Passing a secret with --build-arg or ARG bakes it into the image: ARG values are recorded in the image history, and anything written to the filesystem during a RUN persists in that layer even if a later step removes it. The result is credentials readable by anyone who pulls the image.
docker history --no-trunc <image> | grep -iE 'ARG|token|key|secret'
# Files written then deleted still live in the layer tarballs
docker save <image> -o img.tar && tar -xf img.tar && grep -rniE 'BEGIN PRIVATE KEY|aws_secret' .
Exploitation notes#
ARGis not a secret mechanism; its value is visible indocker history. The intended mechanism is BuildKit--mount=type=secret, which does not persist.- The highest-value leaks are cloud keys, registry credentials, and private deploy keys baked during dependency installation.
- This overlaps Secrets in image layers; the difference is the build-time origin.