Skip to content

feat(plugin): add cockroach sql support - #536

Open
syndbg wants to merge 7 commits into
1Password:mainfrom
syndbg:feat-add-cockroach-sql-support
Open

syndbg wants to merge 7 commits into
1Password:mainfrom
syndbg:feat-add-cockroach-sql-support

Conversation

@syndbg

@syndbg syndbg commented Aug 12, 2025

Copy link
Copy Markdown

Overview

This PR adds a new shell plugin for CockroachDB that enables secure credential management for the cockroach sql command. The plugin supports both local development (insecure mode) and production environments (secure TLS connections) through environment variable configuration.

Type of change

  • Created a new plugin
  • Improved an existing plugin
  • Fixed a bug in an existing plugin
  • Improved contributor utilities or experience

Related Issue(s)

  • Resolves: #
  • Relates: #

How To Test

tl;dr There's a demo. https://streamable.com/btqzp5. It goes from a clean DB credential creation, renaming fields to match the expected format, etc.

Apologies for the streamable link, but GitHub has a 10mb file size limit and the mp4 demo video was already 58 or so mb.

  1. Set up database credentials in 1Password with the following fields:

    • Host: localhost
    • Port: 26257
    • User: root
    • Database: defaultdb
    • insecure: 1 (for local development)
  2. Test with local CockroachDB instance:

    # Start CockroachDB in insecure mode
    cockroach start-single-node --insecure --listen-addr=localhost:26257
    
    # Test the plugin
    op run -- cockroach sql
  3. Test environment variable import:

    export COCKROACH_HOST=localhost
    export COCKROACH_PORT=26257
    export COCKROACH_USER=root
    export COCKROACH_INSECURE=1
    op plugin init cockroachdb
  4. Run plugin validation:

    go run cmd/contrib/main.go cockroachdb/validate

Changelog

The CockroachDB plugin enables authentication for the cockroach sql command using Touch ID and other unlock options with 1Password Shell Plugins.

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ This PR contains unsigned commits. To get your PR merged, please sign those commits (git rebase --exec 'git commit -S --amend --no-edit -n' @{upstream}) and force push them to this branch (git push --force-with-lease).

If you're new to commit signing, there are different ways to set it up:

Sign commits with gpg

Follow the steps below to set up commit signing with gpg:

  1. Generate a GPG key
  2. Add the GPG key to your GitHub account
  3. Configure git to use your GPG key for commit signing
Sign commits with ssh-agent

Follow the steps below to set up commit signing with ssh-agent:

  1. Generate an SSH key and add it to ssh-agent
  2. Add the SSH key to your GitHub account
  3. Configure git to use your SSH key for commit signing
Sign commits with 1Password

You can also sign commits using 1Password, which lets you sign commits with biometrics without the signing key leaving the local 1Password process.

Learn how to use 1Password to sign your commits.

Watch the demo

@syndbg
syndbg force-pushed the feat-add-cockroach-sql-support branch 3 times, most recently from 6122e82 to 24adb36 Compare August 12, 2025 23:23

@Marton6 Marton6 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good! Thank you for your contribution

@syndbg

syndbg commented Aug 26, 2025

Copy link
Copy Markdown
Author

Neat-o. Perhaps 1 more reviewer. 👁️

@mrjones2014 if you have the time

@syndbg

syndbg commented Apr 8, 2026

Copy link
Copy Markdown
Author

Semi-yearly vibe check for 1 more review to get this merged. Perhaps @bertrmz @RyanPrussin

@rr3khan rr3khan closed this Sep 22, 2026
@rr3khan rr3khan reopened this Sep 22, 2026
@syndbg
syndbg force-pushed the feat-add-cockroach-sql-support branch from 24adb36 to 51aadf7 Compare September 22, 2026 21:06
@syndbg

syndbg commented Sep 22, 2026

Copy link
Copy Markdown
Author

@rr3khan I saw that the field name insecure was updated to Insecure. Fixed in 51aadf7 .

Also rebased from origin/main, since I missed a few years of commits. :)

Comment thread plugins/cockroachdb/database_credentials.go Outdated
Comment thread plugins/cockroachdb/database_credentials_test.go Outdated
"COCKROACH_HOST": fieldname.Host,
"COCKROACH_PORT": fieldname.Port,
"COCKROACH_USER": fieldname.User,
"COCKROACH_PASSWORD": fieldname.Password,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
"COCKROACH_PASSWORD": fieldname.Password,
"PGPASSWORD": fieldname.Password,
Image

I tested a real CockroachDB v26.3.1 cluster with COCKROACH_PASSWORD set, cockroach sql still drops to an interactive Enter password: prompt instead of connecting. cockroach's SQL client is libpq-compatible and reads the standard PGPASSWORD env var and I was able to confirm that it worked with this locally.

@rr3khan

rr3khan commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

@rr3khan I saw that the field name insecure was updated to Insecure. Fixed in 51aadf7 .

Also rebased from origin/main, since I missed a few years of commits. :)

@syndbg Thanks so much for fixing that so quickly, I have left some comments with some of my other findings, if you address them I would be more than happy to approve and merge.

@syndbg

syndbg commented Oct 2, 2026

Copy link
Copy Markdown
Author

Cheers. Will re-check over the next few days and get it again in shape.

syndbg added 2 commits October 2, 2026 21:04
Adds the ability to read Database Credentials and
 inject for `cockroach sql`.

Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
The names were updated upstream.

Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
@syndbg
syndbg force-pushed the feat-add-cockroach-sql-support branch from 51aadf7 to d7853bd Compare October 2, 2026 18:04
syndbg added 5 commits October 2, 2026 21:34
1Password rejects URL fields on Database items, which prevents
importing CockroachDB credentials.

Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
The SQL CLI ignores COCKROACH_PASSWORD and prompts for a password.
Use PGPASSWORD so provisioned credentials authenticate correctly.

Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
Run the importer and provisioner against CockroachDB in Docker.
Check insecure and TLS connections, password failures, and the
environment variable the SQL CLI accepts.

Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
@syndbg

syndbg commented Oct 2, 2026

Copy link
Copy Markdown
Author

Okay, had more time than I expected. It's working and verified now.
I took some creative liberty in a5ef840 to actually test it with a real docker container. I think this opens up a nice pattern for existing database plugins to also add their own tests with real containers.

And a user test. I re-checked with the same cockroachdb I had previously tested with cockroachdb:v25.2.4.

This is what I put in my OP Vault

CleanShot 2026-10-02 at 22 31 36@2x

Full gif showcasing the user flow.

From an op init, to actually using the cockroach sql. I explicitly unset the env vars that might influence the result to make sure we're all relying on the shell plugin.

preview

@rr3khan ready for re-review. 🍻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants