Credentials without leaking them.
WHAT NOT TO DO
Bake secrets into images Pass them as build arguments Commit environment files Log them
WHY BUILD ARGUMENTS SPECIFICALLY
They are recorded in image history, readable by anyone with the image.
WHAT ENVIRONMENT VARIABLES EXPOSE
Inspection output Process listings Crash reports and logs
WHY THAT MATTERS LESS THAN IT SOUNDS
Anyone able to read them usually has access anyway.
WHY IT STILL MATTERS
Secrets leak into places you did not consider.
WHAT TO PREFER
Secrets mounted as files, readable only by the process.
WHAT ORCHESTRATORS PROVIDE
A secret object, mounted into the container at run time.
WHAT TO CHECK ABOUT THOSE
Whether they are encrypted at rest, which is not always the default.
WHAT A SECRETS MANAGER ADDS
Central storage, rotation, access control and audit.
WHAT IT COSTS
Another dependency at startup.
WHAT TO PLAN FOR
The manager being unavailable when a container starts.
WHAT TO ROTATE
Everything, on a schedule and after any departure.
WHAT TO DO WHEN A SECRET LEAKS
Rotate immediately, then investigate.
WHAT TO SCAN FOR
Secrets in images and repositories, automatically.
WHY
It happens constantly, and the history is permanent.