Vault 0.10 released
hashicorp.com
hashicorp.com
That is:
$ vault kv undelete -versions=2 secret/my-secret
Success! Data written to: secret/undelete/my-secret
should instead be: $ vault kv undelete -versions=2 secret/my-secret
$
Also, the screenshots on the Vault OSS UI Introduction page [0] are completely unintelligible.[0]: https://www.hashicorp.com/resources/vault-oss-ui-introductio...
Since a lot of people using this tool will be developers with MacBooks and not hardcore *nix users, it’s probably a good choice to ignore that convention.
I disagree, as the average vault user is likely someone familiar with Unix (though there is a Windows binary). Here is an example that I just ran on my machine.. very silent.
$ mkdir source
$ cd source
$ touch file
$ rm file
$ $ rm file
$ echo $?
$ 0
Silent, unless you go looking. The return value of the last executed command is available as $?.I picked this up at http://www.rsync.net/resources/howto/remote_commands.html for running commands over ssh and not seeing the console output.
We should be creating stable and predictable programs so that we can maintain users' trust. Otherwise we have to introduce hand-holding which degrades everyone's experience through extra cognitive overhead and user interaction.
cron adopts this philosophy in that you get an email if there is any output at all.
There is a tool called chronic which you can use as a wrapper which captures stdout and only ouput if the return code is an error:
$ chronic vault kv undelete -versions=2 secret/my-secret
$ $ vault kv put secret/my-secret my-value=itsasecret
$ vault kv patch secret/my-secret new-value=othersecret
^--- this doesn't exist
$ vault kv get secret/my-secret
====== Data ======
Key Value
--- -----
my-value itsasecret
new-value othersecretHowever, the source code was hardcoded to only one logging level (they didn't actually have multiple logging levels). The homepage marketing-speak was disingenuous on this front. Coupled with other poor architecture choices (wasn't actually HA, forced you to use other Hashicorp products, etc), I lost interest in the product.
Seemed they were mostly focused on unique features than standard enterprise requirements. Have things improved?
Also, I believe using Google Storage as a backed now works with clusters meaning Consul is now not required for clustering.