Lesson 15 / 24

op inject and Templates

Generate a config file from a template when an app only reads files.

When a file is unavoidable

Some tools need a config file with real values. op inject replaces {{ op://... }} placeholders in a template and writes the result. Treat the output as a secret: keep it out of Git, restrict its permissions and delete it when done.

Template to file

Commit the template, never the generated file. chmod 600 makes it readable only by you.

# config.yml.tpl
# db:
#   password: {{ op://Dev/Postgres/password }}

op inject -i config.yml.tpl -o config.yml
chmod 600 config.yml
echo "config.yml" >> .gitignore

Prefer op run when possible

op run leaves nothing on disk, while op inject creates a plaintext file. Use inject only when the tool cannot read environment variables.

Quick check: Which file should be committed to Git?

  • config.yml with real passwords
  • The generated output of op inject
  • config.yml.tpl with op:// placeholders
  • A screenshot of the vault
Answer

config.yml.tpl with op:// placeholders — The template contains only references, so it is safe to share.