Everything Your Vault Needs
Kluis adds capabilities that Vault doesn't offer natively—fine-grained access control, automatic policy management, and comprehensive audit logging.
Engine-Level Access Control
The only Vault management solution that lets you grant access to individual secret engine instances. Team A accesses their KV store. Team B accesses theirs.
Per-Engine Access Grants
Grant or revoke access to specific mounted engines through the UI. No more manually crafting policies for every team-engine combination.
Automatic Policy Paths
Kluis generates Vault policies with the exact paths for accessible engines only. Mount a new engine? Grant access with two clicks.
Principle of Least Privilege
Users only see and access the engines they need. Isolation between teams, environments, and projects—enforced automatically.
Access Matrix
Advanced Role-Based Access Control
44 granular permissions across 11 resource types. Create custom roles, assign multiple per user, and let Kluis handle the Vault policies.
44 Granular Permissions
Fine-grained control over KV, Database, PKI, Policies, Engines, Users, Audit, Roles, Secrets, Vault, and Tokens. Each with read, write, delete, and admin actions.
7 Pre-Built Roles
SUPERADMIN, MAINTAINER, USER, KV_ADMIN, DATABASE_OPERATOR, PKI_OPERATOR, and CUSTOM. Cover common scenarios out of the box.
Role Composition
Assign multiple roles to users. Permissions combine automatically. No need to duplicate role definitions.
Permission Example
{
"role": "database-operator",
"permissions": [
"database:read",
"database:create",
"database:revoke",
"secrets:read",
"audit:read"
],
"engines": [
"db/production",
"db/staging"
]
} Automatic Policy Synchronization
Stop writing HCL. Kluis generates Vault policies from role assignments and syncs them in real-time.
Zero HCL Required
Assign roles and engine access through the UI. Kluis translates your configuration into correct Vault HCL policies automatically.
Real-Time Synchronization
Every change triggers automatic policy regeneration. Grant access, policies update. Remove a permission, policies regenerate.
Non-Blocking & Fault-Tolerant
Sync happens asynchronously. If Vault is temporarily unreachable, changes queue and sync when connectivity returns.
23+ Secret Engines Supported
Every engine Vault offers, with purpose-built interfaces. Different workflows, consistent experience.
Key-Value
KV v1, KV v2 with versioning, Cubbyhole for personal secrets
Databases
PostgreSQL, MySQL, MongoDB, Oracle, MSSQL—dynamic credentials on demand
Cloud Providers
AWS IAM, Azure Service Principal, GCP Service Account, AliCloud
PKI & Encryption
Certificate authority, Transit encryption, SSH keys, TOTP tokens
Infrastructure
Kubernetes, Consul, Nomad, LDAP, RabbitMQ service tokens
Enterprise
Transform tokenization, KMIP, Key Management (Enterprise features)
Multi-Provider Authentication
Your identity provider, built-in. Users authenticate with credentials they already have.
OAuth Providers
Google, GitHub, Azure AD, and generic OIDC. Configure via environment variables, users sign in immediately.
Local Authentication
Traditional username/password with bcrypt hashing. For organizations without external identity providers.
Unified Session Management
JWT tokens with refresh, session expiry tracking, and consistent behavior across all providers.
Supported Providers
Comprehensive Audit Logging
Every operation logged with full context. Answer compliance questions in minutes, not days.
Complete Context
User, action, resource, HTTP method, status code, IP address, user agent, duration, and optionally request/response bodies.
Queryable Interface
Filter by user, action, resource type, time range, or status code. No more grepping through log files.
Export for Compliance
Export filtered results for external analysis or compliance documentation. Stored in PostgreSQL for efficient long-term retention.
Audit Log Entry
Ready to Get Started?
Deploy Kluis with Docker, connect to your Vault, and start managing secrets in minutes.