secrets manager
git clone https://git.lucas.co/cce-secrets.git
Ship cce-1password.service: start the headless app with the session
1Password's own "start at login" writes an XDG autostart entry, but no cce
session starts xdg-desktop-autostart.target, so it never fired: after two
logins on 2026-10-02 the app was absent and cce-keyring-sync retried "app
not running" until it was opened by hand. The unit starts it --silent
with graphical-session.target, ordered before the sync daemon. A second
launch hands off to a running instance and exits 0 (measured), so it is
harmless beside an app opened by hand.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
KEYRING-SYNC.md | 5 +++--
cce-1password.service | 22 ++++++++++++++++++++++
2 files changed, 25 insertions(+), 2 deletions(-)
diff --git a/KEYRING-SYNC.md b/KEYRING-SYNC.md
index d5f5e9d..8c53200 100644
--- a/KEYRING-SYNC.md
+++ b/KEYRING-SYNC.md
@@ -644,8 +644,9 @@ daemon's back-off covers the gap until it is measured. (Answered
The question was whether cce programs could replace 1Password's graphical
frontend. Two shapes were weighed:
-- **A — the app stays, headless.** It keeps running (autostart already
- passes `--silent`, so no main window opens) as what `op` authorizes
+- **A — the app stays, headless.** It keeps running (`cce-1password.service`
+ starts it with `--silent`, so no main window opens; its own XDG autostart
+ entry never fires under cce) as what `op` authorizes
against and what syncs with 1Password's servers; cce-secrets is the only
window anyone browses in. **Chosen.**
- **B — the app goes.** `op` without the integration signs in on its own
diff --git a/cce-1password.service b/cce-1password.service
new file mode 100644
index 0000000..bf39d7a
--- /dev/null
+++ b/cce-1password.service
@@ -0,0 +1,22 @@
+# The 1Password app, headless (KEYRING-SYNC.md, option A): what
+# cce-keyring-sync's `op` authorizes against. Its own "start at login" writes
+# ~/.config/autostart/com.onepassword.OnePassword.desktop, but nothing in a cce
+# session starts xdg-desktop-autostart.target, so that file never fires — on
+# 2026-10-02 the app was simply absent after two logins and the sync daemon
+# retried "1Password app not running" until it was opened by hand.
+# A second launch hands off to a running instance and exits 0, so starting
+# this beside an app opened by hand is harmless.
+[Unit]
+Description=1Password (headless, for cce-keyring-sync)
+After=graphical-session.target
+PartOf=graphical-session.target
+Before=cce-keyring-sync.service
+
+[Service]
+Type=simple
+ExecStart=/opt/1Password/1password --silent
+Restart=on-failure
+RestartSec=10
+
+[Install]
+WantedBy=graphical-session.target