Open Source

Vault Management, Simplified

Kluis transforms OpenBao and HashiCorp Vault from complex CLI operations into intuitive workflows. Fine-grained access control, automatic policy sync, and 23+ secret engines—all through a modern web interface.

Kluis Dashboard
Workspace production
Vault Status Connected
Active Engines 12 mounted
Policy Sync Synchronized
Last Audit Event 2s ago

The Problem

  • Writing HCL policies manually is tedious and error-prone
  • Vault's native policies are too coarse for least-privilege
  • No way to restrict access to specific engine instances
  • Onboarding developers requires Vault CLI expertise
  • Audit trails require parsing raw logs

The Kluis Solution

  • Automatic policy generation from role assignments
  • 44 granular permissions across 11 resource types
  • Engine-level access control—unique to Kluis
  • Self-service web UI, no CLI required
  • Queryable audit logs with filtering and export

Everything Your Vault Needs

A complete management platform with capabilities Vault doesn't offer natively.

Engine-Level Access Control

Grant access to specific secret engine instances, not just types. Team A sees their secrets. Team B sees theirs. Policies generate automatically.

Advanced RBAC

44 granular permissions covering 11 resource types. Create custom roles, assign multiple per user, and let Kluis sync policies to Vault.

Automatic Policy Sync

Stop writing HCL. Kluis generates Vault policies from role assignments and syncs them in real-time. Non-blocking and fault-tolerant.

23+ Secret Engines

KV stores, database credentials, PKI certificates, AWS/Azure/GCP credentials, SSH, Transit encryption, and more—with purpose-built UIs.

Multi-Provider Auth

Authenticate through Google, GitHub, Azure AD, OIDC, or local credentials. Users sign in with identities they already have.

Comprehensive Audit

Every operation logged with user, action, IP, duration, and response. Filter by any field. Export for compliance.

How It Works

Kluis sits between your team and Vault, adding the management layer Vault lacks.

Your Team
Kluis Platform RBAC, Policy Sync, Audit
OpenBao / Vault Your Secrets Stay Here

Kluis never stores your secrets. All sensitive data remains in Vault. Kluis provides the management interface and enhanced access control.

23+ Secret Engines Supported

Purpose-built interfaces for every engine type. Different workflows, consistent experience.

Key-Value

KV v1 KV v2 Cubbyhole

Databases

PostgreSQL MySQL MongoDB Oracle MSSQL

Cloud Providers

AWS Azure GCP AliCloud

PKI & Encryption

PKI Transit SSH TOTP

Infrastructure

Kubernetes Consul Nomad LDAP RabbitMQ

Enterprise

Transform KMIP Key Management

Built with Modern Technologies

Production-ready architecture with tools your team already knows.

Frontend

React 19 TypeScript Material-UI v5 TanStack Query

Backend

Node.js 20+ Express.js TypeScript Prisma ORM

Infrastructure

PostgreSQL 15+ OpenBao / Vault Docker

Deployment

Single Container No Complex Orchestration Horizontal Scaling

Ready to Simplify Vault Management?

Get started in minutes. Deploy with Docker, connect to your Vault, and start managing secrets through the Kluis interface.