mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 06:26:16 +00:00
improve docs
This commit is contained in:
@@ -4,31 +4,46 @@ sidebarTitle: "Accounts"
|
||||
description: "Learn how to create and manage accounts in PAM to control access to resources like databases and servers."
|
||||
---
|
||||
|
||||
An account represents a specific set of credentials (e.g., a username and password) used to access a [resource](/documentation/platform/pam/getting-started/resources).
|
||||
An **Account** represents a specific identity or set of credentials (username/password) used to authenticate against a [Resource](/documentation/platform/pam/getting-started/resources).
|
||||
|
||||
## Relationship to Resources
|
||||
|
||||
Accounts are children of Resources. A single Resource can have multiple Accounts associated with it, each with different permission levels.
|
||||
|
||||
For example:
|
||||
- **Resource**: `Production Database` (PostgreSQL)
|
||||
- **Account 1**: `postgres` (Superuser)
|
||||
- **Account 2**: `app_user` (Read/Write)
|
||||
- **Account 3**: `analytics` (Read-only)
|
||||
|
||||
When a user requests access in PAM, they request access to a specific **Account** on a **Resource**.
|
||||
|
||||
## Creating an Account
|
||||
|
||||
<Info>
|
||||
Before you can create an account, you must first [Create a Resource](/documentation/platform/pam/getting-started/resources#creating-a-resource).
|
||||
**Prerequisite**: You must have at least one [Resource](/documentation/platform/pam/getting-started/resources) created before adding accounts.
|
||||
</Info>
|
||||
|
||||
To add an account, navigate to the **Accounts** tab in your PAM project and click **Add Account**.
|
||||
|
||||

|
||||
|
||||
Next, select the resource where you want to add the account.
|
||||
Next, select the **Resource** that this account belongs to.
|
||||
|
||||

|
||||
|
||||
After selecting a resource, provide the necessary credentials. The required fields vary depending on the resource type. For example, an SSH resource needs the username and password for a Unix user.
|
||||
After selecting a resource, provide the credentials (username, password, etc.) for this account. The required fields vary depending on the resource type. For example, for a Linux server, you would enter the username and the corresponding password or SSH key.
|
||||
|
||||

|
||||
|
||||
Clicking **Create Account** triggers a validation check to verify the credentials. If the validation fails, an error message is displayed to help you troubleshoot.
|
||||
Clicking **Create Account** will trigger a validation check. Infisical will attempt to connect to the resource using the provided credentials to verify they are valid.
|
||||
|
||||
## Automated Credential Rotation
|
||||
|
||||
Accounts for certain resources, such as PostgreSQL, support automated credential rotation.
|
||||
Accounts for certain resources, such as PostgreSQL, support automated credential rotation. This feature automatically changes the password for the account at a set interval.
|
||||
|
||||
**Requirements:**
|
||||
1. The parent Resource must have a [Rotation Account](/documentation/platform/pam/getting-started/resources#automated-credential-rotation) configured (a master account with permission to change other users' passwords).
|
||||
2. You must enable rotation in the Account settings.
|
||||
|
||||
You can enable rotation when creating or editing an account and set a desired interval (e.g., every 30 days). This option is only available if a [rotation account is configured](/documentation/platform/pam/getting-started/resources#automated-credential-rotation) on the resource.
|
||||

|
||||
|
||||
Reference in New Issue
Block a user