shouldiuse.io

VERDICT

Should I use Vaultproject (HashiCorp Vault)?

Enterprise secrets and identity management - vaultproject.io

Depends. Buy if you're a mid-to-large platform team that needs dynamic secrets, PKI, and can staff its operation. Small teams and single-cloud shops should use a managed secret store or SOPS instead.

Confidence

Medium. Based on 20+ public sources; most snippets were truncated, so specifics are limited.

Ratings

  • Value for moneyNo published pricing to judge
  • Ease of use
  • Feature depth
  • Support qualityNo evidence reviewed
  • Security posture

Pricing

Not published

Enterprise

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Platform teams at mid-size and large orgs
  • Dynamic, short-lived credentials at scale
  • Multi-cloud PKI and encryption offload
  • Compliance-driven shops (CCPA workflows)

Not for

  • Solo devs — SOPS or .env files suffice
  • Small teams without a dedicated ops owner
  • All-in AWS/Azure shops — managed secret stores are simpler
  • Buyers wanting transparent, self-serve pricing

Gotchas - check before you buy

high

HA, TLS, and unseal operations demand dedicated DevOps ownership

medium

Expect sales-led quotes; no self-serve pricing is published

medium

Sentinel policies and namespaces locked to Enterprise tier

medium

Deep integration creates switching costs; consider an External Secrets abstraction

Pros and cons

Pros

  • Dynamic secrets, PKI, and SSH credential issuance built in
  • Deep ecosystem: Kubernetes, External Secrets, Terraform, OIDC
  • Public HCSEC advisory process for disclosed vulnerabilities
  • Proven at scale; one operator reported ~600k secrets

Cons

  • Documentation reportedly unclear in places
  • No published pricing; premium-only per listings
  • HA and TLS setup widely reported as painful
  • Key features (Sentinel, namespaces) are Enterprise-gated

Sources & method

Analyzed 9/26/2026 - 10 sources - HCSEC advisory process; one disclosed 2020 Enterprise policy issue found in reviewed sources.

official x1review x6security x1news x2
  • HCSEC-2020-24: Vault Enterprise Sentinel EGP policies may impact parent or sibling namespaces, Disclosed Dec 16, 2020; affected Enterprise-grade policy isolation across namespaces.

Key stats

  • Ease of use: 2/5

    Rating

  • Not published

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money. No published pricing to judge
  • Ease of use: 2/5. Docs and HA/TLS setup complaints recur
  • Feature depth: 5/5. Dynamic secrets, PKI, SSH, namespaces, wide integrations
  • Support quality. No evidence reviewed
  • Security posture: 4/5. Purpose-built; public advisories; one 2020 Enterprise issue
  • 2015 First release HN launch thread, Apr 2015
  • Premium only Pricing No public numbers; sales-led
  • ~600k secrets Scale benchmark Operator-reported deployment

Pricing

Enterprise

Not published

  • Sales-led quotes only
  • Sentinel policies, namespaces, replication

Security

HCSEC advisory process; one disclosed 2020 Enterprise policy issue found in reviewed sources.

  • HCSEC-2020-24: Vault Enterprise Sentinel EGP policies may impact parent or sibling namespacesDisclosed Dec 16, 2020; affected Enterprise-grade policy isolation across namespaces.⁵

What users say

Operators praise the API but consistently report setup, HA/TLS, and documentation friction.

“Vault api is awesome”
Reddit, r/devops

Alternatives

Compare Vaultproject (HashiCorp Vault) with each alternative.

  • AWS Secrets Manager

    Managed, pay-per-secret; simplest if you're all-in on AWS.

  • Azure Key Vault

    Azure-native; pairs with AD identity, no servers to run.

  • CyberArk

    Heavier enterprise PAM; proven in regulated industries.

  • SOPS + KMS

    Encrypted files in git; far simpler for small teams.

Companies that use it

  • Unvired10
  • Anapaya
  • Galaxy Project
Full analysis

Based on 20+ public sources; most snippets were truncated, so specifics are limited.

Enterprise-grade secrets manager: powerful but ops-heavy. Small teams get 90% of value from AWS/Azure secret stores or SOPS.

Methodology

Based on 20+ public sources; most snippets were truncated, so specifics are limited.

Sources

  1. review
  2. review
  3. review
  4. official
  5. HCSEC-2020-24 advisorydiscuss.hashicorp.com
    security
  6. review
  7. review
  8. news
  9. review
  10. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.