Pin openbao secrets plugins to exact versions #492
Reference in New Issue
Block a user
Delete Branch "benvin/pin-openbao-plugin-versions"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
ensure: present/latestlets the plugin binaries drift from the sha256 pinned in the terraform-vault catalog (config/plugins/*.yaml). On the next OpenBao restart, a drifted binary fails the sha check and the plugin won't launch — a latent footgun (hit exactly this with rancher onensure: latest).Changes
Pin each secrets plugin to the version whose binary matches its registered catalog sha (all verified against the RPMs in rpm-internal):
openbao-plugin-secrets-litellm: 0.1.1 (sha 2263ebcb…)openbao-plugin-secrets-gpg: 0.1.0 (sha 0e92d740…)openbao-plugin-secrets-rancher: 0.1.1 (sha 9e597cd9…; wasensure: latest)All three are no-op on the binary (installed versions already match) — this just locks them so a future release can't silently upgrade the binary out of lockstep with the catalog.
openbao-plugins(base bundle) left unpinned — its version couldn't be verified from the tooling side and it tracks the openbao package, not a catalog sha.Note
To upgrade a plugin in future: bump the RPM version here and the catalog sha256 in terraform-vault in the same change, then
vault write sys/plugins/reload/backend plugin=<name>.