Why Secrets Management Is a Compliance Requirement
Every regulated enterprise has the same problem: database credentials in environment variables, API keys in config files, TLS certificates managed manually, and no audit trail of who accessed what secret when. This isn't just a security risk — it's a compliance violation under DORA, NIS2, and GDPR.
HashiCorp Vault centralises secrets management, automates credential rotation, provides encryption as a service, and maintains a complete audit log of every secret access.
Vault Capabilities for Compliance
Dynamic Secrets — DORA Art. 9(4), NIS2 Art. 21(2)(i)
Instead of long-lived credentials, Vault generates short-lived, unique credentials on demand:
- Database credentials: Each application instance gets unique credentials with automatic expiration (TTL). No shared passwords.
- Cloud credentials: AWS IAM roles, Azure service principals, GCP service accounts — generated dynamically with minimal permissions
- PKI certificates: TLS certificates issued and rotated automatically. Supports the 47-day certificate lifecycle.
- Kubernetes service accounts: Dynamic K8s tokens with scoped RBAC permissions
Why it matters: Dynamic secrets eliminate credential sprawl. If credentials are compromised, they expire automatically. No more "this database password hasn't been rotated in 3 years."
Encryption as a Service (Transit) — GDPR Art. 32, NIS2 Art. 21(2)(h)
- Application-level encryption: Applications send plaintext to Vault, get ciphertext back. Encryption keys never leave Vault.
- Key rotation without re-encryption: Vault supports key versioning — rotate keys without re-encrypting all data
- Tokenisation: Replace sensitive data (credit card numbers, SSNs) with non-sensitive tokens
- Data masking: Format-preserving encryption for development and testing environments
GDPR compliance: Vault's transit engine provides the "encryption of personal data" measure explicitly called out in GDPR Article 32(1)(a) as an appropriate technical measure.
Audit Logging — DORA Art. 10, Art. 12
- Every operation logged: Every authentication, secret read, secret write, and policy change is logged with timestamp, identity, source IP, and request details
- Multiple audit backends: File, syslog, socket — send to your SIEM for centralised analysis
- HMAC hashing: Audit logs hash sensitive values by default — you can see who accessed what without exposing the secret values
- Tamper evidence: Audit log integrity can be verified
Vault Kubernetes Integration
Three integration patterns for Kubernetes:
- Vault Agent Injector: Sidecar container that automatically injects secrets into pod filesystem. Minimal application changes.
- Vault CSI Provider: Mounts secrets as Kubernetes volumes via the Secrets Store CSI Driver. No sidecar needed.
- Vault Secrets Operator: Kubernetes operator that syncs Vault secrets to Kubernetes Secrets. Most Kubernetes-native approach.
Recommended for regulated environments: Vault Secrets Operator for simplicity, or Agent Injector for maximum control and audit granularity.
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Vault vs Cloud-Native Secrets Managers
| Feature | Vault | AWS Secrets Manager | Azure Key Vault |
|---|---|---|---|
| Multi-cloud | Yes (cloud-agnostic) | AWS only | Azure only |
| Dynamic secrets | Yes (30+ backends) | Rotation only (Lambda) | Limited |
| PKI | Full CA (built-in) | No (use ACM) | Certificate store (no CA) |
| Encryption service | Transit engine (full) | No (use KMS) | Limited |
| Operational burden | High (self-managed) or HCP Vault (managed) | Low (managed service) | Low (managed service) |
Choose Vault if: Multi-cloud, need dynamic secrets and PKI, want a single secrets platform. Choose cloud-native if: Single cloud, simple secret storage needs, want minimal operational overhead.
Deployment Best Practices
- High availability from day one — Deploy Vault in HA mode with Raft storage (3 or 5 nodes)
- Auto-unseal with cloud KMS — Don't rely on manual unseal with Shamir keys for production
- Enable audit logging immediately — Two audit backends minimum (if one fails, Vault stops serving requests)
- Use namespaces for multi-tenancy — Separate teams/environments with Vault namespaces (Enterprise feature)
- Integrate with your identity provider — OIDC, LDAP, or Kubernetes auth — no standalone Vault passwords
Automating Azure DevTest Labs
Automate lab management and integrate with CI/CD pipelines.
Start on Pluralsight →
Luca Berton
