IBM Vault (formerly Hashicorp Vault) is an encryption tool for managing secrets including credentials, passwords and other secrets, providing access control, audit trail, and support for multiple authentication methods. It is available open source, or under an enterprise license.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
Verified User
Consultant in Engineering (5001-10,000 employees employees)
Use Cases and Deployment Scope
We use IBM Vault for keeping secrets and credentials that are used by multiple microservices using the api calls. We also get great access control on the paths for the secrets so only application that require the specific path will be able to access the secrets.
Pros
Secrets management
Access control
Versioning of secrets
Cons
Complexity of setting up Vault should be simplified
DevOps Engineer in Engineering at Kea (51-200 employees employees)
Use Cases and Deployment Scope
We leverage HashiCorp Vault capabilities for storing and managing our secrets and company passwords. HashiCorp Vault integrates with applications and tools to enable transparent secure sensitive information retrieval programmatically. By leveraging HashiCorp Vault we can go with IAC/CAC on almost everything we build. HashiCorp Vault also makes it easy to share secrets between team members and the organization.
Pros
Store secrets
Store configurations
Integrate with kubernetes
Audit log of changes
Team secret sharing
Real time in transit encryption
Cons
Session Management is terrible to manage
Monitoring is hard and not enough information
User management
Configuration is too complex
More user friendly UI
Return on Investment
Vault enabled IAC for kubernetes applications
Central configuration for applications
Version Control on secrets
Improved the company security and secret sharing experience
Enabled the PCI compliance for the company
Alternatives Considered
Bitwarden and AWS Secrets Manager
Other Software Used
Cloudflare, Cloudflare Zero Trust Services, Amazon RDS Performance Insights, Amazon Kinesis, Amazon Simple Queue Service (SQS)
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info