Skip to content

Conversation

jackhodgkiss
Copy link
Contributor

@jackhodgkiss jackhodgkiss commented Jun 7, 2025

Fix two important bugs that prevent deployment of OpenBao across multiple hosts such as OpenStack control plane.

  1. Ensure that the bao client can communicate with bao server via
    127.0.0.1 in situations where the bind_addr it not listening on
    localhost.

  2. If TLS is used on the OpenBao API then raft peers will need to
    configured with a CA certificate to verify the certificates being used
    by the leader otherwise then could not join.

@jackhodgkiss jackhodgkiss self-assigned this Jun 7, 2025
@jackhodgkiss jackhodgkiss force-pushed the openbao-localhost-fix branch from 6cbfe15 to 1b4b2d5 Compare June 7, 2025 18:05
@jackhodgkiss jackhodgkiss changed the title feat: add additional TCP localhost listener feat: add additional TCP localhost listener and leader_ca Jun 9, 2025
@jackhodgkiss jackhodgkiss marked this pull request as ready for review June 9, 2025 09:22
@jackhodgkiss jackhodgkiss requested a review from a team as a code owner June 9, 2025 09:22
Alex-Welsh
Alex-Welsh previously approved these changes Jun 9, 2025
Ensure that the `bao` client can communicate with `bao` server via
`127.0.0.1` in situations where the `bind_addr` it not listening on
localhost.
If `TLS` is used on the `OpenBao` API then raft peers will need to
configured with a `CA` certificate to verify the certificates being used
by the leader otherwise then could not join.
@jackhodgkiss jackhodgkiss merged commit 2b1ae06 into master Jun 9, 2025
13 checks passed
@jackhodgkiss jackhodgkiss deleted the openbao-localhost-fix branch June 9, 2025 14:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants