Vault · Cheat sheet

HashiCorp Vault cheat sheet

HashiCorp Vault cheat sheet: auth, KV v2, policies, dynamic secrets, PKI, transit, and operator tasks.

59 commands·7 sections·Updated ·By SecOpsLog

Rows marked Destructive State operation Caution Exposes secrets can remove data, change authoritative state, affect a running system, or print secrets. Read the note before running them against anything that matters.

Connect & authenticate

Beginner
vault server -dev
Start a throwaway in-memory dev server (never for prod).Example output
Unseal Key: 6S3...
Root Token: hvs.abcd1234
export VAULT_ADDR="http://127.0.0.1:8200"
export VAULT_ADDR=https://vault.example.com:8200
Point the CLI at your Vault server.
vault status
Seal state, version, and HA mode.Example output
Key             Value
Sealed          false
Version         2.1.1
HA Enabled      true
vault login
Authenticate with a token (prompts for it).
vault login -method=userpass username=alice
Log in via a non-token auth method.
export VAULT_TOKEN=hvs.CAES...Exposes secrets
Provide a token non-interactively (CI).Exposes secrets: Token lands in shell history and child process environments.
vault token lookup
Show the current token TTL, policies, and metadata.Example output
policies    [default kv-read]
ttl         767h59m
renewable   true
vault token renew
Extend the current token lease.
vault token create -policy=kv-read -ttl=1hExposes secrets
Mint a scoped child token (the token is printed).Exposes secrets: Prints a usable token; treat the output as a credential.

KV v2 secrets

Beginner
vault secrets enable -path=secret kv-v2
Mount a versioned key/value engine.
vault secrets list
Enabled secrets engines and their mount paths.Example output
Path          Type         Description
cubbyhole/    cubbyhole    per-token private secret storage
secret/       kv           key/value secret storage
vault kv put secret/app db_pass=s3cr3t api_key=xyzExposes secrets
Write (creates version 1).Exposes secrets: Values land in shell history; use key=- (stdin) or @file.Example output
==== Secret Path ====
secret/data/app
version    1
created_time  2025-06-12T...
vault kv get secret/appExposes secrets
Read the latest version of all fields.Exposes secrets: Prints every field of the secret in plain text.Example output
====== Data ======
Key       Value
api_key   xyz
db_pass   s3cr3t
vault kv get -field=db_pass secret/appExposes secrets
Print just one field (scripting).Exposes secrets: Prints the secret value in plain text.Example output
s3cr3t
vault kv get -format=json secret/appExposes secrets
Machine-readable output for pipelines.Exposes secrets: Prints every field of the secret in plain text.
vault kv list secret/
List keys under a path.
vault kv patch secret/app db_pass=newExposes secrets
Update one field, creating a new version.Exposes secrets: New value lands in shell history; use key=- (stdin).
vault kv metadata get secret/app
Version history and current/oldest version.
vault kv get -version=2 secret/appExposes secrets
Read a specific historical version.Exposes secrets: Prints every field of that version in plain text.
vault kv rollback -version=1 secret/appCaution
Restore an old version as the newest.Caution: Readers get the old values immediately as the new current version.
vault kv delete secret/appCaution
Soft-delete the latest version (recoverable).Caution: Readers get no data until vault kv undelete; version data is kept.
vault kv destroy -versions=3 secret/appDestructive
Permanently remove version 3.Destructive: Permanently deletes the data of version 3; it cannot be recovered.

Auth methods

Intermediate
vault auth list
Enabled auth methods and their paths.Example output
Path         Type       Description
token/       token      token based creds
approle/     approle
vault auth enable userpass
Enable username/password auth.
vault write auth/userpass/users/alice password=pw token_policies=kv-readExposes secrets
Create a user bound to a policy.Exposes secrets: Password lands in shell history; use password=- (stdin).
vault auth enable approle
Enable AppRole (machine-to-machine).
vault write auth/approle/role/ci token_policies=deploy token_ttl=20m
Define a role for CI.
vault read auth/approle/role/ci/role-id
Fetch the stable role_id.Example output
role_id    59d6...-...
vault write -f auth/approle/role/ci/secret-idExposes secrets
Generate a secret_id (unlimited uses unless the role sets secret_id_num_uses).Exposes secrets: Prints a usable secret_id; handle the output as a credential.Example output
secret_id           a1b2...
secret_id_ttl       0s
vault write auth/approle/login role_id=.. secret_id=..Exposes secrets
Exchange for a scoped token.Exposes secrets: secret_id lands in shell history and the returned token is printed.Example output
token             hvs.CAES...
token_policies    [default deploy]
vault auth enable kubernetes
Let pods authenticate with their ServiceAccount JWT.

Policies

Intermediate
vault policy list
List all policies.
vault policy write kv-read policy.hcl
Create/update a policy from a file.
path "secret/data/app" { capabilities = ["read"] }
HCL rule — grant read on one path.
vault policy read kv-read
Print a policy body.
vault token capabilities secret/data/app
What can THIS token do on a path?Example output
read

Dynamic database secrets

Advanced
vault secrets enable database
Enable the database secrets engine.
vault write database/config/mydb plugin_name=postgresql-database-plugin ...
Configure the connection + allowed roles.
vault write database/roles/ro db_name=mydb default_ttl=1h creation_statements=@ro.sql
Define a role that mints short-lived DB users.
vault read database/creds/roExposes secrets
Get fresh, expiring DB credentials on demand.Exposes secrets: Prints a live database username and password.Example output
lease_id    database/creds/ro/AbC
username    v-token-ro-x9
password    A1b2-...
ttl         1h
vault lease renew database/creds/ro/<id>
Extend a credential lease.
vault lease revoke database/creds/ro/<id>Caution
Revoke immediately (drops the DB user).Caution: Drops the DB user now; clients still using it lose access.

PKI & transit

Advanced
vault secrets enable pki
Enable Vault as a certificate authority.
vault write pki/root/generate/internal common_name=example.com ttl=8760h
Generate a root CA.
vault write pki/roles/web allowed_domains=example.com allow_subdomains=true
Define what certs a role may issue.
vault write pki/issue/web common_name=app.example.comExposes secrets
Issue a short-lived leaf cert + key.Exposes secrets: Prints the private key; Vault does not store it.Example output
certificate       -----BEGIN CERTIFICATE-----
private_key       -----BEGIN RSA...
serial_number     3a:...
vault secrets enable transit
Encryption-as-a-service (keys never leave Vault).
vault write -f transit/keys/orders
Create a named encryption key.
vault write transit/encrypt/orders plaintext=$(base64 <<< secret)Exposes secrets
Encrypt without handling the key.Exposes secrets: The plaintext is in the command, so it lands in shell history; read it from a file or stdin for real data.Example output
ciphertext    vault:v1:8SDd...
vault write transit/decrypt/orders ciphertext=vault:v1:8SDd...Exposes secrets
Decrypt back to base64 plaintext.Exposes secrets: Prints the decrypted plaintext (base64) to the terminal.

Operate

Advanced
vault operator initExposes secrets
Initialize a new Vault: emits unseal keys + root token.Exposes secrets: Prints all unseal keys and the root token; consider -pgp-keys.Example output
Unseal Key 1: ...
Unseal Key 2: ...
Initial Root Token: hvs...
vault operator unseal
Supply one unseal key share (repeat to threshold).Example output
Unseal Progress    1/3
vault operator sealCaution
Seal Vault (blocks all access until unsealed).Caution: Vault rejects all requests until unsealed with the key threshold.
vault audit enable file file_path=/var/log/vault_audit.logCaution
Log every request and response (secret values HMAC-hashed).Caution: If no enabled audit device can write, Vault refuses requests.
vault operator raft list-peers
Integrated-storage cluster members.
vault operator raft snapshot save backup.snap
Back up integrated storage to a snapshot file.
vault operator raft snapshot restore backup.snapDestructive
Restore integrated storage from a snapshot.Destructive: Replaces the cluster's data with the snapshot; anything written after it was taken is lost.
vault operator step-downCaution
Make the active node give up leadership before maintenance.Caution: Forces a leader election; clients can see errors until a standby takes over.
vault lease revoke -prefix database/credsDestructive
Bulk-revoke every lease under a prefix.Destructive: Revokes every lease under the prefix, dropping all issued DB users.

Primary references

Found a technical issue on this page? Report it with the tool version you used and the behavior you saw. How resources are maintained.

Go deeper
Hands-on courses for Vault