One thing I do to prevent stuff from getting into a public git repo is:
In the git repo, make a file called .gitignore then add the line .env to it. Then git will ignore any file named .env
edit compose files from a computer that is separate from the one that gets secrets. I have my desktop setup to push to github. Then I make a change, then simply run `git pull on my server to download the changes.
make the .env only viewable by root (you'll have to use sudo nano) by running sudo chmod 600 .env && sudo chown root:root .env
Yup! Here's my setup:
https://github.com/shadybraden/compose/blob/main/kiwix/compose.yaml
I've got a Python script that could be adapted easily here:
https://github.com/shadybraden/compose/tree/main/skywatch
You can specify a folder in your files for configs, and a different one for the compose and env:
Edit: then you can map your volume not to
./config:/configbut instead to/config/containerName:/configDefinitely worth a shot.
One thing I do to prevent stuff from getting into a public git repo is:
.gitignorethen add the line.envto it. Then git will ignore any file named.envsudo nano) by runningsudo chmod 600 .env && sudo chown root:root .envI have mine in git! I have:
Then using
docker compose --env-file ../.env -v up -dit uses the above .env file. (../means up one folder)For more details and a bunch of my compose files checkout my repo! https://github.com/shadybraden/homelab/tree/main/docker