vault: move openbao plugin sockets off /tmp onto /run #509

Merged
benvin merged 1 commits from benvin/vault-plugin-tmpdir into develop 2026-08-09 12:14:03 +10:00

1 Commits

Author SHA1 Message Date
unkinben 26c5235d00 vault: move openbao plugin sockets off /tmp onto a /run RuntimeDirectory
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
go-plugin creates each secrets plugin's control socket under the process
TMPDIR (/tmp/pluginNNN by default). The daily systemd-tmpfiles-clean
deletes aged /tmp files, severing the socket of a long-lived plugin while
its process keeps running, so every request fails with rpc Unavailable /
dial unix /tmp/pluginNNN: no such file until a reload respawns it. This
took out the litellm engine (terraform-vault#112); the risk is shared by
every OpenBao plugin (gpg, rancher, gitea, ...).

Add a vault.service drop-in setting TMPDIR to a per-start RuntimeDirectory
on /run (tmpfs, no age-based cleanup), so plugin sockets can never be
reaped. The drop-in notifies a vault restart so the new TMPDIR takes
effect and plugins respawn with sockets under /run.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-06 22:41:46 +10:00