Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
Secrets management with Vault
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Boris Quiroz
December 20, 2017
Technology
73
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Secrets management with Vault
https://www.meetup.com/Santiago-HashiCorp-User-Group/events/245738064/
Boris Quiroz
December 20, 2017
More Decks by Boris Quiroz
See All by Boris Quiroz
Docker Images Best Practices
boris
0
68
Software Freedom Day 2015
boris
0
52
Code Driven Infrastructure
boris
0
77
hola mundo
boris
0
69
DevOps Tools: Chef + Vagrant
boris
0
240
Kitchen.CI
boris
0
120
Introducción a HSTS
boris
0
64
Hands-on Lab
boris
0
86
Tech, Method & Philosophy for the cloud
boris
0
65
Other Decks in Technology
See All in Technology
AWS FinOps Agent 結局何が得意なの?
siromi
0
220
企業の現実世界をグラフで写し取る
sansantech
PRO
0
200
認知負荷を吸収し、プロダクトをまたぐPR Preview基盤の設計事例
taiki45
2
540
なぜ「決定性」が 決定的に重要なのか? Durable Execution 基盤の数理的理解 #serverlessjp / ServerlessDays Tokyo 2026
ytaka23
4
1.4k
「大丈夫そう?」をObservabilityで確かめる
mrmtsu
0
230
AWS App Runnerから Cloudflare Workersへ移行した話
ryota09
0
110
AIに書かせて、プラットフォームで縛る ― EKSプラットフォームで実践した責任境界と権限設計
elmodev09
1
1k
AgentCore Runtime上にAgentic Coding基盤を構築・展開する際の設計ポイントと限界点 / Design considerations and limitations when building an agentic coding platform on AgentCore Runtime
har1101
7
830
MCPゲートウェイを作って運用してわかったこと — Agent時代の権限管理の現在地
mtpooh
4
400
AIに会社の文脈を理解させる技術~上流工程・非エンジニアにも広げるハーネスエンジニアリング実践~
ochtum
0
190
DORA_Metrics.pdf
wagnerfusca
1
130
GitHub Agentic Workflows を触ってみる
htkym
2
870
Featured
See All Featured
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
360
31k
Build your cross-platform service in a week with App Engine
jlugia
234
19k
Collaborative Software Design: How to facilitate domain modelling decisions
baasie
1
330
Typedesign – Prime Four
hannesfritz
42
3.2k
<Decoding/> the Language of Devs - We Love SEO 2024
nikkihalliwell
1
330
Refactoring Trust on Your Teams (GOTO; Chicago 2020)
rmw
35
3.8k
Chrome DevTools: State of the Union 2024 - Debugging React & Beyond
addyosmani
10
1.4k
Bootstrapping a Software Product
garrettdimon
PRO
306
120k
Amusing Abliteration
ianozsvald
1
320
Data-driven link building: lessons from a $708K investment (BrightonSEO talk)
szymonslowik
1
1.3k
Reality Check: Gamification 10 Years Later
codingconduct
0
2.3k
Fantastic passwords and where to find them - at NoRuKo
philnash
52
3.9k
Transcript
Vault Boris Quiroz Q. -
[email protected]
- github.com/boris
¿Qué es Vault?
Una herramienta para acceder a secretos de forma segura.
• Almacenamiento seguro • Secretos dinámicos • Encriptación de data
• Leasing and Renewal • Revocación
Conceptos
• Seal/Unseal • Tokens • Policy • Secret Backend
Políticas
Proporcionan una manera declarativa de delegar acceso a ciertas rutas
y operaciones en Vault.
path “secret/*” { capabilities = [ “write”, “list” ] }
path “secret/very-secret/*” { capabilities = [ “deny” ] }
path “secret/not-secret/*” { capabilities = [ “create”, “delete”, “list”, “read”,
“update” ] }
AWS
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "iam:*",
"Resource": "*" } ] }
Demo https://git.io/scl-vault-meetup