June 2023 Summaries
15 posts from HashiCorp
Filter
Month:
Year:
Post Summaries
Back to Blog
HashiCorp has acquired BluBracket, a startup that specializes in secret-scanning functionality to help prevent accidental leaks and fight secret sprawl. The acquisition will complement HashiCorp Vault's secrets management capabilities by integrating BluBracket's detection and remediation workflows into Vault. BluBracket's product helps companies ship secure code without compromising development speed or changing developer workflows, addressing key problems such as secret detection and managing the lifecycle of secrets. The combined entity aims to provide a more comprehensive lifecycle of managing secrets and deliver a more secure-by-default experience for customers.
Jun 27, 2023
811 words in the original blog post.
Terraform Cloud Plus offers continuous validation to ensure infrastructure is working as expected, providing long-term visibility and checks for health and security. Users can create assertions in their Terraform configuration using check blocks, which are a new HCL language feature that allows users to define custom condition expressions and error messages. Continuous validation helps identify issues when they first appear, allowing users to take immediate actions to remedy the situation. The feature provides visibility into infrastructure's health and security, including service configuration, identity and access management, or business logic, ensuring infrastructure is working as expected. Users can create assertions for various use cases, such as AWS Budgets, Google Cloud Functions, Azure App Service Certificates, and more. By using Terraform Cloud Plus, users can gain visibility into their infrastructure's health and security, enabling them to take proactive measures to prevent issues from occurring.
Jun 26, 2023
2,613 words in the original blog post.
The HashiDays London event marked a shift from the traditional two-day conference format to a single-day event, with multiple locations across Europe. As a HashiCorp Ambassador, Chris van Meer attended the event alongside three colleagues and experienced firsthand the excitement and energy of the gathering. The keynote session featured Armon Dadgar, CTO and Co-Founder of HashiCorp, who shared insights into the 2023 HashiCorp State of Cloud Strategy Survey, highlighting the skills gap as a major barrier to cloud adoption. Chris was impressed by the numerous HashiCorp User Groups operating globally, indicating a growing community. The event showcased new features for HashiCorp Terraform, Vault, Boundary, and Consul, including HCP Vault Secrets, Vault Secrets Operator for Kubernetes, and cluster peering for Consul. These updates aimed to simplify cloud management and improve security. Attendees also participated in breakout sessions, learn labs, and networking opportunities, with a focus on cloud migration and skills development. The event reinforced the importance of addressing the skills gap in the industry, particularly in cloud adoption.
Jun 23, 2023
1,666 words in the original blog post.
HashiCorp Vault 1.14 introduces several key updates, including the general availability of the Vault Secrets Operator, which connects Vault secrets directly into native Kubernetes secrets, simplifying secrets management and returning control to security and operations teams. The release also includes support for Automated Certificate Management Environment (ACME) PKI, a new OpenLDAP secrets engine, multi-issuer functionality for the Vault Terraform provider, and improved replication and licensing utilization. Additionally, Vault 1.14 introduces user experience improvements, such as sidebar-based navigation, dismissable banners, and enhanced PKI management, as well as environmental variable injection with Vault Agent. The release also includes support for static users in the AWS secrets engine and various bug fixes and new features.
Jun 22, 2023
1,531 words in the original blog post.
Watch this 10-minute video for an insightful overview of the survey’s key findings and how HashiCorp can help your organization make the most of the cloud. The 2023 State of Cloud Strategy Survey, conducted by Forrester Consulting and commissioned by HashiCorp, surveyed nearly a thousand practitioners and decision makers from around the world to uncover insights about how organizations are adopting cloud technologies. Operational cloud maturity, defined as the adoption of a combination of technological and organizational best practices at scale, is crucial for successful multi-cloud adoption. Highly mature companies that combine technical and organizational best practices, such as platform teams, gain better outcomes in their cloud implementations. Cloud spending has increased by 56% over the past year, with highly mature organizations boosting their spending by an average of 16%. Platform teams are a key factor in achieving high maturity, with 92% of respondents adopting or scaling them. Security is a top barrier to multi-cloud adoption, but also a major benefit, as it can force security out of necessity and encourage organizations to create a unified security strategy. To achieve success, organizations must establish a platform team, leverage partners and services to overcome skill barriers, and prioritize security when approaching multi-cloud. By adopting these practices, companies can reach true multi-cloud maturity and reap the benefits of cloud adoption.
Jun 20, 2023
1,600 words in the original blog post.
HashiCorp Consul 1.16 introduces new features for reliability, scalability, security, service mesh UX, extensibility, and service discovery, including sameness groups for seamless service failover between clusters, enhanced control plane protection with per-IP rate limits, FIPS 140-2 compliant builds, JWT auth for service-to-service traffic, transparent proxy mode for failover and virtual services, permissive mTLS, simplified API Gateway installation on Kubernetes, and extensions for Envoy such as external AuthZ, property override, Wasm, and improved service discovery with catalog sync support for health checks and ingress resources. These updates aim to enhance enterprise readiness, simplify the user experience, speed app deployments, and bolster application security in a mesh.
Jun 13, 2023
1,762 words in the original blog post.
Terraform Cloud introduces an explorer for workspace visibility and upcoming ephemeral workspaces, enhancing security and management capabilities. The new features include config-driven import, continuous validation with Terraform checks, and improved security measures such as dynamic provider credentials and Vault-backed authentication. These enhancements aim to simplify infrastructure management, reduce risks, and optimize costs for organizations using Terraform Cloud. With the introduction of ephemeral workspaces, customers can set timeouts to automatically destroy temporary resources, reducing infrastructure costs and simplifying workspace management. The new features are designed to provide a more automated, efficient, and secure way to plan multiple imports with existing VCS, UI, and CLI workflows, eliminating the complexity of coordination across multiple users. Continuous validation ensures infrastructure works as expected by sending notifications immediately when things fail, allowing customers to quickly take action to remedy the situation. The new features are available in Terraform Cloud, providing a unified workflow for all infrastructure resources and reducing risks associated with managing credentials and state.
Jun 13, 2023
1,512 words in the original blog post.
The Vault Secrets Operator for Kubernetes provides a first-class integration between HashiCorp's Vault and the Kubernetes platform, enabling native synchronization of secrets between the two systems. This allows developers to centrally store, access, and sync secrets when and where they need them, providing a complete solution for modern secrets management. The operator helps create an operational boundary between SecOps and engineering teams, allowing SecOps to define, enforce, and control security policies independent from development. It also supports multiple authentication methods, including Kubernetes, JSON Web Token (JWT), AppRole, and AWS, as well as validations for common cloud services like AKS, GKE, EKS, and OpenShift. The GA release includes several updates, such as revoking cached Vault client tokens upon Operator deletion and improved security features.
Jun 13, 2023
1,295 words in the original blog post.
The HashiCorp Cloud Platform (HCP) Consul management plane now offers enhanced capabilities, including cloud-based observability, allowing operators to gain deeper insights into their Consul deployments. This feature provides telemetry extraction, metrics storage, and visualizations, making it easier for operators to troubleshoot and monitor their Consul infrastructure. Additionally, the management plane enables cluster linking in both virtual machine and Kubernetes environments, supporting both open source Consul and Consul Enterprise. Cluster peering controls are now generally available, allowing operators to establish cross-cluster connectivity using a single interface. The HCP Consul management plane is now live with no cost, offering $50 credits for new users to get started.
Jun 13, 2023
937 words in the original blog post.
HashiCorp has a major presence at AWS re:Inforce, showcasing its security solutions and collaborations with AWS, including the Security Partner of the Year award. HashiCorp's cloud security platform provides a zero-trust architecture to manage access to applications, systems, and endpoints. The company has announced several new integrations, including syncing secrets with AWS Secrets Manager, using dynamic credentials, and integrating Boundary Enterprise with the AWS host catalog. Additionally, HashiCorp Cloud Platform offers a fully managed platform for its suite of security solutions, including Vault, Consul, and Boundary, to secure applications, networks, and human access delivered on AWS.
Jun 13, 2023
1,508 words in the original blog post.
HashiCorp has released HashiCorp Boundary 0.13, which includes major new functionality such as SSH session recording capability and a new self-managed edition called HashiCorp Boundary Enterprise. This allows organizations to deploy Boundary in their desired public or private clouds to securely access hosts and services consistently across any environment. The release also introduces LDAP authentication methods and managed groups, enabling integration with directory services directly via the LDAP protocol. Additionally, HCP Boundary now includes maintenance windows that allow customers to select a time window for updates to prevent disruptions. With these new features, Boundary becomes an even more powerful tool for identity-based network access.
Jun 13, 2023
1,096 words in the original blog post.
HCP Vault Secrets is a new SaaS-based secrets management platform that enables developers to centrally store, access, and sync secrets when and where they need them. The platform was launched at HashiDays on June 13, 2023, as a public beta offering on the HashiCorp Cloud Platform, with a focus solely on secrets management. It aims to address customer challenges around secret sprawl and improving security posture while maintaining development agility. HCP Vault Secrets offers both pull and push models for integrating secrets into development workflows, centralizes secrets lifecycle management, syncs secrets across teams, and prioritizes developer flexibility. The platform is fully managed by HashiCorp and available on the HashiCorp Cloud Platform, allowing users to get up and running quickly with a unified view of their secrets and applications in minutes.
Jun 13, 2023
978 words in the original blog post.
High-maturity cloud companies, defined by their adoption of best practices and technological and operational best practices at scale, have boosted their cloud investments despite macroeconomic pressure, resulting in better business outcomes such as cost savings, improved security posture, and operational efficiency. The 2023 HashiCorp State of Cloud Strategy Survey found that high-maturity organizations were more likely to increase their cloud spending, reap the benefits of their efforts, and less likely to suffer from "cloud waste". The survey also highlighted the importance of automation, platform teams, security, and organizational best practices in maximizing multi-cloud business goals and benefits.
Jun 12, 2023
1,305 words in the original blog post.
HashiCorp has released Terraform 1.5, featuring a config-driven import workflow and enhanced validation with checks. The new config-driven import mechanism allows for bulk execution of import operations as part of the standard plan and apply cycle, eliminating the risk of unexpected state modification. Additionally, automatic code generation for imported resources reduces the amount of time spent writing code to match the imported resources. Checks are a new top-level construct that gives Terraform practitioners and module authors flexibility to define assertions within Terraform code, allowing for holistic functional validation of infrastructure after it is provisioned.
Jun 12, 2023
1,093 words in the original blog post.
The Prometheus Operator with the Vault Secrets Operator enables monitoring and alerting for Kubernetes secrets in a Grafana dashboard. The Vault Secrets Operator synchronizes secrets from HashiCorp Vault to Kubernetes Secrets, exposing metrics through the Prometheus endpoint. To deploy the Prometheus Operator, users create a ServiceMonitor object that targets the Vault Secrets Operator's namespace. This allows the Prometheus Operator to scrape protected metrics and provide alerts. A sample Grafana dashboard is also provided to visualize the data coming out of the Vault Secrets Operator. Users can customize this dashboard with critical data more closely related to their business needs. Additionally, alerting rules are created using the PrometheusRule API to monitor the Vault secrets system. As users begin to adopt the Vault Secrets Operator, it will become a critical component of production stacks, requiring close monitoring to ensure its effectiveness.
Jun 06, 2023
1,392 words in the original blog post.