Building Scalable Enterprise Secrets Management with GitHub OIDC and HashiCorp Vault

  Рет қаралды 997

HashiCorp

HashiCorp

Жыл бұрын

Software build pipelines are increasingly a vector for abuse, and storing long-lived credentials in solutions like GitHub Secrets adds risk and logistical challenges. GitHub OIDC authentication to Vault solves this by allowing teams to generate short-lived, dynamic tokens scoped to very fine-grained authorization grants.
It is one thing to configure a single repository and quite another to construct a program scaling to hundreds or thousands of repositories and developers. In this talk, you will learn how to leverage an OIDC configuration with Vault as a building block to design (or upgrade!) a paved path enterprise-scale secrets management program. This developer-first approach provides stronger security guarantees than traditional “secret zero” mitigations while enabling smoother adoption for developers and simpler management and auditability for operators.
Speaker: Ari Kalfus
Twitter: / artis3n
Self-service demo and workshop to learn how to configure GitHub OIDC and Vault: github.com/artis3n/course-vau...
DigitalOcean blog post with more details about how they configure GitHub OIDC with Vault: www.digitalocean.com/blog/fin...
Open sourced Terraform module: github.com/digitalocean/terra...
Ned Bellavance's HashiConf Global 2022 talk on Using OIDC With HashiCorp Vault and GitHub Actions: www.hashicorp.com/resources/u...
Subscribe to our KZbin Channel → kzbin.info?s...
For hands-on interactive labs, visit HashiCorp Developer → developer.hashicorp.com/
HashiCorp provides infrastructure automation software for multi-cloud environments, enabling enterprises to unlock a common cloud operating model to provision, secure, connect, and run any application on any infrastructure. HashiCorp open source tools Vagrant, Packer, Terraform, Vault, Consul, Nomad, Boundary, and Waypoint allow organizations to deliver applications faster by helping enterprises transition from manual processes and ITIL practices to self-service automation and DevOps practices.
For more information → hashicorp.com
Twitter → / hashicorp
LinkedIn → / hashicorp
Facebook → / hashicorp

Пікірлер: 1
@DavidLukac-si5yg
@DavidLukac-si5yg Жыл бұрын
Thanks Ari! Amazing talk, packed with lots of great information and best practices for the security and convenience at the same time, my fingers were burning from all the notes I was making! :-D
Writing Your First Waypoint Deploy Plugin
26:20
HashiCorp
Рет қаралды 201
Using OIDC With HashiCorp Vault and GitHub Actions
38:19
HashiCorp
Рет қаралды 4,8 М.
Они так быстро убрались!
01:00
Аришнев
Рет қаралды 2,4 МЛН
Опасность фирменной зарядки Apple
00:57
SuperCrastan
Рет қаралды 12 МЛН
GitHub Actions Certification - Full Course to PASS the Exam
3:09:59
freeCodeCamp.org
Рет қаралды 73 М.
Vault and Secret Management in Kubernetes [I] - Armon Dadgar, HashiCorp
30:44
CNCF [Cloud Native Computing Foundation]
Рет қаралды 34 М.
GitOps Secrets Management with Argo CD
41:37
Akuity
Рет қаралды 10 М.
Working with GitHub Apps instead of a PAT
20:21
Rob Bos
Рет қаралды 8 М.
How To Setup Hashicorp Vault: Creating And Accessing Secrets
20:44
bitsized tech
Рет қаралды 12 М.
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,7 МЛН
Easier Vault Management with Vault’s Identity System
34:47
HashiCorp
Рет қаралды 3 М.
Sync secrets seamlessly from Vault effortlessly
18:26
HashiCorp
Рет қаралды 521
GitHub Azure AD OIDC Authentication
22:13
John Savill's Technical Training
Рет қаралды 12 М.
#samsung #retrophone #nostalgia #x100
0:14
mobijunk
Рет қаралды 14 МЛН
Todos os modelos de smartphone
0:20
Spider Slack
Рет қаралды 66 МЛН
Rate This Smartphone Cooler Set-up ⭐
0:10
Shakeuptech
Рет қаралды 7 МЛН
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 1,1 МЛН