Re: Questions about secret handling in Mesos

2018-04-23 Thread Zhitao Li
Hi Alexander, We discovered that in our own testing thus do not plan to use the environment variable. For the `volume/secret` case, I believe it's possible to be careful enough so we do not log that, so it's more about whether we want to promise that. What do you think? On Mon, Apr 23, 2018 at

Re: Questions about secret handling in Mesos

2018-04-23 Thread Alexander Rojas
Hey Zhitao, I sadly have to tell you that the first assumption is not correct. If you use environment based secrets, docker and verbose mode, they will get printed (see this patch https://reviews.apache.org/r/57846/ ). The reason is that the docker command