I'm using airflow and the dockerOperator to connect to a docker daemon and spin up a container.
As part of my pipeline this container needs to decrypt a file using gpg.
If I copy the gpg key in during docker build then it will be apart of the image forever, this feels insecure?
I have investigated whether or not I can put the key into an environment variable and pass it in that way i.e. through dockers -e VAR:VAL syntax. The only other way I can think of is to mount my local .gnupg file into the container and use that, however this will only work while I'm on my local machine. I want to be able to migrate to ECS or kubernetes at some stage.