AppRole is an authentication method in OpenBao designed for non‑interactive systems, such as automation tools, CI/CD pipelines, batch jobs, and backend services. It provides a secure way for applications to obtain a token without requiring human interaction or a browser‑based login.
AppRole is commonly used when workloads cannot use OIDC or Kubernetes authentication.
How AppRole Works
AppRole authentication is based on two components:
RoleID – identifies the role
SecretID – acts as a credential for the role
An application presents both values to OpenBao to obtain a token:
Codice
bao auth approle login role_id=<role-id> secret_id=<secret-id>
The returned token carries the policies assigned to the AppRole.
When to Use AppRole
AppRole is suitable for:
CI/CD pipelines (GitLab Runner, GitHub Actions, Argo Workflows)
Automation scripts
Services running outside Kubernetes
Systems without OIDC or Kubernetes identity
Environments where browser‑based login is not possible
Creating an AppRole
AppRoles are created inside the tenancy namespace. The process consists of defining the role, assigning policies, and generating a SecretID.
1. Create the AppRole
Define the role and attach one or more policies:
bao auth approle role write my-role \
policies="my-policy"
You can attach multiple policies:
policies="policy-a,policy-b"
More details on creating policies: EWC Secret Manager - Policies
2. Retrieve the RoleID
bao auth approle role-id read my-role
Output example:
role_id = "12345678-aaaa-bbbb-cccc-999999999999"
3. Generate a SecretID
bao auth approle secret-id generate my-role
Output example:
secret_id = "abcd1234-efgh5678-ijkl9012"
SecretIDs can be:
single‑use
periodically rotated
limited by TTL
bound to CIDR blocks
4. Log in using AppRole
Applications authenticate by presenting both values:
Codice
bao auth approle login \
role_id="12345678-aaaa-bbbb-cccc-999999999999" \
secret_id="abcd1234-efgh5678-ijkl9012"
The CLI or application receives a token with the policies assigned to the role.