Skip to content

ADR-0020: 1Password Connect + SDK and Keycloak as the Standing Secrets/Identity Target

Status: Accepted — Connect is the Oracle runtime secret API Date: 2026-07-06 (revised 2026-08-27) Related: STD-AUTH-001 (Engineering-Standard/standards/core/STD-SEC-001-authentication-and-secrets.md), IaC docs/onepassword-connect-architecture.md

Context

~/.op-env grew into a de facto secret registry (duplicate aliases, hand-maintained mappings). Oracle systemd units using plaintext EnvironmentFile= and per-project op run wrapping are the pattern this decision replaces. The constitution forbids Bluefly-built secret caches, token brokers, and copying workstation secrets onto servers.

Decision

1Password (canonical secret names)
    ↓
Semantic aliases (GITLAB_OPERATOR_TOKEN_REF, …) in environment bindings
    ↓
Delivery by surface:
  Workstation → Shell Plugin / `op read` at process scope / SSH Agent
  GitLab CI (off-host) → CI_JOB_TOKEN first, else Service Account + official CLI
  Oracle runtime → 1Password Connect (`op-connect env`)
    ↓
Keycloak for service-to-service identity (not a secret store)

Execution-surface split (CURRENT):

Surface Identity Secret delivery
Developer workstation 1Password desktop session Shell Plugin / bounded op run / SSH Agent
GitLab CI off-host CI_JOB_TOKEN, then Service Account Official 1Password CLI
Oracle long-lived runtime Connect client token 1Password Connect REST API / CLI in Connect mode

Connect is loopback + docker-network only. CI does not reach it. Do not publish Connect on a routable interface.

Authoritative Connect deploy: blueflyio/agent-platform/infra/iac (oracle/onepassword-connect/, scripts/op-connect, deploy:onepassword-connect). Do not stand up a second Connect in agent-docker.

SUPERSEDED: Oracle Service Account → op run → docker compose; host .op-env; HashiCorp Vault as a Bluefly secret API (templates/vault-auth).

Rule

When secrets/CI-variable/service-auth work comes up: native short-lived identity first; Connect for Oracle; Service Account only for off-host CI; Keycloak for service identity. Do not invent a Bluefly cache, .env, or PAT because one invocation failed.

Status

Connect is the accepted Oracle runtime path. Remaining work is consumer migration (systemd EnvironmentFile=, agent-docker .env mounts) after Connect heartbeat is green — not a new secret system.