saltext.vault
Salt Extension for interacting with Vault (or OpenBao)
Decision gist · record as of 2026-08-14
Yes, if you use Salt for infrastructure management and need Vault or OpenBao integration. The extension is actively maintained, has low install friction, carries a permissive license, and has no known vulnerabilities. It is suitable for production use in Beta status, though you should verify feature completeness for your specific Vault version and use case.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later and a working Salt installation with cryptography support.
- Low install friction with a pure-Python wheel distribution.
- Active maintenance with a release 5 days old and recent commits; requires salt and cryptography as runtime dependencies.
License · maintenance · safety
Apache Software License (permissive) — Apache Software License (permissive) allows commercial and private use with minimal restrictions, making it suitable for most deployment contexts.
last release 2026-08-09 (5 days) · last repo commit 2026-08-11 · 21 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 109,233 downloads/mo, #12,525 on PyPI
Alternatives
Verify before relying
pip install saltext-vault
from salt.ext.vault import vault_module
# Use within Salt states or execution modules to retrieve secrets from Vault- Specific Vault API versions or features supported by this extension version
- Whether OpenBao compatibility is feature-complete or partial
- Performance characteristics when retrieving large numbers of secrets
What it is and what it does
saltext-vault is a Salt extension that bridges Salt's configuration management with HashiCorp Vault or OpenBao for centralized secrets management. It allows Salt states and execution modules to authenticate with and retrieve secrets from Vault, enabling secure credential injection into infrastructure provisioning and configuration workflows.
The extension depends on salt and cryptography, and targets modern Python versions (3.10 through 3.14). It is actively maintained with recent releases and welcomes community contributions. The project is in Beta status and has no known security vulnerabilities.
Use it for
- Retrieve database credentials from Vault during Salt state execution for application deployment.
- Manage API keys and tokens centrally in Vault while provisioning infrastructure with Salt.
- Integrate OpenBao as a Vault-compatible secrets backend for air-gapped or self-hosted environments.
- Automate secret rotation workflows by querying Vault dynamically during configuration updates.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you use Salt for infrastructure management and need Vault or OpenBao integration.
The extension is actively maintained, has low install friction, carries a permissive license, and has no known vulnerabilities. It is suitable for production use in Beta status, though you should verify feature completeness for your specific Vault version and use case.
Install
saltext-vault on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Active maintenance with a release 5 days old and recent commits; requires salt and cryptography as runtime dependencies.
Requires Python 3.10 or later and a working Salt installation with cryptography support.
License in practice
Apache Software License (permissive) allows commercial and private use with minimal restrictions, making it suitable for most deployment contexts.
Quickstart
pip install saltext-vault
from salt.ext.vault import vault_module
# Use within Salt states or execution modules to retrieve secrets from Vault
Verify before relying
- Specific Vault API versions or features supported by this extension version
- Whether OpenBao compatibility is feature-complete or partial
- Performance characteristics when retrieving large numbers of secrets
Package facts
| License | Apache Software License permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagessaltcryptography |
| Maintenance | Actively maintained 5 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 109,233 / month, #12,525 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: CythonProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: saltext_vault-1.8.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “salt vault integration”
- saltext.vaultA Salt extension that integrates HashiCorp Vault (or OpenBao) with…
- keyrings.cryptfileA keyring backend that stores passwords in an encrypted file using…
- hvachvac is a Python client library for HashiCorp Vault that enables…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also apache-airflow-providers-hashicorp · pulumi-vault · hvac · robocorp-vault · salt · onepassword-sdk · onepassword · bitwarden-sdk · apache-airflow-providers-akeyless · azure-keyvault-secrets