Lesson 15 / 24
op inject and Templates
Generate a config file from a template when an app only reads files.
When a file is unavoidable
Some tools need a config file with real values. op inject replaces {{ op://... }} placeholders in a template and writes the result. Treat the output as a secret: keep it out of Git, restrict its permissions and delete it when done.
Template to file
Commit the template, never the generated file. chmod 600 makes it readable only by you.
# config.yml.tpl
# db:
# password: {{ op://Dev/Postgres/password }}
op inject -i config.yml.tpl -o config.yml
chmod 600 config.yml
echo "config.yml" >> .gitignorePrefer op run when possible
op run leaves nothing on disk, while op inject creates a plaintext file. Use inject only when the tool cannot read environment variables.
Quick check: Which file should be committed to Git?
- config.yml with real passwords
- The generated output of op inject
- config.yml.tpl with op:// placeholders
- A screenshot of the vault
Answer
config.yml.tpl with op:// placeholders — The template contains only references, so it is safe to share.