Files
agent-secret-vault/docs/secret-vault.md
T
Alice (OpenClaw) 0ca8a9aed2 chore: convert vault.yml from age to ansible-vault encryption
- vault.yml was age-encrypted but scripts use ansible-vault commands
- Converted to ansible-vault format so vault.sh and get-secret.sh work
- Added encryption format change log to docs/secret-vault.md
- Verified: vault.sh view and get-secret.sh both working
2026-08-06 15:26:11 +08:00

2.1 KiB
Raw Blame History

Secret Vault

這個 repo 使用 ansible-vault 來保存開發過程中需要的機密資訊。

設計

  • 加密檔:secrets/vault.yml
  • 本機 vault password file:~/.config/vault-pass.txt
  • 管理腳本:scripts/vault.sh

原則

  • 加密後的 secrets/vault.yml 可以進 git
  • vault-pass.txt 只放在本機,不進 git
  • 解密後的暫存 plaintext 檔不要提交

加密格式變更紀錄

2026-08-06:從 age 轉換為 ansible-vault

原因:repo 內的 scripts(vault.sh、get-secret.sh)全部使用 ansible-vault 命令,但 vault.yml 原本是 age 加密格式,導致 scripts 無法正常解密。

問題:

  • age 加密的 vault.yml 開頭為 age-encryption.org/v1
  • ansible-vault 加密的 vault.yml 開頭為 $ANSIBLE_VAULT;1.1;AES256
  • 兩者格式不相容,ansible-vault 無法解密 age 格式的檔案

修改內容:

  1. 使用 age 私鑰(~/.config/openclaw/age.key)解密 vault.yml
  2. 使用 ansible-vault + vault-pass.txt 重新加密 vault.yml
  3. 驗證 vault.sh view 和 get-secret.sh 正常運作

驗證結果:

./scripts/vault.sh view                           # ✅ 正常顯示 vault 內容
./scripts/get-secret.sh http_nodes.bynara.base_url  # ✅ 正常讀取單一 secret

影響:

  • vault.yml 現在使用 ansible-vault 格式,所有 scripts 可直接使用
  • age 私鑰不再需要(除非未來有其他 age 加密需求)
  • vault password file(~/.config/vault-pass.txt)仍然是唯一的解密鑰匙

常用指令

初始化:

./scripts/vault.sh init

檢視:

./scripts/vault.sh view

編輯:

./scripts/vault.sh edit

把一份 plaintext YAML 加密成 vault:

./scripts/vault.sh encrypt /tmp/my-secrets.yml

解密到暫存檔:

./scripts/vault.sh decrypt /tmp/vault.yml

重置 vault key:

./scripts/vault.sh rekey

建議格式

gitea:
  base_url: https://gitea.cowbay.org
  ssh_url_template: ssh://git@gitea.cowbay.org:2203/{owner}/{repo}.git
  account: hermes
  email: hermes@ntu.edu.rs
  password: ...
  api_token: ...