28 ms·
This looks amazing. Solving secret distribution across containers will be very useful. Being able to see via `docker secret` exactly which services are using
by unpythonic 10y ago
This looks amazing. Solving secret distribution across containers will be very useful. Being able to see via `docker secret` exactly which services are using which secrets is an unexpected treat.
I'm a little worried about two aspects of what has been shown. From the article it shows:
$ docker exec $(docker ps --filter name=redis -q) ls -l /run/secrets
total 4
-r--r--r-- 1 root root 17 Dec 13 22:48 my_secret_data
From this we can tell exactly how long the secret is. If the secret service didn't do it for us, I'd like for the secrets to be null-padded to a uniform 2-4K of bytes.
I'm also a bit worried that the default protection on the file has it set to world-readable. Since it appears that secret distribution is independent of the container setup itself, there doesn't appear to be any way of setting ownership and permissions on this file. That is, if one were able to chmod/chown the file in the Dockerfile, running a `docker service update --secret-rm` and `docker service update --secret-add` would reset such 'fixes'.
A great start, and I can't wait to start using it.
- cyli 10y agoYou can specify the UID, GID, and mode of the secret from within the container: https://docs.docker.com/engine/reference/commandline/service_create/#/create-a-service-with-secrets https://docs.docker.com/engine/reference/commandline/service..., and pass the same configuration to the service update command as well.
- unpythonic 10y agoOh, that's great to know. That coupled with filling out the size to an uninteresting length with nulls (or another delimiter) covers my concerns. For example: $ echo "my secret" | dd bs=512 conv=sync | docker secret create my_secret_data -