# How to manage Docker imagePullSecrets from doppler

**URL:** <https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268>\
**Category:** Need Help\
**Created:** [July 30, 2021, 5:45am UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268 "2021-07-30T05:45:20Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![naga](https://avatars.discourse-cdn.com/v4/letter/n/7ab992/32.png) [@naga](https://community.doppler.com/u/naga)\
**Post date:** [July 30, 2021, 5:45am UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/1 "2021-07-30T05:45:20Z")

</div>

Hi,

I am trying to see if i can store my docker secrets in doppler and pull. Here is what i am looking for

there is a docker secret which i included in the helm chart as a secret.yaml file and it contains base64 encoded artifactory credentials to pull the images from private registry during helm install. since currently if there is any update in the credentials i need to get the new creds and encode to base64 and update in each and every secret.yaml file.

Is there any way i can manage to update the secret from doppler ?

Here is my secret.yaml file which i included in helm charts but i am trying to manage this secret from doppler can you please help me how i can do it ?

secret.yaml  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/doppler/original/1X/b22fe2388f14186acd25ad9369469d4ad61821bf.png)

---

<div class="post-metadata">

**Author:** ![ryan-blunden](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/ryan-blunden/32/9_2.png) [@ryan-blunden](https://community.doppler.com/u/ryan-blunden)\
**Post date:** [July 30, 2021, 3:15pm UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/2 "2021-07-30T15:15:32Z")

</div>

Hi @naga,

You could use [envsubst](https://skofgar.ch/dev/2020/08/how-to-quickly-replace-environment-variables-in-a-file/) (part of the `gettext` package) which takes a file as an input and replaces any matching environment variables inside the file.

Here is an example of how you could achieve what you’re after in a single command, including base64 encoding the secret value from Doppler and creating the secret in Kubernetes without the secret value ever touching the file system.

Your template would be largely the same, but it now has an environment variable placeholder:

```auto
apiVersion: v1
data:
    .dockerconfigjson: $ARTIFACTORY_CREDENTIALS_BASE64
kind: Secret
metadata:
  creationTimestamp: null
  name: test-api-docker-secret
type: kubernetes.io/dockerconfigjson

```

Then to render the YAML with the environment variable substituted and fed to `kubectl`

```auto
ARTIFACTORY_CREDENTIALS_BASE64=$(doppler secrets get ARTIFACTORY_CREDENTIALS --plain | base64) \
envsubst < secret.yaml | kubectl apply -f -

```

NOTE: You may need to install `gettext` on the machine you’re running this on.

Let me know how this works out for you.

---

<div class="post-metadata">

**Author:** ![naga](https://avatars.discourse-cdn.com/v4/letter/n/7ab992/32.png) [@naga](https://community.doppler.com/u/naga)\
**Post date:** [July 30, 2021, 5:58pm UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/5 "2021-07-30T17:58:03Z")

</div>

thank you @ryan-blunden the approach you suggested is working fine but sync is not happening. let’s say if i update the secret in doppler the sync is not happening automatically i need to run this command every time to get the updated value.

**ARTIFACTORY\_CREDENTIALS\_BASE64=$(doppler secrets get ARTIFACTORY\_CREDENTIALS --plain | base64)   
envsubst \< secret.yaml | kubectl apply -f -**

Last time for another request you suggested me to use [GitHub - DopplerHQ/kubernetes-operator](https://github.com/DopplerHQ/kubernetes-operator) for sync so i am currently using this as well

---

<div class="post-metadata">

**Author:** ![ryan-blunden](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/ryan-blunden/32/9_2.png) [@ryan-blunden](https://community.doppler.com/u/ryan-blunden)\
**Post date:** [August 2, 2021, 12:20am UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/6 "2021-08-02T00:20:34Z")

</div>

Hi @naga,

Our Kubernetes operator only supports the ‘Opaque’ type secret at the moment but I’ll speak engineering as to how we could look at supporting the other secret types.

How often do you expect your Artifactory credentials to change?

You could set up a crude sync in the meantime by using something like a [scheduled GitHub Action](https://docs.github.com/en/actions/reference/workflow-syntax-for-github-actions#onschedule) that recreates the secret every 5 mins for example.

Would that satisfy your requirements for now?

---

<div class="post-metadata">

**Author:** ![naga](https://avatars.discourse-cdn.com/v4/letter/n/7ab992/32.png) [@naga](https://community.doppler.com/u/naga)\
**Post date:** [August 3, 2021, 4:43am UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/7 "2021-08-03T04:43:57Z")

</div>

> [@ryan-blunden](#):
>
> ‘Opaque’ type secret

Thank you @ryan-blunden we dont change docker secrets often but if you include this feature in upcoming releases that would be more helpful

---

<div class="post-metadata">

**Author:** ![ryan-blunden](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/ryan-blunden/32/9_2.png) [@ryan-blunden](https://community.doppler.com/u/ryan-blunden)\
**Post date:** [August 3, 2021, 6:06am UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/8 "2021-08-03T06:06:56Z")

</div>

Hi @naga,

As an experiment, I’ve created an implementation that uses a Kubernetes `CronJob` to perform automated syncing of the Doppler secret containing Docker registry credentials to a Kubernetes cluster.

The repo is at [https://github.com/DopplerHQ/kubernetes-docker-creds-sync](https://github.com/DopplerHQ/kubernetes-docker-creds-sync)

I’d be really interested if you could give this a try as this could be a good interim solution until official support lands in our Kubernetes Operator.

---

<div class="post-metadata">

**Author:** ![Francois](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/francois/32/951_2.png) [@Francois](https://community.doppler.com/u/Francois)\
**Post date:** [July 29, 2022, 10:24am UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/10 "2022-07-29T10:24:02Z")

</div>

Hi 👋

Not sure if it is the right place to post, but it would be awesome if Doppler could handle other secret Types in Kubernetes 🙂 such `kubernetes.io/dockerconfigjson`

Is there maybe a roadmap maybe? 🙂

---

<div class="post-metadata">

**Author:** ![ryan-blunden](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/ryan-blunden/32/9_2.png) [@ryan-blunden](https://community.doppler.com/u/ryan-blunden)\
**Post date:** [August 15, 2022, 12:59pm UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/11 "2022-08-15T12:59:43Z")

</div>

Hi @Francois,

It isn’t yet possible but we’re looking to add support for different secret types in the future.

I’ll be sure to reach out when using a dockerconfigjson secret becomes possible.

---

<div class="post-metadata">

**Author:** ![Adonis\_Panagidis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/adonis_panagidis/32/628_2.png) [@Adonis\_Panagidis](https://community.doppler.com/u/Adonis_Panagidis)\
**Post date:** [December 28, 2022, 3:05pm UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/13 "2022-12-28T15:05:53Z")

</div>

Is this feature implemented?

---

<div class="post-metadata">

**Author:** ![salanki](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/salanki/32/699_2.png) [@salanki](https://community.doppler.com/u/salanki)\
**Post date:** [February 23, 2023, 4:24pm UTC](https://community.doppler.com/t/how-to-manage-docker-imagepullsecrets-from-doppler/268/14 "2023-02-23T16:24:49Z")

</div>

This would be a very valuable feature and allow organizations to rotate keys much more frequently.
