No matter where it is stored, it is clearly accessible through the docker inspector. I think it comes down to how safe you want it. For example, instead, you can use a shared volume with file permissions to restrict access to the password file on disk. Or you might have socker / ssh / etc, so you donβt have to put the password in a file on disk at all. It only depends on how much you really want to be safe.
I note that if you say the web server running in the container, I assume that if someone exits the web server, he will be able to access only what the container can receive (and not the host operating system, where docker works).
source share