3 ms·
Basically what you want is a Docker image static analysis tool in your CICD that rejects your pull request if it seems to contain a secret. I'm not really sure
by tmsbrg 5y ago
Basically what you want is a Docker image static analysis tool in your CICD that rejects your pull request if it seems to contain a secret.
I'm not really sure what would be the best tool for this, but googling got me to https://sysdig.com/blog/20-docker-security-tools/ https://sysdig.com/blog/20-docker-security-tools/ which has enough scanning tools to research. I don't think any will be foolproof though.
Maybe you can also do what this guy did, use conftest with some OPA rules to detect what seems like a secret: https://cloudberry.engineering/article/dockerfile-security-best-practices/ https://cloudberry.engineering/article/dockerfile-security-b...
If your secrets all follow RFC 8959 ( https://tools.ietf.org/html/rfc8959 https://tools.ietf.org/html/rfc8959 ) then you could make it fool proof by just searching for secret-token: with the tool from the previous blog post. However I've yet to find a place that uses this RFC for all secrets.