Skip to content

Conversation

m-bull
Copy link
Contributor

@m-bull m-bull commented Sep 15, 2025

Some variables needed updating in the move to openbao from Vault.

Some variables needed updating in the move to
openbao from Vault.
@m-bull m-bull requested a review from a team as a code owner September 15, 2025 17:11
Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary of Changes

Hello @m-bull, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses necessary variable updates to facilitate the migration from HashiCorp Vault to OpenBao within the Kayobe automation setup. It primarily involves adjusting configuration paths and API endpoint references to correctly point to the OpenBao service, ensuring the automation processes can interact with the new secrets management system. The changes aim to fix installation issues related to this transition.

Highlights

  • Configuration Path Updates: The configuration directory for OpenBao and the path for its keys file have been updated from vault to openbao specific locations to align with the migration.
  • OpenBao API Address Definition: The openbao_api_addr variable is now explicitly defined within the playbook, setting the API endpoint to http://127.0.0.1:8200.
  • API Address Referencing: References to the API address in tasks like vault_unseal, hashivault_secret_engine, and vault_write have been updated to use the newly defined openbao_api_addr variable. A potential issue has been introduced where http:// is prepended to openbao_api_addr even though openbao_api_addr already contains http://, resulting in a double http:// prefix (e.g., http://http://127.0.0.1:8200).
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point in your pull request via creating an issue comment (i.e. comment on the pull request page) using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in issue comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates an Ansible playbook to support OpenBao for automation, primarily by renaming paths from vault to openbao and adjusting variable definitions. While the variable updates are a good step, some related parts of the playbook were missed. I've identified a critical issue with URL formation that will cause playbook failure. Additionally, some directory creation tasks still use the old vault paths and need to be updated to openbao to match the changes in this PR. I've provided comments on the relevant changes with suggestions for fixes.

name: stackhpc.hashicorp.openbao
vars:
openbao_config_dir: "/opt/kayobe/vault"
openbao_api_addr: "http://127.0.0.1:8200"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critical

The openbao_api_addr variable is defined with the http:// protocol prefix. However, later in the file (lines 56, 67, and 72), the http:// prefix is added again when using this variable. This results in an invalid URL like http://http://127.0.0.1:8200, which will cause tasks to fail. To fix this, the protocol prefix should be removed from this variable definition. This will make the variable contain only the address, and the protocol can be prepended where needed, as is done in the rest of the file.

        openbao_api_addr: "127.0.0.1:8200"

vars:
openbao_config_dir: "/opt/kayobe/vault"
openbao_api_addr: "http://127.0.0.1:8200"
openbao_config_dir: "/opt/kayobe/openbao"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

This path has been correctly updated for OpenBao. However, a related task on lines 24-27, named Ensure /opt/kayobe/vault exists, still creates the old /opt/kayobe/vault directory. This task should be updated to create /opt/kayobe/openbao to ensure consistency and prevent potential failures.

copy_self_signed_ca: false
openbao_write_keys_file: true
openbao_write_keys_file_path: "{{ kayobe_env_config_path }}/vault/kayobe-automation-keys.json"
openbao_write_keys_file_path: "{{ kayobe_env_config_path }}/openbao/kayobe-automation-keys.json"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

This file path has been correctly updated for OpenBao. However, a related task on lines 30-33, named Ensure vault directory exists in environment, still creates the old .../vault directory in the environment path. This task should be updated to create the .../openbao directory to prevent failures when writing the keys file specified here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant