mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 16:28:19 +00:00
improvements: add ssl options to sql connections and update ui/docs
This commit is contained in:
@@ -11,19 +11,19 @@ description: "Learn how to automatically rotate Microsoft SQL Server credentials
|
||||
An example creation statement might look like:
|
||||
```SQL
|
||||
-- create server-level logins
|
||||
CREATE LOGIN infisical_user_1 WITH PASSWORD = 'my-password';
|
||||
CREATE LOGIN infisical_user_2 WITH PASSWORD = 'my-password';
|
||||
CREATE LOGIN [infisical_user_1] WITH PASSWORD = 'my-password';
|
||||
CREATE LOGIN [infisical_user_2] WITH PASSWORD = 'my-password';
|
||||
GRANT CONNECT SQL TO [infisical_user_1];
|
||||
GRANT CONNECT SQL TO [infisical_user_2];
|
||||
|
||||
-- create database-level users with login from above
|
||||
USE my_database;
|
||||
CREATE USER infisical_user_1 FOR LOGIN infisical_user_1;
|
||||
CREATE USER infisical_user_2 FOR LOGIN infisical_user_2;
|
||||
GRANT CONNECT TO infisical_user_1;
|
||||
GRANT CONNECT TO infisical_user_2;
|
||||
CREATE USER [infisical_user_1] FOR LOGIN [infisical_user_1];
|
||||
CREATE USER [infisical_user_2] FOR LOGIN [infisical_user_2];
|
||||
|
||||
-- grant relevant permissions
|
||||
GRANT SELECT, INSERT, UPDATE, DELETE ON SCHEMA::dbo TO infisical_user_1;
|
||||
GRANT SELECT, INSERT, UPDATE, DELETE ON SCHEMA::dbo TO infisical_user_2;
|
||||
GRANT SELECT, INSERT, UPDATE, DELETE ON SCHEMA::dbo TO [infisical_user_1];
|
||||
GRANT SELECT, INSERT, UPDATE, DELETE ON SCHEMA::dbo TO [infisical_user_2];
|
||||
```
|
||||
|
||||
<Tip>
|
||||
|
||||
@@ -10,14 +10,16 @@ description: "Learn how to automatically rotate PostgreSQL credentials."
|
||||
|
||||
An example creation statement might look like:
|
||||
```SQL
|
||||
-- first user
|
||||
-- create user roles
|
||||
CREATE USER infisical_user_1 WITH ENCRYPTED PASSWORD 'temporary_password';
|
||||
GRANT CONNECT ON DATABASE my_database TO infisical_user_1;
|
||||
GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO infisical_user_1;
|
||||
|
||||
-- second user
|
||||
CREATE USER infisical_user_2 WITH ENCRYPTED PASSWORD 'temporary_password';
|
||||
|
||||
-- grant database connection permissions
|
||||
GRANT CONNECT ON DATABASE my_database TO infisical_user_1;
|
||||
GRANT CONNECT ON DATABASE my_database TO infisical_user_2;
|
||||
|
||||
-- grant relevant table permissions
|
||||
GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO infisical_user_1;
|
||||
GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO infisical_user_2;
|
||||
```
|
||||
|
||||
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 792 KiB After Width: | Height: | Size: 826 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 790 KiB After Width: | Height: | Size: 825 KiB |
@@ -11,16 +11,20 @@ Infisical supports connecting to Microsoft SQL Server using database principals.
|
||||
<Step title="Create a Principal">
|
||||
Infisical recommends creating a designated server login and database user in your Microsoft SQL Server database for your connection.
|
||||
```SQL
|
||||
-- create server-level login
|
||||
CREATE LOGIN infisical_login WITH PASSWORD = 'my-password';
|
||||
-- Create login at the server level
|
||||
CREATE LOGIN [infisical_app] WITH PASSWORD = 'my-password';
|
||||
|
||||
-- create database-level user with login from above
|
||||
-- Grant server-level connect permission
|
||||
GRANT CONNECT SQL TO [infisical_app];
|
||||
|
||||
-- Switch to the specific database where you want to create the user
|
||||
USE my_database;
|
||||
CREATE USER infisical_user FOR LOGIN infisical_login;
|
||||
GRANT CONNECT TO infisical_user;
|
||||
|
||||
-- Create the database user mapped to the login
|
||||
CREATE USER [infisical_app] FOR LOGIN [infisical_app];
|
||||
|
||||
-- If you intend to use Platform Managed Credentials (see below)
|
||||
GRANT ALTER ANY LOGIN TO infisical_login;
|
||||
GRANT ALTER ANY LOGIN TO [infisical_app];
|
||||
```
|
||||
</Step>
|
||||
<Step title="Grant Relevant Permissions">
|
||||
@@ -95,6 +99,8 @@ Infisical supports connecting to Microsoft SQL Server using database principals.
|
||||
"database": "default",
|
||||
"username": "infisical_login",
|
||||
"password": "my-password",
|
||||
"sslEnabled": true,
|
||||
"sslRejectUnauthorized": true
|
||||
},
|
||||
}'
|
||||
```
|
||||
@@ -117,7 +123,9 @@ Infisical supports connecting to Microsoft SQL Server using database principals.
|
||||
"host": "123.4.5.6",
|
||||
"port": 1433,
|
||||
"database": "default",
|
||||
"username": "infisical_login"
|
||||
"username": "infisical_login",
|
||||
"sslEnabled": true,
|
||||
"sslRejectUnauthorized": true
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -12,7 +12,7 @@ Infisical supports connecting to PostgreSQL using a database role.
|
||||
Infisical recommends creating a designated role in your PostgreSQL database for your connection.
|
||||
```SQL
|
||||
-- create user role
|
||||
CREATE ROLE infisical_role WITH LOGIN PASSWORD 'my-password'
|
||||
CREATE ROLE infisical_role WITH LOGIN PASSWORD 'my-password';
|
||||
|
||||
-- grant login access to the specified database
|
||||
GRANT CONNECT ON DATABASE my_database TO infisical_role;
|
||||
@@ -27,6 +27,7 @@ Infisical supports connecting to PostgreSQL using a database role.
|
||||
<Tab title="Secret Rotation">
|
||||
For Secret Rotations, your Infisical user will require the ability to alter other users' passwords:
|
||||
```SQL
|
||||
-- enable permissions to alter login credentials
|
||||
ALTER ROLE infisical_role WITH CREATEROLE;
|
||||
```
|
||||
</Tab>
|
||||
@@ -88,6 +89,8 @@ Infisical supports connecting to PostgreSQL using a database role.
|
||||
"database": "default",
|
||||
"username": "infisical_role",
|
||||
"password": "my-password",
|
||||
"sslEnabled": true,
|
||||
"sslRejectUnauthorized": true
|
||||
},
|
||||
}'
|
||||
```
|
||||
@@ -110,7 +113,9 @@ Infisical supports connecting to PostgreSQL using a database role.
|
||||
"host": "123.4.5.6",
|
||||
"port": 5432,
|
||||
"database": "default",
|
||||
"username": "infisical_role"
|
||||
"username": "infisical_role",
|
||||
"sslEnabled": true,
|
||||
"sslRejectUnauthorized": true
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -439,19 +439,6 @@ When set, all visits to the Infisical login page will automatically redirect use
|
||||
information.
|
||||
</Accordion>
|
||||
|
||||
## External Database Connections
|
||||
|
||||
<ParamField query="DB_SSL_REJECT_UNAUTHORIZED" type="boolean" default="true" optional>
|
||||
Specify whether external database connections should reject unauthorized SSL certificates.
|
||||
We highly recommend keeping this value set to `true` for production use-cases.
|
||||
</ParamField>
|
||||
|
||||
<ParamField query="DB_SSL_REQUIRED" type="boolean" default="true" optional>
|
||||
Specify whether external database connections should require SSL.
|
||||
We highly recommend keeping this value set to `true` for production use-cases.
|
||||
</ParamField>
|
||||
|
||||
|
||||
## App Connections
|
||||
|
||||
You can configure third-party app connections for re-use across Infisical Projects.
|
||||
|
||||
Reference in New Issue
Block a user