HashiCorp announced the general availability of its Vault secrets security management tool as a fully managed service for Amazon Web Services (AWS) environments on the HashiCorp Cloud Platform (HCP). The move is the latest from the vendor to streamline its entire platform and tool portfolio.
The new launch expands customer choice for a fully managed service that is operated and supported by the vendor. HCP Vault comes in three new pricing flavors: Development cluster for non-production, single-node deployment of Vault billed by the hour; Standard cluster (hourly), which is a three-node Vault deployment for multi-node highly available clusters; and Standard cluster (annual) for organizations that plan to run large production deployments.
HashiCorp helps organizations manage the application lifecycle as they make the transition to the cloud. And Vault is the tool designed to keep the sensitive information running within these applications secured. It protects passwords, certificates, and other confidential information that shouldn’t be easily accessible for any application on any infrastructure.
Vault serves as a home base for sensitive data where users can manage, access, and audit secrets across HCP from a central location. It automates the process of regularly updating credentials such as database passwords, certificates, or access tokens used to access other services.
“One of the challenges that has become really clear is we don't have a definitive perimeter anymore,” said Armon Dadgar, co-founder and CTO of HashiCorp. “There's not a single point of entry or exit. So this idea of the perimeter really moves from a physical concept that we have on-premise to very much a logical concept that exists in the cloud. And to make matters worse, as we're in these cloud environments, everything's becoming much more dynamic, much more ephemeral.”
Vault helps companies secure multi-region security across multiple public clouds or private data centers, making it an ideal fit for companies with a distributed workforce as the rise of multicloud continues complicating identity and access controls. It’s currently available in AWS regions in the U.S. (Oregon and Virginia) and Europe (Frankfurt, Ireland, and London).
Keeping Secrets SafeCloud security and the associated lack of control remains a concern across all industries. The increasingly distributed nature of IT systems is likely one major reason many companies are also increasing investment in the technology used to protect and secure them.
Moreover, improved identity and access control are only one part of the puzzle. New governance and security controls are also needed to ensure data protection in a multicloud environment.
“In our worldview, we need to move beyond the perimeter model and start to embrace a zero-trust model,” Dadgar explained. “At the heart of zero trust is really acknowledging that my adversary is on my network as opposed to outside the four walls. And if I assume my adversary is on my network, that really changes my whole approach to security. All of a sudden it's not enough to secure the four walls, I need to harden the inside as well.”
HashiCorp Vaults to the TopHashiCorp’s move follows similar offerings by the public cloud market’s heavyweights. AWS has its Secrets Manager and AWS Key Management Service; Google Cloud Platform (GCP) has Secrets Management and Sops; while Microsoft has its Azure Secrets product.
The rise of Vault and similar tools hasn’t gone unnoticed by the market, either. Defined as “secrets management,” the Cloud Native Computing Foundation (CNCF) recently released a new radar on this category, showing a general shift away from relying on users to manage credentials to automation tools.
HashiCorp Vault grabbed the top honors with the most widespread adoption, which was noted as a surprise in the CNCF report as it was regard to be a “rather complex tool with high operational burden.”
“However, the broad adoption makes sense when you consider many smaller organizations likely would prefer to outsource their secrets management rather than creating and maintaining an in-house solution,” the report notes. “This is backed up by our conclusion that commercial tools have a higher adoption rate since they remove the complexity of creating an in-house tool.”
Comments