OpenBao – FOSS Fork of HashiCorp Vault

A new open source project, OpenBao, has emerged as a fork of HashiCorp Vault after HashiCorp’s license change, aiming to provide a community-governed secrets manager less tied to a single vendor’s commercial priorities. Commenters welcome the fork and its Matrix-based community but note it is very early-stage and not yet production-ready, raising concerns about stability, trust, and the risk of fragmentation in critical security tooling. Alongside comparisons to Vault’s enterprise features, pricing, and operational complexity, the conversation surveys alternative approaches to secrets management—including SOPS, EnvKey, and Infisical—and highlights niche needs like HSM integration, FIPS compliance, and dynamic credential generation that OpenBao would need to address to be a full replacement.

Project status & community

  • OpenBao is described as a very early-stage fork of Vault and not yet production‑ready.
  • Contributors invite participation via multiple Matrix rooms and a mailing list; federation from other Matrix servers appears to work.
  • Some rough edges remain (e.g., leftover “Vault” references in docs and security text).

Motivations for the fork & governance

  • Main stated driver: HashiCorp’s license change; some want a version less aligned with a single company’s business needs.
  • Debate over OSS business models:
    • One side argues companies that release under liberal licenses must learn to compete with cloud resellers and can still win by controlling roadmap and quality.
    • The other side stresses the high cost of maintaining complex software and claims SaaS resellers have a large advantage by not funding core development.

Logo and branding discussion

  • Several commenters note the logo looks very similar to Bun’s bao mascot; others argue there’s limited design space for “cute bao bun with a face.”
  • Some see the similarity as poor taste; others think it’s inconsequential since the products are unrelated.

User experiences with Vault, Consul, and Nomad

  • Mixed views:
    • Some say Vault and Consul make their lives harder, citing operational complexity and past Consul instability (elections, state issues).
    • Others report stable, large Vault deployments (especially with a dedicated DevOps team) and consider it well‑designed rather than “overengineered.”
    • Nomad is jokingly called “perfect,” but no detailed critique given.

Alternatives to Vault

  • Suggestions include:
    • Mozilla SOPS (plus tooling like Step CA and Teleport) for KV secrets and some auth/SSH use cases; praised for simplicity but acknowledged as no full replacement for Vault’s dynamic engines.
    • Infisical and EnvKey as easier secrets/config managers with open-source offerings.
  • Discussion around EnvKey’s marketing: critics say its comparison to Vault downplays Vault’s much broader feature set; defenders argue the comparison focuses on secrets management, not Vault’s full infra capabilities.

Enterprise features: HSM & FIPS

  • One user relies on paid Vault for on‑prem HSM integration and FIPS‑certified operation and doesn’t see OpenBao as a current substitute.
  • Others expect OpenBao might eventually gain HSM support, but note that compliance work is expensive and would need funding (IBM involvement is mentioned but not clearly confirmed).

Security, trust, and audits

  • Some are uneasy about “holy war” vibes around forks and fear instability or malicious changes in a security‑critical tool.
  • Responses emphasize:
    • HashiCorp Vault isn’t considered more vulnerable post‑fork; the conflict is about licensing and governance.
    • Ultimate assurance comes from audits, code review, and/or paying a vendor to own security guarantees.
  • The stock phrase “we take security seriously” is viewed by some as trust‑reducing rather than reassuring.