Helm chart for an OpenBao bootstrap configurator — a one-shot Job that seeds OpenBao KV create-only and reconciles the PKI issuing role you declare.

Helm chart for an OpenBao bootstrap configurator — a one-shot Job that seeds OpenBao KV create-only and reconciles the PKI issuing role you declare. It runs after OpenBao is deployed and initialized, seeding the KV paths and PKI issuing role that the components consuming OpenBao depend on. Policies and Kubernetes auth roles are owned by OpenBao self-init, not by this chart.
What It Does
The configure Job, on every apply:
- Logs in to OpenBao via the configured Kubernetes auth role.
- Seeds KV create-only (-cas=0) from openbao-bootstrap-seeds-* Secrets, idempotent across re-syncs and post-cleanup.
- Reconciles the PKI issuing role from externalConfig, supplied per-deployment via Helm values.
- Configures the PKI issuing-certificate and CRL URLs.
It runs the upstream openbao/openbao image (for the bao CLI); the chart builds no image of its own.
Adding a Consumer
This chart ships externalConfig empty: it is the engine, and the reconcilable set is per-deployment data supplied via Helm values (a values file in your gitops repo), not baked into the chart. Add a consumer's KV seed path, and its PKI role if it needs one, to that values file. The consumer's policy and Kubernetes auth role are created by OpenBao self-init, not here. The chart version is not bumped, and the OpenBao deployment is unchanged.