Home / Companies / HashiCorp / Blog / September 2020

September 2020 Summaries

24 posts from HashiCorp

Filter
Month: Year:
Post Summaries Back to Blog
HashiCorp Consul Service (HCS) on Azure can now be managed using Terraform Cloud, allowing for greater collaboration and automation of cloud networking. HCS provides a fully-managed service for cloud networking automation, enabling customers to discover and automate connections between services running in both Azure Kubernetes Service clusters and Azure VMs without worrying about managing their own Consul deployment. Terraform Cloud can be used to manage the deployment of HCS and services that interact with it, layering on additional guardrails to ensure consistent and compliant changes. By using Terraform Cloud, customers can enable multiple operators to interact with the HCS environment while maintaining control over their infrastructure as code. The process involves setting up a Git repository, configuring Terraform Cloud variables, and then configuring the Consul Terraform provider. This allows for the deployment of workloads into HCS on Azure, enabling the setup of intentions to allow communication between services. By using this approach, customers can automate the management of their Consul environment and ensure consistent configuration across multiple environments.
Sep 30, 2020 1,666 words in the original blog post.
Vault-generated dynamic credentials can be used to provision infrastructure by storing long-lived AWS credentials in Vault's AWS Secrets Engine and leveraging Terraform's Vault provider to generate short-lived, appropriately scoped credentials. This approach eliminates the need for direct access to secrets and allows operators to manage permissions by modifying a Vault role's policy instead of managing static, long-lived secrets with varying scope. By using this method, developers can securely provision resources in AWS without compromising their security or freedom as developers.
Sep 28, 2020 207 words in the original blog post.
HashiCorp has released a suite of Terraform modules for Consul, Nomad, and Vault, providing an opinionated implementation of their Reference Architecture for AWS. These modules aim to accelerate the setup of infrastructure for these products by supplying default values that bring up the necessary infrastructure according to HashiCorp's Enterprise Architecture group recommendations. The modules are designed to be flexible and can be used as quickstarts for new practitioners or as references for more experienced users who want to control configuration manually. The release is part of HashiCorp's effort to encourage remixing and collaboration, with an open-source approach that invites feedback and contribution from the community.
Sep 28, 2020 543 words in the original blog post.
HashiCorp's Nomad 0.12 was announced during HashiConf Digital in June, featuring notable additions such as the Nomad Autoscaler and a new spread-based ranking algorithm to improve resource utilization and reduce waste. The feature updates were well-received by the community, with some highlighting its potential to optimize performance and minimize hotspots. In addition to the keynote, the event offered various talks, workshops, and resources on-demand, including tutorials and panels focused on Nomad networking and security. The HashiCorp team will continue to release new features and updates in the coming months, with upcoming announcements at HashiConf Digital this October.
Sep 25, 2020 514 words in the original blog post.
HashiCorp has released an official Homebrew Tap for macOS, allowing users to easily and securely install Consul, Nomad, Terraform, Packer, and Vault using the popular package manager Homebrew. This tap provides a smoother experience by maintaining up-to-date binaries that are signed by HashiCorp, ensuring secure installations. With this Tap, users can automate updates and focus on learning and using the products without worrying about configuration details. The installation process is streamlined, making it easier for developers to get started with HashiCorp tools.
Sep 25, 2020 422 words in the original blog post.
HashiCorp has announced its Early Career Program aimed at building a diverse generation of technology experts. The program originated from the company's founders' experience as students working on a research project to make cloud technologies available to scientists, which ultimately led to the development of HashiCorp's core products. With over 85% of employees being remote since day one and recognizing the value of innovation and entrepreneurship, HashiCorp is committed to creating an inclusive program that attracts individuals with non-traditional paths to the tech space. The first cohort of student interns will join in summer 2021, followed by new grads in summer 2022, and will have opportunities to work on projects, participate in product certification programs, and develop skills such as business communication and professionalism.
Sep 24, 2020 672 words in the original blog post.
HashiCorp has surpassed 1,000 employees, a milestone achieved through strategic team building and growth across various functions, including Developer Relations, Engagement, Inclusion, Diversity, Design, Sales, Total Rewards, and Talent Acquisition. The company's remote-centric culture, which was already well-suited for remote work before the pandemic, allowed it to easily adapt to the shift in work environment. To celebrate this milestone, HashiCorp spoke with some of its newest employees who shared their reasons for joining the company and what they're most excited about, including opportunities to work on innovative products and contribute to a culture that values principles such as the Tao of HashiCorp. As the company continues to grow, it's looking for world-class talent to join its team across all departments and geographies, with a focus on candidates who are self-starters, can work well in asynchronous communications, and align with the company's culture and values.
Sep 23, 2020 1,278 words in the original blog post.
You can use Auth0 as an identity provider for Single Sign-On into Terraform Cloud Business Tier using the SAML 2.0 integration by setting up Auth0 and Terraform Cloud, including creating a new application in Auth0, configuring the SAML2 WEB APP addon, mapping claims, and setting up the Identity Provider Metadata URL. You can then access the SSO setup menu in Terraform Cloud, paste the Identity Provider Metadata URL, remove Google Analytics query strings, turn off team management, and copy the Assertion Consumer Service URL. Once saved, you enable the SAML login on Terraform Cloud and test the SSO by logging in with an Auth0 login window that appears after clicking a link. After linking your account, you can access workspaces once assigned to a team.
Sep 23, 2020 727 words in the original blog post.
Vault AIDE is a chatbot solution that connects to Slack and provides real-time operational insights on HashiCorp Vault, a secrets management tool. It helps Service Reliability Engineers (SREs) better manage the Vault platform by providing early warnings for high-privilege actions and ensuring best practices are followed. The chatbot analyzes logs from HashiCorp Vault and sends notifications to Slack channels with reliable data in real-time. This allows SREs to take action quickly, preventing security breaches. Vault AIDE is a python process that runs independent of the Vault implementation, consuming only relevant information about user actions and displaying it on Slack. It provides various benefits, including enhancing customer experience, improving operational efficiency, and reducing the cost of customer service. The tool is designed for both technical and non-technical users, providing valuable insights into Vault's impact on an organization.
Sep 22, 2020 1,262 words in the original blog post.
To help you through your Kubernetes adoption journey, a new collection of Terraform tutorials has been created. You can provision a Kubernetes cluster on popular cloud providers such as AWS, Azure, or Google Cloud using these tutorials. Leveraging both Terraform modules and resources, the tutorials will guide you through provisioning a functional cluster that you can connect to and interact with. Additionally, you can use the Terraform Kubernetes provider to manage your newly provisioned Kubernetes cluster, schedule resources like an NGINX instance, scale it easily, and deploy a Consul-backed Vault cluster on Kubernetes. The tutorials also highlight best practices for code management and modules using Terraform Cloud (TFC).
Sep 21, 2020 471 words in the original blog post.
HashiCorp's Developer Advocates team tapped Rob Barnes, who had recently joined the company, to co-emcee HashiConf Digital in June 2020. This was a significant moment for Rob, as he transitioned from being an attendee at previous conferences to hosting one himself. As an African living in the UK, Rob saw this opportunity as important for representation and visibility within the tech community. Despite feeling nervous about taking on the role, Rob's experience was shaped by his unique challenges, including live Q&A discussions with split-second delays and a lack of awareness from the audience that he couldn't hear them due to being deaf in one ear. The production team, led by "Dad," provided creative freedom while also following a script to ensure a smooth delivery. Throughout the conference, Rob's burps became a recurring joke, with the team recording them and even creating a "burp counter." Despite the challenges, Rob found the experience to be a learning one, particularly in adapting to live communication with his deafness. The event was well-received by attendees, who praised its energy and positive atmosphere.
Sep 18, 2020 2,135 words in the original blog post.
HashiCorp Consul Service (HCS) is now available on Azure Production tier, enabling users to deploy production-grade Consul clusters directly from the Microsoft Azure portal. This offering provides a pay-as-you-go pricing structure and highly available, fully managed clusters backed by an uptime SLA, making it ideal for organizations that need fluctuating demands efficiently. HCS enables secure service-to-service communication, automated network configuration, and service discovery, as well as supporting modern application networking features such as progressive application delivery, zero-trust security, and service level observability. The new Production tier supplements the Development and Annual tiers, offering discounted rates for annual commitments and access to enterprise features like namespaces, audit logging, and single sign-on.
Sep 17, 2020 595 words in the original blog post.
Consul's Ingress gateways and Terminating gateways are incredibly useful for integrating workloads that are not service mesh enabled, allowing traffic to safely enter and exit the mesh while enforcing mTLS and network policies. Consul's L7 traffic management features enable advanced rollout methods like canary testing and blue-green deployments through HTTP path-based traffic routing, traffic shifting, and traffic splitting. These features leverage a 3-stage process to resolve upstream services, applying logic at the proxy/Consul layer for resolution, splitting, and routing. Consul provides service discovery, automatic service-to-service encryption, identity-based authorization, and network policy enforcement, making it a powerful tool for improving deployment workflows in hybrid environments.
Sep 16, 2020 2,387 words in the original blog post.
Packer and Cloud-init are tools used to provision infrastructure when using Terraform, allowing for repeatability in image deployment or built-in tools. Packer builds machine images with common dependencies, while Cloud-init uses a scripting language to configure instances. Terraform practitioners can use these tools following HashiCorp's recommended best practices to prepare their infrastructure for software installation and application deployment.
Sep 16, 2020 237 words in the original blog post.
A HashiCorp Terraform example demonstrates how to automate least-privilege access to Consul using Vault, ensuring secure access control and scalability. By defining policies as code with Terraform, teams can collaborate on Consul ACLs and maintain security through infrastructure as code practices. The use of the Consul secrets engine generates dynamic ACL tokens on-demand, handling token lifetimes, and automating token renewal or revocation when necessary. This approach enables secure collaboration and scaling of Consul ACL policies while maintaining visibility into access control changes.
Sep 15, 2020 2,527 words in the original blog post.
The HashiCorp Vault GitHub Action is an officially supported action that allows users to easily inject secrets from their HashiCorp Vault infrastructure into GitHub workflows, automating CI/CD developer workflows. This action was originally created by Richard Simpson and has been taken over by HashiCorp for long-term support. It enables teams to securely store and control access to tokens, passwords, certificates, and encryption keys, allowing them to protect machines and applications. The action can be used to trigger events based on how code is built, tested, or deployed, and can be integrated with GitHub Actions to inject secrets into CI/CD pipelines just in time for API key retrieval or other tasks that require secret injection. Users can authenticate with HashiCorp Vault using a token, AppRole, or GitHub auth methods, and fetch a variety of secrets based on their policy's access. The action is well-suited for use with self-hosted runners to connect to HashiCorp Vault over internal networks.
Sep 14, 2020 706 words in the original blog post.
F5 BIG-IP has been integrated with Consul to enable secure communication between Consul service mesh applications and non-mesh services, such as managed database services. This integration allows organizations to securely route traffic from their mesh-based services to external services in the same logical network, while also enabling secure connections using mTLS. The use of terminating gateways provides a scalable solution for routing traffic, with centralized configuration allowing multiple gateway instances to be registered and configured without additional setup. By leveraging this integration, organizations can simplify and secure communications between their modern mesh-based applications and external non-mesh services, regardless of whether they are on-premise or in the cloud.
Sep 11, 2020 405 words in the original blog post.
HashiCorp's annual gathering of practitioners, HashiConf, was transformed into a digital event called HashiConf Digital due to the situation at hand, allowing more than 6500 attendees to participate over three days with sold-out workshops and great conversations. The latest edition of HashiConf featured the announcement of Terraform 0.13, which brings significant changes to developer experience, including improved type systems, contextual error messages, and reusable infrastructure components through modules. Additionally, Terraform 0.13 introduces a new validation syntax for variables, allowing operators to write more robust code with custom validation rules. The release of version 2.0.0 of the Terraform Extension for Visual Studio Code also includes support for Terraform 0.12 and 0.13 syntax, as well as improved autocompletion for cloud providers. HashiCorp's senior engineer Kristin Laemmert discussed the reasoning behind not yet releasing Terraform 1.0, citing concerns over backward compatibility and product stability. The Terraform Registry has seen rapid adoption and expansion of supported services, with automatic installation of providers through terraform init.
Sep 11, 2020 682 words in the original blog post.
HashiCorp Terraform was used by Redapt to help a SaaS company provision and manage multiple Kubernetes clusters on-premises and in various public clouds. The client needed a solution that could work across multiple infrastructure providers, including AWS, and allow for disaster recovery while maintaining the benefits of Terraform pipelines. Redapt used Terraform Enterprise and a custom Rancher plugin to create a workflow that enabled the client to deploy Rancher, manage upgrades, and handle disaster recovery. The solution involved using Terraform state manipulation procedures, such as import, pull, and push, to restore the cluster in case of a disaster, while also ensuring that Terraform could continue to manage the cluster after the restoration process.
Sep 10, 2020 809 words in the original blog post.
Terraform Cloud's Business tier introduces enterprise-class features, including Single sign-on, self-hosted agents, audit logging capabilities, and a new API service called Audit Trails, which provides a JSON-based API to retrieve audit events for the entire organization. The Terraform Cloud for Splunk app integrates Terraform Cloud's audit logging with customers' existing Splunk Cloud or Splunk Enterprise implementations, providing near real-time visibility into key actions. With this integration, organizations can gain visibility across their entire Terraform organization and have a historical record of exactly what is happening, enabling them to identify trends, detect anomalies, and optimize their operations.
Sep 10, 2020 1,096 words in the original blog post.
Sentinel is a policy as code framework that enables DevOps teams to apply fine-grained logic-based policy controls against critical services. The Sentinel Playground provides a zero-install development environment for learning and experimenting with policy as code, allowing users of all skill levels to practice writing policies without installing runtime environments. The Playground includes an out-of-box policy example, mock data, and support for parameters and testing, enabling users to quickly prototype functions and rules. With the release of the Playground, customers can now access a core feature set and expand to include Azure and GCP services in future releases.
Sep 09, 2020 728 words in the original blog post.
HashiCorp Vault is now validated on Google Cloud Platform's Confidential Computing service, allowing organizations to securely store and control access to sensitive data. This integration enables teams to protect machines and applications by extending confidentiality to the HashiCorp Vault server's system memory, ensuring that malware or malicious users cannot compromise data. With Confidential Computing, data is encrypted in use without requiring code changes or performance degradation, providing additional levels of cryptographic isolation when processing secrets in memory. The partnership between HashiCorp and Google Cloud enables organizations to eliminate system complexity and manage their most critical secrets and assets throughout the entire life cycle.
Sep 09, 2020 569 words in the original blog post.
The key points of the text are that engineers are becoming the new financial controllers of cloud spend due to finance teams losing control over infrastructure consumption models. To manage this, HashiCorp's Terraform Cloud provides a platform for automating cloud cost optimization and governance. The guide outlines how to use Terraform to define roles, processes, and technologies associated with managing cloud financial practices. It covers planning, optimization, and governance aspects of cloud cost management, including using Terraform's Cost Estimation features, integrating third-party cost optimization tools, and implementing Sentinel policies for cost and security controls. The goal is to provide a feedback loop to ensure future cost savings and prevent waste.
Sep 03, 2020 3,278 words in the original blog post.
Ample Organics, a world leader in providing cannabis tech solutions, has implemented HashiCorp Nomad as its replacement for Kubernetes, resulting in improved efficiency, reliability, and reduced operating costs. The company had previously struggled with Kubernetes' limitations, including manual management of hundreds of clusters and limited scalability, which hindered new product development and feature deployment. With Nomad, Ample Organics can now streamline its app development and deployment processes, deploy services across multiple cloud environments, and create an agnostic platform for rolling out its services quickly and efficiently. The company has seen significant improvements in its operations, including reduced operating costs and increased shipping capacity, with virtually zero downtime.
Sep 03, 2020 914 words in the original blog post.