HashiCorp Vault
MentionedTool
Also known as: Vault
A central vault for secrets: stores API keys, passwords and certificates securely and hands them out under control.
HashiCorp Vault, explained
Written by EduVerseWhat it is
HashiCorp Vault is a tool for storing and handing out secrets: passwords, API keys, certificates and database credentials. Applications log in to Vault, for example with their Kubernetes service account, and only receive the secrets their policy allows. Access can be recorded in an audit log.
Why teams use it
Secrets in Git, in .env files or pasted into chat leak sooner or later. Vault keeps them in one controlled place and can even create short-lived database credentials on request, which expire on their own. Teams fully on one cloud sometimes use that provider’s secret manager instead, such as AWS Secrets Manager or Azure Key Vault.
An example from work
Your service crashes on startup with a 403 permission denied from Vault. Running vault kv get secret/payments with your own token works, so the problem is the policy attached to the service’s Kubernetes role, which doesn’t include that path yet.
Our own explanation, not a quote from the book.
Where it fits
Secrets management in CI/CD and production
Coverage in the book
Mentioned as part of the wider landscape, without in-depth coverage.