SlideShare a Scribd company logo
Copyright © 2020 HashiCorp
HashiCorp Vault
David Wright Technical Channel and Alliances APJ
HashiCorp Overview
Leading Cloud Infrastructure
Automation
Founded
2012
Employees
1000
Funding
Round E
Our software stack enables the provisioning, securing,
connecting and running of apps and the infrastructure to
support them.
We unlock the cloud operating model for every business and
enable their digital transformation strategies to succeed.
$5.1B Valuation
45Lowered
infrastructure
and storage costs
41Reported
greater customer
satisfaction
53Increased
operational
efficiencies
Of enterprise companies that have switched to cloud...
How are you unlocking business value with cloud?
Source: https://www.accenture.com/us-en/insight-cloud-business-benefits
Why Adopt Cloud?
CLOUD OPERATING MODEL
Private Cloud AWS Azure GCP
Provision
Operations
Secure
Security
Connect
Networking
Run
Development
A control plane for every layer of the cloud operating model
Before multi-cloud
Provisioning infrastructure was easy...
● Datacenters had fixed sets of resources that lived
for long periods of time
● IT Ops was the central gatekeeper to procure,
validate, and provision infrastructure
But what happens when your apps and
infrastructure extend to multiple datacenters,
clouds, or all the above?
CLOUD OPERATING MODEL
The effects of digital transformation
Cloud adoption is a secular trend
Digital experiences are now the
primary interface between a
customer and a business, or
business and business.
Experiences are typically device- and
cloud-first: rich, personal interface,
with large scale data processing and
intelligence.
This pattern demands a change in the
model for software delivery to meet
delivery goals, and transformation
objectives.
Digital transformation means pressure on application delivery
Accelerating Application Delivery
Facets of delivering applications
in a multi-cloud world
Volume and distribution of services
Ephemerality and immutability
Multiple target environments ?
App
App
THE SHIFT TO MULTI-CLOUD
Traditional datacenter
“Static”
Modern datacenter
“Dynamic”
Dedicated infrastructure Private cloud
SYSTEMS OF RECORD SYSTEMS OF ENGAGEMENT
Public multi-cloud
+
Developer agility improved but this creates new issues for Network, Security and Ops
Multi-cloud challenges around orchestration, provisioning and automation
Security perimeter is much harder to define (zero trust) and secrets are sprawled
How can services connect & communicate with each other?
Reimagining the stack
The implications of the Cloud Operating Model
Run
Development
Dedicated
Infrastructure
Scheduled across the fleet
Connect
Networking
Host-based
Static IP
Service-based
Dynamic IP
Secure
Security
High trust IP-
based
Low trust
Identity-based
Provision
Operations
Dedicated servers
Homogeneous
Capacity on-demand
Heterogeneous
STATIC DYNAMIC
The Cloud Landscape
In search of a common model across multi-cloud
environments
Run
Development
Connect
Networking
Secure
Security
Provision
Operations
DEDICATED
PRIVATE
CLOUD
vSphere
Hardware
IP:
Hardware
vCenter
vSphere
Various
Hardware
Identity:
AD/LDAP
Terraform
EKS / ECS
Lambda
CloudMap/
AppMesh
Identity:
AWS IAM
Cloud
Formation
AKS / ACS
Azure
Functions
Proprietary
Identity:
Azure AD
Resource
Manager
GKE Cloud
Functions
Proprietary
Identity:
GCP IAM
Cloud
Deployment
Manager
AWS AZURE GCP
VAULT
$3.92 Million
(average cost of
a data breach in
2019)
U.S. is the most expensive
country with an average cost
of
USD $8.19M per breach
In the last 10 years, 20
companies have
experienced massive data
breaches of over $1M...
90% of those
companies now
use Vault
*2019 Ponemon Institute: Cost of a Data Breach
VAULT - Overview
Vault provides the foundation for cloud security that uses
trusted sources of identity to keep secrets and application
data secure in the cloud operating model
Secrets management to centrally store and protect
secrets across clouds and applications
Data encryption to keep application data secure
across environments and workloads
Advanced Data Protection to secure workloads and
data across traditional systems, clouds, and
infrastructure.
: Business Challenges
Reduced productivity.
Increased risk of breach.
Secrets sprawled across different systems, files, and repositories.
Inefficiencies with managing different systems to manage secrets,
HSMs, and cryptographic operations across an organization and
different teams
Increased risk of data exposure.
Multi-cloud creates a larger surface area to secure and encrypting
data across hybrid environments with HSMs is painful and hard to
use.
: Single Control Plane for Cloud Security
● Automate, control and secure
infrastructure and applications
through one API
● Unified support across
heterogeneous environments
● Integrate with providers and
technologies you’re already using as
well as those you plan to acquire
: How it works
Vault tightly controls access to
secrets and encryption keys by
authenticating against trusted
sources of identity such as Active
Directory, LDAP, Kubernetes,
CloudFoundry, and cloud
platforms.
Vault enables fine grained
authorization of which users and
applications are permitted access
to secrets and keys.
: Integrations
The HashiCorp Vault Integration
Program allows vendors to integrate
their products to work with Vault. Vault
has a relatively large surface area and
thereby a large set of possible
integrations some of which require the
vendor integration code, like other
integrations that result in the solution
working tightly with Vault.
Vendors integrating their solutions via
the Vault Integration Process provide
their customers a verified and seamless
user experience. The Vault Integration
Program currently only supports coding
with the Go programming language (run
time integrations).
Thank You
dr@hashicorp.com
learn.hashicorp.com
hashicorp.com/events/#snapshots
19

More Related Content

PDF
Azure 101: Shared responsibility in the Azure Cloud
PDF
Military Edge Computing with Vault and Consul
PPTX
Architecting io t solutions with microisoft azure ignite tour version
PDF
Hashicorp Vault - OPEN Public Sector
PPTX
Azure Compute, Networking and Storage Overview
PPTX
CSS17: Atlanta - The AWS Shared Responsibility Model in Practice
PPTX
Multi cloud security architecture
PDF
Multi cloud strategy
Azure 101: Shared responsibility in the Azure Cloud
Military Edge Computing with Vault and Consul
Architecting io t solutions with microisoft azure ignite tour version
Hashicorp Vault - OPEN Public Sector
Azure Compute, Networking and Storage Overview
CSS17: Atlanta - The AWS Shared Responsibility Model in Practice
Multi cloud security architecture
Multi cloud strategy

What's hot (20)

PDF
The AWS Shared Responsibility Model: Presented by Amazon Web Services
PDF
The AWS Shared Responsibility Model in Practice - Nirav Kothari, AWS
PPTX
cloud computing Multi cloud
PDF
Integrating Cloudera & Microsoft Azure
PPTX
Microsoft Azure Overview Class 1
PDF
Adopting Multi-Cloud Services with Confidence
PDF
Demystifying identity on AWS
PPTX
The AWS Shared Security Responsibility Model in Practice
PDF
Security OF The Cloud
PPTX
Azure Overview Arc
PDF
Azure Arc - Managing Hybrid and Multi-Cloud Platforms
PPTX
Cloud security ppt
PPTX
Cloud Reference Architecture - Part 1 Foundation
PPTX
Evolution to the Hybrid Data Center
PPT
Cloud Security Alliance's GRC Stack Overview
PDF
RightScale Webinar: Security and Compliance in the Cloud
PDF
Vmware Seminar Security & Compliance for the cloud with Trend Micro
PPTX
The promise of multi cloud
PPTX
2016, A new era of OS and Cloud Security
PPTX
Introducing Azure Bastion
The AWS Shared Responsibility Model: Presented by Amazon Web Services
The AWS Shared Responsibility Model in Practice - Nirav Kothari, AWS
cloud computing Multi cloud
Integrating Cloudera & Microsoft Azure
Microsoft Azure Overview Class 1
Adopting Multi-Cloud Services with Confidence
Demystifying identity on AWS
The AWS Shared Security Responsibility Model in Practice
Security OF The Cloud
Azure Overview Arc
Azure Arc - Managing Hybrid and Multi-Cloud Platforms
Cloud security ppt
Cloud Reference Architecture - Part 1 Foundation
Evolution to the Hybrid Data Center
Cloud Security Alliance's GRC Stack Overview
RightScale Webinar: Security and Compliance in the Cloud
Vmware Seminar Security & Compliance for the cloud with Trend Micro
The promise of multi cloud
2016, A new era of OS and Cloud Security
Introducing Azure Bastion
Ad

Similar to Securing Your CI Pipeline with HashiCorp Vault - P2 (20)

PDF
Wp cipher graph-cag-topology
PPT
Cloud Computing Ppt
PPT
Cloud Computing
PPT
Cloudcomputingppt 12746363271272 Phpapp01
PDF
Multi-Cloud with Nomad and Consul Connect
PPT
Cloud computing
PPTX
Microsoft Windows Azure - Platfrom Appfabric Service Bus And Access Control P...
PDF
zscaler-aws-zero-trust.pdf
ODP
Zarafa SummerCamp 2012 - Keynote Peter Ganten
PPT
Cloud computing What Why How
PPTX
Application security meetup - cloud security best practices 24062021
PDF
Hybridní cloud s F5 v prostředí kontejnerů
PDF
Unlocking the Cloud Operating Model
PDF
Vault 1.4 launch webinar
PDF
Best Practices for Workload Security: Securing Servers in Modern Data Center ...
PDF
CIO Bulletin - 10 Best Cloud Computing Companies
PDF
Hybride clouds door bart veldhuis
PPTX
CloudComputing_Group1_2021EE83_2021EE75_2021EE89_2Dec2024.pptx
ODP
Cloud Computing & Sun Vision 03262009
PPTX
Introduction-to-Cloud-ComputingFinal.pptx
Wp cipher graph-cag-topology
Cloud Computing Ppt
Cloud Computing
Cloudcomputingppt 12746363271272 Phpapp01
Multi-Cloud with Nomad and Consul Connect
Cloud computing
Microsoft Windows Azure - Platfrom Appfabric Service Bus And Access Control P...
zscaler-aws-zero-trust.pdf
Zarafa SummerCamp 2012 - Keynote Peter Ganten
Cloud computing What Why How
Application security meetup - cloud security best practices 24062021
Hybridní cloud s F5 v prostředí kontejnerů
Unlocking the Cloud Operating Model
Vault 1.4 launch webinar
Best Practices for Workload Security: Securing Servers in Modern Data Center ...
CIO Bulletin - 10 Best Cloud Computing Companies
Hybride clouds door bart veldhuis
CloudComputing_Group1_2021EE83_2021EE75_2021EE89_2Dec2024.pptx
Cloud Computing & Sun Vision 03262009
Introduction-to-Cloud-ComputingFinal.pptx
Ad

More from Ashnikbiz (20)

PPTX
CloudOps_tool.pptx
PPTX
Webinar_CloudOps final.pptx
PPTX
Autoscaling in Kubernetes (K8s)
PPTX
Why and how to use Kubernetes for scaling of your multi-tier (n-tier) appli...
PDF
Zero trust in a multi tenant environment
PPTX
Deploy and automate ‘Secrets Management’ for a multi-cloud environment
PPTX
Deploy, move and manage Postgres across cloud platforms
PPTX
Deploy, move and manage Postgres across cloud platforms
PPTX
The Best Approach For Multi-cloud Infrastructure Provisioning-2
PPTX
The Best Approach For Multi-cloud Infrastructure Provisioning
PPTX
Which PostgreSQL is right for your multi cloud strategy? P2
PPTX
Which PostgreSQL is right for your multi cloud strategy? P1
PPTX
Reduce the complexities of managing Kubernetes clusters anywhere 2
PPTX
Reduce the complexities of managing Kubernetes clusters anywhere
PPTX
Enhance your multi-cloud application performance using Redis Enterprise P2
PPTX
Enhance your multi-cloud application performance using Redis Enterprise P1
PPTX
Gain multi-cloud versatility with software load balancing designed for cloud-...
PPTX
Gain multi-cloud versatility with software load balancing designed for cloud-...
PPTX
Enterprise-class security with PostgreSQL - 1
PPTX
Enterprise-class security with PostgreSQL - 2
CloudOps_tool.pptx
Webinar_CloudOps final.pptx
Autoscaling in Kubernetes (K8s)
Why and how to use Kubernetes for scaling of your multi-tier (n-tier) appli...
Zero trust in a multi tenant environment
Deploy and automate ‘Secrets Management’ for a multi-cloud environment
Deploy, move and manage Postgres across cloud platforms
Deploy, move and manage Postgres across cloud platforms
The Best Approach For Multi-cloud Infrastructure Provisioning-2
The Best Approach For Multi-cloud Infrastructure Provisioning
Which PostgreSQL is right for your multi cloud strategy? P2
Which PostgreSQL is right for your multi cloud strategy? P1
Reduce the complexities of managing Kubernetes clusters anywhere 2
Reduce the complexities of managing Kubernetes clusters anywhere
Enhance your multi-cloud application performance using Redis Enterprise P2
Enhance your multi-cloud application performance using Redis Enterprise P1
Gain multi-cloud versatility with software load balancing designed for cloud-...
Gain multi-cloud versatility with software load balancing designed for cloud-...
Enterprise-class security with PostgreSQL - 1
Enterprise-class security with PostgreSQL - 2

Recently uploaded (20)

PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Advanced IT Governance
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PPTX
Cloud computing and distributed systems.
PDF
Empathic Computing: Creating Shared Understanding
PDF
Electronic commerce courselecture one. Pdf
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PDF
Modernizing your data center with Dell and AMD
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
Understanding_Digital_Forensics_Presentation.pptx
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Mobile App Security Testing_ A Comprehensive Guide.pdf
Reach Out and Touch Someone: Haptics and Empathic Computing
Advanced IT Governance
NewMind AI Monthly Chronicles - July 2025
GamePlan Trading System Review: Professional Trader's Honest Take
Cloud computing and distributed systems.
Empathic Computing: Creating Shared Understanding
Electronic commerce courselecture one. Pdf
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
Modernizing your data center with Dell and AMD
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Advanced methodologies resolving dimensionality complications for autism neur...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Chapter 3 Spatial Domain Image Processing.pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Network Security Unit 5.pdf for BCA BBA.
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...

Securing Your CI Pipeline with HashiCorp Vault - P2

  • 1. Copyright © 2020 HashiCorp HashiCorp Vault David Wright Technical Channel and Alliances APJ
  • 2. HashiCorp Overview Leading Cloud Infrastructure Automation Founded 2012 Employees 1000 Funding Round E Our software stack enables the provisioning, securing, connecting and running of apps and the infrastructure to support them. We unlock the cloud operating model for every business and enable their digital transformation strategies to succeed. $5.1B Valuation
  • 3. 45Lowered infrastructure and storage costs 41Reported greater customer satisfaction 53Increased operational efficiencies Of enterprise companies that have switched to cloud... How are you unlocking business value with cloud? Source: https://www.accenture.com/us-en/insight-cloud-business-benefits Why Adopt Cloud?
  • 4. CLOUD OPERATING MODEL Private Cloud AWS Azure GCP Provision Operations Secure Security Connect Networking Run Development A control plane for every layer of the cloud operating model
  • 5. Before multi-cloud Provisioning infrastructure was easy... ● Datacenters had fixed sets of resources that lived for long periods of time ● IT Ops was the central gatekeeper to procure, validate, and provision infrastructure But what happens when your apps and infrastructure extend to multiple datacenters, clouds, or all the above?
  • 6. CLOUD OPERATING MODEL The effects of digital transformation
  • 7. Cloud adoption is a secular trend Digital experiences are now the primary interface between a customer and a business, or business and business. Experiences are typically device- and cloud-first: rich, personal interface, with large scale data processing and intelligence. This pattern demands a change in the model for software delivery to meet delivery goals, and transformation objectives. Digital transformation means pressure on application delivery
  • 8. Accelerating Application Delivery Facets of delivering applications in a multi-cloud world Volume and distribution of services Ephemerality and immutability Multiple target environments ? App App
  • 9. THE SHIFT TO MULTI-CLOUD Traditional datacenter “Static” Modern datacenter “Dynamic” Dedicated infrastructure Private cloud SYSTEMS OF RECORD SYSTEMS OF ENGAGEMENT Public multi-cloud + Developer agility improved but this creates new issues for Network, Security and Ops Multi-cloud challenges around orchestration, provisioning and automation Security perimeter is much harder to define (zero trust) and secrets are sprawled How can services connect & communicate with each other?
  • 10. Reimagining the stack The implications of the Cloud Operating Model Run Development Dedicated Infrastructure Scheduled across the fleet Connect Networking Host-based Static IP Service-based Dynamic IP Secure Security High trust IP- based Low trust Identity-based Provision Operations Dedicated servers Homogeneous Capacity on-demand Heterogeneous STATIC DYNAMIC
  • 11. The Cloud Landscape In search of a common model across multi-cloud environments Run Development Connect Networking Secure Security Provision Operations DEDICATED PRIVATE CLOUD vSphere Hardware IP: Hardware vCenter vSphere Various Hardware Identity: AD/LDAP Terraform EKS / ECS Lambda CloudMap/ AppMesh Identity: AWS IAM Cloud Formation AKS / ACS Azure Functions Proprietary Identity: Azure AD Resource Manager GKE Cloud Functions Proprietary Identity: GCP IAM Cloud Deployment Manager AWS AZURE GCP
  • 12. VAULT
  • 13. $3.92 Million (average cost of a data breach in 2019) U.S. is the most expensive country with an average cost of USD $8.19M per breach In the last 10 years, 20 companies have experienced massive data breaches of over $1M... 90% of those companies now use Vault *2019 Ponemon Institute: Cost of a Data Breach
  • 14. VAULT - Overview Vault provides the foundation for cloud security that uses trusted sources of identity to keep secrets and application data secure in the cloud operating model Secrets management to centrally store and protect secrets across clouds and applications Data encryption to keep application data secure across environments and workloads Advanced Data Protection to secure workloads and data across traditional systems, clouds, and infrastructure.
  • 15. : Business Challenges Reduced productivity. Increased risk of breach. Secrets sprawled across different systems, files, and repositories. Inefficiencies with managing different systems to manage secrets, HSMs, and cryptographic operations across an organization and different teams Increased risk of data exposure. Multi-cloud creates a larger surface area to secure and encrypting data across hybrid environments with HSMs is painful and hard to use.
  • 16. : Single Control Plane for Cloud Security ● Automate, control and secure infrastructure and applications through one API ● Unified support across heterogeneous environments ● Integrate with providers and technologies you’re already using as well as those you plan to acquire
  • 17. : How it works Vault tightly controls access to secrets and encryption keys by authenticating against trusted sources of identity such as Active Directory, LDAP, Kubernetes, CloudFoundry, and cloud platforms. Vault enables fine grained authorization of which users and applications are permitted access to secrets and keys.
  • 18. : Integrations The HashiCorp Vault Integration Program allows vendors to integrate their products to work with Vault. Vault has a relatively large surface area and thereby a large set of possible integrations some of which require the vendor integration code, like other integrations that result in the solution working tightly with Vault. Vendors integrating their solutions via the Vault Integration Process provide their customers a verified and seamless user experience. The Vault Integration Program currently only supports coding with the Go programming language (run time integrations).