💥 Title: “Rebuilt Vault in One Night: A Real-World Journey with OpenBao, Raft, and Secrets That Work”
THE TRIGGER
HashiCorp Vault works, but the licensing doesn’t scale. The cost was outpacing its actual use. The goal was to build a replacement that kept the features that mattered — HA storage, transit encryption, secrets engines — without carrying the enterprise price tag.
Started work at 4:45 PM. Final test script passed at 2:49 AM.
STEP 1: BUILDING A PRODUCTION-READY CHART
The OpenBao Helm chart worked for local demos, but not much more. Rebuilt the chart with these priorities:
Skipped injector and webhook for this iteration to stay focused on the control plane.
STEP 2: STABILIZING RAFT BACKEND FOR HA
Used Raft (Integrated Storage) for stateful HA.
Config included:
Problems hit:
Wrote a short init script to:
STEP 3: CONFIGURED AND TESTED ENGINES
Used five engines, each tested with real integration.
kv-v2
transit
pki
database
ssh
WHAT NEEDED FIXING
COST ANALYSIS
HashiCorp Vault with Raft, DR, UI, and enterprise auth integration is expensive — and billing grows with usage and teams. This cost goes away with OpenBao. Invested time instead of money. Got:
No license. No audit tier upsells. No enterprise sales cycle.
WHAT COMES NEXT
No team. No vendor calls. No purchase orders. Just time and a sharp goal.
🛠️ Every part is real, tested, and running.
Want to see the scripts or overlays? Happy to share.
Open Source Cryptographer and Violinist - cipherboy.com - OpenBao TSC Chair @ GitLab
2moIf you want to upstream Helm chart improvements, we're happy to discuss them!
Building Cashkr | Innovator in Technology & Sustainability
3moimpressive work! crafting solutions like this encourages innovation in the cloud space, doesn’t it? 💡 #techtransformation