| name | implementing-hashicorp-vault-dynamic-secrets |
| description | Use when implementing HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation to eliminate static secrets in application configurations. Activates for requests involving Vault secrets engine configuration, dynamic database credentials, ephemeral cloud credentials, or automated secret rotation. |
| domain | cybersecurity |
| tags | ["HashiCorp-Vault","dynamic-secrets","secrets-management","database-credentials","AWS-secrets","PKI"] |
| subdomain | identity-access-management |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.AA-01","PR.AA-02","PR.AA-05","PR.AA-06"] |
Implementing Hashicorp Vault Dynamic Secrets
Overview
Cybersecurity skill for implementing hashicorp vault dynamic secrets. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"implementing hashicorp vault dynamic secrets"
-
"Implements HashiCorp Vault dynamic secrets engines for database credentials, AWS"
-
Applications use static database credentials stored in configuration files or environment variables
-
AWS IAM access keys are long-lived and shared across services
-
Need to eliminate credential sprawl by generating short-lived, per-request secrets
-
Compliance requirements mandate credential rotation (PCI-DSS Requirement 8, NIST 800-53 IA-5)
-
Implementing zero-trust secret management where credentials are never stored at rest
-
Migrating from manual credential management to automated secrets lifecycle
Do not use for storing static secrets that cannot be dynamically generated (use Vault's KV secrets engine instead); dynamic secrets are for credentials that can be programmatically created and revoked on target systems.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- HashiCorp Vault 1.15+ (Community or Enterprise edition)
- Vault server initialized and unsealed with auto-unseal configured (AWS KMS, Azure Key Vault, or Transit)
- Target database systems with admin credentials for Vault to create/revoke dynamic accounts
- AWS IAM account with permissions to create/delete IAM users and access keys
- Network connectivity from Vault to all target systems
- Vault policies and authentication methods configured for consuming applications
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": ,
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}