Vault · Cheat sheet
HashiCorp Vault cheat sheet
HashiCorp Vault cheat sheet: auth, KV v2, policies, dynamic secrets, PKI, transit, and operator tasks.
Rows marked Destructive State operation Caution Exposes secrets can remove data, change authoritative state, affect a running system, or print secrets. Read the note before running them against anything that matters.
Connect & authenticate
Beginnervault server -dev- Start a throwaway in-memory dev server (never for prod).Example output
Unseal Key: 6S3... Root Token: hvs.abcd1234 export VAULT_ADDR="http://127.0.0.1:8200"
export VAULT_ADDR=https://vault.example.com:8200- Point the CLI at your Vault server.
vault status- Seal state, version, and HA mode.Example output
Key Value Sealed false Version 2.1.1 HA Enabled true
vault login- Authenticate with a token (prompts for it).
vault login -method=userpass username=alice- Log in via a non-token auth method.
export VAULT_TOKEN=hvs.CAES...Exposes secrets- Provide a token non-interactively (CI).Exposes secrets: Token lands in shell history and child process environments.
vault token lookup- Show the current token TTL, policies, and metadata.Example output
policies [default kv-read] ttl 767h59m renewable true
vault token renew- Extend the current token lease.
vault token create -policy=kv-read -ttl=1hExposes secrets- Mint a scoped child token (the token is printed).Exposes secrets: Prints a usable token; treat the output as a credential.
KV v2 secrets
Beginnervault secrets enable -path=secret kv-v2- Mount a versioned key/value engine.
vault secrets list- Enabled secrets engines and their mount paths.Example output
Path Type Description cubbyhole/ cubbyhole per-token private secret storage secret/ kv key/value secret storage
vault kv put secret/app db_pass=s3cr3t api_key=xyzExposes secrets- Write (creates version 1).Exposes secrets: Values land in shell history; use key=- (stdin) or @file.Example output
==== Secret Path ==== secret/data/app version 1 created_time 2025-06-12T...
vault kv get secret/appExposes secrets- Read the latest version of all fields.Exposes secrets: Prints every field of the secret in plain text.Example output
====== Data ====== Key Value api_key xyz db_pass s3cr3t
vault kv get -field=db_pass secret/appExposes secrets- Print just one field (scripting).Exposes secrets: Prints the secret value in plain text.Example output
s3cr3t
vault kv get -format=json secret/appExposes secrets- Machine-readable output for pipelines.Exposes secrets: Prints every field of the secret in plain text.
vault kv list secret/- List keys under a path.
vault kv patch secret/app db_pass=newExposes secrets- Update one field, creating a new version.Exposes secrets: New value lands in shell history; use key=- (stdin).
vault kv metadata get secret/app- Version history and current/oldest version.
vault kv get -version=2 secret/appExposes secrets- Read a specific historical version.Exposes secrets: Prints every field of that version in plain text.
vault kv rollback -version=1 secret/appCaution- Restore an old version as the newest.Caution: Readers get the old values immediately as the new current version.
vault kv delete secret/appCaution- Soft-delete the latest version (recoverable).Caution: Readers get no data until vault kv undelete; version data is kept.
vault kv destroy -versions=3 secret/appDestructive- Permanently remove version 3.Destructive: Permanently deletes the data of version 3; it cannot be recovered.
Auth methods
Intermediatevault auth list- Enabled auth methods and their paths.Example output
Path Type Description token/ token token based creds approle/ approle
vault auth enable userpass- Enable username/password auth.
vault write auth/userpass/users/alice password=pw token_policies=kv-readExposes secrets- Create a user bound to a policy.Exposes secrets: Password lands in shell history; use password=- (stdin).
vault auth enable approle- Enable AppRole (machine-to-machine).
vault write auth/approle/role/ci token_policies=deploy token_ttl=20m- Define a role for CI.
vault read auth/approle/role/ci/role-id- Fetch the stable role_id.Example output
role_id 59d6...-...
vault write -f auth/approle/role/ci/secret-idExposes secrets- Generate a secret_id (unlimited uses unless the role sets secret_id_num_uses).Exposes secrets: Prints a usable secret_id; handle the output as a credential.Example output
secret_id a1b2... secret_id_ttl 0s
vault write auth/approle/login role_id=.. secret_id=..Exposes secrets- Exchange for a scoped token.Exposes secrets: secret_id lands in shell history and the returned token is printed.Example output
token hvs.CAES... token_policies [default deploy]
vault auth enable kubernetes- Let pods authenticate with their ServiceAccount JWT.
Policies
Intermediatevault policy list- List all policies.
vault policy write kv-read policy.hcl- Create/update a policy from a file.
path "secret/data/app" { capabilities = ["read"] }- HCL rule — grant read on one path.
vault policy read kv-read- Print a policy body.
vault token capabilities secret/data/app- What can THIS token do on a path?Example output
read
Dynamic database secrets
Advancedvault secrets enable database- Enable the database secrets engine.
vault write database/config/mydb plugin_name=postgresql-database-plugin ...- Configure the connection + allowed roles.
vault write database/roles/ro db_name=mydb default_ttl=1h creation_statements=@ro.sql- Define a role that mints short-lived DB users.
vault read database/creds/roExposes secrets- Get fresh, expiring DB credentials on demand.Exposes secrets: Prints a live database username and password.Example output
lease_id database/creds/ro/AbC username v-token-ro-x9 password A1b2-... ttl 1h
vault lease renew database/creds/ro/<id>- Extend a credential lease.
vault lease revoke database/creds/ro/<id>Caution- Revoke immediately (drops the DB user).Caution: Drops the DB user now; clients still using it lose access.
PKI & transit
Advancedvault secrets enable pki- Enable Vault as a certificate authority.
vault write pki/root/generate/internal common_name=example.com ttl=8760h- Generate a root CA.
vault write pki/roles/web allowed_domains=example.com allow_subdomains=true- Define what certs a role may issue.
vault write pki/issue/web common_name=app.example.comExposes secrets- Issue a short-lived leaf cert + key.Exposes secrets: Prints the private key; Vault does not store it.Example output
certificate -----BEGIN CERTIFICATE----- private_key -----BEGIN RSA... serial_number 3a:...
vault secrets enable transit- Encryption-as-a-service (keys never leave Vault).
vault write -f transit/keys/orders- Create a named encryption key.
vault write transit/encrypt/orders plaintext=$(base64 <<< secret)Exposes secrets- Encrypt without handling the key.Exposes secrets: The plaintext is in the command, so it lands in shell history; read it from a file or stdin for real data.Example output
ciphertext vault:v1:8SDd...
vault write transit/decrypt/orders ciphertext=vault:v1:8SDd...Exposes secrets- Decrypt back to base64 plaintext.Exposes secrets: Prints the decrypted plaintext (base64) to the terminal.
Operate
Advancedvault operator initExposes secrets- Initialize a new Vault: emits unseal keys + root token.Exposes secrets: Prints all unseal keys and the root token; consider -pgp-keys.Example output
Unseal Key 1: ... Unseal Key 2: ... Initial Root Token: hvs...
vault operator unseal- Supply one unseal key share (repeat to threshold).Example output
Unseal Progress 1/3
vault operator sealCaution- Seal Vault (blocks all access until unsealed).Caution: Vault rejects all requests until unsealed with the key threshold.
vault audit enable file file_path=/var/log/vault_audit.logCaution- Log every request and response (secret values HMAC-hashed).Caution: If no enabled audit device can write, Vault refuses requests.
vault operator raft list-peers- Integrated-storage cluster members.
vault operator raft snapshot save backup.snap- Back up integrated storage to a snapshot file.
vault operator raft snapshot restore backup.snapDestructive- Restore integrated storage from a snapshot.Destructive: Replaces the cluster's data with the snapshot; anything written after it was taken is lost.
vault operator step-downCaution- Make the active node give up leadership before maintenance.Caution: Forces a leader election; clients can see errors until a standby takes over.
vault lease revoke -prefix database/credsDestructive- Bulk-revoke every lease under a prefix.Destructive: Revokes every lease under the prefix, dropping all issued DB users.
Related
- Interview guideVault & secrets interview questions
- CourseVault from dev to production
- CourseAdvanced secrets management
- CourseSecrets management foundations
- Field noteVault Kubernetes auth: secrets without static tokens
- Field noteShort-lived TLS certificates from Vault PKI
- Field noteDynamic database credentials for Jenkins with Vault
Primary references
Found a technical issue on this page? Report it with the tool version you used and the behavior you saw. How resources are maintained.
Go deeper
Hands-on courses for Vault