prole/docs/PROLE-CFG-SECRETS.md
chrisfu bcc8f23a0d Enhance secret management and k8s infrastructure
- Secret Management: Integrated AESGCM for temporary secret handling in install.py and enhanced OpenBao (Vault) support with namespace injection and additional secret paths (Grafana, Kerberos, TDE).
- Infrastructure & K8s:
    - Added Barman Object Store backup configuration (S3) to prole-db.yaml.
    - Updated Prometheus deployment with PVC and persistent configuration.
    - Updated k3s cluster/registry creation scripts.
    - Added etc/build-a-bao.sh for OpenBao setup.
- MSSQL Integration: Updated docker scripts and k8s deployments for Prole MSSQL database.
- Documentation: Added docs/PROLE-CFG-SECRETS.md explaining the new secret handling.
- General: Refined initialization scripts (init_authority.sh, init_openbao.sh, etc.) and updated the ncurses installer.
2026-02-03 22:39:50 -08:00

1.8 KiB
Raw Blame History

prole.cfg Secrets

This document describes how secrets are handled in prole.cfg and where they are stored in OpenBao.

Temporary encrypted values

During installation, secrets are written to prole.cfg as temporary encrypted values so an interrupted run can resume:

  • Format: ${PROLE_SECRET:v1:<nonce_b64>:<ciphertext_b64>}
  • Encryption: AES256GCM
  • Key storage:
    • macOS: login Keychain (service prole-installer)
    • Other platforms: ~/.prole/secrets/installer.key (0600)

These encrypted values are removed at PostInstall by running etc/build-a-bao.sh.

OpenBao placeholders

After PostInstall, secrets in prole.cfg are replaced with OpenBao placeholders that point to a namespacescoped KV path:

  • Format: ${OPENBAO:kv/prole/<namespace>/<leaf>#<key>}

The namespace comes from NAMESPACE in prole.cfg and makes the file 1:1 with a single prole-db deployment.

Secrets recorded in prole.cfg

The following keys are treated as secrets and stored in OpenBao:

prole.cfg key OpenBao KV path
Inputs.init_password.db_password kv/prole/<namespace>/db#password
Inputs.init_password.db_password_confirm kv/prole/<namespace>/db#password
Global.DB_PASSWORD kv/prole/<namespace>/db#password
Inputs.kerberos_config.password kv/prole/<namespace>/kerberos#password
Kerberos Authentication.PASSWORD kv/prole/<namespace>/kerberos#password
Monitoring.GRAFANA_ADMIN_PASSWORD kv/prole/<namespace>/monitoring#grafana_admin_password

PostInstall step

Run the BuildABao step on the PostInstall screen (or etc/build-a-bao.sh) to:

  1. Decrypt temporary secrets from prole.cfg
  2. Write them to OpenBao under the namespace path
  3. Replace prole.cfg secrets with OpenBao placeholders