Deckhouse Stronghold is available as Enterprise Edition (EE) and Certified Security Edition (CSE), which is certified by the FSTEC of Russia for environments with increased information security requirements.
Deckhouse Stronghold EE and Deckhouse Stronghold CSE are licensed separately. Deckhouse Stronghold EE is available for use in any commercial edition of DP. Deckhouse Stronghold CSE is available only in the DKP CSE edition.
The table below provides a brief comparison of the Deckhouse Stronghold editions and HashiCorp Vault, listing their main features and details:
| Feature | Vault | EE | CSE |
|---|---|---|---|
| Secure management of the secret lifecycle (storage, creation, delivery, revocation, and rotation) | |||
| Support of IaC automation tools (Ansible, Terraform) | |||
| Support of authentication methods | JWT, OIDC, Kubernetes, LDAP, Token | JWT, OIDC, Kubernetes, LDAP, Token, WebAuthn, SAML | JWT, OIDC, Kubernetes, LDAP, Token |
| Support of KV, Kubernetes, Database, SSH, and PKI secret engines | |||
| Support of Russian operating systems (full list of supported OSes) | RED OS, ALT Linux, Astra Linux Special Edition, ROSA Server | RED OS, ALT Linux, Astra Linux Special Edition | |
| Deploying to an air-gapped environment | |||
| Web interface | |||
| Role and access policy management through a web interface | |||
| Support for namespaces | |||
| Built-in automatic vault unsealing (auto unseal) without requiring any external services or KMS | |||
| HA configurations | |||
| Cross-cluster data replication | KV1/KV2, Performance, DR | KV1/KV2, Performance, DR | |
| Automatic backup creation on a schedule | |||
| Audit logging support | |||
| Managed Keys | |||
| GOST algorithm support for PKI/Transit | |||
| Delivered as a standalone executable file | |||
| Certificate of compliance with FSTEC of Russia Order No. 76, trust level 4 |