Home / Docs / DCA Hardened Secrets Manager — for OpenBao™ / Troubleshooting
| Symptom | Check | Fix |
|---|---|---|
| Requests fail because OpenBao is sealed (HTTP 503) after a restart or reboot | bao status → Sealed true | Expected with a Shamir seal: sudo openbao-unseal, or bao operator unseal with three keys. For unattended restarts, set up Cloud KMS auto-unseal. |
| bao status: connection refused or certificate errors | echo $BAO_ADDR $BAO_CACERT | Non-login shells skip /etc/profile.d: run source /etc/profile.d/openbao.sh (BAO_ADDR=https://127.0.0.1:8200, BAO_CACERT=/etc/openbao/tls/tls.crt). |
| openbao-unseal: cannot read /root/openbao-init.json | Has the init file been moved off the VM? | Pass its path (sudo openbao-unseal /path/to/init.json) or unseal with bao operator unseal and three keys from your store. |
| openbao.service won't start | journalctl -u openbao -n 50 | Check the openbao.hcl syntax and that /etc/openbao/tls/tls.crt and tls.key exist and are readable by the openbao group. |
bao status → Initialized true, Sealed falseOpenBao™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the OpenBao project.