OpenBao

RSS: https://openbao.org/blog/rss.xml
OpenBao 开源项目博客,HashiCorp Vault 的社区维护分支。

OpenBao v2.6 发布:命名空间密封与工作流引擎

OpenBao v2.6 正式发布,新增命名空间隔离密封、自动解封插件、跨插件工作流引擎和 Distroless 容器镜像。命名空间密封允许租户通过密钥操作撤销实例操作员的访问权限,不影响其他租户;自动解封插件支持将 KMS 机制以外部二进制插件形式分发;工作流引擎提供 sys/workflows 端点,支持多请求工作流和跨插件通信。
评论点赞收藏43 天前

Flux 与 OpenBao 集成:GitOps 密钥管理与签名方案

OpenBao 与 Flux 集成,实现 GitOps 场景下的密钥管理和 OCI 签名。SOPS 加密的 Secret 通过 OpenBao Transit 引擎解密,无需静态 BAO_TOKEN;Cosign 用 OpenBao 持有的密钥签名 OCI 制品,Flux 可验证签名。 两者都依赖 workload identity——Kubernetes ServiceAccount token 换取短期 OpenBao token,避免长期凭证。
评论点赞收藏49 天前

OpenBao Features - Declarative Plugins

This is the fourth part of a multi-part series on OpenBao's features. Last time we talked about how to declaratively configure audit devices and initialize OpenBao. We saw how this made integration of...
评论点赞收藏62 天前

使用OpenBao进行可持续性秘密管理——开源@西门子2026

<p>本次演讲内容摘自迈克尔在2026年“开源@西门子”大会上的分享,深入探讨OpenBao的起源及其为何成为可持续发展的理想之选。</p><p>如需观看视频,请访问西门子的页面。</p><p>欢迎各位莅临我的OpenBao与可持续秘钥管理专题演讲!我是Adfinis的首席技术官迈克尔·“Hofi”霍弗,同时也是OpenBao技术指导委员会(TSC)的主席。</p><p>能再次回到楚格参加“开源@西门子”盛会,对我来说真是莫大的荣幸——对我个人而言,这场活动始终是年度盛事。衷心感谢西门子团队精心组织了这样一场精彩纷呈的盛会!<br><br>每一年都愈发精彩,而这次我们还特意搭配上了浪漫的氛围灯光,令人倍感惬意。我已经迫不及待地期待着明年的到来。</p><p>此外,也想快速向Jan和Pasquale致以诚挚的问候,感谢他们此前带来的。看到一个邻近的Linux基金会项目真正落地实施,实在令人倍感振奋。</p><p>今天,我想和大家分享:如何让秘钥管理在未来数十年内依然保持开放、以社区为导向,并且持续可持续发展。</p><h2>什么是秘钥管理?</h2><p>在深入探讨OpenBao本身之前,让我们先简单回顾一下:当我们谈论<em>秘钥管理</em>时,究竟指的是什么?</p><p>环顾四周,我知道在座的各位大多拥有扎实的技术背景,因此这一核心理念并不新鲜。它指的是日常工作中,为确保机器工作负载正常运行所需的所有秘钥进行保护与整合——包括API令牌、TLS证书、凭证对以及客户端秘钥。</p><p>请注意,我提到的是<em>机器工作…</em></p>
评论点赞收藏65 天前

OpenBao 特性解析:声明式配置

OpenBao v2.4.0 引入声明式自初始化和审计设备配置,允许在部署前定义系统状态。针对 Vault API 模型导致审计配置与初始化顺序难以保证的问题,该功能支持通过配置文件定义审计设备并在 SIGHUP 重载,旨在解决因配置交互引发的远程代码执行漏洞风险,提升运维安全性与可复现性。
评论点赞收藏71 天前

OpenBao:敏感数据的存储与管理

OpenBao 是 HashiCorp Vault 的开源分支,旨在维护和改进敏感数据管理方案。支持密钥加密、动态生成与自动续期、统一身份访问控制及批量撤销。 目前由社区治理,获多家企业支持。
评论点赞收藏77 天前

构想更优的Shamir秘密共享用户体验

OpenBao团队探讨如何改进Shamir秘密共享的用户体验,解决高熵密钥分享难以存储和输入的问题。提出基于密码掩码的方案,支持声明式自初始化和无状态解封,旨在降低运维复杂度,特别是针对气隙环境。
评论点赞收藏85 天前

OpenBao 新功能:分页列表与性能优化

OpenBao v2.0 引入分页列表功能,解决 Vault 因历史存储接口限制导致的内存溢出问题。通过新增 ListPage 接口,支持 limit 和 after 参数,显著降低大规模数据查询时的资源消耗。 插件作者可利用兼容层同时支持 Vault 和 OpenBao。
评论点赞收藏91 天前

Improved Horizontal Scalability

Summary ​ In this blog post, I will give you an overview of the new Horizontal Scalability feature of OpenBao, its (current) limitations and planned future developments. In the second part, I will sho...
评论点赞收藏189 天前

The Perfectly Unperfect Mentorship

Imagine starting a mentorship program with a big goal and... not a perfect plan. Sound familiar? That was us, three months ago. We had a brilliant mentee, Fatima Patel, a crucial feature for OpenBao’s...
评论点赞收藏372 天前

Meet OpenBao at Open Source Summit Europe 2025

Open source builders, security engineers, and platform teams are converging on Amsterdam and OpenBao will be in the middle of it, thanks to the generosity of the Linux Foundation. We’re excited to ann...
评论点赞收藏407 天前

Vision for Namespaces, Horizontal Scalability

As the OpenBao community starts development on Namespaces and the Horizontal Scalability Working Group has its kickoff, I wanted to take the opportunity to put forward a blog post describing how these...
评论点赞收藏581 天前

OpenBao @ GitLab - FOSDEM '25

Slides and content from Alex's FOSDEM '25 talk about OpenBao's usage at GitLab. For a video, see our official YouTube channel or on the FOSDEM video mirror. SVG rendering is not supported on your brow...
评论点赞收藏595 天前

OpenBao Travels Back Home

OpenBao returns from FOSDEM '25 and OpenUK's State of Open Con this week, reflecting on the travels and activities of the events. Many thanks to Fatima for running the community calls in our absence! ...
评论点赞收藏600 天前

OpenBao Travels to FOSDEM

Follow along with OpenBao's travels this week as we attend FOSDEM '25 and State of Open Con! info Check out Alex's talk at FOSDEM, on Sunday, February 2nd, at 2:05 PM GMT+1 in room UA2.118 (Henriot) a...
评论点赞收藏607 天前

登录芦苇

登录后关注作者、收藏内容和参与讨论。