apache / apache/couchdb-docker

Add option to pass secrets as files

Open
#256 4 comments 4 reactions 0 assignees View on GitHub
Dominant language
Dockerfile
Stars
290
Forks
146
PR merge metrics
No merged PRs in 30d

Description

## Expected Behavior

I'd like an option to pass secret values as files when appending `_FILE` after the current environment variable used for the value.

This behavior is consistent with other images such as MySQL, PostgreSQL (see the docker secrets section in the readme files for both).

Related to: https://github.com/apache/couchdb-helm/issues/140

## Current Behavior

Currently, the secret values can only be passed through environment variables which can be problematic when benchmark/scanner tools are used, see: https://avd.aquasec.com/compliance/kubernetes/cis-kubernetes-benchmarks-v1.23-1.23/5.4.1/ or bind mounts.

Enabling the `_FILE` option would allow for a cleaner implementation in the chart and is consistent with other official docker image behavior.

## Possible Solution

The docker entry point could be updated to use `COUCHDB_ADMIN_USER_FILE`, `COUCHDB_SECRET_FILE` etc environment variables which have the path to a file holding the actual secret value.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.