HashiCorp an IBM Company
Security lifecycle management

Agentic runtime security, the sequence

It starts in the chat. Claude calls an AI gateway, the gateway routes to a Postgres MCP server (the data agent), Nomad runs everything, Consul secures every path, and Vault issues a credential that lives for seconds.

Dan VDI session, OIDC Claude chat interface MCP client Identity provider OIDC + token exchange IdP NOMAD CLUSTER Nomad AI gateway task + workload identity Envoy sidecar Mesh ingress Consul API gateway Envoy listener Postgres MCP server data agent task Envoy sidecar Terraform MCP MCP server task plan, never apply Consul catalog + intentions mesh CA (SPIFFE) Consul Vault JWT auth, entity = user database secrets engine Vault Postgres analytics schema dynamic roles only
Arrow keys work too. Blue means the user's identity, gray means the workload's. The rule the whole flow obeys: a token is never forwarded to an audience it was not minted for.
HashiCorp, an IBM Company Vault Consul Nomad Terraform Reference flow. Add official logo assets from the HashiCorp brand hub for external use.