doc: added docs

This commit is contained in:
Sheen
2025-03-18 14:43:19 +00:00
parent ed6306747a
commit 1ec11d5963
3 changed files with 307 additions and 1 deletions

View File

@@ -0,0 +1,134 @@
---
title: "infisical bootstrap"
description: "Automate the initial setup of a new Infisical instance for headless deployment and infrastructure-as-code workflows"
---
```bash
infisical bootstrap --domain=<domain> --email=<email> --password=<password> --organization=<organization>
```
## Description
The `infisical bootstrap` command is used when deploying Infisical in automated environments where manual UI setup is not feasible. It's ideal for:
- Containerized deployments in Kubernetes or Docker environments
- Infrastructure-as-code pipelines with Terraform or similar tools
- Continuous deployment workflows
- DevOps automation scenarios
The command initializes a fresh Infisical instance by creating an admin user, organization, and instance admin machine identity, enabling subsequent programmatic configuration without human intervention.
**Security Warning**: This command creates an instance admin machine identity with the highest level of privileges. The returned token should be treated with the utmost security, similar to a root credential. Unauthorized access to this token could compromise your entire Infisical instance.
## Flags
<Accordion title="--domain" defaultOpen="true">
The URL of your Infisical instance.
```bash
# Example
infisical bootstrap --domain=https://your-infisical-instance.com
```
This flag is required.
</Accordion>
<Accordion title="--email">
Email address for the admin user account that will be created.
```bash
# Example
infisical bootstrap --email=admin@example.com
```
This flag is required.
</Accordion>
<Accordion title="--password">
Password for the admin user account.
```bash
# Example
infisical bootstrap --password=your-secure-password
```
This flag is required.
</Accordion>
<Accordion title="--organization">
Name of the organization that will be created within the instance.
```bash
# Example
infisical bootstrap --organization=your-org-name
```
This flag is required.
</Accordion>
## Response
The command returns a JSON response with details about the created user, organization, and machine identity:
```json
{
"message": "Successfully initialized instance",
"user": {
"id": "911d6d11-2bf8-4f1b-861d-6a0ec43e7e1a",
"email": "admin@example.com",
"authMethods": [
"email"
],
"superAdmin": true,
"firstName": "Admin",
"lastName": "User",
"isAccepted": true,
"isMfaEnabled": false,
// Additional user properties...
},
"organization": {
"id": "65a54d51-cac9-418a-ae17-20bfc715c6df",
"name": "your-org-name",
"slug": "your-org-name-xxxx",
"createdAt": "2025-03-17T11:11:41.564Z",
"updatedAt": "2025-03-17T11:11:41.564Z",
// Additional organization properties...
},
"identity": {
"id": "4fa39767-39ce-440f-bb00-f6aae64b3dd5",
"name": "Admin Identity",
"authMethod": null,
"createdAt": "2025-03-17T11:11:41.569Z",
"updatedAt": "2025-03-17T11:11:41.569Z",
"credentials": {
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
}
}
```
## Usage with Automation
For automation purposes, you can extract just the machine identity token from the response:
```bash
infisical bootstrap --domain=https://your-infisical-instance.com --email=admin@example.com --password=your-secure-password --organization=your-org-name | jq ".identity.credentials.token"
```
This extracts only the token, which can be captured in a variable or piped to other commands.
## Example: Capture Token in a Variable
```bash
TOKEN=$(infisical bootstrap --domain=https://your-infisical-instance.com --email=admin@example.com --password=your-secure-password --organization=your-org-name | jq -r ".identity.credentials.token")
# Now use the token for further automation
echo "Token has been captured and can be used for authentication"
```
## Notes
- The bootstrap process can only be performed once on a fresh Infisical instance
- All flags are required for the bootstrap process to complete successfully
- Security controls prevent privilege escalation: instance admin identities cannot be managed by non-instance admin users and identities
- The generated admin user account can be used to log in via the UI if needed