python hvac

  • Application patterns: direct API, sidecar, env vars, CSI

  • Secret zero problem và giải pháp

Bài 22: Vault với Terraform, Ansible và CI/CD Pipelines

  • Terraform Vault Provider (Infrastructure as Code)

  • Ansible Vault lookup plugin

  • GitHub Actions OIDC, GitLab CI JWT auth

  • Jenkins AppRole integration

  • ArgoCD Vault Plugin, External Secrets Operator

Phần 7: Production, Enterprise và Vận hành

Bài 23: High Availability, Integrated Storage và Production Hardening

  • Integrated Storage (Raft) cluster setup

  • Autopilot, Raft snapshots, WAL log store

  • HA: active/standby/performance standby

  • Production hardening: TLS, mlock, systemd, security checklist

Bài 24: Vault Enterprise - Namespaces, Replication và DR

  • Namespaces (multi-tenancy)

  • Performance Replication, Disaster Recovery

  • Sentinel policies (EGP/RGP)

  • Control Groups, Seal Wrap, Entropy Augmentation

  • License management và Enterprise upgrades

Bài 25: Monitoring, Audit Logging, Backup/Restore và Troubleshooting

  • Audit Devices (File, Syslog, Socket)

  • Prometheus metrics, Grafana dashboards

  • OpenTelemetry tracing

  • Raft snapshots, Secret recovery (Vault 1.21)

  • Troubleshooting, vault debug, production runbook

DUY TRAN
Tác giả

DUY TRAN

Pursuing an AI-first mindset and intelligent system architecture. I build solutions by combining technology, creativity, and the ability to see structure in chaos — the foundation for becoming a Solution Architect.

Bình luận