---
title: "Secrets in HashiCorp Vault"
description: "Guide to using HashiCorp Vault for managing Aerospike Database Enterprise Edition configuration secrets."
---

# Secrets in HashiCorp Vault

> For the complete documentation index see: [llms.txt](https://aerospike.com/docs/llms.txt)
> 
> All documentation pages available in markdown.

Aerospike Database Enterprise Edition (EE) can fetch secrets from Hashicorp Vault, instead of storing them in the filesystem or an environment variable.

## Configuration parameters that can be secrets

The server can fetch the following configuration parameters from Vault.

-   [`auth-password-file`](https://aerospike.com/docs/database/reference/config#xdr__auth-password-file)
-   [`cert-blacklist`](https://aerospike.com/docs/database/reference/config#network__cert-blacklist)
-   [`cert-file`](https://aerospike.com/docs/database/reference/config#network__cert-file)
-   [`encryption-key-file`](https://aerospike.com/docs/database/reference/config#namespace__encryption-key-file)
-   [`encryption-old-key-file`](https://aerospike.com/docs/database/reference/config#namespace__encryption-old-key-file)
-   [`feature-key-file`](https://aerospike.com/docs/database/reference/config#service__feature-key-file)
-   [`key-file`](https://aerospike.com/docs/database/reference/config#network__key-file)
-   [`key-file-password`](https://aerospike.com/docs/database/reference/config#network__key-file-password)
-   [`query-user-password-file`](https://aerospike.com/docs/database/reference/config#security__query-user-password-file)

::: note
The [`ca-file`](https://aerospike.com/docs/database/reference/config#network__ca-file) parameter cannot be stored in Vault.
:::

## Configuring access to Vault

You must provide the Vault service details in the `service` section of the Aerospike configuration file.

Terminal window

```bash
service {

    ...

    vault-ca  /path/to/vaultcert.pem

    vault-url https://10.0.0.99:8200

    vault-path v1/aerospike-secrets

    vault-token-file /path/to/vault-token

    # vault-namespace asd # (optional) the Vault Enterprise namespace to use

    ...

}
```

| Configuration parameter | Required | Description |
| --- | --- | --- |
| [`vault-ca`](https://aerospike.com/docs/database/reference/config#service__vault-ca) | Y | Path to the TLS certificate used for authenticating against the Vault service. |
| [`vault-token-file`](https://aerospike.com/docs/database/reference/config#service__vault-token-file) | Y | Path to a file containing the Vault token, which authenticates the Aerospike server with the Vault service. |
| [`vault-url`](https://aerospike.com/docs/database/reference/config#service__vault-url) | Y | Address and port of the Vault service. |
| [`vault-path`](https://aerospike.com/docs/database/reference/config#service__vault-path) | Y | Vault path to the stored Aerospike secrets.  
  
A prefix indicating KV Secrets Engine [Version 1](https://developer.hashicorp.com/vault/docs/secrets/kv/kv-v1) or [Version 2](https://developer.hashicorp.com/vault/docs/secrets/kv/kv-v2) may be necessary, depending on the Vault service configuration. |
| [`vault-namespace`](https://aerospike.com/docs/database/reference/config#service__vault-namespace) | N | Vault Enterprise namespace. Added in Database 6.3.0. |

### Updating the Vault token

Starting with Database 6.3.0, you can update the Vault token dynamically during runtime.

1.  Write the new Vault token in the Vault token file.
2.  Dynamically change the `vault-token-file` configuration parameter to the token file path, which can remain the same path.

Terminal window

```bash
asadm

Admin> enable

Admin+> manage config service param vault-token-file to /path/to/vault-token
```

Aerospike reloads the new Vault token and uses it.

## Setting up Aerospike secrets in Vault

Your Aerospike EE secrets must be stored in the Vault service as uniquely named KV engine secrets.

The secret must be a single key-value pair with a key named `key` and a base64-encoded value.

::: caution
Embedding non-trailing whitespace in base64-encoded secrets is not supported. Add `-w 0` to coreutils `base64` to prevent the default line break every 76 characters.
:::

Terminal window

```bash
vault kv put aerospike-secrets/feature-key key=$(base64 -w 0 ~/eval-features.conf)
```

Aerospike does not support secrets with multiple key-value pairs at this point of time.

## Fetching secrets

Aerospike EE fetches a secret from Vault when the configuration parameter’s value starts with a `vault:` prefix, followed by the name of the secret in the Vault service.

### Configuration parameter examples

In the following example, the `feature-key-file` secret is fetched from the Vault service.

Terminal window

```bash
service {

    ...

    feature-key-file vault:feature-key

    ...

}
```

### How the Vault URI is constructed

Using the example values above, the `feature-key-file` secret is constructed in the following way:

| `vault-url` | `vault-path` | Secret name |
| --- | --- | --- |
| `https://10.0.0.99:8200` | `v1/aerospike-secrets` | `feature-key` |

Assuming the KV secrets engine version 1 API is enabled at the path `/aerospike-secrets` in Vault, the server constructs a URI equivalent to the following:

Terminal window

```bash
curl -H "X-Vault-Token: `cat /path/to/vault-token`" http://10.0.0.99:8200/v1/aerospike-secrets/feature-key
```

### Dynamically changing secrets

You can dynamically configure the [`auth-password-file`](https://aerospike.com/docs/database/reference/config#xdr__auth-password-file) parameter with the [set-config](https://aerospike.com/docs/database/reference/info#set-config) `asinfo` command.

## Vault plugin

A community-supported Vault database secrets engine plugin for Aerospike is available at the GitHub repository [aerospike-community/vault-plugin-database-aerospike](https://github.com/aerospike-community/vault-plugin-database-aerospike).