HashiCorp Vault - The Exit Guide Conversation

Many of the alternatives to IBM’s HashiCorp Vault require retooling: CyberArk, Akeyless, cloud providers’ secrets managers, but one product doesn’t: ControlPlane Enterprise for OpenBao. A continuation of Vault Community Edition, governed under the Linux Foundation’s OpenSSF. The same APIs, the same parameters, under a friendlier, cost-effective package.
Even with forks, it can often be confusing to swap. Should we run MariaDB or MySQL? Valkey or Redis? ControlPlane Enterprise for OpenBao or Vault Enterprise?
We’ve asked Alex Scheel, Head of OpenBao Development at ControlPlane, to discuss how our customers handle the migration and the Vault Exit.
How do organisations find out about OpenBao?
Alex: A lot of the time, if you ask around the engineering or platform teams at an organisation, there’s a strong chance someone already knows about OpenBao. Maybe they’ve followed development on GitHub, seen some posts on social media, or met community members at conferences. Once conversations about OpenBao start within an organisation, we often hear stories of people discovering that it’s already being used by someone close to them. A former colleague of mine once mentioned that when they brought up working on OpenBao, their brother was shocked, as it turns out he’d already been running it at his own job for months!
That momentum isn’t accidental; organisations, particularly in Europe, are actively seeking open source alternatives to avoid dependence on American big tech. OpenBao’s reach is growing rapidly, and we have an active contributor base spanning nearly every continent, although no one from Antarctica yet, as far as I know, haha!
Given its global nature, I’m continually impressed by the people in the community coming together to build something deeply important.
For teams unfamiliar with the ecosystem, how do you explain OpenBao?
Alex: I always start by describing it as being like a password manager for developers within an enterprise. It’s a unified way to bridge identities, whether human, non-human, machine, application, third-party service, static, dynamic, cryptographic, or anything else in between. Essentially, it covers just about any security-critical infrastructure you might depend on from a cloud provider or need for securing a data centre. It is a flexible security toolkit.
What are the main business drivers causing teams to exit HashiCorp Vault?
Alex: Organisations typically come to us with a specific business pain point.
Some organisations have a financial trigger, such as their Vault Enterprise renewal or quote that is significantly more expensive than budgeted. Usually, that’s because of complex client counts that create unpredictable scaling costs or the upcoming usage-based billing for on-prem infrastructure introduces serious financial risk when trying to mitigate security risks.
Operational requirements also drive the conversation; many teams outgrow what Vault Community Edition provides and need proper horizontal scalability, disaster recovery, or FIPS or HSM support. We’ve seen it all and we’ve built that compatibility.
A few are even building out secrets management or identity capabilities for the first-time. We’ve helped organisations audit their existing secrets sprawl, identify critical secrets to migrate and rotate first, and support early adopters of the new platform.
Whatever the starting point, we’re happy to have a conversation around how we can help, whether that looks like supporting OpenBao through our Enterprise for OpenBao offering or conducting consulting engagements around threat modelling and business risk assessments.
For a team ready to adopt OpenBao, what do the initial steps look like?
Alex: Enterprise adoption operates on a model of mutual trust. We don’t just send a quote over and expect organisations to move their most critical infrastructure overnight.
Typically, we recommend starting by building out a new OpenBao deployment for a scoped project, such as a new internal platform that needs agentic identity or a new payment processing flow that requires high-performance, FIPS-certified encryption. This lets your team get hands-on with OpenBao’s features, evaluate real workloads, and build trust in both the solution and our team.
Once a team has completed this phase, how does scaling work?
Alex: You really have unlimited choices. Scaling with ControlPlane’s Enterprise for OpenBao is simple because you don’t need to avoid the third rails of client counts, cluster sizing, or usage-based billing. Depending on your business’s risk profile and timelines, you could migrate existing Vault clusters to OpenBao, or you could spin up new clusters and right-size them to your use cases.
If you need consulting help, ControlPlane has a strong history of customer success in our cloud native and threat modeling and we are capable of supporting you no matter how you choose to adopt.
What’s something unique about OpenBao?
Alex: We, both ControlPlane as a company and the OpenBao community, very much value working in public. So much great collaboration across companies happens on GitHub, Zulip and during our community calls.
That public ethos is reflected in the community’s open governance, which makes OpenBao much more receptive to change. When I was at HashiCorp right before the relicensing, I was trying to build a contribution program for the Vault CryptoSec group to partner with contributors to review and land changes. So when I got involved with OpenBao, we put in place a public RFC process, held weekly community meetings, and split into smaller working groups when topical areas of focus needed closer coordination, such as horizontal scalability or PKCS#11/KMS integrations.
Our community-led governance enables us to respond more quickly and be far more accepting of community-driven innovation and ship features more sustainably at a faster rate.
Our open structure means anyone can make a tangible impact, whether you’re a grizzled Vault veteran looking to finally sand the rough edges, part of an OSPO arm wanting to contribute to an impactful project, or someone just starting out and learning, there’s something for everyone to do. You can make and see meaningful changes in the community, and that’s facilitated by our commercial partnerships with our customers.
You mentioned shipping some new features. What are they?
Alex: Oh my, how much time do you have!?
The community has done a lot, together, to get OpenBao to a point where it is already competitive with Vault Enterprise.
We’ve got horizontal scalability, including upcoming support for PostgreSQL. We’ve already landed namespaces, including original support for strong cryptographic separation between tenants. We’ve shipped PKCS#11 and many other auto-unseal devices, with support for external, HSM- or KMS-backed keys landing soon, and much, much more.
But we’ve also spent a fair bit of time on novel features, including declarative self-initialisation, declarative plugin configuration, core storage improvements such as paginated lists and transactional storage, and ACL improvements, for example, filtering LIST and SCAN (recursive lists) or limiting pagination.
Our roadmap looks fairly aggressive as well. We’ll be expanding the way policies work by adding CEL support to a bunch more places, including in the certificate authentication engine, for fully-customizable authorisation. We’re improving horizontal scalability through lazy-loading of mounts, and considering designs for cross-plugin communication.
And I’m excited for what 2027 and beyond brings to ControlPlane Enterprise for OpenBao.
Next steps?
ControlPlane: If you are ready to assess your secrets management estate, evaluate options for adopting OpenBao, or want to understand more about ControlPlane Enterprise for OpenBao, contact our team to discuss how we can support you and your organisation.
Related blogs

Sovereign Signing: A Self-Hosted Supply Chain with OpenBao, Cosign, and Flux CD

OpenBao - Leadership from the Ground Up
