#vault (2020-09)
Discussions related to Hashicorp Vault
2020-09-07
data:image/s3,"s3://crabby-images/87453/87453e25998d813f63b1e91632ef9ed60389ece2" alt="Ed avatar"
Has anyone tried using vault-k8s? It seems like an interesting Kubernetes-native way to inject secrets into pods, and access via the file system
data:image/s3,"s3://crabby-images/87453/87453e25998d813f63b1e91632ef9ed60389ece2" alt="Ed avatar"
First-class support for Vault and Kubernetes. Contribute to hashicorp/vault-k8s development by creating an account on GitHub.
data:image/s3,"s3://crabby-images/87453/87453e25998d813f63b1e91632ef9ed60389ece2" alt="Ed avatar"
Good demo:
data:image/s3,"s3://crabby-images/87453/87453e25998d813f63b1e91632ef9ed60389ece2" alt="Ed avatar"
Watch this from-the-ground-up demo illustrating how to use HashiCorp Vault’s newest method for managing secrets in a Kubernetes environment.
data:image/s3,"s3://crabby-images/87453/87453e25998d813f63b1e91632ef9ed60389ece2" alt="Ed avatar"
The one thing that seems somewhat strange is the sidecar that injects secrets gets grouped in with the total number of running pods, which could be confusing - how many actual pods do I have running and how many are sidecars?
data:image/s3,"s3://crabby-images/87453/87453e25998d813f63b1e91632ef9ed60389ece2" alt="Ed avatar"
I’d be interested to hear if anybody has experience running vault-k8s in production?
2020-09-09
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Haven’t tried it yet, and while it’s an arguably more secure implementation using the sidecars, the kubernetes-external-secrets
manager appeals more to me since it’s just populating kubernetes secrets originating from vault.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Integrate external secret management systems with Kubernetes - godaddy/kubernetes-external-secrets
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
it gets pretty annoying when you have one sidecar for your mesh, one for your secrets management, one for your forensics (twistlock), one for your logging, etc…
2020-09-29
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
Gang, anyone here providing vault as a platform in a larger organization?
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
Firstly, they released some cool tf modules for deploying Vault (along with Consul and others) into AWS using their best practices (https://www.hashicorp.com/blog/announcing-new-hashicorp-terraform-modules-for-consul-nomad-and-vault). That’s pretty cool
data:image/s3,"s3://crabby-images/3a075/3a07583b8729a91a3ce2c39e8440f195f924e759" alt="attachment image"
New starter modules are available for Nomad, Consul, and Vault in AWS.