misc: addressed review comments

This commit is contained in:
Sheen Capadngan
2024-10-16 19:54:35 +08:00
parent 08ed544e52
commit 080cf67b8c
6 changed files with 26 additions and 27 deletions

View File

@@ -120,12 +120,12 @@ const envSchema = z
// github oauth
CLIENT_ID_GITHUB: zpStr(z.string().optional()),
CLIENT_SECRET_GITHUB: zpStr(z.string().optional()),
CLIENT_SLUG_GITHUB_APP: zpStr(z.string().optional()),
// github app
CLIENT_ID_GITHUB_APP: zpStr(z.string().optional()),
CLIENT_SECRET_GITHUB_APP: zpStr(z.string().optional()),
CLIENT_PRIVATE_KEY_GITHUB_APP: zpStr(z.string().optional()),
CLIENT_APP_ID_GITHUB_APP: z.coerce.number().optional(),
CLIENT_SLUG_GITHUB_APP: zpStr(z.string().optional()),
// azure
CLIENT_ID_AZURE: zpStr(z.string().optional()),

View File

@@ -18,7 +18,7 @@ import { KmsDataKey } from "../kms/kms-types";
import { TProjectBotServiceFactory } from "../project-bot/project-bot-service";
import { getApps } from "./integration-app-list";
import { TIntegrationAuthDALFactory } from "./integration-auth-dal";
import { IntegrationAuthMetadataSchema } from "./integration-auth-schema";
import { IntegrationAuthMetadataSchema, TIntegrationAuthMetadata } from "./integration-auth-schema";
import {
TBitbucketWorkspace,
TChecklyGroups,
@@ -642,7 +642,7 @@ export const integrationAuthServiceFactory = ({
const { shouldUseSecretV2Bridge, botKey } = await projectBotService.getBotKey(integrationAuth.projectId);
let octokit: Octokit;
const { installationId } = (integrationAuth.metadata as { installationId: string }) || {};
const { installationId } = (integrationAuth.metadata as TIntegrationAuthMetadata) || {};
if (installationId) {
octokit = new Octokit({
authStrategy: createAppAuth,

Binary file not shown.

Before

Width:  |  Height:  |  Size: 363 KiB

After

Width:  |  Height:  |  Size: 367 KiB

View File

@@ -4,31 +4,31 @@ description: "How to sync secrets from Infisical to GitHub Actions"
---
<Note>
Alternatively, you can use Infisical's official Github Action
Alternatively, you can use Infisical's official GitHub Action
[here](https://github.com/Infisical/secrets-action).
</Note>
Infisical lets you sync secrets to GitHub at the organization-level, repository-level, and repository environment-level.
## Connecting with Github App (Recommended)
## Connecting with GitHub App (Recommended)
<Tabs>
<Tab title="Usage">
<Steps>
<Step title="Authorize Github Infisical App">
<Step title="Authorize GitHub Infisical App">
Navigate to your project's integrations tab in Infisical and press on the GitHub tile.
![integrations](../../images/integrations/github/app/integration-overview.png)
Select Github App as the authentication method and click **Connect to Github**.
Select GitHub App as the authentication method and click **Connect to GitHub**.
![integrations github app auth selection](../../images/integrations/github/app/github-app-method-selection.png)
You will then be redirected to the Github app installation page.
You will then be redirected to the GitHub app installation page.
![integrations github app installation](../../images/integrations/github/app/github-app-installation.png)
Install and authorize the Github application. This will redirect you back to the Infisical integration page.
Install and authorize the GitHub application. This will redirect you back to the Infisical integration page.
</Step>
<Step title="Configure Infisical GitHub integration">
@@ -41,7 +41,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
<Tab title="Organization">
![integrations github](../../images/integrations/github/integrations-github-scope-org.png)
When using the organization scope, your secrets will be saved in the top-level of your Github Organization.
When using the organization scope, your secrets will be saved in the top-level of your GitHub Organization.
You can choose the visibility, which defines which repositories can access the secrets. The options are:
- **All public repositories**: All public repositories in the organization can access the secrets.
@@ -65,7 +65,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
and registering your instance with it.
<Steps>
<Step title="Create an application on GitHub">
Navigate to the Github app settings [here](https://github.com/settings/apps). Click **New Github App**.
Navigate to the GitHub app settings [here](https://github.com/settings/apps). Click **New GitHub App**.
![integrations github app create](../../images/integrations/github/app/self-hosted-github-app-create.png)
@@ -79,7 +79,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
Disable webhook by unchecking the Active checkbox.
![integrations github app webhook](../../images/integrations/github/app/self-hosted-github-app-webhook.png)
Set the repository permissions as follows: Metadata: Read-only, Secrets: Read and write.
Set the repository permissions as follows: Metadata: Read-only, Secrets: Read and write, Environments: Read and write.
![integrations github app repository](../../images/integrations/github/app/self-hosted-github-app-repository.png)
Similarly, set the organization permissions as follows: Secrets: Read and write.
@@ -90,7 +90,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
<Note>
If you have a GitHub organization, you can create an application under it
in your organization Settings > Developer settings > Github Apps > New Github App.
in your organization Settings > Developer settings > GitHub Apps > New GitHub App.
</Note>
</Step>
<Step title="Add your application credentials to Infisical">
@@ -107,9 +107,9 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
- `CLIENT_ID_GITHUB_APP`: The **Client ID** of your GitHub application.
- `CLIENT_SECRET_GITHUB_APP`: The **Client Secret** of your GitHub application.
- `CLIENT_SLUG_GITHUB_APP`: The **Slug** of your Github application. This is the one found in the URL.
- `CLIENT_APP_ID_GITHUB_APP`: The **App ID** of your Github application.
- `CLIENT_PRIVATE_KEY_GITHUB_APP`: The **Private Key** of your Github application.
- `CLIENT_SLUG_GITHUB_APP`: The **Slug** of your GitHub application. This is the one found in the URL.
- `CLIENT_APP_ID_GITHUB_APP`: The **App ID** of your GitHub application.
- `CLIENT_PRIVATE_KEY_GITHUB_APP`: The **Private Key** of your GitHub application.
Once added, restart your Infisical instance and use the GitHub integration via app authentication.
</Step>
@@ -118,7 +118,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
</Tab>
</Tabs>
## Connecting with Github OAuth
## Connecting with GitHub OAuth
Prerequisites:
@@ -129,10 +129,10 @@ Prerequisites:
<Tab title="Usage">
<Steps>
<Step title="Authorize Infisical for GitHub">
Navigate to your project's integrations tab in Infisical and press on the Github tile.
Navigate to your project's integrations tab in Infisical and press on the GitHub tile.
![integrations](../../images/integrations/github/integration-overview.png)
Select OAuth as the authentication method and click **Connect to Github**.
Select OAuth as the authentication method and click **Connect to GitHub**.
![integrations github oauth auth selection](../../images/integrations/github/github-oauth-method-selection.png)
Grant Infisical access to your GitHub account (organization and repo privileges).
@@ -149,7 +149,7 @@ Prerequisites:
<Tab title="Organization">
![integrations github](../../images/integrations/github/integrations-github-scope-org.png)
When using the organization scope, your secrets will be saved in the top-level of your Github Organization.
When using the organization scope, your secrets will be saved in the top-level of your GitHub Organization.
You can choose the visibility, which defines which repositories can access the secrets. The options are:
- **All public repositories**: All public repositories in the organization can access the secrets.

View File

@@ -33,7 +33,7 @@ export default function GithubIntegrationAuthModeSelectionPage() {
return (
<div className="flex h-full w-full items-center justify-center">
<Head>
<title>Select Github Integration Auth</title>
<title>Select GitHub Integration Auth</title>
<link rel="icon" href="/infisical.ico" />
</Head>
<Card className="mb-12 max-w-lg rounded-md border border-mineshaft-600">
@@ -50,7 +50,7 @@ export default function GithubIntegrationAuthModeSelectionPage() {
alt="Github logo"
/>
</div>
<span className="ml-2.5">Github Integration </span>
<span className="ml-2.5">GitHub Integration </span>
<Link href="https://infisical.com/docs/integrations/cicd/githubactions" passHref>
<a target="_blank" rel="noopener noreferrer">
<div className="ml-2 mb-1 inline-block cursor-default rounded-md bg-yellow/20 px-1.5 pb-[0.03rem] pt-[0.04rem] text-sm text-yellow opacity-80 hover:opacity-100">
@@ -74,7 +74,7 @@ export default function GithubIntegrationAuthModeSelectionPage() {
}}
className="w-full border border-mineshaft-500"
>
<SelectItem value={AuthMethod.APP}>Github App (Recommended)</SelectItem>
<SelectItem value={AuthMethod.APP}>GitHub App (Recommended)</SelectItem>
<SelectItem value={AuthMethod.OAUTH}>OAuth</SelectItem>
</Select>
</FormControl>
@@ -96,7 +96,7 @@ export default function GithubIntegrationAuthModeSelectionPage() {
variant="outline_bg"
className="mt-4 ml-auto w-min"
>
Connect to Github
Connect to GitHub
</Button>
</div>
</CardBody>

View File

@@ -137,7 +137,7 @@ export default function SelectIntegrationAuthPage() {
<Card className="mb-12 max-w-lg rounded-md border border-mineshaft-600">
<CardTitle
className="px-6 text-left text-xl"
subTitle="Select a connection that you want to use for the new integration."
subTitle="Select an existing connection below or create a new one for your integration."
>
<div className="flex flex-row items-center">
<div className="flex items-center pb-0.5">
@@ -157,8 +157,7 @@ export default function SelectIntegrationAuthPage() {
return (
<Button
colorSchema="gray"
variant="outline"
colorSchema="secondary"
className="mt-3 w-3/4"
isDisabled={isIntegrationAuthSelectLoading}
key={integrationAuth.id}