This sounds wrong. If secrets are in the environment they are not in the Dockerfile, so they are NOT distributed with the application.
This sounds wrong. If secrets are in the environment they are not in the Dockerfile, so they are NOT distributed with the application.
Injecting environment variables at runtime, however (through docker run -e or whatever orchestration system you're using), is good.
It was the heading that got me on the wrong path, I think that should be clarified further:
> Do not store secrets in environment variables
Because PID 1 has that env, all processes spawned from that can read all of those.
I prefer mounting them to /run/secrets via tmpfs. Which can also have selinux policy attached.
This way, someone else cannot read them by spawning shell inside container
Seems such an obvious tip first up that it put me off reading the rest of the article.