-
A password vault is not a secrets manager

I set up a self-hosted password vault so household logins stop appearing in chat. The easy assumption was that it could replace the encrypted config store behind the homelab. It cannot, at least not cleanly.
A person’s vault needs sharing and recovery. An automation process needs a narrow identity, a limited collection, and a way to retrieve a credential without receiving the whole vault. I kept the encrypted config store for machine bootstrap and made the password vault a separate user-facing layer. The rule I want to keep is simple: give the bot an account with an empty personal vault and access only to the secrets it genuinely needs.