Resource

Description

AppRole

An AppRole is an authentication method designed for machines, automation, CI/CD pipelines, and services. It provides role‑based, credential‑driven login using:

  • a RoleID (public identifier)

  • a SecretID (private credential)

AppRole is used when you cannot rely on human‑interactive login or cloud‑native identity. It is ideal for batch jobs, Kubernetes workloads, and automation scripts.

Authentication Method

An Authentication Method is how a client proves its identity to OpenBao. Examples include:

  • AppRole

  • OIDC

Each auth method issues a token with policies attached. Auth methods do not grant permissions by themselves — they only authenticate the client.

Group

A Group is a logical collection of users or entities inside OpenBao. Groups allow you to:

  • assign policies to many users at once

  • map external identities (LDAP, OIDC, GitHub) to OpenBao permissions

  • manage RBAC more cleanly

Groups do not store secrets; they only define who gets what policy.

Mount/Secret Engine

Mount / Secret Engine

A Secret Engine is a pluggable backend that stores or generates secrets. Examples:

  • KV (static secrets)

  • external-secret-operation

A mount is simply the path where the engine is enabled, e.g.:

Namespace

A Namespace is an isolated administrative boundary inside OpenBao. Think of it as a “tenant” or “sub‑cluster” within the same OpenBao instance.

Namespaces allow:

  • separate teams or projects

  • isolated auth methods

  • isolated secret engines

  • isolated policies

  • delegated administration

Everything inside a namespace is independent from the root namespace.

Policy

A Policy defines what a token is allowed to do. Policies are written in HCL and specify:

  • allowed paths

  • allowed operations (read, list, update, delete)

  • constraints (TTL, max TTL, etc.)

Example:
Codice
 

path "kv/data/app/*" {
  capabilities = ["read", "list"]
}

Policies are attached to tokens via:

  • auth methods

  • groups

  • direct assignment

Policies are the core of authorization in OpenBao.

Secret

A Secret is the actual data stored or generated by OpenBao. Secrets can be:

  • static (KV)

  • dynamic (database credentials, cloud IAM keys)

  • ephemeral (PKI certificates, short‑lived tokens)

  • cryptographic (transit encryption keys)

OpenBao ensures:

  • encryption at rest

  • encryption in transit

  • access control via policies

  • audit logging

  • automatic rotation (for dynamic secrets)

  • No labels