Step 1: Set up an Environment
To configure the variables you need to use in a GitHub Actions workflow, make sure you have the latest version of the 1Password desktop app, then create a new 1Password Environment with your variables or add your variables to an existing Environment.Step 2: Connect your Environment to your GitHub Actions workflow
After you’ve set up an Environment and added your secrets, you can connect the Environment to your GitHub Actions workflow:- Open your Environment, then select Connect in the GitHub Actions section.
- Select the integration field, then choose the integration for the GitHub organization you need.
- Enter the name of the repository where your workflow needs to run.
- (Optional) Specify if you want to restrict access to a specific GitHub Actions workflow, environment, or branch in your repository.
- Select Add workflow.
Step 3: Modify your GitHub Actions workflow
After you’ve connected your Environment to GitHub Actions, copy the snippet from the 1Password desktop app and include it in a GitHub Actions workflow in order to reference any secrets in your Environment. You can choose from two methods to reference variables in your workflow:- If you include
export-env: "true"as an import parameter to the step you copied into your workflow, you can reference the variables with the following structure:${{ env.<variable-name> }} - If you add a unique identifier to the step you copied into your workflow, you can reference the variables with the following structure:
${{ steps.<id>.outputs.<variable-name> }}
Usage example
The following example shows how to use 1Password Credential Broker to load a username and token variable from an Environment, then use them to sign in to Docker Hub.config.yml
Get help
If you don’t see GitHub Actions as a destination in the 1Password desktop app, make sure your administrator has connected your GitHub organization to your 1Password account. If you see an OIDC-related error in your workflow log in GitHub, make sure you haveid-token: write set in the permissions within your workflow. . This permission allows GitHub to generate a short-lived token that 1Password uses to identify your workflow before supplying your secrets at runtime.