4.10 Do not store secrets in Dockerfiles

Information

https://github.com/docker/docker/issues/13490
2.http://12factor.net/config
3.https://avicoder.me/2016/07/22/Twitter-Vine-Source-code-dump/
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Do not store any kind of secrets within Dockerfiles.Impact-You would need to identify a way to handle secrets for your Docker images.Default Value-By default, there are no restrictions on storing config secrets in the Dockerfiles.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 50b5b584b18f3a79ca6235f5b44f6c65a24018d67be49c857ce75797d698d622