For the complete documentation index, see llms.txt. This page is also available as Markdown.

How To Use the Secrets Manager with Rhino FCP

To ensure the Rhino FCP can retrieve the correct secret for a Code Run, the secret's key ID in the Secrets Manager must exactly match the tag of the container image being executed. Example: If your container image is tagged v1, the corresponding secret in the Secrets Manager must also have the tag v1.

During a Code Run execution, the Rhino FCP dynamically injects the retrieved secret into the running container at a specific, standardized location:

  • Injection Path: The secret is provided as a JSON file named secret_run_params.json at the absolute path: /input/secret_run_params.json.

  • Runtime Access: The container's code, e.g. decrypt_weights function, accesses this file at runtime to securely retrieve the necessary keys (e.g., decrypt_key or encrypt_key). Note that the function used here (decrypt_weights) is just an example. But, there should be a file inside the container should be used for decrypting.

Was this helpful?