this means we no longer have to hardcode the password in the docker-compose file, and can treat the file as configuration rather than a secret.