Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / DCA Hardened Secrets Manager — for OpenBao™ / Troubleshooting

Troubleshoot DCA Hardened Secrets Manager — for OpenBao™

SymptomCheckFix
Requests fail because OpenBao is sealed (HTTP 503) after a restart or rebootbao status → Sealed trueExpected with a Shamir seal: sudo openbao-unseal, or bao operator unseal with three keys. For unattended restarts, set up Cloud KMS auto-unseal.
bao status: connection refused or certificate errorsecho $BAO_ADDR $BAO_CACERTNon-login shells skip /etc/profile.d: run source /etc/profile.d/openbao.sh (BAO_ADDR=https://127.0.0.1:8200, BAO_CACERT=/etc/openbao/tls/tls.crt).
openbao-unseal: cannot read /root/openbao-init.jsonHas the init file been moved off the VM?Pass its path (sudo openbao-unseal /path/to/init.json) or unseal with bao operator unseal and three keys from your store.
openbao.service won't startjournalctl -u openbao -n 50Check the openbao.hcl syntax and that /etc/openbao/tls/tls.crt and tls.key exist and are readable by the openbao group.

Logs & useful commands

Still stuck? Email support@dcassociatesgroup.com with the product name, cloud + region, instance size, and the output of the health command — first response within 1 business day, most tickets same-day.

OpenBao™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the OpenBao project.