15–19 Apr 2024
Laboratoire Astroparticule et Cosmologie (APC) de l'Université Paris-Cité
Europe/Paris timezone

Secret management with HashiCorp Vault at DESY

19 Apr 2024, 11:35
25m
Amphithéatre Buffon (Laboratoire Astroparticule et Cosmologie (APC) de l'Université Paris-Cité)

Amphithéatre Buffon

Laboratoire Astroparticule et Cosmologie (APC) de l'Université Paris-Cité

15 rue Hélène Brion 75013 Paris France
Basic and End-User IT Services Basic and end-user IT services

Speaker

Kai Wiemann (DESY Hamburg)

Description

An important aspect of IT security is the management, controlled sharing and storage of sensitive data such as passwords or API tokens. In this talk we present how HashiCorp Vault is used at DESY to address this challenge and how the system is integrated into workflows like certificate management and the existing IT infrastructure such as Puppet and GitLab. As secret management is a critical component for site operations, we describe how we aim for a fault tolerant and hardened setup.

Desired slot length 20 minutes
Speaker release Yes

Author

Kai Wiemann (DESY Hamburg)

Co-authors

Krunoslav Sever (Deutsches Elektronen-Synchrotron DESY) Mr Maximilian Kölpin (DESY Hamburg) Sven Sternberger (DESY) Thomas Hartmann (Deutsches Elektronen-Synchrotron (DE))

Presentation materials