Skip to content

Let the OpenBao bootstrap initialise an uninitialised store directly - #28

Merged
ChrisonSimtian merged 1 commit into
mainfrom
fix/openbao-init-path
Oct 1, 2026
Merged

ChrisonSimtian merged 1 commit into
mainfrom
fix/openbao-init-path

Conversation

@ChrisonSimtian

Copy link
Copy Markdown
Collaborator

The CT 3007 install died before its init: the OpenBao 2.7.0 .deb still ships storage "file", which 2.7.0 removed. The superproject provisioner now renders raft storage (companion PR), so the store comes up uninitialised.

tools/openbao-bootstrap.sh now accepts two starting states. init (uninitialised) runs sys/init 2-of-3 directly, unseals with 2 shares and configures, so no single key and no on-disk root token ever exist. rekey is the original path for the installer's 1-of-1 plaintext state, for when community-scripts/ProxmoxVE#17548 lands. Everything after that is shared: Bitwarden + read-back, revoke root, strip plaintext, re-issue TLS, prove sealed after restart, unseal.

Superproject Chrison-Homelab/Homelab#609.

🤖 Generated with Claude Code

https://claude.ai/code/session_01V2afcTcowT1YVBwLzrJFtH

On CT 3007 the community-scripts install died before its init step, because the
OpenBao 2.7.0 package still ships `storage "file"`, which 2.7.0 removed. The
store was therefore never initialised, which is the better starting point: the
bootstrap now inits 2-of-3 directly, so no single key and no on-disk root token
ever exist. The rekey path stays for when the upstream installer fix
(community-scripts/ProxmoxVE#17548) lands and a rebuild gets the 1-of-1 state.

Superproject #609.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V2afcTcowT1YVBwLzrJFtH
@ChrisonSimtian ChrisonSimtian added the bug Something isn't working label Oct 1, 2026
@ChrisonSimtian
ChrisonSimtian merged commit 7392264 into main Oct 1, 2026
1 check passed
@ChrisonSimtian
ChrisonSimtian deleted the fix/openbao-init-path branch October 1, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant