Files
stack/docker/openbao/Dockerfile
Jason Woltje 067e1015dd
All checks were successful
ci/woodpecker/push/infra Pipeline was successful
fix: bump openbao base image 2.5.0→2.5.1 (CVE-2026-24051)
go.opentelemetry.io/otel/sdk v1.39.0 had PATH hijacking vulnerability.
Fixed in otel/sdk v1.40.0, included in openbao 2.5.1.
2026-02-28 20:47:51 -06:00

20 lines
547 B
Docker

FROM quay.io/openbao/openbao:2.5.1
LABEL maintainer="Mosaic Stack <dev@mosaic.local>"
LABEL description="OpenBao secrets management for Mosaic Stack"
# Copy OpenBao configuration
COPY config.hcl /openbao/config/config.hcl
# Copy auto-initialization script
COPY init.sh /openbao/init.sh
RUN chmod +x /openbao/init.sh
# Expose OpenBao port
EXPOSE 8200
# Use the default entrypoint from the base image
# The container will be started with either:
# - Default: openbao server -config=/openbao/config/config.hcl
# - Init sidecar: /openbao/init.sh