Unclear "secrets" merging behavior in "docker stack"
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 64/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- docker
- 领域
- cli
调研方向
使用 docker-stack.yml 和 docker-stack.prod.yml 重现合并,然后运行 docker stack config -c docker-stack.yml -c docker-stack.prod.yml。跟踪 docker stack config 如何合并顶层 secrets,并在输出保留 external: true 以及 override 名称而不是添加文件路径时,认为该行为已完成。
由索引模型根据 Issue 内容生成。
描述
Description
Toplevel secrets defined partially in multiple Docker stack files are merged with an unclear behavior. In this particular case the base file is supposed to only define external: true and the override file define the exact external name.
Reproduce
Have these two files:
docker-stack.yml
version: "3.8"
services:
app:
image: foo
secrets:
- FOO_BAR
secrets:
FOO_BAR:
external: true
docker-stack.prod.yml
version: "3.8"
secrets:
FOO_BAR:
name: app-prod-foo-bar
Run docker stack config with these two files:
$ pwd
/home/mbrodala/example
$ docker stack config -c docker-stack.yml -c docker-stack.prod.yml
version: "3.8"
services:
app:
image: foo
secrets:
- source: FOO_BAR
secrets:
FOO_BAR:
name: app-prod-foo-bar
file: /home/mbrodala/example
Expected behavior
The expected output:
version: "3.8"
services:
app:
image: foo
secrets:
- source: FOO_BAR
secrets:
FOO_BAR:
name: app-prod-foo-bar
external: true
Incidentally this is exactly what docker compose config produces:
name: example
services:
app:
image: foo
networks:
default: null
secrets:
- source: FOO_BAR
target: /run/secrets/FOO_BAR
networks:
default:
name: example_default
secrets:
FOO_BAR:
name: app-prod-foo-bar
external: true
docker version
Client: Docker Engine - Community
Version: 29.7.2
API version: 1.55
Go version: go1.26.5
Git commit: a7dcaa6
Built: Wed Aug 5 18:29:26 2026
OS/Arch: linux/amd64
Context: default
Server: Docker Engine - Community
Engine:
Version: 29.7.2
API version: 1.55 (minimum version 1.24)
Go version: go1.26.5
Git commit: 6a43e3d
Built: Wed Aug 5 18:29:26 2026
OS/Arch: linux/amd64
Experimental: false
containerd:
Version: v2.3.3
GitCommit: aad11006b869517fcd3009450b6f82da282e1a9b
runc:
Version: 1.4.3
GitCommit: v1.4.3-0-gbb14dabe
docker-init:
Version: 0.19.0
GitCommit: de40ad0
docker info
Client: Docker Engine - Community
Version: 29.7.2
Context: default
Debug Mode: false
Plugins:
buildx: Docker Buildx (Docker Inc.)
Version: v0.36.1
Path: /usr/libexec/docker/cli-plugins/docker-buildx
compose: Docker Compose (Docker Inc.)
Version: v5.5.0
Path: /usr/libexec/docker/cli-plugins/docker-compose
rollout: Rollout new Compose service version (Karol Musur)
Version: v0.9
Path: /home/mbrodala/.docker/cli-plugins/docker-rollout
Server:
Containers: 25
Running: 9
Paused: 0
Stopped: 16
Images: 160
Server Version: 29.7.2
Storage Driver: btrfs
Btrfs:
Logging Driver: json-file
Cgroup Driver: systemd
Cgroup Version: 2
Plugins:
Volume: local
Network: bridge host ipvlan macvlan null overlay
Log: awslogs fluentd gcplogs gelf journald json-file local splunk syslog
CDI spec directories:
/etc/cdi
/var/run/cdi
Swarm: inactive
Runtimes: io.containerd.runc.v2 runc
Default Runtime: runc
Init Binary: docker-init
containerd version: aad11006b869517fcd3009450b6f82da282e1a9b
runc version: v1.4.3-0-gbb14dabe
init version: de40ad0
Security Options:
apparmor
seccomp
Profile: builtin
cgroupns
Kernel Version: 6.16.9+deb14-amd64
Operating System: Debian GNU/Linux forky/sid
OSType: linux
Architecture: x86_64
CPUs: 4
Total Memory: 30.79GiB
Name: yui
ID: 155711a7-d70b-45a8-a98a-f6144758837a
Docker Root Dir: /var/lib/docker
Debug Mode: false
Username: mbrodala
Experimental: false
Insecure Registries:
::1/128
127.0.0.0/8
Live Restore Enabled: false
Firewall Backend: iptables
EnableUserlandProxy: true
UserlandProxyPath: /usr/bin/docker-proxy
Additional Info
No response
- 主要语言
- Go
- 星标
- 6.1k
- 派生
- 2.2k
- 平均合并
- 1 天 17 小时
- 30 天内合并 PR
- 28
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
docker/cli 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 92/100
维护者通常 1 天内回复
-
kind/bug status/0-triage
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复
-
kind/bug status/0-triage
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 74/100
维护者通常 1 天内回复
-
kind/feature status/0-triage
难度 2/5 1-3 小时 新手友好度 70/100
维护者通常 1 天内回复
相似的 Issue
-
self-host checker: E021 bound check reads an untyped literal at i32, not the type the call binds未关闭
难度 2/5 1-3 小时 新手友好度 84/100
JakeChampion/lang#11055 ·
维护者通常 1 天内回复
-
priority: low status: ready for dev
难度 2/5 1-3 小时 新手友好度 88/100
hyperledger-labs/fabric-smart-client#2033 ·
维护者通常 1 天内回复
-
agent-butler-finding agent-research bug
难度 2/5 1-3 小时 新手友好度 90/100
jordansmall/spindrift#4249 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 86/100
维护者通常 1 天内回复
-
acceptance-tests phase-coding schema-coverage testing triaged
难度 2/5 1-2 天 新手友好度 84/100
elastic/terraform-provider-elasticstack#5053 ·
维护者通常 1 天内回复