vault - A tool for securely accessing secrets (HashiCorp Vault 2.1 CLI)
vault <command> [options] [args]
Options you will use
-address=ADDR- Address of the Vault server (default https://127.0.0.1:8200). Also VAULT_ADDR.
-ca-cert=FILE- PEM CA certificate to verify the server's TLS certificate. Also VAULT_CACERT.
-tls-skip-verify- Do not verify the server certificate (never in production). Also VAULT_SKIP_VERIFY.
-namespace=NS- The namespace to use (Vault Enterprise / HCP Vault Dedicated). Also VAULT_NAMESPACE.
-wrap-ttl=DURATION- Wrap the response in a single-use wrapping token that lives this long;
vault unwrapreads it. Also VAULT_WRAP_TTL. -output-curl-string- Print the equivalent curl command instead of sending the request.
-output-policy- Print the policy the request would need instead of sending it.
-format=FORMAT- Print the output in table (default), json, yaml or pretty. Also VAULT_FORMAT.
-field=NAME- Print only this field of the response, with no trailing newline when piped (for $(...) in scripts).
-h, -help- Print the usage of the command.
Examples
$ vault statussealed? initialised? version, storage
$ vault kv get -field=password secret/app/dbone value, for a script
$ vault token lookupwho am I: policies, TTL
$ vault kv get -output-policy secret/app/dbthe policy this read needs
Gotchas
- Flags go BEFORE positional arguments:
vault kv get -format=json secret/x. After them they are taken as arguments, with a warning. - VAULT_ADDR defaults to https://127.0.0.1:8200: a dev server on http gives "http: server gave HTTP response to HTTPS client".
- KV v2 data lives at <mount>/data/<key>: a policy on secret/app/* does not cover
vault kv get secret/app/x(that reads secret/data/app/x). - VAULT_TOKEN wins over ~/.vault-token: unset it when
vault loginseems to have no effect.
Taught in
- 32.1 Why a secrets manager, and your first Vault
- 32.3 How Vault works: the barrier, seal and unseal, storage, HA
- 32.5 Tokens and auth methods: TTLs, renewal, the token tree
- 32.8 KV v2: versions, paths and the put that wipes
- 32.11 Policies: paths, capabilities, and the rule that wins
- 32.16 AppRole: logins for CI jobs and services
- 32.18 Dynamic secrets: database credentials and leases
- 32.21 PKI and transit: certificates on demand, encryption as a service
Try vault in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.