- vault.yml was age-encrypted but scripts use ansible-vault commands - Converted to ansible-vault format so vault.sh and get-secret.sh work - Added encryption format change log to docs/secret-vault.md - Verified: vault.sh view and get-secret.sh both working
2.1 KiB
2.1 KiB
Secret Vault
這個 repo 使用 ansible-vault 來保存開發過程中需要的機密資訊。
設計
- 加密檔:
secrets/vault.yml - 本機 vault password file:
~/.config/vault-pass.txt - 管理腳本:
scripts/vault.sh
原則
- 加密後的
secrets/vault.yml可以進 git vault-pass.txt只放在本機,不進 git- 解密後的暫存 plaintext 檔不要提交
加密格式變更紀錄
2026-08-06:從 age 轉換為 ansible-vault
原因:repo 內的 scripts(vault.sh、get-secret.sh)全部使用 ansible-vault 命令,但 vault.yml 原本是 age 加密格式,導致 scripts 無法正常解密。
問題:
- age 加密的 vault.yml 開頭為
age-encryption.org/v1 - ansible-vault 加密的 vault.yml 開頭為
$ANSIBLE_VAULT;1.1;AES256 - 兩者格式不相容,ansible-vault 無法解密 age 格式的檔案
修改內容:
- 使用 age 私鑰(
~/.config/openclaw/age.key)解密 vault.yml - 使用 ansible-vault + vault-pass.txt 重新加密 vault.yml
- 驗證
vault.sh view和get-secret.sh正常運作
驗證結果:
./scripts/vault.sh view # ✅ 正常顯示 vault 內容
./scripts/get-secret.sh http_nodes.bynara.base_url # ✅ 正常讀取單一 secret
影響:
- vault.yml 現在使用 ansible-vault 格式,所有 scripts 可直接使用
- age 私鑰不再需要(除非未來有其他 age 加密需求)
- vault password file(
~/.config/vault-pass.txt)仍然是唯一的解密鑰匙
常用指令
初始化:
./scripts/vault.sh init
檢視:
./scripts/vault.sh view
編輯:
./scripts/vault.sh edit
把一份 plaintext YAML 加密成 vault:
./scripts/vault.sh encrypt /tmp/my-secrets.yml
解密到暫存檔:
./scripts/vault.sh decrypt /tmp/vault.yml
重置 vault key:
./scripts/vault.sh rekey
建議格式
gitea:
base_url: https://gitea.cowbay.org
ssh_url_template: ssh://git@gitea.cowbay.org:2203/{owner}/{repo}.git
account: hermes
email: hermes@ntu.edu.rs
password: ...
api_token: ...