
HashiCorp Vault
Protect access to the HashiCorp Vault user interface and HTTP API as upstream applications.
Overview
HashiCorp Vault is a secrets management and data protection system. Its user interface and client API normally use port 8200. Port 8201 is internal cluster traffic and is not a user endpoint.
HashiCorp Vault can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to HashiCorp Vault. HashiCorp Vault remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Expose only the selected interface and API listener. Set the public address and trusted proxy behavior, then keep Vault TLS and audit devices active.
Example
Security operators use a Pomerium HTTPS route for the private Vault interface. Vault still requires its normal authentication and applies token, identity, policy, namespace, and secret permissions.
Considerations
- Do not route Vault cluster traffic on port 8201 as user access.
- Pomerium does not replace Vault authentication, tokens, policies, ACLs, namespaces, or TLS. CLI and automation need noninteractive credentials.
