ArchitectureSecurity model
Secrets in a build
Variables go to docker build as BuildKit secrets. They do not stay in the image or its history.
Ferry gives the values to the Docker CLI in its environment, never on its command line.
1 / 4
Variables reach docker build as BuildKit secrets: --secret id=KEY,env=…. A build secret exists only during one build step.
A Dockerfile that Ferry generates never declares a variable as ARG. Thus the values do not go into the image or its history.
In your own Dockerfile
Mount the secrets the same way:
RUN --mount=type=secret,id=KEY,env=KEY …ARG puts the value in the image history
For compatibility, your Dockerfile also gets --build-arg KEY for each ARG that it declares. BuildKit records these values in the image history. A secret in an ARG is the choice of your Dockerfile.