3 ms·
>> Do not store secrets in environment variables > Yes, definitely don't put secrets in the Dockerfile itself. I'm curious if there are reasons not to use a .e
by PowerBar 6y ago
>> Do not store secrets in environment variables
> Yes, definitely don't put secrets in the Dockerfile itself. I'm curious if there are reasons not to use a .env file though?
Environment variables are a terrible place to store secrets, regardless of whether you're using docker.
Environment variable values get dumped all over the place. /proc/*/environ, docker inspect, /var/log/..., core dumps, error messages, info pages (phpinfo), etc. Also, unlike file handles and secrets services (hashicorp vault, etc), every child process inherits all of its parents' environment variables, greatly increasing the attack surface.