April 2024 Summaries
20 posts from HashiCorp
Filter
Month:
Year:
Post Summaries
Back to Blog
The blog post outlines the deployment of HashiCorp Vault on HashiCorp Nomad, detailing the infrastructure setup and configuration using HCP Terraform. It emphasizes Vault's role in secure secrets management and highlights Nomad's simplicity and efficiency in scheduling and managing clusters compared to Kubernetes. The deployment involves creating a virtual private cloud (VPC) on AWS with multiple virtual machines (VMs) for Nomad servers and clients, including a backup server for Vault. The post discusses the use of Terraform to manage different workspaces and remote backends, ensuring separate yet interdependent configurations for infrastructure and Vault deployment. It also covers the necessity of configuring security groups, IP addresses, and other prerequisites, such as SSH key pairs and cloud-init scripts, for the Nomad server and client VMs. Additionally, the post introduces TerraCurl for API calls to Nomad for ACL bootstrapping, outlining how Terraform's outputs can be shared between workspaces. The post concludes by previewing future installments in the series that will focus on deploying Vault as a Nomad job and implementing automation to streamline Vault's operations.
Apr 30, 2024
2,725 words in the original blog post.
HashiCorp has introduced granular permissions for managing teams in HCP Terraform and Terraform Enterprise, enhancing the management of team members within organizations. This improvement allows organization owners to delegate the ability to manage teams at the organizational level, reducing the reliance on a single owner and mitigating security risks. The new feature is available now in HCP Terraform and coming soon to Terraform Enterprise.
Apr 29, 2024
388 words in the original blog post.
ServiceNow has released version 2.5 of its Service Catalog for Terraform, enabling users to provision infrastructure using no-code modules published in their organization's private registry. This update allows customers to connect external applications to ServiceNow and simplifies the process of provisioning resources with Terraform. The plugin is now certified for the latest "Washington DC" version of ServiceNow server. New features include streamlined MID server routing, enhanced control over the release process, and a self-service model that allows users to deploy pre-approved modules without writing any code.
Apr 25, 2024
660 words in the original blog post.
HashiCorp has signed an agreement to be acquired by IBM, aiming to accelerate their multi-cloud automation journey. The acquisition will enable HashiCorp products to reach a larger audience and expand its community of users and partners. As a division inside IBM Software, HashiCorp will continue to build products and services while benefiting from the scale of IBM and Red Hat communities.
Apr 24, 2024
1,461 words in the original blog post.
HashiCorp Configuration Language (HCL) has introduced a new feature in HCP Terraform called no-code provisioning module version upgrades. This feature allows organizations to provide validated self-service infrastructure, reducing the need for manual tasks and lowering cloud spend. No-code provisioning enables application developers and other stakeholders with infrastructure needs to access approved infrastructure modules without needing knowledge of Terraform or HCL. The new module version upgrade capability significantly reduces friction when updating no-code modules in an HCP Terraform workspace, ensuring that users receive notifications about changes and can apply upgrades seamlessly. This feature helps bridge the cloud-related skill gaps faced by 90% of organizations, enabling developers to provision infrastructure quickly without significant training.
Apr 23, 2024
489 words in the original blog post.
HCP Packer now includes version tracking for Packer Community Edition and associated plugins, allowing users to verify the versions used during artifact creation. This enhancement supports a secure build pipeline and helps organizations ensure they are using the latest features of Packer. As security demands on the software supply chain grow, proper image management is crucial in addressing risks early in the infrastructure deployment process. With this new feature, users can gain more visibility into their artifacts' creation pipelines for troubleshooting and risk mitigation purposes.
Apr 23, 2024
401 words in the original blog post.
HashiCorp introduces The Infrastructure Cloud to help organizations maximize their cloud investment by unlocking developer potential while controlling costs and risks. This new approach leverages the HashiCorp Cloud Platform (HCP), a unified SaaS platform for infrastructure and security lifecycle management. By bringing Terraform to HCP, HashiCorp aims to provide Infrastructure Lifecycle Management (ILM) and Security Lifecycle Management (SLM) through well-integrated workflows, systems of record, and enterprise-grade capabilities. The Infrastructure Cloud addresses the challenges faced by organizations during cloud migrations, ensuring successful adoption and management of cloud applications, infrastructure, and security.
Apr 22, 2024
907 words in the original blog post.
HCP Vault Radar is a new extension to HashiCorp Vault that conducts ongoing reconnaissance of unsecured secrets stored as plain text in code repositories, configuration tools, DevOps tools, and collaboration platforms. Secret scanning helps identify and prevent security threats posed by exposed sensitive information, passwords, API keys, and other credentials. HCP Vault Radar uses a hybrid scanning approach with regular expressions and dictionaries to find leaked secrets and sensitive information. It supports Git-based source control tools like GitHub, GitLab, and BitBucket, and can be automated to conduct scans over code repositories or integrated into developers' native workflows by scanning commits and pull requests. HCP Vault Radar provides comprehensive coverage of relevant locations where secrets may be found, leverages a hybrid approach for accuracy, offers monitoring and alerting capabilities, prioritizes evaluation results based on risk, and allows customization of scanning rules to meet specific organizational needs.
Apr 18, 2024
637 words in the original blog post.
HashiCorp has opened a new Madrid Tech Hub, marking its commitment to expand in Europe and support companies with Infrastructure and Security Lifecycle Management software. The hub is located at Paseo de La Castellana in Nuevos Ministerios, Madrid, and aims to positively impact the local economy and community. Three HashiCorp employees were given the opportunity to be part of the Madrid Founders Program, a six-month assignment to support new employees and cultivate the HashiCorp community in Madrid. The company is looking for passionate individuals to join the team at its new Madrid Tech Hub location as it expands its presence in this thriving city.
Apr 17, 2024
1,143 words in the original blog post.
HashiCorp has announced the general availability of webhooks for HCP Packer, a tool that automates notifications to external systems about image-related events across any cloud and on-premises environment. Webhooks streamline and secure image lifecycle workflows by eliminating manual orchestration of external workflows, reducing complexity and security risks caused by human errors. Users can now set up automated actions for specific image lifecycle events such as publishing a new image version, deleting an image or template in the cloud provider, and sending notifications to stakeholders.
Apr 16, 2024
361 words in the original blog post.
HashiCorp has introduced a new feature called Secrets Sync in its Vault Enterprise 1.16, which aims to centralize the management, governance, and control of secrets for multiple external secret managers. This feature helps organizations manage secrets sprawl by bringing together the governance and control of secrets stored within other secret managers. The shift-left trends have led to the distribution of secrets across multiple secret managers, CI/CD tools, and platforms, making it difficult to manage secrets effectively. Secrets Sync provides a single management plane for controlling the distribution of secrets for last-mile usage, helping organizations resolve secrets sprawl.
Apr 11, 2024
546 words in the original blog post.
HashiCorp participated in Google Cloud Next conference with demos, breakout sessions, presentations, and experts at their booth. The event highlighted the partnership between HashiCorp and Google Cloud, which helps organizations control cloud spend, improve risk profile, and enhance developer productivity for faster time to market. Key developments from the event include:
1. HashiCorp joins the new Google Distributed Cloud partner program, working with partners to validate their solutions by tuning and enhancing existing integrations and features to better support customer use cases for GDC.
2. Sync secrets with Google Cloud Secrets Manager Vault Enterprise secrets sync is now generally available in Vault Enterprise 1.16, helping organizations manage secrets sprawl by centralizing the governance and control of secrets stored within other secret managers.
3. Terraform Google Cloud provider-defined functions are now generally available, allowing anyone in the Terraform community to build custom functions within providers and extend the capabilities of Terraform.
4. Consul fleet-wide availability on GKE Autopilot is supported, addressing the challenge of consistently managing and connecting applications across various environments, including on-premises datacenters, multiple clouds, and existing legacy systems.
5. HashiCorp held two speaking sessions at Google Cloud Next: Multi-region, multi-runtime, multi-project infrastructure as code and Scaling Infrastructure as Code: Proven Strategies and Productive Workflows.
Apr 11, 2024
873 words in the original blog post.
HashiCorp has released Terraform 1.8, which introduces two new capabilities to improve extensibility and flexibility: provider-defined functions and refactoring across resource types. Provider-defined functions allow users to extend the capabilities of Terraform with custom logic and can be used in any Terraform expression. Refactoring code is now supported between resource types, making it faster and less error-prone. These features enhance the overall functionality of Terraform 1.8.
Apr 10, 2024
581 words in the original blog post.
HashiCorp has announced the general availability of provider-defined functions in its AWS, Google Cloud, and Kubernetes providers with the release of Terraform 1.8. These custom functions allow users to extend the capabilities of Terraform by building custom functions within providers. The new feature is a significant step forward in HashiCorp's unique approach to ecosystem extensibility. Provider-defined functions can perform various tasks, such as parsing and building Amazon Resource Names (ARNs), simplifying Terraform configurations where ARN manipulation is required. Additionally, the Google Cloud provider includes new functions for obtaining regions, zones, names, and projects from resource IDs, while the Kubernetes provider offers encoding and decoding of Kubernetes manifests into Terraform.
Apr 10, 2024
1,103 words in the original blog post.
The text discusses how to use the Vault Secrets Operator (VSO) to retrieve dynamic secrets from HashiCorp Cloud Platform (HCP) Vault Secrets and write them to a Kubernetes Secret for other workloads and resources to reference. It explains that HCP Vault Secrets enables users to manage the lifecycle of credentials and track their usage, while minimizing the need to refactor applications to access a secrets manager directly by using native Kubernetes Secrets. The text also provides an example configuration using HashiCorp Terraform to store GitHub App's private key, application identifier, and application installation identifier in HCP Vault Secrets, as well as instructions on installing the Vault Secrets Operator and defining resources for synchronizing secrets from HCP Vault Secrets to Kubernetes.
Apr 09, 2024
1,329 words in the original blog post.
The article discusses the importance of securing Docker containers against potential attack vectors originating from exposed secrets. It highlights that 5,500 out of 10,000 public docker images contained sensitive information, making it crucial for security and platform teams to understand common attack methods and how to close them. The article provides a brief checklist of various attack vectors into Docker containers specifically related to exposed secrets. It emphasizes the need for regular scanning and removal of unused images, using secret managers like HashiCorp Vault, and employing tools such as HCP Vault Radar to detect secrets in docker images across different repositories.
Apr 08, 2024
1,278 words in the original blog post.
HashiCorp Terraform Cloud has introduced new features to simplify and enhance the functionality of its projects, including a dedicated project overview page for better visibility and manageability, as well as project scoping for VCS connections to reduce risk. The latest enhancement allows administrators to control the project scope of VCS connections, preventing end users from accessing sensitive information from other teams. These improvements aim to provide customers with better control over their environment throughout their infrastructure lifecycle.
Apr 04, 2024
521 words in the original blog post.
HashiCorp introduces Long-Term Support (LTS) releases for Vault Enterprise, starting with version 1.16 series. The first major release of each year will be an LTS release. This program aims to help customers reduce operational overhead and stage their upgrades over a longer time. Vault Enterprise joins other HashiCorp commercial products in offering LTS with key characteristics such as critical bug and security fixes for up to two years. The first LTS version is 1.16, and the next will be 1.19.
Apr 03, 2024
457 words in the original blog post.
HashiCorp Vault 1.16 introduces several enhancements to its secrets management capabilities, including the general availability of Vault Enterprise secrets sync, a new event notification system, and UI alert configurability. Additionally, this release includes a beta for PKI secrets engine EST support and workload identity federation (WIF) plugin capability. The update also offers tunable audit logs to better meet compliance reporting needs and LTS releases for Vault Enterprise to reduce operational overhead.
Apr 03, 2024
990 words in the original blog post.
The HashiCorp Terraform Cloud Operator for Kubernetes continuously reconciles infrastructure resources using Terraform Cloud. To better secure secrets, such as API tokens, instead of hard-coding them, they can be stored and managed in a centralized secrets manager like HashiCorp Vault. In this approach, the Vault Secrets Operator (VSO) retrieves secrets from an external secrets manager and stores them in a Kubernetes secret for workloads to use. This post demonstrates how to use VSO to retrieve dynamic secrets from Vault and write them to a Kubernetes secret for the Terraform Cloud Operator to reference when creating a workspace.
Apr 02, 2024
1,997 words in the original blog post.