blumeops/docs/reference/services/1password.md
Erich Blume d3be0b0e92 Add how-to guide for restoring 1Password backup from borgmatic
Verified end-to-end: extracted .age + .key.enc from borg archive,
decrypted age key with openssl, decrypted .1pux with age, confirmed
valid 31MB zip containing vault data. Added cross-links from
disaster-recovery, 1password, borgmatic, backups, and how-to index.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 10:44:23 -08:00

46 lines
1,008 B
Markdown

---
title: 1Password
tags:
- service
- secrets
---
# 1Password
Root credential store for all BlumeOps secrets, synced to Kubernetes via External Secrets Operator.
## Architecture
```
1Password Cloud
|
v
1Password Connect (namespace: 1password)
|
v
External Secrets Operator (namespace: external-secrets)
|
v
Native Kubernetes Secrets
```
## Vault
The `blumeops` vault contains all infrastructure credentials.
## Kubernetes Integration
**ClusterSecretStore:** `onepassword-blumeops`
Services reference 1Password items via `ExternalSecret` manifests.
## Disaster Recovery Backup
The `mise run op-backup` task encrypts a `.1pux` vault export and transfers it to [[indri]] for inclusion in [[borgmatic]] backups. See [[restore-1password-backup]] for the full recovery procedure.
## Related
- [[argocd]] - Uses secrets for git access
- [[postgresql]] - Database credentials
- [[restore-1password-backup]] - Recovery from backup
- [[borgmatic]] - Backup system