August 2018
Intermediate to advanced
352 pages
12h 30m
English
It works like this, when you add a secret to Swarm, it will store this encrypted secret in its internal Raft store. When you create your service and reference that secret, Swarm will give those containers access to the secret, and it will add the unencrypted secret as an in-memory filesystem mount inside the container. In order to read the secret, your application will need to look at the filesystem mount instead of the environment.
If the secret is removed, or the service is updated to remove the secret, the secret will no longer be available to the container.
Read now
Unlock full access