10 ms·
OpenBao – FOSS Fork of HashiCorp Vault
- jimmyed 3y agoWhy is the logo the same as bun.sh?
- frenchman99 3y agoIt's not the same.
- omneity 3y agoThere are minor differences, but the similarity is indeed striking.
- mrunkel 3y agoIt's an anthropomorphized bao bun. How much variance can you expect? https://imgur.com/a/tNRuEpb https://imgur.com/a/tNRuEpb
- deleted 3y ago[deleted]
- emptysongglass 3y agoIt looks extremely similar to me. I would not be pleased if I was behind Bun.
- richbell 3y agoThe only real similarity is that it's a bao bun with a face, which Bun didn't create the concept of.
- FringeXT 3y agoWho cares? It’s not like they’re in a remotely related niche. Nobody’s gonna confuse the two.
- yencabulator 3y agoSounds like Bun chose a bad logo then. They're not going to own the concept of a bao bun with a face.
- shwouchk 3y agoWhat about the concept of a window? Can anyone own that? Or, a cat octopus? How about a discarded piece of fruit?
- richbell 3y agoThere is nothing distinct about a window or piece of fruit. Obviously if you made an operating system called Windows and used a window as a logo that would be trademark violation, but there's nothing stopping me from opening John's Windows with the logo being a window.
- shwouchk 3y agoSure, a trivial strawman example. But then, if you made not an OS but rather say, a search engine called “pane.io” and used a logo of a 4 pane window of different colors ? I am open to being wrong here but I doubt it would have gone smoothly.
- mrunkel 3y agoThey aren't. https://imgur.com/a/tNRuEpb https://imgur.com/a/tNRuEpb But how much variance can you reasonably expect from a logo based on an anthropomorphized bao bun?
- BadBadJellyBean 3y agoMaybe bao in a steamer. If the boa are the secrets the steamer is the vault.
- codetrotter 3y ago> If the boa are the secrets the steamer is the vault I think the inside of the bao is the secret, and the bao is the vault.
- codetrotter 3y ago> how much variance can you reasonably expect from a logo based on an anthropomorphized bao bun Agreed. Try this: do an image search for cute cartoon bao bun https://duckduckgo.com/?q=cute+cartoon+bao+bun&iar=images&iax=images&ia=images https://duckduckgo.com/?q=cute+cartoon+bao+bun&iar=images&ia... There are, completely as expected, a bunch of different pictures that fundamentally look very similar.
- ksec 3y ago>But how much variance can you reasonably expect from a logo based on an anthropomorphized bao bun? Not much. But taking a similar logo from a current hot / hyped tech in a similar vertical just strike me as poor taste.
- intelVISA 3y agoBun is kinda DOA last I was asked to evaluate it...
- 12345hn6789 3y agoHow so?
- nan60 3y agoHaha, I thought the exact same thing.
- g0xA52A2A 3y agoDupe of https://news.ycombinator.com/item?id=38578247 https://news.ycombinator.com/item?id=38578247
- gchamonlive 3y agoNot exactly. The linked post is from theregister announcing the fork. This post is the fork itself.
- iamawacko 3y agoThat's real cool, still hoping for a Nomad fork.
- heipei 3y agoWhy though? Nomad is perfect ;)
- sc0rpil 3y agoHey HN, I'm involved with this project, glad you found it interesting! Keep in mind it's still a _very_ early stage and not in a usable state. A lot of work in progress but also plenty of opportunities if you want to contribute. If you want to help out, you can : Join Matrix rooms: - https://chat.lfx.linuxfoundation.org/#/room/#openbao-announcements:chat.lfx.linuxfoundation.org https://chat.lfx.linuxfoundation.org/#/room/#openbao-announc... - https://chat.lfx.linuxfoundation.org/#/room/#openbao-development:chat.lfx.linuxfoundation.org https://chat.lfx.linuxfoundation.org/#/room/#openbao-develop... - https://chat.lfx.linuxfoundation.org/#/room/#openbao-general:chat.lfx.linuxfoundation.org https://chat.lfx.linuxfoundation.org/#/room/#openbao-general... - https://chat.lfx.linuxfoundation.org/#/room/#openbao-questions:chat.lfx.linuxfoundation.org https://chat.lfx.linuxfoundation.org/#/room/#openbao-questio... - https://chat.lfx.linuxfoundation.org/#/room/#openbao-random:chat.lfx.linuxfoundation.org https://chat.lfx.linuxfoundation.org/#/room/#openbao-random:... Join the mailing list: https://lists.lfedge.org/g/openbao https://lists.lfedge.org/g/openbao
- zufallsheld 3y agoGlad you use matrix and not discord!
- jasonvorhe 3y agoHas anyone figured out if it's possible to join these rooms from a federated Matrix account?
- notpushkin 3y agoJust joined from :matrix.org. Haven’t tried other servers but should be fine I think.
- brunoqc 3y agohttps://matrix.to/#/#openbao-general:chat.lfx.linuxfoundation.org https://matrix.to/#/#openbao-general:chat.lfx.linuxfoundatio...
- Hnrobert42 3y agoWhy did you all choose to fork?
- antisocialist 3y ago[flagged]
- sc0rpil 3y agoNone. OpenTofu name comes from Terraform => TF => Tofu. Bao is another asian food, so it kinda fits (people involved with OpenTofu are not the same as people working on OpenBao, but why not have some common theme).
- makeitshine 3y agoBao (包子) is usually referencing a steamed bun, for those interested.
- isilofi 3y agoSo basically the cake containing the file to break out of the vault?
- cassianoleal 3y agoThis one is already open though. The file is gone.
- odiroot 3y agoAnd is as tasty as the logo itself :)
- _joel 3y agoThey would have gotten away with it too if it wasn't, er, (checks notes) open source.
- taspeotis 3y agoOops https://github.com/openbao/openbao/tree/development?tab=readme-ov-file#developing-vault https://github.com/openbao/openbao/tree/development?tab=read...
- gchamonlive 3y agoThe Devs probably know this (grepping code for "vault" is trivial). The fork was announced yesterday, so it is bound to be in need of polishing here and there.
- raffraffraff 3y ago> Please note: We take OpenBao's security and our users' trust very seriously. If you believe you have found a security issue in Vault, please responsibly disclose by contacting us at openbao-security@lists.lfedge.org. You might wanna change Vault to OpenBao
- projektfu 3y agoI think they're asking for responsible disclosure that's sent to Hashicorp to also be sent to them so they can test and help fix before public disclosure.
- cipherboy 3y agoLike OpenTofu, this will likely take some time and likely will be a blocking step that prevents other contributions until it is done.
- deleted 3y ago[deleted]
- baz00 3y agoAs much as I appreciate open source forks of things like this I’d rather just completely avoid vault if I can. This and consul are bits of software that make my life harder not better in the last few years.
- deleted 3y ago[deleted]
- szszrk 3y agoWhat are the alternatives to both that don't make your life harder? Curious if there are any.
- totallywrong 3y agoI just replaced a clunky secrets manager with Mozilla SOPS and secrets-in-code that we keep in git encrypted and can version like any other file. I like this approach better than any alternative I've used so far.
- szszrk 3y agoWell, that actually may be a good hint for me for a project I'm working on right now. I just fell of the chair when I realized how Vault charges for Enterprise "clients" (identities). This could be some fresh air.
- glitchcrab 3y agoTheir pricing was laughable when we investigated it a couple of years back; I imagine it's only gotten worse since. When I told them how ridiculously expensive it was for our use-case they suddenly managed to find a ~50% discount for us. That brought it down to just laughably expensive. Needless to say, we stuck with DIY.
- Sayrus 3y agoSOPS is only an alternative for vault KV Store. Even then, it requires a lot of manual plumbing when you have operators and Terraform pushing secrets or keys into Vault KV. To replace SSH Sign and Cert Authority or databases engines, both generating short-lived credentials on-demand, SOPS will not easily solve the issue. If you only need KV Store, SOPS experience is way better than Vault and maintenance cost is low.
- aestetix 3y agoHi, This is concerning. To me it looks like there is a holy war going on with devs who maintain a secrets manager. The last thing I want is instability with the tool that holds my passwords and credentials. On the low end of my concern is the annoyance of constantly updating names in yaml files, and on the high end is worry that a rogue dev could deliberately add in a security hole that would compromise my secrets. Is there any assurance this won't happen?
- mt42or 3y agoJust pay for it so.
- aestetix 3y agoIt's not about money, it's about trust.
- api 3y agoWhat could Hashicorp have done to preserve trust while maintaining some kind of business model and being able to charge companies monetizing their software?
- brodock 3y agoOutcompete them. Do more, do better, do faster
- aestetix 3y agoBut "move fast and break things" is precisely the opposite of what I want for a place where I store my passwords.
- api 3y agoSo software makers should give their competitors their software with a liberal free “as in beer” license and then try to compete with them. This isn’t a workable or sustainable model. The companies leveraging free software don’t have to work nearly as hard on software which means they can focus 100% on ops and marketing. And of course they don’t give anything back to the software creators.
- KomoD 3y ago[flagged]
- NewJazz 3y agoYou stuff secrets into your dumpling, duh. /s
- triyambakam 3y agoProbably to be similar to OpenTofu to avoid trademark/copyright (or whatever it is called)
- vmatsiiako 3y agoAppreciate the fork, but I think it's time for people to move on from Vault and other HashiCorp tools (especially that I'm hearing this is financed by IMB to keep their Vault competitor going). Check out Infisical for secret management: https://github.com/Infisical/infisical https://github.com/Infisical/infisical Disclaimer: I'm one of the maintainers.
- aliasxneo 3y agoDoesn't seem to support one of our major use cases as a private CA.
- bogomipz 3y agoWho is IMB here? IBM? Can you say what is their Vault competitor?
- vmatsiiako 3y agoThis product is built on top of open source Vault: https://www.ibm.com/products/secrets-manager https://www.ibm.com/products/secrets-manager
- candiddevmike 3y agoThis is a terrible advertisement, you should at least sell your tool on it's own merits.
- fishnchips 3y agoI honestly believe both you and the Akeyless folks should join the steering committee once one forms, and together work towards common standards y'all can benefit from.
- firesteelrain 3y agoI use HashiCorp Vault paid version to interface with an on premises HSM and for its FIPS compliance. I don’t know of any other software that is as lightweight and easy to use with an HSM as vault. We are using Vault to store the signed intermediate CA and automatically unseal Vault by storing the shards in the HSM (along with the Root CA). OpenBao wouldn’t solve this for me.
- bogomipz 3y agoCan I ask what regulatory domain you are in that requires on-prem HSM(vs cloud offering)? Also do you have a recommendation for on-prem HSM vendors that work well with Vault?
- firesteelrain 3y agoFinancial Sector and Thales TCT HSM https://cpl.thalesgroup.com/sites/default/files/content/integration_guides/field_document/2022-07/HashiCorpVault_LunaHSM_IntegrationGuide_RevE.pdf https://cpl.thalesgroup.com/sites/default/files/content/inte...
- candiddevmike 3y ago> OpenBao wouldn’t solve this for me. I'd bet OpenBao gets native HSM support. The problem will be doing it in a clean room setting to avoid any legal issues.
- firesteelrain 3y agoSomeone would have to fund it. The compliance issues alone are very expensive.
- NewJazz 3y agoForgive my ignorance, but what does compliance have to do with HSM support? Aren't they orthogonal features?
- danenania 3y agoAnother option that focuses on ease-of-use and security is EnvKey - https://envkey.com https://envkey.com (I’m the founder) It’s has client-side end-to-end encryption with no backdoors or compromises, is open source, and, apart from secrets management, provides a robust set of tools to manage and de-duplicate config. Comparison with Vault: https://www.envkey.com/compare/hashicorp-vault/ https://www.envkey.com/compare/hashicorp-vault/
- Jishin 3y ago[dead]
- dang 3y agoRecent and related: HashiCorp Vault forked into OpenBAO - https://news.ycombinator.com/item?id=38578247 https://news.ycombinator.com/item?id=38578247 - Dec 2023 (70 comments)
- account42 3y ago> Please note: We take OpenBao's security and our users' trust very seriously. Funny how that sentence is one of the quickest ways to make me mistrust something (even if possibly undeserved).
- skeptrune 3y agoBased that you use Matrix and not disc