apiVersion: apps/v1 kind: Deployment metadata: name: kube-1password-secrets spec: selector: matchLabels: app.kubernetes.io/name: kube-1password-secrets replicas: 1 template: metadata: labels: app.kubernetes.io/name: kube-1password-secrets spec: containers: - image: kube-1password-secrets name: kube-1password-secrets env: - name: OP_SERVICE_ACCOUNT_TOKEN valueFrom: secretKeyRef: name: kube-1password-secrets key: OP_SERVICE_ACCOUNT_TOKEN volumeMounts: - mountPath: "/root/.op" name: op serviceAccountName: kube-1password-secrets restartPolicy: Always volumes: - name: op persistentVolumeClaim: claimName: kube-1password-secrets