Identity Architecture: OpenBao Secrets · advanced

AppRole Is Machine Identity, Not a Shared Master Password

Workloads should authenticate to the secret authority with narrow machine identities rather than one credential copied across services.

Current. Current production engineering note based on the hserver authentication and secret-control-plane architecture.

Human operators and workloads do not have the same authentication problem. A person can complete MFA. A background service needs a non-interactive identity that can be scoped and revoked independently.

OpenBao's AppRole model fits that boundary. The hserver design enables AppRole for machine access and maps narrow roles to reviewed policies. A consumer authenticates, receives a token and uses that token only for the paths permitted by its policy.

The anti-pattern would be a single long-lived master token copied into every container. One leak would then collapse the whole secret plane, rotation would require touching every workload and audit events would lose useful identity context.

Machine identity should be boring and replaceable. Each workload gets only the permissions it requires, token lifetime is bounded, and compromise of one role should not imply compromise of unrelated secret paths.

Engineering evidence

The hserver repository evidence for this note is commit 1f583b4. The architecture is documented as current state or future phase explicitly; planned OIDC integration is not presented as already deployed.

Quick navigationEsc