OpenBao Migration Lint — HashiCorp Vault

OpenBao migration check for HashiCorp Vault files: flags BSL Vault 1.15+ images, Helm charts, storage backends, seals and plugins OpenBao 2.7 does not build in, with the OpenBao fix. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

OpenBao migration check for HashiCorp Vault scripts, Terraform, Helm values and server HCL: 14 rules, each with the OpenBao fix

DOJ's Fitzpatrick Matrix rates a 15-year litigator at $851/hour for billing year 2026, which is one hour of counsel reading the BSL Additional Use Grant.

Buy the full version — $29
Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool

· ReadyStack

Worked example

Real numbers from this tool, line by line.

OpenBao Migration Lint — HashiCorp Vault

17 findings in a 31-line HashiCorp Vault deploy script: that is what a line-by-line OpenBao migration check reports for the platform, SRE and DevOps engineers who own self-managed Vault and now have to move it to OpenBao.

Migrate from HashiCorp Vault to OpenBao: what changed and when

The Vault LICENSE file names "Vault Version 1.15.0 or later" as the Licensed Work under the Business Source License, with IBM as licensor. Vault 1.14.x was the last line before that, and OpenBao, the fork, publishes an in-place migration guide tested from Vault 1.14.1 only. Then, on September 23, 2026, OpenBao 2.7.0 shipped and moved more pieces out of the binary: the pkcs11, alicloudkms, awskms, azurekeyvault, gcpckms and ocikms seals became external plugins, the Kerberos, LDAP and RADIUS auth methods and the LDAP secrets engine left the main distribution, and the file storage backend was removed.

So a migration plan written in the spring is already out of date. The config that unsealed with awskms on OpenBao 2.6 needs a plugin installed before it starts on 2.7.0.

The sample script

Our sample is a normal bootstrap script: it exports VAULT_ADDR, writes a server config through a heredoc, pulls hashicorp/vault:1.17.2, installs the HashiCorp Helm chart, logs in, enables aws auth, configures an mssql database connection and rejects any token that does not start with hvs.

Run through the 14 rules, it gives 7 errors, 9 warnings and 1 info:

The warnings are the quiet ones: VAULT_ADDR and VAULT_TOKEN (OpenBao's api/client.go reads BAO_ADDR and BAO_TOKEN), four calls to the vault binary (the command is bao) and two Enterprise licence settings. The info is disable_mlock, which OpenBao has not used since 2.0.0.

Why grep and chatbots miss it

A grep for vault matches every path, comment and bucket name, and says nothing about which seal names are now plugins. A chatbot trained before September 23, 2026 still describes awskms as built in. The facts sit in three places that change every release: the CHANGELOG, internal/helper/builtinplugins/registry.go and internal/command/commands.go. The linter carries those lists and shows the exact line.

Try it on your own files

Open the free web version, paste a script, Terraform module, Helm values file or server HCL and press Check. The same engine runs in the VS Code extension on the open file, with every finding free. The OpenBao version of the sample script gives 0 findings, so a clean result means clean. The full version scans a whole workspace and writes one migration report for the change ticket.

15 seconds — what it actually does

Questions people ask

What does OpenBao Migration Lint check in my HashiCorp Vault files?

It reads shell scripts, Terraform, Helm values, Dockerfiles and Vault server HCL line by line against 14 rules and marks every line that breaks or changes on OpenBao: hashicorp/vault images at 1.15.0 or later (BSL), HashiCorp Helm charts, consul or s3 storage, awskms or pkcs11 seals, auth and secrets plugins OpenBao does not build in, VAULT_* variables, the vault binary and hvs. token checks. Each finding names the OpenBao fix.

Who is OpenBao Migration Lint for?

Platform, SRE and DevOps engineers who run self-managed HashiCorp Vault Community Edition and must move to OpenBao because Vault 1.15.0 and later ship under the Business Source License. It suits the person who owns the deploy scripts, Terraform modules and Helm values and has to say, before the change window, which lines will stop working after the swap.

Why not ask a chatbot or grep for the word vault?

A plain grep for vault hits every comment and path and misses the real breakers: a seal "awskms" stanza that OpenBao 2.7.0 (September 23, 2026) no longer builds in, a storage "consul" block OpenBao never registered, or a script that rejects any token not starting with hvs. Chatbots trained before 2.7.0 still describe those seals as built in.

What is free and what does the $29 version add?

Free: every finding in the open file, in VS Code or on the web page, with the Vault line that breaks and the OpenBao fix, offline and without an account. The $29 full version, paid once, scans the whole workspace in one pass and writes one migration report for the change ticket, listing each file, line, rule and fix.

What does the alternative cost?

Reading the Vault LICENSE, the OpenBao 2.7.0 changelog and the plugin registry by hand takes an engineer most of a day per repository. If the question becomes legal, DOJ's Fitzpatrick Matrix rates a 15-year litigator at $851/hour for billing year 2026. The free tier answers the technical half for each file at no cost.

Why not just ask ChatGPT or another AI chat?

A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. OpenBao Migration Lint — HashiCorp Vault checks the file you open against 14 rules from a rule set dated 2026-09-28, and points at the exact line with the fix. For a filing, an audit or a client you need that dated result on your own files.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.