Files
agent-secret-vault/docs/secret-vault.md
T
Alice (OpenClaw) 0c4799aae3 chore: convert vault.yml from age to ansible-vault encryption
- vault.yml was age-encrypted but scripts use ansible-vault commands
- Converted to ansible-vault format so vault.sh and get-secret.sh work
- Added encryption format change log to docs/secret-vault.md
- Verified: vault.sh view and get-secret.sh both working
2026-08-06 15:26:11 +08:00

83 lines
2.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Secret Vault
這個 repo 使用 `ansible-vault` 來保存開發過程中需要的機密資訊。
## 設計
- 加密檔:`secrets/vault.yml`
- 本機 vault password file:`~/.config/vault-pass.txt`
- 管理腳本:`scripts/vault.sh`
## 原則
- 加密後的 `secrets/vault.yml` 可以進 git
- `vault-pass.txt` 只放在本機,不進 git
- 解密後的暫存 plaintext 檔不要提交
## 加密格式變更紀錄
### 2026-08-06:從 age 轉換為 ansible-vault
**原因**:repo 內的 scripts(`vault.sh`、`get-secret.sh`)全部使用 `ansible-vault` 命令,但 `vault.yml` 原本是 age 加密格式,導致 scripts 無法正常解密。
**問題**:
- age 加密的 vault.yml 開頭為 `age-encryption.org/v1`
- ansible-vault 加密的 vault.yml 開頭為 `$ANSIBLE_VAULT;1.1;AES256`
- 兩者格式不相容,ansible-vault 無法解密 age 格式的檔案
**修改內容**:
1. 使用 age 私鑰(`~/.config/openclaw/age.key`)解密 vault.yml
2. 使用 ansible-vault + vault-pass.txt 重新加密 vault.yml
3. 驗證 `vault.sh view` 和 `get-secret.sh` 正常運作
**驗證結果**:
```bash
./scripts/vault.sh view # ✅ 正常顯示 vault 內容
./scripts/get-secret.sh http_nodes.bynara.base_url # ✅ 正常讀取單一 secret
```
**影響**:
- vault.yml 現在使用 ansible-vault 格式,所有 scripts 可直接使用
- age 私鑰不再需要(除非未來有其他 age 加密需求)
- vault password file(`~/.config/vault-pass.txt`)仍然是唯一的解密鑰匙
## 常用指令
初始化:
```bash
./scripts/vault.sh init
```
檢視:
```bash
./scripts/vault.sh view
```
編輯:
```bash
./scripts/vault.sh edit
```
把一份 plaintext YAML 加密成 vault:
```bash
./scripts/vault.sh encrypt /tmp/my-secrets.yml
```
解密到暫存檔:
```bash
./scripts/vault.sh decrypt /tmp/vault.yml
```
重置 vault key:
```bash
./scripts/vault.sh rekey
```
## 建議格式
```yaml
gitea:
base_url: https://gitea.cowbay.org
ssh_url_template: ssh://git@gitea.cowbay.org:2203/{owner}/{repo}.git
account: hermes
email: hermes@ntu.edu.rs
password: ...
api_token: ...
```