# Rancher Secret Support

**URL:** <https://forums.suse.com/t/rancher-secret-support/6422>\
**Category:** Rancher 1.x\
**Created:** [May 19, 2017, 1:36pm UTC](https://forums.suse.com/t/rancher-secret-support/6422 "2017-05-19T13:36:53Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Listener\_me](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/listener_me/32/5836_2.png) [@Listener\_me](https://forums.suse.com/u/Listener_me)\
**Post date:** [May 19, 2017, 1:36pm UTC](https://forums.suse.com/t/rancher-secret-support/6422/1 "2017-05-19T13:36:53Z")

</div>

Hello,

We got to know that, from v1.6.0 onwards, compose file support for rancher secret is enabled. But we are unable to do with below configuration in docker-compose.yml of the catalog. Its giving "Error (Service ‘mariadb’ configuration key ‘environment’ contains an invalid type, it should be an array or object) "

environment:  
- MYSQL\_ROOT\_PASSWORD\_FILE=/run/secrets/dbpass  
volumes:  
mariadb:  
driver: secrets-driver

Is there anything missing?

---

<div class="post-metadata">

**Author:** ![courcelm](https://avatars.discourse-cdn.com/v4/letter/c/a8b319/32.png) [@courcelm](https://forums.suse.com/u/courcelm)\
**Post date:** [May 23, 2017, 6:35pm UTC](https://forums.suse.com/t/rancher-secret-support/6422/2 "2017-05-23T18:35:42Z")

</div>

You need to add this section:

`  
secrets:

- source: secretname  
target: dbpass  
`

You don’t need secrets-driver.

---

<div class="post-metadata">

**Author:** ![Listener\_me](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/listener_me/32/5836_2.png) [@Listener\_me](https://forums.suse.com/u/Listener_me)\
**Post date:** [June 6, 2017, 4:36pm UTC](https://forums.suse.com/t/rancher-secret-support/6422/3 "2017-06-06T16:36:40Z")

</div>

Thanks for the reply, but it appears to be docker secrets, not the rancher secrets.

From the release notes on rancher 1.6, it appears that secret parameter supports docker-compose.yml in UI. It uses secret-driver. I can now even deploy with environment variable named MYSQL\_ROOT\_PASSWORD\_FILE, but the value defined in /run/secrets/dbpass is not populating into variable MYSQL\_ROOT\_PASSWORD. But it simply map the path name /run/secrets/dbpass to entire variable name MYSQL\_ROOT\_PASSWORD\_FILE

So I suspect we have to define environment variable in a different way(than \_FILE)

Any idea?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 6, 2017, 4:57pm UTC](https://forums.suse.com/t/rancher-secret-support/6422/4 "2017-06-06T16:57:59Z")

</div>

Secrets does not populate an environment variable with the password. The entire point of it is to provide an alternative to that, because environment variables have a variety of problems. They populate a file (through the secrets volume driver) which can be read in the container.

The pseudo-standard supported by official images like MySQL is to read a _path_ from an environment variable (`..._FILE`) and get the password from the contents of that file.

---

<div class="post-metadata">

**Author:** ![G\_Userfeeds](https://avatars.discourse-cdn.com/v4/letter/g/f0a364/32.png) [@G\_Userfeeds](https://forums.suse.com/u/G_Userfeeds)\
**Post date:** [June 12, 2017, 10:13am UTC](https://forums.suse.com/t/rancher-secret-support/6422/5 "2017-06-12T10:13:43Z")

</div>

@vincent in the docs there is ([https://docs.rancher.com/rancher/v1.6/en/cattle/secrets/](https://docs.rancher.com/rancher/v1.6/en/cattle/secrets/)):

`To take advantage of this, append _FILE to the environment variable name and the value would be /run/secrets/NAME>. When the container starts up, the value in the file will be assigned to the environment variable.`

I was under the impression that the environment variable will be populated with value from file after reading this.  
I couldn’t get it to work.

So the reality is that the images have unofficial convention of reading values from files if the env-var name ends with \_FILE? and there is not way to put value from /run/secrets/x to environment variable automatically? Is that correct?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 12, 2017, 9:59pm UTC](https://forums.suse.com/t/rancher-secret-support/6422/6 "2017-06-12T21:59:33Z")

</div>

That is what actually happens, but it is [implemented](https://github.com/docker-library/mysql/blob/master/5.7/docker-entrypoint.sh#L21-L41) by the image/entrypoint itself, not functionality built-in to Docker/Rancher. It’s just the pattern the common library images implement.

---

<div class="post-metadata">

**Author:** ![beatcracker](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/beatcracker/32/1482_2.png) [@beatcracker](https://forums.suse.com/u/beatcracker)\
**Post date:** [June 16, 2017, 4:29pm UTC](https://forums.suse.com/t/rancher-secret-support/6422/7 "2017-06-16T16:29:01Z")

</div>

> To take advantage of this, append \_FILE to the environment variable name and the value would be /run/secrets/NAME\>. When the container starts up, the value in the file will be assigned to the environment variable.

I had high hopes too, when I read this part. But quick googling revealed that you need image that implements this. Kinda disappointed.

I’d love to see native support for secrets as environment variables in Rancher. Is there any chance? Would creating GitHub issue help to bring more attention to this feature?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 16, 2017, 5:53pm UTC](https://forums.suse.com/t/rancher-secret-support/6422/8 "2017-06-16T17:53:16Z")

</div>

No; environment variables are less secure and we (and Docker secrets) intentionally do not support that.

---

<div class="post-metadata">

**Author:** ![Listener\_me](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/listener_me/32/5836_2.png) [@Listener\_me](https://forums.suse.com/u/Listener_me)\
**Post date:** [June 19, 2017, 4:25am UTC](https://forums.suse.com/t/rancher-secret-support/6422/9 "2017-06-19T04:25:54Z")

</div>

okay. But is it possible to atleast hide(encrypt) the values corresponding environment variables in “View config” section of a stack created?(just like hiding in UI while using “password” type option of a variable). Guess it will improve the security more

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 19, 2017, 4:25pm UTC](https://forums.suse.com/t/rancher-secret-support/6422/10 "2017-06-19T16:25:20Z")

</div>

The environment of a process is not secret. And that doesn’t accomplish anything anyway, the same string has to work if reimported and you can just print it out there.

If you want security, use secrets and read them from the (in-memory filesystem) file into your process memory. There is really not a lot in between.

(For bonus points, run the app as a non-root user and `chmod` the secrets so they’re no longer readable from the container after you load the values.)
