Skip to main content
NVIDIA
NMC OpenBao Configurator
Helm Chart
NVIDIA
NMC OpenBao Configurator

Helm chart for an OpenBao bootstrap configurator — a one-shot Job that seeds OpenBao KV create-only and reconciles the PKI issuing role you declare.

Subscribe to get accessSubscribe to the product below to access this premium content:
NVIDIA Mission Control
NVIDIA Mission ControlNVIDIA Mission Control™ powers every aspect of AI factory operations — from developer workloads to infrastructure to facilities — with the skills of a world-class operations team delivered as software. It powers NVIDIA Blackwell™ data centers for the newest frontiers of AI, bringing instant agility to inference and training workloads and full-stack intelligence that delivers world-class infrastructure resiliency. Mission Control lets every enterprise run AI with hyperscale-grade efficiency so you can accelerate AI experimentation.
Note: You can gain access to hundreds more GPU-optimized artifacts by creating a free NGC account.
Already Subscribed?Log in
Subscribe Now

Helm chart for an OpenBao bootstrap configurator — a one-shot Job that seeds OpenBao KV create-only and reconciles the PKI issuing role you declare. It runs after OpenBao is deployed and initialized, seeding the KV paths and PKI issuing role that the components consuming OpenBao depend on. Policies and Kubernetes auth roles are owned by OpenBao self-init, not by this chart.

What It Does

The configure Job, on every apply:

  • Logs in to OpenBao via the configured Kubernetes auth role.
  • Seeds KV create-only (-cas=0) from openbao-bootstrap-seeds-* Secrets, idempotent across re-syncs and post-cleanup.
  • Reconciles the PKI issuing role from externalConfig, supplied per-deployment via Helm values.
  • Configures the PKI issuing-certificate and CRL URLs.

It runs the upstream openbao/openbao image (for the bao CLI); the chart builds no image of its own.

Adding a Consumer

This chart ships externalConfig empty: it is the engine, and the reconcilable set is per-deployment data supplied via Helm values (a values file in your gitops repo), not baked into the chart. Add a consumer's KV seed path, and its PKI role if it needs one, to that values file. The consumer's policy and Kubernetes auth role are created by OpenBao self-init, not here. The chart version is not bumped, and the OpenBao deployment is unchanged.

Publisher
NVIDIA
Latest Version0.2.4
UpdatedSeptember 28, 2026 UTC
Compressed Size6.21 KB

NVIDIA uses cookies to improve your experience on our web site. We and our third-party partners also use cookies and other tools to collect and record information you provide as well as information about your interactions with our websites for performance improvement, analytics, and to assist in marketing efforts. By clicking "Accept All", you consent to our use of cookies and other tools as described in our Cookie Policy. You can manage your cookie settings by clicking on "Manage Settings." By continuing to use this site or by clicking one of the buttons below, you agree to our Terms of Service (which contains important waivers). Please see our Privacy Policy for more information on our privacy practices.