FerryDocs
ArchitectureSecurity model

Secrets in a build

Variables go to docker build as BuildKit secrets. They do not stay in the image or its history.

Edit on GitHub
environment--secretFerrydocker buildBuild stepsecret mountImageno secret

Ferry gives the values to the Docker CLI in its environment, never on its command line.

1 / 4

Variables reach docker build as BuildKit secrets: --secret id=KEY,env=…. A exists only during one build step.

A that Ferry generates never declares a variable as ARG. Thus the values do not go into the or its .

In your own Dockerfile

Mount the secrets the same way:

Dockerfile
RUN --mount=type=secret,id=KEY,env=KEY …

ARG puts the value in the image history

For compatibility, your Dockerfile also gets --build-arg KEY for each ARG that it declares. BuildKit records these values in the image history. A secret in an ARG is the choice of your Dockerfile.

On this page