alt/docs/kis-live-secret-handoff.md
toki cb8bdd3470 docs: add KIS Live secret guide and SOPS configuration
- Add .sops.yaml for SOPS encryption configuration
- Add kis-live-secret-guide.md with setup instructions
- Add kis-live-secret-handoff.md for secret handoff procedure
- Add secrets/kis.live.sops.yaml with encrypted credentials
- Update kis-live-data-collection-pipeline milestone document
2026-06-02 15:01:11 +09:00

1.7 KiB

KIS Live Secret Handoff

Current Setup

  • Remote field host owns the secret boundary.
  • Vaultwarden runs outside the code-server container as a sibling container.
  • sops and age are installed on the remote host only.
  • The remote host age recipient for KIS live smoke is:
age1fwqdkmqh3ykq7cnchcrr5nfwr77qsdt4p79lpa49g6q5k88cluvqkfw8d3

Repo Files

  • .sops.yaml: SOPS rule for secrets/kis.live.sops.yaml.
  • secrets/kis.live.sops.yaml: encrypted KIS live smoke env template.
  • docs/kis-live-secret-guide.md: user-facing guide for how to fill and use the secret.

User Fill-In

Do not paste secret values into chat, roadmap, docs, task logs, or command output.

Open the Vaultwarden SSH tunnel from the local machine:

ssh -L 18088:127.0.0.1:18088 toki@192.168.0.97

Then open Vaultwarden in the browser:

http://127.0.0.1:18088

On the remote host, edit the encrypted file:

cd /Users/toki/docker/services/code-server/data/volume/workspace/alt
SOPS_AGE_KEY_FILE="$HOME/.config/sops/age/keys.txt" sops secrets/kis.live.sops.yaml

Fill only the env names required for first KIS daily-bar smoke:

KIS_APP_KEY
KIS_APP_SECRET
KIS_BASE_URL
KIS_IS_PAPER

Account number, account product, account password, order password, balance, and order scopes are not part of the first daily-bar smoke unless a later task explicitly expands the scope.

Agent Handoff

After the user fills the encrypted file, tell the agent only:

SOPS file is filled.
First smoke target:
- market: KR
- symbol: 005930
- date range: <YYYYMMDD>~<YYYYMMDD>

The agent should then implement or run a host-wrapper flow that decrypts on the remote host and passes env vars into the code-server container only for the command lifetime.