Podman and Secrets – a Odyssee
We all deal with sensitive information when working with computer systems. Sysadmins move SSH keys around and web developers need to worry about API tokens. The problem with sensitive information is that it's sensitive, meaning that it could cause a security disaster if it were to somehow fall into the wrong hands. Containers are no exception to this issue—users need to utilize sensitive information inside containers while also needing to keep the sensitive information safe. [1]
you can create secrets on a easy way.
$ echo "secretdata" > secretfile.txt
$ podman secret create secretname secretfile.txt
e17465c9772b38f336fc4cbac
you can use the created secret easy, too
$ podman run --secret secretname --name foo alpine cat /run/secrets/secretname secretdata
actually there are only 2 ways to use this secrets.
- from local environment variable to container, as file
- from secret manager to container, as file
no nice way to get the secret direct to your container environment.
So far, so good.
a other way to create
is to read from stdin with read -s SECRET.
This way you have no traces in bash history.
$ read -s SECRET && echo -n $SECRET | podman secret create --replace MYSECRET - && unset SECRET
a other way to inject
is to possible by composers 'command' or 'entrypoint' directive.
services:
myservice:
...
command: bash -c 'declare -x MYSECRET=$(cat /run/secrets/MYSECRET) && ./start-up.sh'
secrets:
- MYSECRET
...
secrets:
MYSECRET:
external: true
how it works
after inserting the secret over read it will be echoed without a newline (-n) and passed to podman secret create --replace MYSECRET -. This (—replace existing key) creates the key from stdin (–) you want to use in your compose.
In the compose file is the initial command replaced by the import of the key and followed from the start command.
You can get the command / entrypoint by using
docker inspect RUNNING_CONTAINER_NAME --format='ENTRYPOINT: {{.Config.Entrypoint}} CMD: {{.Config.Cmd}}' and append them to the “new”
command / entrypoint line.
The secret injection use bash to declare the content of your secret-file in the enviroment-variable name you like to have.
Thats it!
[1] https://www.redhat.com/en/blog/new-podman-secrets-command