Season 7: It Worked on My Laptop · Episode 3 of 8
You play: Junior AI Developer
A routine security review of Code Nexus's registry pulled the layers of the published Code Nexus Assist image and found an API key in them: a synthetic training credential, but a credential all the same. Someone had been careful. There is even a line in the Dockerfile that deletes the file after copying it in. The review's question is not whether the key is real but who can pull the image, and how the team would know if someone already had.
Lydia Roe
Security Engineer
Kabelo Mokoena
Platform and DevOps Engineer
8-BIT
Code Nexus Internal AI Assistant
The `rm` in the Dockerfile hid the key from the running container and left it in the layer, and the ENV line put it in the image configuration in plain text, so anyone who could pull the image could read it. The clean rebuild keeps the key out of the build context and supplies it at run time, bumps the vulnerable dependency, runs as a non-root user, and is pinned by digest, so the deployment runs exactly the image that was scanned. Containing the leak meant revoking the credential after the replacement was live, stopping and unpublishing the leaky image, and then proving both halves: the old key fails with a revoked-credential error, and the new image authenticates and runs.