TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OpenBao – FOSS Fork of HashiCorp Vault

314 pointsby thinkmassiveover 1 year ago

14 comments

dangover 1 year ago
Recent and related:<p><i>HashiCorp Vault forked into OpenBAO</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38578247">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38578247</a> - Dec 2023 (70 comments)
sc0rpilover 1 year ago
Hey HN, I&#x27;m involved with this project, glad you found it interesting! Keep in mind it&#x27;s still a _very_ early stage and not in a usable state. A lot of work in progress but also plenty of opportunities if you want to contribute.<p>If you want to help out, you can :<p>Join Matrix rooms:<p>- <a href="https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-announcements:chat.lfx.linuxfoundation.org" rel="nofollow noreferrer">https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-announc...</a><p>- <a href="https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-development:chat.lfx.linuxfoundation.org" rel="nofollow noreferrer">https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-develop...</a><p>- <a href="https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-general:chat.lfx.linuxfoundation.org" rel="nofollow noreferrer">https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-general...</a><p>- <a href="https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-questions:chat.lfx.linuxfoundation.org" rel="nofollow noreferrer">https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-questio...</a><p>- <a href="https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-random:chat.lfx.linuxfoundation.org" rel="nofollow noreferrer">https:&#x2F;&#x2F;chat.lfx.linuxfoundation.org&#x2F;#&#x2F;room&#x2F;#openbao-random:...</a><p>Join the mailing list: <a href="https:&#x2F;&#x2F;lists.lfedge.org&#x2F;g&#x2F;openbao" rel="nofollow noreferrer">https:&#x2F;&#x2F;lists.lfedge.org&#x2F;g&#x2F;openbao</a>
评论 #38583658 未加载
评论 #38580335 未加载
评论 #38580636 未加载
评论 #38581792 未加载
firesteelrainover 1 year ago
I use HashiCorp Vault paid version to interface with an on premises HSM and for its FIPS compliance. I don’t know of any other software that is as lightweight and easy to use with an HSM as vault. We are using Vault to store the signed intermediate CA and automatically unseal Vault by storing the shards in the HSM (along with the Root CA). OpenBao wouldn’t solve this for me.
评论 #38583875 未加载
评论 #38585709 未加载
评论 #38583665 未加载
iamawackoover 1 year ago
That&#x27;s real cool, still hoping for a Nomad fork.
评论 #38585432 未加载
g0xA52A2Aover 1 year ago
Dupe of <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38578247">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38578247</a>
评论 #38583118 未加载
baz00over 1 year ago
As much as I appreciate open source forks of things like this I’d rather just completely avoid vault if I can. This and consul are bits of software that make my life harder not better in the last few years.
评论 #38581116 未加载
评论 #38580820 未加载
评论 #38583156 未加载
评论 #38583103 未加载
评论 #38582689 未加载
account42over 1 year ago
&gt; Please note: We take OpenBao&#x27;s security and our users&#x27; trust very seriously.<p>Funny how that sentence is one of the quickest ways to make me mistrust something (even if possibly undeserved).
aestetixover 1 year ago
Hi,<p>This is concerning. To me it looks like there is a holy war going on with devs who maintain a secrets manager. The last thing I want is instability with the tool that holds my passwords and credentials. On the low end of my concern is the annoyance of constantly updating names in yaml files, and on the high end is worry that a rogue dev could deliberately add in a security hole that would compromise my secrets.<p>Is there any assurance this won&#x27;t happen?
评论 #38582190 未加载
评论 #38581522 未加载
评论 #38582323 未加载
taspeotisover 1 year ago
Oops <a href="https:&#x2F;&#x2F;github.com&#x2F;openbao&#x2F;openbao&#x2F;tree&#x2F;development?tab=readme-ov-file#developing-vault">https:&#x2F;&#x2F;github.com&#x2F;openbao&#x2F;openbao&#x2F;tree&#x2F;development?tab=read...</a>
评论 #38583132 未加载
skeptruneover 1 year ago
Based that you use Matrix and not disc
raffraffraffover 1 year ago
&gt; Please note: We take OpenBao&#x27;s security and our users&#x27; trust very seriously. If you believe you have found a security issue in Vault, please responsibly disclose by contacting us at openbao-security@lists.lfedge.org.<p>You might wanna change Vault to OpenBao
评论 #38583351 未加载
评论 #38584322 未加载
jimmyedover 1 year ago
Why is the logo the same as bun.sh?
评论 #38580115 未加载
评论 #38579902 未加载
评论 #38580573 未加载
vmatsiiakoover 1 year ago
Appreciate the fork, but I think it&#x27;s time for people to move on from Vault and other HashiCorp tools (especially that I&#x27;m hearing this is financed by IMB to keep their Vault competitor going).<p>Check out Infisical for secret management: <a href="https:&#x2F;&#x2F;github.com&#x2F;Infisical&#x2F;infisical">https:&#x2F;&#x2F;github.com&#x2F;Infisical&#x2F;infisical</a><p>Disclaimer: I&#x27;m one of the maintainers.
评论 #38583862 未加载
评论 #38583313 未加载
评论 #38586534 未加载
评论 #38583692 未加载
danenaniaover 1 year ago
Another option that focuses on ease-of-use and security is EnvKey - <a href="https:&#x2F;&#x2F;envkey.com">https:&#x2F;&#x2F;envkey.com</a> (I’m the founder)<p>It’s has client-side end-to-end encryption with no backdoors or compromises, is open source, and, apart from secrets management, provides a robust set of tools to manage and de-duplicate config.<p>Comparison with Vault: <a href="https:&#x2F;&#x2F;www.envkey.com&#x2F;compare&#x2F;hashicorp-vault&#x2F;">https:&#x2F;&#x2F;www.envkey.com&#x2F;compare&#x2F;hashicorp-vault&#x2F;</a>