AppRole is an authentication method in OpenBao designed for non‑interactive systems, such as automation tools, CI/CD pipelines, batch jobs, and backend services. It provides a secure way for applications to obtain a token without requiring human interaction or a browser‑based login.

AppRole is commonly used when workloads cannot use OIDC or Kubernetes authentication.

How AppRole Works

AppRole authentication is based on two components:

  • RoleID – identifies the role

  • SecretID – acts as a credential for the role

An application presents both values to OpenBao to obtain a token:
Codice
 

bao auth approle login role_id=<role-id> secret_id=<secret-id>

The returned token carries the policies assigned to the AppRole.


When to Use AppRole

AppRole is suitable for:

  • CI/CD pipelines (GitLab Runner, GitHub Actions, Argo Workflows)

  • Automation scripts

  • Services running outside Kubernetes

  • Systems without OIDC or Kubernetes identity

  • Environments where browser‑based login is not possible


Creating an AppRole

AppRoles are created inside the tenancy namespace. The process consists of defining the role, assigning policies, and generating a SecretID.
 

1. Create the AppRole

Define the role and attach one or more policies: 

bao auth approle role write my-role \
  policies="my-policy"

You can attach multiple policies:

policies="policy-a,policy-b"

More details on creating policies: EWC Secret Manager - Policies
 

2. Retrieve the RoleID 

bao auth approle role-id read my-role

Output example:

role_id = "12345678-aaaa-bbbb-cccc-999999999999"

3. Generate a SecretID

bao auth approle secret-id generate my-role

Output example:

secret_id = "abcd1234-efgh5678-ijkl9012"

SecretIDs can be:

  • single‑use

  • periodically rotated

  • limited by TTL

  • bound to CIDR blocks

4. Log in using AppRole

Applications authenticate by presenting both values:
Codice
 

bao auth approle login \
  role_id="12345678-aaaa-bbbb-cccc-999999999999" \
  secret_id="abcd1234-efgh5678-ijkl9012"

The CLI or application receives a token with the policies assigned to the role.

  • No labels