Securing Databases with Dynamic Credentials and Vault
Thomas Kula
Sr. Solutions Engineer
github.com/thomashashi/hashihang-dynamic-db-creds
Applications Stacks Are Changing
What used to work
Applications Stacks Are Changing
No longer scales
The Challenges
● Short-lived dynamic infrastructure shares long-lived static secrets
● A secrets problem with one instance is a problem for all instances
● Rolling out new secrets takes a long time - time you may not have
● Identifying the scope of problems is a challenge
The Solution: Dynamic Secrets
● Short-lived, per-instance credentials
● Secret lifetime matches instance lifetime
● A problem in a single instance affects only that instance
● Discovering the scope of problems is much easier
Securing Databases with Dynamic Credentials and Vault
DEMO
www.hashicorp.com
hello@hashicorp.com
Q & A
Securing Databases with Dynamic Credentials and Vault
Thomas Kula
Sr. Solutions Engineer
github.com/thomashashi/hashihang-dynamic-db-creds

Securing Databases with Dynamic Credentials and HashiCorp Vault