infra: set up OpenBao instance for pipeline secrets

did:plc:wcx4c3osbuzrwmxkqdfqygwv opened this Dec 7, 2025 0 comments
did:plc:wcx4c3osbuzrwmxkqdfqygwv opened Dec 7, 2025

About this issue

At the moment, manual migration is required for pipeline secrets added before the instance setup, so we are putting this ticket as a notice for anyone using the service. The plan would be running it separately from Nest to minimize downtime risk and the toil of manually unlocking the server after a server restart. I expect this to be enabled on the knot server around December 10-12 to allow me to find where to host it.

Prior art / Additional resources

To be added.

No activity yet.

cospan · schematic version control on atproto built on AT Protocol