#hashicorp — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #hashicorp, aggregated by home.social.
-
⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects
🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists
-
⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects
🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists
-
⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects
🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists
-
⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects
🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists
-
⚙️ 80+ S3 operations: versioning, multipart upload, object locking (WORM), lifecycle rules, presigned URLs, batch delete, S3 Select with SQL on CSV, JSON & Parquet objects
🔐 AES-256-GCM encryption at rest with SSE-S3 and SSE-KMS via #HashiCorp #Vault, IAM users/groups/policies with default-deny evaluation, STS temporary credentials, LDAP & #OIDC SSO, IP allow/blocklists
-
Supply chains and package managers are a considerable security concern, making a secure dev environment more important than ever before.
I published my #webdev environment publicly, with docs, so anyone can see how and why I do what I do, and reuse/replicate.
A #Mac #Docker Desktop devenv 4 ppl who need #browsers, #NodeJS, #Golang, #Caddy (auto SSL), #Hashicorp #openbao vault secrets, and multi project support:
https://github.com/localnerve/dev-container
Attach and go.
Security for you, security for all.
-
Supply chains and package managers are a considerable security concern, making a secure dev environment more important than ever before.
I published my #webdev environment publicly, with docs, so anyone can see how and why I do what I do, and reuse/replicate.
A #Mac #Docker Desktop devenv 4 ppl who need #browsers, #NodeJS, #Golang, #Caddy (auto SSL), #Hashicorp #openbao vault secrets, and multi project support:
https://github.com/localnerve/dev-container
Attach and go.
Security for you, security for all.
-
Supply chains and package managers are a considerable security concern, making a secure dev environment more important than ever before.
I published my #webdev environment publicly, with docs, so anyone can see how and why I do what I do, and reuse/replicate.
A #Mac #Docker Desktop devenv 4 ppl who need #browsers, #NodeJS, #Golang, #Caddy (auto SSL), #Hashicorp #openbao vault secrets, and multi project support:
https://github.com/localnerve/dev-container
Attach and go.
Security for you, security for all.
-
Supply chains and package managers are a considerable security concern, making a secure dev environment more important than ever before.
I published my #webdev environment publicly, with docs, so anyone can see how and why I do what I do, and reuse/replicate.
A #Mac #Docker Desktop devenv 4 ppl who need #browsers, #NodeJS, #Golang, #Caddy (auto SSL), #Hashicorp #openbao vault secrets, and multi project support:
https://github.com/localnerve/dev-container
Attach and go.
Security for you, security for all.
-
Ooh I just found this shiny thing. Scale to zero component for Nomad & Traefik. https://github.com/Metatable-ai/nscale
-
Ooh I just found this shiny thing. Scale to zero component for Nomad & Traefik. https://github.com/Metatable-ai/nscale
-
Ooh I just found this shiny thing. Scale to zero component for Nomad & Traefik. https://github.com/Metatable-ai/nscale
-
Ooh I just found this shiny thing. Scale to zero component for Nomad & Traefik. https://github.com/Metatable-ai/nscale
-
Ooh I just found this shiny thing. Scale to zero component for Nomad & Traefik. https://github.com/Metatable-ai/nscale
-
A Vault Secrets Operator vulnerability, CVE-2026-8715, lets tenants read pod files and gain privilege escalation. Patch to 1.5.0 now.
#HashiCorp #Vault #Kubernetes #CVE #PrivilegeEscalation #CyberSecurity #InfoSec #Vulnerability
-
HashiCorp has released the public beta of Vault Kubernetes Key Management.
The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.
Details 👉 https://bit.ly/4wKCvhN
-
HashiCorp has released the public beta of Vault Kubernetes Key Management.
The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.
Details 👉 https://bit.ly/4wKCvhN
-
HashiCorp has released the public beta of Vault Kubernetes Key Management.
The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.
Details 👉 https://bit.ly/4wKCvhN
-
HashiCorp has released the public beta of Vault Kubernetes Key Management.
The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.
Details 👉 https://bit.ly/4wKCvhN
-
HashiCorp has released the public beta of Vault Kubernetes Key Management.
The KMS v2-compatible plugin (vault-kube-kms) lets the Kubernetes API server delegate envelope encryption to Vault Enterprise - moving key encryption keys (KEKs) out of the cluster into an independent trust domain.
Details 👉 https://bit.ly/4wKCvhN
-
Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks
Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!
-
Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks
Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!
-
Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks
Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!
-
Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks
Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!
-
Excited to share this discussion with now-former #HashiCorp co-founder and CTO Armon Dadgar about the philosophy behind his recent op-ed, "The Wall-E Economy." In it, he warned of a potential dystopia brought on by a frictionless consumer society -- but there are takeaways for business and tech leaders, too. #AI #AIrisks
Check it out, give it a thumbs up, and don't forget to rate, review and subscribe!
-
Ramble v0.5.10 is now available.
This release improves installation and distribution security:
• Developer ID signed and Apple-notarized macOS binaries
• Trusted Homebrew Cask
• Patched Go dependencies
• Signed builds for Intel and Apple SiliconInstall with:
brew install --cask open-wander/tap/ramble -
Ramble v0.5.10 is now available.
This release improves installation and distribution security:
• Developer ID signed and Apple-notarized macOS binaries
• Trusted Homebrew Cask
• Patched Go dependencies
• Signed builds for Intel and Apple SiliconInstall with:
brew install --cask open-wander/tap/ramble -
Ramble v0.5.10 is now available.
This release improves installation and distribution security:
• Developer ID signed and Apple-notarized macOS binaries
• Trusted Homebrew Cask
• Patched Go dependencies
• Signed builds for Intel and Apple SiliconInstall with:
brew install --cask open-wander/tap/ramble -
Ramble v0.5.10 is now available.
This release improves installation and distribution security:
• Developer ID signed and Apple-notarized macOS binaries
• Trusted Homebrew Cask
• Patched Go dependencies
• Signed builds for Intel and Apple SiliconInstall with:
brew install --cask open-wander/tap/ramble -
Мониторинг сорока сайтов мышкой: как я написал Terraform-провайдер и опубликовал его в реестре
Сорок клиентских сайтов. У каждого четыре проверки: доступность, сертификат, срок домена, битые ссылки. Сто шестьдесят проверок, заведённых руками через веб-интерфейс. Пока их двадцать, это терпимо. Когда приходит сорок первый клиент, ты открываешь кабинет и снова кликаешь: создать проверку, интервал, порог, теги, сохранить. Четыре раза. А потом кто-то спрашивает: «а почему у этого сайта порог два, а у соседнего три?» — и честный ответ звучит как «не помню». Инфраструктуру мы описываем кодом уже лет десять. Мониторинг — почему-то нет. Хотя это ровно такая же конфигурация: её надо ревьюить, версионировать и уметь воспроизвести.
https://habr.com/ru/articles/1063658/
#terraform #terraform_provider #terraform_registry #monitoring_as_code #infrastructure_as_code #go #hashicorp #goreleaser #configdriven_import #мониторинг
-
Мониторинг сорока сайтов мышкой: как я написал Terraform-провайдер и опубликовал его в реестре
Сорок клиентских сайтов. У каждого четыре проверки: доступность, сертификат, срок домена, битые ссылки. Сто шестьдесят проверок, заведённых руками через веб-интерфейс. Пока их двадцать, это терпимо. Когда приходит сорок первый клиент, ты открываешь кабинет и снова кликаешь: создать проверку, интервал, порог, теги, сохранить. Четыре раза. А потом кто-то спрашивает: «а почему у этого сайта порог два, а у соседнего три?» — и честный ответ звучит как «не помню». Инфраструктуру мы описываем кодом уже лет десять. Мониторинг — почему-то нет. Хотя это ровно такая же конфигурация: её надо ревьюить, версионировать и уметь воспроизвести.
https://habr.com/ru/articles/1063658/
#terraform #terraform_provider #terraform_registry #monitoring_as_code #infrastructure_as_code #go #hashicorp #goreleaser #configdriven_import #мониторинг
-
Мониторинг сорока сайтов мышкой: как я написал Terraform-провайдер и опубликовал его в реестре
Сорок клиентских сайтов. У каждого четыре проверки: доступность, сертификат, срок домена, битые ссылки. Сто шестьдесят проверок, заведённых руками через веб-интерфейс. Пока их двадцать, это терпимо. Когда приходит сорок первый клиент, ты открываешь кабинет и снова кликаешь: создать проверку, интервал, порог, теги, сохранить. Четыре раза. А потом кто-то спрашивает: «а почему у этого сайта порог два, а у соседнего три?» — и честный ответ звучит как «не помню». Инфраструктуру мы описываем кодом уже лет десять. Мониторинг — почему-то нет. Хотя это ровно такая же конфигурация: её надо ревьюить, версионировать и уметь воспроизвести.
https://habr.com/ru/articles/1063658/
#terraform #terraform_provider #terraform_registry #monitoring_as_code #infrastructure_as_code #go #hashicorp #goreleaser #configdriven_import #мониторинг
-
Dear Hashicorp Vault or OpenBao users,
what is the least expensive way to unseal a Vault/OpenBao?
Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.
HSM is out of the question for a small setup, developer mode is too.
Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?
-
Dear Hashicorp Vault or OpenBao users,
what is the least expensive way to unseal a Vault/OpenBao?
Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.
HSM is out of the question for a small setup, developer mode is too.
Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?
-
Dear Hashicorp Vault or OpenBao users,
what is the least expensive way to unseal a Vault/OpenBao?
Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.
HSM is out of the question for a small setup, developer mode is too.
Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?
-
Dear Hashicorp Vault or OpenBao users,
what is the least expensive way to unseal a Vault/OpenBao?
Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.
HSM is out of the question for a small setup, developer mode is too.
Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?
-
Dear Hashicorp Vault or OpenBao users,
what is the least expensive way to unseal a Vault/OpenBao?
Last time I looked, some years ago, AWS charged 1 €/month for keeping one (!) Secret, that would unseal a Vault instance. Same with Azure.
HSM is out of the question for a small setup, developer mode is too.
Not sure if Hetzner, Stackit or OVH have anything usable for storing the unseal secret?
-
📦 jippi/awesome-nomad
A curated list of amazingly awesome Nomad tools and shiny things.
A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities
⭐ Stars: 913
📅 Last Update: Jun 06, 2026https://github.com/jippi/awesome-nomad
#selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp
-
📦 jippi/awesome-nomad
A curated list of amazingly awesome Nomad tools and shiny things.
A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities
⭐ Stars: 913
📅 Last Update: Jun 06, 2026https://github.com/jippi/awesome-nomad
#selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp
-
📦 jippi/awesome-nomad
A curated list of amazingly awesome Nomad tools and shiny things.
A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities
⭐ Stars: 913
📅 Last Update: Jun 06, 2026https://github.com/jippi/awesome-nomad
#selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp
-
📦 jippi/awesome-nomad
A curated list of amazingly awesome Nomad tools and shiny things.
A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities
⭐ Stars: 913
📅 Last Update: Jun 06, 2026https://github.com/jippi/awesome-nomad
#selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp
-
📦 jippi/awesome-nomad
A curated list of amazingly awesome Nomad tools and shiny things.
A curated collection of Nomad tools plugins and integrations for deployment UI autoscaling CI/CD and utilities
⭐ Stars: 913
📅 Last Update: Jun 06, 2026https://github.com/jippi/awesome-nomad
#selfhosted #homelab #selfhost #selfhosting #opensource #nomad #hashicorp
-
https://github.com/hashicorp/agent-skills - #Hashicorp #Agent #skills and plugins
-
Terraform MCP Server 1.0: теперь AI пишет конфиги по свежим провайдерам — но в prod без поводка нельзя
11 июня 2026 HashiCorp перевела в GA официальный Terraform MCP Server 1.0 — прокладку между LLM и Terraform Registry, чтобы AI писал HCL по актуальной схеме провайдера, а не по памяти годичной давности. Разбираю по официальным докам: что под капотом (toolsets и конкретные tools), как поднять стенд за один docker run, чем отличаются stdio и streamable-http, что даёт доступ к приватному registry в HCP/Terraform Enterprise — и почему деструктивные операции выключены по умолчанию. Отдельно — модель угроз самой HashiCorp (prompt injection, tool poisoning, rug pull) и практический чеклист, чтобы агент однажды не снёс staging. Читать дальше →
https://habr.com/ru/articles/1047922/
#Terraform #MCP #Model_Context_Protocol #HashiCorp #Infrastructure_as_Code #DevOps #AIагенты
-
Terraform MCP Server 1.0: теперь AI пишет конфиги по свежим провайдерам — но в prod без поводка нельзя
11 июня 2026 HashiCorp перевела в GA официальный Terraform MCP Server 1.0 — прокладку между LLM и Terraform Registry, чтобы AI писал HCL по актуальной схеме провайдера, а не по памяти годичной давности. Разбираю по официальным докам: что под капотом (toolsets и конкретные tools), как поднять стенд за один docker run, чем отличаются stdio и streamable-http, что даёт доступ к приватному registry в HCP/Terraform Enterprise — и почему деструктивные операции выключены по умолчанию. Отдельно — модель угроз самой HashiCorp (prompt injection, tool poisoning, rug pull) и практический чеклист, чтобы агент однажды не снёс staging. Читать дальше →
https://habr.com/ru/articles/1047922/
#Terraform #MCP #Model_Context_Protocol #HashiCorp #Infrastructure_as_Code #DevOps #AIагенты
-
Terraform MCP Server 1.0: теперь AI пишет конфиги по свежим провайдерам — но в prod без поводка нельзя
11 июня 2026 HashiCorp перевела в GA официальный Terraform MCP Server 1.0 — прокладку между LLM и Terraform Registry, чтобы AI писал HCL по актуальной схеме провайдера, а не по памяти годичной давности. Разбираю по официальным докам: что под капотом (toolsets и конкретные tools), как поднять стенд за один docker run, чем отличаются stdio и streamable-http, что даёт доступ к приватному registry в HCP/Terraform Enterprise — и почему деструктивные операции выключены по умолчанию. Отдельно — модель угроз самой HashiCorp (prompt injection, tool poisoning, rug pull) и практический чеклист, чтобы агент однажды не снёс staging. Читать дальше →
https://habr.com/ru/articles/1047922/
#Terraform #MCP #Model_Context_Protocol #HashiCorp #Infrastructure_as_Code #DevOps #AIагенты
-
🔐 vault-plugin-secrets-keycloak v0.2.1
HashiCorp Vault secrets engine for Keycloak. Rotate service account passwords on-demand via the Admin REST API. Cryptographically random, audit-logged, and never stored by Vault.
✨ What's new:
• bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2
• **security:** bump to go1.26.4 and x/net v0.55.0 to fix 5 CVEs
• **security:** harden CI supply chain and add fuzz tests🔗 https://github.com/RoFz/vault-plugin-secrets-keycloak/releases/tag/v0.2.1
#HashiCorp #Vault #Keycloak #IAM #OpenSource #DevOps #Kubernetes
-
🔐 vault-plugin-secrets-keycloak v0.2.1
HashiCorp Vault secrets engine for Keycloak. Rotate service account passwords on-demand via the Admin REST API. Cryptographically random, audit-logged, and never stored by Vault.
✨ What's new:
• bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2
• **security:** bump to go1.26.4 and x/net v0.55.0 to fix 5 CVEs
• **security:** harden CI supply chain and add fuzz tests🔗 https://github.com/RoFz/vault-plugin-secrets-keycloak/releases/tag/v0.2.1
#HashiCorp #Vault #Keycloak #IAM #OpenSource #DevOps #Kubernetes
-
🔐 vault-plugin-secrets-keycloak v0.2.1
HashiCorp Vault secrets engine for Keycloak. Rotate service account passwords on-demand via the Admin REST API. Cryptographically random, audit-logged, and never stored by Vault.
✨ What's new:
• bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2
• **security:** bump to go1.26.4 and x/net v0.55.0 to fix 5 CVEs
• **security:** harden CI supply chain and add fuzz tests🔗 https://github.com/RoFz/vault-plugin-secrets-keycloak/releases/tag/v0.2.1
#HashiCorp #Vault #Keycloak #IAM #OpenSource #DevOps #Kubernetes
-
🔐 vault-plugin-secrets-keycloak v0.2.0
HashiCorp Vault secrets engine for Keycloak. Rotate service account passwords on-demand via the Admin REST API — random, audit-logged, and never stored by Vault.
✨ v0.2.0: new KV v2 sync — rotated passwords are automatically patched into a KV v2 secret, keeping Kubernetes secret operators in sync.
🔗 https://github.com/RoFz/vault-plugin-secrets-keycloak/releases/tag/v0.2.0
#HashiCorp #Vault #Keycloak #IAM #OpenSource #DevOps #Kubernetes
-
Ahh, I had forgot that #Hashicorp got bought by IBM...
So anybody I know able to poke people and get Fedora 44 support added to DNF repo?
-
Ahh, I had forgot that #Hashicorp got bought by IBM...
So anybody I know able to poke people and get Fedora 44 support added to DNF repo?
-
Ahh, I had forgot that #Hashicorp got bought by IBM...
So anybody I know able to poke people and get Fedora 44 support added to DNF repo?
-
Ahh, I had forgot that #Hashicorp got bought by IBM...
So anybody I know able to poke people and get Fedora 44 support added to DNF repo?
-
Ahh, I had forgot that #Hashicorp got bought by IBM...
So anybody I know able to poke people and get Fedora 44 support added to DNF repo?
-
Great Hashicorp don't have Fedora 44 repos yet (I need packer)