Introduction
Why use HashiCorp Validated Designs?
HashiCorp Validated Designs (HVD) provide practitioners with opinionated guidance for achieving production-grade deployments of HashiCorp products. These designs are purpose-built for delivering foundational use cases, with a baseline level of architectural and operational maturity. They draw on the field experiences of Solutions Engineers and Solutions Architects working with customers across a wide range of environments and organizational requirements.
Each guide provides access to an opinionated reference architecture, including key design decisions and the rationale behind them. Where applicable, guides identify modular design components that you can adjust to align with organizational or regulatory requirements without compromising the overall integrity of the implementation. For many deployments we include Terraform modules to automate large portions of infrastructure provisioning and software installation.
This Administration Guide covers the ongoing configuration, operation, and governance of HCP Vault Radar for the platform, security operations (SecOps), and HCP administrator teams who run Radar as a service for their organization.
Because Vault Radar is a software-as-a-service (SaaS) offering delivered through the HashiCorp Cloud Platform (HCP), there is no self-managed installation to perform: HashiCorp operates the underlying platform. This guide therefore assumes your organization already has access to an HCP organization with Vault Radar enabled. Infrastructure concerns that do not apply to a fully-managed SaaS product — such as backup, disaster recovery, upgrades, and capacity sizing — are handled by HashiCorp and are out of scope for this guide.
What this guide covers
- People and process — the roles and responsibilities involved in running Vault Radar.
- Identity and access management — HCP roles and resource-based access control for operators and consumers.
- Data source onboarding — connecting and tuning the data sources Radar scans.
- Agent deployment — deploying and scaling agents for scanning private, non-internet-accessible sources.
- Observability and alert management — configuring alerting, notification, and ticketing integrations.
Related guides
For how developers and application teams consume Vault Radar — deployment models, using Radar in developer pipelines, and remediating findings — see the User Guide.