Having recently completed a detailed cost and operational burden analysis for a client facing a similar decision, I believe the conventional wisdom of "startups should use managed secret managers" requires a more nuanced breakdown. While Doppler presents itself as the obvious, budget-friendly SaaS choice, a self-hosted Vault deployment on a properly architected AWS infrastructure can, counterintuitively, lead to lower long-term costs and greater architectural flexibility, provided you are willing to accept a defined operational overhead.
The critical factors are your team's tolerance for infrastructure management, your expected scale trajectory, and the specific feature set you require. Let's examine the cost components first.
**Operational Cost Breakdown (Annual Estimate)**
* **Doppler (SaaS):**
* Base plan (Team): $12 per user/month
* **5 engineers:** 5 * $12 * 12 = **$720/year**
* Additional costs: Zero infrastructure management, minimal AWS data transfer fees.
* **Vault (Self-Hosted on AWS):**
* Compute: 2x t3.small (HA across AZs): ~$15/month each = **$360/year**
* Storage: DynamoDB for backend (25 WCU/50 RCU): ~$18/month = **$216/year**
* Load Balancer: ALB (partial share): ~$20/month = **$240/year**
* **Total AWS Resource Cost:** ~$816/year
* **Engineer Overhead:** ~2-4 hours/month for patching, monitoring, and updates. This is the crucial variable.
The raw infrastructure numbers are already close. However, the self-hosted Vault cost is largely fixed, while Doppler's scales linearly with team size. The break-even point on raw dollars occurs quickly.
**Technical & Strategic Considerations**
* **Architectural Control:** Vault's dynamic secret generation for databases or AWS IAM roles is a paradigm shift in security. Doppler focuses on secret injection. If your long-term roadmap includes zero-trust networking or ephemeral credentials, Vault's foundational model is superior.
* **AWS Integration:** A self-hosted Vault can utilize AWS IAM for authentication, reducing another external dependency. Your engineers already have AWS CLI profiles; they can authenticate to Vault with the same identity.
* **Resilience & Scaling:** A three-node Vault cluster on spot instances or reserved instances (1-year, No Upfront) can reduce the compute cost by >50%, making it decisively cheaper than Doppler. The DynamoDB backend handles scaling automatically.
* **Operational Burden:** This is the real cost. You must establish:
* Automated deployment (e.g., Terraform, CloudFormation)
* Patching pipeline
* Monitoring/alerting for seal status, leader health, and audit log integrity
* Secure, automated initialization/unseal procedures (e.g., using AWS KMS)
A minimal, production-ready HA setup for Vault on ECS Fargate (which reduces patching burden) might look like this Terraform snippet for the core definition:
```hcl
resource "aws_ecs_task_definition" "vault" {
family = "vault-server"
network_mode = "awsvpc"
cpu = "512"
memory = "1024"
requires_compatibilities = ["FARGATE"]
execution_role_arn = aws_iam_role.ecs_execution.arn
container_definitions = jsonencode([
{
name = "vault"
image = "hashicorp/vault:1.15.0"
portMappings = [{ containerPort = 8200 }]
secrets = [
{ name = "AWS_ACCESS_KEY_ID", valueFrom = "arn:aws:ssm:.../AWS_ACCESS_KEY_ID" },
{ name = "AWS_SECRET_ACCESS_KEY", valueFrom = "arn:aws:ssm:.../AWS_SECRET_ACCESS_KEY" }
]
command = ["server"]
logConfiguration = {
logDriver = "awslogs"
options = {
"awslogs-group" = "/ecs/vault",
"awslogs-region" = var.aws_region
}
}
}
])
}
```
**Recommendation:**
If your team has even one engineer with modest infrastructure-as-code experience (Terraform, CDK), and your headcount is projected to grow, I recommend starting with a self-hosted Vault. The fixed cost base, architectural advantages, and avoidance of per-user pricing will yield dividends. The operational load can be contained to an afternoon per month once the automation is established.
If your team is purely application-focused and any infrastructure work would be a severe distraction, Doppler's $60/month is a justifiable tax for focus. However, please model your costs at 10 and 20 engineers to understand the SaaS scaling curve.
-cc
every dollar counts