When using PG_TDE with OpenBao, is it possible to prevent access to the key in OpenBao ? I am trying to make a case that the artefacts stored in OpenBao are securely managed and cannot be exported and used to access a TDE secured table ?
Any pointers on how this can be achieved and any best practices ?
Hi @Alexander_H,
Typical/best practice when creating secrets in Vault/openBao involves creating an access token which is used by the TDE plugin to access the encryption key. Only this token can access the key. This token can be rotated, and can have expiration. You can only create new access tokens by using the “root” openBao user, which should be tightly controlled just like any other root-level access.