Docker secrets not usable

(#720) Feature Under consideration security self-hosting

Summary

Using docker .env file for storing keys for the various services is highly insecure. Appending _FILE to env variables to read from /run/secrets/etc makes the services unable to start due to missing information. Docker foundation recommends using docker secrets either via local file(compose) or docker secret create(swarm mode). This allows better security practices for all secure keys. https://docs.docker.com/compose/how-tos/use-secrets/ https://docs.docker.com/engine/swarm/secrets/

Steps to reproduce

  1. generate keys and place into files/docker secrets(NOT .ENV FILE)
  2. append "_FILE" to all env variables relating to securely generated keys, changing the value to match /run/secrets/ location that is mounted within the containers
  3. attempt to start the stack.
The stack fails to start due to it not finding information for keys(postgres password etc)

Logs or screenshots

Can provide logs and screenshots if needed.
  1. Rex changed the status from Needs triage to Under consideration

3 comments

Sign in with Fluxer to comment and vote.
Comment by @midblep
RexSystem 1 vote originally by @midblep on GitHub
This is a very nice feature that would've saved me headaches as well, but hardly a bug I think. If you want to get it done, you can wrap the image's entrypoint in a custom script that inserts the needed secret files into the environment with export bash commands at runtime.
Comment by @kaibsora
RexSystem 1 vote edited originally by @kaibsora on GitHub OP
Can you give me an example? I used the example from postgress to do this but it doesn't seem to work. You can see what I'm using in the API folder on my fork.
Comment by @kaibsora
RexSystem 1 vote originally by @kaibsora on GitHub OP
I have successfully refactored the api keys to be usable with secrets. I've just tested it with api and it works as expected. I'll be making pull request for refactoring with use of docker secrets for sensitive information
Deleted comment
Removed by moderator Rex: Removed a general status note that was posted on many GitHub threads. It no longer applies here.