Integration · Secrets manager

Your secrets vault, watched.

Suriq watches your OpenBao cluster the way you would if you had the time - is it sealed, who is the leader, are tokens and leases piling up, which certificates are about to expire - and gives you the controls to act, in the same console as the rest of your security.

The OpenBao integration in the Suriq console: seal status, cluster health, version and node, a three-member raft topology with leader and voter badges, and step down, snapshot and seal controls.
Click to expand

A secrets manager you can actually keep an eye on.

OpenBao holds your most sensitive secrets, so a sealed node or a blocked audit log is not something you want to find out about late. Suriq reads the cluster live, watches the things that bite, and turns them into a status you can read at a glance.

What it shows you
  • Whether each node is sealed or unsealed, watched without a pause - so a node that seals raises an alert, not a surprise
  • The whole raft cluster on one screen: every node, which one is the leader, who is a voter, who is on standby, and the version each is running
  • Whether the cluster still has an active node serving secrets at all - the alert you most want and least want to miss
  • Audit logging that has stopped or had a device removed, flagged the moment it happens
  • Certificates heading for expiry, so a PKI issuer does not lapse on a quiet weekend
  • Tokens and leases piling up before they become a memory problem
  • A node running a different version than the rest of the cluster
  • Quiet edits to the OpenBao config on disk, caught and recorded
What it lets you do
  • Unseal a node through a guided ceremony - one key share at a time, never stored
  • Take a raft snapshot of the cluster on the active node, in one click
  • Hand off leadership by stepping the active node down, when you need to drain it
  • Seal a node fast when something is wrong - the panic button, right there
  • Tidy stale tokens, leases and certificates, or rotate a CRL, without SSH-ing in
  • Every action is one you trigger, runs with its work shown, and is logged - so you can prove what changed and when

It starts with zero credentials. OpenBao's health, seal-status and leader endpoints are open by design, so a Guardian on the host can read seal state, cluster identity, leadership and version with no token at all. When you are ready for the deeper view - leases, tokens, PKI, audit devices, raft config - a short opt-in wizard provisions two read and action tokens with least-privilege policies. The bootstrap is one-shot and never stored.

Frequently asked questions

What does the Suriq OpenBao integration do?

Suriq watches your OpenBao cluster live - seal status per node, the raft topology and which node is the leader, token and lease pressure, PKI certificate expiry, and audit-log health - in the same console as the rest of your security, with controls to act.

Does it alert when a node seals or audit logging stops?

Yes. A node that seals raises an alert rather than a surprise, and audit logging that stops or has a device removed is flagged the moment it happens. Suriq also warns when the cluster has no active node serving secrets.

Can I unseal or manage OpenBao from the console?

Yes. You can unseal a node through a guided ceremony - one key share at a time, never stored - take a raft snapshot, step the active node down, or seal a node fast. Every action is one you trigger, shows its work, and is logged.

Does the OpenBao integration need credentials?

It starts with zero credentials - OpenBao's health, seal-status, and leader endpoints are open by design, so a Guardian reads seal state, cluster identity, leadership, and version with no token. A short opt-in wizard then provisions least-privilege tokens for the deeper view.

Know your vault is healthy before it bites.

Deploy a Guardian on the host and OpenBao shows up in the console - sealed or unsealed, clustered, watched, and ready to act on.