* refactor(secrets): delegate POSIX plan creation to fs-safe Use released strict file durability while preserving exclusive creation, owner-only output, readable output directory modes and the collision diagnostic. Keep the Windows private creator unchanged. Existing Vault CLI cases pass before and after the cutover; changed checks and independent review pass. * refactor(snapshot): prepare fs-safe ACL batch adoption Delegate Windows owner and DACL transport to readOwnerAndDaclBatch while retaining snapshot trust and access policy. Keep the private Windows creation backend unchanged. Release-blocked: this uses the accepted but unreleased fs-safe batch API. Dependency pins remain unchanged and this branch must not land before a supporting release is adopted. * refactor: delegate atomic text writes to fs-safe |
||
|---|---|---|
| .. | ||
| assets | ||
| src | ||
| index.ts | ||
| openclaw.plugin.json | ||
| package.json | ||
| README.md | ||
| vault-secret-id.d.ts | ||
| vault-secret-id.js | ||
| vault-secret-ref-resolver.js | ||
Vault
Resolve OpenClaw credentials from HashiCorp Vault using SecretRefs. Configuration stores references to Vault fields; resolved secrets stay in the active runtime snapshot instead of being written back into OpenClaw configuration.
Get started
Enable the plugin with openclaw plugins enable vault. Give the Gateway a
reachable VAULT_ADDR and scoped Vault authentication, then check
openclaw vault status.
Use openclaw vault setup --help to select credential targets and generate a
SecretRef plan. Preview the saved plan before applying it:
openclaw secrets apply --from ./vault-secrets-plan.json --dry-run --allow-exec
Follow the guide to apply the reviewed plan and reload secrets.
The resolver supports Vault KV secrets and needs read permission for the selected paths. Enabling the plugin does not provision a Vault server.
See the Vault guide for authentication methods, plan commands, and deployment examples.