Learn How to Run Vault on Kubernetes
Kubernetes users can now bring Vault into their Kubernetes environment using the Vault Helm chart to manage secrets. The Vault Helm chart provides core Vault deployments in Kubernetes and enables you to express the secrets required by your applications in a declarative way.
» Get Started With Hands-On Tutorials
The following guides on HashiCorp Learn demonstrate operating Vault in a variety of modes within Kubernetes:
-
Vault Installation on Minikube via Helm starts a highly-available (HA) Vault cluster with a Consul storage backend and Vault's Kubernetes authentication, and then launches a sample application that directly requests secrets through Vault API calls.
-
Injecting Secrets into Kubernetes Pods via Vault Helm Sidecar starts Vault in standalone mode and deploys several applications that define their secrets through the declarative annotations interface.
-
Mount Vault Secrets through Container Storage Interface Volume starts Vault in development mode and deploys an application that mounts an ephemeral volume that declaratively defines secrets.
-
Integrate a Kubernetes Cluster with an External Vault starts a Vault server external to the cluster and deploys applications that address it directly, address it through a service, and then leverage the declarative power of annotations.
These guides focus on the concepts while eschewing larger security concerns to increase the time-to-value in a learning environment. But when it comes time to take Vault to production these reference guides describe how to do it securely and competently:
Sign up for the latest HashiCorp news
More blog posts like this one
HCP Vault Dedicated adds secrets sync, cross-region DR, EST PKI, and more
The newest HCP Vault Dedicated 1.18 upgrade includes a range of new features that include expanding DR region coverage, syncing secrets across providers, and adding PKI EST among other key features.
Fix the developers vs. security conflict by shifting further left
Resolve the friction between dev and security teams with platform-led workflows that make cloud security seamless and scalable.
HashiCorp at AWS re:Invent: Your blueprint to cloud success
If you’re attending AWS re:Invent in Las Vegas, Dec. 2 - Dec. 6th, visit us for breakout sessions, expert talks, and product demos to learn how to take a unified approach to Infrastructure and Security Lifecycle Management.