mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 12:29:26 +00:00
few more feedback changes
This commit is contained in:
@@ -65,11 +65,11 @@ resource "aws_security_group" "infisical_relay_sg" {
|
|||||||
cidr_blocks = ["0.0.0.0/0"] # Restrict this to your IP in production
|
cidr_blocks = ["0.0.0.0/0"] # Restrict this to your IP in production
|
||||||
}
|
}
|
||||||
|
|
||||||
# Outbound: Allows the Relay server to make necessary outbound connections.
|
# Outbound: Allows the Relay server to make necessary outbound connections to the Infisical platform.
|
||||||
egress {
|
egress {
|
||||||
from_port = 0
|
from_port = 0
|
||||||
to_port = 0
|
to_port = 0
|
||||||
protocol = "-1"
|
protocol = "tcp"
|
||||||
cidr_blocks = ["0.0.0.0/0"]
|
cidr_blocks = ["0.0.0.0/0"]
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -106,10 +106,11 @@ module "infisical_relay_instance" {
|
|||||||
apt-get update && apt-get install -y infisical
|
apt-get update && apt-get install -y infisical
|
||||||
|
|
||||||
# Install the relay as a systemd service.
|
# Install the relay as a systemd service.
|
||||||
# This example uses a Machine Identity token for authentication (--token).
|
# This example uses a Machine Identity token for authentication via the INFISICAL_TOKEN environment variable.
|
||||||
# For other authentication methods, see https://infisical.com/docs/cli/commands/relay#available-authentication-methods
|
#
|
||||||
|
# Note: For production environments, you might consider fetching the token from AWS Parameter Store or AWS Secrets Manager.
|
||||||
|
export INFISICAL_TOKEN="your-machine-identity-token"
|
||||||
sudo infisical relay systemd install \
|
sudo infisical relay systemd install \
|
||||||
--token "your-machine-identity-token" \
|
|
||||||
--name "my-relay-example" \
|
--name "my-relay-example" \
|
||||||
--domain "https://app.infisical.com" \
|
--domain "https://app.infisical.com" \
|
||||||
--host "${aws_eip.infisical_relay_eip.public_ip}"
|
--host "${aws_eip.infisical_relay_eip.public_ip}"
|
||||||
@@ -138,7 +139,7 @@ The provided security group rules are open to the internet (`0.0.0.0/0`) for sim
|
|||||||
- `region` in the `provider` block.
|
- `region` in the `provider` block.
|
||||||
- `vpc_id` in the `aws_security_group` resource.
|
- `vpc_id` in the `aws_security_group` resource.
|
||||||
- `ami` and `subnet_id` in the `infisical_relay_instance` module.
|
- `ami` and `subnet_id` in the `infisical_relay_instance` module.
|
||||||
- The authentication flag and value in the `user_data` script (e.g., `--token "your-machine-identity-token"`).
|
- The `INFISICAL_TOKEN` environment variable in the `user_data` script (e.g., `export INFISICAL_TOKEN="your-machine-identity-token"`).
|
||||||
- The `--domain` in the `user_data` script if you are self-hosting Infisical.
|
- The `--domain` in the `user_data` script if you are self-hosting Infisical.
|
||||||
3. **Apply the configuration:** Run the following Terraform commands in your terminal:
|
3. **Apply the configuration:** Run the following Terraform commands in your terminal:
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
Reference in New Issue
Block a user