From be219f10e69652e6d663a228d3cda10cc2ed7517 Mon Sep 17 00:00:00 2001 From: Armon Dadgar Date: Mon, 26 Jun 2017 14:00:36 -0700 Subject: [PATCH] website: Add more hardening tips --- website/source/docs/guides/production.html.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/website/source/docs/guides/production.html.md b/website/source/docs/guides/production.html.md index 54b0c703fd..4b073800d9 100644 --- a/website/source/docs/guides/production.html.md +++ b/website/source/docs/guides/production.html.md @@ -38,3 +38,5 @@ It is entirely possible to use Vault without applying any of the following recom * **Configure SELinux / AppArmor**. Using additional mechanisms like SELinux and AppArmor can help provide additional layers of security when using Vault. While Vault can run on many operating systems, we recommend Linux due to the various security primitives mentioned here. +* **Restrict Storage Access**. Vault encrypts all data at rest, regardless of which storage backend is used. Although the data is encrypted, an attacker with arbitrary control can cause data corruption or loss by modifying or deleting keys. Access to the storage backend should be restricted to only Vault to avoid unauthorized access or operations. +