Lesson 14 / 24

op read and op run

Fetch a single value with op read and run a command with secrets injected as environment variables.

Resolve at the last moment

op read prints one field. op run is better for apps: it scans environment variables for op:// references, replaces them with real values for that process only, and masks them in the output. Nothing is written to disk.

A .env that holds only references

This .env.1p file is safe to commit because it has no real secret. op run fills the values in when starting the app.

# .env.1p
DATABASE_URL=op://Dev/Postgres/url
STRIPE_KEY=op://Dev/Stripe/secret-key

# run the app with real values only in its environment
op run --env-file=.env.1p -- npm start

# read a single field
op read "op://Dev/Postgres/password"

Do not echo secrets

Avoid echo $(op read ...) and logging environment variables. op run masks values it knows about, but your own code can still print them, so never log whole environments.

Quick check: What does `op run --env-file=.env.1p -- npm start` do?

  • Uploads .env.1p to GitHub
  • Resolves op:// references and starts the app with real values in its environment
  • Deletes the vault
  • Prints all secrets to the terminal
Answer

Resolves op:// references and starts the app with real values in its environment — The values exist only in the child process environment while it runs.