Archives 2026/04

Using 1Password and direnv to store developer secrets

This is more notes to myself so i don’t forget. Goals:

  • no secrets stored on the filesystem (so they can’t be sucked up by credential-harvesting malware)
  • individual vault per project
  • secrets automatically injected to envvars so that apps can follow 12-Factor App methodology
  • deployed secrets use platform native secret manager (e.g. Cloudflare secrets manager, Azure keyvault, AWS SSM Parameter Store etc.)
  • separation of this vault from my main password vault in BitWarden. My whole world exists in Bitwarden - i dont want to inadvertently expose it. And as Bitwarden has a pretty awful CLI experience, it doesnt work for me.
  • Safe to commit secret file to source control
  • Safe to commit my .env files to source control because they no longer contain secrets

Benefits of 1Password: