HashiCorp Vault
Deploy HashiCorp Vault, an open source, centralized secrets management system for storing and distributing sensitive data, including API keys, access tokens, and passwords.
1. Deploy HashiCorp Vault
Follow the deployment instructions from the Get started section to configure the app, deploy it, and verify software installation.
For information on the app-specific configurations, see the Configuration options section.
Base distribution and plan
- Supported distribution: Ubuntu 24.04 LTS
- Recommended plans: Use a 4GB Dedicated CPU or Shared CPU Compute Instance.
Configuration options
Configure the required options to deploy your instance. For additional customization, add advanced options.
The table maps the Cloud Manager UI fields to their corresponding API/CLI keys (stackscript_data) required for automated deployments.
StackScript ID: 1037038
| UI field | API/CLI key | Description |
|---|---|---|
| Required options | ||
| Limited sudo user | user_name |
Your preferred username for the limited sudo user entered without any capital letters, spaces, or special characters. When adding a limited sudo user, the user is created with a strong generated password for your new Linode instance, and the account is assigned to the sudo group, which provides elevated permissions when running commands with the sudo prefix.
Note: For easier and more secure access with the sudo user, add an account SSH key for the Cloud Manager user during deployment and select that user as an
|
| Email address (for the Let's Encrypt SSL certificate) | soa_email_address |
Your email address to use for generating SSL certificates. |
| Advanced options | ||
| Disable root access over SSH | disable_root |
Applies to a limited sudo user. To block the root user from logging in over SSH, select Yes. Defaults to No. Note: When you disable the root user from logging in over SSH and don't provide a valid Account SSH Key assigned to the |
| Linode API token | token_password |
Applies to a custom domain. The Linode API token if you want to use Linode’s DNS Manager to manage DNS records for your custom domain. Follow Manage personal access tokens to get your token on your account with Read/Write access to Domains.
|
| Subdomain | subdomain | Applies to a custom domain. The subdomain you want to use, like blog for blog.example.com. Use it only if you specify a Domain. |
| Domain | domain | Applies to a custom domain. The domain name you want to use, like example.com. Use it only if you specify a Linode API token. |
| Optional data exporter Add-ons | add_ons | An option to include add-ons for your deployment. Possible values are:
|
Notes:
- After the app deployment completes, the password for your limited sudo user is generated and stored in the
.credentialsfile in the home directory, along with application-specific passwords. Log in to your instance asrootthrough the Lish console or SSH, then runcat /home/$USERNAME/.credentialsto view its contents.- You can automatically configure a custom domain (optional) during deployment. To do that:
- First, configure your domain to use Linode’s name servers via your registrar. See Configure your domain's authoritative name servers for details.
- Once you complete that, specify the Linode API token, subdomain, and domain for the app in Cloud Manager or via API/CLI/Terraform.
Use API, CLI, or Terraform
In addition to deploying the app to a new Linode instance via Cloud Manager, you can also use the Linode API, CLI, or Terraform. When running the operation, you need to provide the StackScript ID, supported Linux distribution, and app-specific fields along with the standard Linode deployment configurations.
Note: Generate a personal access token to authenticate your API, CLI, or Terraform requests.
curl --location 'https://api.linode.com/v4/linode/instances' \
--header 'Content-Type: application/json' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer abc123def456hij789klm' \
--data-raw '{
"region": "us-east",
"type": "g6-standard-2",
"image": "linode/ubuntu24.04",
"label": "my-vault-one-click-app",
"root_pass": "@C0mpl3x#P@ssw0rd",
"stackscript_id": 1037038,
"stackscript_data": {
"soa_email_address": "jsmith@example.com",
"user_name": "jsmith"
}
}'linode-cli linodes create \
--region us-east \
--type g6-standard-2 \
--label my-vault-one-click-app \
--image linode/ubuntu24.04 \
--root_pass @C0mpl3x#P@ssw0rd \
--stackscript_id 1037038 \
--stackscript_data '{"soa_email_address":"jsmith@example.com", "user_name":"jsmith"}'resource "linode_instance" "my-linode" {
region = "us-east"
type = "g6-standard-2"
label = "my-vault-one-click-app"
image = "linode/ubuntu24.04"
root_pass = "@C0mpl3x#P@ssw0rd"
stackscript_id = 1037038
stackscript_data = {
"soa_email_address" = "jsmith@example.com"
"user_name" = "jsmith"
}
}2. Access Vault
After deployment, Vault must be initialized and unsealed before it can be used.
Get the unseal key
To view the unseal key and root token:
-
Log in to the Linode instance through SSH or Lish using the
rootuser credentials you created during deployment. -
Display the generated five portions of the unseal key. These portions can be used together to decrypt the root key and unseal Vault.
See also the Seal/Unseal guide for details.
cat /root/.vault_tokens.txtUnseal Key 1: aB1cD2eF/3gH+4iJ5kL//mN6oP7qR8sT9uV1wX2yZ3aB Unseal Key 2: cD4eF5gH+6iJ//kL7mN8oP9qR1sT2uV3wX4yZ5aB6cD Unseal Key 3: eF7gH8iJ/9kL+1mN2oP//qR3sT4uV5wX6yZ7aB8cD9eF Unseal Key 4: gH1iJ2kL//3mN4oP+5qR6sT7uV8wX9yZ1aB2cD3eF4gH Unseal Key 5: iJ5kL6mN+7oP8qR//9sT1uV2wX3yZ4aB5cD6eF7gH8iJ Initial Root Token: hvs.nO9pQ1rS+2tU3vW4xY5zA6 -
Store the unseal key portions and initial root token securely, then delete the file when you no longer need it on the server.
rm /root/.vault_tokens.txt
Access the Vault web UI
- Open your web browser and navigate to
http://[ip-address]:8200, replacing [ip-address] with your Linode instance IPv4 address. See the Manage IP addresses on a Linode guide for information on viewing IP addresses. - Enter any three of the five unseal keys along with the root token to access the Vault instance.
- Once Vault is unsealed, use the web UI to configure secrets, authentication methods, and policies.
Additional resources
HashiCorp recommends using mutual TLS (mTLS) with a private CA to secure cluster communications and the web UI. Review these HashiCorp guides for details:
Additional configurations are required to use the HashiCorp Vault app instance in a production environment. Review these HashiCorp guides before proceeding further:
Note that we can't vouch for the accuracy or timeliness of externally hosted resources.
Updated about 11 hours ago
