renew-app-tokens.sh only walked ~/.config/openbao/*.token, so the three root-owned tokens were never renewed and lapsed on 2026-07-29: /etc/openbao-backup.token -> nightly raft snapshots failed (403) /etc/openbao-unsealer-backup.token -> same, unsealer instance /etc/openbao-cert-renew.token -> would have failed silently at <21d Nightly backups had been failing for 24 days before this was noticed; the last good snapshot was 2026-07-28. All three tokens have been re-issued as periodic (30d) and the script now covers both sets. The unsealer's token belongs to a separate instance with no published port, so it renews via `docker compose exec` rather than curl -- renewing it against main returns 403. Note `bao token renew` takes no -self flag; the bare form is the renew-self call. Service now runs as root to read /etc, and chowns the log back to lutz. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NFtVLA7VVqXL5G2S18c4Jk
3.3 KiB
Executable File
3.3 KiB
Executable File