OpenBao OpenBao Observability
Architecture Concepts Profiles Metrics Logging Audit Dashboards Runbooks Contracts
Search GitHub

Sections

  • Architecture
    • Reference architecture overview
    • Adopt the reference architecture
  • Concepts
    • OpenBao observability model
    • Metrics, logs, and audit logs
    • Active-node and all-node observability
    • High-cardinality and label safety
    • Audit logs as security records
    • OpenBao HA/Raft observability
    • Token and lease observability
    • Namespaces and scale observability
  • Profiles
    • Prometheus, Loki, Grafana, and Alloy profile
    • Run the Docker Compose stack
    • Configure a secure metrics scrape
    • Configure an all-node metrics scrape
    • OpenBao Operator companion profile
    • OpenBao Operator integration contract
  • Metrics
    • Understanding OpenBao metrics
    • Configure a secure metrics scrape
    • Configure an all-node metrics scrape
    • Metric compatibility matrix
    • OpenBao HA/Raft metrics
    • OpenBao token and lease metrics
  • Logging
    • Understanding OpenBao logs
    • Loki label strategy for OpenBao
    • Log retention and access control
    • Audit archive reference design
  • Audit
    • Configure declarative audit devices
    • Audit logs as security records
    • Audit archive reference design
    • OpenBao audit overview dashboard
    • OpenBao audit investigation dashboard
    • Audit request and response failures
    • Audit canary missing
    • Audit archive degraded
  • Dashboards
    • OpenBao overview dashboard
    • OpenBao HA/Raft dashboard
    • OpenBao audit overview dashboard
    • OpenBao audit investigation dashboard
    • OpenBao operational logs dashboard
    • OpenBao auth and identity dashboard
    • OpenBao token and lease lifecycle dashboard
    • OpenBao database secrets dashboard
    • OpenBao Transit dashboard
    • OpenBao PKI dashboard
    • OpenBao secret engines and mounts dashboard
    • OpenBao runtime and storage dashboard
    • OpenBao Kubernetes platform dashboard
    • OpenBao SLO and availability dashboard
  • Runbooks
    • OpenBao metrics scrape failing
    • OpenBao sealed unexpectedly
    • No active OpenBao leader
    • Multiple active OpenBao nodes
    • OpenBao Raft and Autopilot health
    • Audit request and response failures
    • Audit canary missing
    • Audit log stream missing
    • Audit archive degraded
    • Operational log stream missing
    • Debug logging enabled
    • Completed request logging enabled
    • Irrevocable leases present
    • Runtime and storage warnings
    • Secret engine feature warnings
    • Kubernetes platform health
    • SLO and availability
    • Security audit detections
  • Contracts
    • Understand metric prefixes and recording rules

Logging

Use this section to design OpenBao operational log and audit log pipelines without turning sensitive request metadata into unsafe labels or broad access.

Topics

  • Understanding OpenBao logs explains operational logs, completed request logs, and audit logs.
  • Loki label strategy explains safe labels and query-time parsing.
  • Log retention and access control explains retention boundaries for operational and audit records.

Browse

In This Section

Understanding OpenBao logs Use this explainer to understand the OpenBao and platform log streams used by this reference architecture. It is for operators who need to distinguish operational logs, completed … Loki label strategy for OpenBao Use this explainer to choose safe Loki labels for OpenBao logs. It is for operators who need useful log routing and dashboard filters without indexing sensitive or high-cardinality … Log retention and access control Use this explainer to design retention and access boundaries for OpenBao logs. It is for operators who need different handling for operational logs, completed request logs, audit … Audit archive reference design Use this explainer to design a durable audit archive path for OpenBao. It is for platform, security, and compliance teams that need audit evidence beyond short-term dashboard …

On This Page

  • Topics

OpenBao Observability reference architecture documentation, published with Hugo.

Source repository