Using docker .env file for storing keys for the various services is highly insecure. Appending _FILE to env variables to read from /run/secrets/etc makes the services unable to start due to missing information.
Docker foundation recommends using docker secrets either via local file(compose) or docker secret create(swarm mode). This allows better security practices for all secure keys.
https://docs.docker.com/compose/how-tos/use-secrets/https://docs.docker.com/engine/swarm/secrets/
Steps to reproduce
generate keys and place into files/docker secrets(NOT .ENV FILE)
append "_FILE" to all env variables relating to securely generated keys, changing the value to match /run/secrets/ location that is mounted within the containers
attempt to start the stack.
The stack fails to start due to it not finding information for keys(postgres password etc)
Logs or screenshots
Can provide logs and screenshots if needed.
Rex changed the status from Needs triage to Under consideration
This is a very nice feature that would've saved me headaches as well, but hardly a bug I think. If you want to get it done, you can wrap the image's entrypoint in a custom script that inserts the needed secret files into the environment with export bash commands at runtime.
Can you give me an example? I used the example from postgress to do this
but it doesn't seem to work. You can see what I'm using in the API folder
on my fork.
RexSystem1 voteoriginally by @kaibsora on GitHub OP
I have successfully refactored the api keys to be usable with secrets. I've just tested it with api and it works as expected. I'll be making pull request for refactoring with use of docker secrets for sensitive information
3 comments
Comment by @midblep
exportbash commands at runtime.Comment by @kaibsora
Comment by @kaibsora
Deleted comment