{"repo":"lrstanley/vault-unseal","free":true,"listed":false,"github":"https://github.com/lrstanley/vault-unseal","clone":"git clone https://github.com/lrstanley/vault-unseal.git","description":"auto-unseal utility for Hashicorp Vault","language":"Go","stars":314,"topics":["vault","hashicorp","unseal","go","golang","unseals-vault-servers","vault-api","auto-unseal","vault-unseal","cli"],"license":"MIT","category":"cli-tools","readme_excerpt":":link: Table of Contents - Why - Solution - Installation - Container Images (ghcr) - Source - Usage - TODO - Support &amp; Assistance - Contributing - License :grey question: Why HashiCorp Vault provides a few options for auto-unsealing clusters: - Cloud KMS (AWS, Azure, GCP, and others) (cloud only) - Hardware Security Modules with PKCS11 (enterprise only) - Transit Engine via Vault (requires another vault cluster) - Potentially others However, depending on your deployment conditions and use-cases of Vault, some of the above may not be feasible (cost, network connectivity, complexity). This may lead you to want to roll your own unseal functionality, however, it's not easy to do in a relatively secure manner. So, what do we need to solve? We want to auto-unseal a vault cluster, by providing the necessary unseal tokens when we find vault is sealed. We also want to make sure we're sending notifications when this happens, so if vault was unsealed unintentionally (not patching, upgrades, etc), possibly related to crashing or malicious intent, a human can investigate at a later time ( not 3am in the morning). :heavy check mark: Solution The goal for this project is to find the best way to unseal vault in a way that doesn't compromise too much security (a good balance between security and ease of use/uptime), without the requirement of Vault Enterprise, or having to move to a cloud platform. We do this by running multiple instances of vault-unseal (you could run one on each node in","default_branch":null,"files":null,"tree":[],"storefront":"/r/lrstanley","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/lrstanley/vault-unseal/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}