SlideShare a Scribd company logo
CREDENTIAL STORECREDENTIAL STORE
MAYANK PATELMAYANK PATEL
APPLICATION ARCHITECT @APPLICATION ARCHITECT @
/ /
OILDEXOILDEX
Linkedin @maxy_ermayank Medium
SOFTWARE AS A SERVICE PROVIDER FOR OIL ANDSOFTWARE AS A SERVICE PROVIDER FOR OIL AND
GAS COMPANIESGAS COMPANIES
7.5 Years
OILDEXOILDEX
FOCUSED ONFOCUSED ON
Streaming, Reactive, Non-blocking Architecture
API Design
DevOps
Cloud Native Architecture
Empowering so ware development teams
Digital Transformation and Digital Optimization
AGENDAAGENDA
Common Challenges
Vault Use Cases & Features
Demo
Common Challenges / Problems we are trying to
solve?
Credentials stored & transmitted in Plaintext format
Credentials almost never get renewed once it is issued
or manual renewal
No PKI Certificate Management
API Keys are hand generated and never renewed
No SSH Key storage
No Audit Control
No Kill Switch
Lack of automation for secrets deployment
MANY MORE...
How do we manage credentials in Cloud Native,
Distributed Infrastructure ?
Credential store using HashiCorp Vault
VAULT USE CASESVAULT USE CASES
Secure Credential Management on a Budget
VAULT FEATURESVAULT FEATURES
Secure Secret Storage
Dynamic Secrets (Secret as a Service)
Data Encryption
Leasing and Renewal (Key Rotation)
Revocation
Audit Control
Integration with wide variety of Databases and Tools
Custom Plugin
SECURE SECRET STORAGESECURE SECRET STORAGE
Basic Credentials
Tokens, TOTP
PKI Certificate Management (It’s easy to be your own
certificate authority)
LDAP
SSH Keys
Handle SSH logins across the org.
One time SSH access
It increases the usefulness of audit logs during
incident response
...
DYNAMIC SECRETSDYNAMIC SECRETS
AWS Cassandra Consul Hana
MariaDB MongoDB MSSQL MySQL
Oracle PKI Certificates PostgreSQL
RabbitMQ SSH Transit Custom..
WHY DYNAMIC SECRETS?WHY DYNAMIC SECRETS?
Dynamic passwords provide a bunch of benefits
No need to write down, store, or share passwords
Enables very short lived passwords, less exposure if
compromised
For distributed applications, every instance gets
unique credentials
Constantly changing and expiring
usernames/passwords are much harder to brute force
Automatic password rotation/expiration
Better audit trail
HTTP API/CLI
Integration
consul-template
Envconsul
Native Client Libraries
Integration with Ansible, Chef, Puppet, Salt, etc.
HashiCorp Vault Jenkins plugin
Credential store using HashiCorp Vault
RESOURCESRESOURCES
Vault-Consul Docker Swarm Cluster
Denver HashiCorp User Group Talk - Credential
Store using Vault
awesome-vault-tools
Vault Demo Console
THANK YOU!THANK YOU!
QUESTIONS?QUESTIONS?
You can contact me at:
/ /Linkedin @maxy_ermayank Medium

More Related Content

What's hot (20)

PPTX
Vault - Secret and Key Management
Anthony Ikeda
 
PDF
Chickens & Eggs: Managing secrets in AWS with Hashicorp Vault
Jeff Horwitz
 
PDF
Overview of secret management solutions and architecture
Yuechuan (Mike) Chen
 
PDF
Adopting HashiCorp Vault
Nicolas Corrarello
 
PPTX
Secret Management with Hashicorp Vault and Consul on Kubernetes
An Nguyen
 
PDF
Demystifying Initial Access in Azure
Gabriel Mathenge
 
PDF
Securing Kubernetes Applications with HashiCorp Vault
DevOps.com
 
PDF
HashiCorp Vault Workshop:幫 Credentials 找個窩
smalltown
 
PDF
Eliminating Secret Sprawl in the Cloud with HashiCorp Vault - 07.11.2018
HashiCorp
 
PDF
Neil Saunders (Beamly) - Securing your AWS Infrastructure with Hashicorp Vault
Outlyer
 
PPTX
Integrating your on-premises Active Directory with Azure and Office 365
nelmedia
 
PDF
Keycloak SSO basics
Juan Vicente Herrera Ruiz de Alejo
 
PDF
Windows attacks - AT is the new black
Chris Gates
 
PPTX
Azure key vault
Rahul Nath
 
PDF
OAuth & OpenID Connect Deep Dive
Nordic APIs
 
PPTX
Microsoft Security Development Lifecycle
Razi Rais
 
PPT
OAuth 2.0 and OpenId Connect
Saran Doraiswamy
 
PDF
Spring security oauth2
axykim00
 
PPTX
OpenId Connect Protocol
Michael Furman
 
Vault - Secret and Key Management
Anthony Ikeda
 
Chickens & Eggs: Managing secrets in AWS with Hashicorp Vault
Jeff Horwitz
 
Overview of secret management solutions and architecture
Yuechuan (Mike) Chen
 
Adopting HashiCorp Vault
Nicolas Corrarello
 
Secret Management with Hashicorp Vault and Consul on Kubernetes
An Nguyen
 
Demystifying Initial Access in Azure
Gabriel Mathenge
 
Securing Kubernetes Applications with HashiCorp Vault
DevOps.com
 
HashiCorp Vault Workshop:幫 Credentials 找個窩
smalltown
 
Eliminating Secret Sprawl in the Cloud with HashiCorp Vault - 07.11.2018
HashiCorp
 
Neil Saunders (Beamly) - Securing your AWS Infrastructure with Hashicorp Vault
Outlyer
 
Integrating your on-premises Active Directory with Azure and Office 365
nelmedia
 
Windows attacks - AT is the new black
Chris Gates
 
Azure key vault
Rahul Nath
 
OAuth & OpenID Connect Deep Dive
Nordic APIs
 
Microsoft Security Development Lifecycle
Razi Rais
 
OAuth 2.0 and OpenId Connect
Saran Doraiswamy
 
Spring security oauth2
axykim00
 
OpenId Connect Protocol
Michael Furman
 

Similar to Credential store using HashiCorp Vault (20)

PDF
20180111 we bde-bs - serverless url shortener
Luca Bianchi
 
PPTX
How to implement DevSecOps on AWS for startups
Aleksandr Maklakov
 
PDF
Keepler | Full-Stack Serverless Applications on GCP
Keepler Data Tech
 
PPTX
Introduction to basic governance in Azure - #GABDK
Peter Selch Dahl
 
PDF
ServerlessConf Tokyo キーノート
Amazon Web Services Japan
 
PDF
20141021 AWS Cloud Taekwon - Startup Best Practices on AWS
Amazon Web Services Korea
 
PPTX
Apigee Product Roadmap Part 2
Apigee | Google Cloud
 
PPTX
Introduction to the WSO2 Identity Server &Contributing to an OS Project
Michael J Geiser
 
PPT
AWS & Infrastructure Hardening - Cloud Infrastructure Security
Nutanix Beam
 
PPTX
Scaling Security in the Cloud With Open Source
CloudVillage
 
PDF
Pragmatic Security Automation for Cloud
Priyanka Aash
 
PDF
Kaleido Platform Overview and Full-stack Blockchain Services
Peter Broadhurst
 
PPTX
Authentication - Alberto Bellotti - ManageIQ Design Summit 2016
ManageIQ
 
PPTX
Secure your Config with Key Vault for Node.JS
Lakshman S
 
PPTX
Connect your datacenter to Microsoft Azure
K.Mohamed Faizal
 
PPTX
Azure Community Tour 2019 - AZUGDK
Peter Selch Dahl
 
PPTX
Azure app service to create web and mobile apps
Ken Cenerelli
 
PPT
Megha_Osi my sql productroadmap
OpenSourceIndia
 
PDF
Eyes Wide Shut: What Do Your Passwords Do When No One is Watching?
BeyondTrust
 
PDF
Red hat ansible automation technical deck
Juraj Hantak
 
20180111 we bde-bs - serverless url shortener
Luca Bianchi
 
How to implement DevSecOps on AWS for startups
Aleksandr Maklakov
 
Keepler | Full-Stack Serverless Applications on GCP
Keepler Data Tech
 
Introduction to basic governance in Azure - #GABDK
Peter Selch Dahl
 
ServerlessConf Tokyo キーノート
Amazon Web Services Japan
 
20141021 AWS Cloud Taekwon - Startup Best Practices on AWS
Amazon Web Services Korea
 
Apigee Product Roadmap Part 2
Apigee | Google Cloud
 
Introduction to the WSO2 Identity Server &Contributing to an OS Project
Michael J Geiser
 
AWS & Infrastructure Hardening - Cloud Infrastructure Security
Nutanix Beam
 
Scaling Security in the Cloud With Open Source
CloudVillage
 
Pragmatic Security Automation for Cloud
Priyanka Aash
 
Kaleido Platform Overview and Full-stack Blockchain Services
Peter Broadhurst
 
Authentication - Alberto Bellotti - ManageIQ Design Summit 2016
ManageIQ
 
Secure your Config with Key Vault for Node.JS
Lakshman S
 
Connect your datacenter to Microsoft Azure
K.Mohamed Faizal
 
Azure Community Tour 2019 - AZUGDK
Peter Selch Dahl
 
Azure app service to create web and mobile apps
Ken Cenerelli
 
Megha_Osi my sql productroadmap
OpenSourceIndia
 
Eyes Wide Shut: What Do Your Passwords Do When No One is Watching?
BeyondTrust
 
Red hat ansible automation technical deck
Juraj Hantak
 
Ad

More from Mayank Patel (9)

PDF
CI/CD Pipeline as a Code using Jenkins 2
Mayank Patel
 
PDF
Amazon Web Services EC2 Container Service (ECS)
Mayank Patel
 
PDF
Json web token
Mayank Patel
 
PDF
Docker
Mayank Patel
 
PDF
Git
Mayank Patel
 
PDF
Java 9 and Beyond
Mayank Patel
 
PDF
Quality culture
Mayank Patel
 
PDF
Workflow automation for Front-end web applications
Mayank Patel
 
PDF
Scala days 2016 overview
Mayank Patel
 
CI/CD Pipeline as a Code using Jenkins 2
Mayank Patel
 
Amazon Web Services EC2 Container Service (ECS)
Mayank Patel
 
Json web token
Mayank Patel
 
Docker
Mayank Patel
 
Java 9 and Beyond
Mayank Patel
 
Quality culture
Mayank Patel
 
Workflow automation for Front-end web applications
Mayank Patel
 
Scala days 2016 overview
Mayank Patel
 
Ad

Recently uploaded (20)

PPTX
AI Penetration Testing Essentials: A Cybersecurity Guide for 2025
defencerabbit Team
 
PDF
HCIP-Data Center Facility Deployment V2.0 Training Material (Without Remarks ...
mcastillo49
 
PDF
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
PDF
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
PDF
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
PPTX
UiPath Academic Alliance Educator Panels: Session 2 - Business Analyst Content
DianaGray10
 
PDF
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
PDF
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
PDF
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
PDF
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PPTX
Webinar: Introduction to LF Energy EVerest
DanBrown980551
 
PDF
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
PPTX
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
PDF
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
Using FME to Develop Self-Service CAD Applications for a Major UK Police Force
Safe Software
 
AI Penetration Testing Essentials: A Cybersecurity Guide for 2025
defencerabbit Team
 
HCIP-Data Center Facility Deployment V2.0 Training Material (Without Remarks ...
mcastillo49
 
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
UiPath Academic Alliance Educator Panels: Session 2 - Business Analyst Content
DianaGray10
 
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
Webinar: Introduction to LF Energy EVerest
DanBrown980551
 
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
Using FME to Develop Self-Service CAD Applications for a Major UK Police Force
Safe Software
 

Credential store using HashiCorp Vault