vault
Installation
SKILL.md
Vault
Workflow
- Classify the environment (dev/test/prod) and your threat model.
- Choose deployment style (systemd, Docker, Kubernetes) and isolate Vault (single-tenancy when possible).
- Harden the host/runtime and run Vault with least privilege (non-root, mlock, no swap, no core dumps).
- Choose the storage backend and HA topology (prefer integrated storage/Raft for most new deployments).
- Configure TLS end-to-end and restrict network access (ingress and egress).
- Initialize and unseal safely (Shamir key shares or auto-unseal via KMS/HSM).
- Enable audit logging early and ship logs to centralized, protected storage.
- Configure auth methods and least-privilege policies (separate human vs machine access).
- Enable only the required secrets engines and prefer dynamic secrets + short TTLs.
- Validate operations: monitoring, backups/snapshots, restore drills, upgrades, and break-glass procedures.