WOWZER. I get having a managed solution is great, but you don't have to store many secrets before running your own Vault server makes sense.
WOWZER. I get having a managed solution is great, but you don't have to store many secrets before running your own Vault server makes sense.
The real issue for some of the people at my work is the vendor lock-in versus vault.
Point being: if you're using a modern stack, you can use modern tools. If you're stuck on a legacy stack, you use legacy tools, and that appears to be who AWS is building for nowadays. Legacy tools, value-based pricing instead of cost-based, charge a boatload, buzzword heaven, sell it to the enterprise, rinse repeat.
The HSM component is the only part here that appears to be worth the price. Azure's competing product is a LOT cheaper, except that their HSM-generated keys are more expensive. Which naturally means, Azure is cost-based pricing, whereas AWS is value-based pricing.
That being said, if the security traffic and/or amount of data is huge, Vault might be cheaper, even with the extra work. I guess it depends on the scenario.