OpenBao migration check for HashiCorp Vault files: flags BSL Vault 1.15+ images, Helm charts, storage backends, seals and plugins OpenBao 2.7 does not build in, with the OpenBao fix. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
OpenBao migration check for HashiCorp Vault scripts, Terraform, Helm values and server HCL: 14 rules, each with the OpenBao fix
DOJ's Fitzpatrick Matrix rates a 15-year litigator at $851/hour for billing year 2026, which is one hour of counsel reading the BSL Additional Use Grant.
Buy the full version — $29· ReadyStack
Real numbers from this tool, line by line.

17 findings in a 31-line HashiCorp Vault deploy script: that is what a line-by-line OpenBao migration check reports for the platform, SRE and DevOps engineers who own self-managed Vault and now have to move it to OpenBao.
The Vault LICENSE file names "Vault Version 1.15.0 or later" as the Licensed Work under the Business Source License, with IBM as licensor. Vault 1.14.x was the last line before that, and OpenBao, the fork, publishes an in-place migration guide tested from Vault 1.14.1 only. Then, on September 23, 2026, OpenBao 2.7.0 shipped and moved more pieces out of the binary: the pkcs11, alicloudkms, awskms, azurekeyvault, gcpckms and ocikms seals became external plugins, the Kerberos, LDAP and RADIUS auth methods and the LDAP secrets engine left the main distribution, and the file storage backend was removed.
So a migration plan written in the spring is already out of date. The config that unsealed with awskms on OpenBao 2.6 needs a plugin installed before it starts on 2.7.0.
Our sample is a normal bootstrap script: it exports VAULT_ADDR, writes a server config through a heredoc, pulls hashicorp/vault:1.17.2, installs the HashiCorp Helm chart, logs in, enables aws auth, configures an mssql database connection and rejects any token that does not start with hvs.
Run through the 14 rules, it gives 7 errors, 9 warnings and 1 info:
The warnings are the quiet ones: VAULT_ADDR and VAULT_TOKEN (OpenBao's api/client.go reads BAO_ADDR and BAO_TOKEN), four calls to the vault binary (the command is bao) and two Enterprise licence settings. The info is disable_mlock, which OpenBao has not used since 2.0.0.
A grep for vault matches every path, comment and bucket name, and says nothing about which seal names are now plugins. A chatbot trained before September 23, 2026 still describes awskms as built in. The facts sit in three places that change every release: the CHANGELOG, internal/helper/builtinplugins/registry.go and internal/command/commands.go. The linter carries those lists and shows the exact line.
Open the free web version, paste a script, Terraform module, Helm values file or server HCL and press Check. The same engine runs in the VS Code extension on the open file, with every finding free. The OpenBao version of the sample script gives 0 findings, so a clean result means clean. The full version scans a whole workspace and writes one migration report for the change ticket.
It reads shell scripts, Terraform, Helm values, Dockerfiles and Vault server HCL line by line against 14 rules and marks every line that breaks or changes on OpenBao: hashicorp/vault images at 1.15.0 or later (BSL), HashiCorp Helm charts, consul or s3 storage, awskms or pkcs11 seals, auth and secrets plugins OpenBao does not build in, VAULT_* variables, the vault binary and hvs. token checks. Each finding names the OpenBao fix.
Platform, SRE and DevOps engineers who run self-managed HashiCorp Vault Community Edition and must move to OpenBao because Vault 1.15.0 and later ship under the Business Source License. It suits the person who owns the deploy scripts, Terraform modules and Helm values and has to say, before the change window, which lines will stop working after the swap.
A plain grep for vault hits every comment and path and misses the real breakers: a seal "awskms" stanza that OpenBao 2.7.0 (September 23, 2026) no longer builds in, a storage "consul" block OpenBao never registered, or a script that rejects any token not starting with hvs. Chatbots trained before 2.7.0 still describe those seals as built in.
Free: every finding in the open file, in VS Code or on the web page, with the Vault line that breaks and the OpenBao fix, offline and without an account. The $29 full version, paid once, scans the whole workspace in one pass and writes one migration report for the change ticket, listing each file, line, rule and fix.
Reading the Vault LICENSE, the OpenBao 2.7.0 changelog and the plugin registry by hand takes an engineer most of a day per repository. If the question becomes legal, DOJ's Fitzpatrick Matrix rates a 15-year litigator at $851/hour for billing year 2026. The free tier answers the technical half for each file at no cost.
A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. OpenBao Migration Lint — HashiCorp Vault checks the file you open against 14 rules from a rule set dated 2026-09-28, and points at the exact line with the fix. For a filing, an audit or a client you need that dated result on your own files.
One question, answered by the person who built it. Your email only if you want the answer sent.