Home / Docs / DCA Hardened Secrets Manager — for OpenBao™ / Security
| Port | Purpose | State |
|---|---|---|
| 22 | SSH — key-only, OS Login (IAM); the deployment package adds no SSH rule | your VPC's firewall rules |
| 8200 | OpenBao API + UI, TLS (per-VM certificate) — bound to 127.0.0.1 | customer-must-open (config + firewall toggle) |
| 8201 | Cluster port — 127.0.0.1 (single node) | loopback only |
"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.
| We maintain | The hardened image: package selection, hardening baseline, CVE rebuilds, listing freshness, and these docs. |
|---|---|
| You control | The running instance: OS patching between image versions, network exposure, IAM, data, and backups. |
| Your cloud provides | Physical/hypervisor security, marketplace billing, and the firewall primitives this design relies on. |
OpenBao™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the OpenBao project.