Skip to content
BotServBotServ
InfisicalSecret ManagementOpen SourceLocal AISecurity

Infisical for Local AI

Run Infisical open-source secret management locally. Team secrets, rotation, and agent integration.

S

schutzgeist

3 min read
Infisical for Local AI

Infisical for Local AI

What This Article Covers

  • What Infisical is and how it differs from Vault.
  • Running Infisical locally with Docker.
  • Organizing projects, environments, and secrets.
  • How applications retrieve secrets at runtime.
  • Secret rotation and team management.

Introduction: Infisical for Local AI

Infisical is an open-source secret management tool designed for teams and smaller projects. Unlike HashiCorp Vault, it’s simpler to set up and offers a modern web interface. For local AI projects with multiple agents, tools, or team members, Infisical is a practical alternative to plain .env files.

This article shows how to install Infisical locally and use it for API keys, database passwords, and other secrets in AI workflows.

Key Concepts

  • Project: Groups secrets together, for example openclaw-agent.
  • Environment: Distinguishes between dev, staging, and prod.
  • Secret: A key-value pair with an encrypted value.
  • Service Token: Token for machines and applications.
  • Integration: Connection to CI/CD, Docker, or Kubernetes.
  • Rotation: Automatic exchange of secrets.
  • Access Control: Roles and permissions for users.

Why Infisical?

  • Simple interface: Modern web UI with clear project structures.
  • Open source: Self-hostable without vendor lock-in.
  • Team features: Users, roles, and shared secrets.
  • Integrations: CLI, SDKs, Docker, and Kubernetes.
  • Versioning: History and recovery of earlier values.
  • Rotation: Supports automatic renewal with certain providers.

Installation with Docker

Infisical starts easily with Docker Compose:

services:
  infisical:
    image: infisical/infisical:latest-postgres
    container_name: infisical
    ports:
      - "8080:8080"
    environment:
      - SITE_URL=http://localhost:8080
      - ENCRYPTION_KEY=DEIN_32_BYTE_SCHLUESSEL
      - REDIS_URL=redis://redis:6379
      - DB_CONNECTION_URI=postgres://infisical:password@postgres:5432/infisical
    depends_on:
      - postgres
      - redis

  postgres:
    image: postgres:16
    environment:
      POSTGRES_USER: infisical
      POSTGRES_PASSWORD: password
      POSTGRES_DB: infisical
    volumes:
      - postgres-data:/var/lib/postgresql/data

  redis:
    image: redis:7

volumes:
  postgres-data:

Start it:

docker compose up -d

Access the interface at http://localhost:8080.

Creating Your First Project and Secrets

  1. Open http://localhost:8080 in your browser.
  2. Create an account or log in.
  3. Create a new project, for example local-ai.
  4. Add a secret with a name and value:
    • Key: ANTHROPIC_API_KEY
    • Value: DEIN_ANTHROPIC_API_KEY
  5. Save it to your desired environment.

Install the CLI and Retrieve Secrets

curl -1sLf 'https://dl.cloudsmith.io/public/infisical/infisical-cli/setup.deb.sh' | sudo bash
sudo apt update && sudo apt install -y infisical

Log in:

infisical login

Load secrets into the current directory:

infisical run --env=dev --projectId=DEINE_PROJEKT_ID -- ollama serve

Alternatively, export as environment variables:

infisical export --env=dev --projectId=DEINE_PROJEKT_ID > .env

Integration into Applications

Infisical provides SDKs for various languages. Example in Python:

from infisical_client import InfisicalClient

client = InfisicalClient(token="ST_DEIN_SERVICE_TOKEN")
secret = client.get_secret("ANTHROPIC_API_KEY", environment="dev", secret_path="/")
print(secret.secret_value)

Shell scripts and Docker containers can also load secrets via service tokens or the CLI.

Access Control

  • Admins: Full access to all projects.
  • Developers: Read and write in defined environments.
  • Viewers: Read-only access.
  • Service Tokens: Machine access to specific projects and environments.

Each team member should see only the secrets they actually need.

Rotation

Infisical supports rotation for certain integration providers. For custom secrets, you can use workflows or cron jobs to generate new values regularly and store them in Infisical. Services fetch current values at startup or through watch mechanisms.

Infisical in Your AI Stack

For OpenClaw, OpenHands, or other agents, Infisical can be the central secrets source:

  • A service token is passed when starting the agent.
  • The agent reads API keys, database passwords, and credentials from Infisical.
  • No more secrets in .env files or repositories.
  • Rotation and access management centralized.

Common Pitfalls

  • Forgotten default passwords: Configure PostgreSQL and Infisical with your own passwords.
  • No TLS on local network: Enable TLS for production access across the network.
  • Unprotected service tokens: Keep them out of logs and repositories.
  • Wrong project ID: Ensure CLI commands point to the correct project.
  • Missing backups: Back up PostgreSQL data regularly.

Further Resources

FAQ: Infisical Local

Is Infisical free? Yes, the open-source version is free to self-host.

What’s the difference from HashiCorp Vault? Infisical is easier to set up and has a more modern UI. Vault offers more enterprise features.

Can I install Infisical without Docker? Yes, there are binaries available, but Docker is the simplest approach.

How secure are the secrets? With your own encryption key and TLS, they are secure.

Can I connect Infisical with Ollama? Ollama doesn’t read secrets directly, but you can use Infisical to manage API keys for agents or web UIs.

Sources and Further Reading

Summary: Infisical for Local AI

Infisical is a user-friendly, open-source alternative for secret management in local AI projects. With Docker, it runs quickly and offers projects, environments, roles, service tokens, and rotation. For teams and agent stacks, it’s far superior to scattered .env files. With attention to TLS, backups, and clean access control, you get a solid secrets management solution on your own network.

Back to Blog
Share:

Related Posts