mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge branch 'Infisical:main' into I-36-use-pre-built-frontend-image
This commit is contained in:
33
.github/workflows/helm-chart-release.yaml
vendored
33
.github/workflows/helm-chart-release.yaml
vendored
@@ -1,33 +0,0 @@
|
|||||||
name: Release Charts
|
|
||||||
|
|
||||||
on: [workflow_dispatch]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
release:
|
|
||||||
# depending on default permission settings for your org (contents being read-only or read-write for workloads), you will have to add permissions
|
|
||||||
# see: https://docs.github.com/en/actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v2
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
|
|
||||||
- name: Configure Git
|
|
||||||
run: |
|
|
||||||
git config user.name "$GITHUB_ACTOR"
|
|
||||||
git config user.email "$GITHUB_ACTOR@users.noreply.github.com"
|
|
||||||
|
|
||||||
- name: Install Helm
|
|
||||||
uses: azure/setup-helm@v3
|
|
||||||
with:
|
|
||||||
version: v3.10.0
|
|
||||||
|
|
||||||
- name: Run chart-releaser
|
|
||||||
uses: helm/chart-releaser-action@v1.4.1
|
|
||||||
with:
|
|
||||||
charts_dir: helm-charts
|
|
||||||
env:
|
|
||||||
CR_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
|
|
||||||
22
.github/workflows/helm_chart_release.yml
vendored
Normal file
22
.github/workflows/helm_chart_release.yml
vendored
Normal file
@@ -0,0 +1,22 @@
|
|||||||
|
name: Release Helm Charts
|
||||||
|
|
||||||
|
on: [workflow_dispatch]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
release:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
- name: Install Helm
|
||||||
|
uses: azure/setup-helm@v3
|
||||||
|
with:
|
||||||
|
version: v3.10.0
|
||||||
|
- name: Install python
|
||||||
|
uses: actions/setup-python@v4
|
||||||
|
- name: Install Cloudsmith CLI
|
||||||
|
run: pip install --upgrade cloudsmith-cli
|
||||||
|
- name: Build and push helm package to Cloudsmith
|
||||||
|
run: cd helm-charts && sh upload-to-cloudsmith.sh
|
||||||
|
env:
|
||||||
|
CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }}
|
||||||
2
.github/workflows/release_build.yml
vendored
2
.github/workflows/release_build.yml
vendored
@@ -1,4 +1,4 @@
|
|||||||
name: goreleaser
|
name: Go releaser
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
|
|||||||
@@ -102,8 +102,11 @@
|
|||||||
"pages": [
|
"pages": [
|
||||||
"self-hosting/overview",
|
"self-hosting/overview",
|
||||||
{
|
{
|
||||||
"group": "Deployments",
|
"group": "Deployments options",
|
||||||
"pages": ["self-hosting/deployments/linux"]
|
"pages": [
|
||||||
|
"self-hosting/deployments/linux",
|
||||||
|
"self-hosting/deployments/kubernetes"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Configuration",
|
"group": "Configuration",
|
||||||
|
|||||||
54
docs/self-hosting/deployments/kubernetes.mdx
Normal file
54
docs/self-hosting/deployments/kubernetes.mdx
Normal file
@@ -0,0 +1,54 @@
|
|||||||
|
---
|
||||||
|
title: "Kubernetes"
|
||||||
|
description: "Deploy with Kubernetes"
|
||||||
|
---
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
Self-host vs. Infisical Cloud
|
||||||
|
|
||||||
|
Self-hosting Infisical means managing the service yourself, taking care of upgrades, scaling, security, etc.
|
||||||
|
|
||||||
|
If you're less technical and looking for a hands-free experience with minimal overhead then we recommend Infisical Cloud.
|
||||||
|
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Prerequisites**
|
||||||
|
- You have understanding of [Kubernetes](https://kubernetes.io/)
|
||||||
|
- You have understanding of [Helm package manager](https://helm.sh/)
|
||||||
|
- You have [kubectl](https://kubernetes.io/docs/reference/kubectl/kubectl/) installed and connected to your kubernetes cluster
|
||||||
|
|
||||||
|
|
||||||
|
#### 1. Fill our environment variables
|
||||||
|
|
||||||
|
Before you can deploy the Helm chart, you must fill out the required environment variables. To do so, please either download or copy the
|
||||||
|
contents of [this file](https://raw.githubusercontent.com/Infisical/infisical/main/helm-charts/infisical/values.yaml) to a `.yaml` file.
|
||||||
|
_Refer to the available [environment variables](../../self-hosting/configuration/envars)_
|
||||||
|
|
||||||
|
Once you have a local copy of the values file, fill our the required environment variables and save the file.
|
||||||
|
|
||||||
|
|
||||||
|
#### 2. Install Infisical Helm repository
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm repo add infisical-helm-charts 'https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/'
|
||||||
|
|
||||||
|
helm repo update
|
||||||
|
```
|
||||||
|
|
||||||
|
#### 3. Install the Helm chart
|
||||||
|
|
||||||
|
By default, the helm chart will be installed on your default namespace. If you wish to install the Chart on a different namespace, you may specify
|
||||||
|
that by adding the `--namespace <namespace-to-install-to>` to your `helm install` command.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
## Installs to default namespace
|
||||||
|
helm install infisical-helm-charts/infisical --values <path to the values.yaml you downloaded/created in step 2>
|
||||||
|
```
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
If you have not filled out all of the required environment variables, you will see an error message prompting you to
|
||||||
|
do so.
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
4. Your Infisical installation is complete and should be running on the host name you specified in Ingress in `values.yaml`.
|
||||||
|
Note: Please allow an additional time (2 minutes) for the frontend pods to be fully ready.
|
||||||
@@ -9,17 +9,22 @@ Self-hosting Infisical means managing the service yourself, taking care of upgra
|
|||||||
|
|
||||||
If you're less technical and looking for a hands-free experience with minimal overhead then we recommend Infisical Cloud.
|
If you're less technical and looking for a hands-free experience with minimal overhead then we recommend Infisical Cloud.
|
||||||
|
|
||||||
Infisical Cloud also comes with some extra features unavailabe in the self-hosted edition. You can find more information about Infisical Cloud's offering on the pricing page.
|
Infisical Cloud also comes with some extra features unavailable in the self-hosted edition. You can find more information about Infisical Cloud's offering on the pricing page.
|
||||||
|
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
## Deployment options
|
## Deployment options
|
||||||
|
|
||||||
Infisical can be deployed on a Linux VM with docker-compose. We're rolling out more specific deployment options for DigitalOcean, AWS, GCP, and Azure soon.
|
Infisical can be deployed on a Linux VM with docker-compose and Kubernetes. We're rolling out more specific deployment options for DigitalOcean, AWS, GCP, and Azure soon.
|
||||||
|
|
||||||
Options:
|
<CardGroup cols={2}>
|
||||||
|
<Card title="Any Linux" icon="square-1" color="#ea5a0c" href="/self-hosting/deployments/linux">
|
||||||
- [Linux VM](/self-hosting/deployments/linux)
|
Deploy to any Linux with Docker
|
||||||
|
</Card>
|
||||||
|
<Card title="Kubernetes" icon="square-2" color="#0285c7" href="/self-hosting/deployments/kubernetes">
|
||||||
|
Deploy to your Kubernetes cluster
|
||||||
|
</Card>
|
||||||
|
</CardGroup>
|
||||||
|
|
||||||
## Telemetry
|
## Telemetry
|
||||||
|
|
||||||
|
|||||||
@@ -1,22 +1,16 @@
|
|||||||
## Usage
|
### helm repository Setup
|
||||||
|
Assuming you have helm already installed, it is straight-forward to add a Cloudsmith-based chart repository:
|
||||||
[Helm](https://helm.sh) must be installed to use the charts. Please refer to
|
|
||||||
Helm's [documentation](https://helm.sh/docs) to get started.
|
|
||||||
|
|
||||||
Once Helm has been set up correctly, add the repo as follows:
|
|
||||||
|
|
||||||
```
|
```
|
||||||
helm repo add <alias> https://infisical.github.io/helm-charts
|
helm repo add infisical-helm-charts 'https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/'
|
||||||
|
|
||||||
|
helm repo update
|
||||||
```
|
```
|
||||||
|
|
||||||
If you had already added this repo earlier, run `helm repo update` to retrieve
|
### Installing a Helm Chart
|
||||||
the latest versions of the packages. You can then run `helm search repo
|
```
|
||||||
<alias>` to see the charts.
|
helm install infisical-helm-charts/<name-of-helm-chart>
|
||||||
|
```
|
||||||
|
|
||||||
To install the <chart-name> chart:
|
#### Available chart names
|
||||||
|
- infisical
|
||||||
helm install my-<chart-name> <alias>/<chart-name>
|
|
||||||
|
|
||||||
To uninstall the chart:
|
|
||||||
|
|
||||||
helm delete my-<chart-name>
|
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ metadata:
|
|||||||
name: {{ .Release.Name }}-backend-deployment
|
name: {{ .Release.Name }}-backend-deployment
|
||||||
labels:
|
labels:
|
||||||
app: backend
|
app: backend
|
||||||
namespace: {{ .Values.namespace }}
|
|
||||||
spec:
|
spec:
|
||||||
replicas: {{ .Values.backend.replicaCount }}
|
replicas: {{ .Values.backend.replicaCount }}
|
||||||
selector:
|
selector:
|
||||||
@@ -35,7 +34,6 @@ apiVersion: v1
|
|||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
name: infisical-backend-service
|
name: infisical-backend-service
|
||||||
namespace: {{ .Values.namespace }}
|
|
||||||
spec:
|
spec:
|
||||||
selector:
|
selector:
|
||||||
app: backend
|
app: backend
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ metadata:
|
|||||||
name: {{ .Release.Name }}-frontend-deployment
|
name: {{ .Release.Name }}-frontend-deployment
|
||||||
labels:
|
labels:
|
||||||
app: frontend
|
app: frontend
|
||||||
namespace: {{ .Values.namespace }}
|
|
||||||
spec:
|
spec:
|
||||||
replicas: {{ .Values.frontend.replicaCount }}
|
replicas: {{ .Values.frontend.replicaCount }}
|
||||||
selector:
|
selector:
|
||||||
@@ -26,7 +25,6 @@ apiVersion: v1
|
|||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
name: infisical-frontend-service
|
name: infisical-frontend-service
|
||||||
namespace: {{ .Values.namespace }}
|
|
||||||
spec:
|
spec:
|
||||||
selector:
|
selector:
|
||||||
app: frontend
|
app: frontend
|
||||||
|
|||||||
@@ -3,7 +3,6 @@ apiVersion: networking.k8s.io/v1
|
|||||||
kind: Ingress
|
kind: Ingress
|
||||||
metadata:
|
metadata:
|
||||||
name: infisical-ingress
|
name: infisical-ingress
|
||||||
namespace: {{ .Values.namespace }}
|
|
||||||
{{- with .Values.ingress.annotations }}
|
{{- with .Values.ingress.annotations }}
|
||||||
annotations:
|
annotations:
|
||||||
{{- toYaml . | nindent 4 }}
|
{{- toYaml . | nindent 4 }}
|
||||||
|
|||||||
@@ -2,7 +2,6 @@ apiVersion: apps/v1
|
|||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
name: mongodb-deployment
|
name: mongodb-deployment
|
||||||
namespace: {{ .Values.namespace }}
|
|
||||||
labels:
|
labels:
|
||||||
app: mongodb
|
app: mongodb
|
||||||
spec:
|
spec:
|
||||||
@@ -30,7 +29,6 @@ apiVersion: v1
|
|||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
name: mongodb-service
|
name: mongodb-service
|
||||||
namespace: {{ .Values.namespace }}
|
|
||||||
spec:
|
spec:
|
||||||
selector:
|
selector:
|
||||||
app: mongodb
|
app: mongodb
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: infisical
|
|
||||||
10
helm-charts/upload-to-cloudsmith.sh
Normal file
10
helm-charts/upload-to-cloudsmith.sh
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
## Loop through each helm chart directoy and build each into helm package
|
||||||
|
for d in */ ; do
|
||||||
|
helm package $d
|
||||||
|
done
|
||||||
|
|
||||||
|
## Upload each packaged helm chart
|
||||||
|
for i in *.tgz; do
|
||||||
|
[ -f "$i" ] || break
|
||||||
|
cloudsmith push helm --republish infisical/helm-charts $i
|
||||||
|
done
|
||||||
Reference in New Issue
Block a user