Most images are configured using environment variables, such as the name of the database server, the username and the password. When you create a container, the wizard suggests the necessary details; mandatory fields are marked as such.
Changing variables later
- Open your project and click on the container.
- In the Settings tab, go to the Environment variables and secrets section.
- Change values directly in the row. Use Add variable to create a new row, and the bin icon to remove one.
- Click Save in the bar at the bottom.
Names consist of uppercase letters, numbers and underscores. Reserved names are PATH, HOME, USER, HOSTNAME as well as names beginning with SIT_, PODMAN_, CONTAINER_ or LD_.
The ‘Secret’ button
Mark passwords, tokens and keys as secret. Secret values are stored in encrypted form, are never displayed again after saving, and are passed to the container as a protected secret. They therefore appear neither in plain text in the configuration on the server nor in the user interface. Within the container itself, they are available as environment variables as usual.
- A saved secret only shows ‘Saved - leave blank to keep’. If you enter a new value, it will replace the old one.
- If a name sounds like a password or key, for example
SMTP_PASSWORD, and if it is not marked as secret, the editor points this out. One click on Mark as secret fixes it. - Normal variables can be read by anyone with access to your project, such as team members.
Saving restarts the container
As soon as you make a change, a bar appears at the bottom showing the areas that have been modified. Saving applies the changes immediately: the container is recreated and restarted with the new configuration and will be briefly unavailable during this process. Data in volumes is retained. Click Discard to undo all unsaved changes.
Important for database images
Many database images, such as MariaDB, MySQL or PostgreSQL, only evaluate login details (username, password, database) the first time they are started with an empty volume. If you subsequently change, for example, MARIADB_PASSWORD, the database will retain the old password. The application will then report a login error.
How to change a database password correctly:
- Change the password within the database itself, for example via the browser console (option) using the database’s own commands.
- Then enter the new password in the database variable and in the application variable, for example
WORDPRESS_DB_PASSWORD. - Save both containers.
For a new, empty installation, you can reinstall the database container instead. This will delete all data from its volumes - see the article Finding and fixing errors.
What counts as a secret?
Anything that grants access: passwords, API keys, tokens, private keys and login details for email or external services.