HashiCorp Vault Security
completeA deep dive into securing HashiCorp Vault deployments — from audit logging and root token management to policy governance and compliance hardening.

HashiCorp Vault is the industry-standard solution for secrets management, but securing Vault itself is often overlooked. This project covers the operational security practices I’ve explored — from establishing a solid audit logging foundation to detecting suspicious root token activity and enforcing policy governance at scale.
Posts in this project
Vault Audit Logging
February 1, 2018
Detecting HashiCorp Vault Root Login
February 9, 2020
Detecting HashiCorp Vault Root Token Generation
May 20, 2020
Detecting HashiCorp Vault Policy Changes
July 13, 2022
Identifying Active HashiCorp Vault Root Tokens
Revoking the root token on a production HashiCorp Vault deployment is one of the recommended best practices for securing an instance of Hash
May 25, 2020
HashiCorp Vault Policy Metrics
I gave a talk for HashiCorp's HashiDays event earlier this year that centered around operational intelligence for HashiCorp Vault. The focus
June 4, 2019
HashiCorp Vault Unique AppRole Identity Logging
HashiCorp Vault supports several authentication methods for human and non-human access. Several of the non-human authentication methods are
December 1, 2021
Vault Hardening Compliance using Chef InSpec
August 7, 2018