# Copy to .env and fill in. docker compose picks .env up automatically. # deploy.sh seeds .env from this on first run; an existing .env is never # overwritten. Never commit the populated .env. # ─── Reachability ─────────────────────────────────────────────────────────── # Address (IP or DNS name) the KANRISHA tape host uses to reach this vault on # the LAN. Seeds the self-signed cert SAN below and is what you point # [encryption.openbao].address at (https://${OPENBAO_ADDR}:8200). OPENBAO_ADDR=10.0.0.10 # Interface the published API port binds to on the host. Leave blank/all and # deploy.sh narrows it to OPENBAO_ADDR when that is an IP; set it explicitly to # pin a specific LAN IP. (A published port bypasses the host INPUT firewall — see # the README — so this bind is the main interface restriction.) OPENBAO_BIND=0.0.0.0 # ─── TLS ──────────────────────────────────────────────────────────────────── # EXTRA SANs for the self-signed cert, beyond OPENBAO_ADDR + loopback (which # deploy.sh always includes). This is read from the ENVIRONMENT at deploy time, # so to add names export it before running deploy.sh, e.g. # OPENBAO_TLS_SANS=DNS:vault.lan,IP:10.0.0.11 bash deploy.sh # (deploy.sh records the final SAN list back into this .env for reference.) To # use a CA-signed cert instead (e.g. Smallstep over ACME), drop tls.crt + tls.key # into ./tls and this is ignored — see the README. OPENBAO_TLS_SANS= OPENBAO_TLS_DAYS=825 # ─── Web UI ───────────────────────────────────────────────────────────────── # 1 = serve the built-in web UI on the same listener (default), 0 = API only. # Not a new exposure: anything that can reach :8200 can already do everything # via the API. With the UI on you can initialise and unseal from a browser, # which keeps the unseal keys out of a server shell's history. OPENBAO_UI=1 # ─── Image tag ────────────────────────────────────────────────────────────── # Pin for reproducible deploys. OPENBAO_TAG=2.6.2 # ─── Auto-unseal (optional; default is MANUAL unseal) ─────────────────────── # Only used when the seal "pkcs11" stanza is enabled in config.hcl (and the HSM # module/device is mounted into the container). Otherwise leave blank and unseal # manually after each restart. OPENBAO_HSM_PIN=