I’m not familiar with Kaniko, and a generated LEAF service apparently doesn’t play nicely with its unique approach to building images without Docker. An internet search shows that Kaniko doesn’t support Docker’s --secret for safely injecting secrets at build time. Here’s a StackOverflow thread describing a workaround, which lets you modify the temporary filesystem as its being built:
It looks like you might need to modify the RUN ... poetry install Dockerfile line if using that workaround.
…
Alternately, it looks like you might be able to instead inject Poetry’s authentication info using environment variables POETRY_HTTP_BASIC_PYPI_USERNAME and POETRY_HTTP_BASIC_PYPI_PASSWORD: