Run Production-Grade Vault on Kubernetes

KubeVault is a Git-Ops ready, production-grade solution for deploying and configuring Hashicorp's Vault on Kubernetes.

Production-Grade Security 30-Day Free License Any Kubernetes Distribution
Terminal
$ helm install kubevault \
  oci://ghcr.io/appscode-charts/kubevault \
  --version v2026.8.7 \
  --namespace kubevault --create-namespace \
  --set-file global.license=/path/to/the/license.txt
✓ KubeVault installed successfully

Trusted by engineers at

100 Fortune
Bank al Etihad
Course Hero
Emerson
Enterprise Products Partners L.P.
NOKIA
OAK RIDGE
Orange
300K+
Docker Pulls
9+
Storage Backends
5+
Authentication Methods
30-Day
Free Trial License
How it works

Vault on Kubernetes in 4 steps

A Git-Ops-ready workflow for deploying, unsealing, and operating HashiCorp Vault — declared entirely with Kubernetes-native CRDs.

Install the Operator

Deploy KubeVault via Helm into any Kubernetes cluster — EKS, GKE, AKS, or on-prem. One command, a few minutes.

helm install kubevault …

Deploy a VaultServer

A single VaultServer CRD provisions a TLS-secured HashiCorp Vault that is automatically initialized and unsealed using your cloud KMS or a Kubernetes secret.

kind: VaultServer

Enable Secret Engines

Declare SecretEngine and role CRDs to issue short-lived, dynamic credentials for AWS, Azure, GCP, and databases — no static secrets to rotate.

kind: SecretEngine

Request Secrets Securely

Workloads get scoped, audited access through SecretAccessRequest and the Secrets Store CSI Driver — secrets are delivered straight into pods.

kind: SecretAccessRequest
Capabilities

Built for production-grade Vault

A Git-Ops-ready solution for deploying and configuring HashiCorp Vault on Kubernetes — with automated unsealing, dynamic secrets, and fine-grained access control.

vaultserverversions
Deploy

Vault Kubernetes Deployment

You can deploy TLS secured Vault Servers on Kubernetes using KubeVault. You can manage TLS with self-signed or cert-manager managed TLS. Running & managing Vault & it’s resources has never been easier.

Read More
http
Automation

Auto Initialization & Unsealing

KubeVault provides various ways to automatically initialize & unseal your Vault Servers. You can use your choice of cloud providers among GCP, AWS, Azure, etc. or even K8s secret to store unseal keys & vault token.

Read More
vault-backup-restore
Backup

Vault Backup & Restore

You can Backup & Restore your Vault cluster managed by KubeVault or deployed with Helm-charts using Stash. Stash simplifies & generalizes the process for Vault regardless of the Storage Backend used by the Vault. It protects your Vault cluster against data corruption or sabotage.

Read More
secrets
Secrets

Consume KubeVault Secrets with CSI

KubeVault works seamlessly with the Secrets Store CSI Driver. Consuming Vault secrets in K8s resources is way more simpler with the automation provided by KubeVault.

Read More
http
Access

Manage DB Users Privileges

Managing DB user privileges is a complicated task which is made simple with KubeVault. KubeVault works seamlessly with KubeDB managed DBs. CRDs like SecretAccessRequest, SecretRoleBinding, etc. make grant, revoke, audit user privileges extremely convenient.

Read More
storageclasses
Storage

Storage Backend

KubeVault lets you choose your preferred way to store & persist Vault data. Each Storage Backend has its own pros and cons. GCS, AWS S3, Azure, Consul, Raft, Etcd, MySQL, Postgres, DynanoDB, etc. to name a few.

Read More
View All Features
Start Securing Today

Ready to Run Vault on Kubernetes?

Join platform teams at Emerson, Nokia, and Orange running TLS-secured, auto-unsealed HashiCorp Vault with dynamic secrets on Kubernetes using KubeVault.

  • TLS-secured, automatically unsealed Vault by default
  • Dynamic secrets for AWS, Azure, GCP & databases
  • 30-day free license, no credit card required
4+
Secret Engines
5+
Auth Methods
9+
Storage Backends
24/7
Expert Support