{"id":1998,"date":"2021-05-06T20:01:37","date_gmt":"2021-05-06T20:01:37","guid":{"rendered":"https:\/\/jan.schnasse.org\/blog\/?p=1998"},"modified":"2021-05-06T20:01:37","modified_gmt":"2021-05-06T20:01:37","slug":"password-leaks-using-docker","status":"publish","type":"post","link":"https:\/\/jan.schnasse.org\/blog\/2021\/05\/06\/password-leaks-using-docker\/","title":{"rendered":"Password Leaks in Docker"},"content":{"rendered":"<p><a href=\"https:\/\/pythonspeed.com\/articles\/leaking-secrets-docker\/\">https:\/\/pythonspeed.com\/articles\/leaking-secrets-docker\/<\/a><\/p>\n<p>&#8222;How can you prevent copying in secrets by mistake?<\/p>\n<ul>\n<li><strong>Limited copying:<\/strong> Instead of <code class=\"highlighter-rouge\">COPY . \/app<\/code> you might copy only specific files or directories you know you need. For example, <code class=\"highlighter-rouge\">COPY setup.py myapp \/app<\/code>.<\/li>\n<li><strong>.dockerignore<\/strong>: You can make sure files don\u2019t get <code class=\"highlighter-rouge\">COPY<\/code>ed in by adding them to the <a href=\"https:\/\/docs.docker.com\/engine\/reference\/builder\/#dockerignore-file\"><code class=\"highlighter-rouge\">.dockerignore<\/code> file<\/a>.<\/li>\n<li><strong>Avoid manually building images:<\/strong> Your development machine is much more likely to have random files lying around than an automated build system, so building public images on your dev machine is more likely to leak files.<\/li>\n<li><strong>Store CI secrets as environment variables:<\/strong> If your CI or build environment needs to use secrets, keep them in environment variables rather than files on disk.&#8220;<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>https:\/\/pythonspeed.com\/articles\/leaking-secrets-docker\/ &#8222;How can you prevent copying in secrets by mistake? Limited copying: Instead of COPY . \/app you might copy only specific files or directories you know you need. For example, COPY setup.py myapp \/app. .dockerignore: You can make sure files don\u2019t get COPYed in by adding them to the .dockerignore file. Avoid manually building [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-1998","post","type-post","status-publish","format-standard","hentry","category-bookmarks"],"_links":{"self":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts\/1998","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/comments?post=1998"}],"version-history":[{"count":0,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts\/1998\/revisions"}],"wp:attachment":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/media?parent=1998"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/categories?post=1998"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/tags?post=1998"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}