Store a secret¶
Briefing, not authority. (R) rule at linked source · (O) dated upstream fact · (P) procedure · (C) open work · (G) not established.
WHAT THIS MEANS IN DRUPAL¶
Drupal consumes sensitive values through the Key module; the value lives in 1Password and config stores only the reference (R) how-we-build §15.
OWNER¶
- Secret authority: 1Password; Drupal-facing abstraction: Key (R) how-we-build §15.
- Constitution: STD-SEC-001 (references, not values; agents use their own identity).
PREREQUISITES¶
- (P) The secret exists in 1Password; you have an
op://Vault/Item/fieldreference (R) STD-SEC-001 §11.
DO THIS¶
- (P) Create a Key entity that resolves at runtime from the external provider (R) Drupal secrets.
- (P) Point provider/module config at the Key ID, never the value.
- (P) Export config and confirm only the reference is exported (R) Drupal secrets.
WATCH FOR¶
- A 401/403 is diagnosed by layer; one 401 is not proof of expiry (R) STD-SEC-001 §14-15.
- Never print token values (R) STD-SEC-001 §15.
DO NOT¶
- Secret in config sync,
recipe.yml, committed settings, a Bead, a prompt or a transcript (R) how-we-build §15. - Ask Thomas to paste a credential (R) Drupal secrets.
- Search vaults or enumerate secrets (R) STD-SEC-001 §15.
OWNERSHIP / CAN-SHOULD-MAY¶
- CAN: Key UI and config.
- SHOULD: platforms rotate their own credentials (R) STD-SEC-001 §13; Drupal holds references only.
- MUST: autonomous agents use their own machine identity; a missing one is
MACHINE_IDENTITY_PROVISIONING_GAP(R) STD-SEC-001 §5.
DO NOT REDISCOVER¶
SECRET_VALUE_IN_SOURCE=NO,..._CONFIG_EXPORT=NO,..._RECIPE=NO,..._TRANSCRIPT=NO(R) how-we-build §15.
CONFLICTS¶
| ID | A | B | Resolution |
|---|---|---|---|
| C-1P-KEY-MODULE | Drupal secrets: install "One Password Connect Key Integration" + Connect server | matrix: no record for that module | Run adoption before install; pattern stands. |
GO DEEPER¶
Anchored sources: frontmatter authority_sources. Expires last_verified + 30d.