Перейти к содержимому

Migrate Secrets from AWS Secrets Manager to HashiCorp Vault with Terraform

TeKanAid - Platform Engineering and AI

0:00 / 0:00

Migrate Secrets from AWS Secrets Manager to HashiCorp Vault with Terraform

4 217 просмотров · 3 года назад
TeKanAid - Platform Engineering and AI
6,92 тыс. подписчиков
4 217 просмотров · 3 года назад
Learn how to migrate secrets from #aws Secrets Manager to HashiCorp Vault with Terraform. Andrew at Money Leaves Bank finally convinced Claire, his CIO, that HashiCorp #Vault should be their secrets management solution as they are becoming a multi-cloud company. Now he is faced with the challenge of migrating their secrets hosted in AWS Secrets Manager to HashiCorp Vault. In this blog post, learn why Andrew decides to use #terraform for this task and how he implements the solution. To accomplish his task, Andrew considers a couple of options: 1. He could use a multi-purpose language such as Python to get the secrets from AWS Secrets Manager and populate them in HashiCorp Vault 2. Use a wide-spread domain-specific language such as Terraform to do the same task While both options are valid, he considers the expertise within his platform engineering team and finds that his team is more comfortable with Terraform. Moreover, they are adopting a multi-cloud strategy. They just started adding apps to Azure and within 6 months the dev team will build some apps in Google cloud to leverage GCP's machine learning services. He wanted to encourage his team to continue working with Terraform. One downside to using Terraform for this task is that the secrets will show up in Terraform's state file. He needs to plan for this. He decides to use Terraform Cloud to store the state file securely. Once the secrets are moved successfully he can destroy the Terraform workspace to remove all traces of these secrets. ▬▬▬▬▬▬ T I M E S T A M P S ⏰ ▬▬▬▬▬▬ 00:00 - Introduction 00:17 - Scenario 01:36 - Terraform Public Module Overview 03:49 - Terraform101 and Vault101 Announcements 07:07 - Demo Starts 11:52 - Secrets in the State File 12:39 - Important Closing Remarks ▬▬▬▬▬▬▬▬ Useful Links 🛠 ▬▬▬▬▬▬▬ Blog post ► https://tekanaid.com/posts/migrate-se... Code ► https://tekanaid.com/posts/migrate-se... ▬▬▬▬▬▬▬▬▬ Courses 🎓 ▬▬▬▬▬▬▬▬ TeKanAid Academy ► https://tekanaid.com/courses ▬▬▬▬ 🎓 FREE 7-Day Platform Engineering Crash Course ▬▬▬▬ One email a day for 7 days. Real tools, real CLI commands, hands-on labs. Day 1: What is Platform Engineering (the role, the market, why every large org is building a PE team) Day 2: Infrastructure as Code with Terraform Day 3: Containers and Kubernetes Day 4: Policy as Code (OPA + Sentinel) Day 5: CI/CD and GitOps (GitHub Actions + ArgoCD) Day 6: Observability and Security Day 7: Building Your Internal Developer Platform with Backstage + your 6-month career roadmap 👉 Sign up free: https://tekanaid.com/platform-enginee... ▬▬▬▬▬▬▬▬ 🛠️ Recommended Tools ▬▬▬▬▬▬▬▬ Cloud hosting, infra, and tooling I recommend for AI Platform Engineering. Includes affiliate links that help fund TeKanAid Academy at no cost to you. 👉 https://tekanaid.com/recommended-tools ▬▬▬▬▬▬▬▬ Connect 👋 ▬▬▬▬▬▬▬▬▬ TeKanAid Academy ► https://tekanaid.com/courses Website ► https://tekanaid.com Facebook Page ►   / tekanaid   Don't forget to subscribe ► https://bit.ly/TeKanAid_YouTube_Subsc... MEDIUM ►   / sam-gabrail   TWITTER TeKanAid ► https://x.com/tekanaid TWITTER Sam ► https://x.com/Sam_Gabrail LINKEDIN TeKanAid ►   / tekanaid   LINKEDIN Sam ►   / samgabrail