k9s for Vault
Vault, at the speed
of your keyboard_
VaultUI is a terminal UI for HashiCorp Vault. Browse secrets and their versions, policies, auth methods, PKI, Transit and Identity, then copy what you need, all without leaving the terminal.
A replay of the real app: every screen was captured from VaultUI v0.8 running against a local Vault dev server with sample data.
// views
Everything Vault knows, one keystroke away.
// headless
Scripts get JSON.
The same client and config, without the UI. vaultui get prints JSON, so it drops into shell scripts and CI next to jq.
$ vaultui get secret secret/apps/myapp/config | jq .db_host "fake-db.test.internal" $ vaultui get engines | jq -r '.[].Path' aws/ cubbyhole/ database/ identity/ pki/ secret/ sys/ transit/ $ vaultui get health | jq -c '{Sealed, Version}' {"Sealed":false,"Version":"1.21.4"}
// contexts
Dev, staging and prod in one file.
Keep every Vault you work with in ~/.vaultui.yaml and switch with :ctx. Token, userpass and AppRole auth are supported, along with Enterprise namespaces. Flags and VAULT_ADDR / VAULT_TOKEN still work if you'd rather not have a config file.
- Clipboard auto-clear. Copied secrets are wiped after 30 seconds.
- Your keys. Rebind any shortcut in the config file.
- Vim-style. j k g G ctrl+d ctrl+u, plus arrows for everyone else.
current_context: dev contexts: - name: dev address: http://127.0.0.1:8200 token: root - name: staging address: https://vault.staging.example.com auth: method: userpass username: admin - name: prod address: https://vault.example.com auth: method: approle role_id: "…" settings: clipboard_timeout: 30
// install
Pick your poison.
macOS and Linux, amd64 and arm64. Downloads the latest release for your machine.
VERSION=$(curl -fsSLI -o /dev/null -w '%{url_effective}' https://github.com/miladbeigi/vaultui/releases/latest | sed 's|.*/v||')
OS=$(uname -s | tr '[:upper:]' '[:lower:]'); ARCH=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
curl -fsSL "https://github.com/miladbeigi/vaultui/releases/download/v${VERSION}/vaultui_${VERSION}_${OS}_${ARCH}.tar.gz" | tar -xz vaultui
sudo install vaultui /usr/local/bin/
Requires Go 1.25 or later. The version shows as dev in builds made this way.
go install github.com/miladbeigi/vaultui@latest
Passes your Vault address and token through from the environment.
docker run --rm -it -e VAULT_ADDR -e VAULT_TOKEN ghcr.io/miladbeigi/vaultui
Then:
VAULT_ADDR=https://vault.example.com VAULT_TOKEN=… vaultui
No Vault handy? docker compose up -d in the repo starts one with sample data. How it works