Skip to content
This repository has been archived by the owner on Sep 11, 2023. It is now read-only.


Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
This branch is 4 commits ahead, 234 commits behind bank-vaults:main.

Latest commit

Signed-off-by: Mark Sagi-Kazar <>

Git stats


Failed to load latest commit information.
Latest commit message
Commit time
June 20, 2023 16:36
June 20, 2023 17:16
October 8, 2019 14:28
March 7, 2018 17:02
June 20, 2023 17:31
September 11, 2023 13:27
July 26, 2019 14:11
July 17, 2023 14:23
June 26, 2023 23:03
July 26, 2018 17:49

Bank-Vaults has been migrated to a new organization:

See this post for changes and migration steps.

This project does not receive any more updates. We encourage you to upgrade.

Docker Automated build Docker Pulls GoDoc CircleCI Go Report Card Gitpod Ready-to-Code Total alerts

Bank Vaults is a thick, tricky, shifty right with a fast and intense tube for experienced surfers only, located on Mentawai. Think heavy steel doors, secret unlocking combinations and burly guards with smack-down attitude. Watch out for clean-up sets.

Bank-Vaults is an umbrella project which provides various tools for Vault to make using and operating Hashicorp Vault easier. It's a wrapper for the official Vault client with automatic token renewal and built-in Kubernetes support, dynamic database credential provider for Golang database/sql based clients. It has a CLI tool to automatically initialize, unseal, and configure Vault. It also provides a Kubernetes operator for provisioning, and a mutating webhook for injecting secrets.

Bank-Vaults is a core building block of the Banzai Cloud Pipeline platform. Some of the usage patterns are highlighted through these blog posts:

Securing Kubernetes deployments with Vault:

We use Vault across our large Kubernetes deployments and all the projects were reinventing the wheel. We have externalized all the codebase into this project and removed all the Pipeline and Hollowtrees dependencies thus this project can be used independently as a CLI tool to manage Vault, a Golang library to build upon (OAuth2 tokens, K8s auth, Vault operator, dynamic secrets, cloud credential storage, etc), Helm chart for a HA cluster, operator, mutating webhook and a collection of scripts to support some advanced features (dynamic SSH, etc).

We take bank-vaults' security and our users' trust very seriously. If you believe you have found a security issue in bank-vaults, please contact us at

Bank-Vaults is a core part of Banzai Cloud Pipeline, a Cloud Native application and devops platform that natively supports multi- and hybrid-cloud deployments.

Supported Kubernetes and Vault versions

This project aims to support the latest supported Vault image versions, and three Kubernetes minor versions excluding the latest one.


You usually don't need to use the CLI directly, rather you should install the charts and create Vault instances with the operator and use the webhook inside Kubernetes to mutate Kubernetes resources.

To grab the bank-vaults and vault-env CLI binaries go to the releases page and download them.


Read more about the usage of bank-vaults in the detailed Bank-Vaults documentation and in our blog posts about Bank-Vaults.


If you want to hack with bank-vaults please follow the development documentation.

Bank-Vaults Support

If you encounter any problems that is not addressed in our documentation, open an issue or talk to us on the Banzai Cloud Slack channel #Bank-Vaults.

If you find this project useful, help us:

  • Support the development of this project and star this repo! ⭐
  • If you use Bank-Vaults in a production environment, add yourself to the list of production adopters.🤘
  • Help new users with issues they may encounter 💪
  • Send a pull request with your new features and bug fixes 🚀

Engineering Blog

To be up-to-date with Bank-Vaults and the other open source and commercial products of Banzai Cloud, read our blog.


Kudos to HashiCorp for open sourcing Vault and making secret management easier and more secure.


Copyright (c) 2017-2021 Banzai Cloud, Inc.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.


A Vault swiss-army knife: A CLI tool to init, unseal and configure Vault (auth methods, secret engines).



Code of conduct

Security policy





No packages published


  • Go 84.6%
  • Shell 10.6%
  • Makefile 3.0%
  • Nix 1.2%
  • Dockerfile 0.6%