Home / Companies / HashiCorp / Blog / October 2023

October 2023 Summaries

26 posts from HashiCorp

Filter
Month: Year:
Post Summaries Back to Blog
PKI is a critical component of modern cybersecurity, enabling secure communications between servers, digital identities, and application services by leveraging public key cryptography to encrypt, decrypt, and authenticate information. Governed by the International Telecommunications Union (ITU), PKI certificates are widely used online, verifying authenticity and protecting sensitive data from theft. Asymmetric encryption is the core technology that enables PKI, using two separate keys and more complex algorithms for encryption and decryption. While symmetric encryption is faster, it requires both parties to have access to private secret keys, making asymmetric encryption more suitable for public channels. The benefits of PKI include preventing unauthorized use or access, securing billions of daily communications, and providing a scalable digital identity security solution. Automating PKI certificate management with tools like HashiCorp Vault can help reduce risk, achieve regulatory compliance, and shorten time-to-market, while also addressing the growing demand for protecting workloads, applications, services, and IoT connected devices.
Oct 27, 2023 1,049 words in the original blog post.
HashiCorp has been recognized as one of the Best Workplaces for Women by Fortune and Great Place to Work, based on employee feedback. The company is launching a podcast series called HashiCast Women in Tech to empower women and others to enable change in the tech industry. The first episode features Sigal Zarmi, an award-winning CIO and former Morgan Stanley executive, who shares her secrets to building a successful career in tech, including lessons on overcoming challenges, self-care, and the importance of mentors and sponsors. The podcast aims to provide practical advice and real-world stories for growing careers in technology.
Oct 26, 2023 505 words in the original blog post.
HashiCorp has made available performance replication with multiple secondary clusters for its HCP Vault service, allowing customers to spin up production-grade three-node Vault clusters across multiple regions within the same cloud provider. This feature is now available in both AWS and Microsoft Azure, enabling large-scale organizations with high-throughput applications to manage their secrets securely while reducing latency and supporting customers across geographic locations and regions. With performance replication, HCP Vault Plus customers can have fully managed performance replication across many regions spread across various cloud providers, ensuring consistency and scalability for mission-critical services.
Oct 26, 2023 437 words in the original blog post.
HashiCorp Vault is a secrets and encryption management system that can help organizations comply with the new PCI DSS v4.0 requirements by providing secure and auditable access to sensitive data, including cardholder data. The system validates and authorizes clients before providing them access to secrets or stored sensitive data, ensuring tight control over access and recording detailed audit logs. Vault addresses several key PCI requirements, including securing configuration and management of systems, protecting account data, encrypting transmission over public networks, and defining processes for strong cryptography during transmission. To leverage Vault effectively for PCI compliance, organizations must integrate it into a broader compliance strategy that includes training, regular audits, and ongoing monitoring of their systems and processes.
Oct 25, 2023 730 words in the original blog post.
HashiCorp's Armon Dadgar discusses the future of cloud infrastructure, highlighting the growth of edge computing and the need for solutions that simplify management across platforms. He notes that the industry is experiencing a fragmentation in infrastructure due to the increasing adoption of public cloud and edge technologies. This trend brings new challenges, such as unifying management landscapes across multiple providers, managing growing numbers of endpoints, devices, and applications, and adopting an identity-first approach to security. Dadgar emphasizes the importance of tooling that provides consistency and simplicity for managing multi-cloud and edge environments, as well as moving away from manual processes and embracing automation. He also touches on the need for a standardized approach to network management and the rise of internal developer platforms that abstract infrastructure complexity.
Oct 22, 2023 1,599 words in the original blog post.
The HashiCorp Cloud Platform (HCP) has introduced a new feature called HCP groups, which offers organizations a centralized role-management interface within the HCP console. This feature enables users to group identities and assign roles and projects to them, making user management faster and more robust. The use of groups allows administrators to bundle user identities as a single unit, receive role assignments, and project associations in a logical and efficient manner. With HCP groups, organizations can enforce regular reviews of roles and their associated permissions, ensuring that users have the necessary access while adhering to security best practices such as the principle of least privilege. The feature represents a significant enhancement to HCP's IAM capabilities, improving security, efficiency, and compliance with industry standards.
Oct 18, 2023 552 words in the original blog post.
HashiCorp is introducing a tech preview of its Terraform provider code generation tool, which automates the process of generating Terraform provider code from OpenAPI specifications. This solution aims to reduce maintenance burden and create consistency in codebases by providing a scalable ecosystem that can be extended by the existing provider developer community. The tool offers three general-purpose solutions for bootstrapping the ecosystem, allowing developers to generate provider code using either OpenAPI or alternative IDLs such as Protobuf. The tech preview is currently available for testing, and HashiCorp invites users to share their feedback and suggestions via the Terraform discussion forum.
Oct 17, 2023 467 words in the original blog post.
HashiCorp will stop publishing packages for end-of-life distributions to production sites and migrate them to an archive site, where users can continue to download them. Starting January 10th, 2024, HashiCorp will no longer support Linux versions that have reached EoL status, moving them to the new archive site instead. Users of impacted systems must update to major versions of Red Hat Enterprise Linux (RHEL) and remove minor version aliases, with the company advising users to migrate to current supported OS versions for official support. The changes are part of a regular process that will be applied when distribution versions reach end-of-life status.
Oct 16, 2023 542 words in the original blog post.
CDK for Terraform 0.19 adds support for importing existing resources with auto-generated configuration in CDKTF projects, simplifying the process of bringing existing infrastructure into CDKTF projects. This release builds upon previous updates to CDKTF, which introduced multi-language provider documentation and supported new Terraform features to achieve cost savings and improve security. The new feature allows developers to safely move resources and bring existing infrastructure into CDKTF projects with auto-generated code, without jeopardizing business continuity. Importing existing resources is now a more straightforward process, thanks to the introduction of config-driven import and refactoring capabilities such as `moveTo` and `generateConfigForImport`. These features enable developers to refactor code without losing state or destroying and recreating resources, making it easier to work in production environments with minimal downtime or data loss. The release also includes support for terraform provider code generation in tech preview.
Oct 16, 2023 613 words in the original blog post.
PKI workloads can be hosted in either the cloud or on-premises, each with its own advantages and disadvantages. Cloud-based PKI provides agility, ease of use, and reduced operational overhead, while self-managed PKI offers more options to customize and meet specific security and compliance requirements. HashiCorp's cloud PKI functionality resides in HashiCorp Cloud Platform (HCP) Vault, a fully managed implementation of Vault that allows organizations to get up and running quickly. With HCP Vault, organizations can secure, store, and tightly control access to tokens, passwords, certificates, and encryption keys within one unified cloud-based platform. Self-managed PKI environments also have their benefits, including the ability to customize and meet specific security and compliance requirements. Ultimately, both cloud-based and self-managed PKI solutions have their pros and cons, and organizations should consider their particular needs when choosing how and where to host their PKI environment.
Oct 16, 2023 705 words in the original blog post.
The HashiCorp Technology Partner Awards recognize partners who have prioritized customer solutions around the HashiCorp Cloud Platform (HCP) framework, delivering value through integrations, co-engineered solutions, and joint marketing initiatives. Palo Alto Networks earned a second award for its collaboration on cloud security and was also named launch partner for Terraform Cloud streamlined run task reviews. Datadog was recognized as Collaboration Partner of the Year for its proactive engagement with HashiCorp, offering integrations across the product set, including HCP Vault and Consul. Zscaler was awarded for its seven integrations with HashiCorp, including Posture Control to prevent cloud security issues. Tines, a new partner that worked with HashiCorp for less than a year, received the Emerging Partner of the Year award for its cross-product integrations and collaborative customer outreach.
Oct 12, 2023 482 words in the original blog post.
The HashiCorp Partner Network Awards recognize top-performing partners who have demonstrated excellence in sales and services for HashiCorp solutions, helping enterprises accelerate their cloud adoption strategies. The 2023 winners come from various regions around the world, including the Americas, Asia-Pacific, Europe, Middle East, and Africa, as well as globally. These companies were recognized for delivering significant technology capabilities, assisting with growing HashiCorp's products, and consistently delivering value to joint customers through services and innovation initiatives. The awards honor Insight Enterprises, Inc., CDW Corporation, Effectual, Leidos, Adfinis, FullStackS, Nuaware, Cloud Kinetics, Versent, Tokyo Electron Device (TED), River Point Technology, PwC, and Accenture, among others, for their contributions to HashiCorp's success. The winners were announced in recognition of their commitment to helping enterprises accelerate their cloud adoption strategies.
Oct 12, 2023 1,290 words in the original blog post.
The latest version of Consul, 1.17 beta, introduces several significant enhancements for simplified workflow management, reliability, scale, and security in service networking. HCP Consul Central adds global visibility and control to the platform, allowing users to centralize their Consul deployments and gain a unified view of their clusters. The new APIs simplify workflow management by enabling multi-port services and flexible routing, while also introducing locality-aware routing for low-latency connections and JWT-based authentication and authorization support for API Gateway. Additionally, Consul 1.17 bolsters reliability with sameness groups and rate limiting for services, making it easier to manage and scale Consul deployments in private networking environments. The platform is designed to be deployed in datacenters or public cloud regions, where requests are routed by the downstream proxy to any healthy and available upstream instance within the same region. With these enhancements, Consul empowers organizations to build resilient and efficient applications in distributed environments, enabling a consistent, enterprise-ready control plane to discover and securely connect any application.
Oct 11, 2023 1,733 words in the original blog post.
HCP Packer is introducing two new features to improve the efficiency and security of image-related workflows across multi-cloud environments: project-level webhooks, which allow users to automate notifications about specific events, and streamlined run task reviews, which provide meaningful context on run task evaluations for HCP Packer tasks on HashiCorp Terraform Cloud. These additions help organizations streamline their image management workflows, reduce security risks caused by human errors, and improve deployment speed.
Oct 11, 2023 691 words in the original blog post.
HashiCorp has announced several new products, features, and updates at HashiConf 2023, focusing on enhancing workflow automation for developers and lifecycle management for cloud platform teams across both infrastructure and security. The company aims to deliver developer-driven workflows that are well-integrated with the standardized services enabled by platform teams. New features include Terraform testing and UX improvements, HCP Packer's project-level webhooks and streamlined run task reviews, updated HCP Waypoint templates and add-ons, new security lifecycle management capabilities, HCP Vault Secrets for secrets management, Cloud secrets sync for centralizing secrets management, and HCP Consul Central for global visibility and management of Consul deployments. These enhancements aim to simplify security best practices for developers and improve the end-user experience, with a focus on resolving secrets sprawl and improving overall security posture.
Oct 11, 2023 1,258 words in the original blog post.
HashiCorp Vault is announcing several new features and updates at HashiConf, including the alpha program for HCP Vault Radar, general availability of HCP Vault Secrets, and a beta release of secrets sync in Vault Enterprise 1.15. The new capabilities aim to help organizations secure their applications and services as they adopt a cloud operating model. HCP Vault Radar automates secret detection and remediation, while HCP Vault Secrets provides a managed offering for secrets management. The secrets sync feature allows teams to centralize their secrets management across multiple platforms, reducing the attack surface and improving compliance. These updates aim to fight secret sprawl, reduce operational costs, improve speed of delivery, and lower risk for organizations using HashiCorp Vault.
Oct 11, 2023 1,157 words in the original blog post.
The new Terraform test framework and test-integrated module testing workflow aim to improve developer velocity, code quality, and infrastructure cost management by providing a native testing solution in HashiCorp Configuration Language (HCL). The test framework allows for easy unit and integration testing of Terraform code, while the test-integrated module testing workflow enables systematic control and publishing of high-quality modules through the private registry. Additionally, generated module tests can be used to jumpstart adoption by instantly producing customized tests for a module within the private registry. Another enhancement is enhanced editor validation in the Terraform extension for Visual Studio Code, which automatically validates Terraform code as early as possible, creating an integrated authoring experience. Furthermore, stacks are introduced as a new approach to automate and optimize the coordination, deployment, and lifecycle management of interdependent Terraform configurations, reducing time and overhead. Ephemeral workspaces are also available in general availability for Terraform Cloud Plus and Terraform Enterprise, allowing customers to schedule automatic destruction of non-production resources and eliminate manual cleanup.
Oct 11, 2023 1,296 words in the original blog post.
HCP Vault Secrets is a managed offering of HashiCorp Vault focusing on secrets management for developers that offers key capabilities including secrets sync. The general availability release builds on the beta release with production-ready secrets management capabilities, additional secrets sync destinations, and multiple consumption tiers. HCP Vault Secrets centralizes secrets lifecycle management into one place, introducing a new domain model based on applications to logically group secrets, and offering centralized management of secrets and syncing them to existing destinations such as GitHub Actions, Vercel, and AWS Secrets Manager. The solution is a multi-tenant SaaS offering that relies on HashiCorp for deployment, updates, scale, reliability, security, compliance, and support, eliminating the need for manual upgrades and allowing reallocation of resources to more strategic projects. Organizations can consume HCP Vault Secrets in two ways, with an always-free tier to manage up to 25 secrets or a paid Standard tier offering extended capabilities.
Oct 11, 2023 725 words in the original blog post.
HashiCorp has released HashiCorp Boundary 0.14, which includes an embedded terminal in the desktop client for a seamless user experience and LDAP general availability support, making it easier for organizations to securely manage privileged access to their cloud-driven environments. The new release also enhances security features such as session recording, credential injection, and storage bucket support, allowing users to streamline their workflow and reduce the risk of human error when connecting to resources. With this update, HashiCorp continues to strengthen its position in the privileged access management market with a modern PAM offering that provides just-in-time access to infrastructure without requiring end-users to manage IP addresses or credentials.
Oct 11, 2023 578 words in the original blog post.
HashiCorp is updating its HCP Waypoint platform to empower platform teams to define golden patterns and workflows for developers to manage applications at scale, addressing challenges such as software management complexity and consistency, evolving application needs, and lack of insights. The new vision aims to provide a clear and consistent developer experience while providing a central catalog of applications and their associated metadata. HCP Waypoint now supports templates and add-ons, enabling platform teams to abstract and standardize application scaffolding and manage application dependencies, respectively. These features represent the first installments in HashiCorp's plans to execute on its new roadmap, with additional features in the works, including creating golden workflows, rich application insights, and environments.
Oct 11, 2023 998 words in the original blog post.
The HashiCast podcast series, Navigating the Cloud for C-Suites, explores cloud adoption challenges for C-suite executives, emphasizing that successful cloud adoption transforms business operations and strategy. The series provides digestible takeaways on cloud strategy, innovation, and staying ahead of the curve, with expert insights from HashiCorp cloud experts. By embracing the cloud, leaders can achieve maturity, digital transformation, and a brighter future in the cloud.
Oct 05, 2023 444 words in the original blog post.
Terraform 1.6 is now generally available, bringing a powerful new testing framework that allows authors to systematically validate the functionality of their code. This release enhances developer productivity and practitioner workflows with features such as improved config-driven import, enhancements for Terraform Cloud CLI workflows, and changes to the Amazon S3 remote state backend. The new test framework uses familiar HashiCorp Configuration Language (HCL) syntax and allows authors to create a suite of unit and integration tests with custom assertions. Additionally, Terraform 1.6 introduces support for dynamic `id` attributes in import blocks, two new features in Terraform Cloud CLI workflows, and significant changes to the configuration format of the Amazon S3 remote state backend.
Oct 04, 2023 835 words in the original blog post.
Vault Enterprise 1.15 introduces a beta release of secrets sync, a feature designed to control secret sprawl and manage the secrets lifecycle by synchronizing secrets across platforms. This feature addresses the challenge of maintaining centralized visibility into secrets lifecycle management as workloads become more distributed across CI/CD tooling and cloud platforms. By adopting Vault Enterprise secrets sync, organizations can establish a single control plane for secrets lifecycle management, eliminating the need to switch between multiple secrets management platforms. The beta release covers common destinations for secrets, such as external secrets managers, allowing users to synchronize secrets when needed and keep them up-to-date with Vault Enterprise.
Oct 04, 2023 397 words in the original blog post.
The Terraform Google provider version 5.0 introduces improvements to default labels, allowing practitioners to set common metadata labels at the provider level, which applies them across all supported resources in the configuration. This feature increases productivity and reduces risk by making it easier for users to manage labels efficiently. The update also includes a `default_labels` field that automatically applies defined labels to all resources, removing limitations on integrating with existing resources and modules. Additionally, Terraform plans now reliably show default values used in configurations, improving clarity when reviewing planned changes to infrastructure, and handling of default projects has been improved to enable teams to write the new state value into the project information when unset at the resource-level. The release also removes deprecated attributes and features, updates error handling and adds multi-file support for Google endpoints service.
Oct 03, 2023 837 words in the original blog post.
With this new feature, users can now select Sentinel or OPA versions when provisioning in Terraform Cloud. Policies are rules that HashiCorp Terraform Cloud enforces at the Terraform run phase to help with security, compliance, and cost management, which can be defined in Terraform Cloud using Sentinel and Open Policy Agent policy as code frameworks. A new feature enables users to select specific Sentinel or OPA runtime versions for their policy sets to reduce version conflicts, upgrades, and bugs, making policy enforcement more stable and efficient. Previously, users were required to use the most recent version of Sentinel or OPA, but now they can choose from a list of previously supported releases, providing increased control over policy as code versioning in Terraform Cloud.
Oct 03, 2023 383 words in the original blog post.
HashiCorp Vault 1.15 introduces Microsoft Workload Identity Federation to improve security by enabling applications and services in Azure, Google Cloud, and GitHub to authenticate and access resources without the need for secrets in some scenarios. This technology removes the burden of secrets management from developers, simplifying their experience while providing a powerful tool to secure their applications and services. With WIF, developers can configure Azure AD applications and services to trust tokens issued by HashiCorp Vault, leveraging them to access resources in those applications. The integration aims to deepen Vault's connection with MS Azure, addressing concerns around secrets storage, password leakage, and service downtime associated with secrets rotation.
Oct 02, 2023 340 words in the original blog post.