Infisical for Local AI
What This Article Covers
- What Infisical is and how it differs from Vault.
- Running Infisical locally with Docker.
- Organizing projects, environments, and secrets.
- How applications retrieve secrets at runtime.
- Secret rotation and team management.
Introduction: Infisical for Local AI
Infisical is an open-source secret management tool designed for teams and smaller projects. Unlike HashiCorp Vault, it’s simpler to set up and offers a modern web interface. For local AI projects with multiple agents, tools, or team members, Infisical is a practical alternative to plain .env files.
This article shows how to install Infisical locally and use it for API keys, database passwords, and other secrets in AI workflows.
Key Concepts
- Project: Groups secrets together, for example
openclaw-agent. - Environment: Distinguishes between
dev,staging, andprod. - Secret: A key-value pair with an encrypted value.
- Service Token: Token for machines and applications.
- Integration: Connection to CI/CD, Docker, or Kubernetes.
- Rotation: Automatic exchange of secrets.
- Access Control: Roles and permissions for users.
Why Infisical?
- Simple interface: Modern web UI with clear project structures.
- Open source: Self-hostable without vendor lock-in.
- Team features: Users, roles, and shared secrets.
- Integrations: CLI, SDKs, Docker, and Kubernetes.
- Versioning: History and recovery of earlier values.
- Rotation: Supports automatic renewal with certain providers.
Installation with Docker
Infisical starts easily with Docker Compose:
services:
infisical:
image: infisical/infisical:latest-postgres
container_name: infisical
ports:
- "8080:8080"
environment:
- SITE_URL=http://localhost:8080
- ENCRYPTION_KEY=DEIN_32_BYTE_SCHLUESSEL
- REDIS_URL=redis://redis:6379
- DB_CONNECTION_URI=postgres://infisical:password@postgres:5432/infisical
depends_on:
- postgres
- redis
postgres:
image: postgres:16
environment:
POSTGRES_USER: infisical
POSTGRES_PASSWORD: password
POSTGRES_DB: infisical
volumes:
- postgres-data:/var/lib/postgresql/data
redis:
image: redis:7
volumes:
postgres-data:
Start it:
docker compose up -d
Access the interface at http://localhost:8080.
Creating Your First Project and Secrets
- Open
http://localhost:8080in your browser. - Create an account or log in.
- Create a new project, for example
local-ai. - Add a secret with a name and value:
- Key:
ANTHROPIC_API_KEY - Value:
DEIN_ANTHROPIC_API_KEY
- Key:
- Save it to your desired environment.
Install the CLI and Retrieve Secrets
curl -1sLf 'https://dl.cloudsmith.io/public/infisical/infisical-cli/setup.deb.sh' | sudo bash
sudo apt update && sudo apt install -y infisical
Log in:
infisical login
Load secrets into the current directory:
infisical run --env=dev --projectId=DEINE_PROJEKT_ID -- ollama serve
Alternatively, export as environment variables:
infisical export --env=dev --projectId=DEINE_PROJEKT_ID > .env
Integration into Applications
Infisical provides SDKs for various languages. Example in Python:
from infisical_client import InfisicalClient
client = InfisicalClient(token="ST_DEIN_SERVICE_TOKEN")
secret = client.get_secret("ANTHROPIC_API_KEY", environment="dev", secret_path="/")
print(secret.secret_value)
Shell scripts and Docker containers can also load secrets via service tokens or the CLI.
Access Control
- Admins: Full access to all projects.
- Developers: Read and write in defined environments.
- Viewers: Read-only access.
- Service Tokens: Machine access to specific projects and environments.
Each team member should see only the secrets they actually need.
Rotation
Infisical supports rotation for certain integration providers. For custom secrets, you can use workflows or cron jobs to generate new values regularly and store them in Infisical. Services fetch current values at startup or through watch mechanisms.
Infisical in Your AI Stack
For OpenClaw, OpenHands, or other agents, Infisical can be the central secrets source:
- A service token is passed when starting the agent.
- The agent reads API keys, database passwords, and credentials from Infisical.
- No more secrets in
.envfiles or repositories. - Rotation and access management centralized.
Common Pitfalls
- Forgotten default passwords: Configure PostgreSQL and Infisical with your own passwords.
- No TLS on local network: Enable TLS for production access across the network.
- Unprotected service tokens: Keep them out of logs and repositories.
- Wrong project ID: Ensure CLI commands point to the correct project.
- Missing backups: Back up PostgreSQL data regularly.
Further Resources
- BotServ.de Secret Management
- BotServ.de Secret Rotation
- BotServ.de HashiCorp Vault
- BotServ.de Secure API Key Management
FAQ: Infisical Local
Is Infisical free? Yes, the open-source version is free to self-host.
What’s the difference from HashiCorp Vault? Infisical is easier to set up and has a more modern UI. Vault offers more enterprise features.
Can I install Infisical without Docker? Yes, there are binaries available, but Docker is the simplest approach.
How secure are the secrets? With your own encryption key and TLS, they are secure.
Can I connect Infisical with Ollama? Ollama doesn’t read secrets directly, but you can use Infisical to manage API keys for agents or web UIs.
Sources and Further Reading
- Infisical Docs: https://infisical.com/docs/
- Infisical GitHub: https://github.com/Infisical/infisical
- Infisical Docker: https://infisical.com/docs/self-hosting/deployment-options/docker-compose
Summary: Infisical for Local AI
Infisical is a user-friendly, open-source alternative for secret management in local AI projects. With Docker, it runs quickly and offers projects, environments, roles, service tokens, and rotation. For teams and agent stacks, it’s far superior to scattered .env files. With attention to TLS, backups, and clean access control, you get a solid secrets management solution on your own network.


