3 ms·
This looks interesting. We use 1Password, and I always thought it would be useful to programmatically pull values out and use in our cloud infrastructure. Curr
by patwolf 5y ago
This looks interesting. We use 1Password, and I always thought it would be useful to programmatically pull values out and use in our cloud infrastructure.
Currently we end up using the secret managers available in AWS or GCP, which seems pretty half baked. In GCP, for example, secrets are stored at a project level. It's not unusual to have certain secrets that are needed by more than one project, which means they get duplicated. The granularity also prevents me from controlling which secrets are visible to a given user.
I'd love to have one centralized source of truth for all infrastructure secrets.
- nops 5y agohttps://www.vaultproject.io/ https://www.vaultproject.io/
- outworlder 5y agoThis is why we use Vault. Until recently, there was no good option to host it, so you had to manage it. It's good to have independent competition in this space.
- Kudos 5y agoThey're not competing with Vault,they see this as an alternative for simpler use cases where Vault is overkill, or a complimentary product otherwise.
- whazor 5y agoAlso it would be cool to unlock the vault via 1password.
- stimur 5y ago[I work for 1Password] 1Password is not competing with Vault. In fact we have very good relationships and mutual respect with HashiCorp on many levels. Also Secret automation integrates (acts as a provider) with HC Vault[1] 1. https://github.com/1Password/vault-plugin-secrets-onepassword https://github.com/1Password/vault-plugin-secrets-onepasswor...
- gingerlime 5y agoplugging envwarden[0] which is just a tiny open source wrapper around the Bitwarden CLI to let you manage your server secrets inside your password manager. [0] https://github.com/envwarden/envwarden https://github.com/envwarden/envwarden
- hn_throwaway_99 5y ago> The granularity also prevents me from controlling which secrets are visible to a given user. What do you mean by this? Each secret has a "Permissions" tab which allows you to grant access to individual IAM users.
- patwolf 5y agoYou're correct. Not sure if I overlooked it or at some iteration of usage it wasn't there.
- zomglings 5y agoMy team uses 1Password to share account credentials, etc. When we need to deploy secrets into production, we use AWS Systems Manager Parameter Store. The name is quite a mouthful, but we have found the service to be awesome. We have a small Python script that loads a script with environment variable definitions from the Parameter Store and we use that as an EnvFile for our systemd services.
- sroussey 5y agoWe reverse engineered it so we can pull stuff ourselves. BTW: don’t forget to empty trust in 1P. Noticed the API giving back a lot more stuff than expected and that is why.
- directionless 5y agoFor AWS and GCP you can setup cross-project permissions. I've run a single project of secrets, which grants specific access to various service accounts