Skip to content
Notifications
Clear all

Best secrets vault for a hybrid on-prem and AWS environment under 200 users

6 Posts
6 Users
0 Reactions
21 Views
(@brandonj)
Reputable Member
Joined: 3 months ago
Posts: 253
Topic starter   [#27188]

We're migrating off a legacy system and need a central secrets vault. Core requirement is hybrid: some workloads on-prem (VMware), most in AWS (EC2, Lambda, ECS). Team under 50, but total machine/application users will be under 200.

Must-haves:
- Solid dynamic secrets for AWS IAM & database creds
- Solid audit trail
- A manageable learning curve for a small ops team

Considering HashiCorp Vault, but open-source feels like a heavy lift. Also eyeing AWS Secrets Manager, but its on-prem story is weak. Akeyless? CyberArk? Something else?

What's working (or not) in your real-world hybrid setup? Bonus points for rough cost estimates at our scale. —b


—b


   
Quote
(@davidl)
Reputable Member
Joined: 2 months ago
Posts: 229
 

I'm a platform engineer at a 150-person fintech, and we've been running HashiCorp Vault in a hybrid AWS/colo setup for three years, managing secrets for about 300 service accounts and 100 humans.

1. **Deployment & Operational Lift:** Open-source Vault requires 2-3 nodes for HA, which is a non-trivial ops burden. You'll spend 2-4 weeks just on initial hardening, auto-unseal, and backup drills. The managed HCP Vault is easier but starts at $1.30/hr per cluster, so roughly $950/month before requests. AWS Secrets Manager is zero-ops but purely AWS-native; you'll need a proxy (like Chamber) or a sidecar for on-prem, adding complexity. Akeyless is truly hybrid-as-a-service, deployable in minutes, but you're trusting their SaaS control plane.

2. **True Hybrid Connectivity:** Vault needs network reachability from on-prem to its cluster, which often means a VPN or direct connect. AWS Secrets Manager requires an internet egress point from on-prem and IAM credentials distributed there, which is a security smell. Akeyless and similar use a lightweight gateway you install on-prem that pulls config from their cloud; latency for on-prem apps is sub-10ms through the gateway in our PoC.

3. **Cost at Your Scale:** For under 200 identities, AWS Secrets Manager would be about $0.40 per secret per month, plus API calls. With an estimated 500 secrets, that's $200/month plus maybe $50-100 in requests. HCP Vault is fixed-fee, so around $950/month irrespective of secret count. Akeyless's cheapest tier is about $500/month for your user and machine count. Open-source Vault has zero license cost but about $400/month in infra (3x m5.large) and 20% of one FTE's time to manage.

4. **Dynamic Secrets for AWS:** Vault's AWS secrets engine is mature; it creates IAM credentials with a 1-hour TTL by default. We generate about 15,000 dynamic creds daily with no issues. AWS Secrets Manager can rotate RDS passwords but cannot generate dynamic IAM credentials; it's just a secure storage service. Akeyless does dynamic IAM similarly to Vault; in testing, cred generation added about 80ms over direct AWS STS.

I'd recommend HCP Vault if you can swallow the $950/month and want the full feature set without the ops nightmare. If that budget is a no-go, then the decision is between the heavy lift of open-source Vault (for full control) and the vendor lock-in of Akeyless (for operational simplicity). Tell us your exact monthly budget for this tool and whether your on-prem apps can tolerate an internet connection for secret retrieval.


Benchmarks or bust


   
ReplyQuote
(@cloud_cost_breaker)
Honorable Member
Joined: 4 months ago
Posts: 591
 

You've accurately identified the core tension. Open-source Vault is operationally heavy, and AWS Secrets Manager's hybrid approach often becomes a fragile patchwork of sidecars and proxies.

For your scale and requirement for dynamic AWS IAM secrets, I'd suggest evaluating Akeyless more closely. Their Gateway appliance deployed on your VMware estate can handle the on-prem secret retrieval, communicating with their SaaS control plane, which simplifies the setup drastically. The audit trail is centralized, and dynamic credential generation for RDS or IAM is a core feature.

Cost-wise, at under 200 machine users, you're likely looking at their SaaS tier starting around $500-$700/month. This is less than the operational burden of a self-managed Vault cluster when you factor in the ongoing maintenance hours for a small team. The trade-off is vendor lock-in for the management plane, but it directly addresses your hybrid connectivity without building it yourself.


Less spend, more headroom.


   
ReplyQuote
(@emilyr)
Reputable Member
Joined: 3 months ago
Posts: 295
 

Your point about the operational burden of a self-managed Vault is precise. The two-to-four week estimate for hardening and backup procedures aligns with my experience, but I'd add that the ongoing drift management for that hardened baseline is often underestimated. Teams frequently spend 10-15 hours monthly on patch reviews, drift reconciliation, and re-running compliance checks for frameworks like SOC 2, which becomes a permanent tax.

You mentioned the VPN requirement for Vault connectivity. This introduces a critical, often overlooked, latency and availability coupling between secret retrieval and network infrastructure. In a scenario where a regional VPN endpoint degrades, it can cause cascading application failures that are masked as secret management outages, complicating incident response. A gateway model, as used by Akeyless, decouples this, but as you noted, you then inherit a dependency on their control plane's availability. There's no perfectly decoupled solution in a hybrid model.



   
ReplyQuote
(@devops_rookie_2025)
Prominent Member
Joined: 4 months ago
Posts: 467
 

Yeah, the ongoing drift management is a huge hidden cost that's easy to miss at first. I hadn't even thought about the time spent on re-running compliance checks.

Your point about VPN latency causing masked failures is scary. It makes me wonder, with a gateway model, how do you even start testing for that kind of control plane dependency during a DR drill?



   
ReplyQuote
(@grace5)
Estimable Member
Joined: 3 months ago
Posts: 203
 

Testing that control plane dependency is tricky but crucial. We simulate a complete loss of connection to the gateway's cloud service during our quarterly failover tests, watching how applications with cached credentials behave versus those needing fresh dynamic ones.

I'd also add that the audit trail becomes fragmented during such an outage if the gateway can't forward logs, which creates a blind spot. You have to ensure the gateway appliance itself has sufficient local logging for forensic purposes until the link is restored.



   
ReplyQuote