KB-001: 1Password Connect PushSecret False 400 Errors¶
Status: Pending upstream fix: monitoring external-secrets#3631 for resolution from the 1Password Connect team.
Symptom¶
PushSecret resources generate spurious HTTP 400 errors in logs despite successfully syncing secrets to 1Password:
Warning: Errored
set secret failed: could not write remote ref tls.key to target secretstore onepassword-connect:
error updating 1Password Item: status 400: Unable to update item "<domain>-production-tls"
in Vault "<vault-id>"
However, checking the PushSecret status shows it is actually working:
Affected versions:
- 1Password Connect: 1.7.3+ (including 1.8.1)
- External Secrets Operator: 0.9.19+
- Working version: 1Password Connect 1.15.0
Cause¶
This is a known bug in 1Password Connect starting from version 1.7.3+:
- 1Password Connect returns HTTP 400 errors even when updates succeed.
- The External Secrets Operator correctly reports the PushSecret as
Synced: True. - The errors are cosmetic noise from 1Password Connect itself.
There is no functional impact on cert-manager or PushSecret operations. Secrets ARE syncing successfully to 1Password, and the 400 errors are false positives that can be safely ignored.
Fix¶
Option 1: Ignore the errors (recommended)¶
The errors are harmless. Verify the PushSecret is working:
If status shows Synced: True, the secret is successfully pushed to 1Password.
Option 2: Downgrade 1Password Connect¶
Downgrade to the last known working version by pinning the image repositories in the HelmRelease and the chart version via the OCIRepository tag:
# kubernetes/apps/external-secrets/onepassword-connect/app/helmrelease.yaml
spec:
values:
connect:
api:
imageRepository: ghcr.io/1password/connect-api
sync:
imageRepository: ghcr.io/1password/connect-sync
# kubernetes/apps/external-secrets/onepassword-connect/app/ocirepository.yaml
spec:
ref:
tag: <chart-version-that-bundles-connect-1.15.0>
The image tag is controlled by the chart version pinned in the OCIRepository ref.tag, not by a
separate image.tag field in the HelmRelease values.
Option 3: Restart 1Password Connect periodically¶
Temporary workaround that clears errors for a few days:
Verification¶
To verify secrets are actually syncing to 1Password:
-
Check PushSecret status:
-
Look for the
Synced Push Secretssection showing successful sync. - Verify in the 1Password vault that the item exists and contains current data.
-
Check External Secrets Operator logs for actual errors vs. noise:
Example configuration¶
Working PushSecret configuration for cert-manager TLS certificates:
---
apiVersion: external-secrets.io/v1alpha1
kind: PushSecret
metadata:
name: &name "${SECRET_DOMAIN/./-}-production-tls"
spec:
secretStoreRefs:
- name: onepassword-connect
kind: ClusterSecretStore
selector:
secret:
name: *name
template:
engineVersion: v2
data:
tls.crt: '{{ index . "tls.crt" | b64enc }}'
tls.key: '{{ index . "tls.key" | b64enc }}'
data:
- match:
secretKey: &key tls.crt
remoteRef:
remoteKey: *name
property: *key
- match:
secretKey: &key tls.key
remoteRef:
remoteKey: *name
property: *key