[E00-S02-T08] Secrets are not embedded in image #175
Closed
opened 2026-08-27 00:07:17 +00:00 by kpcto
·
27 comments
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#175
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Intent
Ensure no secrets are embedded in the application image.
Acceptance criteria
apps/server/Dockerfiledeclares no secret-bearingARG/ENV(the onlyENVisNODE_ENV=production), and everyCOPYtargets a fixed, non-secret path (noCOPYof.env/credential files, no blanketCOPY . .)postgres://eppp:eppp@db:5432/eppp).dockerignorepatterns for env/credential files are**/-prefixed (**/.env,**/.env.*,**/node_modules,**/.npmrc,**/.netrc,**/.credentials,**/.aws,**/.ssh,**/secrets,**/*.pem,**/*.key,**/*.p12,**/*.pfx,**/*.jks,**/id_rsa,**/id_ed25519), because Docker's real matcher (moby/patternmatcher) anchors slash-less patterns to the context root — a bare.npmrc/*.key/secretsexcludes nothing underapps/server/….dockerignoresemantics (anchored full-path match + parent-directory propagation, as in moby/patternmatcher), not gitignore basename semantics; the tests assert nested example paths (apps/server/.npmrc,config/server.key,apps/server/secrets/…) are excluded, and no redundant equivalent patterns (e.g. bothsecretsandsecrets/) are required verbatimnode --test(and, where Docker is available, the image layer-scan probe) on every PR, so the static assertions gate merges rather than only dev machinesExplicitly out of scope
Test plan
tests/secrets-not-embedded.test.mjs) assert the Dockerfile declares no secretARG/ENVand copies no secret paths, and that.dockerignoreexcludes credential files at the root and at any depth via a Docker-faithful matcher (asserting nested example paths such asapps/server/.npmrc,config/server.key,apps/server/secrets/*)docker buildfrom the repo root with a marker env file in the context) and scan every layer (raw + decompressed) plus the image config, confirming no secret values are presentnode --test tests/*.test.mjs) on every PR; a Docker-enabled job runs the layer-scan probe where a daemon existsRollback note
Owning stream
platform
Risk quadrant
agent-full
status/readymay only be applied by a human maintainer.