Skip to content

Add OpenBao on CT 3007 as a secrets store trial - #27

Merged
ChrisonSimtian merged 1 commit into
mainfrom
feat/openbao
Oct 1, 2026
Merged

ChrisonSimtian merged 1 commit into
mainfrom
feat/openbao

Conversation

@ChrisonSimtian

Copy link
Copy Markdown
Collaborator

Trial for superproject Chrison-Homelab/Homelab#609.

  • openbao.lxc.yaml: CT 3007 on hpe-01, 1 core / 512 MB / 4 GB, onboot: true. DHCP reservation 10.10.30.7 + openbao.devops.chrison.internal. LAN only; no Pangolin route or tunnel.

  • Its own CT, not a quadlet on 3006: that host runs a Chromium with a live Facebook session and an unauthenticated CDP port, and its shape already refuses to co-locate credentials with it.

  • tools/openbao-bootstrap.sh: the community-scripts installer inits 1-of-1 and keeps the unseal key and root token in plaintext with auto-unseal. Run once by Christian, this script:

    • rekeys to 2-of-3;
    • stores the shares and an admin userpass login in Bitwarden, then reads them back and compares;
    • revokes root and removes the plaintext and the auto-unseal drop-in;
    • re-issues TLS with a proper SAN;
    • proves the store is SEALED after a restart, then unseals it.

    Secrets only ever travel on ssh stdin, and a mode-600 lifeline file keeps the shares until Bitwarden has them. --check runs the preflight only. --test-no-bitwarden is a rehearsal against a CT snapshot that gets rolled back.

  • The engine side (the assert-only openbao provisioner + catalogue entry) comes in the superproject PR that bumps this submodule.

🤖 Generated with Claude Code

https://claude.ai/code/session_01V2afcTcowT1YVBwLzrJFtH

…ning script

OpenBao gets its own CT rather than a quadlet on CT 3006, which hosts a
Chromium with a live Facebook session behind an unauthenticated DevTools port.

community-scripts' installer leaves the unseal key and root token in plaintext
on disk and auto-unseals from them, so the seal protects nothing and every
backup would carry the keys. tools/openbao-bootstrap.sh fixes that once from the
workstation: rekey to 2-of-3, shares and an admin login into Bitwarden (read
back and compared), root revoked, plaintext removed, TLS re-issued with a real
SAN, and the store proven sealed after a restart before being unsealed. The
engine's openbao provisioner only asserts that state and never handles keys.

Superproject #609.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V2afcTcowT1YVBwLzrJFtH
@ChrisonSimtian ChrisonSimtian added the enhancement New feature or request label Oct 1, 2026
@ChrisonSimtian
ChrisonSimtian merged commit ea39020 into main Oct 1, 2026
1 check passed
@ChrisonSimtian
ChrisonSimtian deleted the feat/openbao branch October 1, 2026 00:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant