Phần 1: Nền tảng HashiCorp Vault
Bài 1: Giới thiệu HashiCorp Vault - Secret Management trong Enterprise
HashiCorp Vault là gì? Lịch sử phát triển (từ HashiCorp đến CNCF)
Tại sao cần Secret Management tập trung?
Kiến trúc Vault: Storage Backend, Barrier, Secrets Engines, Auth Methods, Audit Devices
So sánh Vault vs AWS Secrets Manager vs Azure Key Vault vs Google Secret Manager
Các use cases: Static Secrets, Dynamic Credentials, Encryption as a Service, PKI, SSH
Bài 2: Cài đặt Vault - Standalone, Docker và Kubernetes
Cài đặt Vault trên Ubuntu/CentOS (package manager)
Chạy Vault với Docker và Docker Compose
Kubernetes Helm chart deployment
Cấu hình Storage Backend (Integrated Storage, File, Consul)
Dev Server vs Production Mode
Khởi tạo Vault (operator init), Seal/Unseal workflow
Bài 3: Vault CLI, API và Web UI
Vault CLI commands (read, write, list, delete, kv, auth, secrets, policy, operator)
Environment variables (VAULT_ADDR, VAULT_TOKEN, VAULT_NAMESPACE)
Vault HTTP API, cURL examples
SDK clients (Go, Python, Java, Node.js)
Vault Web UI overview và navigation
Bài 4: Seal/Unseal, Auto-unseal và Recovery Keys
Seal/Unseal mechanism và Shamir Secret Sharing
Key Shares, Key Threshold, Master Key
Auto-unseal (AWS KMS, Azure Key Vault, GCP Cloud KMS, Transit, HSM)
Recovery Keys và Re-keying (operator rekey)
Key Rotation và Seal Migration
Bài 5: Tokens, Leases và Renewal
Token types: Service tokens, Batch tokens
Token hierarchy, Orphan tokens, Token accessors
Token roles, Periodic tokens, TTL và Max TTL
Lease concept, Lease renewal, Lease revocation
Cubbyhole Response Wrapping
Phần 2: Secrets Engines - Quản lý Bí mật
Bài 6: KV Secrets Engine - Static Secrets Management
KV v1 vs KV v2 so sánh chi tiết
Enable/Configure KV Secrets Engine
CRUD operations, versioning, metadata
KV v2 version attribution (Vault 1.21)
Check-and-set (CAS), soft delete, patch operations
Bài 7: Database Secrets Engine - Dynamic Credentials
Database Secrets Engine concept
Cấu hình connections: PostgreSQL, MySQL, MongoDB, MSSQL
Dynamic roles và Static roles
Root credential rotation
Tích hợp với ứng dụng thực tế
Bài 8: PKI Secrets Engine - Certificate Authority
Tạo Root CA và Intermediate CA
Certificate roles, Issue/Sign certificates
CRL, OCSP, Auto-rotation, ACME protocol
PKI certificate counter (Vault 1.21)
Tích hợp với cert-manager, Nginx, mTLS
Bài 9: Transit Secrets Engine - Encryption as a Service
Encryption/Decryption operations
Key management và rotation
Key types, HMAC, Sign/Verify
Data key generation, Convergent encryption
BYOK và Batch operations
Bài 10: AWS, Azure, GCP và Cloud Secrets Engines
AWS Secrets Engine (IAM, STS AssumeRole)
Azure Secrets Engine (Static roles trong 1.21)
GCP Secrets Engine (Service Account, OAuth2)
Multi-cloud secret management best practices
Phần 3: Auth Methods - Xác thực và Ủy quyền
Bài 11: Auth Methods cơ bản - Token, Userpass và AppRole
Token Auth Method, Root tokens
Userpass Auth Method, Password policies
AppRole (RoleID, SecretID, CIDR binding)
Response wrapping cho SecretID
AppRole cho CI/CD pipelines
Bài 12: LDAP, OIDC và JWT Auth Methods
LDAP Auth Method (Active Directory integration)
OIDC Auth Method (Keycloak, Azure AD, Okta)
JWT Auth Method (GitHub Actions OIDC, GitLab CI)
Bound claims, Claim mappings
Bài 13: Kubernetes, AWS và Cloud Auth Methods
Kubernetes Auth Method (Service Account token review)
AWS Auth Method (IAM, EC2)
Azure, GCP Auth Methods
SPIFFE Auth Method (mới trong 1.21)
Workload identity best practices
Bài 14: Policies - ACL, Sentinel và RBAC
HCL policy syntax, Path-based policies
Capabilities (create, read, update, delete, list, sudo, deny)
Policy templates (identity parameters)
Fine-grained control (allowed_parameters, denied_parameters)
Sentinel policies (Enterprise) — EGP, RGP
Bài 15: Identity Secrets Engine, Entities và MFA
Identity Secrets Engine, Entities và Aliases
Internal Groups vs External Groups
Identity Tokens (OIDC provider)
MFA — TOTP, Duo, Okta, PingID
MFA TOTP self-enrollment (Vault 1.21)
Phần 4: Secrets Engines nâng cao
Bài 16: SSH Secrets Engine và TOTP
SSH Signed Certificates (CA mode)
SSH One-Time Password (OTP mode)
Host key signing, allowed users/extensions
TOTP Secrets Engine
LDAP Secrets Engine (RACF passphrase support 1.21)
Bài 17: Transform và Tokenization - Data Protection
Transform Secrets Engine (Enterprise)
Format Preserving Encryption (FPE), Masking
Tokenization stores (internal, external)
PCI DSS compliance, PII protection
Transit vs Transform — khi nào dùng cái nào
Bài 18: KMIP, Consul, Nomad Secrets Engines và Custom Plugins
KMIP Secrets Engine (Key Management Interoperability Protocol)
Consul và Nomad Secrets Engines
Vault Plugin System và plugin catalog
Developing custom secrets engines/auth methods (Go)
Plugin multiplexing và versioned plugins
Phần 5: Vault Agent, Proxy và Kubernetes Integration
Bài 19: Vault Agent và Vault Proxy
Vault Agent: Auto-auth, Template rendering, File sink
Agent caching, Process supervisor
Vault Proxy: API proxy mode, Static secret caching
Agent vs Proxy — khi nào dùng cái nào
Deployment patterns (systemd, Docker sidecar)
Bài 20: Vault trên Kubernetes - Helm, Operator và CSI
Deploy Vault bằng Helm chart (Standalone, HA, External)
Vault Secrets Operator (VaultAuth, VaultStaticSecret, VaultDynamicSecret)
Vault CSI Provider (SecretProviderClass)
Vault Agent Injector (annotations, templates)
VSO vs CSI vs Agent Injector comparison
Phần 6: Tích hợp ứng dụng thực tế
Bài 21: Tích hợp Vault với Spring Boot và Node.js
Spring Cloud Vault integration
Database credential rotation trong Java
Node.js với node-vault, Python hvac
Application patterns: direct API, sidecar, env vars, CSI
Secret zero problem và giải pháp
Bài 22: Vault với Terraform, Ansible và CI/CD Pipelines
Terraform Vault Provider (Infrastructure as Code)
Ansible Vault lookup plugin
GitHub Actions OIDC, GitLab CI JWT auth
Jenkins AppRole integration
ArgoCD Vault Plugin, External Secrets Operator
Phần 7: Production, Enterprise và Vận hành
Bài 23: High Availability, Integrated Storage và Production Hardening
Integrated Storage (Raft) cluster setup
Autopilot, Raft snapshots, WAL log store
HA: active/standby/performance standby
Production hardening: TLS, mlock, systemd, security checklist
Bài 24: Vault Enterprise - Namespaces, Replication và DR
Namespaces (multi-tenancy)
Performance Replication, Disaster Recovery
Sentinel policies (EGP/RGP)
Control Groups, Seal Wrap, Entropy Augmentation
License management và Enterprise upgrades
Bài 25: Monitoring, Audit Logging, Backup/Restore và Troubleshooting
Audit Devices (File, Syslog, Socket)
Prometheus metrics, Grafana dashboards
OpenTelemetry tracing
Raft snapshots, Secret recovery (Vault 1.21)
Troubleshooting, vault debug, production runbook
