secretexec

package
v0.51.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package secretexec is the governed entrypoint shim of ADR-0045 Stage 2 (plan 20, "Images that read a secret only from the environment"). A native container whose image reads a secret only from its environment starts this shim as its entrypoint: the shim reads each mounted owner-only secret file, adds the value to its own environment and replaces itself (execve) with the image's original entrypoint and command. The value then exists only in the running process, never in the OpenTofu root, its state or the container configuration (`docker inspect`).

The shim is the static stackkit binary itself, started under the name BinaryName (argv[0] dispatch), so no further binary ships with a release.

Index

Constants

View Source
const BinaryName = "stackkit-secret-exec"

BinaryName is the argv[0] under which the stackkit binary acts as the shim.

View Source
const MountPath = "/run/stackkit/bin/" + BinaryName

MountPath is where a native container sees the shim (read-only).

Variables

This section is empty.

Functions

func Invoked

func Invoked(argv0 string) bool

Invoked reports whether argv0 names the shim.

func Main

func Main(args []string) int

Main runs the shim with the process arguments and never returns on success.

func Plan

func Plan(args, environ []string, readFile func(string) ([]byte, error)) (string, []string, []string, error)

Plan resolves the shim's arguments `--env NAME=FILE ... -- PROGRAM ARGS...` into the program, its argv and its environment. A secret file must hold exactly one value: no NUL, no line break, no surrounding space; a variable the environment already carries is refused, so an image cannot receive the value twice or have a declared variable silently replaced.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL