You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Docker Swarm的docker service create中用Secret值作为环境变量

Got it, let's tackle this problem. Since your PostgreSQL container's entrypoint needs the POSTGRES_USER and POSTGRES_PASSWORD as environment variables at startup (not just access to the secret files later), here's a step-by-step solution with a reusable script:

Step 1: Create the Required Docker Secrets

First, make sure you've created the secrets that store your PostgreSQL credentials. If you haven't already, run these commands (replace the example values with your own):

# Create secret for POSTGRES_USER (reads input from stdin)
echo "my_db_admin" | docker secret create postgres_user -

# Create secret for POSTGRES_PASSWORD (use a secure value in production!)
echo "my_strong_db_pass123" | docker secret create postgres_password -

Step 2: Bash Script to Create the Swarm Service

This script will validate that the secrets exist, extract their decoded values, and pass them as environment variables to the docker service create command:

#!/bin/bash

# Define the secrets we need for the service
REQUIRED_SECRETS=("postgres_user" "postgres_password")

# Check if all required secrets exist
for SECRET in "${REQUIRED_SECRETS[@]}"; do
    if ! docker secret inspect "$SECRET" &>/dev/null; then
        echo "❌ Error: Secret '$SECRET' doesn't exist. Please create it first."
        exit 1
    fi
done

# Extract decoded values from the secrets (Docker stores secrets as base64)
POSTGRES_USER=$(docker secret inspect --format='{{.Spec.Data | base64decode}}' postgres_user)
POSTGRES_PASSWORD=$(docker secret inspect --format='{{.Spec.Data | base64decode}}' postgres_password)

# Create the PostgreSQL Swarm service
docker service create \
    --name postgres-swarm-service \
    --env "POSTGRES_USER=$POSTGRES_USER" \
    --env "POSTGRES_PASSWORD=$POSTGRES_PASSWORD" \
    # Optional: Keep these lines if you also need the secret files accessible in the container
    --secret source=postgres_user,target=postgres_user \
    --secret source=postgres_password,target=postgres_password \
    --replicas 1 \
    postgres:latest

echo "✅ PostgreSQL service created successfully! Credentials loaded from Docker Secrets."

Key Details:

  • Reading Secret Values: The docker secret inspect command uses a Go template ({{.Spec.Data | base64decode}}) to decode the base64-encoded secret content stored by Docker.
  • Environment Variable Injection: We directly pass the decoded secret values as environment variables, so the container's entrypoint gets them immediately on startup.
  • Optional Secret Mounting: The --secret flags (commented as optional) will mount the secrets as files in /run/secrets/ inside the container, which can be useful if your app needs to read them later.
  • Error Prevention: The script checks for missing secrets upfront, so you don't get a half-created service due to missing credentials.

Pro Tip for Production:

Instead of hardcoding passwords, generate a secure random password for the secret:

openssl rand -hex 16 | docker secret create postgres_password -

内容的提问来源于stack exchange,提问作者nagylzs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:48:05