mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 21:26:40 +00:00
Merge pull request #2634 from Infisical/azure-permission-docs
Add permission note for Azure Key Vault (KV) integration documentation
This commit is contained in:
Binary file not shown.
|
Before Width: | Height: | Size: 189 KiB After Width: | Height: | Size: 511 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 379 KiB After Width: | Height: | Size: 706 KiB |
@@ -29,8 +29,15 @@ description: "How to sync secrets from Infisical to Azure Key Vault"
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
<Note>
|
||||||
|
The Azure Key Vault integration requires the following secrets permissions to be set on the user / service principal
|
||||||
|
for Infisical to sync secrets to Azure Key Vault: `secrets/list`, `secrets/get`, `secrets/set`, `secrets/recover`.
|
||||||
|
|
||||||
|
Any role with these permissions would work such as the **Key Vault Secrets Officer** role.
|
||||||
|
</Note>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Self-Hosted Setup">
|
<Tab title="Self-Hosted Setup">
|
||||||
Using the Azure KV integration on a self-hosted instance of Infisical requires configuring an application in Azure
|
Using the Azure KV integration on a self-hosted instance of Infisical requires configuring an application in Azure
|
||||||
@@ -43,28 +50,28 @@ description: "How to sync secrets from Infisical to Azure Key Vault"
|
|||||||
<Info>
|
<Info>
|
||||||
Azure Active Directory is now Microsoft Entra ID.
|
Azure Active Directory is now Microsoft Entra ID.
|
||||||
</Info>
|
</Info>
|
||||||

|

|
||||||

|

|
||||||
|
|
||||||
Create the application. As part of the form, set the **Redirect URI** to `https://your-domain.com/integrations/azure-key-vault/oauth2/callback`.
|
Create the application. As part of the form, set the **Redirect URI** to `https://your-domain.com/integrations/azure-key-vault/oauth2/callback`.
|
||||||
|
|
||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Add your application credentials to Infisical">
|
<Step title="Add your application credentials to Infisical">
|
||||||
Obtain the **Application (Client) ID** in Overview and generate a **Client Secret** in Certificate & secrets for your Azure application.
|
Obtain the **Application (Client) ID** in Overview and generate a **Client Secret** in Certificate & secrets for your Azure application.
|
||||||
|
|
||||||

|

|
||||||

|

|
||||||

|

|
||||||
|
|
||||||
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
||||||
|
|
||||||
- `CLIENT_ID_AZURE`: The **Application (Client) ID** of your Azure application.
|
- `CLIENT_ID_AZURE`: The **Application (Client) ID** of your Azure application.
|
||||||
- `CLIENT_SECRET_AZURE`: The **Client Secret** of your Azure application.
|
- `CLIENT_SECRET_AZURE`: The **Client Secret** of your Azure application.
|
||||||
|
|
||||||
Once added, restart your Infisical instance and use the Azure KV integration.
|
Once added, restart your Infisical instance and use the Azure KV integration.
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user