移行

HashiCorp Vault から OpenBao への移行

ライセンスと利用条件

HashiCorp Vault
Other, ソースアベイラブル
OpenBao
MPL-2.0, オープンソース
置き換えの度合い
ドロップイン Fork of Vault 1.14 under MPL-2.0, same API.

このページは英語で書かれています。

Compatibility

OpenBao’s guide describes an in-place swap: the OpenBao server replaces the Vault process on every node, and endpoints and URLs stay the same. The API aims to be compatible enough that existing clients do not notice, although some may need a restart. The server configuration is largely compatible.

Before you switch

The guide was tested with Vault Community Edition 1.14.1 on Raft storage with Shamir unseal, moving to OpenBao 2.2.0.

  1. Take a backup: a Raft snapshot, or an atomic filesystem snapshot.
  2. List what you have mounted with vault secrets list and vault auth list.
  3. Install and configure OpenBao on each node without starting it. A separate storage path is recommended, since nodes pull their data from the cluster when they join, and it makes a rollback easier.
  4. Remove disable_mlock from the configuration: OpenBao has not used mlock since 2.0.0.
  5. Replace the followers one at a time. Stop Vault, start OpenBao, join the node with bao operator raft join, unseal it, and wait until it is a voter.
  6. Make the leader step down, check that a new leader was elected, then replace the former leader the same way.

Pitfalls

公式ガイド

OpenBaoの移行ガイド ↗

2026-09-24にレビュー済み。

出典

HashiCorp Vaultのその他の代替 →