HashiCorp Vault
By HashiCorp
HashiCorp Vault is a secrets management tool that securely stores, generates, and controls access to credentials, API keys, certificates, and encryption keys, issuing them dynamically to applications and users rather than requiring secrets…
Definition
HashiCorp Vault is a secrets management tool that securely stores, generates, and controls access to credentials, API keys, certificates, and encryption keys, issuing them dynamically to applications and users rather than requiring secrets to be hardcoded or statically distributed. It is designed to work the same way regardless of where an application runs, so a single Vault deployment can serve applications spread across multiple cloud providers and on-premises data centers under one consistent access model.
Overview
Vault centralizes secret storage behind a policy-based access control system, so that instead of embedding a database password or cloud API key directly in application code or configuration files, an application authenticates to Vault and requests the secret it needs at runtime. Access policies define exactly which secrets a given identity can retrieve, and every access is logged, giving security teams an audit trail of who or what accessed a secret and when. A policy attached to an application's identity typically grants access only to the specific secrets that application needs, following the principle that a compromised service should not be able to read every credential in the organization simply because it can reach the secrets store at all. One of Vault's more distinctive capabilities is dynamic secrets: rather than storing a single long-lived credential, Vault can generate a short-lived, unique credential on demand for services like databases or cloud providers, automatically revoking it after a configured time-to-live expires. This significantly reduces the value of a leaked credential, since it is only valid briefly and tied to a specific request rather than a shared secret that persists indefinitely. Vault also provides encryption-as-a-service, letting applications delegate cryptographic operations to Vault without directly handling encryption keys, and supports a pluggable authentication system covering methods such as tokens, cloud IAM roles, Kubernetes service accounts, and LDAP. Dynamic secrets extend this further by having Vault itself create a temporary account on the target system, such as a database, at the moment it is requested, rather than merely retrieving a pre-existing static password that would remain valid indefinitely if ever copied out of Vault. Vault competes with cloud-provider-native secret managers such as AWS Secrets Manager, Azure Key Vault, and Google Secret Manager, as well as with CyberArk in privileged access management contexts. Its main advantage over cloud-native options is being cloud-agnostic, letting an organization run one consistent secrets management layer across multi-cloud or hybrid environments rather than a separate tool per cloud provider; the trade-off is that Vault must be deployed, configured, and operated by the organization itself (or consumed via HashiCorp's managed HCP Vault offering), adding operational responsibility that a fully managed cloud-native service does not carry. Cloud-provider secret stores generally only manage credentials for services within that same cloud, so an organization running infrastructure across more than one provider either runs a separate secrets tool per cloud or adopts something cloud-agnostic like Vault to keep one consistent policy model everywhere. Organizations adopt Vault when operating across multiple clouds or hybrid infrastructure and wanting a single secrets management standard, or when dynamic, short-lived credentials are a security requirement that static cloud-native secret stores do not natively provide. Smaller, single-cloud-native shops sometimes find their cloud provider's built-in secrets manager sufficient without taking on Vault's additional operational overhead. Common deployment patterns include injecting secrets into a container at startup through a sidecar process, or having an application call Vault's API directly at runtime, both of which avoid ever writing the secret to disk in plaintext as part of a configuration file. Running Vault well requires attention to its own operational concerns, such as how its storage backend is unsealed after a restart and how its own high-availability cluster is kept resilient, which is real ongoing work that a fully managed cloud-native secret store does not impose on its users.
Key Features
- Centralized, policy-based storage and access control for secrets
- Dynamic secrets generation with automatic, short-lived expiration
- Detailed audit logging of every secret access request
- Encryption-as-a-service for delegating cryptographic operations
- Pluggable authentication supporting tokens, cloud IAM, and Kubernetes
- Cloud-agnostic design usable across multi-cloud and hybrid environments
- Open-source core with a managed HCP Vault cloud offering
- Integrates with CI/CD and infrastructure-as-code tooling