Integrating AWS SSM and Hashicorp Keyvault

Viewed 32

Currently, we heavily rely on AWS SSM to store and read secrets from. All of our services and CodePipelines use AWS SSM for fetching the secrets.Secret rotation with AWS SSM requires the use of lambda functions, it would get quite tiresome since we have large number of secrets.

We researched about HashiCorp Vault and the two features that we would like to use our Secret rotation and Dynamic secrets. The secret rotation with HashiCorp seems painless as compared to SSM secret rotation.

Is it possible to use both of them together? Basically, the secret rotation would be done by HashiCorp Vault and the new values can be written back to AWS SSM. All the services (such as ECS, Beanstalk) will need to be restarted to fetch the new secrets.

In short, does Vault provide some sort of integration for the above or do I have to include the writing back part in the same secret rotation cron job script for the Vault?

1 Answers

HashiCorp Vault provides functionality of dynamic secretsts so there will be a vault agent which will fetch secrets from HashiCorp Vault and put it into a file or set as an environment variable. Application will read from the file or use environment variables. so you should not use SSM to fully leverage HashiCorp Vault.

But, if you want to use both HashiCorp Vault and SSM then what you can do is like Vault agent will fetch secrets from HashiCorp Vault and there will be a cron job which will change secrets into SSM.

Related