Likelihood to Recommend HashiCorp Vault, in my opinion, is a defacto standard for any cloud or automation implementation. They're the best of the best as far as products for secrets management and the ability to use it against relatively any service you have is unheard of for other products. HashiCorp has really taken out all the stops when it comes to creating a nice, extensible tool that people can use to suit their needs.
Read full review Puppet is good enough to get the job done, you can use it to automate deployments and maintain files and configurations, if this is all you're looking for it's great. If you're looking for more control over your systems as a whole without having to write your own scripts or install multiple configuration management systems then Puppet is not what you're looking for.
Read full review Pros The HTTP API you use to write and read secrets is open and can be used by any application. It keeps our sensitive data/credentials out of our GitLab repositories. Sealing and unsealing the Vault on demand adds an additional layer of security. Read full review Provides a clear map of how a system is configured Eases the creation of a system in a specific cluster as it is scripted in code Simplifies configuration changes to a cluster or to every system such as rolling out vhost configurations, updating ldap roles, NFS mounts, etc The syntax is very easy to read and carries a lot of fluidity once the language is learned. Read full review Cons Documentation could be better. The multiple key unseal process can be a problem if the need arises. It would make more sense if HashiCorp Vault combined with HashiCorp Consul to create a unique product. Read full review The setup of Puppet is a nightmare compared to ansible. Anyone watching a youtube video can easily set up ansible with minimal IT knowledge. All one needs is the source IP addresses and we are good to go. Setting up Puppet is a more hands-on task and pushing the puppet agents to all the boxes is another issue. If the installation and setup were simplified like ansible that would attract a lot of people to this platform The syntax of the code for Puppet is not as easy as ansible. Ansible simply follows a YAML format and it's like typing in normal English. Even complicated tasks can be written by just understanding YAML syntax. Perhaps Puppet needs to revisit the lanugage used and try to come up with a much simpler lanugage for writing code. This will make day-to-day usage easier. Read full review Likelihood to Renew HashiCorp Vault is the best there is out there, and it has become critical to our secret management use cases. It would be difficult to find anything that would suit our needs better and that would be beneficial for us to switch over to.
Read full review Usability We spent a little more time than we imagined to conceptually understand how HashiCorp Vault operates, as well as how it is configured. This is not trivial, and keep in mind that you will need to take some time to get a thorough understanding of the tool. The documentation could be more helpful in this regard.
Read full review Support Rating Hashicorp has been very responsive to our questions and inquiries up to this point. We are currently working on them to develop a more granular permissions model within Vault. We are very close to achieving our objectives with the help of their support team. We do not seem to be in the same time zone which makes it hard for escalated issues.
Read full review Puppet has top class support. You can simply mail them with their query and they will respond to your query in a timely manner. We do have enterprise license for puppet. Also there is a vibrant community for puppet out there. So even if you dont purchase a premium support option you can simply google your queries and get answers
Read full review Alternatives Considered HashiCorp Vault is way better than
Azure Key Vault ; it has more features and it goes beyond a key-value secret store.
Read full review HPSA is a licensed product and incurs significant upfront investment costs due to COTS licensing. Puppet Data Center Automation has a significantly lower upfront investment and product documentation is more readily available. Chef is a very similar offering, however, at the time our decision was considered, the adoption of Chef vs. Puppet was significantly less in the community.
Read full review Return on Investment Helped us reach our security compliance goals. Helped us strengthen our security position in our infrastructure by improving on poor secret management practices. Read full review Cut deployment times down to around 1 hour from 4-5 hours. Allows us to get a fully running system up from scratch in around 30 minutes. Allows for a more clear view of what is required to get a host running. Read full review ScreenShots HashiCorp Vault Screenshots