Secrets Manager¶
The Secrets Manager provides centralized credential storage and secure deployment to the Strato VM. All sensitive data for the OpenClaw infrastructure is managed through a single YAML file on the host, with a web UI integrated into the Control Center.
Architecture¶
┌─────────────────────┐ SSH + sudo tee ┌──────────────────────┐
│ Strato Host │ ─────────────────────────▶ │ Strato VM │
│ │ │ │
│ /opt/secrets/ │ │ /opt/openclaw- │
│ secrets.yml │ │ secrets/ │
│ (master store) │ │ ├── gitea/.env │
│ │ │ ├── nextcloud/.env │
│ Control Center │ │ ├── trading-main/ │
│ :8089/secrets │ │ │ .env │
│ (UI + API) │ │ ├── ... │
│ │ │ └── MANIFEST.yml │
└─────────────────────┘ └──────────────────────┘
Secrets YAML Structure¶
The master file at /opt/secrets/secrets.yml holds all credentials:
version: '1.0'
description: OpenClaw Centralized Secrets - All Services
applications:
gitea:
description: Gitea Git server - admin, DB, runner, AI token
secrets:
GITEA_ADMIN_USER:
value: "..."
description: ""
GITEA_ADMIN_PASSWORD:
value: "..."
description: ""
trading-main:
description: AI Trading main service - DB, API keys, Redis, Celery, Flower
secrets:
ALPHA_VANTAGE_API_KEY:
value: "..."
description: ""
Application Groups¶
| Application | Keys | Description |
|---|---|---|
gitea |
12 | Git server: admin, PostgreSQL DB, runner token, AI token |
nextcloud |
7 | Cloud storage: admin, MySQL DB |
pihole |
1 | DNS server: web interface password |
traefik |
3 | Reverse proxy: dashboard BasicAuth |
website-accounts |
9 | External API provider account credentials |
smb |
4 | NAS/CIFS share credentials |
trading-main |
30 | AI Trading: DB, API keys, Redis, Celery, Flower |
trading-worker |
23 | Trading worker: DB, Redis, Celery, SMB, Tailscale |
trading-api-keys |
5 | Dedicated API key file for trading workers |
openclaw |
3 | Bot configuration: providers, channels, gateway |
lebronsaez-nextcloud |
7 | Nextcloud: admin, MySQL DB credentials |
lebronsaez-nextcloud-db |
4 | MariaDB: root password, database, user credentials |
lebronsaez-gitea |
4 | Gitea: admin credentials, secret key |
lebronsaez-gitea-db |
3 | PostgreSQL: database, user, password |
lebronsaez-gitea-runner |
2 | Gitea Actions runner: instance URL, token |
lebronsaez-pihole |
1 | Pi-hole web password (legacy) |
lebronsaez-traefik |
3 | Traefik dashboard BasicAuth (legacy) |
lebronsaez-portainer |
2 | Portainer admin credentials |
lebronsaez-mailserver |
8 | Docker Mailserver: accounts, SSL, hostname |
lebronsaez-webmail |
2 | Rainloop webmail credentials |
lebronsaez-website-accounts |
9 | External service account credentials |
lebronsaez-smb |
4 | NAS/CIFS share credentials |
lebronsaez-openclaw |
22 | OpenClaw bot: providers, channels, gateway, AI tokens |
| Total | ~168 |
VM Deployment¶
When you click Deploy to VM, the Control Center:
- SSHs to the VM as
adminusing the mounted SSH key - Creates
/opt/openclaw-secrets/<app>/(mode700, root-only) - Writes
.envfile per application (mode600, root-only) - Generates
MANIFEST.yml(mode644, readable by openclaw user)
The manifest lists key names and env file paths — no values.
Using Secrets in Docker Compose¶
services:
trading-app:
env_file:
- /opt/openclaw-secrets/trading-main/.env
- /opt/openclaw-secrets/trading-api-keys/.env
API Endpoints¶
| Method | Endpoint | Description |
|---|---|---|
GET |
/api/secrets |
List all apps and secrets (values masked) |
POST |
/api/secrets/apps |
Create new application group |
DELETE |
/api/secrets/apps/{name} |
Delete application group |
POST |
/api/secrets/apps/{app}/secrets/{key} |
Add a secret |
PUT |
/api/secrets/apps/{app}/secrets/{key} |
Update a secret |
DELETE |
/api/secrets/apps/{app}/secrets/{key} |
Delete a secret |
POST |
/api/secrets/deploy |
Deploy all secrets to VM |
Security Model¶
| Aspect | Implementation |
|---|---|
| Master store | /opt/secrets/secrets.yml on host (root:root, 600) |
| API masking | Values returned as ••••••••xxxx (last 4 chars only) |
| VM delivery | SSH with dedicated key, sudo tee for root-only writes |
| App env files | Mode 600, root:root — not readable by unprivileged users |
| Manifest | Mode 644 — lists key names only, no values |
| Container mount | /opt/secrets mounted read-write into CC container |
| SSH key | Mounted read-only at /root/.ssh/vm-key |
| Audit | All create/update/delete operations logged |
UI¶
The Secrets tab in the Control Center provides:
- Application listing with description and key count
- Secret table per app with masked values and value status indicators
- Add/edit/delete operations for both apps and individual secrets
- Deploy button with confirmation modal and per-app status reporting