Announcing OpenBao v2.6! – Open Source Security Foundation
Download the Free eBook: Built to Last: Understanding the European Cyber Resilience Act (CRA)
Search
Close Search
Announcing OpenBao v2.6!
By OpenSSFAugust 6, 2026Blog, Guest Blog
No Comments
Share Share Share Share<br>Love0
We are thrilled to announce the availability of OpenBao v2.6, adding per-namespace sealing and the new workflow engine for cross-plugin communication!
Our most collaborative release to date, v2.6 features contributions from 42 first-time contributors, 27 individuals contributing multiple changes, and 8 users with double-digit change counts. Simply fantastic work and a big thanks to the community that makes this happen!
Key highlights of this release
We saw many innovative improvements this release:
Namespace Sealing : Allows construction of an additional Shamir seal and scoped barrier keyring on namespace creation to partition tenant storage with distinct cryptographic key material. This allows tenants to revoke instance operator’s access to their namespace via seal operation without impacting other tenants.
Auto Unseal Plugins : Adds a new kms plugin type in the configuration file which enables auto-unseal mechanisms to be distributed as external binary plugins. This allows a decoupled release process and easier adoption of third-party key management systems (KMSes).
Workflows : Adds new endpoints under sys/workflows to allow operators to create multi-request workflows for cross-plugin communication and allows users to execute them. This can unlock in-process, organization-specific native governance of OpenBao or simplified facades over multiple individual pieces of OpenBao functionality.
Distroless container images : Introduces a new container image variant based on distroless/static, available as openbao-distroless. The only executable contained in these images is OpenBao itself.
Authenticated root generation: New sys/generate-root-token endpoints are available as replacements for the deprecated unauthenticated ones.
There were also over 38 other feature improvements to our core plugins; refer to the improvements section of our release notes for information on all of them!
Stay tuned for more great features to come!
Looking ahead
OpenBao v2.7.0 is already shaping up to be an exciting release! Control Groups landed early, allowing human-in-the-loop review of sensitive operations. External keys, a redesign of Vault Enterprise’s Managed Keys, will allow for HSM- and KMS-backed key material in secret engines such as PKI and Transit. And support for PostgreSQL horizontal scalability will bring significant disaster recovery and operator experience improvements over the existing Raft support.
Interested in getting involved? Take a look at our roadmap, fix a bug, help with documentation, join our community calls, publicize the release, or join us on the Linux Foundation’s Zulip instance!
About the Author
Alex Scheel (“cipherboy”) is the Head of OpenBao Development at ControlPlane, a member of the OpenBao Technical Steering Committee, and Chair of the OpenBao Development Working Group. He has built a career on open source contributions, previously working at GitLab with OpenBao, at Keyfactor on Bouncy Castle, at HashiCorp on Vault, and at Canonical and Red Hat. He continues to participate in and give back to the Minnesota arts community and serves as a board member for the Artaria String Quartet.
Comments are closed.<br>-->
We envision a future where OSS is universally trusted, secure, and reliable. Join us in making open source more secure.
Get Involved
Subscribe to the OpenSSF Newsletter!
Get the latest announcements, event info, and the community news in your inbox
twitter<br>bluesky<br>facebook<br>linkedin<br>youtube<br>github<br>slack<br>mastodon
Copyright © 2026 The Linux Foundation® . All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page. Linux is a registered trademark of Linus Torvalds. Privacy Policy and Terms of Use.
Close Menu
About
About Us
Members
Governing Board
Technical Advisory Council
Staff
Antitrust Policy
Brand Guidelines
Contact Us
Projects
AI/ML Security
Compliance
Developer Best Practices
Fuzzing
Repository Security
SBOM Tools
Software Supply Chain
Vulnerability Disclosures
All Projects
Learning
Courses
Guides
Tech Talks
Cybersecurity Skills Framework
Best Practices
Community
Working Groups
Getting Started with OpenSSF
Slack
GitHub
OpenSSF Ambassadors
Developer Relations
Membership Hub
Technical Initiative Funding
Job Board
Store
Code of Conduct
Public Policy
OSS in Public Policy
EU Cyber Resilience Act
Blog & News
Blog
Podcast 🎤
Newsletter
Press Releases
Reports
Case Studies
Events
OpenSSF Events Calendar
Community Calendar
Upcoming CFPs
Town Hall Meetings
Guidelines for Meetups
Join