A CNCF blog post provides a guide to running OpenBao, an open-source fork of HashiCorp Vault, on Kubernetes with CloudNativePG, a PostgreSQL operator for Kubernetes.

In the recipe, OpenBao uses the PostgreSQL storage of a three-instance CloudNativePG cluster. The recipe configures TLS client certificates instead of passwords for the schema owner and OpenBao’s runtime user.

Claim check:

  • A CNCF blog post provides a guide to running OpenBao on Kubernetes with CloudNativePG. (confirmed by the publication itself: evidence; «Running OpenBao on Kubernetes with a CloudNativePG PostgreSQL backend»)
  • In the recipe, OpenBao uses the PostgreSQL storage of a three-instance CloudNativePG cluster. (confirmed by the publication itself: evidence; «This recipe deploys a three-instance CNPG cluster as OpenBao’s storage backend»)
  • The recipe configures TLS client certificates instead of passwords for the schema owner and OpenBao’s runtime user. (confirmed by the publication itself: evidence; «both authenticate with a DatabaseRole-issued TLS client certificate»)

Primary sources:

score 64.9 out of 100 · kind: guide