BaGet icon indicating copy to clipboard operation
BaGet copied to clipboard

[Feature Request] API key as docker secret

Open lonix1 opened this issue 3 years ago • 0 comments

Currently the API key is provided in an env file. That means it is exposed as an environment variable, as well as in logs.

Ideally it should be a docker secret.

On the host it would (still be) the responsibility of the user how to handle it - it's not baget's problem. But in the container, it would be mounted as a file and so cannot leak.

If the user is not using a docker swarm then docker secrets are not available, so in that case just let him use environment variables as usual (or he should run a single-node swarm, which is easy to do). That would be backwards compatible.

Thank you for considering it!

lonix1 avatar Jul 12 '22 03:07 lonix1