Prerequisites
- An account on the target cloud with permission to launch VM instances (no special IAM roles are required by this product unless stated below — IAM required: none).
- An SSH key pair registered in the target cloud (all access is key-only; password SSH is disabled).
- Instance size ≥ 4 vCPU (pricing floor; 8 vCPU recommended).
- No internet access or external dependency is required at deploy time — the image is self-contained.
Google Cloud
- Deploy from the Google Cloud Marketplace listing (or its deployment package): at least 4 vCPU and 16 GB RAM (default n2-standard-8, 50 GB balanced boot disk). Leave the tcp:8200 firewall toggle off for now.
Expected result The VM DEPLOYMENT-vm is RUNNING; on it, bao status reports Initialized true, Sealed false. - Secure the init material: copy /root/openbao-init.json to your secret store, distribute the unseal keys, then remove it from the VM.
Expected result Only your key holders can unseal OpenBao after a restart. - For clients in your VPC: change the listener address in /etc/openbao/openbao.hcl, restart, unseal, then allow tcp:8200 from your client range only.
Expected result bao status from a client in that range verifies TLS against the VM's certificate.
Validate
bao status → Initialized true, Sealed false
First boot: openbao-firstboot.service mints the listener's TLS key and certificate; openbao-init-firstboot initializes OpenBao (5 key shares, threshold 3), writes /root/openbao-init.json, unseals, and proves the root token works, a bogus token is refused, the version is 2.7.1 and the listener is loopback-only, then writes /var/lib/dca-firstboot/openbao.verified. After every later restart or reboot OpenBao starts SEALED: run sudo openbao-unseal.
First login / credentials
- Connect with OS Login: gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap (reading /root/openbao-init.json needs sudo, i.e. roles/compute.osAdminLogin).
- bao status shows Initialized true and Sealed false on the first boot. After any restart or reboot it is sealed again — run sudo openbao-unseal.
- Authenticate for first setup: export BAO_TOKEN="$(sudo python3 -c 'import json; print(json.load(open("/root/openbao-init.json"))["root_token"])')". Then move the init file off the VM, set up named identities, and revoke the root token (Configuration page).
Secure it
- Restrict SSH (22) to your own IP range in the cloud firewall/security group.
- Open application ports only per the ports table — closed-by-default is deliberate.
- Volume encryption: use your cloud's native volume encryption (enabled by default on most accounts); the image adds no proprietary encryption layer.
Costs & quotas
Software is billed by the marketplace at the listed rate; infrastructure (VM, storage, egress) is billed
by your cloud at its standard rates. The recommended size fits default service quotas in most accounts —
if you scale out, review your cloud's quota console before launch.
Next: configuration · troubleshooting · security notes
OpenBao™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the OpenBao project.