Using 1Password and direnv to store developer secrets
This is more notes to myself so i don’t forget. Goals:
- no secrets stored on the filesystem (so they can’t be sucked up by credential-harvesting malware)
- individual vault per project
- secrets automatically injected to envvars so that apps can follow 12-Factor App methodology
- deployed secrets use platform native secret manager (e.g. Cloudflare secrets manager, Azure keyvault, AWS SSM Parameter Store etc.)
- separation of this vault from my main password vault in BitWarden. My whole world exists in Bitwarden - i dont want to inadvertently expose it. And as Bitwarden has a pretty awful CLI experience, it doesnt work for me.
- Safe to commit secret file to source control
- Safe to commit my
.envfiles to source control because they no longer contain secrets
Benefits of 1Password: