Follow-up from "Add BuildKit documentation as secure alternative to Kaniko"
The following discussion from !192429 (merged) should be addressed:
-
@marcel.amirault started a discussion: (+2 comments) This example is important, but there are limitations to CI/CD variables that mean we try to avoid calling them a "secure" option. We'd also need to talk about variable masking, protected variables (potentially).
For example, seeing
echo "$BUILD_SECRET"in an example always makes me🙈 Do you think we could remove this section for now, and add it in a followup that I can get reviewed by folks in pipeline security? There's already a TON of great examples in here, so I think we can delay this one section for a followup?
🙏
Link for reference: !192429 (30619be6)
Edited by Lysanne Pinto