// the find
1Password/onepassword-operator
The 1Password Connect Kubernetes Operator provides the ability to integrate Kubernetes Secrets with 1Password. The operator also handles autorestarting deployments when 1Password items are updated.
A Kubernetes operator from 1Password that watches OnePasswordItem/OnePasswordItemList CRDs and syncs the referenced 1Password vault items into native Kubernetes Secrets, restarting Deployments automatically when the source item changes. It's for teams already paying for 1Password who want to stop hand-copying API keys into `kubectl create secret` commands.
It supports two backend clients (pkg/onepassword/client/connect and client/sdk), so you can either run a self-hosted Connect server or authenticate directly with a service account token - the older Connect-only requirement was a real friction point and this removes it. Scaffolding follows kubebuilder/operator-sdk conventions cleanly (api/v1, internal/controller, config/rbac, config/crd), so anyone who's touched another Go operator will find their way around fast. Test coverage is unusually good for this category - nearly every file in pkg/onepassword has a matching _test.go, plus a real e2e suite that spins up kind and applies actual manifests rather than just unit-testing the reconcile loop in isolation.
The auto-restart behavior is scoped to Deployments only (deployment_controller.go) - StatefulSets, DaemonSets, and CronJobs don't get the same treatment, so if your secret-consuming workload isn't a Deployment you're back to manual rollouts. There's a bootstrapping problem baked into the design: the credentials needed to talk to Connect or the SDK themselves have to land in a Kubernetes Secret first, so you haven't actually escaped manual secret management, just moved it one level up. The CRD model syncs whole items into whole Secrets - there's no mechanism for merging specific fields into an existing Secret or namespacing control without a redundant resource per namespace, which is the usual complaint against this operator versus something like External Secrets Operator's provider model.