Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Automating Secrets Management with Vault and Waypoint

HashiCorp
04/09/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • Centralize secrets management using HCP Vault Secrets and automate onboarding with HCP Waypoint templates, enabling self-service for application teams without requiring code changes or platform team support tickets
  • Leverage Vault Secrets' one-way sync capability to push secrets from the centralized vault to native cloud systems (AWS Secrets Manager, Azure Key Vault, GCP, Terraform Cloud) so applications continue using existing integrations unchanged
  • Implement granular IAM controls with service principals scoped to individual Vault Secrets apps, ensuring workload identity separation and preventing cross-contamination of secrets between applications
  • Utilize auto-rotating secrets (up to 50 versions, two active) and dynamic secrets generation with automatic downstream synchronization, demonstrated with AWS credentials rotating and syncing to Secrets Manager in real-time
  • Provide security teams with comprehensive audit logging showing who accessed what secrets when, with export to SIEM tools, while eliminating infrastructure overhead through serverless HCP Vault Secrets deployment

Centralizing Secrets Without Disrupting Applications

This presentation demonstrates how organizations can centralize secrets management using HCP Vault Secrets while minimizing disruption to application teams. The approach leverages HCP Waypoint automation to enable self-service onboarding, allowing application teams to migrate to centralized secrets management without rewriting applications or creating additional support burden for platform engineering teams. The solution addresses the common challenge of secret sprawl across databases, API keys, AWS Secrets Manager, Azure Key Vault, GitHub variables, and Azure DevOps by establishing a single source of truth that security teams can audit while maintaining granular access controls that prevent cross-contamination between applications.

Waypoint Templates and No-Code Automation

The implementation uses HCP Waypoint's three core capabilities—templates, add-ons, and actions—to automate infrastructure provisioning. Platform engineers build Terraform no-code modules that create HCP projects, Vault Secrets apps, and inject secrets, then publish these as Waypoint templates. Application teams can then self-service their onboarding by selecting templates through the Waypoint portal, which automatically generates workspaces, runs Terraform plans and applies, and provisions all necessary resources including service principals with appropriate IAM scopes. This approach eliminates ticket-based workflows and enables application teams to onboard when ready without waiting on platform teams.

Secrets Sync and Native Cloud Integration

A critical feature demonstrated is Vault Secrets' ability to sync secrets one-way from the centralized vault down to native cloud secrets management systems including AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, and Terraform Cloud variables. This capability allows applications to continue using their existing integrations and code without modification—the secrets are simply sourced from the centralized system and pushed to where applications already expect them. The presentation includes live demonstrations of auto-rotating secrets (supporting up to 50 versions with two active simultaneously) and dynamic secrets generation, showing how rotated credentials automatically sync to downstream systems like AWS Secrets Manager within seconds.

Security, Audit, and Access Controls

The solution addresses security team requirements through comprehensive audit logging that captures who accessed what secrets, when, and how, with export capabilities to Splunk, Datadog, and CloudWatch. Granular IAM access controls ensure workload identity separation—each application receives service principals scoped only to their specific Vault Secrets app, preventing secret sharing between applications. The presentation demonstrates both successful and failed access attempts in audit logs, showing how the system enforces least-privilege access. The serverless nature of HCP Vault Secrets eliminates patching and version management overhead while providing enterprise-grade security controls from day one.

Chapters

0:00 - Introduction and Problem Statement
1:31 - Secret Sprawl Challenge
3:56 - Solution Overview: Waypoint and Vault Secrets
4:47 - Waypoint Capabilities Explained
5:32 - HCP Vault Secrets Features
7:24 - Platform Engineering Perspective
8:33 - Building Templates and No-Code Modules
12:15 - Application Team Perspective
13:39 - Demo: Creating HCP Project
14:58 - Demo: Creating Vault Secrets App
16:01 - Demo: Injecting Secrets
17:51 - Auto-Rotating and Dynamic Secrets
19:12 - Secrets Sync to Native Cloud Systems
21:19 - Security Team Requirements: Audit Logging
22:24 - Granular Access Controls
22:55 - Conclusion and Key Takeaways

Key Quotes

0:52 "If you would have asked me at Hashi comp 2023, is it a good idea to centralize your secrets in one system? sure. But there's going to be an impact to your application teams. They need to rewrite their applications to point to this system. Your platform engineering teams need to support this process. Is it worth the squeeze? I'm not sure. Now, hashi comp 2024, i would still say yes. This is a great idea. But if you'll give me a mic, 30 minutes, and a platform, i'll show you how we can do it and minimize that risk and eliminate any undue support by our platform engineering teams."
6:11 "This is the key piece you want to pay attention to. We can sync those secrets from our cloud secrets app down into one-way push, not bidirectional, one-way push down into our native cloud secrets management systems. Things like Azure key vault, secrets manager, GCP, you can read, you can see it."
6:53 "Auto rotate up to 50 versions and up to two active any given time. This matters. Why? Because an application that's currently running, we cannot retire the secrets it's actively using. So we create a second version and allow the application to refresh, reboot, restart, recycle, whatever it might be, and recache those credentials at a time that's convenient for them, perhaps a change window."
12:19 "Your requirements and objectives are make it self-service. Make it easy for me to onboard when i'm ready. I don't want any additional overhead of submitting tickets or waiting on other platform teams to do the work for me. I want to do it myself."
14:10 "This is self-service, and it's easy. We've already built the underlying infrastructure behind the scenes in terraform, so all it's doing is generating a workspace, running the terraform plan and apply for the app team, and spinning up these resources for them."
19:17 "We're going to sync those secrets from our vault secrets app after we rotate them into these different systems. And this is where we're not moving the cheese for our application teams, right? we're going to ensure that they can continue to leverage the applications and native services that they have been until today."
21:22 "We need to ensure that our security team has visibility into everything and understands what's happening on our secrets management platform. They want logs, they want audit trails for compliance, and most of all, they need to know the who, what, when, where, and how. We haven't forgot about you. We now have audit logging now on the vault secrets app."
22:28 "You need to ensure that we're only accessing the secrets that we were meant to access. We can see here the vault secrets app manager has project level, which is denoted by the cool little notepad icon, and it has admin access and vault secrets app manager. While the sales web ui reader and manager only have access to the vault secrets app that they are designated access to. It's a good, refined iam access controls here."

Categories:
  • » Cybersecurity » Application Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • DevSecOps
  • Technical Deep Dive
  • Demo
  • Best Practices
  • Secrets Management
  • HCP Vault Secrets
  • HCP Waypoint
  • Infrastructure Automation
  • Terraform No-Code Modules
  • Self-Service Platform Engineering
  • Workload Identity
  • Secrets Sync
  • IAM Access Controls
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Automating Secrets Management with Vault and Waypoint

              Upcoming Webinar Calendar

              • 04/30/2026
                10:00 AM
                04/30/2026
                Insights into SaaS Data Protection from the Keepit Annual Data Report 2026
                https://www.truthinit.com/index.php/channel/1868/insights-into-saas-data-protection-from-the-keepit-annual-data-report-2026/
              • 04/30/2026
                01:00 PM
                04/30/2026
                The New Economics of a VMware Exit
                https://www.truthinit.com/index.php/channel/1880/the-new-economics-of-vmware-exit/
              • 05/06/2026
                02:00 AM
                05/06/2026
                Detecting Cyber Attacks Before They Evolve Into Breaches with AI Insights
                https://www.truthinit.com/index.php/channel/1886/detecting-cyber-attacks-before-they-evolve-into-breaches-with-ai-insights/
              • 05/06/2026
                10:00 PM
                05/06/2026
                World Password Day: Strategies for Managing Your Passwords Effectively.
                https://www.truthinit.com/index.php/channel/1913/world-password-day-strategies-for-managing-your-passwords-effectively/
              • 05/07/2026
                05:00 AM
                05/07/2026
                World Password Day: Strategies for Managing Your Passwords Effectively.
                https://www.truthinit.com/index.php/channel/1914/world-password-day-strategies-for-managing-your-passwords-effectively/
              • 05/07/2026
                01:00 PM
                05/07/2026
                World Password Day: Strategies for Managing Your Passwords Effectively
                https://www.truthinit.com/index.php/channel/1915/world-password-day-strategies-for-managing-your-passwords-effectively/
              • 05/12/2026
                01:00 PM
                05/12/2026
                Transforming Black Box to Glass Box: Revealing Hidden Threats and AI Risks through Data Lineage
                https://www.truthinit.com/index.php/channel/1895/transforming-black-box-to-glass-box-revealing-hidden-threats-and-ai-risks-through-data-lineage/
              • 05/12/2026
                11:30 PM
                05/12/2026
                Implement Effective Strategies for Securing Active Directory and Minimizing Data Exposure
                https://www.truthinit.com/index.php/channel/1888/implement-effective-strategies-for-securing-active-directory-and-minimizing-data-exposure/
              • 05/13/2026
                01:00 AM
                05/13/2026
                Transforming the Black Box: Revealing AI Risks and Hidden Threats through Data Lineage
                https://www.truthinit.com/index.php/channel/1890/transforming-the-black-box-revealing-ai-risks-and-hidden-threats-through-data-lineage/
              • 05/13/2026
                05:00 AM
                05/13/2026
                Transforming Black Box to Glass Box: Revealing AI Risks and Hidden Threats through Data Lineage
                https://www.truthinit.com/index.php/channel/1894/transforming-black-box-to-glass-box-revealing-ai-risks-and-hidden-threats-through-data-lineage/
              • 05/19/2026
                01:00 PM
                05/19/2026
                Spring of Satori: A Deep Dive into 2026's Threat Landscape and Findings
                https://www.truthinit.com/index.php/channel/1930/spring-of-satori-a-deep-dive-into-2026s-threat-landscape-and-findings/
              • 05/21/2026
                11:00 AM
                05/21/2026
                The Autonomous Era: Orchestrating a Resilient Enterprise
                https://www.truthinit.com/index.php/channel/1372/the-autonomous-era-orchestrating-a-resilient-enterprise/
              • 05/27/2026
                04:00 AM
                05/27/2026
                Rivoluziona i rischi dell'AI in opportunità con Netskope AI Security
                https://www.truthinit.com/index.php/channel/1925/rivoluziona-i-rischi-dellai-in-opportunità-con-netskope-ai-security/
              • 05/28/2026
                10:00 AM
                05/28/2026
                Transforming AI from fantasy to purposeful management
                https://www.truthinit.com/index.php/channel/1924/transforming-ai-from-fantasy-to-purposeful-management/

              Upcoming Events

              • Apr
                30

                Insights into SaaS Data Protection from the Keepit Annual Data Report 2026

                04/30/202610:00 AM ET
                • Apr
                  30

                  The New Economics of a VMware Exit

                  04/30/202601:00 PM ET
                  • May
                    06

                    Detecting Cyber Attacks Before They Evolve Into Breaches with AI Insights

                    05/06/202602:00 AM ET
                    • May
                      06

                      World Password Day: Strategies for Managing Your Passwords Effectively.

                      05/06/202610:00 PM ET
                      • May
                        07

                        World Password Day: Strategies for Managing Your Passwords Effectively.

                        05/07/202605:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version