Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / DCA Hardened Secrets Manager — for OpenBao™

DCA Hardened Secrets Manager — for OpenBao™ — documentation & support card

OpenBao 2.7 initialized on each VM's first boot with its own Shamir unseal keys, root token and TLS certificate, behind a loopback TLS listener.

Install Configure Troubleshoot Security

At a glance

TypeHardened VM image
Upstream / licenseOpenBao (MPL-2.0) — see licenses
VersionOpenBao 2.7.1 (upstream linux_amd64 release binary; GPG-signed checksums verified) with integrated raft storage, Ubuntu 24.04 LTS; Google Cloud image built 2026-10-07. Exact image version: see the listing. Current builds: release notes.
Architecturex86-64
SizingAny current-generation instance with ≥ 4 vCPU (pay-as-you-go floor); 8 vCPU recommended for production.

Marketplaces

Network ports

PortPurposeState
22SSH — key-only, OS Login (IAM); the deployment package adds no SSH ruleyour VPC's firewall rules
8200OpenBao API + UI, TLS (per-VM certificate) — bound to 127.0.0.1customer-must-open (config + firewall toggle)
8201Cluster port — 127.0.0.1 (single node)loopback only

"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.

Access & credentials

No shared or default credentials are included in this image. Access uses the SSH key you supply at launch; any application credential is generated uniquely on your instance at first boot and stored only there — we never know it.

Log in: SSH in with OS Login; the bao CLI is pre-configured for login shells (BAO_ADDR, BAO_CACERT). Authenticate with the root token from /root/openbao-init.json for first setup.

On THIS VM's first boot OpenBao is initialized with 5 Shamir unseal key shares (3 needed) and a root token, written to /root/openbao-init.json (root-only, 0600); the listener's TLS key and certificate are minted on the VM too. Nothing secret exists in the image.

sudo python3 -c 'import json; print(json.load(open("/root/openbao-init.json"))["root_token"])'

Rotation: Move /root/openbao-init.json to a secure store, hand the unseal keys to separate people, create named admin identities and policies, then revoke the root token (bao token revoke). bao operator rekey replaces the unseal keys.

Step-by-step: first login / credentials.

Data & dependencies

Operate

Known limitations

Single node (integrated raft, one voter). Shamir seal: sealed after every restart until unsealed, unless you configure Cloud KMS auto-unseal. No audit device is enabled by default.

Support

Email support@dcassociatesgroup.com — first response within 1 business day (US Eastern), most tickets same-day. To escalate an open ticket, reply "ESCALATE"; it is reviewed by the founder within 1 business day. Security reports: vulnerability disclosure.

Privacy: policy · Terms: terms · Security practices: security & trust · Vulnerability reports: disclosure policy

OpenBao™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the OpenBao project.