Podman and Secrets – a Odyssee

We all deal with sensitive information when working with computer systems. Sysadmins move SSH keys around and web developers need to worry about API tokens. The problem with sensitive information is that it's sensitive, meaning that it could cause a security disaster if it were to somehow fall into the wrong hands. Containers are no exception to this issue—users need to utilize sensitive information inside containers while also needing to keep the sensitive information safe. [1]

you can create secrets on a easy way.

$ echo "secretdata" > secretfile.txt
$ podman secret create secretname secretfile.txt
e17465c9772b38f336fc4cbac

you can use the created secret easy, too

$ podman run --secret secretname --name foo alpine cat /run/secrets/secretname secretdata

actually there are only 2 ways to use this secrets.

  1. from local environment variable to container, as file
  2. from secret manager to container, as file

no nice way to get the secret direct to your container environment.

So far, so good.

a other way to create

is to read from stdin with read -s SECRET. This way you have no traces in bash history.

$ read -s SECRET && echo -n $SECRET | podman secret create --replace MYSECRET - && unset SECRET 

a other way to inject

is to possible by composers 'command' or 'entrypoint' directive.

services:
  myservice:
...
  command: bash -c 'declare -x MYSECRET=$(cat /run/secrets/MYSECRET) && ./start-up.sh'
  secrets:
      - MYSECRET
...
secrets:
  MYSECRET:
    external: true

how it works

after inserting the secret over read it will be echoed without a newline (-n) and passed to podman secret create --replace MYSECRET -. This (—replace existing key) creates the key from stdin (–) you want to use in your compose.

In the compose file is the initial command replaced by the import of the key and followed from the start command.

You can get the command / entrypoint by using docker inspect RUNNING_CONTAINER_NAME --format='ENTRYPOINT: {{.Config.Entrypoint}} CMD: {{.Config.Cmd}}' and append them to the “new” command / entrypoint line.

The secret injection use bash to declare the content of your secret-file in the enviroment-variable name you like to have.

Thats it!

[1] https://www.redhat.com/en/blog/new-podman-secrets-command