Skip to content
EduVerse
HashiCorp Vault

HashiCorp Vault

Mentioned

Tool

Also known as: Vault

A central vault for secrets: stores API keys, passwords and certificates securely and hands them out under control.

HashiCorp Vault, explained

Written by EduVerse

What it is

HashiCorp Vault is a tool for storing and handing out secrets: passwords, API keys, certificates and database credentials. Applications log in to Vault, for example with their Kubernetes service account, and only receive the secrets their policy allows. Access can be recorded in an audit log.

Why teams use it

Secrets in Git, in .env files or pasted into chat leak sooner or later. Vault keeps them in one controlled place and can even create short-lived database credentials on request, which expire on their own. Teams fully on one cloud sometimes use that provider’s secret manager instead, such as AWS Secrets Manager or Azure Key Vault.

An example from work

Your service crashes on startup with a 403 permission denied from Vault. Running vault kv get secret/payments with your own token works, so the problem is the policy attached to the service’s Kubernetes role, which doesn’t include that path yet.

Our own explanation, not a quote from the book.

Where it fits

Secrets management in CI/CD and production

Coverage in the book

Mentioned

Mentioned as part of the wider landscape, without in-depth coverage.

Appears in