k9s for Vault

Vault, at the speed
of your keyboard_

VaultUI is a terminal UI for HashiCorp Vault. Browse secrets and their versions, policies, auth methods, PKI, Transit and Identity, then copy what you need, all without leaving the terminal.

Install VaultUI v0.8.0 · macOS and Linux · MIT
vaultui — 120×34 click, then type

          

A replay of the real app: every screen was captured from VaultUI v0.8 running against a local Vault dev server with sample data.

// views

Everything Vault knows, one keystroke away.

// headless

Scripts get JSON.

The same client and config, without the UI. vaultui get prints JSON, so it drops into shell scripts and CI next to jq.

zsh
$ vaultui get secret secret/apps/myapp/config | jq .db_host
"fake-db.test.internal"

$ vaultui get engines | jq -r '.[].Path'
aws/
cubbyhole/
database/
identity/
pki/
secret/
sys/
transit/

$ vaultui get health | jq -c '{Sealed, Version}'
{"Sealed":false,"Version":"1.21.4"}

// contexts

Dev, staging and prod in one file.

Keep every Vault you work with in ~/.vaultui.yaml and switch with :ctx. Token, userpass and AppRole auth are supported, along with Enterprise namespaces. Flags and VAULT_ADDR / VAULT_TOKEN still work if you'd rather not have a config file.

  • Clipboard auto-clear. Copied secrets are wiped after 30 seconds.
  • Your keys. Rebind any shortcut in the config file.
  • Vim-style. j k g G ctrl+d ctrl+u, plus arrows for everyone else.
~/.vaultui.yaml
current_context: dev

contexts:
  - name: dev
    address: http://127.0.0.1:8200
    token: root

  - name: staging
    address: https://vault.staging.example.com
    auth:
      method: userpass
      username: admin

  - name: prod
    address: https://vault.example.com
    auth:
      method: approle
      role_id: "…"

settings:
  clipboard_timeout: 30

// install

Pick your poison.

macOS and Linux, amd64 and arm64. Downloads the latest release for your machine.

VERSION=$(curl -fsSLI -o /dev/null -w '%{url_effective}' https://github.com/miladbeigi/vaultui/releases/latest | sed 's|.*/v||')
OS=$(uname -s | tr '[:upper:]' '[:lower:]'); ARCH=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
curl -fsSL "https://github.com/miladbeigi/vaultui/releases/download/v${VERSION}/vaultui_${VERSION}_${OS}_${ARCH}.tar.gz" | tar -xz vaultui
sudo install vaultui /usr/local/bin/

Then:

VAULT_ADDR=https://vault.example.com VAULT_TOKEN=… vaultui

No Vault handy? docker compose up -d in the repo starts one with sample data. How it works