Skip to content

Store a secret

Briefing, not authority. (R) rule at linked source · (O) dated upstream fact · (P) procedure · (C) open work · (G) not established.

WHAT THIS MEANS IN DRUPAL

Drupal consumes sensitive values through the Key module; the value lives in 1Password and config stores only the reference (R) how-we-build §15.

OWNER

  • Secret authority: 1Password; Drupal-facing abstraction: Key (R) how-we-build §15.
  • Constitution: STD-SEC-001 (references, not values; agents use their own identity).

PREREQUISITES

  1. (P) The secret exists in 1Password; you have an op://Vault/Item/field reference (R) STD-SEC-001 §11.

DO THIS

  1. (P) Create a Key entity that resolves at runtime from the external provider (R) Drupal secrets.
  2. (P) Point provider/module config at the Key ID, never the value.
  3. (P) Export config and confirm only the reference is exported (R) Drupal secrets.

WATCH FOR

  • A 401/403 is diagnosed by layer; one 401 is not proof of expiry (R) STD-SEC-001 §14-15.
  • Never print token values (R) STD-SEC-001 §15.

DO NOT

  • Secret in config sync, recipe.yml, committed settings, a Bead, a prompt or a transcript (R) how-we-build §15.
  • Ask Thomas to paste a credential (R) Drupal secrets.
  • Search vaults or enumerate secrets (R) STD-SEC-001 §15.

OWNERSHIP / CAN-SHOULD-MAY

  • CAN: Key UI and config.
  • SHOULD: platforms rotate their own credentials (R) STD-SEC-001 §13; Drupal holds references only.
  • MUST: autonomous agents use their own machine identity; a missing one is MACHINE_IDENTITY_PROVISIONING_GAP (R) STD-SEC-001 §5.

DO NOT REDISCOVER

  • SECRET_VALUE_IN_SOURCE=NO, ..._CONFIG_EXPORT=NO, ..._RECIPE=NO, ..._TRANSCRIPT=NO (R) how-we-build §15.

CONFLICTS

ID A B Resolution
C-1P-KEY-MODULE Drupal secrets: install "One Password Connect Key Integration" + Connect server matrix: no record for that module Run adoption before install; pattern stands.

GO DEEPER

Anchored sources: frontmatter authority_sources. Expires last_verified + 30d.