maz

maz

Hi all, I have an elixir umbrella app that I deploy via docker-compose. I’d like to use env_file directive in my docker-compose.yml for things like guardian keys etc. I have my env vars in a my_app.env file which is referred to in the docker-compose.yml. The vars do not appear to be available at runtime because when I try to generate a JWT with guardian, the phoenix endpoint generates a Bad Request. If I return the hardcoded key, it works OK.

Any recommendations to getting secrets or env vars injected into a running docker elixir app? I also tried docker secrets via the docker-compose file and I can confirm that the umbrella app cannot find the /run/secrets/secret_file path/volume, even though docker builds the image without error. I did notice that /run/secrets doesn’t appear in docker volumes ls but that might not be either here or there.

Showing Posts 1 to 10

NobbZ

NobbZ

Docker secrets only work when you are using docker swarm.

And the environment variables should be available but perhaps you are reading them at the wrong time?

Can you tell us more about your build process and how you read from the environment?

cnck1387

cnck1387

I haven’t deployed my app yet, but in development environment variables are working with Docker Compose using the same patterns that worked with other applications.

I have a .env file in the same directory as my docker-compose.yml file and then in the compose file I use:

    env_file:
      - ".env"

At this point all of the env variables are available in my Phoenix config files. For example you can use System.get_env("SOME_ENV_VAR_FROM_THE_ENV_FILE").

Are you doing something different, or maybe you forgot the env_file property on one of your services?

maz

maz OP

Is env_file: a child of services: level or a child of my_app: level?

I’m open to trying anything at this point.

cnck1387

cnck1387

It’s a child of myapp. Each individual service can have its own list of environment files (they are loaded and merged from top to bottom since technically you can have more than 1 file).

Basically, Docker isn’t going to automatically read in your environment variables. By setting env_file on a specific service, that instructs Docker to make them available.

The only file that gets automatically used is a .env file, but that’s for setting things like the COMPOSE_PROJECT_NAME or using variable substitution in the docker-compose.yml file itself. The vars in the .env file won’t get loaded into your services unless you explicitly set it in env_file.

Edit: There’s also the environment property which you can use either in combination with or as an alternative to env_file. The environment property lets you pass in key / value pairs of environment variables instead of having them loaded in from a file. Could be useful in some cases.

NobbZ

NobbZ

@maz, let me ask you again, how exactly is your build process?

The Dockerfile won’t see environment variables that are only injected at container runtime via an env file. So depending on if you are doing compiletime or runtime configuration, the environment might already be backed in as “empty”.

maz

maz OP

Sorry about the lack of response, I only had time this morning to make a quick response to @cnck1387. This is my docker compose with the env changes(they are not yet checked-in from my linux box at home which is where I can do quick turnaround development with docker)

I set - port: to localhost:4000:4000, commented out the web network, and commented-out the traefik directives in order to speed up iterations:

for building I do:

docker-compose pull 
docker-compose build --pull olivetree
docker-compose up --build -d postgres
docker-compose run --rm olivetree seed
docker-compose run --rm olivetree generate_hash_ids
docker-compose up --build olivetree

So going from what you are saying, I’d need access to those environment variables at least by docker-compose build --pull olivetree but that doesn’t seem to be the case.

[EDIT] added Dockerfile to gist.

maz

maz OP

yeah I’m still not sure why my env_file:\n - ./olivetree.env is not being honored. Or maybe it is but the timing of the SET is too late. It might be something I’m doing/not doing in my build process.

cnck1387

cnck1387

You can’t access environment variables from env_file at build time. It’s for run time.

If you want env variables to be set at build time, take a look at build arguments in the Docker Compose documentaton.

maz

maz OP

Right, so I guess I would want, say, System.get_env("GUARDIAN_SECRET_KEY") in config.exs to resolve at buildtime? Is there any situation where I’d prefer get_env() to resolve at runtime? Because if they can only be resolved at buildtime, I am barking up the wrong tree.

cnck1387

cnck1387

I never messed around with releases, but in development using mix to launch Phoenix, System.get_env("FOO") will resolve at run time and it will obtain that value thanks to Docker Compose making that environment variable available to Phoenix due to env_file (or environment) in the docker-compose.yml file.

You can double check what’s available in your container by running docker-compose run olivetree env. It should return back all of your environment variables that you set.

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
ChrisAmelia
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication): toke...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews