Home / Companies / HashiCorp / Blog / October 2024

October 2024 Summaries

16 posts from HashiCorp

Filter
Month: Year:
Post Summaries Back to Blog
Building an internal developer platform with a golden path, lifecycle management, and integrated secrets management can help avoid a majority of security and compliance risks in cloud infrastructure. By focusing on risk avoidance rather than mitigation, organizations can reduce costs associated with breaches and non-compliance problems. Key best practices include leveraging infrastructure as code to develop standardized templates for infrastructure deployment, implementing lifecycle management processes for golden components, and incorporating integrated secrets management capabilities to secure credentials, keys, and other sensitive data. These strategies enable faster time-to-market for product features while maintaining a high level of security and compliance.
Oct 31, 2024 1,338 words in the original blog post.
This blog compares the AzureRM and AzAPI Terraform providers for optimal Azure infrastructure management. AzureRM provides a stable, well-tested layer on top of Azure APIs, while AzAPI is a lightweight wrapper around Azure APIs, enabling direct access to the latest features. AzureRM is ideal for users looking for stability and simplified configuration management, whereas AzAPI is recommended for scenarios where early access to new Azure features is crucial or when granular control over resource versions is needed. Both providers are backed by Microsoft and HashiCorp and can be adapted based on user needs.
Oct 30, 2024 824 words in the original blog post.
Balancing innovation and security is crucial for businesses to stay ahead in the rapidly changing market. Experts suggest that embedding security early within an organization accelerates innovation without adding risk. By viewing security as a catalyst for innovation, integrating it into organizational processes, adapting operational models to support regulatory compliance and innovation, embracing ongoing transformation and flexibility, promoting collaboration, and understanding why the paradox exists, businesses can harmonize security and innovation to drive growth and competitiveness.
Oct 22, 2024 1,177 words in the original blog post.
HashiCorp has released version 1.9 of its orchestrator, Nomad, which introduces new features such as NVIDIA MIG support, golden job versions, and more. Nomad is a simple and flexible tool used to deploy and manage containers and non-containerized applications across multiple cloud, on-premises, and edge environments. The latest version includes updates like an updated NVIDIA device driver for Multi-Instance GPU (MIG) support, quotas for device resources, NUMA awareness for device resources, exec2 task driver general availability, golden job versions, libvirt task driver beta, and improved IPv6 support.
Oct 15, 2024 1,548 words in the original blog post.
HashiCorp's HCP Waypoint is now generally available with added support for golden workflow capabilities, including variable support in actions (beta), upgrade workflow for templates, API support, and more. The new release features enhancements to the previously announced HCP Waypoint templates and add-ons, which allow platform teams to abstract and share standardized application deployment patterns with developers without worrying about infrastructure details. These updates aim to provide better composability, customization, and end-to-end Day 2+ workflows for organizations tailored to meet the specific needs of application developers.
Oct 15, 2024 1,039 words in the original blog post.
HashiCorp has announced new features in its Security Lifecycle Management (SLM) products - Vault, Boundary, and Consul at HashiConf 2024. These updates aim to make adopting secure practices easier for developers. HCP Vault Secrets now supports secret auto-rotation, dynamic secrets, and dynamic cloud credentials for HCP Terraform. Additionally, HCP Vault Radar is in public beta, Boundary offers transparent sessions (also in public beta), and Consul DNS views are available. These updates aim to streamline security integration into developer workflows while maintaining robust security measures.
Oct 15, 2024 2,334 words in the original blog post.
Cloud security is a top concern for CIOs as cloud resources are rapidly being provisioned across enterprises, potentially introducing systemic vulnerabilities that increase cybersecurity risk. This blog presents seven common mistakes development teams make when managing cloud resources and how to avoid them through effective Infrastructure Lifecycle Management (ILM). By adopting tools and techniques to standardize the approach to infrastructure enterprise-wide, CIOs and IT organizations can reduce current cyber risks and advance their ILM maturity. The seven solution steps discussed in this blog include using an infrastructure as code (IaC) solution for automation, enabling cross-functional collaboration with a platform-oriented approach, standardizing cloud provisioning with golden best practice templates, incorporating policy as code to meet risk and cost requirements, monitoring infrastructure drift and health over time, automating infrastructure deletion, and providing developers with self-service freedom within the golden path.
Oct 15, 2024 1,618 words in the original blog post.
Boundary 0.18 introduces transparent sessions, a new feature that streamlines secure connections to infrastructure resources. This improvement enables authorized remote users to connect in one step without changing their workflows or client tools. Transparent sessions simplify user access by minimizing interactions with Boundary's CLI or Desktop clients and intercepting DNS calls to route traffic through the platform. Additionally, transparent sessions now support secure access to web applications over HTTPS. This feature enhances developer experience and boosts focus on providing easy-to-use access management without compromising security.
Oct 15, 2024 857 words in the original blog post.
HashiCorp Consul 1.20 is a significant upgrade for the Kubernetes operator and developer experience, including better multi-tenant service discovery, catalog registration metrics, and secure OpenShift integration. The latest release includes improvements for Kubernetes environments for both service discovery and service mesh use cases. It also introduces Consul DNS views, an enterprise feature that improves the usability of service discovery in multi-tenant environments and tightens security by allowing organizations to limit discovery between tenants. Additionally, Consul 1.20 now includes improved metrics for Consul catalog sync, resulting in more visibility for operators. Lastly, operators no longer need to provide elevated permissions to containers when using transparent proxy, resulting in tighter security in OpenShift deployments.
Oct 15, 2024 1,081 words in the original blog post.
HashiCorp's HCP Vault Secrets has added new features such as auto-rotation (GA), dynamic secrets (beta), a new secret sync destination, and more to its cloud-native secrets lifecycle management platform. The aim is to make secure software delivery paths easy for developers to follow by solving secret sprawl with centralized secrets lifecycle management and lowering the overhead of creating, storing, rotating, and deleting secrets. Key upgrades include auto-rotation, dynamic secrets, granular access control capabilities, a new secrets sync destination, Workload Identity Federation (WIF) authentication via HashiCorp Cloud Platform (HCP), and notification webhooks.
Oct 15, 2024 1,438 words in the original blog post.
HashiCorp has announced updates to its Infrastructure Lifecycle Management (ILM) portfolio at HashiConf in Boston, including HashiCorp Terraform, Packer, Nomad, and Waypoint. These updates aim to help organizations manage their infrastructure at scale with reduced complexity. The latest ILM capabilities include Day 0 features such as HCP Packer CI/CD pipeline metadata and bucket-level RBAC; Day 1 features like HCP Terraform Stacks and module lifecycle management; and Day 2+ features such as Terraform migrate and HCP Waypoint with templates, add-ons, API support, and an upgrade workflow for templates. These updates contribute to speeding, securing, and simplifying the full lifecycle management of infrastructure.
Oct 15, 2024 2,269 words in the original blog post.
The 2024 HashiCorp Partner of the Year Awards have been announced at HashiConf in Boston. The System Integrator Awards honor top-performing partners that excel in sales and services for HashiCorp solutions, while the Technology Partner Awards celebrate those who build and expand ecosystem solutions for customers through new integrations, co-engineered solutions, and joint marketing initiatives. River Point Technology was named AMER SI Partner of the Year, Versent as APJ SI Partner of the Year, GlobalLogic Corp UK LTD as EMEA SI Partner of the Year, Datadog as Technology Partner of the Year, Palo Alto Networks as Collaboration Partner of the Year, Coder as Integration Partner of the Year, and JetBrains as Emerging Partner of the Year.
Oct 14, 2024 969 words in the original blog post.
HashiCorp Vault 1.18 introduces support for IPv6 and CMPv2 while improving security team user experience. Key feature additions include CMPv2 PKI support, adaptive overload protection, password rotation for static PostgreSQL database accounts, Raft library updates, and improved UI support for AWS WIF and KVv2 secrets path management. The latest release also includes more new features, workflow enhancements, general improvements, and bug fixes.
Oct 09, 2024 1,256 words in the original blog post.
HashiCorp Cloud Platform (HCP) has expanded its service principals access options and role assignments to enhance security, efficiency, and collaboration. Cross-project service principals enable access to resources in other projects while adhering to least-privileged access principles. Fine-grained roles support more tailored access control to match specific personas and responsibilities within HCP organizations. These features strengthen and streamline operations across HCP.
Oct 08, 2024 824 words in the original blog post.
False positives are a significant challenge in cybersecurity as they can distract security teams, exhaust resources, and increase the risk of missed threats. They occur when secret scanning solutions flag legitimate content as suspicious due to overly sensitive tools, lack of contextual data, or insufficient functionality. The costs of false positives include missed threats, wasted time and resources, increased labor costs, security tool maintenance, alert fatigue, burnout and turnover, and decreased trust in security systems. HCP Vault Radar is designed to reduce false positives by assigning severity levels to findings, evaluating high entropy content, performing activeness checks, correlating secrets with Vault, and allowing custom ignore rules. Additionally, it supports remediation workflows via ticketing and alerting solutions.
Oct 02, 2024 1,484 words in the original blog post.
Microsoft Azure DevOps' workload identity federation (WIF) feature can now be used to seamlessly integrate Azure DevOps pipelines with HashiCorp Vault, improving upon previous integration options by providing a simplified, passwordless integration that uses the widely adopted OpenID Connect standard. This allows for secure access to secret data centrally managed by HashiCorp Vault, including static and dynamic secrets as well as many other kinds of credentials. The integration can be configured using Terraform, making it easier to implement at scale.
Oct 01, 2024 2,557 words in the original blog post.