#cloud-config # # OpenBao (Kanrisha tape-encryption key store) — harden SSH, then deploy, on a # fresh Alpine/Debian/Alma host on the SAME LAN as the Kanrisha tape host. # # Fill in REPO_URL and the values in the runcmd block, then paste this as the # instance user-data. No public DNS / 80 / 443 needed — this is a LAN vault with # native TLS on 8200. After boot, initialise + unseal once (see the README). packages: - git runcmd: - hostnamectl set-hostname openbao || true - | set -e REPO_URL=https://git.anomalous.dev/57_Wolve/automations.git REPO_BRANCH=main HARDEN_SSH=1 # harden SSH on this fresh VM (set 0 to skip) SSH_PORT=22 ALLOWED_IP= # optional: whitelist your client IP in sshguard git clone --depth 1 --branch "$REPO_BRANCH" "$REPO_URL" /opt/automations cd /opt/automations # Harden SSH: PQ KEX, key-only auth, sshguard. Seeds root from # globals/authorized_keys (or SSH_KEYS_URL). if [ "$HARDEN_SSH" = 1 ]; then SSH_PORT="$SSH_PORT" ALLOWED_IP="$ALLOWED_IP" SKIP_PROMPTS=1 FORCE=1 \ bash scripts/harden-ssh.sh fi # Deploy OpenBao. OPENBAO_ADDR is the LAN address the Kanrisha tape host # reaches this vault at — it goes in the TLS cert SAN. deploy.sh disables # swap (for mlock) and firewalls 8200/tcp. OPENBAO_ADDR=10.0.0.10 \ SKIP_PROMPTS=1 \ bash deployments/openbao/deploy.sh