Platform

Everything Your Vault Needs

Kluis adds capabilities that Vault doesn't offer natively—fine-grained access control, automatic policy management, and comprehensive audit logging.

Unique to Kluis

Engine-Level Access Control

The only Vault management solution that lets you grant access to individual secret engine instances. Team A accesses their KV store. Team B accesses theirs.

Per-Engine Access Grants

Grant or revoke access to specific mounted engines through the UI. No more manually crafting policies for every team-engine combination.

Automatic Policy Paths

Kluis generates Vault policies with the exact paths for accessible engines only. Mount a new engine? Grant access with two clicks.

Principle of Least Privilege

Users only see and access the engines they need. Isolation between teams, environments, and projects—enforced automatically.

Access Matrix

kv/prod kv/dev db/prod
Platform Team
Dev Team
Contractors

Advanced Role-Based Access Control

44 granular permissions across 11 resource types. Create custom roles, assign multiple per user, and let Kluis handle the Vault policies.

44 Granular Permissions

Fine-grained control over KV, Database, PKI, Policies, Engines, Users, Audit, Roles, Secrets, Vault, and Tokens. Each with read, write, delete, and admin actions.

7 Pre-Built Roles

SUPERADMIN, MAINTAINER, USER, KV_ADMIN, DATABASE_OPERATOR, PKI_OPERATOR, and CUSTOM. Cover common scenarios out of the box.

Role Composition

Assign multiple roles to users. Permissions combine automatically. No need to duplicate role definitions.

Permission Example

{
  "role": "database-operator",
  "permissions": [
    "database:read",
    "database:create",
    "database:revoke",
    "secrets:read",
    "audit:read"
  ],
  "engines": [
    "db/production",
    "db/staging"
  ]
}

Automatic Policy Synchronization

Stop writing HCL. Kluis generates Vault policies from role assignments and syncs them in real-time.

Zero HCL Required

Assign roles and engine access through the UI. Kluis translates your configuration into correct Vault HCL policies automatically.

Real-Time Synchronization

Every change triggers automatic policy regeneration. Grant access, policies update. Remove a permission, policies regenerate.

Non-Blocking & Fault-Tolerant

Sync happens asynchronously. If Vault is temporarily unreachable, changes queue and sync when connectivity returns.

1 Assign Role to Engine
2 Kluis Generates HCL
3 Policy Syncs to Vault

23+ Secret Engines Supported

Every engine Vault offers, with purpose-built interfaces. Different workflows, consistent experience.

Key-Value

KV v1, KV v2 with versioning, Cubbyhole for personal secrets

Databases

PostgreSQL, MySQL, MongoDB, Oracle, MSSQL—dynamic credentials on demand

Cloud Providers

AWS IAM, Azure Service Principal, GCP Service Account, AliCloud

PKI & Encryption

Certificate authority, Transit encryption, SSH keys, TOTP tokens

Infrastructure

Kubernetes, Consul, Nomad, LDAP, RabbitMQ service tokens

Enterprise

Transform tokenization, KMIP, Key Management (Enterprise features)

Multi-Provider Authentication

Your identity provider, built-in. Users authenticate with credentials they already have.

OAuth Providers

Google, GitHub, Azure AD, and generic OIDC. Configure via environment variables, users sign in immediately.

Local Authentication

Traditional username/password with bcrypt hashing. For organizations without external identity providers.

Unified Session Management

JWT tokens with refresh, session expiry tracking, and consistent behavior across all providers.

Supported Providers

Google
GitHub
Azure AD
OIDC
Local

Comprehensive Audit Logging

Every operation logged with full context. Answer compliance questions in minutes, not days.

Complete Context

User, action, resource, HTTP method, status code, IP address, user agent, duration, and optionally request/response bodies.

Queryable Interface

Filter by user, action, resource type, time range, or status code. No more grepping through log files.

Export for Compliance

Export filtered results for external analysis or compliance documentation. Stored in PostgreSQL for efficient long-term retention.

Audit Log Entry

Action secrets:read
Resource kv/production/api-keys
Status 200 OK
IP 192.168.1.42
Duration 23ms

Ready to Get Started?

Deploy Kluis with Docker, connect to your Vault, and start managing secrets in minutes.