---
title: "How do you handle secrets and sensitive data in Docker without hardcoding them?"  
description: "How do you handle secrets and sensitive data in Docker without hardcoding them?"  
author: "Anubhav Sharma"  
published: 2026-09-29  
canonical: https://answers.mindstick.com/qa/117308/how-do-you-handle-secrets-and-sensitive-data-in-docker-without-hardcoding-them  
category: "Docker"  
tags: ["docker", "security", "Best practices"]  
reading_time: 1 minute  

---

# How do you handle secrets and sensitive data in Docker without hardcoding them?

I'm setting up a multi-service application using Docker, and I need to pass API keys, database passwords, and tokens to my containers. I know embedding these directly in the Dockerfile or `docker run` commands is a bad practice, but what are the recommended alternatives?

### Environment Variables vs. Secrets

I've seen **[environment variables](https://www.mindstick.com/forum/159994/how-to-set-up-and-use-environment-variables-in-a-nodejs-application)** used frequently, but I'm worried they might be exposed in `docker inspect` output. On the other hand, Docker Swarm and Kubernetes offer dedicated secret management. For a standalone Docker setup without orchestration, is there a built-in way to keep sensitive data out of plain sight, or should I rely on external tools?

Also, how does this approach differ when using `docker-compose` versus a production registry like Docker Hub? I want to make sure I'm not accidentally leaking credentials during the build or push process.


---

Original Source: https://answers.mindstick.com/qa/117308/how-do-you-handle-secrets-and-sensitive-data-in-docker-without-hardcoding-them

Copyright © MindStick Software Pvt. Ltd. This Markdown version is provided for developers, AI systems, and offline reading.
