From e6687be6e56228732ecb887d2e8769d72ae01f52 Mon Sep 17 00:00:00 2001 From: "push-app-to-main[bot]" <203845782+push-app-to-main[bot]@users.noreply.github.com> Date: Sun, 30 Aug 2026 20:53:12 +0200 Subject: [PATCH] OpenBao (#16872) --- ct/headers/openbao | 6 ++++ ct/openbao.sh | 68 ++++++++++++++++++++++++++++++++++++++ install/openbao-install.sh | 67 +++++++++++++++++++++++++++++++++++++ 3 files changed, 141 insertions(+) create mode 100644 ct/headers/openbao create mode 100755 ct/openbao.sh create mode 100755 install/openbao-install.sh diff --git a/ct/headers/openbao b/ct/headers/openbao new file mode 100644 index 000000000..adedc8590 --- /dev/null +++ b/ct/headers/openbao @@ -0,0 +1,6 @@ + ____ ____ + / __ \____ ___ ____ / __ )____ _____ + / / / / __ \/ _ \/ __ \/ __ / __ `/ __ \ +/ /_/ / /_/ / __/ / / / /_/ / /_/ / /_/ / +\____/ .___/\___/_/ /_/_____/\__,_/\____/ + /_/ diff --git a/ct/openbao.sh b/ct/openbao.sh new file mode 100755 index 000000000..552d11e7b --- /dev/null +++ b/ct/openbao.sh @@ -0,0 +1,68 @@ +#!/usr/bin/env bash +_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main" +_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func" +source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func") +# Copyright (c) 2021-2026 community-scripts ORG +# Author: Marc Went (Dunky13) +# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE +# Source: https://openbao.org/ + +APP="OpenBao" +var_tags="${var_tags:-security;secrets}" +var_cpu="${var_cpu:-1}" +var_ram="${var_ram:-1024}" +var_disk="${var_disk:-4}" +var_os="${var_os:-debian}" +var_version="${var_version:-13}" +var_arm64="${var_arm64:-yes}" +var_unprivileged="${var_unprivileged:-1}" + +header_info "$APP" +variables +color +catch_errors + +function update_script() { + header_info + check_container_storage + check_container_resources + + if [[ ! -f /usr/bin/bao ]]; then + msg_error "No ${APP} Installation Found!" + exit + fi + + if check_for_gh_release "openbao" "openbao/openbao"; then + msg_info "Stopping Service" + systemctl stop openbao + msg_ok "Stopped Service" + + create_backup /etc/openbao + DPKG_FORCE_CONFOLD=1 fetch_and_deploy_gh_release "openbao" "openbao/openbao" "binary" "latest" "/opt/openbao" "openbao_*_linux_$(arch_resolve).deb" + restore_backup + + msg_info "Starting Service" + $STD systemctl daemon-reload + systemctl start openbao + msg_ok "Started Service" + for _ in {1..15}; do + BAO_ADDR=https://127.0.0.1:8200 BAO_SKIP_VERIFY=true bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null && break + sleep 2 + done + if ! BAO_ADDR=https://127.0.0.1:8200 BAO_SKIP_VERIFY=true bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null; then + msg_error "OpenBao did not unseal within 30 seconds" + exit 1 + fi + msg_ok "Updated successfully!" + fi + exit +} + +start +build_container +description + +msg_ok "Completed Successfully!\n" +echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}" +echo -e "${INFO}${YW} Access it using the following URL:${CL}" +echo -e "${TAB}${GATEWAY}${BGN}https://${IP}:8200${CL}" diff --git a/install/openbao-install.sh b/install/openbao-install.sh new file mode 100755 index 000000000..38b80f4f8 --- /dev/null +++ b/install/openbao-install.sh @@ -0,0 +1,67 @@ +#!/usr/bin/env bash +# Copyright (c) 2021-2026 community-scripts ORG +# Author: Marc Went (Dunky13) +# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE +# Source: https://openbao.org/ + +source /dev/stdin <<<"$FUNCTIONS_FILE_PATH" +color +verb_ip6 +catch_errors +setting_up_container +network_check +update_os + +fetch_and_deploy_gh_release "openbao" "openbao/openbao" "binary" "latest" "/opt/openbao" "openbao_*_linux_$(arch_resolve).deb" + +msg_info "Configuring CLI Environment" +cat </etc/profile.d/openbao.sh +export BAO_ADDR=https://127.0.0.1:8200 +export BAO_SKIP_VERIFY=true +EOF +source /etc/profile.d/openbao.sh +msg_ok "Configured CLI Environment" + +msg_info "Starting OpenBao" +systemctl enable -q --now openbao +for _ in {1..30}; do + curl -fsSk -o /dev/null "https://127.0.0.1:8200/v1/sys/seal-status" && break + sleep 2 +done +msg_ok "Started OpenBao" + +msg_info "Initializing OpenBao" +( + umask 077 + cat <<'EOF' >/etc/openbao/openbao-init.json +EOF +) +bao operator init -key-shares=1 -key-threshold=1 -format=json >/etc/openbao/openbao-init.json +chmod 600 /etc/openbao/openbao.env +chown root:root /etc/openbao/openbao.env +cat <>/etc/openbao/openbao.env +BAO_ADDR=https://127.0.0.1:8200 +BAO_SKIP_VERIFY=true +BAO_UNSEAL_KEY=$(jq -r '.unseal_keys_b64[0]' /etc/openbao/openbao-init.json) +BAO_ROOT_TOKEN=$(jq -r '.root_token' /etc/openbao/openbao-init.json) +EOF +rm -f /etc/openbao/openbao-init.json +msg_ok "Initialized OpenBao" + +msg_info "Enabling Auto-Unseal" +mkdir -p /etc/systemd/system/openbao.service.d +cat <<'EOF' >/etc/systemd/system/openbao.service.d/unseal.conf +[Service] +ExecStartPost=-/usr/bin/bao operator unseal ${BAO_UNSEAL_KEY} +EOF +systemctl daemon-reload +systemctl restart openbao +for _ in {1..15}; do + bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null && break + sleep 2 +done +msg_ok "Enabled Auto-Unseal" + +motd_ssh +customize +cleanup_lxc