Skip to content

Fix two bootstrap failures found by rehearsing it against a CT snapshot - #29

Merged
ChrisonSimtian merged 1 commit into
mainfrom
fix/openbao-bootstrap-sigpipe
Oct 1, 2026
Merged

ChrisonSimtian merged 1 commit into
mainfrom
fix/openbao-bootstrap-sigpipe

Conversation

@ChrisonSimtian

Copy link
Copy Markdown
Collaborator

Rehearsed tools/openbao-bootstrap.sh --test-no-bitwarden against a CT 3007 snapshot, then rolled it back. Two failures, both fixed:

  1. SIGPIPE: tr < /dev/urandom | head -c 32 under pipefail exited 141 right after preflight. Now openssl rand -hex 24.
  2. Audit over the API is refused by OpenBao 2.x (cannot enable audit device via API; use declarative, config-based audit device management). The provisioner now declares it in openbao.hcl (companion superproject PR), so the bootstrap no longer calls audit enable.

Final rehearsal: sealed after restart ✅, 2-of-3 ✅, old root 403 ✅, admin login 200 ✅, plaintext lines 0 ✅, SAN openbao.devops.chrison.internal + 10.10.30.7 ✅. Provisioner verdict on that state: hardened, 2-of-3 seal, unsealed. Rolled back afterwards; the rehearsal shares are destroyed.

Superproject Chrison-Homelab/Homelab#609.

🤖 Generated with Claude Code

https://claude.ai/code/session_01V2afcTcowT1YVBwLzrJFtH

The admin password came from `tr < /dev/urandom | head`, which dies of SIGPIPE
under pipefail: the first rehearsal exited 141 straight after preflight. It is
now `openssl rand -hex 24`, with no pipe.

OpenBao 2.x refuses `bao audit enable` ("use declarative, config-based audit
device management"), so the configure step failed after init. The audit device
is now declared in openbao.hcl by the provisioner, and the bootstrap no longer
tries to create it.

With both fixed, the full rehearsal passed every post-condition (sealed after
restart, 2-of-3, old root 403, admin login 200, no plaintext, SAN set) and was
rolled back.

Superproject #609.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V2afcTcowT1YVBwLzrJFtH
@ChrisonSimtian ChrisonSimtian added the bug Something isn't working label Oct 1, 2026
@ChrisonSimtian
ChrisonSimtian merged commit 06c9ccf into main Oct 1, 2026
1 check passed
@ChrisonSimtian
ChrisonSimtian deleted the fix/openbao-bootstrap-sigpipe branch October 1, 2026 00:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant