HashiCorp Vault - Dynamic Database Credentials

  Рет қаралды 3,979

Bryan Krausen

Bryan Krausen

Күн бұрын

Пікірлер: 17
@JohnLovell-FTW
@JohnLovell-FTW Жыл бұрын
Thank you for this video! Clear and concise.
@btkrausen
@btkrausen Жыл бұрын
Glad you enjoyed it!
@RafaelDurelli
@RafaelDurelli 6 ай бұрын
Given this example, how can I get the secret inside a POD using external secret operator? Could u please provide a video about it? Thanks in advance.
@Kk-rl7nv
@Kk-rl7nv 10 ай бұрын
Thanks for the video very good video, can you suggest on below Can we use the same scenario for production applications which required RDS database if yes then after or before expiring the credential whether application will retrieve new credentials to keep a continue connectivity with database without any downtime ?
@MrNoartik
@MrNoartik Жыл бұрын
Thanks for the explanation!
@btkrausen
@btkrausen Жыл бұрын
Glad it was helpful!
@eliekhattar
@eliekhattar 5 ай бұрын
Quick question, looking at the config that you wrote for HC , the username and password giving in the config, are superusers on postgresql or what is the role of this user?
@VinceBaileydns-direct
@VinceBaileydns-direct 16 күн бұрын
Thank you for another great video again. I see that you have courses on Udemy and i am going to purchase those vault training courses this week. I have one question for you in Lou of booking the training courses i have just started a new role which have a 5 node vault server cluster in aws as ec2 instances. I have been asked if we can have a vault agent? Does the vault agent need to be a separate ec2 instances in aws or can it be run on one of the vault server nodes in the cluster? Many thanks for your help i am just going to book your courses now on Udemy
@btkrausen
@btkrausen 16 күн бұрын
The Vault Agent generally runs alongside of an application to facilitate the communication between the app and the Vault cluster without having to modify the application itself. The Agent can auth to Vault and, for example, grab a secret from Vault and write it locally for the app to read. Or it can set an environment variable using that secret. It's pretty flexible.
@VinceBaileydns-direct
@VinceBaileydns-direct 15 күн бұрын
@@btkrausen just booked on to your hashicorp vault training course association and professional cert courses
@VijayaragavanS
@VijayaragavanS Жыл бұрын
This is really useful! thanks a lot! keep it up!
@btkrausen
@btkrausen Жыл бұрын
Glad it was helpful!
@AdrianHernandez-m5g
@AdrianHernandez-m5g Жыл бұрын
We normally use a parent token to issue this creds under and authenticated backend. My lease period for that parent token is lower than the one that I was using for the actual creds store. The problem that I'm facing as you can imagine is that this token get revoked before the actual lease period expired and I'm using the lease period of the child token to renew the db creds. What do you suggest to address this so common use case? It will be k8s authentication (short lived token) -> database/creds/role (longer ttl)
@venkatasubbareddyn17
@venkatasubbareddyn17 Жыл бұрын
at 4:41, i have created a vault instance in aws, and also created RDS databse (postgresql ) in aws, i followed same steps but unfortunately unable to connect to the databse. Cuuld you please let me know how to enable to ports to connect vault to AWS RDS (postgresql), created the both vault and AWS RDS instances in same regions only.
@btkrausen
@btkrausen Жыл бұрын
RDS should have the default PostgreSQL ports available. Make sure your security groups permit the connectivity and routing is configured between Vault and RDS.
@VijayaragavanS
@VijayaragavanS Жыл бұрын
This is really useful! thanks a lot! keep it up!
@btkrausen
@btkrausen Жыл бұрын
You're welcome!
Beyond secrets, using Vault to automate PKI
30:59
HashiCorp
Рет қаралды 6 М.
Basic secret injection for microservices on Kubernetes using Vault
16:52
VIP ACCESS
00:47
Natan por Aí
Рет қаралды 30 МЛН
Мен атып көрмегенмін ! | Qalam | 5 серия
25:41
黑天使只对C罗有感觉#short #angel #clown
00:39
Super Beauty team
Рет қаралды 36 МЛН
Spring Tips: Easy Password Rotation with Hashicorp Vault
26:32
SpringDeveloper
Рет қаралды 4,8 М.
Create Dynamic Database Credentials with Vault Secrets Operator
10:13
Getting started with HashiCorp Vault
18:34
Tobi's Developer Corner
Рет қаралды 28 М.
IaC on AWS with Terraform: HashiCorp Vault
26:48
Cumulus Cycles
Рет қаралды 5 М.
Introduction to HashiCorp Vault with Armon Dadgar
16:53
HashiCorp
Рет қаралды 210 М.
Command Line Navigation
33:59
Dave Cross
Рет қаралды 35
Neo4j (Graph Database) Crash Course
1:23:08
Laith Academy
Рет қаралды 256 М.
VIP ACCESS
00:47
Natan por Aí
Рет қаралды 30 МЛН