Address PR comments

This commit is contained in:
Carlos Monastyrski
2025-09-19 03:43:22 -03:00
parent 8130be5e2f
commit 27dbe5b013
72 changed files with 2913 additions and 1367 deletions

View File

@@ -45,6 +45,7 @@ description: "Learn how to configure an Azure Key Vault Certificate Sync for Inf
- **Auto-Sync Enabled**: If enabled, certificates will automatically be synced from the source PKI subscriber when changes occur. Disable to enforce manual syncing only.
- **Enable Certificate Removal**: If enabled, Infisical will remove expired certificates from the destination during sync operations. Disable this option if you intend to manage certificate cleanup manually.
- **Certificate Name Schema** (Optional): Customize how certificate names are generated in Azure Key Vault. Use `{{certificateId}}` as a placeholder for the certificate ID. If not specified, defaults to `Infisical-{{certificateId}}`.
6. Configure the **Details** of your Azure Key Vault Certificate Sync, then click **Next**.
![Configure Details](/images/certificate-syncs/azure-key-vault/vault-details.png)
@@ -60,13 +61,13 @@ description: "Learn how to configure an Azure Key Vault Certificate Sync for Inf
</Tab>
<Tab title="API">
To create an **Azure Key Vault Certificate Sync**, make an API request to the [Create Azure Key Vault Certificate Sync](/api-reference/endpoints/certificate-syncs/azure-key-vault/create) API endpoint.
To create an **Azure Key Vault Certificate Sync**, make an API request to the [Create Azure Key Vault Certificate Sync](/api-reference/endpoints/pki/syncs/azure-key-vault/create) API endpoint.
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/pki-syncs \
--url https://app.infisical.com/api/v1/pki/syncs/azure-key-vault \
--header 'Content-Type: application/json' \
--data '{
"name": "my-key-vault-cert-sync",
@@ -77,7 +78,8 @@ description: "Learn how to configure an Azure Key Vault Certificate Sync for Inf
"destination": "azure-key-vault",
"isAutoSyncEnabled": true,
"syncOptions": {
"canRemoveCertificates": true
"canRemoveCertificates": true,
"certificateNameSchema": "myapp-{{certificateId}}"
},
"destinationConfig": {
"vaultBaseUrl": "https://my-key-vault.vault.azure.net"
@@ -99,7 +101,8 @@ description: "Learn how to configure an Azure Key Vault Certificate Sync for Inf
"vaultBaseUrl": "https://my-key-vault.vault.azure.net"
},
"syncOptions": {
"canRemoveCertificates": true
"canRemoveCertificates": true,
"certificateNameSchema": "myapp-{{certificateId}}"
},
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"subscriberId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
@@ -125,12 +128,17 @@ Your Azure Key Vault Certificate Sync will:
Azure Key Vault Certificate Syncs support both automatic and manual synchronization modes. When auto-sync is enabled, certificates are automatically deployed as they are issued or renewed.
</Note>
## Manual Certificate Import
## Manual Certificate Sync
You can manually import existing certificates from your PKI subscriber to Azure Key Vault using the import certificates functionality. This is useful for:
You can manually trigger certificate synchronization from your PKI subscriber to Azure Key Vault using the sync certificates functionality. This is useful for:
- Initial setup when you have existing certificates to migrate
- One-time imports of specific certificates
- Initial setup when you have existing certificates to deploy
- One-time sync of specific certificates
- Testing certificate sync configurations
- Force sync after making changes
To manually import certificates, use the [Import Certificates](/api-reference/endpoints/certificate-syncs/azure-key-vault/import) API endpoint or the manual import option in the Infisical UI.
To manually sync certificates, use the [Sync Certificates](/api-reference/endpoints/pki/syncs/azure-key-vault/sync-certificates) API endpoint or the manual sync option in the Infisical UI.
<Note>
Azure Key Vault does not support importing certificates back into Infisical due to security limitations where private keys cannot be extracted from Azure Key Vault.
</Note>

View File

@@ -75,13 +75,15 @@ via the UI or API for the third-party service you intend to sync certificates to
2. <strong>Create Certificate Sync:</strong> Configure a Certificate Sync in the desired project by specifying the following parameters via the UI or API:
- <strong>Source:</strong> The PKI subscriber you wish to retrieve certificates from.
- <strong>Destination:</strong> The App Connection to utilize and the destination endpoint to deploy certificates to. These can vary between services.
- <strong>Options:</strong> Customize how certificates should be synced, such as whether or not certificates should be removed from the destination when they expire.
- <strong>Options:</strong> Customize how certificates should be synced, including:
- Whether certificates should be removed from the destination when they expire
- Certificate naming schema to control how certificate names are generated in the destination
<Note>
Certificate Syncs are the source of truth for connected third-party services. Any certificate,
including associated data, not present or managed by Infisical before syncing will be
overwritten, and changes made directly in the connected service outside of Infisical may also
be overwritten by future syncs.
Certificate Syncs manage certificates that are prefixed with "Infisical-" in the destination. Only
certificates managed by Infisical will be affected during sync operations. Certificates not created or
managed by Infisical will remain untouched, and changes made to Infisical-managed certificates directly
in the destination service may be overwritten by future syncs.
</Note>
<Info>
@@ -95,6 +97,31 @@ via the UI or API for the third-party service you intend to sync certificates to
contact us at team@infisical.com to make a request.
</Note>
## Certificate Naming
Certificate Syncs support flexible certificate naming through configurable naming schemas. This allows you to customize how certificate names appear in your destination services.
### Default Naming
By default, certificates are named using the pattern `Infisical-{certificateId}` where `{certificateId}` is the unique identifier of the certificate with hyphens removed for compatibility with services like Azure Key Vault.
### Custom Naming Schema
You can customize certificate naming by providing a **Certificate Name Schema** when creating or updating a Certificate Sync. The schema supports the following placeholders:
- `{{certificateId}}` - The unique certificate identifier (required)
- `{{environment}}` - The environment context (always "global" for PKI syncs)
**Examples:**
- `myapp-{{certificateId}}` → `myapp-abc123def456`
- `{{environment}}-cert-{{certificateId}}` → `global-cert-abc123def456`
- `ssl/{{certificateId}}` → `ssl/abc123def456`
**Rules:**
- Must include exactly one `{{certificateId}}` placeholder
- Only alphanumeric characters, dashes (-), underscores (_), and slashes (/) are allowed
- Certificate names matching your schema will be managed by Infisical during sync operations
## Certificate Management
Certificate Syncs handle the full lifecycle of certificate management: