FerryDocs
ArchitectureSecurity model

Secrets

Ferry keeps secret values out of images, logs and command lines. Only the containers get them.

Edit on GitHub

Settings. A service stores a reference to a datastore password, not a copy.

1 / 6
Where a secret goes, and where it does not go

A secret is a value that only your app must know: a password, a token, a key. Ferry keeps each secret out of the places where secrets leak.

Each secret has a page

SecretProtection
Variables during a buildSecrets in a build
Datastore passwordsDatastore passwords
A token in a repository URLRepository credentials
The secrets of a connected git accountConnected git accounts
All of them, on the diskThe data directory

The API gives secrets to each authenticated caller

The API returns variable values and datastore passwords to each caller that has the session or an API token. The dashboard shows them so that you can copy .

On this page