{"templateId":"markdown","versions":[{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-connect","default":true,"active":true,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-connect","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-connect","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-connect","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-connect","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-connect","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Deploy a vault","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"deploy-a-vault","__idx":0},"children":["Deploy a vault"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This page describes how to deploy a vault in ","Ripple Custody"," to connect to a hardware security module (HSM) in AWS CloudHSM. Before following these instructions, you need to have created and initialized your HSM in AWS CloudHSM, as described in ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-initialize"},"children":["Initialize an AWS CloudHSM"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once you have initialized the HSM, complete the following steps to use the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":[null]}," to deploy a vault that uses the HSM."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Install the ",null,"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Deploy the vault."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Connect the vault."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following sections describe these steps in detail."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":1},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before starting, make sure you have the following information:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["User-supplied information — Be prepared to supply the following to the ",null,":"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Vault name"]}," — A name you choose to reflect the intended purpose of the vault."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Vault ID"]}," — A user-defined unique identifier (UUID). Note: This ID cannot be modified once the vault is created."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["IAM Profile"]}," — The Identity and Access Management (IAM) role that will be attached to the EC2 instances. This is a drop-down menu in the ",null,"."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["From Ripple — Your Ripple liaison will provide this information:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open telemetry (OTEL) information, as follows:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OTEL Collector Address"]}," — URL of your OTEL collector where telemetry data will be sent for processing and analysis"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OTEL Username"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Password"]}," — Basic authentication credentials"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Docker registry information:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Docker Server DNS Name"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Docker Username"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Password"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["From your AWS CloudHSM cluster — see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-initialize"},"children":["Initialize an AWS CloudHSM"]},":"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["VPC"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["VPC subnet"]}," — An existing Virtual Private Cloud (VPC) and subnet where you want to provision your resources. (Alternatively, you have the ",null," create a new VPC.)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Region"]}," — The preferred AWS region where you want to provision resources."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AWS CloudHSM cluster"]}," — The name of the HSM you created"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["CA Certificate"]}," — The client certificate file, ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["customerCA.crt"]},", generated when you created the HSM cluster."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["PKCS11 authentication — The credentials required to authenticate the PKCS11 client application with AWS CloudHSM:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["PKCS11 Login username"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["password"]}," HSM crypto user login username and password"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Hardware AES key prerequisite:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AES256 key ID"]}," attribute"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Second AES256"]}," wrapping key"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"1-install-the","__idx":2},"children":["1. Install the ",null]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you can deploy the vault, you need to install the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":[null]},", which you can do using a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Cloud Formation (CF)"]}," template available through your Ripple liaison."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To provision the ",null," resources (AWS App Runner, predefined IAM Instance-role, and AWS Cognito user pool):"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Provide the following:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["custom DNS domain name"]}," where the AWS App Runner application will be exposed."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["tenant name"]}," as a string.",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"Ripple provides you with the tenant name."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AWS region"]}," where the resources will be provisioned."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Submit the form to install the ",null,". ",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"Once the installation is complete, you can authenticate and then access the ",null," at the custom DNS name you provided. To add users to the AWS Cognito user pool for access to the ",null,", see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://docs.aws.amazon.com/cognito/latest/developerguide/signing-up-users-in-your-app.html"},"children":["Signing up and confirming user accounts"]},"."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2-deploy-the-vault","__idx":3},"children":["2. Deploy the vault"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["From the ",null," you just opened, you (or any assigned user) can now deploy the vault:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Enter your username and password.",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/custody-aws-onboarding.fd53c88493a96456fcf7f95c48da067afa2938c0e0212894953c34fd3a097861.87b60652.png","alt":"Custody onboarding"},"children":[]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"em","attributes":{},"children":["This screen shows the ",null," with the Getting started widget from where you can start to deploy the vault."]}," ",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Getting started"]}," widget, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Start"]}," and complete all sections to deploy a vault:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Create a new vault"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Configure networking"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Configure the key management system (KMS)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Configure telemetry (optional)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Connect a Docker container registry"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Installation"]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"success","name":"Note:"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",null," provides step-by-step instructions to guide you through the onboarding experience."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/custody-aws-onboarding-summary.3529e229f43fee91b67b1877d1c1aab611b0069c659ab8908df3b9c89ed8fafe.87b60652.png","alt":"Custody onboarding summary"},"children":[]}," ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["This screen shows the ",null," with the summary of the settings you selected for deploying the vault. Review the summary before you select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Submit"]},"."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once you ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["submit"]}," for installation, it takes from three to five minutes to create the resources on AWS Cloud. When the process is complete, the ",null," displays the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ID"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Public key"]}," that you will need to enter in ","Ripple Custody","."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/custody-onboarding-id-key-aws.5be61d9c784df46bac4eb05667a634cd16540f1a1b4726b7ac787925914c118d.87b60652.png","alt":"Copy ID and public key"},"children":[]}," ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["This screen shows the ",null," with the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ID"]}," and the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Public key"]}," that you must copy and then paste into your ","Ripple Custody"," instance to connect the vault."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Save a copy of the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ID"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Public Key"]}," values, as you will need to enter them in your ",null," instance."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"3-connect-the-vault","__idx":4},"children":["3. Connect the vault"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After the installation is complete, you must connect your vault to your ","Ripple Custody"," instance."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the ",null,", make sure you have saved a copy of the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ID"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Public Key"]}," values, and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Open ","Ripple Custody"," instance"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Log in to your ","Ripple Custody"," instance."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Administration"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Vaults"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create a vault"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Vault name"]}," field, enter a unique name for the vault."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ID"]}," value you copied from ",null,", and paste it into the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ID"]}," field in your ","Ripple Custody"," instance."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Public Key"]}," value you copied from ",null,", and paste it into the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Vault public key"]}," field in your ","Ripple Custody"," instance."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Submit for approval"]}," and follow the process for submitting and approving the intent to create the new vault."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The vault is connected when it appears in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Administration"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Vaults"]}," window, and its ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Activation status"]}," has changed from ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Pending"]}," to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Completed"]},". ",{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/vault-completed.456e8fd11ae5c915e4057c1f26c4723f146185545083a366e874efcfbc9d2c24.87b60652.png","alt":"Custody vaults"},"children":[]},"."]}]}]}]},"headings":[{"value":"Deploy a vault","id":"deploy-a-vault","depth":1},{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"1. Install the","id":"1-install-the","depth":2},{"value":"2. Deploy the vault","id":"2-deploy-the-vault","depth":2},{"value":"3. Connect the vault","id":"3-connect-the-vault","depth":2}],"frontmatter":{"seo":{"title":"Deploy a vault"}},"lastModified":"2026-08-04T20:25:11.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/deployment/integrate-kms/cloud-hsm/aws-cloudhsm-connect","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}