vault

Installation
SKILL.md

Vault

Workflow

  1. Classify the environment (dev/test/prod) and your threat model.
  2. Choose deployment style (systemd, Docker, Kubernetes) and isolate Vault (single-tenancy when possible).
  3. Harden the host/runtime and run Vault with least privilege (non-root, mlock, no swap, no core dumps).
  4. Choose the storage backend and HA topology (prefer integrated storage/Raft for most new deployments).
  5. Configure TLS end-to-end and restrict network access (ingress and egress).
  6. Initialize and unseal safely (Shamir key shares or auto-unseal via KMS/HSM).
  7. Enable audit logging early and ship logs to centralized, protected storage.
  8. Configure auth methods and least-privilege policies (separate human vs machine access).
  9. Enable only the required secrets engines and prefer dynamic secrets + short TTLs.
  10. Validate operations: monitoring, backups/snapshots, restore drills, upgrades, and break-glass procedures.
Installs
2
GitHub Stars
2
First Seen
Mar 21, 2026
vault — kittne/codex-skills-by-codex