jankneumann

bao-vault

"OpenBao/Vault credential seeding and management scripts"

jankneumann 4 1 Updated 1w ago

Resources

1
GitHub

Install

npx skillscat add jankneumann/agentic-coding-tools/bao-vault

Install via the SkillsCat registry.

SKILL.md

Bao Vault Infrastructure Skill

Non-user-invocable infrastructure skill for OpenBao/Vault credential seeding and management.

Scripts

scripts/bao_seed.py

Seeds OpenBao with agent API keys and secrets from agents.yaml configuration. Reads any string-valued key in .secrets.yaml and writes it under the configured KV mount, so adding new credential names (e.g. LANGFUSE_PUBLIC_KEY) requires no code change — just add the key to .secrets.yaml and re-run.

Usage:

python3 "<skill-base-dir>/scripts/bao_seed.py" [options]

Environment variables:

  • BAO_ADDR — OpenBao server address
  • BAO_TOKEN — Root or privileged token for seeding
  • BAO_SECRETS_FILE — secrets YAML path (defaults to .secrets.yaml in the current project)
  • AGENTS_YAML — agent configuration path (defaults to agents.yaml in the current project)

Both inputs can also be supplied with --secrets-path and --agents-path.
The skill does not assume that the consumer contains an agent-coordinator/
checkout.

Exit codes: 0 = seeded successfully, 1 = error

scripts/langfuse_env.sh

Resolves LANGFUSE_PUBLIC_KEY, LANGFUSE_SECRET_KEY, and LANGFUSE_HOST from OpenBao (preferring values already in the environment), computes LANGFUSE_BASIC_AUTH = base64(public:secret), and emits four export lines on stdout. Designed to be sourced via eval:

eval "$("<skill-base-dir>/scripts/langfuse_env.sh")"

Falls back silently when BAO_ADDR is unset or the keys are already populated, so it is safe to put in shell init or scripts.

Authentication: uses BAO_TOKEN if set, otherwise logs in through the isolated coordinator-internal AppRole using BAO_INTERNAL_ROLE_ID and BAO_INTERNAL_SECRET_ID. The legacy BAO_ROLE_ID and BAO_SECRET_ID inputs are ignored by this helper. Stage the retained Langfuse values at secret/coordinator and grant the internal role access to that path before enabling Bao mode.

Consumed by:

  • <skill-base-dir>/../langfuse/scripts/install-mcp.sh — computes the literal Basic-auth token written into Codex / Gemini user-global config files.
  • <skill-base-dir>/../langfuse/scripts/run_stop_hook.sh — populates the env for the Claude Code Stop-hook tracer.

Categories