add openbao deployment

This commit is contained in:
2026-09-18 19:50:46 +02:00
parent 0defdf343e
commit 1c2ba585dc
6 changed files with 189 additions and 0 deletions
+6
View File
@@ -0,0 +1,6 @@
dependencies:
- name: openbao
repository: https://openbao.github.io/openbao-helm
version: 0.29.5
digest: sha256:010799b5366eec27e8e4d717e352e443850ac3a2e2bff05f13c6aefbd560a550
generated: "2026-09-18T19:41:59.078705685+02:00"
+25
View File
@@ -0,0 +1,25 @@
apiVersion: v2
name: openbao-gitops
description: >
Deploys OpenBao (standalone, file storage) as the cluster's secret
management backend, plus the Kubernetes RBAC/CRDs needed to bind the
External Secrets Operator (ESO) to it via the Vault-compatible Kubernetes
auth method.
type: application
version: 0.1.0
appVersion: "2.6.2"
home: https://git.smokyzone.de/SmokyZone/openbao-gitops
sources:
- https://git.smokyzone.de/SmokyZone/openbao-gitops
- https://github.com/openbao/openbao-helm
keywords:
- openbao
- vault
- secrets-management
- external-secrets
maintainers:
- name: SmokyZone
dependencies:
- name: openbao
version: "0.29.5"
repository: https://openbao.github.io/openbao-helm
Binary file not shown.
+70
View File
@@ -0,0 +1,70 @@
{{- if .Values.bootstrap.enabled }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: openbao-bootstrap
namespace: {{ .Release.Namespace }}
annotations:
"helm.sh/hook": post-install,post-upgrade
"helm.sh/hook-weight": "1"
"helm.sh/hook-delete-policy": before-hook-creation
---
apiVersion: batch/v1
kind: Job
metadata:
name: openbao-bootstrap
namespace: {{ .Release.Namespace }}
annotations:
"helm.sh/hook": post-install,post-upgrade
"helm.sh/hook-weight": "2"
"helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded
spec:
backoffLimit: 3
template:
spec:
serviceAccountName: openbao-bootstrap
restartPolicy: Never
containers:
- name: bootstrap
image: {{ .Values.bootstrap.image }}
env:
- name: BAO_ADDR
value: "http://{{ .Release.Name }}-openbao:8200"
- name: BAO_TOKEN
valueFrom:
secretKeyRef:
name: {{ .Values.bootstrap.rootTokenSecretName }}
key: {{ .Values.bootstrap.rootTokenSecretKey }}
command:
- sh
- -ec
- |
echo "Enabling kv-v2 secrets engine at {{ .Values.eso.kvMountPath }} (if not already enabled)..."
bao secrets enable -path={{ .Values.eso.kvMountPath }} kv-v2 || true
echo "Enabling kubernetes auth method (if not already enabled)..."
bao auth enable kubernetes || true
echo "Configuring kubernetes auth method against the in-cluster API..."
bao write auth/kubernetes/config \
kubernetes_host="https://kubernetes.default.svc:443"
echo "Writing eso-read policy..."
cat <<EOF | bao policy write eso-read -
path "{{ .Values.eso.kvMountPath }}/data/*" {
capabilities = ["read"]
}
path "{{ .Values.eso.kvMountPath }}/metadata/*" {
capabilities = ["list", "read"]
}
EOF
echo "Binding role '{{ .Values.eso.roleName }}' to ServiceAccount {{ .Values.eso.namespace }}/{{ .Values.eso.serviceAccountName }}..."
bao write auth/kubernetes/role/{{ .Values.eso.roleName }} \
bound_service_account_names={{ .Values.eso.serviceAccountName }} \
bound_service_account_namespaces={{ .Values.eso.namespace }} \
policies=eso-read \
ttl=1h
echo "Bootstrap complete."
{{- end }}
+20
View File
@@ -0,0 +1,20 @@
apiVersion: external-secrets.io/v1
kind: ClusterSecretStore
metadata:
name: openbao
annotations:
# Give ESO + OpenBao time to become healthy before ArgoCD tries to sync this.
argocd.argoproj.io/sync-wave: "1"
spec:
provider:
vault:
server: "http://{{ .Release.Name }}-openbao.{{ .Release.Namespace }}.svc:8200"
path: {{ .Values.eso.kvMountPath }}
version: v2
auth:
kubernetes:
mountPath: kubernetes
role: {{ .Values.eso.roleName }}
serviceAccountRef:
name: {{ .Values.eso.serviceAccountName }}
namespace: {{ .Values.eso.namespace }}
+68
View File
@@ -0,0 +1,68 @@
## Values for openbao-gitops.
##
## `openbao:` maps directly onto the upstream openbao-helm chart values
## (https://github.com/openbao/openbao-helm). Only the settings relevant for
## a standalone/file-storage deployment with ESO integration are overridden
## here - see `helm show values openbao/openbao` for the full list.
openbao:
server:
# Standalone mode: single replica, file storage backend, PVC-backed.
standalone:
enabled: true
dataStorage:
enabled: true
size: 10Gi
# Empty = cluster default StorageClass.
storageClass: ""
# Required so OpenBao's ServiceAccount can call the Kubernetes
# TokenReview API - needed for the "kubernetes" auth method used by ESO.
serviceAccount:
create: true
authDelegator:
enabled: true
resources:
requests:
cpu: 250m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
ui:
enabled: true
serviceType: ClusterIP
injector:
# Sidecar-injector webhook is not needed for ESO integration.
enabled: false
# --- ESO <-> OpenBao binding -------------------------------------------------
eso:
# Namespace and ServiceAccount name that the External Secrets Operator
# (its `SecretStore`/`ClusterSecretStore`) authenticates with. Must match
# the ESO Helm release deployed via apps-in-apps.
serviceAccountName: external-secrets
namespace: external-secrets
# Name of the Vault/OpenBao Kubernetes auth role that ESO will use.
roleName: eso-role
# KV v2 mount path that ClusterSecretStore(s) will read from.
kvMountPath: secret
# One-time bootstrap Job that enables the Kubernetes auth method, creates the
# "eso-read" policy and the "eso-role" role bound to the ESO ServiceAccount.
#
# OpenBao must already be initialized AND unsealed before this can run (see
# README). Enable this only after that manual step, providing the root token
# via the referenced secret.
bootstrap:
enabled: false
image: openbao/openbao:2.6.2
rootTokenSecretName: openbao-root-token
rootTokenSecretKey: token