Knowledgebase

Handling Secrets in Containers Print

  • 0

Credentials without leaking them.

WHAT NOT TO DO

Bake secrets into images Pass them as build arguments Commit environment files Log them

WHY BUILD ARGUMENTS SPECIFICALLY

They are recorded in image history, readable by anyone with the image.

WHAT ENVIRONMENT VARIABLES EXPOSE

Inspection output Process listings Crash reports and logs

WHY THAT MATTERS LESS THAN IT SOUNDS

Anyone able to read them usually has access anyway.

WHY IT STILL MATTERS

Secrets leak into places you did not consider.

WHAT TO PREFER

Secrets mounted as files, readable only by the process.

WHAT ORCHESTRATORS PROVIDE

A secret object, mounted into the container at run time.

WHAT TO CHECK ABOUT THOSE

Whether they are encrypted at rest, which is not always the default.

WHAT A SECRETS MANAGER ADDS

Central storage, rotation, access control and audit.

WHAT IT COSTS

Another dependency at startup.

WHAT TO PLAN FOR

The manager being unavailable when a container starts.

WHAT TO ROTATE

Everything, on a schedule and after any departure.

WHAT TO DO WHEN A SECRET LEAKS

Rotate immediately, then investigate.

WHAT TO SCAN FOR

Secrets in images and repositories, automatically.

WHY

It happens constantly, and the history is permanent.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot