openbao: fix bootstrap so it completes on 2.6.x #134

Closed
admin_emi wants to merge 0 commits from fix/openbao-bootstrap-2-6 into dev
Owner

bootstrap.sh could not run to completion on OpenBao 2.6.1:

  • Release asset names were wrong. bao_<ver>_linux_amd64.tar.gz and
    bao_<ver>_SHA256SUMS both 404; the assets are openbao_<ver>_... and
    checksums.txt. The tarball is now saved under its real name and the checksum
    grep anchored to end-of-line, because checksums.txt also lists a .sbom.json and
    sha256sum -c resolves each line by the filename inside it.
  • openssl rand -base64 32 appends a newline and the static seal reads the key
    file raw, so the service failed with Error configuring seal "static": unknown encoding for AES-256 key.
  • The audit stanza relied on the block label being the device type. 2.6.1 requires
    explicit type and path with device settings under options. Worth noting the
    intermediate state: with type and path but a bare file_path, the server starts
    and silently ignores the log location, which is the worse failure given a wedged
    audit device stops OpenBao answering at all.
  • disable_mlock is unsupported in 2.6.1 and warned on every start.
  • Nothing opened port 8200 and ufw defaults to deny(incoming), so vps1 could not
    reach the vault. dev renders on vps1, so this would have surfaced as a timeout
    during cutover rather than here.

bootstrap-policies.sh installed beta's credentials as deploy:deploy, but vps2 has
no deploy user and both environments deploy as agent (env-topology.sh sets
TG_SSH_TARGET=agent@ for both; deploy.yml uses one VPS2_SSH_USER). install_creds
also printed a success line after a failed chown: the call site wrapped it in
|| echo, which suppresses set -e for everything inside the function, so it fell
through to chmod and reported an ownership it never applied. It now removes the
half-written file and returns non-zero.

Corrects the isolation rationale accordingly — separate credentials buy audit
attribution and a policy boundary against mistakes, not deploy-user isolation.

Documents the 2.6.0 root-token change (HCSEC-2026-08): generate-root now targets
an authenticated endpoint, so recovery keys cannot mint a replacement token and
revoking the last root token before a second admin identity exists is a one-way
door. Also corrects the runbook's verify-parity.sh --all, which cannot work from
a single host given the AppRole CIDR bindings.

bootstrap.sh could not run to completion on OpenBao 2.6.1: - Release asset names were wrong. `bao_<ver>_linux_amd64.tar.gz` and `bao_<ver>_SHA256SUMS` both 404; the assets are `openbao_<ver>_...` and `checksums.txt`. The tarball is now saved under its real name and the checksum grep anchored to end-of-line, because checksums.txt also lists a .sbom.json and `sha256sum -c` resolves each line by the filename inside it. - `openssl rand -base64 32` appends a newline and the static seal reads the key file raw, so the service failed with `Error configuring seal "static": unknown encoding for AES-256 key`. - The audit stanza relied on the block label being the device type. 2.6.1 requires explicit `type` and `path` with device settings under `options`. Worth noting the intermediate state: with type and path but a bare `file_path`, the server starts and silently ignores the log location, which is the worse failure given a wedged audit device stops OpenBao answering at all. - `disable_mlock` is unsupported in 2.6.1 and warned on every start. - Nothing opened port 8200 and ufw defaults to deny(incoming), so vps1 could not reach the vault. dev renders on vps1, so this would have surfaced as a timeout during cutover rather than here. bootstrap-policies.sh installed beta's credentials as `deploy:deploy`, but vps2 has no `deploy` user and both environments deploy as `agent` (env-topology.sh sets TG_SSH_TARGET=agent@ for both; deploy.yml uses one VPS2_SSH_USER). install_creds also printed a success line after a failed chown: the call site wrapped it in `|| echo`, which suppresses `set -e` for everything inside the function, so it fell through to chmod and reported an ownership it never applied. It now removes the half-written file and returns non-zero. Corrects the isolation rationale accordingly — separate credentials buy audit attribution and a policy boundary against mistakes, not deploy-user isolation. Documents the 2.6.0 root-token change (HCSEC-2026-08): `generate-root` now targets an authenticated endpoint, so recovery keys cannot mint a replacement token and revoking the last root token before a second admin identity exists is a one-way door. Also corrects the runbook's `verify-parity.sh --all`, which cannot work from a single host given the AppRole CIDR bindings.
admin_emi closed this pull request 2026-07-31 05:15:27 +00:00
All checks were successful
secrets-guard / encrypted (pull_request) Successful in 4s
PR build (required check) / changes (pull_request) Successful in 7s
shell-lint / shellcheck (pull_request) Successful in 6s
PR build (required check) / build-backend (pull_request) Has been skipped
PR build (required check) / build-frontend (pull_request) Has been skipped
PR build (required check) / validate-observability (pull_request) Has been skipped
PR build (required check) / gate (pull_request) Successful in 1s
Required
Details

Pull request closed

Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: Jinemi/thermograph#134
No description provided.