A Docker CLI plugin that lets docker commands use
sops-encrypted files without decrypting them
by hand. Secrets stay encrypted in git and are decrypted only while a command
runs. Like helm-secrets, for Docker.
docker sops run --rm --env-file secrets.enc.env myimage
docker sops compose up -d
docker sops build --secret id=npmrc,src=npmrc.enc .
docker sops decrypt secrets.enc.yamlScript (macOS and Linux):
curl -fsSL https://raw.githubusercontent.com/mohsen0/docker-sops/main/install.sh | shHomebrew:
brew tap mohsen0/docker-sops https://github.com/mohsen0/docker-sops
brew install docker-sops
mkdir -p ~/.docker/cli-plugins && ln -sfn "$(brew --prefix)/opt/docker-sops/bin/docker-sops" ~/.docker/cli-plugins/docker-sopsManual: download the binary for your platform from the releases page, then
chmod +x docker-sops_*_darwin_arm64
mkdir -p ~/.docker/cli-plugins
mv docker-sops_*_darwin_arm64 ~/.docker/cli-plugins/docker-sopsWindows: move the .exe to %USERPROFILE%\.docker\cli-plugins\docker-sops.exe.
Windows binaries are built and shipped but not yet covered by the test
suite; WSL users should use the Linux binary. Keys can live in Credential
Manager, see docs/keychain.md.
From source: make install (needs Go 1.27+).
Prefix a docker command with sops. Any argument that is a sops-encrypted
file is replaced by a decrypted copy in a private temp dir, the real docker
runs, and the copy is deleted when it exits. Plain files pass through
untouched. Files are recognised by their sops metadata, not their names.
For compose, encrypted env_file: entries and secrets:/configs: files
inside the project are handled too, through a generated override file. Your
compose files are never modified.
| Command | Purpose |
|---|---|
docker sops [OPTIONS] COMMAND [ARGS...] |
Run any docker command with encrypted files decrypted on the fly. |
docker sops decrypt [-i] [-o FILE] FILE |
Print or write the plaintext of a file. |
docker sops encrypt ..., docker sops edit ... |
Pass-through to the sops binary. |
docker sops key set|show|rm |
Manage an age key in the OS keychain. |
docker sops version |
Print the version. |
Options before the docker command: -q/--quiet, --tmpdir DIR,
--pattern GLOB, --no-detect, --dry-run. Run docker sops --help.
Keys work exactly as with the sops binary: age, AWS KMS, GCP KMS, Azure Key
Vault, Vault, PGP and .sops.yaml. Decrypting does not need sops installed.
Apache-2.0. Not affiliated with Docker, Inc. or the sops project.