Skip to main content

S3Vaultlib

pypi build status code quality documentation 3rd party libs

S3Vaultlib is a Python Library and CLI tool that enable you to implements a secure vault / configuration datastore for your AWS platform by using AWS resources: CloudFormation, S3, IAM, KMS S3Vaultlib it’s yet another vault with the goal to give easy maintainability, use only AWS resource and with strong security patterns in mind.

Why a vault?

It’s a common pattern in SRE and DevSecOps to create resources environment unaware and configure the resource automatically when is deployed in a specific environment

S3Vaultlib Features

  • Use Server Side Encryption to store the objects on S3 with per-role KMS key

  • Use per role encryption with least privilege patterns to access the vault. Each role in the vault can only consume its own keymaterials

  • Special elevated privileged mode with a specific role able to produce and configure keymaterials, with only temporary access

  • Save, retrieve, update objects in the vault

  • Integrates flawlessly with Ansible by exposing an action plugin that allows you to expand templates by using variables / keymaterials from the vault

  • Powerful CLI to create, manage and update the objects in the vault

  • Easy maintainable via simple yaml file

  • Expose a flexyble python library to extend functionalities or implement the retrieval of keymaterials from your code.

S3vaultlib Architecture

S3Vaultlib requires no installation or security patches / updates. The architecture leverages entirely on AWS existing resource to create a secure vault with Role Base Access Control, versioning and region awareness.

It integrates with the IAM to generate the necessary roles and policies, KMS to generate per-role keys, S3 to configure the bucket policies to enforce high level of security and CloudFormation to create the Infrastructure as Code that combine all the above in a powerful vault.

Check In depth Architecture for more information

HOW-TOs

Example scenarios

  • Provisioning a vault: A simple example to see how to provision a vault via the command line interface

  • Configure NGINX with S3Vaultlib: A simple example where we deploy an environment unaware NGINX instance and it’s configured via S3Vaultlib ansible plugin

CLI Usage

The complete documentation can be found here: CLI Usage

Alternatives

Currently there are several alternative patterns used.

  • Configuration / Keymaterials encrypted in git
    Please don’t do this, really!
  • Vault by Hashicorp
    Full featured vault system, widely used in the DevOPS community. But it’s also yet another system to deploy and maintain in high availability and also, it requires keymaterials for the installation (since is not a native AWS component)
  • Very valid alternative offered by AWS. Still lack a bit of flexibility to be used transparently in your bootstrap pipelines for EC2 / Dockers / Lambdas / Applications

Release files for s3vaultlib 4.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for s3vaultlib 4.0.2
File Size Uploaded
s3vaultlib-4.0.2.tar.gz 52.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for s3vaultlib 4.0.2
File Interpreter ABI Platform
s3vaultlib-4.0.2-py2.py3-none-any.whl Python 3, Python 2 none any Details

Total release size: 105.5 kB

Release files / s3vaultlib-4.0.2.tar.gz

Download URL s3vaultlib-4.0.2.tar.gz
Size 52.7 kB
Tags Source
SHA-256 checksum
How to use checksums
5511c99adfb899a57c8b8023ab2f65e9387241244251ad3ce02871b65dbe3eec
BLAKE2b-256 checksum
How to use checksums
410c92ba77e62367c0dc3c2ddb90a4288c572457438a1788993f8fb7b1c83ec4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.4.1 importlib_metadata/4.6.1 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.61.2 CPython/3.9.6

Release files / s3vaultlib-4.0.2-py2.py3-none-any.whl

Download URL s3vaultlib-4.0.2-py2.py3-none-any.whl
Size 52.8 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
8897e10c119a374a86840120697591bc93d957f66255837569cdd2df05dd7333
BLAKE2b-256 checksum
How to use checksums
e599cf2c58c7d8e63a8a9aa154bbf7ca3bbebdac6b6958ba528ba4323fb6e8d5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.4.1 importlib_metadata/4.6.1 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.61.2 CPython/3.9.6

Release history Release notifications | RSS feed

This release

4.0.2 This release

2 release files

3.1.0

1 release file

3.0.1

1 release file

2.3.4

1 release file

2.3.3

1 release file

2.3.2

1 release file

2.3.1

1 release file

2.3.0

1 release file

2.2.0

1 release file

2.1.2

1 release file

2.1.1

1 release file

2.1.0

1 release file

2.0.8

1 release file

2.0.7

1 release file

2.0.6

1 release file

2.0.5

1 release file

2.0.4

1 release file

2.0.3

1 release file

2.0.2

1 release file

2.0.1

1 release file

2.0.0

1 release file

1.11.0

1 release file

1.10.1

1 release file

1.10.0

1 release file

1.9.0

1 release file

1.8.1

1 release file

1.8.0

1 release file

1.7.1

1 release file

1.6.2

1 release file

1.6.1

1 release file

1.6.0

1 release file

1.5.0

1 release file

1.4.3

1 release file

1.4.2

1 release file

1.4.1

1 release file

1.4.0

1 release file

1.3.0

1 release file

1.2.1

1 release file

1.2.0

1 release file

1.1.6

1 release file

1.1.5

1 release file

1.1.4

1 release file

1.1.3

1 release file

1.1.1

1 release file

1.1.0

1 release file

1.0.0

1 release file

0.2.0

1 release file

0.1.3

1 release file

0.1.2

1 release file

0.1.1

2 release files

0.1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page