| Resource | Description |
| AppRole | An AppRole is an authentication method designed for machines, automation, CI/CD pipelines, and services. It provides role‑based, credential‑driven login using:
AppRole is used when you cannot rely on human‑interactive login or cloud‑native identity. It is ideal for batch jobs, Kubernetes workloads, and automation scripts. |
| Authentication Method | An Authentication Method is how a client proves its identity to OpenBao. Examples include:
Each auth method issues a token with policies attached. Auth methods do not grant permissions by themselves — they only authenticate the client. |
| Group | A Group is a logical collection of users or entities inside OpenBao. Groups allow you to:
Groups do not store secrets; they only define who gets what policy. |
| Mount/Secret Engine | Mount / Secret EngineA Secret Engine is a pluggable backend that stores or generates secrets. Examples:
A mount is simply the path where the engine is enabled, e.g.: |
| Namespace | A Namespace is an isolated administrative boundary inside OpenBao. Think of it as a “tenant” or “sub‑cluster” within the same OpenBao instance. Namespaces allow:
Everything inside a namespace is independent from the root namespace. |
| Policy | A Policy defines what a token is allowed to do. Policies are written in HCL and specify:
Example: Policies are attached to tokens via:
Policies are the core of authorization in OpenBao. |
| Secret | A Secret is the actual data stored or generated by OpenBao. Secrets can be:
OpenBao ensures:
|