openclaw/extensions/vault
Peter Steinberger 90869ccd9c
refactor: share ACL inspection and file writes with fs-safe (#158772)
* refactor(secrets): delegate POSIX plan creation to fs-safe

Use released strict file durability while preserving exclusive creation, owner-only output, readable output directory modes and the collision diagnostic. Keep the Windows private creator unchanged. Existing Vault CLI cases pass before and after the cutover; changed checks and independent review pass.

* refactor(snapshot): prepare fs-safe ACL batch adoption

Delegate Windows owner and DACL transport to readOwnerAndDaclBatch while retaining snapshot trust and access policy. Keep the private Windows creation backend unchanged.

Release-blocked: this uses the accepted but unreleased fs-safe batch API. Dependency pins remain unchanged and this branch must not land before a supporting release is adopted.

* refactor: delegate atomic text writes to fs-safe
2026-09-26 09:52:39 +00:00
..
assets improve(plugins): give bundled logos consistent white icon tiles (#155259) 2026-09-23 19:09:26 -07:00
src refactor: share ACL inspection and file writes with fs-safe (#158772) 2026-09-26 09:52:39 +00:00
index.ts
openclaw.plugin.json feat(plugins): assign one purpose category to every bundled plugin (#142760) 2026-09-10 20:44:20 -07:00
package.json chore(release): close out 2026.9.6 on main (#156869) 2026-09-23 23:02:54 -07:00
README.md feat: show declared plugin capabilities and setup guides (#157956) 2026-09-25 16:43:53 -07:00
vault-secret-id.d.ts
vault-secret-id.js
vault-secret-ref-resolver.js

Vault

Resolve OpenClaw credentials from HashiCorp Vault using SecretRefs. Configuration stores references to Vault fields; resolved secrets stay in the active runtime snapshot instead of being written back into OpenClaw configuration.

Get started

Enable the plugin with openclaw plugins enable vault. Give the Gateway a reachable VAULT_ADDR and scoped Vault authentication, then check openclaw vault status.

Use openclaw vault setup --help to select credential targets and generate a SecretRef plan. Preview the saved plan before applying it:

openclaw secrets apply --from ./vault-secrets-plan.json --dry-run --allow-exec

Follow the guide to apply the reviewed plan and reload secrets.

The resolver supports Vault KV secrets and needs read permission for the selected paths. Enabling the plugin does not provision a Vault server.

See the Vault guide for authentication methods, plan commands, and deployment examples.