Skip to content

[Sandbox] Bank-Vaults #54

Description

@sagikazarmark

Application contact emails

mark.sagikazar@gmail.com, team@bank-vaults.dev, ospo@cisco.com

Project Summary

Bank-Vaults is a set of tools covering many aspects of secret management in the Cloud Native ecosystem.

Project Description

Bank-Vaults is an umbrella project for Cloud Native secret management tools:

  • Bank-Vaults CLI to make configuring Hashicorp Vault easier
  • Vault operator to make operating Hashicorp Vault on top of Kubernetes easier
  • Vault secrets webhook to inject secrets directly into Kubernetes pods
  • Vault SDK to make working with Vault easier in Go
  • and others

Bank-Vaults aims to help developers and SREs alike by covering the entire secret management pipeline from operating a secret store to injecting and using secrets in applications.

Org repo URL (provide if all repos under the org are in scope of the application)

https://github.com/bank-vaults

Project repo URL in scope of application

https://github.com/bank-vaults/bank-vaults

Additional repos in scope of the application

https://github.com/bank-vaults/vault-operator
https://github.com/bank-vaults/vault-secrets-webhook
https://github.com/bank-vaults/vault-sdk
https://github.com/bank-vaults/vault-helm-chart

Website URL

https://bank-vaults.dev

Roadmap

Roadmap

Roadmap context

The roadmap is still being defined. We are talking to users to figure out their needs and prioritize new features. We already have a number of items on the roadmap, but most of the effort is still going into the project migration from the banzaicloud GitHub organization.

One important goal for the near future is to broaden the scope of the project and add support for other secret management solutions than Hashicorp’s Vault.

Contributing Guide

https://bank-vaults.dev/docs/contributing/

Code of Conduct (CoC)

https://bank-vaults.dev/docs/code-of-conduct/

Adopters

https://github.com/bank-vaults/bank-vaults/blob/main/ADOPTERS.md

Contributing or Sponsoring Org

https://opensource.cisco.com

Maintainers file

https://github.com/bank-vaults/bank-vaults/blob/main/MAINTAINERS.md

IP Policy

  • If the project is accepted, I agree the project will follow the CNCF IP Policy

Trademark and accounts

  • If the project is accepted, I agree to donate all project trademarks and accounts to the CNCF

Why CNCF?

The CNCF hosts a vibrant and diverse community of developers and organizations. Contributing to this ecosystem allows the Bank-Vaults to attract more contributors, leading to better and faster improvements. Furthermore, the CNCF is able to provide a vendor neutral home for the project, allowing for collaboration among various vendors, fostering the creation of a solution that delivers collective benefits to all stakeholders within the ecosystem.

Benefit to the Landscape

Bank-Vaults is a well-known solution in the Cloud Native ecosystem. It’s been around longer than most of the competing projects (in fact, Bank-Vaults served as an inspiration for some of them). When looking at secret management solutions in the Cloud Native ecosystem (particularly Kubernetes), Bank-Vaults represents one of the established models for application secret management.

Cloud Native 'Fit'

Bank-Vaults best fits under the Security & Compliance category.

Cloud Native 'Integration'

The project does not depend on any CNCF projects per se. It uses various libraries (for example from Kubernetes). It primarily depends on Hashicorp Vault at the moment.

Cloud Native Overlap

There is no strong overlap with existing solutions. There are other secret management solutions in the CNCF landscape (for example External Secrets Operator), but it takes a fundamentally different approach to managing secrets. Also, Bank-Vaults has a much broader scope (for example has an operator for managing Vault on Kubernetes in addition to managing secret injection).

Similar projects

The aforementioned External Secrets Operator is what’s closest within the CNCF.

DoiT has a secrets-init component that’s basically a fork of the Vault secrets webhook implementing the same functionality for AWS and GCP secret managers (something that we also plan to add):

https://github.com/doitintl/secrets-init
https://github.com/doitintl/kube-secrets-init

(It’s basically unmaintained at this point)

Another tool based on Bank-Vaults’ webhook: https://github.com/innovia/secrets-consumer-webhook

Another similar tool (basically unmaintained): https://github.com/OT-CONTAINER-KIT/k8s-vault-webhook

Landscape

No

Business Product or Service to Project separation

N/A

Project presentations

Automating secret rotation in Kubernetes:
https://fosdem.org/2023/schedule/event/container_kubernetes_secret_rotation/

Automate Secret Rotation in Kubernetes, Then Get Out of the Way!:
https://www.youtube.com/watch?v=NTdyznb6Lc4

Project champions

@sagikazarmark
@justaugustus

Additional information

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions