Alternative to HSMs: Always Encrypted HashiCorp Vault by Enclaive
github.comHashiCorp vault is the de-facto key management solution to rotate keys in docker, docker swarm or k8s environments. So far, HashiCorp Vault allowed for data-at-rest encryption of keys and secrets.
The open sourced project "always encrypted Hashicorp vault" by team enclaive makes sure keys and secrets are encrypted at runtime (aka data-in-use encryption) without changing or limiting the functionality and performance of the vault.
Always encrypted Hashicorp vault is an attractive alternative to HSMs, allowing businesses to drastically reduces security expenses.