OpenBao – FOSS Fork of HashiCorp Vault
github.com
github.com
HashiCorp Vault forked into OpenBAO - https://news.ycombinator.com/item?id=38578247 - Dec 2023 (70 comments)
If you want to help out, you can :
Join Matrix rooms:
- https://chat.lfx.linuxfoundation.org/#/room/#openbao-announc...
- https://chat.lfx.linuxfoundation.org/#/room/#openbao-develop...
- https://chat.lfx.linuxfoundation.org/#/room/#openbao-general...
- https://chat.lfx.linuxfoundation.org/#/room/#openbao-questio...
- https://chat.lfx.linuxfoundation.org/#/room/#openbao-random:...
Join the mailing list: https://lists.lfedge.org/g/openbao
https://cpl.thalesgroup.com/sites/default/files/content/inte...
I'd bet OpenBao gets native HSM support. The problem will be doing it in a clean room setting to avoid any legal issues.
Having operated a large Vault (FOSS, not commercial) installation, "overengineered" is not the word I'd use.
When I told them how ridiculously expensive it was for our use-case they suddenly managed to find a ~50% discount for us. That brought it down to just laughably expensive. Needless to say, we stuck with DIY.
To replace SSH Sign and Cert Authority or databases engines, both generating short-lived credentials on-demand, SOPS will not easily solve the issue.
If you only need KV Store, SOPS experience is way better than Vault and maintenance cost is low.
I readily admit it's not the same amount of :fu: as BuSL or whatever the fuck is going on over at Sentry but still :-( as compared to their much friendlier Apache 2
Disclaimer: I'm one of the founders
Looks well polished at first glance.
It’s simple, has real client-side end-to-end encryption with no backdoors or compromises, is open source, and gives you a bunch of ways to manage and de-duplicate config.
Comparison with Vault: https://www.envkey.com/compare/hashicorp-vault/
It also doesn’t have private CA or cert generation features, so if you need that then perhaps Vault or OpenBao would be a better fit. Though if you wanted to use EnvKey for simplicity and security reasons, you could potentially do your cert generation with openssl or another tool and then store the certs in EnvKey.
The featureset isn’t 1-to-1. EnvKey is more focused on config management and ease-of-use and not so much on slotting into more complex custom infra that needs eg a private CA. Though like I said it is quite flexible so you could make it fit into just about any system if you’re willing to do a bit of scripting.
The point of the comparison is not to have an itemized list of every feature, but to compare the most important features and tradeoffs at a high level. It includes the disclaimer that Vault could be better for some more complex use cases (as I have also done here in my reply to you).
A fair comparison would point out that EnvKey only does a small but important part of what Vault does, and explain why it does it well. Somebody who didn't know either piece of software, might read your comparison and get the false impression that they had equivalent functionality.
I don't expect you to agree, because that would mean you had to change the page to one which maybe doesn't convert so well.
Vault has some long tail infra/enterprise features that EnvKey lacks and perhaps those are relevant to you, but a lot of them aren’t really secrets management per se, and for the core objective of managing secrets and config, EnvKey has a lot in terms of de-duplication, automation, and UI/UX/DX that Vault lacks. But for sure it depends on your use case.
Of course we are going to be somewhat biased, but everything in the quick compare section is backed up below. On security, EnvKey has end-to-end encryption; Vault doesn’t and requires trusting the host server. EnvKey is clearly easier to set up and use. EnvKey has an MIT license. EnvKey fits into a local development workflow and keeps config in sync much more effectively.
For sure you could write something that gives more attention to Vault’s specific strengths, but I stand by the comparison as broadly accurate.
Never entrust consistent state to things based on arguments and opinions.
My company has started using Vault a few months ago - seems pretty easy for me (store secret in vault, get it during gitlab's pipeline pass it as a kuber secret)
Me the other hand, I can assure you... I am not reliable. /jk
Funny how that sentence is one of the quickest ways to make me mistrust something (even if possibly undeserved).
This is concerning. To me it looks like there is a holy war going on with devs who maintain a secrets manager. The last thing I want is instability with the tool that holds my passwords and credentials. On the low end of my concern is the annoyance of constantly updating names in yaml files, and on the high end is worry that a rogue dev could deliberately add in a security hole that would compromise my secrets.
Is there any assurance this won't happen?
This isn’t a workable or sustainable model. The companies leveraging free software don’t have to work nearly as hard on software which means they can focus 100% on ops and marketing. And of course they don’t give anything back to the software creators.
This is literally what they did when they released their product code under an OSS license. It was their free choice.
> This isn’t a workable or sustainable model. The companies leveraging free software don’t have to work nearly as hard on software which means they can focus 100% on ops and marketing. And of course they don’t give anything back to the software creators
The other companies might not need to work so hard, but they also have little to no control.
If you can't build a sustainable business on a piece of software when you are the steward of that software, control the product direction and backlog etc., then you're not very good at the business.
Or, put another way, if your business success hinges on people not competing when they have access to (and license to use) your source code, when releasing it under an OSS license demonstrates that you're not very good at the business.
The elephant in the room here is that software is incredibly expensive. Developing and maintaining a large project requires a large team of high salary software devs.
I’d estimate the cost of building, supporting, and maintaining Vault at $3-4M a year bare minimum for the core team and related overhead. It also takes a ton of energy and focus all the way to the top of the organization.
The company building and maintaining the software must spend that. Someone just using the software to resell in the cloud or rebranding it can instead put all that money and mental energy into marketing and ops.
The company that does not have to maintain the software has a massive advantage. They’re freed from that burden.
There's plenty of expensive, major open source projects that seem to have figured this out. The fact that Hashicop can't doesn't mean the model is broken, it just means Hashicorp aren't very good at this.
> Someone just using the software to resell in the cloud or rebranding it can instead put all that money and mental energy into marketing and ops.
It's not that simple. Once again, the "reseller" doesn't have control over the direction of their business. Which means they should always fail, long term, relative to the org that actually spends the money on controlling the development.
If you can't compete and outmanoeuvre someone who's simply slapping a label on your software, you probably shouldn't release your software under an OSS license.
> The company that does not have to maintain the software has a massive advantage. They’re freed from that burden.
I think it's pretty clear that we both take very different views on what maintaining and developing software means. You see it as a massive burden, I see it as an enormous advantage / opportunity.
Like? Red Hat are the only one, and they sell very special software. I can't think of any other ones that are successful as a fully open source project that also has a sustainable profitable business build on top of it.
> On the low end of my concern is the annoyance of constantly updating names in yaml files, and on the high end is worry that a rogue dev could deliberately add in a security hole that would compromise my secrets.
> Is there any assurance this won't happen?
This isn’t really a reasonable request. You can do any of this yourself as well, so your assurances are your own. If you want someone else to own those assurances you need to pay up.
Sure it is. This is what third party security audits exist for. For example: https://www.hashicorp.com/solutions/auditing-and-compliance
This isn't unique to Hashicorp. Any organization which claims to offer secure protection should be willing to share this kind of information.
https://docs.securedrop.org/en/stable/what_is_securedrop.htm...
https://threatpost.com/openssl-security-audit-ready-to-start...
The point here is not "we pay more money and get better security." That's the kind of garbage logic the SSL CA cabal used for decades to maintain a monopoly before LetsEncrypt showed up. The question is, what is an indication that, although there is clearly some drama, that I can trust the software with my secrets? Did some of the people come to this new project from the Hashicorp security team? Could it be that the majority of changes in codebase are on the UX/UI, and not the security protocol implementation? There are plenty of ways to publish trust validation without demanding that a potential user spend hours poring through code looking for exploits.
I'm not sure I understand your concerns in the previous comment. What would cause you to constantly update your YAML, and why are you just now worried about a rogue dev? Also, who doesn't trust whom?
I see three primary differences between HashiCorp Vault and OpenBao:
1. License: BSL vs. MPLv2.
2. Development model: cathedral vs. bazaar.
3. Maturity: production vs. barely started.
It sounds to me like you don't care about the license, trust cathedral more than bazaar, and value the maturity of the incumbent Vault project. If you're currently a Vault user, I would stay the course for now.
I don't think there's any particular mistrust of HashiCorp in the sense that they will compromise your security, either deliberately or incompetently. However, there is an awareness that their interests aren't necessarily aligned with their customers'.
You might wanna change Vault to OpenBao
But then, if you made not an OS but rather say, a search engine called “pane.io” and used a logo of a 4 pane window of different colors ?
I am open to being wrong here but I doubt it would have gone smoothly.
But how much variance can you reasonably expect from a logo based on an anthropomorphized bao bun?
I think the inside of the bao is the secret, and the bao is the vault.
Agreed. Try this: do an image search for cute cartoon bao bun
https://duckduckgo.com/?q=cute+cartoon+bao+bun&iar=images&ia...
There are, completely as expected, a bunch of different pictures that fundamentally look very similar.
Not much. But taking a similar logo from a current hot / hyped tech in a similar vertical just strike me as poor taste.
I have no idea why you would say this. Genuinely confused.
Check out Infisical for secret management: https://github.com/Infisical/infisical
Disclaimer: I'm one of the maintainers.
It’s has client-side end-to-end encryption with no backdoors or compromises, is open source, and, apart from secrets management, provides a robust set of tools to manage and de-duplicate config.
Comparison with Vault: https://www.envkey.com/compare/hashicorp-vault/