Lesson 14 / 24
op read and op run
Fetch a single value with op read and run a command with secrets injected as environment variables.
Resolve at the last moment
op read prints one field. op run is better for apps: it scans environment variables for op:// references, replaces them with real values for that process only, and masks them in the output. Nothing is written to disk.
A .env that holds only references
This .env.1p file is safe to commit because it has no real secret. op run fills the values in when starting the app.
# .env.1p
DATABASE_URL=op://Dev/Postgres/url
STRIPE_KEY=op://Dev/Stripe/secret-key
# run the app with real values only in its environment
op run --env-file=.env.1p -- npm start
# read a single field
op read "op://Dev/Postgres/password"Do not echo secrets
Avoid echo $(op read ...) and logging environment variables. op run masks values it knows about, but your own code can still print them, so never log whole environments.
Quick check: What does `op run --env-file=.env.1p -- npm start` do?
- Uploads .env.1p to GitHub
- Resolves op:// references and starts the app with real values in its environment
- Deletes the vault
- Prints all secrets to the terminal
Answer
Resolves op:// references and starts the app with real values in its environment — The values exist only in the child process environment while it runs.