Skip to content

Secrets Manager

The Secrets Manager provides centralized credential storage and secure deployment to the Strato VM. All sensitive data for the OpenClaw infrastructure is managed through a single YAML file on the host, with a web UI integrated into the Control Center.

Architecture

┌─────────────────────┐      SSH + sudo tee       ┌──────────────────────┐
│   Strato Host       │ ─────────────────────────▶ │   Strato VM          │
│                     │                            │                      │
│  /opt/secrets/      │                            │  /opt/openclaw-       │
│    secrets.yml      │                            │    secrets/           │
│    (master store)   │                            │    ├── gitea/.env     │
│                     │                            │    ├── nextcloud/.env │
│  Control Center     │                            │    ├── trading-main/  │
│    :8089/secrets    │                            │    │   .env           │
│    (UI + API)       │                            │    ├── ...            │
│                     │                            │    └── MANIFEST.yml   │
└─────────────────────┘                            └──────────────────────┘

Secrets YAML Structure

The master file at /opt/secrets/secrets.yml holds all credentials:

version: '1.0'
description: OpenClaw Centralized Secrets - All Services
applications:
  gitea:
    description: Gitea Git server - admin, DB, runner, AI token
    secrets:
      GITEA_ADMIN_USER:
        value: "..."
        description: ""
      GITEA_ADMIN_PASSWORD:
        value: "..."
        description: ""
  trading-main:
    description: AI Trading main service - DB, API keys, Redis, Celery, Flower
    secrets:
      ALPHA_VANTAGE_API_KEY:
        value: "..."
        description: ""

Application Groups

Application Keys Description
gitea 12 Git server: admin, PostgreSQL DB, runner token, AI token
nextcloud 7 Cloud storage: admin, MySQL DB
pihole 1 DNS server: web interface password
traefik 3 Reverse proxy: dashboard BasicAuth
website-accounts 9 External API provider account credentials
smb 4 NAS/CIFS share credentials
trading-main 30 AI Trading: DB, API keys, Redis, Celery, Flower
trading-worker 23 Trading worker: DB, Redis, Celery, SMB, Tailscale
trading-api-keys 5 Dedicated API key file for trading workers
openclaw 3 Bot configuration: providers, channels, gateway
lebronsaez-nextcloud 7 Nextcloud: admin, MySQL DB credentials
lebronsaez-nextcloud-db 4 MariaDB: root password, database, user credentials
lebronsaez-gitea 4 Gitea: admin credentials, secret key
lebronsaez-gitea-db 3 PostgreSQL: database, user, password
lebronsaez-gitea-runner 2 Gitea Actions runner: instance URL, token
lebronsaez-pihole 1 Pi-hole web password (legacy)
lebronsaez-traefik 3 Traefik dashboard BasicAuth (legacy)
lebronsaez-portainer 2 Portainer admin credentials
lebronsaez-mailserver 8 Docker Mailserver: accounts, SSL, hostname
lebronsaez-webmail 2 Rainloop webmail credentials
lebronsaez-website-accounts 9 External service account credentials
lebronsaez-smb 4 NAS/CIFS share credentials
lebronsaez-openclaw 22 OpenClaw bot: providers, channels, gateway, AI tokens
Total ~168

VM Deployment

When you click Deploy to VM, the Control Center:

  1. SSHs to the VM as admin using the mounted SSH key
  2. Creates /opt/openclaw-secrets/<app>/ (mode 700, root-only)
  3. Writes .env file per application (mode 600, root-only)
  4. Generates MANIFEST.yml (mode 644, readable by openclaw user)

The manifest lists key names and env file paths — no values.

Using Secrets in Docker Compose

services:
  trading-app:
    env_file:
      - /opt/openclaw-secrets/trading-main/.env
      - /opt/openclaw-secrets/trading-api-keys/.env

API Endpoints

Method Endpoint Description
GET /api/secrets List all apps and secrets (values masked)
POST /api/secrets/apps Create new application group
DELETE /api/secrets/apps/{name} Delete application group
POST /api/secrets/apps/{app}/secrets/{key} Add a secret
PUT /api/secrets/apps/{app}/secrets/{key} Update a secret
DELETE /api/secrets/apps/{app}/secrets/{key} Delete a secret
POST /api/secrets/deploy Deploy all secrets to VM

Security Model

Aspect Implementation
Master store /opt/secrets/secrets.yml on host (root:root, 600)
API masking Values returned as ••••••••xxxx (last 4 chars only)
VM delivery SSH with dedicated key, sudo tee for root-only writes
App env files Mode 600, root:root — not readable by unprivileged users
Manifest Mode 644 — lists key names only, no values
Container mount /opt/secrets mounted read-write into CC container
SSH key Mounted read-only at /root/.ssh/vm-key
Audit All create/update/delete operations logged

UI

The Secrets tab in the Control Center provides:

  • Application listing with description and key count
  • Secret table per app with masked values and value status indicators
  • Add/edit/delete operations for both apps and individual secrets
  • Deploy button with confirmation modal and per-app status reporting