Skip to content
Stackship documentation Svenska

SecretsUsers

Secrets in container instances

Pass vault secrets to a container instance as environment variables.

Reference a secret

In the container instance's Components tab, add an environment variable to a container and take its value from a vault: pick the vault and the secret. The variable's name is yours to choose, but a vault-backed name must be unique within the component, across all its containers.

Important

Secrets are delivered per component, not per container. As soon as one container in a component references a vault secret, every container in that component — init containers included — gets all of the component's vault-backed values: the file /secrets/env.json is mounted in each of them, and each container whose command is known is started through the wrapper below and receives the values as environment variables. Put a container that must not see the secrets in a component of its own.

Declare the command

Secrets reach a container as real environment variables because the platform starts the container through a small wrapper: it loads the values and then runs the container's own command. For that it must know the command, so a container that references a vault secret has to declare it — the image's ENTRYPOINT as the command and its CMD as the arguments. Without it the change is refused:

text
Container '<name>' references a vault secret but declares no command. Vault-backed variables are delivered by wrapping the container's entrypoint, so declare the image's ENTRYPOINT (and CMD as args).

The portal warns about a missing command before you save.

Access to the vault

Saving the container instance assigns its identity Secrets Reader on every vault it references, if you are allowed to — see Give a workload access.

When a value changes

Values are loaded when a container starts. Restart the container instance to pick up a changed secret.