Format:
Export:

Architecture & setup diagrams

UNSEAL — HOW THE BARRIER OPENS 🔒 openbao-N — Sealed: true API refuses reads · pod 0/1 Ready Shamir — manual PRE-06 / PRE-07 · UNSEAL-001 init → 5 key shares · threshold 3 openbao-init.json bao operator unseal ×3 3 keys · repeat per pod ⚠ humans hold the keys restart needs manual unseal Transit — auto-unseal PRE-09 · UNSEAL-002 2nd OpenBao (ns openbao-transit) transit · key: autounseal seal "transit" { token … } periodic token · policy ✓ decrypts barrier on start transit must be up + unsealed AWS KMS — auto-unseal UNSEAL-003 · BK-002 (DR) KMS key (ARN) in AWS aws-kms-creds / IRSA seal "awskms" { … } recovery shares, not key shares ✓ cloud KMS opens barrier needs AWS reachability + IAM Possible other options not covered in this plan Azure Key Vault GCP Cloud KMS PKCS#11 / HSM same sealed → unsealed outcome

Search test plan

Type at least 2 characters to search

Keyboard shortcuts

P
Go to prerequisites
T
Go to test cases
G
Go to glossary
D
Go to diagrams
J
Next card
K
Previous card
Enter
Open / close focused card
/
Open search
CtrlK
Open search modal
?
Show shortcuts
Esc
Close panel / blur search