Sign inSign up

readystack/openbao

By readystack

•Updated about 22 hours ago

OpenBao — v2.5.5 r1-r3 withdrawn (dev mode, root token "root"); fixed v2.7.1 coming

Image
0

1.2K

readystack/openbao repository overview

⁠OpenBao

Docker Scout: Grade A Fixable Critical/High CVEs: 0 Signed: cosign

readystack/openbao:v2.7.1-CE-ubuntu24.04-r1

A hardened, cosign-signed, offline-rebuildable build of github.com/openbao/openbao v2.7.1 (MPL-2.0 — Linux Foundation OSS fork of HashiCorp Vault), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

  • Docker Scout Grade A — 0 fixable Critical/High, non-root, SBOM + provenance attestations; re-checked daily at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/openbao:v2.7.1-CE-ubuntu24.04-r1.
  • Built from source, non-root.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v2.7.1-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/openbao:v2.7.1-CE-ubuntu24.04-r1

# ✗ unsupported (do not pull)
docker pull readystack/openbao:internal-...

Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/openbao:v2.7.1-CE-ubuntu24.04-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠.

⁠Deployment

Single container, single static Go binary. The image's ENTRYPOINT is bao and its default command is server -config=/openbao/config/openbao.hcl, a configuration shipped in the image: integrated (raft) storage in /openbao/data, a plain-HTTP listener on 0.0.0.0:8200 (tls_disable = true), api_addr http://127.0.0.1:8200⁠ and cluster_addr http://127.0.0.1:8201⁠ (cluster port 8201). The server starts uninitialized and sealed and has no built-in root token: nothing is usable until you initialize it once (bao operator init prints the unseal keys and the initial root token, only that once) and unseal it (bao operator unseal, once per key until the threshold, 3 of 5 by default). Secrets management, KV, dynamic secrets, PKI and transit encryption over the HTTP API on :8200. No SQL database, no sidecar. The web UI is not bundled; the API and the bao CLI are.

docker run -d --name openbao -p 127.0.0.1:8200:8200 -v openbao-data:/openbao/data readystack/openbao:v2.7.1-CE-ubuntu24.04-r1

Starts a persistent OpenBao server with its data in the openbao-data volume. It answers within a few seconds, uninitialized and sealed: initialize it once with docker exec openbao bao operator init (it prints the unseal keys and the root token, only this once) and unseal it with docker exec openbao bao operator unseal '<unseal key>', once per key until the threshold (3 of 5 by default); unseal it again after every restart. Port 8200 is published on 127.0.0.1 only: the listener speaks plain HTTP, and until the server is initialized, anyone who can reach the port can initialize it and receive the root token. The archive ships no Compose file.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:162c2d2b9…

Size

105.3 MB

Last updated

about 22 hours ago

docker pull readystack/openbao:v2.7.1-CE-ubuntu24.04-r1