Course · Training · Workshop
OpenBao Operations & Architecture
Introduce and run OpenBao as a central secrets platform: architecture, storage and high availability, auto-unseal, namespaces and governance, audit and monitoring, backup and DR, upgrades, hardening and migration from HashiCorp Vault.
Built with Adfinis, core maintainer of OpenBao and provider of Secretz Enterprise (OpenBao enterprise subscription).
Setting up OpenBao takes an afternoon. Running it as a central secrets platform for hundreds of developers is a different job: Which storage backend, how many nodes, how does the cluster unseal after a restart? How do you separate teams, connect your identity provider and keep policies manageable when every team wants self-service? And how do you get the cluster back after a failure? This course is for the engineers who introduce OpenBao in a company and run it afterwards. We build a production-grade cluster on Kubernetes, break it on purpose and put it back together - and work through the architecture and governance decisions with your concrete setup.
What participants say






These customers booked courses in the same topic cluster.More customers →
Content
The course consists of the following topics. We select and weight them together with you, depending on your platform, your goals and the group’s prior knowledge. We work throughout on your own OpenBao cluster on Kubernetes in the letsboot labmachine.
– OpenBao in the landscape:
- OpenBao and HashiCorp Vault: shared roots, differences, roadmap and governance
- OpenBao next to cloud secret stores, KMS and existing PAM tools
- Core concepts refresher: mounts, auth methods, policies, tokens and leases
- Community releases, Secretz Enterprise and support options – Architecture and design:
- Storage backends: integrated Raft vs. PostgreSQL
- Raft consensus, quorum and autopilot
- Sizing, node count and reference architectures
- Deployment on Kubernetes with Helm, on VMs or bare metal
- Hands-On: set up an OpenBao cluster on Kubernetes – High availability:
- Active and standby nodes, request forwarding
- Load balancer integration and health checks
- Failure scenarios: node loss, network partition, lost quorum
- Hands-On: test failover and recover a cluster that lost quorum – Seal and unseal:
- Shamir’s secret sharing and key ceremonies
- Auto-unseal with KMS, HSM or Transit
- Seal as an emergency switch, recovery keys and rekeying
- Hands-On: migrate from Shamir to auto-unseal – Namespaces and multi-tenancy:
- Namespaces for teams, environments and customers
- Structure, delegation and limits of namespaces
- Hands-On: namespace structure for several teams – Identity and access:
- IAM and OIDC integration with the company identity provider
- Auth methods per use case: people, applications, pipelines, Kubernetes
- Entities, groups and group mapping from the identity provider
- Hands-On: OIDC login with group-based access – Policy governance:
- Naming conventions for mounts, paths, roles and policies
- Templated policies and delegated self-service for teams
- Policies as code: review, tests and deployment via Git
- Hands-On: policy set for a new team via GitOps – Platform integration:
- Kubernetes and OpenShift: auth, Agent Injector, CSI provider, External Secrets Operator at platform scale
- GitLab CI/CD and other pipelines with JWT auth
- Dynamic secrets and PKI in production: roles, TTLs, CA hierarchy – Audit and monitoring:
- Audit devices, log format and HMAC
- SIEM integration (e.g. Splunk, Elastic)
- Telemetry, Prometheus metrics, Grafana dashboards and alerting
- Token lifecycle, TTLs and lease management at scale
- Hands-On: dashboards and alerts for a running cluster – Backup and disaster recovery:
- Raft snapshots and PostgreSQL backups
- Restore procedures and regular restore tests
- Disaster recovery concepts and runbooks
- Hands-On: restore the cluster from a snapshot after a failure – Upgrades and lifecycle:
- Release cycle, changelogs and deprecations
- Zero-downtime rolling upgrades
- Plugin management and version pinning
- Hands-On: rolling upgrade of a running cluster – Hardening and security:
- TLS, network segmentation and listener configuration
- Root token handling, break-glass procedures
- Least privilege for operators and the platform team
- Incident response: leaked secrets, compromised tokens – Troubleshooting:
- Sealed nodes, lost quorum, lease explosions, performance issues
- Reading logs, metrics and audit trails
- Hands-On: find and fix prepared failures – Migration from HashiCorp Vault:
- Compatibility of API, clients, plugins and data
- Migration paths, rollback and hybrid operation
- Hands-On: migrate a Vault setup to OpenBao – Introducing OpenBao in the company:
- Adoption playbook: pilot teams, onboarding, documentation
- Operating model: responsibilities between platform, security and development teams
- Architecture review of your own cases – Optional exam:
- Practical exam in the lab - tasks, not multiple choice
- Certificate and Credly badge for everyone who passes
The goal is an OpenBao platform that your teams trust: designed deliberately, documented, monitored and recoverable - and a clear plan for how the development teams get on board. For the developers and DevOps engineers who will use the platform, see the course Secrets Management with OpenBao.
The actual course content may differ from the above depending on the trainer, delivery, duration and the composition of participants.
Request this course in-house
Request a public date
No suitable public date? Register without obligation — once there is enough interest we schedule a new public date and let you know first.
More about running OpenBao
OpenBao is the open-source fork of HashiCorp Vault under the Mozilla Public License 2.0. It runs as a single binary with integrated Raft storage or on PostgreSQL, scales from a single node to a highly available cluster and supports namespaces for multi-tenancy - without an enterprise licence. For companies that want enterprise support, Adfinis offers Secretz Enterprise, a subscription for OpenBao.Further Resources:
History and Development
OpenBao emerged in 2023 as a response to HashiCorp's decision to place Vault under the Business Source License (BSL). The Linux Foundation initiated the project to ensure a fully open-source alternative controlled by the community.
Since then OpenBao has developed its own features for operators, such as namespaces in the open-source version and a highly available PostgreSQL storage backend. It stays API-compatible with Vault, so existing clients, tools and integrations keep working after a migration.


