Skip to main content
drupalreleases

Use direct release data with your AI assistant.

Learn more

Vault for Drupal

Security covered Under active development 308 sites

Part of the Vault ecosystem · 5 projects

This project provides core APIs for securely integrating Drupal with Hashicorp Vault or The Linux Foundation OpenBao. It allows Drupal to access secrets like API keys or passwords stored securely outside of the Drupal environment, supporting features like encrypted storage and encryption-as-a-service.

Core APIs for integrating Drupal with Hashicorp Vault or the Linux Foundation OpenBao.

What is Vault for Drupal?

Vault for Drupal is a tool for securely accessing secrets using the Hashicorp Vault API.

A secret is anything that you want to tightly control access to, such as API keys, passwords, or certificates.

What is Hashicorp Vault or The Linux Foundation OpenBao?

Hashicorp Vault is a source available (BSL license) project.
The Linux Foundation OpenBao is an open source (MPL 2.0 license) fork of Hashicorp Vault.

Both provide secure storage of secrets outside of Drupal.

Hashicorp Vault

The Linux Foundation OpenBao

Why Vault/OpenBao with Drupal?

Unparalleled Feature-Set

Vault and OpenBao have a significant range of features for storing secrets in a secure manner:

Some features include:

  • Encrypted key/value storage
  • Encryption-as-a-service
  • Automatic rotation of credentials
  • Revocation of credentials
  • Audit logging for compliance and intrusion detection

Free and Open Source Software

The Drupal community has produced some excellent tooling to abstract secret storage and encryption. However there are issues with the ecosystem of tools which leverage these abstractions to perform the cryptographic functions.

  • Most of the existing integrations are for commercial services
  • The FOSS options are difficult to operate in a secure manner

Modules Integrating with Vault for Drupal

Authentication Strategies

Authentication strategies allow Drupal to securely authenticate with the secret storage.

Secret Engines

Secret engines provide a method for storing/retrieving static/dynamic secrets from the storage.

Encrypt-as-a-Service

Provides methods where encryption/decryption are performed by the secrets storage without revealing the cryptographic keys. Storage of the encrypted content is outside of the secrets server.

Drupal 10–11

Ask your assistant about Vault for Drupal

Check compatibility with your Drupal and PHP version, maintenance and security coverage, from current release data. How it works

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Activity

Tracked releases
4
Tracked since
Apr 2023
Latest release
1 year ago
Releases (12 mo)
0 ▼ from 1
Maintenance
Slowing

Release Timeline

Releases

Version Type Core PHP Release date
3.0.0 Stable 10–11 Nov 12, 2024
3.0.0-alpha1 Pre-release 10 PHP ^8.1 Apr 2, 2023
2.0.0-alpha2 Pre-release 9 PHP 8.1 Apr 2, 2023
3.x-dev Dev 10–11 PHP ^8.1 Apr 2, 2023