mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
fix: revert yaml
This commit is contained in:
@@ -7,8 +7,7 @@ metadata:
|
|||||||
annotations:
|
annotations:
|
||||||
example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
|
example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
|
||||||
spec:
|
spec:
|
||||||
# hostAPI: https://app.infisical.com/api
|
hostAPI: https://app.infisical.com/api
|
||||||
hostAPI: http://localhost:8085/api
|
|
||||||
resyncInterval: 10
|
resyncInterval: 10
|
||||||
instantUpdates: true
|
instantUpdates: true
|
||||||
# tls:
|
# tls:
|
||||||
@@ -33,7 +32,7 @@ spec:
|
|||||||
# Universal Auth
|
# Universal Auth
|
||||||
universalAuth:
|
universalAuth:
|
||||||
secretsScope:
|
secretsScope:
|
||||||
projectSlug: test-j7-kx
|
projectSlug: <your-project-slug>
|
||||||
envSlug: dev # "dev", "staging", "prod", etc..
|
envSlug: dev # "dev", "staging", "prod", etc..
|
||||||
secretsPath: "/" # Root is "/"
|
secretsPath: "/" # Root is "/"
|
||||||
recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
|
recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
|
||||||
@@ -41,80 +40,6 @@ spec:
|
|||||||
secretName: universal-auth-credentials
|
secretName: universal-auth-credentials
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
|
|
||||||
# Native Kubernetes Auth
|
|
||||||
kubernetesAuth:
|
|
||||||
serviceAccountRef:
|
|
||||||
name: <secret-name>
|
|
||||||
namespace: <secret-namespace>
|
|
||||||
identityId: <machine-identity-id>
|
|
||||||
serviceAccountTokenPath: "/path/to/your/service-account/token" # Optional, defaults to /var/run/secrets/kubernetes.io/serviceaccount/token
|
|
||||||
|
|
||||||
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: your-project-slug
|
|
||||||
envSlug: prod
|
|
||||||
secretsPath: "/path"
|
|
||||||
recursive: true
|
|
||||||
|
|
||||||
# AWS IAM Auth
|
|
||||||
awsIamAuth:
|
|
||||||
identityId: <your-machine-identity-id>
|
|
||||||
|
|
||||||
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: your-project-slug
|
|
||||||
envSlug: prod
|
|
||||||
secretsPath: "/path"
|
|
||||||
recursive: true
|
|
||||||
|
|
||||||
ldapAuth:
|
|
||||||
identityId: <machine-identity-id>
|
|
||||||
credentialsRef:
|
|
||||||
secretName: <secret-name> # ldap-auth-credentials
|
|
||||||
secretNamespace: <secret-namespace> # default
|
|
||||||
|
|
||||||
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: your-project-slug
|
|
||||||
envSlug: prod
|
|
||||||
secretsPath: "/path"
|
|
||||||
recursive: true
|
|
||||||
|
|
||||||
# Azure Auth
|
|
||||||
azureAuth:
|
|
||||||
identityId: <your-machine-identity-id>
|
|
||||||
resource: https://management.azure.com/&client_id=your_client_id # This field is optional, and will default to "https://management.azure.com/" if nothing is provided.
|
|
||||||
|
|
||||||
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: your-project-slug
|
|
||||||
envSlug: prod
|
|
||||||
secretsPath: "/path"
|
|
||||||
recursive: true
|
|
||||||
|
|
||||||
# GCP ID Token Auth
|
|
||||||
gcpIdTokenAuth:
|
|
||||||
identityId: <your-machine-identity-id>
|
|
||||||
|
|
||||||
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: your-project-slug
|
|
||||||
envSlug: prod
|
|
||||||
secretsPath: "/path"
|
|
||||||
recursive: true
|
|
||||||
|
|
||||||
# GCP IAM Auth
|
|
||||||
gcpIamAuth:
|
|
||||||
identityId: <your-machine-identity-id>
|
|
||||||
serviceAccountKeyFilePath: "/path/to-service-account-key-file-path.json"
|
|
||||||
|
|
||||||
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: your-project-slug
|
|
||||||
envSlug: prod
|
|
||||||
secretsPath: "/path"
|
|
||||||
recursive: true
|
|
||||||
|
|
||||||
managedKubeSecretReferences:
|
managedKubeSecretReferences:
|
||||||
- secretName: managed-secret
|
- secretName: managed-secret
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
|
|||||||
@@ -9,4 +9,4 @@ metadata:
|
|||||||
name: infisical-config
|
name: infisical-config
|
||||||
namespace: infisical-operator-system
|
namespace: infisical-operator-system
|
||||||
data:
|
data:
|
||||||
hostAPI: "http://localhost:8085/api"
|
hostAPI: "http://example.com:8085/api"
|
||||||
|
|||||||
@@ -4,5 +4,5 @@ metadata:
|
|||||||
name: universal-auth-credentials
|
name: universal-auth-credentials
|
||||||
type: Opaque
|
type: Opaque
|
||||||
stringData:
|
stringData:
|
||||||
clientId: 86c17800-00b9-4556-89a8-ea11ac6f8371
|
clientId: <your-client-id>
|
||||||
clientSecret: 6792edff19e0b7a43647501958c9a0d1a7964b2db1ff2401fbdd555cfd1ae757
|
clientSecret: <your-client-secret>
|
||||||
|
|||||||
Reference in New Issue
Block a user