Is possible to scale out Hashicorp Vault using DynamoDB storage backend? The 2019 Stack Overflow Developer Survey Results Are InHow to add storage-level caching between DynamoDB and Titan?Hashicorp Vault for file storage?AWS ELB and Nat Gateway not playing well togetherHashiCorp Vault sealing questionsHow does the Titan (not backend storage) clustering work?HashiCorp Vault: Secret backendsHashicorp Vault ACLsHashicorp Vault single nodeEncryption Details of filesystem backend for Hashicorp Vault Community EditionHashiCorp Consul vs AWS S3 as backend storage for HashiCorp Vault?

A poker game description that does not feel gimmicky

Is bread bad for ducks?

What tool would a Roman-age civilization have to grind silver and other metals into dust?

How to make payment on the internet without leaving a money trail?

How to manage monthly salary

In microwave frequencies, do you use a circulator when you need a (near) perfect diode?

aging parents with no investments

How was Skylab's orbit inclination chosen?

Why is Grand Jury testimony secret?

Limit the amount of RAM Mathematica may access?

"To split hairs" vs "To be pedantic"

What does Linus Torvalds mean when he says that Git "never ever" tracks a file?

Could a US political party gain complete control over the government by removing checks & balances?

Deadlock Graph and Interpretation, solution to avoid

Inversion Puzzle

Spanish for "widget"

Should I use my personal or workplace e-mail when registering to external websites for work purpose?

Extreme, unacceptable situation and I can't attend work tomorrow morning

What do hard-Brexiteers want with respect to the Irish border?

How long do I have to send payment?

Carnot-Caratheodory metric

How to change the limits of integration

Why do UK politicians seemingly ignore opinion polls on Brexit?

Inline version of a function returns different value than non-inline version



Is possible to scale out Hashicorp Vault using DynamoDB storage backend?



The 2019 Stack Overflow Developer Survey Results Are InHow to add storage-level caching between DynamoDB and Titan?Hashicorp Vault for file storage?AWS ELB and Nat Gateway not playing well togetherHashiCorp Vault sealing questionsHow does the Titan (not backend storage) clustering work?HashiCorp Vault: Secret backendsHashicorp Vault ACLsHashicorp Vault single nodeEncryption Details of filesystem backend for Hashicorp Vault Community EditionHashiCorp Consul vs AWS S3 as backend storage for HashiCorp Vault?



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















I am using Vault on AWS with the DynamoDB backend. The backend supports HA.



storage "dynamodb" 
ha_enabled = "true"
region = "us-west-2"
table = "vault-data"



Reading the HA concept documentation:
https://www.vaultproject.io/docs/concepts/ha.html




To be highly available, one of the Vault server nodes grabs a lock within the data store. The successful server node then becomes the active node; all other nodes become standby nodes. At this point, if the standby nodes receive a request, they will either forward the request or redirect the client depending on the current configuration and state of the cluster -- see the sections below for details. Due to this architecture, HA does not enable increased scalability.




I am not interested in having a fleet of EC2 instances behind a ELB, where only 1 instance behaves like a master and talks to DynamoDB.



I would like to run N Ec2 instances running Vault, that read and write independently from DynamoDB.



Because DynamoDB supports read/write from multiple EC2 instances, I would expect to be able to unseal Vault from multiple instances simultaneously and perform read and write operations. This should work even with ha_enabled = "false", without doing the leader election.



Why this architecture is not suggested in the documentation ? Why it should not work ? Is there any cryptographic limitation that I am missing ?



thank you










share|improve this question




























    1















    I am using Vault on AWS with the DynamoDB backend. The backend supports HA.



    storage "dynamodb" 
    ha_enabled = "true"
    region = "us-west-2"
    table = "vault-data"



    Reading the HA concept documentation:
    https://www.vaultproject.io/docs/concepts/ha.html




    To be highly available, one of the Vault server nodes grabs a lock within the data store. The successful server node then becomes the active node; all other nodes become standby nodes. At this point, if the standby nodes receive a request, they will either forward the request or redirect the client depending on the current configuration and state of the cluster -- see the sections below for details. Due to this architecture, HA does not enable increased scalability.




    I am not interested in having a fleet of EC2 instances behind a ELB, where only 1 instance behaves like a master and talks to DynamoDB.



    I would like to run N Ec2 instances running Vault, that read and write independently from DynamoDB.



    Because DynamoDB supports read/write from multiple EC2 instances, I would expect to be able to unseal Vault from multiple instances simultaneously and perform read and write operations. This should work even with ha_enabled = "false", without doing the leader election.



    Why this architecture is not suggested in the documentation ? Why it should not work ? Is there any cryptographic limitation that I am missing ?



    thank you










    share|improve this question
























      1












      1








      1








      I am using Vault on AWS with the DynamoDB backend. The backend supports HA.



      storage "dynamodb" 
      ha_enabled = "true"
      region = "us-west-2"
      table = "vault-data"



      Reading the HA concept documentation:
      https://www.vaultproject.io/docs/concepts/ha.html




      To be highly available, one of the Vault server nodes grabs a lock within the data store. The successful server node then becomes the active node; all other nodes become standby nodes. At this point, if the standby nodes receive a request, they will either forward the request or redirect the client depending on the current configuration and state of the cluster -- see the sections below for details. Due to this architecture, HA does not enable increased scalability.




      I am not interested in having a fleet of EC2 instances behind a ELB, where only 1 instance behaves like a master and talks to DynamoDB.



      I would like to run N Ec2 instances running Vault, that read and write independently from DynamoDB.



      Because DynamoDB supports read/write from multiple EC2 instances, I would expect to be able to unseal Vault from multiple instances simultaneously and perform read and write operations. This should work even with ha_enabled = "false", without doing the leader election.



      Why this architecture is not suggested in the documentation ? Why it should not work ? Is there any cryptographic limitation that I am missing ?



      thank you










      share|improve this question














      I am using Vault on AWS with the DynamoDB backend. The backend supports HA.



      storage "dynamodb" 
      ha_enabled = "true"
      region = "us-west-2"
      table = "vault-data"



      Reading the HA concept documentation:
      https://www.vaultproject.io/docs/concepts/ha.html




      To be highly available, one of the Vault server nodes grabs a lock within the data store. The successful server node then becomes the active node; all other nodes become standby nodes. At this point, if the standby nodes receive a request, they will either forward the request or redirect the client depending on the current configuration and state of the cluster -- see the sections below for details. Due to this architecture, HA does not enable increased scalability.




      I am not interested in having a fleet of EC2 instances behind a ELB, where only 1 instance behaves like a master and talks to DynamoDB.



      I would like to run N Ec2 instances running Vault, that read and write independently from DynamoDB.



      Because DynamoDB supports read/write from multiple EC2 instances, I would expect to be able to unseal Vault from multiple instances simultaneously and perform read and write operations. This should work even with ha_enabled = "false", without doing the leader election.



      Why this architecture is not suggested in the documentation ? Why it should not work ? Is there any cryptographic limitation that I am missing ?



      thank you







      amazon-dynamodb hashicorp-vault






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Mar 8 at 8:46









      Saverio ProtoSaverio Proto

      513316




      513316






















          0






          active

          oldest

          votes












          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55059564%2fis-possible-to-scale-out-hashicorp-vault-using-dynamodb-storage-backend%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55059564%2fis-possible-to-scale-out-hashicorp-vault-using-dynamodb-storage-backend%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Save data to MySQL database using ExtJS and PHP [closed]2019 Community Moderator ElectionHow can I prevent SQL injection in PHP?Which MySQL data type to use for storing boolean valuesPHP: Delete an element from an arrayHow do I connect to a MySQL Database in Python?Should I use the datetime or timestamp data type in MySQL?How to get a list of MySQL user accountsHow Do You Parse and Process HTML/XML in PHP?Reference — What does this symbol mean in PHP?How does PHP 'foreach' actually work?Why shouldn't I use mysql_* functions in PHP?

          Compiling GNU Global with universal-ctags support Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern) Data science time! April 2019 and salary with experience The Ask Question Wizard is Live!Tags for Emacs: Relationship between etags, ebrowse, cscope, GNU Global and exuberant ctagsVim and Ctags tips and trickscscope or ctags why choose one over the other?scons and ctagsctags cannot open option file “.ctags”Adding tag scopes in universal-ctagsShould I use Universal-ctags?Universal ctags on WindowsHow do I install GNU Global with universal ctags support using Homebrew?Universal ctags with emacsHow to highlight ctags generated by Universal Ctags in Vim?

          Add ONERROR event to image from jsp tldHow to add an image to a JPanel?Saving image from PHP URLHTML img scalingCheck if an image is loaded (no errors) with jQueryHow to force an <img> to take up width, even if the image is not loadedHow do I populate hidden form field with a value set in Spring ControllerStyling Raw elements Generated from JSP tagds with Jquery MobileLimit resizing of images with explicitly set width and height attributeserror TLD use in a jsp fileJsp tld files cannot be resolved