Files

108 lines
3.1 KiB
Markdown
Raw Permalink Normal View History

# Vault Secrets Guide
HashiCorp Vault runs in the `silma-ai` k8s namespace on Tabitha. It is the authoritative store for all credentials and API keys in this environment.
---
## Access
| Field | Value |
|-------|-------|
| **Host port** | `18200` (port-forwarded from k8s cluster port 8200) |
| **URL** | `http://localhost:18200` |
| **Root token** | `devroot` |
| **KV engine** | `silma/` (KV v2) |
| **UI** | `http://localhost:18200/ui` |
⚠️ **Requires k8s port-forward to be active.** Run first:
```bash
bash /Users/Tabitha/.openclaw/k8s/silma-ai/scripts/port-forward.sh
```
---
## Quick Access via Helper Script
```bash
cd /Users/Tabitha/.openclaw/workspace
bash scripts/vault.sh read <path>
```
---
## Available Secrets
| Path | Contents |
|------|---------|
| `discord` | `bot_token`, `client_id` |
| `telegram` | `bot_token` |
| `github/silma` | `username`, `pat`, `password` |
| `github/hunter` | `pat` |
| `twitter/silma` | `password` |
| `twitter/blb` | `email`, `password` |
| `buffer` | `email`, `password` |
| `spotify` | `username`, `password`, `client_id`, `client_secret`, `redirect_uri` |
| `google` | `password` |
| `gmail` | `imap_app_password` |
| `zoho` | `mail_password` |
| `aws` | `account_id`, `iam_username`, `iam_password`, `signin_url` |
| `reddit/silma-paws` | `username`, `email`, `password` |
| `reddit/silma-claws` | `username`, `email`, `password` |
| `hackerone` | `email`, `password` |
| `openclaw` | `gateway_token` |
| `patreon/blb` | `email`, `password` |
| `hunter/ngrok` | `creon_secret` |
| `api-keys/gemini` | `api_key` |
| `api-keys/nvidia` | `api_key`, `base_url` |
| `api-keys/runware` | `api_key` |
| `api-keys/eia` | `api_key` |
| `api-keys/airnow` | `api_key` |
| `api-keys/census` | `api_key` |
| `api-keys/noaa` | `token` |
| `api-keys/ticketmaster` | `api_key`, `secret` |
| `api-keys/banner-pyre` | `gemini_api_key`, `gcp_project` |
---
## Reading Secrets (curl)
```bash
VAULT_TOKEN=devroot
VAULT_ADDR=http://localhost:18200
# Read a secret
curl -s -H "X-Vault-Token: $VAULT_TOKEN" \
"$VAULT_ADDR/v1/silma/data/discord" | python3 -m json.tool
# Extract a specific field
curl -s -H "X-Vault-Token: $VAULT_TOKEN" \
"$VAULT_ADDR/v1/silma/data/discord" \
| python3 -c "import sys,json; d=json.load(sys.stdin); print(d['data']['data']['bot_token'])"
# List all secret paths
curl -s -H "X-Vault-Token: $VAULT_TOKEN" \
-X LIST "$VAULT_ADDR/v1/silma/metadata/" \
| python3 -c "import sys,json; d=json.load(sys.stdin); [print(k) for k in d['data']['keys']]"
```
---
## Writing Secrets
```bash
# Write / update a secret
curl -s -H "X-Vault-Token: $VAULT_TOKEN" \
-X POST "$VAULT_ADDR/v1/silma/data/my-secret" \
-H "Content-Type: application/json" \
-d '{"data": {"key": "value"}}'
```
---
## Notes for AI Agents
- Vault is **only reachable on Tabitha** after the k8s port-forward is active
- The root token `devroot` is intentional for this local dev instance — do not rotate it without updating all scripts
- Prefer Vault over `credentials/secrets.env` for any new secrets — `secrets.env` is a fallback for when Vault isn't running
- Do not print or log full secret values — extract only the field you need