"But that is as far as I want to automate... otherwise I'll have to
put keys somewhere, sure that, and it is turtles all the way down."
Hah, I love it.
I fully agree, but in a bit more detail: Vault is designed to be the
thing that keeps *everything else* from having to have hardcoded
secrets. But the flip side of that is that Vault needs manual
unsealing. If you hardcode Vault's unseal key somewhere, you've just
shifted the problem...then you have to figure out how to protect that,
and potentially automate *that* protection. As Adam said, turtles.
Security is always butting heads with convenience. You can automate
unsealing for convenience, but you'll be giving up a core part of
Vault's security, and I can't really recommend a particular way to go
about doing so. My suggestion is: let Vault be your one pain point,
and if need be, treat it as a special flower -- for instance, make it
the one thing you don't put in autoscaling groups, so that you can
safely put everything else in them.
--Jeff
> --
> This mailing list is governed under the HashiCorp Community Guidelines -
>
https://www.hashicorp.com/community-guidelines.html. Behavior in violation
> of those guidelines may result in your removal from this mailing list.
>
> GitHub Issues:
https://github.com/hashicorp/vault/issues
> IRC: #vault-tool on Freenode
> ---
> You received this message because you are subscribed to the Google Groups
> "Vault" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to
vault-tool+...@googlegroups.com.
> To view this discussion on the web visit
>
https://groups.google.com/d/msgid/vault-tool/5db0919b-ee40-41bf-95bb-33078582e934%40googlegroups.com.
>
> For more options, visit
https://groups.google.com/d/optout.