ArchitectureSecurity model
Secrets
Ferry keeps secret values out of images, logs and command lines. Only the containers get them.
Settings. A service stores a reference to a datastore password, not a copy.
1 / 6
A secret is a value that only your app must know: a password, a token, a key. Ferry keeps each secret out of the places where secrets leak.
Each secret has a page
| Secret | Protection |
|---|---|
| Variables during a build | Secrets in a build |
| Datastore passwords | Datastore passwords |
| A token in a repository URL | Repository credentials |
| The secrets of a connected git account | Connected git accounts |
| All of them, on the disk | The data directory |
The API gives secrets to each authenticated caller
The API returns variable values and datastore passwords to each caller that has the session or an API token. The dashboard shows them so that you can copy connection strings.