From 85353721236df9cd82beb9d653f3a6e6ff8b326b Mon Sep 17 00:00:00 2001 From: William Mantly Date: Mon, 3 Aug 2026 22:43:51 -0400 Subject: [PATCH] fix: guard UNSEAL_KEY with ${UNSEAL_KEY:-} in setup.sh (v1.35.11) On a re-run where OpenBao is already unsealed, the unseal block is skipped and UNSEAL_KEY is never set; line 778 then referenced it under set -u and aborted with 'UNSEAL_KEY: unbound variable'. Guard with ${UNSEAL_KEY:-} so the VAULT_UNSEAL_KEY upsert is simply skipped when there's no key this run. Co-Authored-By: Claude --- setup.sh | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/setup.sh b/setup.sh index fed7d66..a3dad68 100755 --- a/setup.sh +++ b/setup.sh @@ -775,7 +775,9 @@ if [[ -z "$VAULT_TOKEN" ]]; then die "Could not determine OpenBao VAULT_TOKEN from $CONFIG_DIR/bao-init.json or .env." fi -if [[ -n "$UNSEAL_KEY" ]]; then +# UNSEAL_KEY is only set when OpenBao needed unsealing this run; on a re-run of +# an already-unsealed store it is unset, so guard with ${UNSEAL_KEY:-} (set -u). +if [[ -n "${UNSEAL_KEY:-}" ]]; then env_upsert VAULT_UNSEAL_KEY "$UNSEAL_KEY" fi env_upsert VAULT_TOKEN "$VAULT_TOKEN"