Repository navigation
feat(openbao): support KMS auto-unseal in the self-managed chart #2310
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
sbaum1994
merged 11 commits into
NVIDIA:main
from
sunilthorat09:feat/openbao-kms-auto-unseal
Oct 7, 2026
Merged
Changes from all commits
Commits
Show all changes
11 commits
Select commit
Hold shift + click to select a range
1f25bd6
feat(openbao): support KMS auto-unseal in the self-managed chart
78f2129
Merge branch 'main' into feat/openbao-kms-auto-unseal
sunilthorat09 4c21d85
fix(openbao): fail closed on unparseable seal status, add resolver test
bbfbcfd
fix(openbao): fail on bao operator init error before parsing output
c770412
docs(openbao): clarify recovery-key custody and PKCS#11 prerequisites
4d00dad
Merge branch 'NVIDIA:main' into feat/openbao-kms-auto-unseal
sunilthorat09 e14c8e3
fix(openbao): delete recovery-keys Secret in cleanup.sh
d9aed00
docs(openbao): don't assert the default image lacks PKCS#11 support
0f02f1c
Merge branch 'main' into feat/openbao-kms-auto-unseal
gsharma-nv 32474d5
Merge branch 'main' into feat/openbao-kms-auto-unseal
gsharma-nv 8c4f7a8
Merge branch 'main' into feat/openbao-kms-auto-unseal
sunilthorat09 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
106 changes: 106 additions & 0 deletions
106
deploy/helm/openbao/helm/values-autounseal.yaml.example
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,106 @@ | ||
| # SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. | ||
| # SPDX-License-Identifier: Apache-2.0 | ||
| # | ||
| # Licensed under the Apache License, Version 2.0 (the "License"); | ||
| # you may not use this file except in compliance with the License. | ||
| # You may obtain a copy of the License at | ||
| # | ||
| # http://www.apache.org/licenses/LICENSE-2.0 | ||
| # | ||
| # Unless required by applicable law or agreed to in writing, software | ||
| # distributed under the License is distributed on an "AS IS" BASIS, | ||
| # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| # See the License for the specific language governing permissions and | ||
| # limitations under the License. | ||
|
|
||
| # Example values overlay for OpenBao auto-unseal. Apply on top of values.yaml. | ||
| # | ||
| # This turns on server.autoUnseal, adds a seal stanza so each node unseals | ||
| # through the seal on start, and drops the Shamir auto-unseal sidecar and its | ||
| # unseal Secret volume. The init hook then initializes with recovery keys. | ||
| # | ||
| # The seal block below uses AWS KMS as a concrete example. For Azure Key Vault, | ||
| # GCP KMS, or HashiCorp/OpenBao Transit, replace just the seal stanza with that | ||
| # provider's block (see the OpenBao seal documentation); the rest of this overlay | ||
| # is identical. | ||
| # | ||
| # A PKCS#11 HSM is not a drop-in stanza swap. The seal "pkcs11" block points at | ||
| # the HSM vendor's PKCS#11 library (lib, token_label, key_label), which must be | ||
| # present in the server container. PKCS#11 support itself comes from either an | ||
| # HSM-enabled OpenBao build with PKCS#11 compiled in via cgo, or the external | ||
| # PKCS#11 KMS provider plugin (openbao-plugins). Make sure the OpenBao image you | ||
| # run provides one of these; the seal stanza alone does not. See the OpenBao | ||
| # pkcs11 seal docs. | ||
| # | ||
| # The server pod needs the provider's unwrap permission on the key, granted out | ||
| # of band. For AWS KMS that is kms:Encrypt, kms:Decrypt and kms:DescribeKey, for | ||
| # example through an EKS Pod Identity or IRSA role. Automatic key rotation is | ||
| # safe where the provider keeps the key id and can still decrypt the previously | ||
| # wrapped root key. | ||
| # | ||
| # Required post-install step, before treating the cluster as production. The init | ||
| # hook stores all recovery shares in one Secret, <statefulset>-recovery-keys. | ||
| # While it exists, any reader of that Secret holds the full recovery quorum, so | ||
| # the shares/threshold below give no protection. Finish the install by exporting | ||
| # the shares, splitting them among separate custodians offline, and deleting the | ||
| # Secret: | ||
| # | ||
| # kubectl get secret <statefulset>-recovery-keys -n <namespace> \ | ||
| # -o jsonpath='{.data.recovery_keys_b64}' | base64 -d # then split offline | ||
| # kubectl delete secret <statefulset>-recovery-keys -n <namespace> | ||
| # | ||
| # Only after the delete does the threshold protect the quorum. deploy.sh logs the | ||
| # same reminder at the end of init. | ||
|
|
||
| openbao: | ||
| server: | ||
| autoUnseal: | ||
| enabled: true | ||
| recovery: | ||
| shares: 5 | ||
| threshold: 3 | ||
|
|
||
| # Override the raft config to add the seal stanza. Keep the rest in sync | ||
| # with values.yaml; only the seal block is new here. | ||
| ha: | ||
| raft: | ||
| config: | | ||
| ui = true | ||
| storage "raft" { | ||
| path = "/openbao/data/" | ||
| retry_join { | ||
| leader_api_addr = "http://openbao-server-0.openbao-server-internal:8200" | ||
| } | ||
| retry_join { | ||
| leader_api_addr = "http://openbao-server-1.openbao-server-internal:8200" | ||
| } | ||
| retry_join { | ||
| leader_api_addr = "http://openbao-server-2.openbao-server-internal:8200" | ||
| } | ||
| } | ||
| listener "tcp" { | ||
| tls_disable = 1 | ||
| address = "[::]:8200" | ||
| cluster_address = "[::]:8201" | ||
|
|
||
| custom_response_headers { | ||
| "default" = { | ||
| "X-Custom-Header" = ["HOSTNAME"], | ||
| }, | ||
| } | ||
| } | ||
| # Example: AWS KMS. Swap this block for azurekeyvault, gcpckms, | ||
| # transit, or pkcs11 to use a different provider. | ||
| seal "awskms" { | ||
| region = "<region>" | ||
| kms_key_id = "<kms-key-id>" | ||
| } | ||
| plugin_directory = "/openbao/plugins/" | ||
| service_registration "kubernetes" {} | ||
| disable_standby_reads = true | ||
|
|
||
| # KMS unseals the server, so the Shamir unseal sidecar and its Secret volume | ||
| # are not used. Drop them. | ||
| extraContainers: [] | ||
| volumes: [] | ||
| volumeMounts: [] |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.