Connect Platform to HashiCorp Vault
This page explains how to connect Itential Platform to HashiCorp Vault. When you connect Platform to Vault, you manage secrets in one place and keep credentials out of Platform configuration files.
Before you begin
Before you connect Platform to Vault, make sure you have the following.
HashiCorp Vault requirements
- A running HashiCorp Vault installation. For instructions, see Install Vault in the HashiCorp documentation.
- The kv-v2 secrets engine enabled. For instructions, see KV secrets engine version 2 in the HashiCorp documentation.
- Authentication credentials, either a Vault token file or an AppRole
role_idandsecret_id. - Network connectivity between Platform and your Vault server.
Platform supports only the kv-v2 secrets engine.
Platform requirements
- SSH access to the Platform servers.
- Write access to the
/etc/itential/platform.propertiesfile, or permission to set environment variables.
Configure Platform
You can configure Platform to connect to Vault in any of the following ways:
- Set properties in the Platform properties file.
- Set environment variables. For a list of variables, see Platform properties and environment variables reference.
- Configure a server profile in properties.json.
Platform 6 supports all three methods. Platform 2023.2 supports only the server profile (properties.json) method.
Configuration parameters
The vault_secrets_endpoint value must include /data after the mount point. For example, if your kv-v2 engine is mounted at kv-v2, set the endpoint to kv-v2/data. Platform prepends /v1/ to build the full Vault API URL.
Configuration examples
Read-only mode
The readOnly property controls whether Platform can write secrets back to Vault.
When readOnly is true, which is the default:
- Platform retrieves secrets from Vault but doesn’t write any values back.
- Automatic property encryption is disabled.
When readOnly is false, Platform stores sensitive adapter and integration properties directly in Vault as it processes them. We don’t recommend this setting.
If you change readOnly from false to true after Platform stores secrets in Vault, those secrets become inaccessible. You must re-enter them manually in Itential.
Verify the connection
After you configure Platform, verify that it can connect to Vault.
View the configuration
In Admin Essentials, view the read-only Vault configuration:
- Platform 6: Go to Admin Essentials > Configuration.
- Platform 2023.2: Go to Admin Essentials > Profiles.
Check the Platform logs
Check the Platform logs for Vault messages:
Confirm that the logs show successful authentication and no connection errors.
Test secret retrieval
Retrieve a test secret to validate your setup. For instructions, see Use secrets.