@assemblyline-agents/1password
v10.3.2
Published
Official Assembly Line 1Password vault and item connection for service accounts.
Maintainers
Readme
@assemblyline-agents/1password
Official 1Password plugin for three separate jobs: host-side secret storage, host-side credential sourcing, and optional model-facing metadata browsing.
Model-facing connection
assembly-line add 1password agentThe command installs and selects the plugin in agent.md, then pins its
authority in plugins.lock. Store OP_SERVICE_ACCOUNT_TOKEN in the configured
secret store. The broker supplies it only to the 1Password connection. The
agent receives read-only tools to list vaults and items and search metadata.
Complete items, concealed values, and arbitrary resolve_secret results are
not model-facing capabilities.
The same connection is a trusted host-side credential source. A reviewed sink,
such as Orgo, can consume an op:// value without returning the value to the
model or authored code.
Host-only boot secrets
Install and pin the secrets-provider role:
assembly-line add 1password agent --role secretsUse the scalar default when OP_VAULT names the secret vault:
secrets: 1passwordSet an explicit exception only when needed:
secrets:
1password:
vault: Production Runtime
field: credentialvault defaults to OP_VAULT; field defaults to credential. The store
resolves only the credential name requested by an authorized connection as
op://<vault>/<name>/<field>. It does not overlay a shared runtime environment.
Use OP_SECRETS_SERVICE_ACCOUNT_TOKEN for this store when the same agent also
has model-facing metadata browsing. Use separate accounts and vault scopes so
the browsing account cannot enumerate the framework credential vault.
Add only the secrets-store role with:
assembly-line add 1password agent --role secretsSee the Declarative Reference for the exact schema and defaults, and Configuration And Credentials for secure source-to-sink transfer.
License
MIT
