OpenBao

Linux Foundation fork of Vault's last MPL-licensed release. Manages secrets, certificates, and encryption keys with dynamic credential generation and fine-grained access policies.

Identity & Access ManagementOpen sourceSelf-hosted
Visit official website

Published Updated

CategoryIdentity & Access Management
AccessSelf-hosted
PricingOpen source
APIAvailable
Overview

What is OpenBao?

OpenBao was created in 2024 after HashiCorp relicensed Vault to BSL, breaking open-source compatibility. Hosted under the Linux Foundation's OpenSSF umbrella, it preserves the MPL 2.0 license and adds active community governance with co-maintainers from Adfinis, ControlPlane, GitLab, IOTech, SAP, and WALLIX.

Read the full overview

The project reached a critical adoption inflection in 2026: NVIDIA and GitLab publicly endorsed it, GitLab 19.0 ships OpenBao as its native secrets engine, and Broadcom integrated it into vSphere Supervisor as part of VMware Cloud Foundation 9.0. Percona Server for MongoDB and EdgeX Foundry 4.0 also switched their default secret store to OpenBao.

Why teams use it

Key capabilities

  • Dynamic secrets - short-lived credentials generated on demand for databases, cloud providers, SSH, and PKI.
  • KV store - versioned key-value secret storage with access control at path level.
  • Encryption as a service - transit engine for data encryption without exposing keys.
  • Auth methods - Kubernetes, OIDC, LDAP, AWS, GitHub, and more.
  • Audit logging - tamper-evident log of every secret access and operation.
Core areas
  • Secrets management - central, audited store for credentials, API keys, and tokens across teams and services.
  • PKI and certificate automation - internal CA with automated certificate issuance and renewal.
  • Database credential rotation - dynamic, time-limited database logins without hardcoded passwords.
  • Zero-trust infrastructure - fine-grained identity-based access for services, not just humans.
Positioning

OpenBao is the drop-in open-source replacement for HashiCorp Vault for teams unwilling to accept BSL restrictions on internal tools or SaaS products. The API is wire-compatible with Vault, so migration requires minimal code changes. Choose OpenBao when you need enterprise-grade secrets management without vendor lock-in or usage-based licensing risk.

Why it matters

Most teams start with .env files or CI variables and eventually face a credentials sprawl incident. OpenBao provides the audit trail, rotation, and least-privilege access that static secrets cannot. The Linux Foundation stewardship removes the licensing uncertainty that stalled Vault adoption after HashiCorp's 2023 BSL shift, making OpenBao the credible long-term open alternative backed by enterprise contributors.

Deployment & technical details

Technical details

Access
Self-hosted
Source model
Open source
Founded
2024
Headquarters
Linux Foundation (global)
Pricing model
Open source
API
Available
Published release
Stable — latest release on GitHub Releases 2.0.4 ↗ (checked )
Check with the publisher

Official resources

Community experience

Reviews of OpenBao

No published reviews yet.

Loading review form…