Unifies the GitHub Pages docs site: the SSO/Proxy/Jump Host pages, their
nav labels, and each component's own README now consistently say Theta
Directory / Theta Proxy / Theta Gateway, drop marketing sections ("Why this
over the alternatives", "Get it", "Related projects") that don't apply to a
suite component, remove every standalone/bare-metal install path, and link
to theta42.github.io/theta-suite/... instead of the old per-repo Pages sites.
Bumps submodules: theta-directory v2.0.2, proxy v2.0.1, jump-host v2.0.1.
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2.5 KiB
layout, title, nav_order
| layout | title | nav_order |
|---|---|---|
| default | Secrets Vault | 6 |
Secrets Vault
Theta Directory integrates natively with OpenBao (a Vault fork) to securely manage and store sensitive data, configuration, and API keys.
The Vault proxy endpoint is exposed directly through Theta Directory at /api/vault/v1/, which safely authenticates and authorizes requests before forwarding them to the internal OpenBao container.
Architecture
The secrets engine uses a persistent file backend (/var/lib/docker/volumes/theta-env_openbao-data/_data) to ensure high availability and durability.
When the environment is initialized via setup.sh, OpenBao is automatically unsealed and seeded with a root token that the application uses for authentication. The root token is kept securely inside the container environment.
Accessing the Vault
The Theta Directory Vault can be accessed in two ways:
- Via the Theta Directory UI: Go to the Admin Configuration page (
/conf) to edit the application's configuration secrets directly. SMTP and OAuth settings are edited through structured form fields (not a raw JSON blob) and saved to OpenBao atsecret/sso-manager/confat runtime, taking effect immediately. Secret fields — the SMTP password and the OAuth JWT secret — are returned masked (********); leave the field unchanged (or blank) to keep the stored value, or enter a new value to replace it. - Via the REST API: Send requests to
/api/vault/v1/...with your Theta Directory session or API Token.
API Example
To read secrets from the default key-value store, issue a GET request to:
/api/vault/v1/secret/data/sso-manager/conf
Only administrators with app_sso_admin or admin permissions can query the vault endpoints.
Namespaces and Paths
Currently, secrets are maintained at /v1/secret/data/sso-manager/conf using the kv-v2 backend. When configurations are edited via the admin UI, Theta Directory performs a deep-merge so that partial updates don't overwrite unrelated keys (such as SMTP vs OAuth configurations).
Plugin Integration
Plugin instances store their per-instance secrets in OpenBao at
secret/plugins/<instance-id>/conf (configured, loaded/unloaded, and run from
the Plugins page — see Plugins). The plugin process runs
in-process, so Theta Directory reads/writes those secrets server-side through
the sso-broker token; the admin UI only ever sees masked values, and external
apps can retrieve API tokens via the /api/vault proxy to keep permissions
consistently enforced instead of hardcoding them.