home.social

#hashicorp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hashicorp, aggregated by home.social.

fetched live
  1. ⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects

    🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists

  2. ⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects

    🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists

  3. ⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects

    🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists

  4. ⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects

    🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists

  5. ⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects

    🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists

  6. Supply chains and package managers are a considerable security concern, making a secure dev environment more important than ever before.

    I published my #webdev environment publicly, with docs, so anyone can see how and why I do what I do, and reuse/replicate.

    A #Mac #Docker Desktop devenv 4 ppl who need #browsers, #NodeJS, #Golang, #Caddy (auto SSL), #Hashicorp #openbao vault secrets, and multi project support:

    github.com/localnerve/dev-cont

    Attach and go.

    Security for you, security for all.

  7. Supply chains and package managers are a considerable security concern, making a secure dev environment more important than ever before.

    I published my #webdev environment publicly, with docs, so anyone can see how and why I do what I do, and reuse/replicate.

    A #Mac #Docker Desktop devenv 4 ppl who need #browsers, #NodeJS, #Golang, #Caddy (auto SSL), #Hashicorp #openbao vault secrets, and multi project support:

    github.com/localnerve/dev-cont

    Attach and go.

    Security for you, security for all.

  8. Supply chains and package managers are a considerable security concern, making a secure dev environment more important than ever before.

    I published my #webdev environment publicly, with docs, so anyone can see how and why I do what I do, and reuse/replicate.

    A #Mac #Docker Desktop devenv 4 ppl who need #browsers, #NodeJS, #Golang, #Caddy (auto SSL), #Hashicorp #openbao vault secrets, and multi project support:

    github.com/localnerve/dev-cont

    Attach and go.

    Security for you, security for all.

  9. Supply chains and package managers are a considerable security concern, making a secure dev environment more important than ever before.

    I published my #webdev environment publicly, with docs, so anyone can see how and why I do what I do, and reuse/replicate.

    A #Mac #Docker Desktop devenv 4 ppl who need #browsers, #NodeJS, #Golang, #Caddy (auto SSL), #Hashicorp #openbao vault secrets, and multi project support:

    github.com/localnerve/dev-cont

    Attach and go.

    Security for you, security for all.

  10. HashiCorp has released the public beta of Vault Kubernetes Key Management.

    The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.

    Details 👉 bit.ly/4wKCvhN

    #InfoQ #Kubernetes #Security #DevOps #HashiCorp #Encryption

  11. HashiCorp has released the public beta of Vault Kubernetes Key Management.

    The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.

    Details 👉 bit.ly/4wKCvhN

    #InfoQ #Kubernetes #Security #DevOps #HashiCorp #Encryption

  12. HashiCorp has released the public beta of Vault Kubernetes Key Management.

    The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.

    Details 👉 bit.ly/4wKCvhN

    #InfoQ #Kubernetes #Security #DevOps #HashiCorp #Encryption

  13. HashiCorp has released the public beta of Vault Kubernetes Key Management.

    The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.

    Details 👉 bit.ly/4wKCvhN

    #InfoQ #Kubernetes #Security #DevOps #HashiCorp #Encryption

  14. HashiCorp has released the public beta of Vault Kubernetes Key Management.

    The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.

    Details 👉 bit.ly/4wKCvhN

  15. Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks

    Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!

    youtube.com/watch?v=Ppcb87gTAY

  16. Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks

    Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!

    youtube.com/watch?v=Ppcb87gTAY

  17. Excited to share this discussion with now-former co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too.

    Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!

    youtube.com/watch?v=Ppcb87gTAY

  18. Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks

    Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!

    youtube.com/watch?v=Ppcb87gTAY

  19. Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks

    Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!

    youtube.com/watch?v=Ppcb87gTAY

  20. Ramble v0.5.10 is now available.

    This release improves installation and distribution security:

    • Developer ID signed and Apple-notarized macOS binaries
    • Trusted Homebrew Cask
    • Patched Go dependencies
    • Signed builds for Intel and Apple Silicon

    Install with:
    brew install --cask open-wander/tap/ramble

    github.com/open-wander/ramble/

    #OpenSource #HashiCorp #Nomad #Homebrew #GoLang

  21. Ramble v0.5.10 is now available.

    This release improves installation and distribution security:

    • Developer ID signed and Apple-notarized macOS binaries
    • Trusted Homebrew Cask
    • Patched Go dependencies
    • Signed builds for Intel and Apple Silicon

    Install with:
    brew install --cask open-wander/tap/ramble

    github.com/open-wander/ramble/

    #OpenSource #HashiCorp #Nomad #Homebrew #GoLang

  22. Ramble v0.5.10 is now available.

    This release improves installation and distribution security:

    • Developer ID signed and Apple-notarized macOS binaries
    • Trusted Homebrew Cask
    • Patched Go dependencies
    • Signed builds for Intel and Apple Silicon

    Install with:
    brew install --cask open-wander/tap/ramble

    github.com/open-wander/ramble/

  23. Ramble v0.5.10 is now available.

    This release improves installation and distribution security:

    • Developer ID signed and Apple-notarized macOS binaries
    • Trusted Homebrew Cask
    • Patched Go dependencies
    • Signed builds for Intel and Apple Silicon

    Install with:
    brew install --cask open-wander/tap/ramble

    github.com/open-wander/ramble/

    #OpenSource #HashiCorp #Nomad #Homebrew #GoLang

  24. Мониторинг сорока сайтов мышкой: как я написал Terraform-провайдер и опубликовал его в реестре

    Сорок клиентских сайтов. У каждого четыре проверки: доступность, сертификат, срок домена, битые ссылки. Сто шестьдесят проверок, заведённых руками через веб-интерфейс. Пока их двадцать, это терпимо. Когда приходит сорок первый клиент, ты открываешь кабинет и снова кликаешь: создать проверку, интервал, порог, теги, сохранить. Четыре раза. А потом кто-то спрашивает: «а почему у этого сайта порог два, а у соседнего три?» — и честный ответ звучит как «не помню». Инфраструктуру мы описываем кодом уже лет десять. Мониторинг — почему-то нет. Хотя это ровно такая же конфигурация: её надо ревьюить, версионировать и уметь воспроизвести.

    habr.com/ru/articles/1063658/

    #terraform #terraform_provider #terraform_registry #monitoring_as_code #infrastructure_as_code #go #hashicorp #goreleaser #configdriven_import #мониторинг

  25. Мониторинг сорока сайтов мышкой: как я написал Terraform-провайдер и опубликовал его в реестре

    Сорок клиентских сайтов. У каждого четыре проверки: доступность, сертификат, срок домена, битые ссылки. Сто шестьдесят проверок, заведённых руками через веб-интерфейс. Пока их двадцать, это терпимо. Когда приходит сорок первый клиент, ты открываешь кабинет и снова кликаешь: создать проверку, интервал, порог, теги, сохранить. Четыре раза. А потом кто-то спрашивает: «а почему у этого сайта порог два, а у соседнего три?» — и честный ответ звучит как «не помню». Инфраструктуру мы описываем кодом уже лет десять. Мониторинг — почему-то нет. Хотя это ровно такая же конфигурация: её надо ревьюить, версионировать и уметь воспроизвести.

    habr.com/ru/articles/1063658/

    #terraform #terraform_provider #terraform_registry #monitoring_as_code #infrastructure_as_code #go #hashicorp #goreleaser #configdriven_import #мониторинг

  26. Мониторинг сорока сайтов мышкой: как я написал Terraform-провайдер и опубликовал его в реестре

    Сорок клиентских сайтов. У каждого четыре проверки: доступность, сертификат, срок домена, битые ссылки. Сто шестьдесят проверок, заведённых руками через веб-интерфейс. Пока их двадцать, это терпимо. Когда приходит сорок первый клиент, ты открываешь кабинет и снова кликаешь: создать проверку, интервал, порог, теги, сохранить. Четыре раза. А потом кто-то спрашивает: «а почему у этого сайта порог два, а у соседнего три?» — и честный ответ звучит как «не помню». Инфраструктуру мы описываем кодом уже лет десять. Мониторинг — почему-то нет. Хотя это ровно такая же конфигурация: её надо ревьюить, версионировать и уметь воспроизвести.

    habr.com/ru/articles/1063658/

    #terraform #terraform_provider #terraform_registry #monitoring_as_code #infrastructure_as_code #go #hashicorp #goreleaser #configdriven_import #мониторинг

  27. Dear Hashicorp Vault or OpenBao users,

    what is the least expensive way to unseal a Vault/OpenBao?

    Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.

    HSM is out of the question for a small setup, developer mode is too.

    Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?

    #Vault #OpenBao #DevOps #Hashicorp

  28. Dear Hashicorp Vault or OpenBao users,

    what is the least expensive way to unseal a Vault/OpenBao?

    Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.

    HSM is out of the question for a small setup, developer mode is too.

    Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?

    #Vault #OpenBao #DevOps #Hashicorp

  29. Dear Hashicorp Vault or OpenBao users,

    what is the least expensive way to unseal a Vault/OpenBao?

    Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.

    HSM is out of the question for a small setup, developer mode is too.

    Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?

    #Vault #OpenBao #DevOps #Hashicorp

  30. Dear Hashicorp Vault or OpenBao users,

    what is the least expensive way to unseal a Vault/OpenBao?

    Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.

    HSM is out of the question for a small setup, developer mode is too.

    Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?

    #Vault #OpenBao #DevOps #Hashicorp

  31. Dear Hashicorp Vault or OpenBao users,

    what is the least expensive way to unseal a Vault/OpenBao?

    Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.

    HSM is out of the question for a small setup, developer mode is too.

    Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?

    #Vault #OpenBao #DevOps #Hashicorp

  32. 📦 jippi/awesome-nomad

    A curated list of amazingly awesome Nomad tools and shiny things.

    A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities

    ⭐ Stars: 913
    📅 Last Update: Jun 06, 2026

    github.com/jippi/awesome-nomad

    #selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp

  33. 📦 jippi/awesome-nomad

    A curated list of amazingly awesome Nomad tools and shiny things.

    A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities

    ⭐ Stars: 913
    📅 Last Update: Jun 06, 2026

    github.com/jippi/awesome-nomad

    #selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp

  34. 📦 jippi/awesome-nomad

    A curated list of amazingly awesome Nomad tools and shiny things.

    A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities

    ⭐ Stars: 913
    📅 Last Update: Jun 06, 2026

    github.com/jippi/awesome-nomad

    #selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp

  35. 📦 jippi/awesome-nomad

    A curated list of amazingly awesome Nomad tools and shiny things.

    A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities

    ⭐ Stars: 913
    📅 Last Update: Jun 06, 2026

    github.com/jippi/awesome-nomad

    #selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp

  36. 📦 jippi/awesome-nomad

    A curated list of amazingly awesome Nomad tools and shiny things.

    A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities

    ⭐ Stars: 913
    📅 Last Update: Jun 06, 2026

    github.com/jippi/awesome-nomad

    #selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp

  37. Terraform MCP Server 1.0: теперь AI пишет конфиги по свежим провайдерам — но в prod без поводка нельзя

    11 июня 2026 HashiCorp перевела в GA официальный Terraform MCP Server 1.0 — прокладку между LLM и Terraform Registry, чтобы AI писал HCL по актуальной схеме провайдера, а не по памяти годичной давности. Разбираю по официальным докам: что под капотом (toolsets и конкретные tools), как поднять стенд за один docker run, чем отличаются stdio и streamable-http, что даёт доступ к приватному registry в HCP/Terraform Enterprise — и почему деструктивные операции выключены по умолчанию. Отдельно — модель угроз самой HashiCorp (prompt injection, tool poisoning, rug pull) и практический чеклист, чтобы агент однажды не снёс staging. Читать дальше →

    habr.com/ru/articles/1047922/

    #Terraform #MCP #Model_Context_Protocol #HashiCorp #Infrastructure_as_Code #DevOps #AIагенты

  38. Terraform MCP Server 1.0: теперь AI пишет конфиги по свежим провайдерам — но в prod без поводка нельзя

    11 июня 2026 HashiCorp перевела в GA официальный Terraform MCP Server 1.0 — прокладку между LLM и Terraform Registry, чтобы AI писал HCL по актуальной схеме провайдера, а не по памяти годичной давности. Разбираю по официальным докам: что под капотом (toolsets и конкретные tools), как поднять стенд за один docker run, чем отличаются stdio и streamable-http, что даёт доступ к приватному registry в HCP/Terraform Enterprise — и почему деструктивные операции выключены по умолчанию. Отдельно — модель угроз самой HashiCorp (prompt injection, tool poisoning, rug pull) и практический чеклист, чтобы агент однажды не снёс staging. Читать дальше →

    habr.com/ru/articles/1047922/

    #Terraform #MCP #Model_Context_Protocol #HashiCorp #Infrastructure_as_Code #DevOps #AIагенты

  39. Terraform MCP Server 1.0: теперь AI пишет конфиги по свежим провайдерам — но в prod без поводка нельзя

    11 июня 2026 HashiCorp перевела в GA официальный Terraform MCP Server 1.0 — прокладку между LLM и Terraform Registry, чтобы AI писал HCL по актуальной схеме провайдера, а не по памяти годичной давности. Разбираю по официальным докам: что под капотом (toolsets и конкретные tools), как поднять стенд за один docker run, чем отличаются stdio и streamable-http, что даёт доступ к приватному registry в HCP/Terraform Enterprise — и почему деструктивные операции выключены по умолчанию. Отдельно — модель угроз самой HashiCorp (prompt injection, tool poisoning, rug pull) и практический чеклист, чтобы агент однажды не снёс staging. Читать дальше →

    habr.com/ru/articles/1047922/

    #Terraform #MCP #Model_Context_Protocol #HashiCorp #Infrastructure_as_Code #DevOps #AIагенты

  40. 🔐 vault-plugin-secrets-keycloak v0.2.1

    HashiCorp Vault secrets engine for Keycloak. Rotate service account passwords on-demand via the Admin REST API. Cryptographically random, audit-logged, and never stored by Vault.

    ✨ What's new:
    • bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2
    • **security:** bump to go1.26.4 and x/net v0.55.0 to fix 5 CVEs
    • **security:** harden CI supply chain and add fuzz tests

    🔗 github.com/RoFz/vault-plugin-s

    #HashiCorp #Vault #Keycloak #IAM #OpenSource #DevOps #Kubernetes

  41. 🔐 vault-plugin-secrets-keycloak v0.2.1

    HashiCorp Vault secrets engine for Keycloak. Rotate service account passwords on-demand via the Admin REST API. Cryptographically random, audit-logged, and never stored by Vault.

    ✨ What's new:
    • bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2
    • **security:** bump to go1.26.4 and x/net v0.55.0 to fix 5 CVEs
    • **security:** harden CI supply chain and add fuzz tests

    🔗 github.com/RoFz/vault-plugin-s

    #HashiCorp #Vault #Keycloak #IAM #OpenSource #DevOps #Kubernetes

  42. 🔐 vault-plugin-secrets-keycloak v0.2.1

    HashiCorp Vault secrets engine for Keycloak. Rotate service account passwords on-demand via the Admin REST API. Cryptographically random, audit-logged, and never stored by Vault.

    ✨ What's new:
    • bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2
    • **security:** bump to go1.26.4 and x/net v0.55.0 to fix 5 CVEs
    • **security:** harden CI supply chain and add fuzz tests

    🔗 github.com/RoFz/vault-plugin-s

    #HashiCorp #Vault #Keycloak #IAM #OpenSource #DevOps #Kubernetes

  43. 🔐 vault-plugin-secrets-keycloak v0.2.0

    HashiCorp Vault secrets engine for Keycloak. Rotate service account passwords on-demand via the Admin REST API — random, audit-logged, and never stored by Vault.

    ✨ v0.2.0: new KV v2 sync — rotated passwords are automatically patched into a KV v2 secret, keeping Kubernetes secret operators in sync.

    🔗 github.com/RoFz/vault-plugin-s

    #HashiCorp #Vault #Keycloak #IAM #OpenSource #DevOps #Kubernetes

  44. Ahh, I had forgot that #Hashicorp got bought by IBM...

    So anybody I know able to poke people and get Fedora 44 support added to DNF repo?

    github.com/hashicorp/packer/is

    bluetoot.hardill.me.uk/@ben/11

  45. Ahh, I had forgot that #Hashicorp got bought by IBM...

    So anybody I know able to poke people and get Fedora 44 support added to DNF repo?

    github.com/hashicorp/packer/is

    bluetoot.hardill.me.uk/@ben/11

  46. Ahh, I had forgot that #Hashicorp got bought by IBM...

    So anybody I know able to poke people and get Fedora 44 support added to DNF repo?

    github.com/hashicorp/packer/is

    bluetoot.hardill.me.uk/@ben/11

  47. Ahh, I had forgot that #Hashicorp got bought by IBM...

    So anybody I know able to poke people and get Fedora 44 support added to DNF repo?

    github.com/hashicorp/packer/is

    bluetoot.hardill.me.uk/@ben/11

  48. Ahh, I had forgot that #Hashicorp got bought by IBM...

    So anybody I know able to poke people and get Fedora 44 support added to DNF repo?

    github.com/hashicorp/packer/is

    bluetoot.hardill.me.uk/@ben/11

  49. Great Hashicorp don't have Fedora 44 repos yet (I need packer)

    #hashicorp #packer