Skip to content

Glob and folder patterns

hhrvoic edited this page Aug 21, 2026 · 1 revision

Besides literal paths, files entries can be patterns:

Pattern Meaning
* Any characters within one path component (never crosses /).
? One character within a component.
** As a whole path component, any characters across directories; **/ matches zero or more whole directories.
dir/ Trailing slash is folder shorthand for dir/** — everything under dir, recursively.
{
  "vaults": [
    {
      "name": "staging",
      "vault": "project-myapp-ios-staging",
      "files": [
        "MyApp/SupportingFiles/Vault/**/*.staging.*",
        "Certs/"
      ]
    }
  ]
}

On write, patterns expand against the local tree and every match is uploaded (and stamped with its path). On read, patterns match the path fields stored on the vault's documents, and every hit is downloaded to its stamped path — documents without the field are invisible to patterns, so run write once before relying on pattern read. When a literal entry and a pattern overlap, the file syncs once. Regex metacharacters in patterns are treated literally, and ** is only directory-crossing as a component of its own — inside a component (a**b) it behaves as two ordinary stars, like gitignore.

A pattern hands the vault control over where files land, so read refuses any stored path that could escape the repo (absolute, ~, .., leading -) or take over the next run: .git, .github, .gitmodules, .gitattributes and .secrets.config.json are never written, at any depth. Two documents stamped with the same path are skipped rather than raced.

Moving a file leaves its old document behind: write creates a new one at the new path, and the old stamp keeps matching your pattern, so read would restore the file at its old location indefinitely. write points at the leftover when it spots one — delete that item in 1Password.

Typical setups

Depending on how a project lays out its secrets, glob handling enables a few common configuration styles:

  • One secrets folder per environment vault. Each vault owns the whole folder via the trailing-slash shorthand, and new files sync without touching the config:

    "files": ["MyApp/SupportingFiles/Vault/"]
  • Shared tree, environment picked by suffix. Both environments keep files in the same folders; each vault selects its own by name:

    "files": ["MyApp/Vault/**/*.staging.*"]     // staging vault
    "files": ["MyApp/Vault/**/*.production.*"]  // production vault
  • Target-based folders with identical file names. Folder shorthand per vault; the stored path field keeps the same-named documents apart:

    "files": ["Staging/"]      // e.g. Staging/GoogleService-Info.plist
    "files": ["Production/"]   // e.g. Production/GoogleService-Info.plist
  • One file type, wherever it lives. Scope by extension, optionally under a subtree:

    "files": ["**/*.xcconfig", "Certs/**/*.pem"]
  • Literal anchors plus a catch-all. Must-have files stay explicit (so a missing one is reported by name), the folder pattern picks up the rest — an overlap syncs once:

    "files": ["Keys/Keys.swift", "Keys/"]

Clone this wiki locally