Fix merge conflicts
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Available"
|
||||
openapi: "GET /api/v1/app-connections/hashicorp-vault/available"
|
||||
---
|
||||
@@ -0,0 +1,8 @@
|
||||
---
|
||||
title: "Create"
|
||||
openapi: "POST /api/v1/app-connections/hashicorp-vault"
|
||||
---
|
||||
|
||||
<Note>
|
||||
Check out the configuration docs for [Hashicorp Vault Connections](/integrations/app-connections/hashicorp-vault) to learn how to obtain the required credentials.
|
||||
</Note>
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Delete"
|
||||
openapi: "DELETE /api/v1/app-connections/hashicorp-vault/{connectionId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by ID"
|
||||
openapi: "GET /api/v1/app-connections/hashicorp-vault/{connectionId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by Name"
|
||||
openapi: "GET /api/v1/app-connections/hashicorp-vault/connection-name/{connectionName}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "List"
|
||||
openapi: "GET /api/v1/app-connections/hashicorp-vault"
|
||||
---
|
||||
@@ -0,0 +1,8 @@
|
||||
---
|
||||
title: "Update"
|
||||
openapi: "PATCH /api/v1/app-connections/hashicorp-vault/{connectionId}"
|
||||
---
|
||||
|
||||
<Note>
|
||||
Check out the configuration docs for [Hashicorp Vault Connections](/integrations/app-connections/hashicorp-vault) to learn how to obtain the required credentials.
|
||||
</Note>
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Create"
|
||||
openapi: "POST /api/v1/secret-syncs/hashicorp-vault"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Delete"
|
||||
openapi: "DELETE /api/v1/secret-syncs/hashicorp-vault/{syncId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by ID"
|
||||
openapi: "GET /api/v1/secret-syncs/hashicorp-vault/{syncId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by Name"
|
||||
openapi: "GET /api/v1/secret-syncs/hashicorp-vault/sync-name/{syncName}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Import Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/hashicorp-vault/{syncId}/import-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "List"
|
||||
openapi: "GET /api/v1/secret-syncs/hashicorp-vault"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Remove Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/hashicorp-vault/{syncId}/remove-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Sync Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/hashicorp-vault/{syncId}/sync-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Update"
|
||||
openapi: "PATCH /api/v1/secret-syncs/hashicorp-vault/{syncId}"
|
||||
---
|
||||
@@ -45,6 +45,10 @@ description: "Learn how to configure Auth0 OIDC for Infisical SSO."
|
||||
3.2. For configuration type, select **Discovery URL**. Then, set **Discovery Document URL**, **JWT Signature Algorithm**, **Client ID**, and **Client Secret** from step 2.1 and 2.2.
|
||||

|
||||
|
||||
<Info>
|
||||
Currently, the following JWT signature algorithms are supported: RS256, RS512, HS256, and EdDSA
|
||||
</Info>
|
||||
|
||||
Once you've done that, press **Update** to complete the required configuration.
|
||||
|
||||
</Step>
|
||||
|
||||
@@ -44,7 +44,9 @@ Prerequisites:
|
||||
To configure OIDC via the custom endpoints, set the **Configuration Type** field to **Custom** and input the required endpoint fields.
|
||||

|
||||
|
||||
2.3. Optionally, you can define a whitelist of allowed email domains.
|
||||
2.3. Select the appropriate JWT signature algorithm for your IdP. Currently, the supported options are RS256, RS512, HS256, and EdDSA.
|
||||
|
||||
2.4. Optionally, you can define a whitelist of allowed email domains.
|
||||
|
||||
Finally, fill out the **Client ID** and **Client Secret** fields and press **Update** to complete the required configuration.
|
||||
|
||||
|
||||
@@ -72,6 +72,10 @@ description: "Learn how to configure Keycloak OIDC for Infisical SSO."
|
||||
3.2. For configuration type, select Discovery URL. Then, set the appropriate values for **Discovery Document URL**, **JWT Signature Algorithm**, **Client ID**, and **Client Secret**.
|
||||

|
||||
|
||||
<Info>
|
||||
Currently, the following JWT signature algorithms are supported: RS256, RS512, HS256, and EdDSA
|
||||
</Info>
|
||||
|
||||
Once you've done that, press **Update** to complete the required configuration.
|
||||
|
||||
</Step>
|
||||
|
||||
@@ -35,6 +35,10 @@ Infisical supports these and many other identity providers:
|
||||
|
||||
If your required identity provider is not shown in the list above, please reach out to [team@infisical.com](mailto:team@infisical.com) for assistance.
|
||||
|
||||
<Info>
|
||||
For enhanced security, Infisical enforces PKCE (Proof Key for Code Exchange) with the OAuth 2.0-based SSO providers and OIDC. This provides additional protection against authorization code interception attacks and strengthens your authentication flow security.
|
||||
</Info>
|
||||
|
||||
## FAQ
|
||||
|
||||
<AccordionGroup>
|
||||
|
||||
@@ -0,0 +1,192 @@
|
||||
---
|
||||
title: "Microsoft Teams Integration"
|
||||
description: "Learn how to setup the Microsoft Teams integration"
|
||||
---
|
||||
|
||||
import MicrosoftTeamsWorkflowIntegration from '/snippets/documentation/platform/workflow-integrations/microsoft-teams-integration.mdx';
|
||||
|
||||
|
||||
This guide will provide step by step instructions on how to configure Microsoft Teams integration for your Infisical projects.
|
||||
|
||||
## Setting up Microsoft Teams integration in your projects
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical Cloud">
|
||||
<MicrosoftTeamsWorkflowIntegration />
|
||||
</Tab>
|
||||
<Tab title="Self-hosted setup">
|
||||
### Configure Azure Resources
|
||||
To create a Microsoft Teams bot, you must first create an Azure Bot from the Azure Marketplace, an app registration, and a Microsoft Teams app. The steps below document in detail how to create and configure these resources.
|
||||
|
||||
<Steps>
|
||||
|
||||
<Step title="Create Microsoft Teams app">
|
||||
Navigate to the [Microsoft Teams Developer Portal](https://dev.teams.microsoft.com/).
|
||||
|
||||
Once you're on the Microsoft Teams Developer Portal, press the "Create a new app" button on the overview page. Give the bot a name and press the "Add" button.
|
||||
|
||||

|
||||
</Step>
|
||||
|
||||
<Step title="Create a Microsoft Teams bot">
|
||||
After creating the Microsoft Teams app, you'll need to create a Microsoft Teams bot.
|
||||
|
||||
Navigate to the app's bot settings page and click "Create a new bot".
|
||||
|
||||

|
||||

|
||||
|
||||
After clicking the "Create a new bot" button, you'll be navigated to the Teams Developer Portal for bot management. Press the "New bot" button, and enter the name of the bot.
|
||||
Please keep in mind that the name of the bot can only contain alphanumeric characters, dashes, and underscores.
|
||||
|
||||

|
||||
</Step>
|
||||
|
||||
<Step title="Add a message endpoint to the bot">
|
||||
After creating the bot, you'll need to add a message endpoint to the bot. Navigate to the "Configure" tab, and input the following endpoint under "Endpoint address":
|
||||
`https://<your-infisical-instance-url>/api/v1/workflow-integrations/microsoft-teams/message-endpoint`
|
||||
Replace `<your-infisical-instance-url>` with the URL of your Infisical instance.
|
||||
|
||||
Press the "Save" button to save the changes.
|
||||
|
||||

|
||||
</Step>
|
||||
|
||||
<Step title="Find the bot in Azure App Registrations">
|
||||
When you create a bot through the Teams Developer Portal, an Azure App Registration is also created.
|
||||
|
||||
Open your [Azure Portal](https://portal.azure.com/) and navigate to the "App Registrations" section to find the newly created app registration.
|
||||
The name of the app registration will be the same as the name of the bot you created in the previous step.
|
||||
|
||||
|
||||
Press the app registration to open the app registration overview page.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step title="Add API Permissions to the App Registration">
|
||||
Navigate to the "API Permissions" section of the app registration, and add the following permissions:
|
||||
- `AppCatalog.Read.All`
|
||||
- `ChannelSettings.Read.All`
|
||||
- `MultiTenantOrganization.Read.All`
|
||||
- `Organization.Read.All`
|
||||
- `Team.ReadBasic.All`
|
||||
- `TeamsAppInstallation.Read.All`
|
||||
|
||||
After adding the API permissions, press the "Grant admin consent" button to grant the permissions.
|
||||
|
||||

|
||||
</Step>
|
||||
|
||||
<Step title="Add a new web application to the App Registration">
|
||||
Navigate to the "Authentication" section of the App Registration, and press the "Add a platform" button. Select the "Web" platform and enter the following redirect URI:
|
||||
`https://<your-infisical-instance-url>/organization/settings/oauth/callback`. Replace `<your-infisical-instance-url>` with the URL of your Infisical instance.
|
||||
|
||||

|
||||
</Step>
|
||||
|
||||
<Step title="Get App Registration Client ID and Client Secret">
|
||||
Next we need to get the application client ID and create a new client secret. **Save these values for later, as they're required to configure the Microsoft Teams integration in Infisical.**
|
||||
|
||||
**Get the Application (Client) ID**
|
||||
|
||||
To get the Application (Client) ID, press the "Copy" button next to the "Application (client) ID" field.
|
||||
|
||||

|
||||
|
||||
**Create a new client secret**
|
||||
|
||||
Create a new client secret within the app registration. Navigate to the "Certificates & Secrets" section of the app registration, and press the "New client secret" button.
|
||||
|
||||

|
||||
|
||||
<Warning>
|
||||
Remember to rotate your client secret before it expires. Consider setting up a reminder or automated process to replace the secret and update your Infisical configuration before expiration.
|
||||
</Warning>
|
||||
</Step>
|
||||
|
||||
<Step title="Get the Microsoft Teams App ID">
|
||||
Navigate back to the [Microsoft Teams Developer Portal](https://dev.teams.microsoft.com/), and press the "Apps" tab and select the app you created earlier.
|
||||
Here you can find the Microsoft Teams App ID in the overview page, which you need to copy and save for later.
|
||||
|
||||

|
||||
|
||||
</Step>
|
||||
|
||||
<Step title="Link the Microsoft Teams App to the bot">
|
||||
You need to link the Microsoft Teams App with the bot/app registration you created earlier.
|
||||
Inside the [Microsoft Teams Developer Portal](https://dev.teams.microsoft.com/), navigate to the "Bot" tab and select the bot you created earlier. Navigate to the "App Features" section, and press the "Bot" button.
|
||||
|
||||
Under the "What can your bot do?" section, enable `Only send notifications (one-way conversations)`.
|
||||
|
||||
Under the "Select the scopes where people can use your bot" section, select `Personal`, `Team`, and `Group Chat`.
|
||||
|
||||
Finally, press the "Save" button to save the changes.
|
||||
|
||||

|
||||

|
||||
</Step>
|
||||
|
||||
<Step title="Run an app validation test (Recommended)">
|
||||
To ensure that the Microsoft Teams App is working correctly, you can run an app validation test. This step is optional, but recommended to ensure the app is working correctly.
|
||||
|
||||
You should expect to see two errors related to sending welcome messages, because we haven't configured the Microsoft Teams App inside Infisical yet, which is required for proactive messages.
|
||||
|
||||

|
||||
|
||||
<Note>
|
||||
You may see manifest validation errors. Before running an app validation test, you must ensure that your app has all errors resolved, such as having a description and a valid name.
|
||||
</Note>
|
||||
|
||||

|
||||
|
||||
<Note>
|
||||
If you see two errors for bot welcome messages, you can ignore them. This is expected until you configure the Microsoft Teams App inside Infisical.
|
||||
</Note>
|
||||
</Step>
|
||||
|
||||
<Step title="Download the App Package">
|
||||
Once the Microsoft Teams App is working correctly, you can download the app package by navigating to the "Publish to Store" page, and pressing the "Download app package" button.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
### Configure Microsoft Teams Bot in Infisical
|
||||
|
||||
After creating the Microsoft Teams App and Bot, you are ready to configure the Microsoft Teams integration in Infisical.
|
||||
Please note that you must be an instance admin in order to configure the Microsoft Teams instance-wide settings.
|
||||
|
||||
<Steps>
|
||||
<Step title="Navigate to the Integrations tab in your Server Admin Console settings">
|
||||

|
||||

|
||||
|
||||
Enter the values you saved from the earlier steps into the respective fields.
|
||||
|
||||
- **Application (Client) ID**: The Client ID of the App Registration from the previous steps.
|
||||
- **Client Secret**: The Client Secret of the App Registration from the previous steps.
|
||||
- **Microsoft Teams App ID**: The App ID of the Microsoft Teams App from the previous steps.
|
||||
|
||||
Once completed, press the "Save" button to save your changes.
|
||||
|
||||
</Step>
|
||||
</Steps>
|
||||
<MicrosoftTeamsWorkflowIntegration />
|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
<Accordion title="Notifications are not being sent to Microsoft Teams even though the integration is configured">
|
||||
If you recently added the Microsoft Teams app to your tenant, **it may take up to 24 hours for Microsoft Teams to propagate the changes.**
|
||||
A common indication of propagation issues is that the workflow integration is shown as "Installed", and you're able to view the teams and channels when configuring the workflow integration on your project, but no notification is being sent.
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Workflow Integration is stuck on 'Pending' status">
|
||||
The workflow integration can get stuck on Pending if you created the workflow integration before the Infisical Microsoft Teams bot was installed in the tenant.
|
||||
To resolve this, make sure you have installed the Infisical Microsoft Teams app in your tenant.
|
||||
|
||||
You can manually recheck the installation status by pressing the "Check Installation Status" button in the workflow organization settings.
|
||||
|
||||

|
||||
</Accordion>
|
||||
@@ -1,6 +1,6 @@
|
||||
---
|
||||
title: "Slack integration"
|
||||
description: "Learn how to setup Slack integration"
|
||||
title: "Slack Integration"
|
||||
description: "Learn how to setup the Slack integration"
|
||||
---
|
||||
|
||||
This guide will provide step by step instructions on how to configure Slack integration for your Infisical projects.
|
||||
|
||||
BIN
docs/images/app-connections/hashicorp-vault/vault-access.png
Normal file
|
After Width: | Height: | Size: 400 KiB |
BIN
docs/images/app-connections/hashicorp-vault/vault-approle.png
Normal file
|
After Width: | Height: | Size: 312 KiB |
|
After Width: | Height: | Size: 237 KiB |
|
After Width: | Height: | Size: 495 KiB |
|
After Width: | Height: | Size: 275 KiB |
|
After Width: | Height: | Size: 230 KiB |
|
After Width: | Height: | Size: 643 KiB |
|
After Width: | Height: | Size: 726 KiB |
|
After Width: | Height: | Size: 1.1 MiB |
|
After Width: | Height: | Size: 399 KiB |
|
After Width: | Height: | Size: 209 KiB |
|
After Width: | Height: | Size: 407 KiB |
|
After Width: | Height: | Size: 380 KiB |
BIN
docs/images/app-connections/hashicorp-vault/vault-shell.png
Normal file
|
After Width: | Height: | Size: 361 KiB |
BIN
docs/images/app-connections/hashicorp-vault/vault-token.png
Normal file
|
After Width: | Height: | Size: 407 KiB |
|
Before Width: | Height: | Size: 140 KiB |
|
Before Width: | Height: | Size: 608 KiB |
|
Before Width: | Height: | Size: 736 KiB |
|
Before Width: | Height: | Size: 1.1 MiB |
|
Before Width: | Height: | Size: 1.1 MiB |
|
Before Width: | Height: | Size: 1.1 MiB |
|
Before Width: | Height: | Size: 141 KiB |
|
Before Width: | Height: | Size: 770 KiB |
|
Before Width: | Height: | Size: 868 KiB |
|
Before Width: | Height: | Size: 140 KiB |
|
Before Width: | Height: | Size: 641 KiB |
|
Before Width: | Height: | Size: 753 KiB |
|
Before Width: | Height: | Size: 545 KiB |
|
Before Width: | Height: | Size: 599 KiB |
|
After Width: | Height: | Size: 230 KiB |
|
After Width: | Height: | Size: 259 KiB |
|
After Width: | Height: | Size: 192 KiB |
|
After Width: | Height: | Size: 271 KiB |
|
After Width: | Height: | Size: 125 KiB |
|
After Width: | Height: | Size: 278 KiB |
|
After Width: | Height: | Size: 206 KiB |
|
After Width: | Height: | Size: 227 KiB |
|
After Width: | Height: | Size: 299 KiB |
|
After Width: | Height: | Size: 229 KiB |
|
After Width: | Height: | Size: 292 KiB |
|
After Width: | Height: | Size: 156 KiB |
|
After Width: | Height: | Size: 787 KiB |
|
After Width: | Height: | Size: 139 KiB |
|
After Width: | Height: | Size: 304 KiB |
|
After Width: | Height: | Size: 194 KiB |
|
After Width: | Height: | Size: 206 KiB |
|
After Width: | Height: | Size: 300 KiB |
|
After Width: | Height: | Size: 83 KiB |
|
After Width: | Height: | Size: 206 KiB |
|
After Width: | Height: | Size: 152 KiB |
|
After Width: | Height: | Size: 192 KiB |
|
After Width: | Height: | Size: 154 KiB |
|
After Width: | Height: | Size: 207 KiB |
|
After Width: | Height: | Size: 137 KiB |
|
After Width: | Height: | Size: 421 KiB |
|
After Width: | Height: | Size: 74 KiB |
|
After Width: | Height: | Size: 230 KiB |
BIN
docs/images/secret-syncs/hashicorp-vault/select-option.png
Normal file
|
After Width: | Height: | Size: 687 KiB |
BIN
docs/images/secret-syncs/hashicorp-vault/sync-created.png
Normal file
|
After Width: | Height: | Size: 1.1 MiB |
BIN
docs/images/secret-syncs/hashicorp-vault/sync-destination.png
Normal file
|
After Width: | Height: | Size: 655 KiB |
BIN
docs/images/secret-syncs/hashicorp-vault/sync-details.png
Normal file
|
After Width: | Height: | Size: 634 KiB |
BIN
docs/images/secret-syncs/hashicorp-vault/sync-options.png
Normal file
|
After Width: | Height: | Size: 656 KiB |
BIN
docs/images/secret-syncs/hashicorp-vault/sync-review.png
Normal file
|
After Width: | Height: | Size: 662 KiB |
BIN
docs/images/secret-syncs/hashicorp-vault/sync-source.png
Normal file
|
After Width: | Height: | Size: 626 KiB |
|
Before Width: | Height: | Size: 535 KiB After Width: | Height: | Size: 673 KiB |
|
Before Width: | Height: | Size: 475 KiB After Width: | Height: | Size: 581 KiB |
214
docs/integrations/app-connections/hashicorp-vault.mdx
Normal file
@@ -0,0 +1,214 @@
|
||||
---
|
||||
title: "Hashicorp Vault Connection"
|
||||
description: "Learn how to configure a Hashicorp Vault Connection for Infisical."
|
||||
---
|
||||
|
||||
<Note>
|
||||
Infisical is compatible with Vault Self-hosted, HCP Vault Dedicated, and HCP Vault Enterprise deployments. Please note that HCP Generic Secrets are currently not supported.
|
||||
</Note>
|
||||
|
||||
Infisical supports two methods for connecting to Hashicorp Vault.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="App Role (Recommended)">
|
||||
<Steps>
|
||||
<Step title="Navigate to Vault Access">
|
||||

|
||||
</Step>
|
||||
<Step title="Enable New Method">
|
||||
In the **Authentication Methods** tab, click on **Enable new method**.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Select AppRole">
|
||||

|
||||
</Step>
|
||||
<Step title="Enable Method">
|
||||
You may change the name of the method, but we suggest keeping it as `approle`.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Navigate to Vault Policies">
|
||||
From the home page, navigate to **Policies**.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Create ACL Policy">
|
||||

|
||||
</Step>
|
||||
<Step title="Create Policy">
|
||||
You may name your policy whatever you want, but remember the name as it will be used in future steps.
|
||||
|
||||
Depending on your use case, you may have different policy configurations:
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Secret Sync">
|
||||
```hcl
|
||||
path "demo_mount/data/*" {
|
||||
capabilities = [ "create", "read", "update" ]
|
||||
}
|
||||
|
||||
path "sys/mounts" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
```
|
||||
|
||||
- **demo_mount**: The name of the target secrets engine (e.g., 'secret', 'kv').
|
||||
- **data/\***: The path within the secrets engine used for storing secrets. The wildcard (*) grants access to all secrets within this mount point.
|
||||
|
||||
<Note>
|
||||
Make sure to replace the policy path with the specific path where you intend to sync your secrets. For better security and control, it's recommended to use a more granular path instead of a wildcard (*). You can also specify a path that doesn’t yet exist—Infisical will automatically create it for you during the sync process.
|
||||
</Note>
|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Run Shell Commands">
|
||||
**Open Vault Shell**
|
||||
|
||||

|
||||
|
||||
<Note>
|
||||
If you used custom approle or policy names in previous steps, you'll need to customize the following commands.
|
||||
</Note>
|
||||
|
||||
**Create Infisical Role**
|
||||
|
||||
```hcl
|
||||
vault write auth/approle/role/infisical token_policies="infisical-policy" token_ttl=30s token_max_ttl=2m
|
||||
```
|
||||
|
||||
**Read RoleID**
|
||||
|
||||
```hcl
|
||||
vault read auth/approle/role/infisical/role-id
|
||||
```
|
||||
|
||||
**Generate New SecretID**
|
||||
|
||||
```hcl
|
||||
vault write -force auth/approle/role/infisical/secret-id
|
||||
```
|
||||
|
||||
Your shell output should look similar to the image below. Save the RoleID and SecretID values for later steps.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
<Tab title="Access Token">
|
||||
## Get a Hashicorp Vault Access Token
|
||||
|
||||
Open your profile dropdown and click **Copy token**. This token will be used in later steps.
|
||||
|
||||

|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
## Getting Vault Instance URL
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Self Hosted">
|
||||
For self-hosted instances, locate and copy your vault's base URL (for example: `https://vault.example.com`).
|
||||
|
||||
Save the URL for later steps.
|
||||
</Tab>
|
||||
<Tab title="Hashicorp Cloud Platform">
|
||||
On HCP instances, you may need to navigate to **Cluster Overview** to see your cluster URL. Save this value for later steps.
|
||||
|
||||

|
||||
|
||||
<Note>
|
||||
Cluster Overview is found in the HCP dashboard, not in your cluster's web UI.
|
||||
</Note>
|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
## Setup Vault Connection in Infisical
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
<Steps>
|
||||
<Step title="Navigate to App Connections">
|
||||
In your Infisical dashboard, go to **Organization Settings** and select the **App Connections** tab.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Add Connection">
|
||||
Click the **+ Add Connection** button and select the **Hashicorp Vault Connection** option.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Configure Connection">
|
||||
Configure your Vault Connection using the Instance URL and credentials from the steps above. **Depending on if you chose to authenticate with an Access Token or AppRole, you may need to input different information.**
|
||||
|
||||

|
||||
|
||||
<Tabs>
|
||||
<Tab title="App Role">
|
||||
- **Name**: The name of the connection being created. Must be slug-friendly.
|
||||
- **Description**: An optional description to provide details about this connection.
|
||||
- **Instance URL**: The URL of your Hashicorp Vault instance.
|
||||
- **Namespace (optional)**: The namespace within your vault. Self-hosted and enterprise clusters may not use namespaces.
|
||||
- **Role ID**: The Role ID generated in the steps above.
|
||||
- **Secret ID**: The Secret ID generated in the steps above.
|
||||
</Tab>
|
||||
<Tab title="Access Token">
|
||||
- **Name**: The name of the connection being created. Must be slug-friendly.
|
||||
- **Description**: An optional description to provide details about this connection.
|
||||
- **Instance URL**: The URL of your Hashicorp Vault instance.
|
||||
- **Namespace (optional)**: The namespace within your vault. Self-hosted and enterprise clusters may not use namespaces.
|
||||
- **Access Token**: The Access Token generated in the steps above.
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
<Step title="Connection Created">
|
||||
Your Vault Connection is now available for use.
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create a Vault Connection, make an API request to the [Create Hashicorp Vault
|
||||
Connection](/api-reference/endpoints/app-connections/hashicorp-vault/create) API endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/app-connections/hashicorp-vault \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-vault-connection",
|
||||
"method": "app-role",
|
||||
"credentials": {
|
||||
"instanceUrl": "https://vault.example.com",
|
||||
"roleId": "4797c4fa-7794-71f0-c8b1-7c87759df5bf",
|
||||
"secretId": "ad24df93-19c8-c865-9997-6b8513253d3a"
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"appConnection": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"name": "my-vault-connection",
|
||||
"version": 1,
|
||||
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"createdAt": "2025-04-01T05:31:56Z",
|
||||
"updatedAt": "2025-04-01T05:31:56Z",
|
||||
"app": "hashicorp-vault",
|
||||
"method": "app-role",
|
||||
"credentials": {
|
||||
"instanceUrl": "https://vault.example.com",
|
||||
"roleId": "4797c4fa-7794-71f0-c8b1-7c87759df5bf"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
@@ -4,158 +4,5 @@ description: "How to sync secrets from Infisical to HashiCorp Vault"
|
||||
---
|
||||
|
||||
<Note>
|
||||
Infisical connects to Vault via the AppRole auth method.
|
||||
|
||||
Currently, each Infisical project can only point and sync secrets to one Vault cluster / namespace
|
||||
but with unlimited integrations to different paths within it.
|
||||
|
||||
This tutorial makes use of Vault's UI but, in principle, instructions can executed via
|
||||
Vault CLI or API call.
|
||||
|
||||
Lastly, you should note that we provide a simple use-case and, in practice, you should adapt and extend it to your own Vault use-case and follow best practices, for instance when defining fine-grained ACL policies.
|
||||
The Hashicorp Vault Native Integration will be deprecated in 2026. Please migrate to our new [Hashicorp Vault Sync](../secret-syncs/hashicorp-vault).
|
||||
</Note>
|
||||
|
||||
Prerequisites:
|
||||
|
||||
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
||||
- Have experience with [HashiCorp Vault](https://www.vaultproject.io/).
|
||||
|
||||
## Navigate to your project's integrations tab
|
||||
|
||||

|
||||
|
||||
## Prepare Vault
|
||||
|
||||
This section mirrors the latter parts of the [Vault quickstart](https://developer.hashicorp.com/vault/tutorials/cloud/getting-started-intro) provided by HashiCorp and uses sample names/values for demonstration.
|
||||
|
||||
To begin, navigate to the cluster / namespace that you want to sync secrets to in Vault; we'll use the default `admin` namespace (in practice, we recommend creating a namespace and not using the default `admin` namespace).
|
||||
|
||||
### Enable KV Secrets Engine
|
||||
|
||||
In Secrets, enable a KV Secrets Engine at a path for Infisical to sync secrets to; we'll use the path `kv`.
|
||||
|
||||

|
||||

|
||||

|
||||
|
||||
### Enable the AppRole auth method
|
||||
|
||||
In Access > Auth Methods, enable the AppRole auth method.
|
||||
|
||||

|
||||

|
||||

|
||||
|
||||
### Create an ACL Policy
|
||||
|
||||
Now in Policies, create a new ACL policy scoped to the path(s) you wish Infisical to be able to sync secrets to.
|
||||
|
||||
We'll call the policy `test` and have it grant access to the `dev` path in the KV Secrets Engine where we will be syncing secrets to from Infisical.
|
||||
|
||||
```console
|
||||
path "kv/data/dev" {
|
||||
capabilities = [ "create", "read", "update" ]
|
||||
}
|
||||
|
||||
path "sys/namespaces/*" {
|
||||
capabilities = [ "create", "read", "update", "delete", "list" ]
|
||||
}
|
||||
```
|
||||
|
||||
<Note>
|
||||
`kv` comes from the path of the KV Secrets Engine that we enabled and `dev` is the chosen path within it
|
||||
that we want to sync secrets to.
|
||||
</Note>
|
||||
|
||||

|
||||

|
||||

|
||||
|
||||
### Create a role with the policy attached
|
||||
|
||||
We now create a `infisical` role with the generated token's time-to-live (TTL) set to 1 hour and can be renewed for up to 4 hours from the time of its creation.
|
||||
|
||||
1. Click the Vault CLI shell icon (`>_`) to open a command shell in the browser.
|
||||
|
||||

|
||||
|
||||
2. Copy the command below.
|
||||
|
||||
```console
|
||||
vault write auth/approle/role/infisical token_policies="test" token_ttl=1h token_max_ttl=4h
|
||||
```
|
||||
|
||||
3. Paste the command into the command shell in the browser and press the enter button.
|
||||
|
||||
### Generate a RoleID and SecretID
|
||||
|
||||
Finally, we need to generate a **RoleID** and **SecretID** (like a username and password) that Infisical can use
|
||||
to authenticate with Vault.
|
||||
|
||||
1. Click the Vault CLI shell icon (>_) again to open a command shell.
|
||||
|
||||
2. Read the RoleID.
|
||||
|
||||
```console
|
||||
vault read auth/approle/role/infisical/role-id
|
||||
```
|
||||
|
||||
Example output:
|
||||
|
||||
```console
|
||||
Key Value
|
||||
role_id b6ccdcca-183b-ce9c-6b98-b556b9a0edb9
|
||||
```
|
||||
|
||||
3. Generate a new SecretID of the `infisical` role.
|
||||
|
||||
```console
|
||||
vault write -force auth/approle/role/infisical/secret-id
|
||||
```
|
||||
|
||||
Example output:
|
||||
|
||||
|
||||
```console
|
||||
Key Value
|
||||
secret_id 735a47cc-7a98-77cc-0128-12b1e96a4157
|
||||
secret_id_accessor 3ab305d1-1eab-df4b-4079-ef7135635c49
|
||||
...snip...
|
||||
```
|
||||
|
||||
Great. We're now ready to connect Infisical to Vault!
|
||||
|
||||
## Enter your Vault instance and authentication details
|
||||
|
||||
Back in Infisical, press on the HashiCorp Vault tile and input your Vault instance and `infisical` role RoleID and SecretID.
|
||||
|
||||

|
||||
|
||||
For additional details on each field:
|
||||
|
||||
- Vault Cluster URL: The address of your cluster, either HCP or self-hosted.
|
||||
|
||||
If using HCP, you can copy your Cluster URL in the Cluster Overview:
|
||||
|
||||

|
||||
|
||||
- Vault Namespace: The Vault namespace you wish to connect to.
|
||||
- Vault RoleID: The RoleID previously created for the `infisical` role.
|
||||
- Vault SecretID: The SecretID previously created for the `infisical` role.
|
||||
|
||||
## Start integration
|
||||
|
||||
Select which Infisical environment secrets you want to sync to Vault.
|
||||
|
||||
For additional details on each field:
|
||||
|
||||
- Vault KV Secrets Engine Path: the path at which you enabled the intended KV Secrets Engine; in this demonstration, we used `kv`.
|
||||
- Vault Secret(s) Path: the path in the KV Secrets Engine that you wish to sync secrets to.
|
||||
|
||||
Press create integration to start syncing secrets to Vault.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
|
||||
|
||||
160
docs/integrations/secret-syncs/hashicorp-vault.mdx
Normal file
@@ -0,0 +1,160 @@
|
||||
---
|
||||
title: "Hashicorp Vault Sync"
|
||||
description: "Learn how to configure a Hashicorp Vault Sync for Infisical."
|
||||
---
|
||||
|
||||
**Prerequisites:**
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create a [Hashicorp Vault Connection](/integrations/app-connections/hashicorp-vault)
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
<Steps>
|
||||
<Step title="Add Sync">
|
||||
Navigate to **Project** > **Integrations** and select the **Secret Syncs** tab. Click on the **Add Sync** button.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Select Hashicorp Vault">
|
||||

|
||||
</Step>
|
||||
<Step title="Configure Source">
|
||||
Configure the **Source** from where secrets should be retrieved, then click **Next**.
|
||||
|
||||

|
||||
|
||||
- **Environment**: The project environment to retrieve secrets from.
|
||||
- **Secret Path**: The folder path to retrieve secrets from.
|
||||
|
||||
<Tip>
|
||||
If you need to sync secrets from multiple folder locations, check out [secret imports](/documentation/platform/secret-reference#secret-imports).
|
||||
</Tip>
|
||||
</Step>
|
||||
<Step title="Configure Destination">
|
||||
Configure the **Destination** to where secrets should be deployed.
|
||||
|
||||

|
||||
|
||||
- **Hashicorp Vault Connection**: The Vault Connection to authenticate with.
|
||||
- **Secrets Engine Mount**: The secrets engine to sync secrets with (e.g., 'secret', 'kv').
|
||||
- **Path**: The specific path within the secrets engine where secrets will be stored.
|
||||
|
||||
After configuring these parameters, click the **Next** button to continue to the Sync Options step.
|
||||
|
||||
<Note>
|
||||
If the **path** you provide does not exist in Vault, it will be created.
|
||||
</Note>
|
||||
</Step>
|
||||
<Step title="Configure Sync Options">
|
||||
Configure the **Sync Options** to specify how secrets should be synced, then click **Next**.
|
||||
|
||||

|
||||
|
||||
- **Initial Sync Behavior**: Determines how Infisical should resolve the initial sync.
|
||||
- **Overwrite Destination Secrets**: Removes any secrets at the destination endpoint not present in Infisical.
|
||||
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over Hashicorp Vault when keys conflict.
|
||||
- **Import Secrets (Prioritize Hashicorp Vault)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Hashicorp Vault over Infisical when keys conflict.
|
||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||
</Step>
|
||||
<Step title="Configure Details">
|
||||
Configure the **Details** of your Hashicorp Vault Sync, then click **Next**.
|
||||
|
||||

|
||||
|
||||
- **Name**: The name of your sync. Must be slug-friendly.
|
||||
- **Description**: An optional description for your sync.
|
||||
</Step>
|
||||
<Step title="Review Configuration">
|
||||
Review your Hashicorp Vault Sync configuration, then click **Create Sync**.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Sync Created">
|
||||
If enabled, your Hashicorp Vault Sync will begin syncing your secrets to the destination endpoint.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create an **Hashicorp Vault Sync**, make an API request to the [Create Hashicorp Vault Sync](/api-reference/endpoints/secret-syncs/hashicorp-vault/create) API endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/secret-syncs/hashicorp-vault \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-vault-sync",
|
||||
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"description": "an example sync",
|
||||
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"environment": "dev",
|
||||
"secretPath": "/",
|
||||
"isEnabled": true,
|
||||
"syncOptions": {
|
||||
"initialSyncBehavior": "overwrite-destination"
|
||||
},
|
||||
"destinationConfig": {
|
||||
"mount": "secret",
|
||||
"path": "dev/nested"
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"secretSync": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"name": "my-vault-sync",
|
||||
"description": "an example sync",
|
||||
"isEnabled": true,
|
||||
"version": 1,
|
||||
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"createdAt": "2023-11-07T05:31:56Z",
|
||||
"updatedAt": "2023-11-07T05:31:56Z",
|
||||
"syncStatus": "succeeded",
|
||||
"lastSyncJobId": "123",
|
||||
"lastSyncMessage": null,
|
||||
"lastSyncedAt": "2023-11-07T05:31:56Z",
|
||||
"importStatus": null,
|
||||
"lastImportJobId": null,
|
||||
"lastImportMessage": null,
|
||||
"lastImportedAt": null,
|
||||
"removeStatus": null,
|
||||
"lastRemoveJobId": null,
|
||||
"lastRemoveMessage": null,
|
||||
"lastRemovedAt": null,
|
||||
"syncOptions": {
|
||||
"initialSyncBehavior": "overwrite-destination"
|
||||
},
|
||||
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"connection": {
|
||||
"app": "hashicorp-vault",
|
||||
"name": "my-vault-connection",
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||
},
|
||||
"environment": {
|
||||
"slug": "dev",
|
||||
"name": "Development",
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||
},
|
||||
"folder": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"path": "/"
|
||||
},
|
||||
"destination": "hashicorp-vault",
|
||||
"destinationConfig": {
|
||||
"mount": "secret",
|
||||
"path": "dev/nested"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
60
docs/internals/bug-bounty.mdx
Normal file
@@ -0,0 +1,60 @@
|
||||
---
|
||||
title: "Bug bounty program"
|
||||
description: " Learn about our bug bounty program and how to report vulnerabilities."
|
||||
---
|
||||
|
||||
The Infisical Bug Bounty Program is our way of recognizing and rewarding the work of security researchers who help keep our platform secure. By reporting vulnerabilities or potential risks, you help us protect secrets, infrastructure, and the organizations who rely on us.
|
||||
|
||||
We value reports that help identify vulnerabilities that affect the integrity of secrets, prevent unauthorized access to environments, or expose flaws in our authentication or authorization flows.
|
||||
|
||||
### How to Report
|
||||
|
||||
- Send reports to **security@infisical.com** with clear steps to reproduce, impact, and (if possible) a proof-of-concept.
|
||||
- We will acknowledge receipt within 3 business days.
|
||||
- We'll provide an initial assessment or next steps within 5 business days.
|
||||
|
||||
### What's in Scope?
|
||||
|
||||
- Vulnerabilities in our cloud-hosted platform (e.g., `app.infisical.com`, `eu.infisical.com`)
|
||||
- Security issues in the open source Infisical codebase, as maintained in our official GitHub repository
|
||||
- Authentication bypass, privilege escalation, or access to secrets/data without authorization
|
||||
|
||||
### Reward Guidelines
|
||||
|
||||
Bounties are based on severity, impact, and exploitability, as well as whether the report introduces a new vulnerability class or helps improve an existing fix.
|
||||
|
||||
| Severity | Examples | Typical Reward (USD currency) |
|
||||
| --- | --- | --- |
|
||||
| **Critical** | Full unauthorized access to secrets, authentication bypass, cross-tenant access, RCE, full compromise, etc | $2,000 - $5,000 |
|
||||
| **High** | Privilege escalation, project-level access without authorization, persistent DoS | $750 - $2,000 |
|
||||
| **Medium** | Info disclosure, scoped DoS (e.g. ReDoS with auth), or minor access control issues | $250 - $1,000 |
|
||||
| **Low / Informational** | Missing headers, CSP warnings, theoretical flaws, self-hosting misconfigurations | Recognition only |
|
||||
|
||||
|
||||
We may award lower amounts for:
|
||||
- Duplicate class vulnerabilities already under review
|
||||
- Patch bypasses of previously rewarded issues
|
||||
- Vulnerabilities requiring unrealistic attacker conditions
|
||||
|
||||
All final reward amounts are determined at Infisical's discretion based on impact, report quality, and how actionable the issue is.
|
||||
|
||||
|
||||
### Out of Scope
|
||||
|
||||
- Social engineering or phishing
|
||||
- Rate limiting issues on non-sensitive endpoints
|
||||
- Denial-of-service attacks that require authentication and don't impact core service availability
|
||||
- Findings based on outdated or forked code not maintained by the Infisical team
|
||||
- Vulnerabilities in third-party dependencies unless they result in a direct risk to Infisical users
|
||||
|
||||
|
||||
### Responsible Disclosure
|
||||
|
||||
We ask that researchers:
|
||||
|
||||
- Avoid accessing data that isn't yours
|
||||
- Do not publicly disclose without coordination
|
||||
- Use testing accounts where possible
|
||||
- Give us a reasonable window to investigate and patch before going public
|
||||
|
||||
Researchers can also spin up our [self-hosted version of Infisical](/self-hosting/overview) to test for vulnerabilities locally.
|
||||
@@ -118,8 +118,6 @@ It should be noted that, even on Infisical Cloud, it is physically impossible fo
|
||||
|
||||
Please email security@infisical.com if you have any specific inquiries about employee data and security policies.
|
||||
|
||||
## Get in touch
|
||||
|
||||
If you have any concerns about Infisical or believe you have uncovered a vulnerability, please get in touch via the e-mail address security@infisical.com. In the message, try to provide a description of the issue and ideally a way of reproducing it. The security team will get back to you as soon as possible.
|
||||
|
||||
Note that this security address should be used for undisclosed vulnerabilities. Please report any security problems to us before disclosing it publicly.
|
||||
## Bug Bounty Program
|
||||
We run a [Bug Bounty Program](/internals/bug-bounty) to recognize and reward security researchers who help make Infisical more secure.
|
||||
If you've found a vulnerability, please review the program details for scope, disclosure guidelines, and reward tiers.
|
||||
@@ -228,7 +228,8 @@
|
||||
{
|
||||
"group": "Workflow Integrations",
|
||||
"pages": [
|
||||
"documentation/platform/workflow-integrations/slack-integration"
|
||||
"documentation/platform/workflow-integrations/slack-integration",
|
||||
"documentation/platform/workflow-integrations/microsoft-teams-integration"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -443,6 +444,7 @@
|
||||
"integrations/app-connections/databricks",
|
||||
"integrations/app-connections/gcp",
|
||||
"integrations/app-connections/github",
|
||||
"integrations/app-connections/hashicorp-vault",
|
||||
"integrations/app-connections/humanitec",
|
||||
"integrations/app-connections/ldap",
|
||||
"integrations/app-connections/mssql",
|
||||
@@ -470,6 +472,7 @@
|
||||
"integrations/secret-syncs/databricks",
|
||||
"integrations/secret-syncs/gcp-secret-manager",
|
||||
"integrations/secret-syncs/github",
|
||||
"integrations/secret-syncs/hashicorp-vault",
|
||||
"integrations/secret-syncs/humanitec",
|
||||
"integrations/secret-syncs/teamcity",
|
||||
"integrations/secret-syncs/terraform-cloud",
|
||||
@@ -1073,6 +1076,18 @@
|
||||
"api-reference/endpoints/app-connections/github/delete"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Hashicorp Vault",
|
||||
"pages": [
|
||||
"api-reference/endpoints/app-connections/hashicorp-vault/list",
|
||||
"api-reference/endpoints/app-connections/hashicorp-vault/available",
|
||||
"api-reference/endpoints/app-connections/hashicorp-vault/get-by-id",
|
||||
"api-reference/endpoints/app-connections/hashicorp-vault/get-by-name",
|
||||
"api-reference/endpoints/app-connections/hashicorp-vault/create",
|
||||
"api-reference/endpoints/app-connections/hashicorp-vault/update",
|
||||
"api-reference/endpoints/app-connections/hashicorp-vault/delete"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Humanitec",
|
||||
"pages": [
|
||||
@@ -1285,6 +1300,20 @@
|
||||
"api-reference/endpoints/secret-syncs/github/remove-secrets"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Hashicorp Vault",
|
||||
"pages": [
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/list",
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/get-by-id",
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/get-by-name",
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/create",
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/update",
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/delete",
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/sync-secrets",
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/import-secrets",
|
||||
"api-reference/endpoints/secret-syncs/hashicorp-vault/remove-secrets"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Humanitec",
|
||||
"pages": [
|
||||
@@ -1554,6 +1583,7 @@
|
||||
},
|
||||
"internals/components",
|
||||
"internals/security",
|
||||
"internals/bug-bounty",
|
||||
"internals/service-tokens"
|
||||
]
|
||||
},
|
||||
|
||||
@@ -0,0 +1,100 @@
|
||||
### Create Microsoft Teams workflow integration
|
||||
<Steps>
|
||||
<Step title="Install the Infisical Microsoft Teams App in Microsoft Teams tenant">
|
||||
|
||||
Currently, Infisical requires you to install a custom Microsoft Teams app into your Microsoft Teams tenant.
|
||||
|
||||
You can download the Infisical Microsoft Teams app package here:
|
||||
- [Infisical Microsoft Teams app package](https://infisical-microsoft-teams-app.s3.us-east-1.amazonaws.com/Infisical.zip)
|
||||
|
||||
<Note>
|
||||
**Important for self-hosted users:**
|
||||
|
||||
If you're self-hosting Infisical, you can skip the download step. Instead you should use the app package file you downloaded from the Microsoft Teams Developer Portal when you followed the Self-hosted guide.
|
||||
</Note>
|
||||
|
||||
Once you've downloaded the app package, you can install the app in your Microsoft Teams tenant by navigating to the **Apps** > **Upload a custom app** page, and selecting the "Upload an app" button.
|
||||
|
||||

|
||||

|
||||
|
||||
Once the app has been submitted, your Microsoft Teams tenant admin will need to approve the app in the [Microsoft Teams Admin Center](https://admin.teams.microsoft.com/policies/manage-apps).
|
||||
|
||||
<Warning>
|
||||
After the app has been approved, it can take a few hours _(up to 24 hours in some cases)_ for Microsoft Teams to reflect the new app. During this period, the Infisical app will not be visible in Microsoft Teams, and won't be usable.
|
||||
</Warning>
|
||||
|
||||
Once the app has been approved, you will be able to use the Infisical Microsoft Teams integration in your projects.
|
||||
</Step>
|
||||
|
||||
<Step title="Add the Infisical Microsoft Teams app to your Microsoft Teams teams">
|
||||
Once the app has been approved and installed in your Microsoft Teams tenant, you can add the app to your Microsoft Teams teams.
|
||||
|
||||

|
||||
|
||||
Navigate to **Apps** > **Built for your org**, select the "Infisical" app, and press the "Add" button to select the teams and channels you wish to add the app to.
|
||||
|
||||
<Info>
|
||||
This can also be done later through the [Microsoft Teams Admin Center](https://admin.teams.microsoft.com/policies/manage-apps), or through the Microsoft Teams client itself by navigating to the individual team's app settings.
|
||||
</Info>
|
||||
|
||||
Once the app has been added to the team, you will be able to use the Infisical Microsoft Teams integration in the team.
|
||||
</Step>
|
||||
|
||||
<Step title="Navigate to the Workflow Integrations tab in your organization settings">
|
||||
|
||||
After installing the Microsoft Teams app, you are now ready to configure the Microsoft Teams integration within Infisical.
|
||||
|
||||
Navigate to the **Workflow Integrations** tab in your organization settings, and press the "Add" button.
|
||||
|
||||

|
||||
</Step>
|
||||
|
||||
<Step title="Create a Microsoft Teams workflow integration">
|
||||
In order to use the Infisical Microsoft Teams integration, you will need to grant admin consent to the app. Once the consent is granted, the Microsoft Teams workflow integration will be created in your Infisical organization.
|
||||
|
||||
Press the "Add" button and select the "Microsoft Teams" platform option.
|
||||

|
||||
|
||||
Select the Microsoft Teams integration you wish to configure, and press the "Configure" button.
|
||||
|
||||
Here you will be prompted to enter an alias, tenant ID, and an optional description for your workflow integration.
|
||||
The tenant ID is the ID of the Microsoft 365 / Azure AD tenant that you installed the Infisical Microsoft Teams app in, in the previous steps.
|
||||
|
||||

|
||||
|
||||
Press the "Create Microsoft Teams Integration" button, and you'll be navigated to the Azure AD consent page.
|
||||
|
||||

|
||||
|
||||
<Note>
|
||||
Please note that you must be a privileged administrator user of your Microsoft 365 / Azure AD tenant in order to grant admin consent to the app.
|
||||
</Note>
|
||||
|
||||
Once you've granted admin consent, you'll be navigated back to the Infisical organization settings, where you can now select the Microsoft Teams integration you just created.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
### Configure project to use Microsoft Teams workflow integration
|
||||
|
||||
<Steps>
|
||||
<Step title="Navigate to the Workflow Integrations tab in the project settings">
|
||||
|
||||
To add a new Microsoft Teams workflow integration, navigate to **Project Settings** > **Workflow Integrations** and press the "Add".
|
||||

|
||||
|
||||
Select the "Microsoft Teams" option from the list of available workflow integrations.
|
||||
|
||||
</Step>
|
||||
<Step title="Configure the Microsoft Teams workflow integration">
|
||||
Your project will send notifications to the connected Microsoft Teams team of the
|
||||
selected Microsoft Teams integration when the configured events are triggered.
|
||||
|
||||
|
||||
Press the "Save" button to save your Microsoft Teams workflow integration.
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
Once you've created the project Microsoft Teams workflow integration, you will now receive Access Requests and Secret Approval Requests notifications in Microsoft Teams according to your configuration.
|
||||