# Why no support for Docker secrets when using Compose?

**URL:** https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730
**Category:** docker
**Created:** [March 9, 2025, 1:18pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730 "2025-03-09T13:18:33Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![hrafn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/hrafn/32/46802_2.png) [@hrafn](https://discourse.pi-hole.net/u/hrafn)
#### Post date: [March 9, 2025, 1:18pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/1 "2025-03-09T13:18:33Z")

</div>

Is there a technical reason for why Docker secrets are not being supported when the container is run in Docker compose but only in swarm mode?

* * *

After using PiHole on a RPI for years, I am currenlty trying out setting it up using the Docker container for the first time. And I am doing so with Docker compose. And so I've hit the issue of how to configure the admin credential via Docker Secrets, when using Compose.

It seems that the implementation of file based secrets, via the `WEBPASSWORD_FILE` parameter is ONLY being used when the container is run in swarm mode (when attempting to use the content of the secret file to log into the PiHole admin portal the password is not being accepted).

At least that seems to be what I gather from other discussions on this forum:

- [one](https://discourse.pi-hole.net/t/v6-on-docker-ftlconf-webserver-api-password-support-secrets/76150/3)
- [another](https://discourse.pi-hole.net/t/problem-with-secret/65176)
- [yet another](https://discourse.pi-hole.net/t/not-able-to-assign-webpassword-file-in-docker-compose/54453/11)

However, nowhere can I find the rational behind only supporting secrets when running in swarm mode.

It can't be due to secrets not being a supported feature in compose:

> **[Secrets in Compose](https://docs.docker.com/compose/how-tos/use-secrets/)**
>
> Learn how to securely manage runtime and build-time secrets in Docker Compose.

To give a complete example, the following secret named `pihole_password` is fully available inside the container given the Docker compose configuration below:

```yaml
# Only relevant parts shared

secrets:
  pihole_password:
    file: /srv/project/pihole_password

services:
  pihole:
      container_name: pihole
      image: pihole/pihole:2025.03.0
      secrets:
        - pihole_password
      environment:
        - WEBPASSWORD_FILE=/run/secrets/pihole_password

```

Shelling into the container `sudo docker exec -it pihole /bin/bash` makes that clear:

```bash
:/# echo $WEBPASSWORD_FILE
/run/secrets/pihole_password
:/# cat $WEBPASSWORD_FILE
super_secret_password_11!!

```

---

<div class="post-metadata">

### Author: ![Bucking\_Horn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/bucking_horn/32/18719_2.png) [@Bucking\_Horn](https://discourse.pi-hole.net/u/Bucking_Horn)
#### Post date: [March 9, 2025, 1:37pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/2 "2025-03-09T13:37:39Z")

</div>

Are you running your Docker daemon and your containers in swarm mode?

[Docker secrets](https://docs.docker.com/reference/cli/docker/secret/) are a feature of Docker Swarm, Docker's container orchestration toolset.

---

<div class="post-metadata">

### Author: ![hrafn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/hrafn/32/46802_2.png) [@hrafn](https://discourse.pi-hole.net/u/hrafn)
#### Post date: [March 9, 2025, 1:45pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/3 "2025-03-09T13:45:46Z")

</div>

Thank you for the quick reply to my question.

As was mentioned in my question above, "..I am doing so with Docker compose". Not using swarm in any way.

Docker secrets are indeed **not** just a feature of Docker Swarm, but also a completely supported feature of Docker Compose. Please see the following [link](https://docs.docker.com/compose/how-tos/use-secrets/) to Docker's own documentation, that was part of my question above.

As an example of a project using Docker secrets for a container running in compose, please see [Nextcloud's container](https://github.com/nextcloud/docker?tab=readme-ov-file#docker-secrets) documentation.

---

<div class="post-metadata">

### Author: ![Bucking\_Horn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/bucking_horn/32/18719_2.png) [@Bucking\_Horn](https://discourse.pi-hole.net/u/Bucking_Horn)
#### Post date: [March 9, 2025, 1:56pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/4 "2025-03-09T13:56:15Z")

</div>

No doubt Docker secrets can be used with docker compose, but they are still a Swarm feature.

> [@hrafn](#):
>
> Docker secrets are indeed **not** just a feature of Docker Swarm

What makes you think that when Docker's documentation says otherwise?  
[![docker-secrets](https://discourse.pi-hole.net/uploads/default/original/3X/8/c/8c37b72453435631746fc1c93af49152e7db29ae.png)](https://docs.docker.com/engine/swarm/secrets/)

---

<div class="post-metadata">

### Author: ![hrafn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/hrafn/32/46802_2.png) [@hrafn](https://discourse.pi-hole.net/u/hrafn)
#### Post date: [March 9, 2025, 2:02pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/5 "2025-03-09T14:02:29Z")

</div>

> [@Bucking\_Horn](#):
>
> What makes you think that when Docker's documentation says otherwise?

Fair enough, what is named "Docker Secrets" is a swarm only feature. Using secrets is **not** a swarm only feature (please see my link above referencing Docker's own documentation). The naming strategy of Docker in this regard is abysmal.

Moving on from splitting hairs on that, the initial question stands:

Is there a technical reason for why the pihole container does not use file based secrets ([such as these](https://docs.docker.com/compose/how-tos/use-secrets/)) unless they are the swarm only Docker secrets ([such as these](https://docs.docker.com/reference/cli/docker/secret/))?

---

<div class="post-metadata">

### Author: ![rdwebdesign](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/rdwebdesign/32/51363_2.png) [@rdwebdesign](https://discourse.pi-hole.net/u/rdwebdesign)
#### Post date: [March 9, 2025, 5:40pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/6 "2025-03-09T17:40:38Z")

</div>

**Suggestion:**

Compose files can use [`.env` files](https://docs.docker.com/compose/how-tos/environment-variables/variable-interpolation/#env-file) ([read also this](https://docs.docker.com/compose/how-tos/environment-variables/set-environment-variables/#use-the-env_file-attribute)) to store environment variables.

Create a file called `.env` on the same directory where you saved your compose file.  
Then add something like this to the file:

```auto
PASSWORD=My_Password_1234

```

Now change your compose file to use the variable, like this:

`FTLCONF_weserver_api_password: "${PASSWORD}"`

---

<div class="post-metadata">

### Author: ![PromoFaux](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/promofaux/32/1545_2.png) [@PromoFaux](https://discourse.pi-hole.net/u/PromoFaux)
#### Post date: [March 9, 2025, 6:11pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/7 "2025-03-09T18:11:25Z")

</div>

> [@hrafn](#):
>
> ```auto
> environment:
> - WEBPASSWORD_FILE=/run/secrets/pihole_password
> 
> ```

This is where it's going wrong - but perhaps our documentation isn't clear enough here. (Note: there is a [PR to fix this](https://github.com/pi-hole/docs/pull/1182) on the docs page...)

Set `WEBPASSWORD_FILE=pihole_password` instead, as the `/run/secrets/` part is implied:

> <https://github.com/pi-hole/docker-pi-hole/blob/78aee9e4b2089263359d6d7e2847028f237b7aef/src/bash_functions.sh#L192>

I've just tried this myself and `WEBPASSWORD_FILE` works as expected in compose

---

<div class="post-metadata">

### Author: ![hrafn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/hrafn/32/46802_2.png) [@hrafn](https://discourse.pi-hole.net/u/hrafn)
#### Post date: [March 10, 2025, 5:31pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/11 "2025-03-10T17:31:36Z")

</div>

Thank you for pointing this out to me! This was exactly what I was missing.

---

<div class="post-metadata">

### Author: ![Bucking\_Horn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/bucking_horn/32/18719_2.png) [@Bucking\_Horn](https://discourse.pi-hole.net/u/Bucking_Horn)
#### Post date: [March 10, 2025, 5:38pm UTC](https://discourse.pi-hole.net/t/why-no-support-for-docker-secrets-when-using-compose/77730/12 "2025-03-10T17:38:42Z")

</div>

> [@hrafn](#):
>
> Fair enough, what is named "Docker Secrets" is a swarm only feature. Using secrets is **not** a swarm only feature (please see my link above referencing Docker's own documentation). The naming strategy of Docker in this regard is abysmal.

I agree Docker's documentation is not as clear as it could be on that matter.  
Lack of proper understanding may have contributed to WEBPASSWORD\_FILE having been dropped in and out of v6 during beta phase, perhaps regarding it as little used when exclusively a Docker swarm feature.  
Thank you for clarifying it's available with plain docker compose as well.
