OpenBao GUI on AWS: Enable and Use the OpenBao Web UI Dashboard¶
Every OpenBao walkthrough starts the same way: open a terminal. Meanwhile OpenBao ships a full web UI, and on the Standalone OpenBao Vault AMI it runs on the same instance as the server — no extra setup, no second host.
The entire first-run flow works from the browser: initialize, unseal, log in. This guide walks that dashboard path end to end, with the CLI equivalents alongside.
Version Note (Read This First)¶
This guide follows the Epok OpenBao documentation, written against OpenBao 2.x — the docs page pins 2.0.0 and the current Marketplace build ships 2.0.1.
OpenBao's dashboard changes between upstream releases. Menu labels, screens, and minor flows may differ from what's described here depending on your exact version. When something doesn't match, trust your eyes and cross-check the official OpenBao documentation for your release.
Before You Start¶
- A running Standalone OpenBao Vault AMI instance with a public IP or DNS name reachable from your machine
- A browser
- SSH access to the instance (only needed for the optional CLI sections)
The vault starts sealed and uninitialized. That's expected — you'll fix both below.
Step 1: Open the Web Console¶
Navigate to:
Your browser will warn about the certificate. Expected: the AMI uses a self-signed TLS certificate stored at /var/lib/openbao/tls/tls.crt (with its key at /var/lib/openbao/tls/tls.key). Handle the warning according to your own security posture.
Step 2: Initialize the Vault¶
A fresh vault has no master key. Initialization creates one and splits it into key shares.
In the UI, set the number of key shares to split the root key into, and the number of shares required to reconstruct it. For simplicity, the Epok docs use 1 share and 1 required share — fine for evaluation. For anything real, split shares across people and storage locations so no single person or machine can unseal alone.
Submit, then store the output — the root token and the unseal keys — somewhere safe. The root token is full admin access; the unseal keys are the only way to bring the vault back after a restart. Losing both means losing the vault's contents.
Step 3: Unseal¶
Every OpenBao restart seals the vault: encrypted at rest, serving nothing. Unsealing reconstructs the root key so it can serve requests again.
Paste an unseal key into the Unseal Key Portion field and continue. With the 1-of-1 configuration from Step 2, one entry completes the unseal.
Step 4: Log In With the Root Token¶
First login uses the root token from initialization. Enter it on the sign-in screen and you're in — the OpenBao dashboard, connected to your own vault instance on AWS.
From here the UI is yours to explore. The steps below cover what to do first.
The Same Flow From the Terminal¶
Prefer the shell? The identical sequence, over SSH:
Check state at any point:
The -tls-skip-verify flag exists because of the self-signed certificate from Step 1. Same commands, same result as the UI — pick whichever fits your workflow.
First Secret: Enable KV v2 and Store Something¶
Confirm the server responds and see what's mounted:
Enable the versioned key-value engine at the secrets/ path:
Write and read back a test secret:
openbao kv put -tls-skip-verify secrets/mysecret password=mysecretvalue
openbao kv get -tls-skip-verify secrets/mysecret
That round-trip is the core loop: put a secret in, get it back out, access controlled. Day-to-day secret management now happens through whichever interface your team standardizes on — the dashboard you just unsealed, this CLI, or the API.
For the full command reference including userpass authentication, see the OpenBao documentation page.
Vault vs OpenBao: The Short Version¶
If you've used HashiCorp Vault, the flow above is already familiar — initialize, unseal, authenticate, manage KV secrets. That's by design: OpenBao is a community-driven fork of HashiCorp Vault, managed under the Linux Foundation, retaining the core workflow while staying fully open source.
Practical takeaway: skills, tooling patterns, and most documentation transfer between them. Choosing OpenBao gets you that workflow without a vendor-license question attached.
Where Things Live on the Instance¶
Reference paths for the Standalone OpenBao Vault AMI:
| What | Path |
|---|---|
| Server configuration | /var/lib/openbao/config/config.hcl |
| systemd service | /etc/systemd/system/openbao.service |
| TLS certificate | /var/lib/openbao/tls/tls.crt |
| TLS key | /var/lib/openbao/tls/tls.key |
Launch It¶
The Standalone OpenBao Vault AMI ships OpenBao pre-installed with the web UI enabled on port 8200 — everything above runs against a fresh launch with zero additional setup. Launch it in your AWS account and follow the four steps.