Home / Companies / HashiCorp / Blog / June 2022

June 2022 Summaries

21 posts from HashiCorp

Filter
Month: Year:
Post Summaries Back to Blog
HashiCorp Waypoint 0.9 introduces on-demand runner introspection, an install command for runners, and support for HashiCorp Cloud Platform (HCP) Waypoint. This update adds several significant new features that allow operators to have more control over where runners are provisioned and how to gather information on what Waypoint is doing with remote-enabled projects. The new `waypoint runner install` command makes it easier to install a static runner to your infrastructure, and to start remotely building, deploying, and releasing anywhere. Additionally, the concept of a project within the Waypoint data model will be removed in favor of a single application configuration in the `waypoint.hcl` file. This change aims to improve the overall understanding of Waypoint and provide better workflows for users who are using a monorepo pattern. The list of new features and improvements is available in the CHANGELOG, and users can learn more about Waypoint with tutorials on the HashiCorp Learn site or contribute to its open source project.
Jun 30, 2022 1,412 words in the original blog post.
HashiCorp's employee resource group, the Blacksmiths, shared their experiences celebrating Juneteenth this year. Members from different locations in the US attended various events and activities, including a Suns of Re-Awakening 5th Annual Juneteenth Celebration in Frederick, MD, Pharrell's Something in the Water Festival in Washington, DC, and a Juneteenth Block Party in Philadelphia. They learned about the history and significance of Juneteenth, which commemorates the emancipation of enslaved African Americans in the US. The employees reflected on what they learned and how they celebrated with their families, including teaching children about the importance of Juneteenth and attending Black-owned businesses to show support. The events highlighted the need for continued awareness and action towards creating an equitable society.
Jun 29, 2022 1,416 words in the original blog post.
This solution provides a centralized network log storage, durable long-term archiving, and alert notifications for critical Vault events. It uses syslog-ng to forward logs from Vault nodes to a central log server, which buffers the audit logs locally before forwarding them to a remote log server. The remote log server is configured to send alerts to Slack when certain conditions are met in the audit or server logs. The solution also includes a log rotation mechanism and can be deployed using Terraform code. It costs only a few dollars a month in AWS compute charges for small installations, making it an affordable option for teams without access to a highly available logging and alerting system.
Jun 28, 2022 2,912 words in the original blog post.
HashiCorp Cloud Platform has introduced several new capabilities, including managed services for HashiCorp Boundary and Waypoint, and Drift Detection for Terraform Cloud. The platform is expanding its offerings to address the growing demand for cloud services, which offer better ROI than running applications in-house. This includes a public beta for HCP Boundary, which secures access to applications with fine-grained authorizations; a managed service version of HCP Waypoint, which eases adoption for platform teams and improves integration with GitHub; Drift Detection for Terraform Cloud, which monitors conditions to identify resources that have changed and notifies operators to take remediation steps; and an expansion of HCP Consul to Microsoft Azure. Additionally, HashiCorp is offering a $50 credit to new users who create an account and spin up their first cluster on the platform.
Jun 23, 2022 968 words in the original blog post.
HashiCorp Consul on Amazon Elastic Container Service (ECS) version 0.5 is now generally available, adding support for AWS IAM authentication and mesh gateways. This release enables services to communicate across multiple runtimes and clouds, reducing risk by enforcing consistent end-to-end security for service communication. The new authentication method allows using AWS IAM identities for authenticating to Consul to receive Consul ACL tokens, eliminating the need for polling and storing tokens in AWS Secrets Manager. Mesh gateways are also supported, enabling cross-datacenter or cross-partition communication over a WAN, and reducing risk by enforcing consistent end-to-end security for service communication. The configuration process involves using Terraform modules, such as `acl_controller` and `mesh-task`, to deploy the Consul service mesh and configure mesh gateways on ECS.
Jun 23, 2022 1,361 words in the original blog post.
Vault 1.11 focuses on improving its core workflows and making key features production-ready, including a new Kubernetes secrets engine that dynamically generates credentials for Kubernetes service accounts, improved KV (key-value) secrets engine usability, support for the PKI engine for non-disruptive rotation, enablement of bring your own key (BYOK) for Transit, and many other improvements. The release also includes integrated storage autopilot with seamless automated upgrades and redundancy zones to improve cluster resiliency, as well as updates to the KV secrets engine utilities, Transform secret engine, and other features such as Kubernetes Helm chart and agent sidecar injector, Kubernetes Vault CSI provider, and mount filters support removal.
Jun 22, 2022 1,689 words in the original blog post.
HCP Consul on Azure becomes generally available, offering a production-ready service mesh deployment on either AWS or Azure infrastructure. This enhances users' choice of cloud platforms for their workloads and brings the company one step closer to providing consistent platforms across multiple clouds. The new feature allows users to deploy redundant versions of logical gateways with highly available gateway instances, giving them greater control over scaling instances using a single command. Consul API Gateway version 0.3 is now generally available, featuring highly available gateway instances that add resilience and control for scaling logical gateway instances. Additionally, AWS Lambda support has been released in beta, allowing users to make applications aware of Lambda functions and set up intentions for traffic management. The upcoming release of Consul 1.13 will feature cluster peering, simplifying the connection of multiple Consul servers and sharing information between datacenters while maintaining isolation at the administrative level.
Jun 21, 2022 903 words in the original blog post.
Cluster peering in Consul 1.13 introduces a new model for cross-cluster federation, enabling connectivity between independently managed Consul clusters or Admin Partitions. This feature provides fine-grained connectivity, minimal coupling, operational autonomy, and support for hub-and-spoke peering relationships, allowing customers to securely connect applications across internal and external organizational boundaries while maintaining security through mutual TLS. Cluster peering is not intended to immediately replace WAN federation but offers greater flexibility in connecting services across organizational boundaries, and the Consul team invites feedback on this new feature.
Jun 21, 2022 734 words in the original blog post.
The latest release of HashiCorp's Consul API Gateway allows users to generate multiple instances of a logical gateway, providing greater control, consistency, and resilience in their deployments. This feature enables users to deploy highly available (HA) gateway instances in a Kubernetes cluster, ensuring consistent access to environments even in the event of pod outages or sudden spikes in external client traffic. The new release allows users to scale up the number of logical gateway instances to meet increased demand without reconfiguring their existing deployment, while also providing resilience through multiple instances and leveraging perimeter security solutions for client requests.
Jun 21, 2022 775 words in the original blog post.
HashiCorp Boundary is now available as a managed service on the HashiCorp Cloud Platform in public beta, offering secure remote access to critical infrastructure across cloud service catalogs, on-premises infrastructure, and Kubernetes clusters without requiring manual management of underlying systems or operations. The solution automates user and target onboarding, streamlines connection to hosts and targets, and integrates with leading identity providers and service catalogs to provide a single, fully managed workflow for secure remote access. By abstracting away complexity, HCP Boundary provides users with a simplified onboarding experience that reduces the risk of credential compromise, while also protecting and safeguarding access to applications and critical systems without exposing underlying networks. The solution is designed to put developers and technical users at the forefront of its access design, automating workflows for both user and target onboarding, and enables operators to keep users and targets up-to-date in cloud environments.
Jun 21, 2022 992 words in the original blog post.
HashiCorp has introduced a new documentation platform, HashiCorp Developer site, which aims to enhance the developer experience by consolidating resources such as interactive lab environments, tutorials, and reference docs for all HashiCorp products. The unified web experience combines documentation, tutorials, sample code, explainer videos, and hands-on lab environments in a single platform at developer.hashicorp.com. A public beta of this site is now available with sections for Vault and Waypoint, while other product sections will be added as the platform progresses towards its General Availability release later this year.
Jun 20, 2022 501 words in the original blog post.
HashiCorp has introduced Drift Detection for Terraform Cloud in public beta, a feature that continuously checks the infrastructure state to detect changes and notify operators. This new capability enhances HashiCorp's Terraform offerings by providing continuous visibility into multi-cloud infrastructure states. Drift Detection follows the release of Terraform 1.2 and Terraform Run Tasks, which improve efficiency while reducing risks related to security, compliance, and operational consistency. The feature is designed to help organizations maintain accurate infrastructure state as they migrate to the cloud and manage their resources efficiently.
Jun 20, 2022 962 words in the original blog post.
HashiCorp has announced the first step towards launching HashiCorp Waypoint as a managed service on the HashiCorp Cloud Platform (HCP). The company created HCP Waypoint to address operational challenges in the open source version of Waypoint and improve the developer experience. Originally introduced in October 2020, HashiCorp Waypoint is an open-source project designed to provide a consistent way for developers to build, deploy, and release their applications across various platforms using a single file and command: "waypoint up." The HCP Waypoint Private Beta Program has been launched to gain more feedback from early adopters who will be selected to participate in a two-month beta program (July 1 - August 31).
Jun 20, 2022 397 words in the original blog post.
The evolution of infrastructure automation is crucial for modern hybrid and multi-cloud environments, as traditional on-premises data centers become obsolete. Infrastructure automation typically involves three phases: adopting and establishing a provisioning workflow, standardizing the workflow, and operating and optimizing at scale. With 76% of organizations already using multiple clouds and 86% expected to do so by 2023, multi-cloud environments are becoming dominant. However, this brings challenges such as disparate workflows, infrastructure sprawl, siloed teams, and skills gaps. To address these issues, organizations need to adopt a consistent approach to provisioning and managing their cloud infrastructure while ensuring collaboration between teams and addressing any skill gaps.
Jun 20, 2022 597 words in the original blog post.
HashiCorp Consul has released public beta support for AWS Lambda functions within its service mesh. This integration allows services in the mesh to invoke AWS Lambda functions, providing consistent workflows and encrypted communications from all mesh services to upstream workloads including Lambda functions. The new Consul Lambda registrator Terraform module automates the registration of Lambda functions into the service mesh. Service-to-Lambda communication benefits from the same reliability, observability, and security features provided by the Consul service mesh.
Jun 16, 2022 478 words in the original blog post.
HashiCorp has been ranked 28 on the 2022 Great Place to Work and Fortune magazine Best Workplaces in the Bay Area list. The company's People team is dedicated to creating amazing experiences for all employees at every stage of their journey with HashiCorp. The company's culture is centered around its principles, which inform how employees interact with one another and make decisions. Despite being a remote-oriented company, HashiCorp offers a flexible work environment that enables each team member to "work your way." With over 2,000 employees, the company continues to grow and support employee development and career advancement opportunities.
Jun 16, 2022 880 words in the original blog post.
HashiCorp Terraform has integrated with OPA-founder Styra to allow users to validate Terraform infrastructure as code using Open Policy Agent (OPA). This integration aims to help organizations achieve their security and compliance goals by enabling policy as code, which allows teams to define security and compliance requirements within the code. The integration of HashiCorp Terraform with Styra Declarative Authorization Service (DAS) provides detailed policy control over Terraform plans, mitigating risks, reducing human error, and accelerating development. Users can leverage pre-built policies or create custom ones using Rego, the OPA policy language. This integration helps enforce any type of rules on Terraform resources and user actions across multiple workspaces.
Jun 15, 2022 556 words in the original blog post.
After two years as a fully digital event, HashiConf Europe is returning to Amsterdam on 20-22 June 2022 with a hybrid event format. Attendees in Amsterdam will have access to live content across three stages, interactive Dev Lounge, and meals and social events. Virtual attendees can join the livestreamed opening keynote, abridged conference highlights, and virtual instructor-led Learn Labs. The event features keynotes from HashiCorp Co-Founder Armon Dadgar and CEO Dave McJannet, product deep dives, customer and community sessions, and more. Registration is open for both in-person and virtual passes.
Jun 14, 2022 691 words in the original blog post.
At Cisco Live from June 12-16, HashiCorp, a strategic infrastructure automation partner for Cisco, will be attending and sharing updates on their collaboration with Cisco to help organizations manage applications. They have been working together since the announcement of Cisco's collaboration with HashiCorp Terraform in 2021. HashiCorp will be featured in more than 40 Cisco-led sessions, including hands-on labs and workshops. They are also a beta launch partner on Cisco’s newly launched Cisco University, a digital learning experience focused on advancing customers' technology knowledge.
Jun 08, 2022 525 words in the original blog post.
HashiCorp Vault Enterprise 1.10 has been evaluated as conformant with the Federal Information Processing Standard (FIPS) 140-2 standards, making it suitable for use in government and other sensitive information processing environments. The FIPS compliance was confirmed by Leidos through a conformance review. HashiCorp Vault Enterprise now supports two options for FIPS compliance: Seal Wrap feature with an external HSM and the new FIPS enabled build without any external dependencies on an HSM, catering to different organizational needs. The FIPS compliance letters are available on the HashiCorp Vault Compliance page.
Jun 07, 2022 319 words in the original blog post.
MongoDB's field-level encryption (FLE) capability pairs with Vault's KMIP secrets engine to provide strong privacy and security controls for organizations. FLE allows developers to selectively encrypt specific data fields, protecting sensitive information and enhancing communication between client apps and server. By pairing an FTE-capable database with a KMIP provider, the highest level of security and control is achieved. MongoDB's FLE features include protection for data in transit, at rest, and in use, making data unreadable to those running the database, and simplifying enforcement of right-to-erasure mandates. The example FLE flow with a KMIP provider demonstrates how MongoDB and HashiCorp Vault can benefit organizations with security management across their databases and applications.
Jun 02, 2022 593 words in the original blog post.