Compare commits
26
Commits
4f54b1573c
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c50ceaad68 | ||
|
|
2a4619f457 | ||
|
|
d0ac6db8aa | ||
|
|
9913e88b27 | ||
|
|
ec36a1e16f | ||
|
|
308a5b921a | ||
|
|
0b536694ec | ||
|
|
64061d486c | ||
|
|
e4171959b8 | ||
|
|
74cec3583d | ||
|
|
67f4932ebd | ||
|
|
2e35c69e78 | ||
|
|
ba82787ba5 | ||
|
|
4ca6a3611d | ||
|
|
f3965bd045 | ||
|
|
2cd4ad0b11 | ||
|
|
b4d8f377a2 | ||
|
|
956d2fd719 | ||
|
|
1bc9c81bf8 | ||
|
|
c8e8f60039 | ||
|
|
b98aa2898a | ||
|
|
0c4799aae3 | ||
|
|
b0abb74c66 | ||
|
|
2c7a4e7c3c | ||
|
|
351e735a43 | ||
|
|
f6891c5be5 |
@@ -13,6 +13,8 @@ secrets/vault-pass.txt
|
|||||||
|
|
||||||
# Placeholder marker generated when password archive is absent
|
# Placeholder marker generated when password archive is absent
|
||||||
secrets/vault-pass.txt.zip.PLACEHOLDER
|
secrets/vault-pass.txt.zip.PLACEHOLDER
|
||||||
|
# Plaintext vault dumps must never be committed
|
||||||
|
secrets/*.text
|
||||||
# Local installer env overrides with real secrets
|
# Local installer env overrides with real secrets
|
||||||
install.local.env
|
install.local.env
|
||||||
*.secret.env
|
*.secret.env
|
||||||
|
|||||||
@@ -11,8 +11,8 @@
|
|||||||
|
|
||||||
## 目標路徑
|
## 目標路徑
|
||||||
|
|
||||||
- Repo:`~/projects/agent-secret-vault`
|
- Repo:`~/agent-secret-vault`
|
||||||
- Vault 檔:`~/projects/agent-secret-vault/secrets/vault.yml`
|
- Vault 檔:`~/agent-secret-vault/secrets/vault.yml`
|
||||||
- Vault password file:`~/.config/vault-pass.txt`
|
- Vault password file:`~/.config/vault-pass.txt`
|
||||||
- 可覆寫環境變數:`VAULT_PASS_FILE=/custom/path`
|
- 可覆寫環境變數:`VAULT_PASS_FILE=/custom/path`
|
||||||
|
|
||||||
@@ -45,8 +45,8 @@ cd agent-secret-vault
|
|||||||
若 clone 失敗,建立 placeholder 讓後續步驟可明確回報缺什麼:
|
若 clone 失敗,建立 placeholder 讓後續步驟可明確回報缺什麼:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mkdir -p ~/projects/agent-secret-vault/{scripts,secrets,docs}
|
mkdir -p ~/agent-secret-vault/{scripts,secrets,docs}
|
||||||
cat > ~/projects/agent-secret-vault/README.PLACEHOLDER.md <<'PLACEHOLDER'
|
cat > ~/agent-secret-vault/README.PLACEHOLDER.md <<'PLACEHOLDER'
|
||||||
# Placeholder
|
# Placeholder
|
||||||
|
|
||||||
agent-secret-vault repo 尚未成功 clone。
|
agent-secret-vault repo 尚未成功 clone。
|
||||||
@@ -68,7 +68,7 @@ install.env # 安裝用 placeholder
|
|||||||
安裝前必須先設定 `install.env`(或指定 `INSTALL_ENV_FILE`),不要跳過這一步:
|
安裝前必須先設定 `install.env`(或指定 `INSTALL_ENV_FILE`),不要跳過這一步:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
cp -n install.env.example install.env
|
cp -n install.env.example install.env
|
||||||
editor install.env
|
editor install.env
|
||||||
```
|
```
|
||||||
@@ -114,7 +114,7 @@ INSTALL_ENV_FILE=install.local.env ./scripts/install-vault-pass.sh
|
|||||||
執行 installer 前再次確認 env,然後安裝:
|
執行 installer 前再次確認 env,然後安裝:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
./scripts/install-vault-pass.sh --check-env
|
./scripts/install-vault-pass.sh --check-env
|
||||||
./scripts/install-vault-pass.sh
|
./scripts/install-vault-pass.sh
|
||||||
```
|
```
|
||||||
@@ -151,8 +151,8 @@ installer 會先判斷 `~/.config/vault-pass.txt` 是否已存在:
|
|||||||
建立 placeholder,不要自行編造密碼:
|
建立 placeholder,不要自行編造密碼:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mkdir -p ~/projects/agent-secret-vault/secrets
|
mkdir -p ~/agent-secret-vault/secrets
|
||||||
cat > ~/projects/agent-secret-vault/secrets/vault-pass.txt.zip.PLACEHOLDER <<'PLACEHOLDER'
|
cat > ~/agent-secret-vault/secrets/vault-pass.txt.zip.PLACEHOLDER <<'PLACEHOLDER'
|
||||||
Missing file: secrets/vault-pass.txt.zip
|
Missing file: secrets/vault-pass.txt.zip
|
||||||
Purpose: password-protected archive containing vault-pass.txt
|
Purpose: password-protected archive containing vault-pass.txt
|
||||||
Action: ask human maintainer to provide this archive or use installer method 1/2/3.
|
Action: ask human maintainer to provide this archive or use installer method 1/2/3.
|
||||||
@@ -202,7 +202,7 @@ VAULT_PASS_CONTENT="..." \
|
|||||||
## 4. 驗證安裝
|
## 4. 驗證安裝
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null
|
ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -211,7 +211,7 @@ ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.
|
|||||||
## 5. 讀取單一 secret
|
## 5. 讀取單一 secret
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
./scripts/get-secret.sh <dot.path>
|
./scripts/get-secret.sh <dot.path>
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -227,7 +227,7 @@ cd ~/projects/agent-secret-vault
|
|||||||
## 6. Worker 需要 env 時
|
## 6. Worker 需要 env 時
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
umask 077
|
umask 077
|
||||||
./scripts/render-env.sh gitea > /tmp/gitea.env
|
./scripts/render-env.sh gitea > /tmp/gitea.env
|
||||||
set -a
|
set -a
|
||||||
@@ -243,7 +243,7 @@ rm -f /tmp/gitea.env
|
|||||||
只有在人類明確要求更新 secrets 時才做:
|
只有在人類明確要求更新 secrets 時才做:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
git pull --ff-only
|
git pull --ff-only
|
||||||
./scripts/vault.sh edit
|
./scripts/vault.sh edit
|
||||||
ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null
|
ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null
|
||||||
|
|||||||
@@ -4,7 +4,7 @@
|
|||||||
|
|
||||||
## 基本資訊
|
## 基本資訊
|
||||||
|
|
||||||
- vault 位置:`~/projects/agent-secret-vault/secrets/vault.yml`
|
- vault 位置:`~/agent-secret-vault/secrets/vault.yml`
|
||||||
- vault password 位置:`~/.config/vault-pass.txt`
|
- vault password 位置:`~/.config/vault-pass.txt`
|
||||||
- 加密格式:ansible-vault(AES256)
|
- 加密格式:ansible-vault(AES256)
|
||||||
|
|
||||||
@@ -13,7 +13,7 @@
|
|||||||
### 方法 1:用 vault.sh 腳本(推薦)
|
### 方法 1:用 vault.sh 腳本(推薦)
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
|
|
||||||
# 檢視 vault 內容
|
# 檢視 vault 內容
|
||||||
./scripts/vault.sh view
|
./scripts/vault.sh view
|
||||||
@@ -56,7 +56,7 @@ rm /tmp/gitea.env
|
|||||||
|
|
||||||
解決:
|
解決:
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
./scripts/vault.sh init
|
./scripts/vault.sh init
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,73 @@
|
|||||||
|
# Agent Secret Vault 流程圖
|
||||||
|
|
||||||
|
## 安裝流程
|
||||||
|
|
||||||
|
```mermaid
|
||||||
|
flowchart TD
|
||||||
|
A[開始] --> B[git clone repo]
|
||||||
|
B --> C{vault-pass.txt 存在?}
|
||||||
|
C -->|是| D[驗證 vault 可解密]
|
||||||
|
C -->|否| E[選擇安裝方式]
|
||||||
|
|
||||||
|
E --> E1[建立新密碼]
|
||||||
|
E --> E2[手動輸入]
|
||||||
|
E --> E3[從 URL 下載]
|
||||||
|
E --> E4[從 zip 解壓]
|
||||||
|
|
||||||
|
E1 --> F[產生 vault-pass.txt]
|
||||||
|
E2 --> F
|
||||||
|
E3 --> F
|
||||||
|
E4 --> F
|
||||||
|
|
||||||
|
F --> D
|
||||||
|
D -->|成功| G[安裝完成]
|
||||||
|
D -->|失敗| H[檢查 vault-pass.txt 內容]
|
||||||
|
H --> F
|
||||||
|
```
|
||||||
|
|
||||||
|
## 日常使用流程
|
||||||
|
|
||||||
|
```mermaid
|
||||||
|
flowchart TD
|
||||||
|
A[開始] --> B[cd agent-secret-vault]
|
||||||
|
B --> C{要做什么?}
|
||||||
|
|
||||||
|
C -->|查看 vault| D[./scripts/vault.sh view]
|
||||||
|
C -->|讀取單一 secret| E[./scripts/get-secret.sh key.path]
|
||||||
|
C -->|編輯 vault| F[./scripts/vault.sh edit]
|
||||||
|
C -->|更新 secret| G[git pull → edit → git push]
|
||||||
|
|
||||||
|
F --> H[編輯完成]
|
||||||
|
H --> I[git add secrets/vault.yml]
|
||||||
|
I --> J[git commit]
|
||||||
|
J --> K[git push]
|
||||||
|
```
|
||||||
|
|
||||||
|
## Secret 結構
|
||||||
|
|
||||||
|
```mermaid
|
||||||
|
flowchart LR
|
||||||
|
Vault[vault.yml] --> OPEN[openclaw_alice]
|
||||||
|
Vault --> KM[KM_gitea]
|
||||||
|
Vault --> GITEA[gitea]
|
||||||
|
Vault --> KUMON[kumon_com_tw]
|
||||||
|
|
||||||
|
OPEN --> HTTP[http_nodes]
|
||||||
|
OPEN --> SSH[ssh_nodes]
|
||||||
|
OPEN --> COWBAY[cowbay_provider]
|
||||||
|
OPEN --> INFRA[infra]
|
||||||
|
|
||||||
|
HTTP --> BYNARA[bynara]
|
||||||
|
HTTP --> GOOGLE[google_ai_studio]
|
||||||
|
HTTP --> NPM[NPM]
|
||||||
|
HTTP --> LINEAR[linear]
|
||||||
|
HTTP --> TAVILY[tavily]
|
||||||
|
HTTP --> MORE[...共 16 個]
|
||||||
|
|
||||||
|
KUMON --> R2[cloudflare_r2]
|
||||||
|
R2 --> BUCKET[bucket: deyu-imgbed]
|
||||||
|
R2 --> ACC[account_id]
|
||||||
|
R2 --> AK[access_key_id]
|
||||||
|
R2 --> EP[endpoint]
|
||||||
|
R2 --> SK[secret_access_key]
|
||||||
|
```
|
||||||
+4
-4
@@ -62,7 +62,7 @@ installer 會先檢查:
|
|||||||
維護者若要讓其他 agent / 機器安裝,先在已可解密的機器上執行:
|
維護者若要讓其他 agent / 機器安裝,先在已可解密的機器上執行:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
./scripts/create-vault-pass-archive.sh
|
./scripts/create-vault-pass-archive.sh
|
||||||
git add secrets/vault-pass.txt.zip
|
git add secrets/vault-pass.txt.zip
|
||||||
git commit -m "Add vault password archive"
|
git commit -m "Add vault password archive"
|
||||||
@@ -76,7 +76,7 @@ git push
|
|||||||
安裝流程要求先填 repo 內的 env 檔:
|
安裝流程要求先填 repo 內的 env 檔:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
cp -n install.env.example install.env
|
cp -n install.env.example install.env
|
||||||
editor install.env
|
editor install.env
|
||||||
./scripts/install-vault-pass.sh --check-env
|
./scripts/install-vault-pass.sh --check-env
|
||||||
@@ -121,14 +121,14 @@ VAULT_PASS_ZIP_PASSWORD_FILE=/secure/path/zip-password.txt \
|
|||||||
### 查看 vault
|
### 查看 vault
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
./scripts/vault.sh view
|
./scripts/vault.sh view
|
||||||
```
|
```
|
||||||
|
|
||||||
### 編輯 vault
|
### 編輯 vault
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/projects/agent-secret-vault
|
cd ~/agent-secret-vault
|
||||||
git pull --ff-only
|
git pull --ff-only
|
||||||
./scripts/vault.sh edit
|
./scripts/vault.sh edit
|
||||||
git add secrets/vault.yml
|
git add secrets/vault.yml
|
||||||
|
|||||||
@@ -12,6 +12,33 @@
|
|||||||
- `vault-pass.txt` 只放在本機,不進 git
|
- `vault-pass.txt` 只放在本機,不進 git
|
||||||
- 解密後的暫存 plaintext 檔不要提交
|
- 解密後的暫存 plaintext 檔不要提交
|
||||||
|
|
||||||
|
## 加密格式變更紀錄
|
||||||
|
|
||||||
|
### 2026-08-06:從 age 轉換為 ansible-vault
|
||||||
|
|
||||||
|
**原因**:repo 內的 scripts(`vault.sh`、`get-secret.sh`)全部使用 `ansible-vault` 命令,但 `vault.yml` 原本是 age 加密格式,導致 scripts 無法正常解密。
|
||||||
|
|
||||||
|
**問題**:
|
||||||
|
- age 加密的 vault.yml 開頭為 `age-encryption.org/v1`
|
||||||
|
- ansible-vault 加密的 vault.yml 開頭為 `$ANSIBLE_VAULT;1.1;AES256`
|
||||||
|
- 兩者格式不相容,ansible-vault 無法解密 age 格式的檔案
|
||||||
|
|
||||||
|
**修改內容**:
|
||||||
|
1. 使用 age 私鑰(`~/.config/openclaw/age.key`)解密 vault.yml
|
||||||
|
2. 使用 ansible-vault + vault-pass.txt 重新加密 vault.yml
|
||||||
|
3. 驗證 `vault.sh view` 和 `get-secret.sh` 正常運作
|
||||||
|
|
||||||
|
**驗證結果**:
|
||||||
|
```bash
|
||||||
|
./scripts/vault.sh view # ✅ 正常顯示 vault 內容
|
||||||
|
./scripts/get-secret.sh http_nodes.bynara.base_url # ✅ 正常讀取單一 secret
|
||||||
|
```
|
||||||
|
|
||||||
|
**影響**:
|
||||||
|
- vault.yml 現在使用 ansible-vault 格式,所有 scripts 可直接使用
|
||||||
|
- age 私鑰不再需要(除非未來有其他 age 加密需求)
|
||||||
|
- vault password file(`~/.config/vault-pass.txt`)仍然是唯一的解密鑰匙
|
||||||
|
|
||||||
## 常用指令
|
## 常用指令
|
||||||
初始化:
|
初始化:
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
+685
-485
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user