| Type | Hardened VM image |
|---|---|
| Upstream / license | OpenBao (MPL-2.0) — see licenses |
| Version | OpenBao 2.7.1 (upstream linux_amd64 release binary; GPG-signed checksums verified) with integrated raft storage, Ubuntu 24.04 LTS; Google Cloud image built 2026-10-07. Exact image version: see the listing. Current builds: release notes. |
| Architecture | x86-64 |
| Sizing | Any current-generation instance with ≥ 4 vCPU (pay-as-you-go floor); 8 vCPU recommended for production. |
| Port | Purpose | State |
|---|---|---|
| 22 | SSH — key-only, OS Login (IAM); the deployment package adds no SSH rule | your VPC's firewall rules |
| 8200 | OpenBao API + UI, TLS (per-VM certificate) — bound to 127.0.0.1 | customer-must-open (config + firewall toggle) |
| 8201 | Cluster port — 127.0.0.1 (single node) | loopback only |
"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.
No shared or default credentials are included in this image. Access uses the SSH key you supply at launch; any application credential is generated uniquely on your instance at first boot and stored only there — we never know it.
Log in: SSH in with OS Login; the bao CLI is pre-configured for login shells (BAO_ADDR, BAO_CACERT). Authenticate with the root token from /root/openbao-init.json for first setup.
On THIS VM's first boot OpenBao is initialized with 5 Shamir unseal key shares (3 needed) and a root token, written to /root/openbao-init.json (root-only, 0600); the listener's TLS key and certificate are minted on the VM too. Nothing secret exists in the image.
sudo python3 -c 'import json; print(json.load(open("/root/openbao-init.json"))["root_token"])'Rotation: Move /root/openbao-init.json to a secure store, hand the unseal keys to separate people, create named admin identities and policies, then revoke the root token (bao token revoke). bao operator rekey replaces the unseal keys.
Step-by-step: first login / credentials.
bao status → Initialized true, Sealed falseSingle node (integrated raft, one voter). Shamir seal: sealed after every restart until unsealed, unless you configure Cloud KMS auto-unseal. No audit device is enabled by default.
Email support@dcassociatesgroup.com — first response within 1 business day (US Eastern), most tickets same-day. To escalate an open ticket, reply "ESCALATE"; it is reviewed by the founder within 1 business day. Security reports: vulnerability disclosure.
Privacy: policy · Terms: terms · Security practices: security & trust · Vulnerability reports: disclosure policy
OpenBao™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the OpenBao project.