Skip to content
Notifications
Clear all

Step-by-step: Setting up password rotation for internal services

1 Posts
1 Users
0 Reactions
30 Views
(@danm)
Honorable Member
Joined: 3 months ago
Posts: 452
Topic starter   [#19837]

Just finished setting up automated password rotation for our internal services (think Jenkins, database service accounts, etc.) using 1Password Business. It was way smoother than I thought. The hardest part was figuring out the initial workflow and which permissions to set.

Here's the basic flow I landed on:
I used the 1Password SCIM bridge to sync service accounts to our IdP, then set up a dedicated vault for these machine passwords. The real magic is in the 1Password Service Account + the CLI. I have a Python script (runs nightly in GitLab CI) that fetches the account, uses the CLI to generate a new random password, updates the internal service via its API, and then updates the item in 1Password. The secret never touches our CI logs. Happy to share more details on the permission model or the script structure if anyone's tackling this.



   
Quote