The Secure Way
Secrets and PKI, the secure way
OpenBao, External Secrets, internal certificate authorities and keeping secrets off the command line.
10 guides
- An offline internal CA with cert-manager, the secure wayKeep the root CA key offline and give cert-manager only a one-year intermediate with pathlen:0 and name constraints, so a stolen key cannot sign anything else.
- External Secrets Operator with OpenBao, the secure wayRun External Secrets Operator against OpenBao with namespaced SecretStores, per-team ServiceAccounts, audience-bound tokens, a pinned CA and no cluster stores.
- Let's Encrypt DNS-01 over RFC 2136 and TSIG, the secure wayGive cert-manager a TSIG key that can only write TXT records in a delegated ACME zone, never your main zone. BIND update-policy, CNAME delegation, real tests.
- Never put a secret on the command line, the secure wayCommand-line arguments are readable by every user on the host and land in shell history. See the leak in ps and /proc, then pass secrets by file, fd or stdin.
- OpenBao hardening, the secure wayHarden an OpenBao server: no swap, TLS 1.3, declarative audit devices, self-init with no root token left behind, and HMAC'd audit logs, shown with real output.
- OpenBao Kubernetes auth across clusters, the secure wayLet pods in several Kubernetes clusters log in to one OpenBao without sharing trust: one mount per cluster, audience-bound tokens, exact subjects, short TTLs.
- OpenBao policies as code with drift detection, the secure wayKeep OpenBao ACL policies in git, apply them from CI, and catch hand edits with a read-only drift check that fails the pipeline. Tested script included.
- OpenBao transit auto-unseal, the secure waySet up OpenBao transit auto-unseal with an orphan periodic token, a two-path policy and TLS, and see what happens when the transit server is sealed or revoked.
- Operator secret stores with pass and an offline copy, the secure wayShare operator secrets in a team with pass: per-person GPG keys, a signed recipient list, re-encryption and rotation when someone leaves, and an offline copy.
- Signing keys no cluster can read, the secure wayKeep cosign signing keys in OpenBao transit, non-exportable, and give CI a 15-minute token that can sign with one key and nothing else. Tested with cosign v3.
T Academy
Every guide here is taught hands-on in H2-CIAE Identity and Access Engineering: a real host in your browser, and every objective checked on the machine.
Start free