Documentation
¶
Overview ¶
Package secretexec is the governed entrypoint shim of ADR-0045 Stage 2 (plan 20, "Images that read a secret only from the environment"). A native container whose image reads a secret only from its environment starts this shim as its entrypoint: the shim reads each mounted owner-only secret file, adds the value to its own environment and replaces itself (execve) with the image's original entrypoint and command. The value then exists only in the running process, never in the OpenTofu root, its state or the container configuration (`docker inspect`).
The shim is the static stackkit binary itself, started under the name BinaryName (argv[0] dispatch), so no further binary ships with a release.
Index ¶
Constants ¶
const BinaryName = "stackkit-secret-exec"
BinaryName is the argv[0] under which the stackkit binary acts as the shim.
const MountPath = "/run/stackkit/bin/" + BinaryName
MountPath is where a native container sees the shim (read-only).
Variables ¶
This section is empty.
Functions ¶
func Plan ¶
func Plan(args, environ []string, readFile func(string) ([]byte, error)) (string, []string, []string, error)
Plan resolves the shim's arguments `--env NAME=FILE ... -- PROGRAM ARGS...` into the program, its argv and its environment. A secret file must hold exactly one value: no NUL, no line break, no surrounding space; a variable the environment already carries is refused, so an image cannot receive the value twice or have a declared variable silently replaced.
Types ¶
This section is empty.