This way the random secret is created on first run instead of docker build. We don't really want all standard imaages to share a password anymore than we want a static password.
jwt.decode