Compare commits
11
Commits
main
..
4f54b1573c
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4f54b1573c | ||
|
|
6405aa0bc2 | ||
|
|
aef84d5395 | ||
|
|
524edd148f | ||
|
|
42737ac7ef | ||
|
|
8dce96c985 | ||
|
|
0ca8a9aed2 | ||
|
|
ab00dc71c3 | ||
|
|
25246bcc17 | ||
|
|
758c395334 | ||
|
|
2955c97eea |
@@ -13,8 +13,6 @@ secrets/vault-pass.txt
|
||||
|
||||
# Placeholder marker generated when password archive is absent
|
||||
secrets/vault-pass.txt.zip.PLACEHOLDER
|
||||
# Plaintext vault dumps must never be committed
|
||||
secrets/*.text
|
||||
# Local installer env overrides with real secrets
|
||||
install.local.env
|
||||
*.secret.env
|
||||
|
||||
@@ -11,8 +11,8 @@
|
||||
|
||||
## 目標路徑
|
||||
|
||||
- Repo:`~/agent-secret-vault`
|
||||
- Vault 檔:`~/agent-secret-vault/secrets/vault.yml`
|
||||
- Repo:`~/projects/agent-secret-vault`
|
||||
- Vault 檔:`~/projects/agent-secret-vault/secrets/vault.yml`
|
||||
- Vault password file:`~/.config/vault-pass.txt`
|
||||
- 可覆寫環境變數:`VAULT_PASS_FILE=/custom/path`
|
||||
|
||||
@@ -45,8 +45,8 @@ cd agent-secret-vault
|
||||
若 clone 失敗,建立 placeholder 讓後續步驟可明確回報缺什麼:
|
||||
|
||||
```bash
|
||||
mkdir -p ~/agent-secret-vault/{scripts,secrets,docs}
|
||||
cat > ~/agent-secret-vault/README.PLACEHOLDER.md <<'PLACEHOLDER'
|
||||
mkdir -p ~/projects/agent-secret-vault/{scripts,secrets,docs}
|
||||
cat > ~/projects/agent-secret-vault/README.PLACEHOLDER.md <<'PLACEHOLDER'
|
||||
# Placeholder
|
||||
|
||||
agent-secret-vault repo 尚未成功 clone。
|
||||
@@ -68,7 +68,7 @@ install.env # 安裝用 placeholder
|
||||
安裝前必須先設定 `install.env`(或指定 `INSTALL_ENV_FILE`),不要跳過這一步:
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
cp -n install.env.example install.env
|
||||
editor install.env
|
||||
```
|
||||
@@ -114,7 +114,7 @@ INSTALL_ENV_FILE=install.local.env ./scripts/install-vault-pass.sh
|
||||
執行 installer 前再次確認 env,然後安裝:
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
./scripts/install-vault-pass.sh --check-env
|
||||
./scripts/install-vault-pass.sh
|
||||
```
|
||||
@@ -151,8 +151,8 @@ installer 會先判斷 `~/.config/vault-pass.txt` 是否已存在:
|
||||
建立 placeholder,不要自行編造密碼:
|
||||
|
||||
```bash
|
||||
mkdir -p ~/agent-secret-vault/secrets
|
||||
cat > ~/agent-secret-vault/secrets/vault-pass.txt.zip.PLACEHOLDER <<'PLACEHOLDER'
|
||||
mkdir -p ~/projects/agent-secret-vault/secrets
|
||||
cat > ~/projects/agent-secret-vault/secrets/vault-pass.txt.zip.PLACEHOLDER <<'PLACEHOLDER'
|
||||
Missing file: secrets/vault-pass.txt.zip
|
||||
Purpose: password-protected archive containing vault-pass.txt
|
||||
Action: ask human maintainer to provide this archive or use installer method 1/2/3.
|
||||
@@ -202,7 +202,7 @@ VAULT_PASS_CONTENT="..." \
|
||||
## 4. 驗證安裝
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null
|
||||
```
|
||||
|
||||
@@ -211,7 +211,7 @@ ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.
|
||||
## 5. 讀取單一 secret
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
./scripts/get-secret.sh <dot.path>
|
||||
```
|
||||
|
||||
@@ -227,7 +227,7 @@ cd ~/agent-secret-vault
|
||||
## 6. Worker 需要 env 時
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
umask 077
|
||||
./scripts/render-env.sh gitea > /tmp/gitea.env
|
||||
set -a
|
||||
@@ -243,7 +243,7 @@ rm -f /tmp/gitea.env
|
||||
只有在人類明確要求更新 secrets 時才做:
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
git pull --ff-only
|
||||
./scripts/vault.sh edit
|
||||
ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
|
||||
## 基本資訊
|
||||
|
||||
- vault 位置:`~/agent-secret-vault/secrets/vault.yml`
|
||||
- vault 位置:`~/projects/agent-secret-vault/secrets/vault.yml`
|
||||
- vault password 位置:`~/.config/vault-pass.txt`
|
||||
- 加密格式:ansible-vault(AES256)
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
### 方法 1:用 vault.sh 腳本(推薦)
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
|
||||
# 檢視 vault 內容
|
||||
./scripts/vault.sh view
|
||||
@@ -56,7 +56,7 @@ rm /tmp/gitea.env
|
||||
|
||||
解決:
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
./scripts/vault.sh init
|
||||
```
|
||||
|
||||
|
||||
+18
-13
@@ -43,30 +43,35 @@ flowchart TD
|
||||
J --> K[git push]
|
||||
```
|
||||
|
||||
## 加密格式變更流程
|
||||
|
||||
```mermaid
|
||||
flowchart TD
|
||||
A[發現 vault.yml 是 age 加密] --> B[scripts 用 ansible-vault 無法解密]
|
||||
B --> C[用 age 私鑰解密 vault.yml]
|
||||
C --> D[暫存明文到 /tmp]
|
||||
D --> E[用 ansible-vault 重新加密]
|
||||
E --> F[驗證 vault.sh view 正常]
|
||||
F --> G[驗證 get-secret.sh 正常]
|
||||
G --> H[git commit + push]
|
||||
```
|
||||
|
||||
## Secret 結構
|
||||
|
||||
```mermaid
|
||||
flowchart LR
|
||||
Vault[vault.yml] --> OPEN[openclaw_alice]
|
||||
Vault --> KM[KM_gitea]
|
||||
Vault --> GITEA[gitea]
|
||||
Vault[vault.yml] --> HTTP[http_nodes]
|
||||
Vault --> KUMON[kumon_com_tw]
|
||||
|
||||
OPEN --> HTTP[http_nodes]
|
||||
OPEN --> SSH[ssh_nodes]
|
||||
OPEN --> COWBAY[cowbay_provider]
|
||||
OPEN --> INFRA[infra]
|
||||
|
||||
HTTP --> BYNARA[bynara]
|
||||
HTTP --> GOOGLE[google_ai_studio]
|
||||
HTTP --> NPM[NPM]
|
||||
HTTP --> LINEAR[linear]
|
||||
HTTP --> TAVILY[tavily]
|
||||
HTTP --> MORE[...共 16 個]
|
||||
|
||||
BYNARA --> BY_KEY[api_key]
|
||||
BYNARA --> BY_URL[base_url]
|
||||
|
||||
KUMON --> R2[cloudflare_r2]
|
||||
R2 --> BUCKET[bucket: deyu-imgbed]
|
||||
R2 --> ACC[account_id]
|
||||
R2 --> ZONE[zone_id]
|
||||
R2 --> AK[access_key_id]
|
||||
R2 --> EP[endpoint]
|
||||
R2 --> SK[secret_access_key]
|
||||
|
||||
+4
-4
@@ -62,7 +62,7 @@ installer 會先檢查:
|
||||
維護者若要讓其他 agent / 機器安裝,先在已可解密的機器上執行:
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
./scripts/create-vault-pass-archive.sh
|
||||
git add secrets/vault-pass.txt.zip
|
||||
git commit -m "Add vault password archive"
|
||||
@@ -76,7 +76,7 @@ git push
|
||||
安裝流程要求先填 repo 內的 env 檔:
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
cp -n install.env.example install.env
|
||||
editor install.env
|
||||
./scripts/install-vault-pass.sh --check-env
|
||||
@@ -121,14 +121,14 @@ VAULT_PASS_ZIP_PASSWORD_FILE=/secure/path/zip-password.txt \
|
||||
### 查看 vault
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
./scripts/vault.sh view
|
||||
```
|
||||
|
||||
### 編輯 vault
|
||||
|
||||
```bash
|
||||
cd ~/agent-secret-vault
|
||||
cd ~/projects/agent-secret-vault
|
||||
git pull --ff-only
|
||||
./scripts/vault.sh edit
|
||||
git add secrets/vault.yml
|
||||
|
||||
+470
-685
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user