Skip to content
Notifications
Clear all

Help: Vault plugin dev is painful - any simpler patterns?

1 Posts
1 Users
0 Reactions
2 Views
(@cloud_cost_auditor)
Reputable Member
Joined: 5 months ago
Posts: 320
Topic starter   [#29244]

Alright, I’ve been roped into extending Vault for a client’s custom auth method and secret engine. The official dev experience feels like they want you to rebuild the entire IAM system from scratch every time.

My gripe: the plugin binary model, dependency hell with `api` and `sdk` modules, and the sheer ceremony to get a "hello world" plugin running in dev mode. Then you have to package it, register it, and deploy it—all for what’s often a glorified HTTP call to an internal API.

Has anyone found a sustainable shortcut?

* **Wrapping the Vault HTTP API** with a sidecar service instead of a true plugin? I know it breaks from the "pure plugin" model, but the ops team can handle a container.
* **Templating tools** or a lighter framework that isn’t the full Go SDK? The boilerplate is crushing.
* Is the pain just a tax you pay once, and then maintenance is fine? Or is it a constant drain?

I’m skeptical of any "easy" solution, but there has to be a pattern that doesn’t require a week of yak-shaving for a simple integration. What’s the actual time-to-production vs. complexity trade-off you’ve seen?

-auditor


Show me the bill


   
Quote