mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 10:28:22 +00:00
misc: addressed review comments
This commit is contained in:
@@ -120,12 +120,12 @@ const envSchema = z
|
|||||||
// github oauth
|
// github oauth
|
||||||
CLIENT_ID_GITHUB: zpStr(z.string().optional()),
|
CLIENT_ID_GITHUB: zpStr(z.string().optional()),
|
||||||
CLIENT_SECRET_GITHUB: zpStr(z.string().optional()),
|
CLIENT_SECRET_GITHUB: zpStr(z.string().optional()),
|
||||||
CLIENT_SLUG_GITHUB_APP: zpStr(z.string().optional()),
|
|
||||||
// github app
|
// github app
|
||||||
CLIENT_ID_GITHUB_APP: zpStr(z.string().optional()),
|
CLIENT_ID_GITHUB_APP: zpStr(z.string().optional()),
|
||||||
CLIENT_SECRET_GITHUB_APP: zpStr(z.string().optional()),
|
CLIENT_SECRET_GITHUB_APP: zpStr(z.string().optional()),
|
||||||
CLIENT_PRIVATE_KEY_GITHUB_APP: zpStr(z.string().optional()),
|
CLIENT_PRIVATE_KEY_GITHUB_APP: zpStr(z.string().optional()),
|
||||||
CLIENT_APP_ID_GITHUB_APP: z.coerce.number().optional(),
|
CLIENT_APP_ID_GITHUB_APP: z.coerce.number().optional(),
|
||||||
|
CLIENT_SLUG_GITHUB_APP: zpStr(z.string().optional()),
|
||||||
|
|
||||||
// azure
|
// azure
|
||||||
CLIENT_ID_AZURE: zpStr(z.string().optional()),
|
CLIENT_ID_AZURE: zpStr(z.string().optional()),
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ import { KmsDataKey } from "../kms/kms-types";
|
|||||||
import { TProjectBotServiceFactory } from "../project-bot/project-bot-service";
|
import { TProjectBotServiceFactory } from "../project-bot/project-bot-service";
|
||||||
import { getApps } from "./integration-app-list";
|
import { getApps } from "./integration-app-list";
|
||||||
import { TIntegrationAuthDALFactory } from "./integration-auth-dal";
|
import { TIntegrationAuthDALFactory } from "./integration-auth-dal";
|
||||||
import { IntegrationAuthMetadataSchema } from "./integration-auth-schema";
|
import { IntegrationAuthMetadataSchema, TIntegrationAuthMetadata } from "./integration-auth-schema";
|
||||||
import {
|
import {
|
||||||
TBitbucketWorkspace,
|
TBitbucketWorkspace,
|
||||||
TChecklyGroups,
|
TChecklyGroups,
|
||||||
@@ -642,7 +642,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
const { shouldUseSecretV2Bridge, botKey } = await projectBotService.getBotKey(integrationAuth.projectId);
|
const { shouldUseSecretV2Bridge, botKey } = await projectBotService.getBotKey(integrationAuth.projectId);
|
||||||
|
|
||||||
let octokit: Octokit;
|
let octokit: Octokit;
|
||||||
const { installationId } = (integrationAuth.metadata as { installationId: string }) || {};
|
const { installationId } = (integrationAuth.metadata as TIntegrationAuthMetadata) || {};
|
||||||
if (installationId) {
|
if (installationId) {
|
||||||
octokit = new Octokit({
|
octokit = new Octokit({
|
||||||
authStrategy: createAppAuth,
|
authStrategy: createAppAuth,
|
||||||
|
|||||||
Binary file not shown.
|
Before Width: | Height: | Size: 363 KiB After Width: | Height: | Size: 367 KiB |
@@ -4,31 +4,31 @@ description: "How to sync secrets from Infisical to GitHub Actions"
|
|||||||
---
|
---
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Alternatively, you can use Infisical's official Github Action
|
Alternatively, you can use Infisical's official GitHub Action
|
||||||
[here](https://github.com/Infisical/secrets-action).
|
[here](https://github.com/Infisical/secrets-action).
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
Infisical lets you sync secrets to GitHub at the organization-level, repository-level, and repository environment-level.
|
Infisical lets you sync secrets to GitHub at the organization-level, repository-level, and repository environment-level.
|
||||||
|
|
||||||
## Connecting with Github App (Recommended)
|
## Connecting with GitHub App (Recommended)
|
||||||
|
|
||||||
<Tabs>
|
<Tabs>
|
||||||
<Tab title="Usage">
|
<Tab title="Usage">
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Authorize Github Infisical App">
|
<Step title="Authorize GitHub Infisical App">
|
||||||
Navigate to your project's integrations tab in Infisical and press on the GitHub tile.
|
Navigate to your project's integrations tab in Infisical and press on the GitHub tile.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
Select Github App as the authentication method and click **Connect to Github**.
|
Select GitHub App as the authentication method and click **Connect to GitHub**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
You will then be redirected to the Github app installation page.
|
You will then be redirected to the GitHub app installation page.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
Install and authorize the Github application. This will redirect you back to the Infisical integration page.
|
Install and authorize the GitHub application. This will redirect you back to the Infisical integration page.
|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Configure Infisical GitHub integration">
|
<Step title="Configure Infisical GitHub integration">
|
||||||
@@ -41,7 +41,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
|
|||||||
<Tab title="Organization">
|
<Tab title="Organization">
|
||||||

|

|
||||||
|
|
||||||
When using the organization scope, your secrets will be saved in the top-level of your Github Organization.
|
When using the organization scope, your secrets will be saved in the top-level of your GitHub Organization.
|
||||||
|
|
||||||
You can choose the visibility, which defines which repositories can access the secrets. The options are:
|
You can choose the visibility, which defines which repositories can access the secrets. The options are:
|
||||||
- **All public repositories**: All public repositories in the organization can access the secrets.
|
- **All public repositories**: All public repositories in the organization can access the secrets.
|
||||||
@@ -65,7 +65,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
|
|||||||
and registering your instance with it.
|
and registering your instance with it.
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Create an application on GitHub">
|
<Step title="Create an application on GitHub">
|
||||||
Navigate to the Github app settings [here](https://github.com/settings/apps). Click **New Github App**.
|
Navigate to the GitHub app settings [here](https://github.com/settings/apps). Click **New GitHub App**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@@ -79,7 +79,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
|
|||||||
Disable webhook by unchecking the Active checkbox.
|
Disable webhook by unchecking the Active checkbox.
|
||||||

|

|
||||||
|
|
||||||
Set the repository permissions as follows: Metadata: Read-only, Secrets: Read and write.
|
Set the repository permissions as follows: Metadata: Read-only, Secrets: Read and write, Environments: Read and write.
|
||||||

|

|
||||||
|
|
||||||
Similarly, set the organization permissions as follows: Secrets: Read and write.
|
Similarly, set the organization permissions as follows: Secrets: Read and write.
|
||||||
@@ -90,7 +90,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
|
|||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
If you have a GitHub organization, you can create an application under it
|
If you have a GitHub organization, you can create an application under it
|
||||||
in your organization Settings > Developer settings > Github Apps > New Github App.
|
in your organization Settings > Developer settings > GitHub Apps > New GitHub App.
|
||||||
</Note>
|
</Note>
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Add your application credentials to Infisical">
|
<Step title="Add your application credentials to Infisical">
|
||||||
@@ -107,9 +107,9 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
|
|||||||
|
|
||||||
- `CLIENT_ID_GITHUB_APP`: The **Client ID** of your GitHub application.
|
- `CLIENT_ID_GITHUB_APP`: The **Client ID** of your GitHub application.
|
||||||
- `CLIENT_SECRET_GITHUB_APP`: The **Client Secret** of your GitHub application.
|
- `CLIENT_SECRET_GITHUB_APP`: The **Client Secret** of your GitHub application.
|
||||||
- `CLIENT_SLUG_GITHUB_APP`: The **Slug** of your Github application. This is the one found in the URL.
|
- `CLIENT_SLUG_GITHUB_APP`: The **Slug** of your GitHub application. This is the one found in the URL.
|
||||||
- `CLIENT_APP_ID_GITHUB_APP`: The **App ID** of your Github application.
|
- `CLIENT_APP_ID_GITHUB_APP`: The **App ID** of your GitHub application.
|
||||||
- `CLIENT_PRIVATE_KEY_GITHUB_APP`: The **Private Key** of your Github application.
|
- `CLIENT_PRIVATE_KEY_GITHUB_APP`: The **Private Key** of your GitHub application.
|
||||||
|
|
||||||
Once added, restart your Infisical instance and use the GitHub integration via app authentication.
|
Once added, restart your Infisical instance and use the GitHub integration via app authentication.
|
||||||
</Step>
|
</Step>
|
||||||
@@ -118,7 +118,7 @@ Infisical lets you sync secrets to GitHub at the organization-level, repository-
|
|||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
## Connecting with Github OAuth
|
## Connecting with GitHub OAuth
|
||||||
|
|
||||||
Prerequisites:
|
Prerequisites:
|
||||||
|
|
||||||
@@ -129,10 +129,10 @@ Prerequisites:
|
|||||||
<Tab title="Usage">
|
<Tab title="Usage">
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Authorize Infisical for GitHub">
|
<Step title="Authorize Infisical for GitHub">
|
||||||
Navigate to your project's integrations tab in Infisical and press on the Github tile.
|
Navigate to your project's integrations tab in Infisical and press on the GitHub tile.
|
||||||

|

|
||||||
|
|
||||||
Select OAuth as the authentication method and click **Connect to Github**.
|
Select OAuth as the authentication method and click **Connect to GitHub**.
|
||||||

|

|
||||||
|
|
||||||
Grant Infisical access to your GitHub account (organization and repo privileges).
|
Grant Infisical access to your GitHub account (organization and repo privileges).
|
||||||
@@ -149,7 +149,7 @@ Prerequisites:
|
|||||||
<Tab title="Organization">
|
<Tab title="Organization">
|
||||||

|

|
||||||
|
|
||||||
When using the organization scope, your secrets will be saved in the top-level of your Github Organization.
|
When using the organization scope, your secrets will be saved in the top-level of your GitHub Organization.
|
||||||
|
|
||||||
You can choose the visibility, which defines which repositories can access the secrets. The options are:
|
You can choose the visibility, which defines which repositories can access the secrets. The options are:
|
||||||
- **All public repositories**: All public repositories in the organization can access the secrets.
|
- **All public repositories**: All public repositories in the organization can access the secrets.
|
||||||
|
|||||||
@@ -33,7 +33,7 @@ export default function GithubIntegrationAuthModeSelectionPage() {
|
|||||||
return (
|
return (
|
||||||
<div className="flex h-full w-full items-center justify-center">
|
<div className="flex h-full w-full items-center justify-center">
|
||||||
<Head>
|
<Head>
|
||||||
<title>Select Github Integration Auth</title>
|
<title>Select GitHub Integration Auth</title>
|
||||||
<link rel="icon" href="/infisical.ico" />
|
<link rel="icon" href="/infisical.ico" />
|
||||||
</Head>
|
</Head>
|
||||||
<Card className="mb-12 max-w-lg rounded-md border border-mineshaft-600">
|
<Card className="mb-12 max-w-lg rounded-md border border-mineshaft-600">
|
||||||
@@ -50,7 +50,7 @@ export default function GithubIntegrationAuthModeSelectionPage() {
|
|||||||
alt="Github logo"
|
alt="Github logo"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
<span className="ml-2.5">Github Integration </span>
|
<span className="ml-2.5">GitHub Integration </span>
|
||||||
<Link href="https://infisical.com/docs/integrations/cicd/githubactions" passHref>
|
<Link href="https://infisical.com/docs/integrations/cicd/githubactions" passHref>
|
||||||
<a target="_blank" rel="noopener noreferrer">
|
<a target="_blank" rel="noopener noreferrer">
|
||||||
<div className="ml-2 mb-1 inline-block cursor-default rounded-md bg-yellow/20 px-1.5 pb-[0.03rem] pt-[0.04rem] text-sm text-yellow opacity-80 hover:opacity-100">
|
<div className="ml-2 mb-1 inline-block cursor-default rounded-md bg-yellow/20 px-1.5 pb-[0.03rem] pt-[0.04rem] text-sm text-yellow opacity-80 hover:opacity-100">
|
||||||
@@ -74,7 +74,7 @@ export default function GithubIntegrationAuthModeSelectionPage() {
|
|||||||
}}
|
}}
|
||||||
className="w-full border border-mineshaft-500"
|
className="w-full border border-mineshaft-500"
|
||||||
>
|
>
|
||||||
<SelectItem value={AuthMethod.APP}>Github App (Recommended)</SelectItem>
|
<SelectItem value={AuthMethod.APP}>GitHub App (Recommended)</SelectItem>
|
||||||
<SelectItem value={AuthMethod.OAUTH}>OAuth</SelectItem>
|
<SelectItem value={AuthMethod.OAUTH}>OAuth</SelectItem>
|
||||||
</Select>
|
</Select>
|
||||||
</FormControl>
|
</FormControl>
|
||||||
@@ -96,7 +96,7 @@ export default function GithubIntegrationAuthModeSelectionPage() {
|
|||||||
variant="outline_bg"
|
variant="outline_bg"
|
||||||
className="mt-4 ml-auto w-min"
|
className="mt-4 ml-auto w-min"
|
||||||
>
|
>
|
||||||
Connect to Github
|
Connect to GitHub
|
||||||
</Button>
|
</Button>
|
||||||
</div>
|
</div>
|
||||||
</CardBody>
|
</CardBody>
|
||||||
|
|||||||
@@ -137,7 +137,7 @@ export default function SelectIntegrationAuthPage() {
|
|||||||
<Card className="mb-12 max-w-lg rounded-md border border-mineshaft-600">
|
<Card className="mb-12 max-w-lg rounded-md border border-mineshaft-600">
|
||||||
<CardTitle
|
<CardTitle
|
||||||
className="px-6 text-left text-xl"
|
className="px-6 text-left text-xl"
|
||||||
subTitle="Select a connection that you want to use for the new integration."
|
subTitle="Select an existing connection below or create a new one for your integration."
|
||||||
>
|
>
|
||||||
<div className="flex flex-row items-center">
|
<div className="flex flex-row items-center">
|
||||||
<div className="flex items-center pb-0.5">
|
<div className="flex items-center pb-0.5">
|
||||||
@@ -157,8 +157,7 @@ export default function SelectIntegrationAuthPage() {
|
|||||||
|
|
||||||
return (
|
return (
|
||||||
<Button
|
<Button
|
||||||
colorSchema="gray"
|
colorSchema="secondary"
|
||||||
variant="outline"
|
|
||||||
className="mt-3 w-3/4"
|
className="mt-3 w-3/4"
|
||||||
isDisabled={isIntegrationAuthSelectLoading}
|
isDisabled={isIntegrationAuthSelectLoading}
|
||||||
key={integrationAuth.id}
|
key={integrationAuth.id}
|
||||||
|
|||||||
Reference in New Issue
Block a user