Skip to content

Add option to pass secrets as files #256

Description

@bryopsida

Expected Behavior

I'd like an option to pass secret values as files when appending _FILE after the current environment variable used for the value.

This behavior is consistent with other images such as MySQL, PostgreSQL (see the docker secrets section in the readme files for both).

Related to: apache/couchdb-helm#140

Current Behavior

Currently, the secret values can only be passed through environment variables which can be problematic when benchmark/scanner tools are used, see: https://avd.aquasec.com/compliance/kubernetes/cis-kubernetes-benchmarks-v1.23-1.23/5.4.1/ or bind mounts.

Enabling the _FILE option would allow for a cleaner implementation in the chart and is consistent with other official docker image behavior.

Possible Solution

The docker entry point could be updated to use COUCHDB_ADMIN_USER_FILE, COUCHDB_SECRET_FILE etc environment variables which have the path to a file holding the actual secret value.

Activity

  1. MichaelBrunn3r commented on Jun 6, 2024

    @MichaelBrunn3r

    An alternative could be a URI-like format like authentik uses (https://docs.goauthentik.io/docs/installation/configuration#about-authentik-configurations).

    services:
      couchdb:
        environment:
          # Original solution 
          COUCHDB_SECRET_FILE: /run/secrets/COUCHDB_SECRET
          # Solution like Authentik
          COUCHDB_SECRET: file:///run/secrets/COUCHDB_SECRET

    I have seen your solution more often and it should be easier to implement, so I would prefer it. Just wanted to show a possible alternative.

  2. janl commented on Sep 28, 2024

    @janl
    Member

    I’d look at a PR for this, if you’d make one :)

  3. axodentally commented on Dec 10, 2024

    @axodentally

    Why did #205 not get merged?

  4. bryopsida commented on Feb 14, 2025

    @bryopsida
    Author

    I created a draft PR here: #276 and am curious if this approach would be acceptable before I go further with it. Also I'm currently hitting some issues testing it due to the image build process breaking on my m1 laptop but should be able to move over to a x86 box to wrap the PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions