OOpenclawnet
  • Introduction
  • Docs
      • 20260425 concept review
      • 20260503 repo split decision
      • Agent runtime
      • Components
      • Glossary
      • Jobs
      • Memory service proposal
      • Nemoclaw mapping
      • Openclaw mapping
      • Overview
      • Provider model
      • Runtime flow
      • Scenarios s4 s5 plan
      • Secrets vault admin ui
      • Secrets vault azure readiness
      • Secrets vault evolution
      • Secrets vault lifecycle phase4
      • Secrets vault lifecycle phase5
      • Secrets vault phase5
      • Secrets vault phase6
      • Secrets vault threat model
      • Source of truth rules
      • Storage
  • Scripts
  • Sessions
    • RELEASE CHECKLIST
    • Session 2 guide es
    • Session 2 guide
    • Session 3 guide es
    • Session 3 guide
    • Session 4 guide es
    • Session 4 guide
    • Session 5 guide es
    • Session 5 guide
    • Speakers
  • Src
  • Tests
Powered by Docsbook
Docs/Architecture/Secrets vault evolution
Secrets vault azure readinessPreviousSecrets vault lifecycle phase4Next

On this page

  • 1. Context
  • 2. Goals (Phase 1 Scope)
  • 3. Non-Goals (Deferred)
  • 4. Proposed Design
  • 4.1 Vault Façade Interface
  • 4.2 vault:// URI Scheme Resolver
  • 4.3 Caching
  • 4.4 Audit Log Table
  • 4.5 Migration CLI
  • 4.6 DataProtection Purposes (Isolation)
  • 5. Schema Changes
  • 5.1 New Table: SecretAccessAudit
  • 5.2 Existing Secrets Table — Proposed Additions
  • 5.3 SchemaMigrator Integration
  • 6. API Surface for Tools/Agents (Phase 1 — .NET Only)
  • 7. Threat Model
  • 7.1 Prompt Injection → Secret Exfiltration
  • 7.2 Audit Log Tampering
  • 7.3 DataProtection Key Ring Loss
  • 7.4 Cache Poisoning
  • 8. Migration Plan
  • 9. Acceptance Criteria
  • 10. Open Questions
  • 11. References

Was this page helpful?