FerryDocs

Secrets in a build

Ferry gives the variables to a build as BuildKit secrets. A secret does not stay in the image.

Edit on GitHub
VariableNPM_TOKENBuild argumentImage historyall can read itBuildKit secretOne build stepnpm ci

Docker records the value of a build argument in the history of the image.

1 / 2

In a generated Dockerfile, Ferry uses and never . Each person who has the image can read its .

In your own Dockerfile

Each variable is a secret. Its id is the name of the variable. Mount it into the steps that need it.

Dockerfile
FROM node:22-alpine
WORKDIR /app
COPY package.json package-lock.json ./
RUN --mount=type=secret,id=NPM_TOKEN,env=NPM_TOKEN npm ci 
COPY . .
RUN npm run build
CMD ["npm", "start"]

Requires Docker Engine 27.3 or newer

env= in --mount=type=secret needs Docker Engine 27.3 or newer on the Ferry server. With an older engine, a build that uses variables fails. The message tells you to upgrade Docker.

On this page