This is HashiCorp's official engineering blog, written by the company behind Terraform, Vault, and Consul. It covers how to automate infrastructure, manage secrets, and enforce security policies across clouds. Ideal for DevOps engineers, security professionals, and cloud architects looking to adopt HashiCorp tools.
HashicorpHashiCorp Blog
This is HashiCorp's official engineering blog, written by the company behind Terraform, Vault, and Consul. It covers how to automate infrastructure, manage secrets, and enforce security policies across clouds. Ideal for DevOps engineers, security professionals, and cloud architects looking to adopt HashiCorp tools.
“HashiCorp's blog on infrastructure security, automation, and multi-cloud management.”
Read this when you want to secure secrets, manage multi-cloud infrastructure, or implement policy as code.
Skip it if you need hands-on tutorials for non-HashiCorp tools or general DevOps culture posts.
Compared to AWS Security Blog, this one is more vendor-specific but offers deeper integration patterns for Terraform and Vault.
What this is
As told for the tourist
Start Here
A recommended reading path through the code
Start Here
A recommended reading path through the code
- 01
- 02
- 03
- 04
- 05
- 06
- 07
What's inside
6 sections of the codebase
Posting History
Activity over time
The Archive
Every post, searchable and filtered
LDAP secrets management now available in IBM Vault Enterprise 2.0
8mThis post explains how to migrate LDAP static roles to IBM Vault Enterprise 2.0's centralized rotation system with self-managed flows and automated lifecycle management.
Introducing HCP Terraform powered by Infragraph - now in public preview
6mThis post introduces HCP Terraform powered by Infragraph, a public preview tool that provides a single source of truth for hybrid and multi-cloud infrastructure optimization.
Mitigate credential exposure in Windows environments with Boundary and Vault
7mThis post discusses how Boundary and Vault integrate with Windows AD DS to secure RDP connections using dynamic credentials.
How Vault Secrets Operator (VSO) automates secret management for enterprises on Kubernetes
9mThis post describes how HashiCorp Vault Secrets Operator (VSO) automates secret delivery in Kubernetes and Red Hat OpenShift for secure lifecycle management at scale.
SPIFFE: Securing the identity of agentic AI and non-human actors
7mThis post explains how Vault Enterprise uses native SPIFFE auth to secure non-human identities, including AI agents.
Announcing the new Partner Premier tier for the Terraform Registry
3mThis post announces the launch of a new Partner Premier tier on the Terraform Registry.
Securing the last mile with local account password rotation
8mThis post explains how IBM Vault Enterprise 2.0 automates local account password rotation via SSH to replace shared passwords with unique, audited credentials.
Secure SSH access at scale with HashiCorp Vault and Boundary
9mThis post presents an updated approach to building scalable, role-based SSH access using SSH certificates, Vault, and Boundary for hybrid and multi-cloud environments.
Turning secret detection into measurable risk reduction
6mThis post explains how Vault Radar helps teams move from secret detection to coordinated remediation, reducing credential sprawl risk.
Bridging the trust gap: Unified public CA orchestration with IBM Vault
8mThis post describes how IBM Vault automates public CA workflows and unifies PKI lifecycle management with new public certificate integration.
Faster threat detection with Boundary session recording + Auditbeat
7mThis post explains how to combine Boundary session recordings with Elastic Auditbeat for SIEM-ready privileged access monitoring.
Terraform adds pre-written Sentinel policies for ISO 27001
5mThis post announces pre-written Sentinel policies for ISO 27001 compliance, released by Terraform and AWS.
From zero trust to continuous trust: Securing autonomous AI systems
8mThis post discusses how continuous trust enforces identity, access, and control at runtime for autonomous AI systems, moving beyond zero trust.
From 80 days to 5: How Banco Bradesco accelerated digital product delivery with HCP Terraform
7mThis post describes how Banco Bradesco accelerated digital product delivery from 80 days to 5 using HCP Terraform with policy as code and curated modules.
Advancing secret sync with workload identity federation
7mThis post explains how Vault Enterprise 2.0 modernizes secret sync with workload identity federation, replacing static credentials with short-lived tokens.
Agentic AI changes the shape of trust
9mThis post explores how agentic AI reshapes identity and access, requiring trust to extend beyond login as autonomy scales.
Vault Enterprise 2.0 modernizes identity security at scale
6mThis post highlights how Vault Enterprise 2.0 strengthens identity-based security with operational and usability improvements for scaling adoption.
Simplifying Terraform dynamic credentials on AWS with native OIDC integration
7mThis post explains how AWS AFT's native OIDC integration simplifies Terraform dynamic credentials implementation and strengthens identity-based access.
AWS permission delegation now generally available in HCP Terraform
5mThis post announces the general availability of AWS temporary permission delegation in HCP Terraform for streamlined setup with security guardrails.
HCP Terraform adds IP allow lists
4mThis post announces IP allowlists at the organization and agent level in HCP Terraform to ensure tokens are only accepted from trusted IPs.
Export & Share
Take the field notes with you