Secrets in container instances
Pass vault secrets to a container instance as environment variables.
Reference a secret
In the container instance's Components tab, add an environment variable to a container and take its value from a vault: pick the vault and the secret. The variable's name is yours to choose, but a vault-backed name must be unique within the component, across all its containers.
Important
Secrets are delivered per component, not per container. As soon as one container in a component references a vault secret, every container in that component — init containers included — gets all of the component's vault-backed values: the file
/secrets/env.jsonis mounted in each of them, and each container whose command is known is started through the wrapper below and receives the values as environment variables. Put a container that must not see the secrets in a component of its own.
Declare the command
Secrets reach a container as real environment variables because the platform starts the
container through a small wrapper: it loads the values and then runs the container's own
command. For that it must know the command, so a container that references a vault secret has
to declare it — the image's ENTRYPOINT as the command and its CMD as the arguments. Without
it the change is refused:
Container '<name>' references a vault secret but declares no command. Vault-backed variables are delivered by wrapping the container's entrypoint, so declare the image's ENTRYPOINT (and CMD as args).The portal warns about a missing command before you save.
Access to the vault
Saving the container instance assigns its identity Secrets Reader on every vault it references, if you are allowed to — see Give a workload access.
When a value changes
Values are loaded when a container starts. Restart the container instance to pick up a changed secret.