HashiCorp Vault Tutorial: How to Get Started With Vault | Rafay
HashiCorp Vault Tutorial: Getting Started With Vault
Every business needs to pay special attention to security matters. Secrets management is one of the leading security tasks. In this tutorial, we will introduce you to the basics of using the Hashicorp Vault, a powerful tool for securing accessing secrets.
Vault Overview
Purpose
What are the secrets that we mentioned above? It may be API and database credentials, passwords, certificates, SSH keys, etc. Vault is used to provide the secure storing of secrets and control the access to the secrets. The tool allows flexible setup and various security conditions manipulation. The main benefit of using Vault is to manage secrets securely in a central location which prevents secret sprawl. A secondary benefit is for Governance that includes policies, audit logs, trails etc.
Features
There are several Vault’s features that make it so popular, including:
- Client Access Interfaces: Vault’s capabilities are accessible programmatically by other services and applications due to the HTTP API. In addition, there are several officially supported libraries for programming languages (Go and Ruby at the time of this writing) and a range of community-supported packages for many languages (Python, PHP, Java, C#, NodeJS, etc.). These libraries make the interaction with the Vault’s API even more convenient. Vault also has a command-line interface (CLI).
- High Availability: Vault has embedded mechanisms that make it resilient from failures. An important role here is replication technology. It is possible to create a Vault cluster using several machines.
- High Throughput: Due to the replication technology, Vault is very scalable and can provide high throughput rates to meet most needs.
- Data Encryption: Vault is capable of encrypting/decrypting data without storing it. The main implication from this is if an intrusion occurs, the hacker will not have access to real secrets even if the attack is successful.
- Dynamic Secrets: This means that the secret doesn’t exist until it is read. The primary purpose of this feature is increased security. The logic is as follows. The less time the secret lives, the less risk of the secret stealing.
- Temporary Secrets & Revocation: Vault can store secrets for a defined period, called a lease. When this period expires, the secrets are automatically revoked.
- Logging: Vault keeps a history of interacting with it and its secrets.
- Convenient Authentication: Vault supports authentication using tokens, which is convenient and secure.
- Customization: It is possible to connect various plugins to Vault in order to extend its functionality.
- Web UI: Vault has a web-based graphical user interface, which you can use to interact with the system.
First Steps in Vault
Installation
It is possible to compile Vault from source. Nevertheless, the standard installation path is as follows:
- Download the package for your system.
- Unzip the package. The main part of the unzipped catalog is the vault binary. All other files can be removed safely.
- For Ubuntu, the final step is to move the vault binary into /usr/local/bin/ directory.
- Verify the installation. Open the new CLI window and type the vault command there. You should see the output similar to this:
- Also, you can check the version of the Vault installed by using the vault --version command.
Server starting
To use Vault, you should start the server. There are two types of servers: development and production. It is easier to start the development server.
- From the CLI issue the command:
- Don’t close the current CLI window.
- Open the new CLI window.
- Set the environment variable VAULT_ADDR:
- Set the environment variable VAULT_DEV_ROOT_TOKEN_ID:
- Save the Unseal Key value.
- Check the server running. To do this, issue the command in the CLI.
Basic Work with Secrets
There are several methods to manage secrets in Vault. It has HTTP API to interact with the system programmatically. Also, it has a web-based GUI. The third major option is to use a command-line interface. In this chapter, we are going to show how to create, view, and delete secrets with the help of CLI.
To create a secret, use the vault kv put command, specifying the path and key/value pair of the secret. For example:
vault kv put secret/test_secret test_secret_key=test_secret_value
To view the stored secret, use the vault kv get command. Here’s how:
vault kv get secret/test_secret
To delete the existing secret manually, use:
vault kv delete secret/test_secret
Vault Web UI Overview
To access Vault web UI, you should start the server first. After starting the server, you will see the URL to the web UI in the output. Use the root token to authenticate to the UI.
Conclusion
In this tutorial, we had a quick look at Vault. It is a modern system for managing secrets (passwords, credentials, keys, etc.). We have looked at the motivation for using Vault and its core features. Then, we described how to install it and set up a development server. After having the server running, we demonstrated basic operations with secrets in Vault: creation, getting, and deletion of the secret. We have used the command-line interface for this. At the same time, we made an overview of the Vault’s web-based user interface.