Skip to main content
September 8, 2026
Question

Windows: Injecting 1Password environments variables into Docker Compose without a plaintext .env file

  • September 8, 2026
  • 0 replies
  • 12 views

Hi, I plan to use 1Password Environments to manage credentials for local development of a Django application running in Docker containers. I want to inject environment variables into those containers at runtime without maintaining a plaintext .env file or baking secrets into images.

I understand that macOS and Linux can use a locally mounted .env file with Docker Compose’s env_file support. I am developing on Windows, however, and I do not see the Local .env file option—only AWS Secrets Manager, GitHub Actions, CLI, and SDK workflows.

Is there a supported Windows-native way to connect a 1Password Environment directly to Docker Compose? If not, is the recommended approach to use the 1Password CLI to load Environment values before running docker compose up?

If so, could you share the current recommended Windows/PowerShell command or workflow—ideally one that makes the same Environment values available to multiple Compose services without writing secrets to disk?

As a last-resort workaround, I considered a Docker wrapper script that runs Docker Compose through op run, using a local .env.1password file containing op:// references to individual vault items. I would prefer not to use that approach because it bypasses the Environment feature I am trying to adopt, requires maintaining a separate reference file, and means developers must use a wrapper rather than the usual docker compose command.

Is there a more direct, supported integration between 1Password Environments and Docker Compose on Windows, or is the CLI-wrapper approach currently the recommended solution?