OnCallReady

Commands

vault - A tool for securely accessing secrets (HashiCorp Vault 2.1 CLI)

vault <command> [options] [args]

Options you will use

-address=ADDR
Address of the Vault server (default https://127.0.0.1:8200). Also VAULT_ADDR.
-ca-cert=FILE
PEM CA certificate to verify the server's TLS certificate. Also VAULT_CACERT.
-tls-skip-verify
Do not verify the server certificate (never in production). Also VAULT_SKIP_VERIFY.
-namespace=NS
The namespace to use (Vault Enterprise / HCP Vault Dedicated). Also VAULT_NAMESPACE.
-wrap-ttl=DURATION
Wrap the response in a single-use wrapping token that lives this long; vault unwrap reads it. Also VAULT_WRAP_TTL.
-output-curl-string
Print the equivalent curl command instead of sending the request.
-output-policy
Print the policy the request would need instead of sending it.
-format=FORMAT
Print the output in table (default), json, yaml or pretty. Also VAULT_FORMAT.
-field=NAME
Print only this field of the response, with no trailing newline when piped (for $(...) in scripts).
-h, -help
Print the usage of the command.

Examples

$ vault status

sealed? initialised? version, storage

$ vault kv get -field=password secret/app/db

one value, for a script

$ vault token lookup

who am I: policies, TTL

$ vault kv get -output-policy secret/app/db

the policy this read needs

Gotchas

Taught in

Try vault in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.