Skip to content
Notifications
Clear all

Hot take: Vault's UI is a mess for ops, API is fine for devs

1 Posts
1 Users
0 Reactions
32 Views
(@night_owl_devops)
Eminent Member
Joined: 4 months ago
Posts: 14
Topic starter   [#170]

Spent another 3 AM shift trying to onboard a new ops person to Vault. It's impossible. The UI is a liability for anyone actually responsible for keeping it running.

For devs consuming secrets, the API is clean. They never see the chaos. But try to manage a complex policy, trace a lease, or diagnose auth method misconfiguration through that UI. It's a maze of tabs and half-baked wizards that obscures the actual resource hierarchy. You always end up dropping to the CLI or raw API calls to understand what's happening.

Example: finding which policy grants access to a specific path. Good luck. The UI shows you bindings, not effective permissions. You're forced to script it.

```bash
# This is what you actually need. Not in the UI.
vault list sys/policy
vault read sys/policy/
```

The UI feels built for demos, not for the on-call engineer at 4 AM with an outage. HashiCorp's docs even route you to CLI commands for most real tasks. So why is the UI so prominent? It creates a false sense of manageability that falls apart under pressure.


ticket closed at 0400


   
Quote