ADR-0020: 1Password Connect + SDK and Keycloak as the Standing Secrets/Identity Target¶
Status: Accepted — Connect is the Oracle runtime secret API
Date: 2026-07-06 (revised 2026-08-27)
Related: STD-AUTH-001 (Engineering-Standard/standards/core/STD-SEC-001-authentication-and-secrets.md), IaC docs/onepassword-connect-architecture.md
Context¶
~/.op-env grew into a de facto secret registry (duplicate aliases, hand-maintained mappings). Oracle systemd units using plaintext EnvironmentFile= and per-project op run wrapping are the pattern this decision replaces. The constitution forbids Bluefly-built secret caches, token brokers, and copying workstation secrets onto servers.
Decision¶
1Password (canonical secret names)
↓
Semantic aliases (GITLAB_OPERATOR_TOKEN_REF, …) in environment bindings
↓
Delivery by surface:
Workstation → Shell Plugin / `op read` at process scope / SSH Agent
GitLab CI (off-host) → CI_JOB_TOKEN first, else Service Account + official CLI
Oracle runtime → 1Password Connect (`op-connect env`)
↓
Keycloak for service-to-service identity (not a secret store)
Execution-surface split (CURRENT):
| Surface | Identity | Secret delivery |
|---|---|---|
| Developer workstation | 1Password desktop session | Shell Plugin / bounded op run / SSH Agent |
| GitLab CI off-host | CI_JOB_TOKEN, then Service Account |
Official 1Password CLI |
| Oracle long-lived runtime | Connect client token | 1Password Connect REST API / CLI in Connect mode |
Connect is loopback + docker-network only. CI does not reach it. Do not publish Connect on a routable interface.
Authoritative Connect deploy: blueflyio/agent-platform/infra/iac (oracle/onepassword-connect/, scripts/op-connect, deploy:onepassword-connect). Do not stand up a second Connect in agent-docker.
SUPERSEDED: Oracle Service Account → op run → docker compose; host .op-env; HashiCorp Vault as a Bluefly secret API (templates/vault-auth).
Rule¶
When secrets/CI-variable/service-auth work comes up: native short-lived identity first; Connect for Oracle; Service Account only for off-host CI; Keycloak for service identity. Do not invent a Bluefly cache, .env, or PAT because one invocation failed.
Status¶
Connect is the accepted Oracle runtime path. Remaining work is consumer migration (systemd EnvironmentFile=, agent-docker .env mounts) after Connect heartbeat is green — not a new secret system.