Introduction
Why use HashiCorp Validated Designs?
HashiCorp Validated Designs (HVD) provide practitioners with opinionated guidance for achieving production-grade deployments of HashiCorp products. These designs are purpose-built for delivering foundational use cases, with a baseline level of architectural and operational maturity. They draw on the field experiences of Solutions Engineers and Solutions Architects working with customers across a wide range of environments and organizational requirements.
Each guide provides access to an opinionated reference architecture, including key design decisions and the rationale behind them. Where applicable, guides identify modular design components that you can adjust to align with organizational or regulatory requirements without compromising the overall integrity of the implementation. For many deployments we include Terraform modules to automate large portions of infrastructure provisioning and software installation.
Vault Radar's purpose is to help inspect, protect, and govern environments by automating the detection and identification of unmanaged secrets in code and other locations so that security teams can take appropriate actions to remediate issues. It continuously scans in real-time for secrets.
Vault Radar scans connected cloud and on-premise data sources, detecting over 300 secret patterns across a large number of data sources. Radar automatically scans data sources when they are initially added, and also when there are new commits and new pull requests.
It provides severity, source, type, and other details to help you prioritize and remediate insecure secrets.
Vault Radar also provides the following benefits:
- Supports easy hand-off to developers and code repository owners for follow-up either in the application or via notification integrations
- Can warn or block pull requests when it finds risk in code
- Prevents secrets and sensitive information appearing in code, before and during CI activities
- Progress reporting
What this guide covers
This User Guide is for the developers and application teams who consume Vault Radar:
- Deployment models — how Radar scans SaaS, hybrid (agent), and pipeline sources.
- Using Vault Radar in pipelines — pre-commit hooks, pre-receive hooks, pull request scanning, and CI/CD scanning.
- Remediation workflows — acting on the findings Radar surfaces.
Vault Radar helps Security Operations (SecOps) teams with automated processes, risk detection rules and repeatable remediation steps. Using it well allows your organization to:
- Accelerate SecOps agility: Centralize monitoring of events and quickly identify insecure secrets
- Streamline remediation processes: Efficiently triage security issues and seamlessly hand them off to development teams
- Prevent security breaches: Detect and eliminate leaked secrets in code repositories, collaboration tools, and other insecure locations
- Reduce business risk: Proactively secure sensitive credentials
- Minimize operational costs: Prevent application downtime and security incidents caused by compromised secrets
Related guides
Vault Radar is configured and governed by platform operators. For roles, access management, data source onboarding, agent deployment, and alerting configuration, see the Administration Guide.