How to pass auth.toml into kaniko

I am working on a kaniko cicd pipeline for a python-functional-service. It is built locally with

docker build ... --secret id=auth_toml,src=$POETRY_CONFIG_DIR/auth.toml

but kaniko doesn’t have a --secret flag. How would I pass the auth.toml file into the kaniko build?

I’m not familiar with Kaniko, and a generated LEAF service apparently doesn’t play nicely with its unique approach to building images without Docker. An internet search shows that Kaniko doesn’t support Docker’s --secret for safely injecting secrets at build time. Here’s a StackOverflow thread describing a workaround, which lets you modify the temporary filesystem as its being built:

It looks like you might need to modify the RUN ... poetry install Dockerfile line if using that workaround.

…

Alternately, it looks like you might be able to instead inject Poetry’s authentication info using environment variables POETRY_HTTP_BASIC_PYPI_USERNAME and POETRY_HTTP_BASIC_PYPI_PASSWORD: