Loading…
Attending this event?
May 15, 2024
New York, New York
View More Details & Registration

The Sched app allows you to build your schedule but is separate from your event registration. You must be registered for Cloud Foundry Day North America 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Standard Time. To see the schedule in your preferred timezone, please select from the drop-down menu to the right above "Filter by Date."
Wednesday, May 15 • 2:15pm - 2:40pm
Vault and Credhub: Better Together - Xiujiao Gao & Dennis Bell, FiveTwenty Inc.

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Secrets management for BOSH deployments means more than just creating secrets. They need to be properly secured and rotated on a regular basis, especially X.509 certificates for SSL/mTLS. When we started deploying with BOSH, we used Vault to handle secrets, but this exposed the secrets during deploy and in retrieved manifests. CredHub came along, and hid all the details behind the curtain, but it hid them a little too well, to the point that you can't even tell that secrets were or were not changed when you deploy. A hybrid approach balances visibility and confidentiality, making secret management more accessible and less daunting. Vault is the "One True Source" for secrets, handling tasks like adding, rotating, and verifying secrets during deployments. CredHub holds the secrets used for deployment, referencing a signature-based path containing a 'fingerprint' of secrets, making changes noticeable without compromising security. This improvement ensures the integrity and confidentiality of deployments, enhancing transparency. Using some open-source tooling to glue this together makes life cycle management of secrets a breeze, rather than a dreaded event lurking over the horizon.

Speakers
avatar for Xiujiao Gao

Xiujiao Gao

COO, FiveTwenty Inc.
With 10+ years of technical leadership in cloud platforms, Xiujiao Gao has unique insights into cloud-native technologies. she's managed multi-million dollar cloud migrations, training developers, and actively contributes to open-source communities.
avatar for Dennis Bell

Dennis Bell

Senior Consultant, Five Twenty Inc
Dennis Bell's career is a blend of innovation, quality, and community engagement. Whether focusing on QA, development, Cloud Foundry integration, or the open source community, Dennis continues to inspire and educate, sharing his insights, experiences, and passion for quality and development... Read More →


Wednesday May 15, 2024 2:15pm - 2:40pm EDT
Education Center, 2nd Floor
Feedback form isn't open yet.