Secrets Backends in Depth

Secrets Backends showed the lookup order with a file. In production the backend is a secrets manager that keeps credentials encrypted, versioned and audited, and hands them only to an authenticated client. BookNest uses OpenBao 2.7.1 (github.com/openbao/openbao (https://github.com/openbao/openbao 8,286 ), MPL 2.0), the OpenSSF-hosted fork made after HashiCorp moved Vault to the Business Source License. Its API is Vault's, so the HashiCorp provider's VaultBackend (4.8.1, in the official image) works unchanged. bao_up.sh starts a dev server as l2-bao, gives the loader's PostgreSQL 1,289 role a generated password, stores the connection and lets an AppRole read only Airflow 129 's paths:

bao_setup.sh (excerpt): the secret, a read-only policy, and Airflow's AppRoleShell
bao kv put airflow/connections/booknest_loader \
  conn_uri="postgresql://booknest_loader:$PW@l2-pg:5432/booknest" >/dev/null
bao policy write airflow-read - >/dev/null <<'HCL'
path "airflow/data/connections/*" { capabilities = ["read"] }
path "airflow/data/variables/*"   { capabilities = ["read"] }
HCL
bao auth enable approle >/dev/null
bao write auth/approle/role/airflow token_policies=airflow-read token_ttl=15m >/dev/null

docker-compose.vault.yaml sets AIRFLOW__SECRETS__BACKEND to airflow.providers.hashicorp.secrets.vault.VaultBackend on all four Airflow services, with the URL, mount point airflow, auth_type approle and the AppRole's IDs in AIRFLOW__SECRETS__BACKEND_KWARGS:

Output of 54
$ airflow connections list
No data found
$ airflow connections get booknest_loader -o yaml
...
  get_uri: postgres://booknest_loader:<redacted>@l2-pg:5432/booknest
...

The metadata database holds no connection, yet every component resolves it. The CLI printed the password twice, as password and inside get_uri (redacted here by sed), so shell access to an Airflow container equals read access to the vault path. The AppRole's secret_id still reaches Airflow through a .env file only you can read; on a cloud, prefer an identity the platform proves (auth_type kubernetes, aws_iam or gcp, or the AWS 24 and Google secrets backends with the workload's IAM role). Note too that OpenBao 2.x refuses to add audit devices through its API (cannot enable audit device via API): declare them in the server configuration, as bao.hcl does.