# op inject and Templates — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/op-inject

> Generate a config file from a template when an app only reads files.

## When a file is unavoidable

Some tools need a config file with real values. `op inject` replaces `{{ op://... }}` placeholders in a template and writes the result. Treat the output as a secret: keep it out of Git, restrict its permissions and delete it when done.

## Template to file

Commit the template, never the generated file. `chmod 600` makes it readable only by you.

```bash
# config.yml.tpl
# db:
#   password: {{ op://Dev/Postgres/password }}

op inject -i config.yml.tpl -o config.yml
chmod 600 config.yml
echo "config.yml" >> .gitignore
```

## Prefer op run when possible

`op run` leaves nothing on disk, while `op inject` creates a plaintext file. Use `inject` only when the tool cannot read environment variables.

**Quiz:** Which file should be committed to Git?

- [ ] config.yml with real passwords
- [ ] The generated output of op inject
- [x] config.yml.tpl with op:// placeholders
- [ ] A screenshot of the vault

*Answer:* config.yml.tpl with op:// placeholders. The template contains only references, so it is safe to share.
