Vault Playground
Secure, store, and tightly control access to tokens, passwords, certificates, encryption keys for protecting secrets, and other sensitive data using a UI, CLI, or HTTP API.

Dev mode
Vault is configured to run in dev mode by default, meaning:
- Initialized and unsealed - The server will be automatically initialized and unsealed.
- In-memory storage - All data is stored (encrypted) in-memory.
- KV engine enabled at
secret/
If you'd prefer to run the service "normally", see the Setup without dev mode section.
For more feature demos, check out the Other playgrounds section.
You can read more about the properties of the dev server here.
Connecting
Connect to Vault using the following command:
vault status
💡 The terminal session should be configured to connect the locally running service.
The root token for connecting from other clients (e.g., the embedded UIs) is iximiuz.
Configuration
To experiment with custom configurations, place your config files in the following location: /etc/vault.d/config.d/
Ensure they're owned by the service user:
chown -R vault:vault /etc/vault.d/config.d/
Other playgrounds
Other playgrounds showcasing features not available here: coming soon!
Setup without dev mode
If you choose to run the service in "normal" mode (i.e. Dev mode disabled), a few extra steps are needed to replicate the dev mode setup.
These steps are outlined in this tutorial.
tl;dr
Review the contents of /opt/lab/setup.sh, then run it.
A real VM, not a container
Get root on a VM with its own kernel, so Docker, Kubernetes, and systemd just work.
Read the docs →
SSH from browser or CLI
Use the built-in web terminal, or connect with labctl ssh, plain ssh, scp, or rsync.
Read the docs →
Drive it with AI
Let Claude, Codex, or any MCP client start this playground and run commands in it.
Read the docs →
Expose HTTP(S) ports
Give any web app running inside the VM a public URL - for yourself or to share with others.
Read the docs →
Share terminals
Invite others into your terminal session, or open it yourself from another device.
Read the docs →
Customize with init scripts
Add shell scripts that run at boot to install packages, clone repos, or seed test data.
Read the docs →
Private networking
VMs reach the internet via NAT with no public IP; several VMs share bridge networks.
Read the docs →
Ephemeral or persistent
By default, VMs are destroyed when the session ends; enable persistence to keep the disks for next time.
Read the docs →
Built-in container registry
A private registry.iximiuz.com for every playground to share images across services and VMs.
Read the docs →