OpenBao migration and managed operations

HashiCorp went proprietary. Your Vault doesn't have to.

Move to OpenBao - same API, same workflows, no license fees - and let us migrate, build and run it with you on Swiss infrastructure.

OpenBao is a drop-in fork of HashiCorp Vault under MPL 2.0, governed by the Linux Foundation. The software itself is free. Migrating what you already have, hardening it, and keeping it running at 3am - that's the work.

  • Zerolicense fees, no per-client counting
  • Same APIyour Vault clients and Terraform code keep working
  • 24×7operations on Swiss cloud infrastructure

Platform and security work we've done for

This is for you if

  • Your Vault Enterprise renewal is priced per client identity, and nobody can tell you what next year costs
  • You're stuck on community Vault after the BSL license change, and falling behind on security fixes
  • Your secrets live in CI variables, config files and someone's password manager, and an audit is coming
  • You already run Vault or OpenBao yourself, and nobody on the team wants to be paged when it seals

What we do

From a one-day architecture review to a full migration with 24×7 operations afterwards. Together with VSHN, we cover the whole path.

Vault to OpenBao migration

We map your secrets engines, policies and auth methods onto OpenBao, run both systems in parallel, and validate that every secret is reachable before the old Vault is switched off. Your clients, integrations and Terraform providers keep working without code changes.

Architecture and deployment

Highly available clusters with three replicas and auto-unseal, encrypted storage, least-privilege policies and full audit logging - on cloudscale.ch, Exoscale, APPUiO, Managed OpenShift or your own data center. HSM key custody goes through PKCS#11, including the Swiss Securosys Primus.

Managed operations, 24×7

Not a phone-support subscription. Together with VSHN we design, deploy and operate the cluster, run automated backups, monitor its health and respond to incidents around the clock. Stop working with us and your OpenBao keeps running unchanged.

Integration and enablement

Dynamic database and cloud credentials, PKI certificate issuance, encryption as a service, and OIDC-based access for GitLab, GitHub Actions and Kubernetes workloads. We hand the platform over with the documentation and training your team needs to own it.

What every engagement includes

  • Architecture design and deployment planning for OpenBao
  • Vault to OpenBao migration: secrets engines, policies, auth methods
  • High-availability setup with three replicas and auto-unseal
  • Encrypted storage, strict access controls and complete audit trails
  • Integration with your CI/CD pipelines, Kubernetes and identity provider
  • Deployment on Swiss cloud, private cloud or on-premises - your choice
  • Ongoing 24×7 operational support and incident response
  • Direct access to the engineers who read the OpenBao source, not a ticket queue

OpenBao with us vs. Vault Enterprise

OpenBao is a fork of Vault, not a rewrite. What changes is who owns the license, the bill and the operations.

Vault EnterpriseOpenBao with us
LicenseBusiness Source License, relicensing decided by a single vendorMPL 2.0, governed by the Linux Foundation
Cost modelPer client identity or managed secret, growing as your platform growsNo license fees and no metering - you pay for engineering and operations
FeaturesGated by subscription tierEvery feature available to everyone, HSM support via PKCS#11 included
API and toolingVault API and Terraform providerThe same API - existing clients and Terraform code work unchanged
JurisdictionUS vendor, exposure to the US CLOUD ActSwiss cloud or your own data center, Swiss law, Swiss engineers
If you walk awayThe subscription ends and the platform goes with itYour cluster keeps running unchanged, with nothing to migrate

Swiss, and staying that way

Secrets management is the one system where jurisdiction isn't a detail. Yours stays where you put it.

  • Deployed on Swiss cloud providers such as cloudscale.ch and Exoscale, on your private cloud, or on-premises in your own data center
  • Swiss companies, Swiss law, no foreign parent company and no exposure to the US CLOUD Act
  • Swiss engineers in your time zone - no offshore delivery teams, no subcontractors you never meet

Who you're working with

bespinian is the engineering partner of the OpenBao Competence Center Switzerland, together with VSHN - The DevOps Company. We bring the Go and security engineering: reading the OpenBao source, debugging it, extending it and integrating it into your platform.

VSHN brings the operations side, with ISO 27001-certified processes, ISAE 3402 Type II reports for regulated customers, and 24×7 on-call. A fully managed OpenBao service on the VSHN Application Catalog is in development, with automated provisioning, backups, monitoring and SLAs up to 99.99% availability - ask us for early access.

What it costs

OpenBao itself is free, and stays free no matter how many applications consume secrets. You pay for the engineering and the operations, and you see both numbers before you commit.

  • A free first call to work out whether OpenBao fits your setup at all
  • A written scope and a cost estimate in CHF, usually within one working day of that call
  • Predictable monthly rates for ongoing operations, without metering your secrets or client identities
  • No commitment at the scoping stage - if the answer is that you don't need us, we'll say so
"bespinian joined us during the last phase of the migration and was quickly able to advise and support us in closing the remaining gaps in our monitoring and alarming landscape."

Placi Flury

Head of DevOps, SwissSign

Before you ask

What exactly is OpenBao?

OpenBao is an open-source secrets management platform hosted by the Linux Foundation, forked from HashiCorp Vault when Vault moved from the MPL to the Business Source License. It covers the same ground: key-value secrets, dynamic database and cloud credentials, PKI certificates, encryption as a service, identity-based access control and audit logging. It keeps full API compatibility with Vault, so existing integrations and tooling continue to work.

How risky is the migration from Vault?

Lower than most teams expect, because OpenBao keeps Vault's API and protocol. We map secrets engines, policies and auth methods, run the two systems in parallel during the transition, and verify that every secret is reachable from OpenBao before the old Vault is decommissioned. In most cases your applications and Terraform code need no changes at all.

We use GitLab. Should we wait for GitLab Secrets Manager?

GitLab built its Secrets Manager on OpenBao, which says something about where the ecosystem is going, but two things decide it for you. It runs as a cloud-native component, so on self-managed GitLab you still operate a Kubernetes cluster, a database, a TLS endpoint, key custody and backups. And it holds credentials for GitLab pipelines, while most teams also need secrets for applications, databases and infrastructure outside CI. A dedicated OpenBao covers both, and your GitLab jobs reach it with CI ID tokens over OIDC.

What's the difference between support and managed operations?

A support subscription gives you someone to call when it breaks - you still architect, deploy, patch and operate it yourself. Managed operations means we design the architecture, deploy the HA cluster, configure auto-unseal, run the backups, watch the monitoring and handle incidents 24×7. Either way the deployment is yours: if you stop working with us, it keeps running unchanged.

Can everything stay in Switzerland?

Yes, and that's the default. OpenBao runs on Swiss cloud providers such as cloudscale.ch and Exoscale, both operating their data centers exclusively in Switzerland, or on APPUiO, Managed OpenShift, your private cloud, or on-premises in your own data center. Contracts are governed by Swiss law, and the engineers working on it are here.

Does this help with our audit?

It usually does. OpenBao maps onto several CIS Controls v8 requirements: encryption as a service and AES-256-GCM storage encryption for data protection, policy-based least-privilege access and dynamic credentials with automatic expiry for access control, and an audit log of every secret access as evidence. On the operations side, VSHN runs OpenBao with ISO 27001-certified processes and provides ISAE 3402 Type II reports for regulated customers.

How quickly can we start?

We reply within two working days with a first call. From there, an architecture review is a matter of days, and a full migration usually runs a few weeks depending on how many secrets engines and consumers are involved.

Request a migration assessment

Tell us what you run today and we'll come back within two working days. No newsletter, no follow-up sequence.

No cost, no obligation, no newsletter. We reply within two working days.

Request a migration assessment