Compare commits

..
11 Commits
Author SHA1 Message Date
Alice (OpenClaw) 4f54b1573c security: remove plaintext vault.yml.text from repo 2026-08-06 16:48:23 +08:00
Alice (OpenClaw) 6405aa0bc2 feat: add kumon_com_tw.cloudflare_r2 with bucket deyu-imgbed 2026-08-06 16:39:47 +08:00
Alice (OpenClaw) aef84d5395 feat: add KM_gitea credentials to vault 2026-08-06 16:00:02 +08:00
Alice (OpenClaw) 524edd148f feat: sync full vault content from vault.yml.text
- Merged all secrets from vault.yml.text into vault.yml
- Includes: openclaw_alice (http_nodes, ssh_nodes, cowbay_provider, infra), gitea
- Encrypted with ansible-vault
2026-08-06 15:50:59 +08:00
Alice (OpenClaw) 42737ac7ef docs: add flowchart for vault setup and usage workflow 2026-08-06 15:33:02 +08:00
Alice (OpenClaw) 8dce96c985 feat: add kumon.com.tw cloudflare_r2 credentials to vault 2026-08-06 15:31:52 +08:00
Alice (OpenClaw) 0ca8a9aed2 chore: convert vault.yml from age to ansible-vault encryption
- vault.yml was age-encrypted but scripts use ansible-vault commands
- Converted to ansible-vault format so vault.sh and get-secret.sh work
- Added encryption format change log to docs/secret-vault.md
- Verified: vault.sh view and get-secret.sh both working
2026-08-06 15:26:11 +08:00
hermes ab00dc71c3 Add google_ai_studio API key to vault 2026-06-25 11:52:11 +08:00
hermes 25246bcc17 add bynara router provider credentials 2026-06-24 11:34:20 +08:00
hermes 758c395334 Add Twinkle Hub MCP secret 2026-06-03 08:12:57 +08:00
hermes 2955c97eea Sync vault from vault.yml.text 2026-05-22 16:36:44 +08:00
6 changed files with 507 additions and 719 deletions
-2
View File
@@ -13,8 +13,6 @@ secrets/vault-pass.txt
# Placeholder marker generated when password archive is absent # Placeholder marker generated when password archive is absent
secrets/vault-pass.txt.zip.PLACEHOLDER secrets/vault-pass.txt.zip.PLACEHOLDER
# Plaintext vault dumps must never be committed
secrets/*.text
# Local installer env overrides with real secrets # Local installer env overrides with real secrets
install.local.env install.local.env
*.secret.env *.secret.env
+12 -12
View File
@@ -11,8 +11,8 @@
## 目標路徑 ## 目標路徑
- Repo:`~/agent-secret-vault` - Repo:`~/projects/agent-secret-vault`
- Vault 檔:`~/agent-secret-vault/secrets/vault.yml` - Vault 檔:`~/projects/agent-secret-vault/secrets/vault.yml`
- Vault password file:`~/.config/vault-pass.txt` - Vault password file:`~/.config/vault-pass.txt`
- 可覆寫環境變數:`VAULT_PASS_FILE=/custom/path` - 可覆寫環境變數:`VAULT_PASS_FILE=/custom/path`
@@ -45,8 +45,8 @@ cd agent-secret-vault
若 clone 失敗,建立 placeholder 讓後續步驟可明確回報缺什麼: 若 clone 失敗,建立 placeholder 讓後續步驟可明確回報缺什麼:
```bash ```bash
mkdir -p ~/agent-secret-vault/{scripts,secrets,docs} mkdir -p ~/projects/agent-secret-vault/{scripts,secrets,docs}
cat > ~/agent-secret-vault/README.PLACEHOLDER.md <<'PLACEHOLDER' cat > ~/projects/agent-secret-vault/README.PLACEHOLDER.md <<'PLACEHOLDER'
# Placeholder # Placeholder
agent-secret-vault repo 尚未成功 clone。 agent-secret-vault repo 尚未成功 clone。
@@ -68,7 +68,7 @@ install.env # 安裝用 placeholder
安裝前必須先設定 `install.env`(或指定 `INSTALL_ENV_FILE`),不要跳過這一步: 安裝前必須先設定 `install.env`(或指定 `INSTALL_ENV_FILE`),不要跳過這一步:
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
cp -n install.env.example install.env cp -n install.env.example install.env
editor install.env editor install.env
``` ```
@@ -114,7 +114,7 @@ INSTALL_ENV_FILE=install.local.env ./scripts/install-vault-pass.sh
執行 installer 前再次確認 env,然後安裝: 執行 installer 前再次確認 env,然後安裝:
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
./scripts/install-vault-pass.sh --check-env ./scripts/install-vault-pass.sh --check-env
./scripts/install-vault-pass.sh ./scripts/install-vault-pass.sh
``` ```
@@ -151,8 +151,8 @@ installer 會先判斷 `~/.config/vault-pass.txt` 是否已存在:
建立 placeholder,不要自行編造密碼: 建立 placeholder,不要自行編造密碼:
```bash ```bash
mkdir -p ~/agent-secret-vault/secrets mkdir -p ~/projects/agent-secret-vault/secrets
cat > ~/agent-secret-vault/secrets/vault-pass.txt.zip.PLACEHOLDER <<'PLACEHOLDER' cat > ~/projects/agent-secret-vault/secrets/vault-pass.txt.zip.PLACEHOLDER <<'PLACEHOLDER'
Missing file: secrets/vault-pass.txt.zip Missing file: secrets/vault-pass.txt.zip
Purpose: password-protected archive containing vault-pass.txt Purpose: password-protected archive containing vault-pass.txt
Action: ask human maintainer to provide this archive or use installer method 1/2/3. Action: ask human maintainer to provide this archive or use installer method 1/2/3.
@@ -202,7 +202,7 @@ VAULT_PASS_CONTENT="..." \
## 4. 驗證安裝 ## 4. 驗證安裝
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null
``` ```
@@ -211,7 +211,7 @@ ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.
## 5. 讀取單一 secret ## 5. 讀取單一 secret
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
./scripts/get-secret.sh <dot.path> ./scripts/get-secret.sh <dot.path>
``` ```
@@ -227,7 +227,7 @@ cd ~/agent-secret-vault
## 6. Worker 需要 env 時 ## 6. Worker 需要 env 時
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
umask 077 umask 077
./scripts/render-env.sh gitea > /tmp/gitea.env ./scripts/render-env.sh gitea > /tmp/gitea.env
set -a set -a
@@ -243,7 +243,7 @@ rm -f /tmp/gitea.env
只有在人類明確要求更新 secrets 時才做: 只有在人類明確要求更新 secrets 時才做:
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
git pull --ff-only git pull --ff-only
./scripts/vault.sh edit ./scripts/vault.sh edit
ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null ansible-vault view secrets/vault.yml --vault-password-file ~/.config/vault-pass.txt >/dev/null
+3 -3
View File
@@ -4,7 +4,7 @@
## 基本資訊 ## 基本資訊
- vault 位置:`~/agent-secret-vault/secrets/vault.yml` - vault 位置:`~/projects/agent-secret-vault/secrets/vault.yml`
- vault password 位置:`~/.config/vault-pass.txt` - vault password 位置:`~/.config/vault-pass.txt`
- 加密格式:ansible-vault(AES256) - 加密格式:ansible-vault(AES256)
@@ -13,7 +13,7 @@
### 方法 1:用 vault.sh 腳本(推薦) ### 方法 1:用 vault.sh 腳本(推薦)
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
# 檢視 vault 內容 # 檢視 vault 內容
./scripts/vault.sh view ./scripts/vault.sh view
@@ -56,7 +56,7 @@ rm /tmp/gitea.env
解決: 解決:
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
./scripts/vault.sh init ./scripts/vault.sh init
``` ```
+18 -13
View File
@@ -43,30 +43,35 @@ flowchart TD
J --> K[git push] J --> K[git push]
``` ```
## 加密格式變更流程
```mermaid
flowchart TD
A[發現 vault.yml 是 age 加密] --> B[scripts 用 ansible-vault 無法解密]
B --> C[用 age 私鑰解密 vault.yml]
C --> D[暫存明文到 /tmp]
D --> E[用 ansible-vault 重新加密]
E --> F[驗證 vault.sh view 正常]
F --> G[驗證 get-secret.sh 正常]
G --> H[git commit + push]
```
## Secret 結構 ## Secret 結構
```mermaid ```mermaid
flowchart LR flowchart LR
Vault[vault.yml] --> OPEN[openclaw_alice] Vault[vault.yml] --> HTTP[http_nodes]
Vault --> KM[KM_gitea]
Vault --> GITEA[gitea]
Vault --> KUMON[kumon_com_tw] Vault --> KUMON[kumon_com_tw]
OPEN --> HTTP[http_nodes]
OPEN --> SSH[ssh_nodes]
OPEN --> COWBAY[cowbay_provider]
OPEN --> INFRA[infra]
HTTP --> BYNARA[bynara] HTTP --> BYNARA[bynara]
HTTP --> GOOGLE[google_ai_studio] HTTP --> GOOGLE[google_ai_studio]
HTTP --> NPM[NPM]
HTTP --> LINEAR[linear] BYNARA --> BY_KEY[api_key]
HTTP --> TAVILY[tavily] BYNARA --> BY_URL[base_url]
HTTP --> MORE[...共 16 個]
KUMON --> R2[cloudflare_r2] KUMON --> R2[cloudflare_r2]
R2 --> BUCKET[bucket: deyu-imgbed]
R2 --> ACC[account_id] R2 --> ACC[account_id]
R2 --> ZONE[zone_id]
R2 --> AK[access_key_id] R2 --> AK[access_key_id]
R2 --> EP[endpoint] R2 --> EP[endpoint]
R2 --> SK[secret_access_key] R2 --> SK[secret_access_key]
+4 -4
View File
@@ -62,7 +62,7 @@ installer 會先檢查:
維護者若要讓其他 agent / 機器安裝,先在已可解密的機器上執行: 維護者若要讓其他 agent / 機器安裝,先在已可解密的機器上執行:
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
./scripts/create-vault-pass-archive.sh ./scripts/create-vault-pass-archive.sh
git add secrets/vault-pass.txt.zip git add secrets/vault-pass.txt.zip
git commit -m "Add vault password archive" git commit -m "Add vault password archive"
@@ -76,7 +76,7 @@ git push
安裝流程要求先填 repo 內的 env 檔: 安裝流程要求先填 repo 內的 env 檔:
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
cp -n install.env.example install.env cp -n install.env.example install.env
editor install.env editor install.env
./scripts/install-vault-pass.sh --check-env ./scripts/install-vault-pass.sh --check-env
@@ -121,14 +121,14 @@ VAULT_PASS_ZIP_PASSWORD_FILE=/secure/path/zip-password.txt \
### 查看 vault ### 查看 vault
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
./scripts/vault.sh view ./scripts/vault.sh view
``` ```
### 編輯 vault ### 編輯 vault
```bash ```bash
cd ~/agent-secret-vault cd ~/projects/agent-secret-vault
git pull --ff-only git pull --ff-only
./scripts/vault.sh edit ./scripts/vault.sh edit
git add secrets/vault.yml git add secrets/vault.yml
+470 -685
View File
File diff suppressed because it is too large Load Diff