Hashicorp Vault - Auto-unseal using AWS KMS #12

Поділитися
Вставка
  • Опубліковано 5 лис 2024

КОМЕНТАРІ • 4

  • @georgesmith9178
    @georgesmith9178 6 місяців тому

    Thank you for the video and for answering the multi-region question below. Thumbs-up!. A few suggestions:
    1. Point the viewers to the fact when auto unseal is configured Vault generates "Recovery" keys, and NOT "Unseal" keys
    2. Explain how the auto unseal works - at startup Vault will connect to the device or service implementing the seal and ask it to decrypt the root key Vault read from storage.

  • @nandeeshb3165
    @nandeeshb3165 2 роки тому

    Hi Sir, KMS key is region specific , if you want to use it in another region in that case?

    • @learnwithgvr
      @learnwithgvr  2 роки тому

      KMS keys are regional that means you can't use outside the region in which they are created, instead copy the key to different regions and use it. Alternatively create MRK multi regional key, replicate to diff region and use it. Hope this helps.
      Pls subscribe if not, keep learning