Secrets the operator way
Seal the cluster. Unseal with shards. Put KV paths. Workloads pull by reference — passwords never live in committed YAML.
-
KV at rest
AES-256-GCM. Paths and namespaces line up with Aeolus scopes so
demo/db/passwordmeans the same place everywhere. -
Quorum first
Three-node Raft from the start. Kill one node; reads and writes still land on the survivors.
-
mTLS mesh
Nodes authenticate to each other on a private CA. Operators stay off the public CA for the control plane.
Cluster shape
# every node answers; leader elected ladon status sealed=false peers=3 leader=n2 raft=healthy ladon kv put demo/db/password ladon kv get demo/db/password
Same CLI on FreeBSD and CloudBSD. Deploy samples for n1–n3 live under deploy/ in the repo.
Consumed, not embedded
Aeolus ensembles reference Ladon. They do not ship a second secrets database.
services: - name: db image: ghcr.io/cloudbsdorg/aeolus-mariadb:16 secretRef: - ladon: demo/db/password env: MYSQL_PASSWORD
Product landing for the runtime: aeolus.cloudbsd.org. FreeBSD 16 image recipes: cloudbsdorg/aeolus-examples.