{"repo":"numberly/vault-db-injector","free":true,"listed":false,"github":"https://github.com/numberly/vault-db-injector","clone":"git clone https://github.com/numberly/vault-db-injector.git","description":"The Vault DB Injector automates secure database credential management in Kubernetes using Hashicorp Vault, providing credential injection, renewal, and revocation for pods.","language":"Go","stars":50,"topics":["kubernetes","vault","database","databases","secret","secrets"],"license":"Apache-2.0","category":"databases-storage","readme_excerpt":"Vault Database Injector The Vault DB Injector relies on the database engine from Vault to generate credentials, distribute them to Kubernetes applications and handle their lifecycle. 1. Feature - Generate credentials through Vault Database Engine - Distribute credentials to workload using annotations and Kubernetes mutating webhook - Renew credentials when necessary - Revoke credentials when application pod is deleted - Optionally protect credentials at the Kubernetes API layer using an NRI plugin substitution layer 2. Documentation Checkout the Vault DB Injector documentation for more informations. 3. Cloud Native Days France – Talk & Demo A production feedback session presenting Vault DB Injector , its design decisions, trade-offs, and lessons learned after running it in production at scale. The talk covers: - why static database credentials become a problem - how ephemeral credentials are injected into Kubernetes workloads - operational feedback from real-world usage - a live demonstration The demo environment is based on: - OpenBao (Vault-compatible secrets management) - CloudNativePG (CNPG) for PostgreSQL on Kubernetes 📺 Replay: https://youtu.be/QhOEMqbrFBk 🧪 Demo code used during the talk: https://github.com/SoulKyu/vault-db-injector-cnd 3.5. Security: NRI mode hardening NRI mode requires the plugin DaemonSet to mount /var/run/nri/nri.sock — the same socket containerd uses for plugin registration. Any pod that mounts this hostPath can register as an NRI plugin and mut","default_branch":null,"files":null,"tree":[],"storefront":"/r/numberly","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/numberly/vault-db-injector/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}