Skip to content

Vault Presets ​

flow can store secrets in its own encrypted vaults, or read them from a secret manager you already use. Presets are tested configurations for that second case, so you don't have to write one by hand.

A vault created from a preset reads through to the provider: it holds links to secrets that already exist there and never writes to them.

PresetProviderRequires
1password1Passwordop, jq
passpass (GPG)pass
aws-ssmAWS Systems Manager Parameter Storeaws

Set one up ​

sh
mochi vault preset list                           # available presets
mochi vault preset preflight --preset 1password   # is the provider installed and usable?
mochi vault preset connect --preset 1password     # run the provider's sign-in step
mochi vault preset render op --preset 1password --out op-vault.json
mochi vault create op --type external --config op-vault.json

Provider options such as the 1Password vault or the AWS region are passed with --set key=value.

mochi vault preset browse lists what a provider holds, to help you find secrets worth linking.