Skip to content

1Password & Drupal Secrets Architecture

Prime Directive

SECRET_SYSTEM_OF_RECORD=1PASSWORD AGENT_SECRET_VISIBILITY=NO

No API keys, LLM tokens, database credentials, or secret strings shall ever be committed to Git repositories, settings.php, or YAML configuration exports.

The Authorized Drupal Secret Pattern

When Drupal (or any recipe, such as recipe_contextual_memory) requires access to an external API or service, agents MUST adhere to the following architecture:

  1. 1Password Connect Server: Acts as the local REST API bridge deployed inside the infrastructure (e.g., in DDEV or production Docker) to securely fetch secrets.
  2. Drupal Key Module Integration: The One Password Connect Key Integration module must be installed. It extends Drupal's Key framework to load sensitive values directly from 1Password vaults at runtime.
  3. Reference Only: Drupal configuration must only store the reference (Key ID) to the secret.

Rules for Agents

  • Do not hardcode secrets: Never write a secret into a recipe, test, or settings file.
  • Do not resolve secrets on export: When capturing or exporting Drupal configuration (via drush cex or blu recipe capture), ensure that only the Key references are exported, not the resolved secret values.
  • Contextual Memory & AI Dependencies: Any recipe requiring Anthropic, OpenAI, or Vector Database credentials must list the 1Password Connect Key Integration module as a dependency and instruct the user to configure the Key entity.

THOMAS IS NOT THE CREDENTIAL BROKER. Do not ask him to paste API keys into the chat. Instruct the environment to use the 1Password Connect bridge.