Update infisical-push-secret-crd.mdx

This commit is contained in:
Daniel Hougaard
2025-05-08 01:47:00 +04:00
parent 0610416677
commit 2f4efad8ae
@@ -241,7 +241,21 @@ After applying the InfisicalPushSecret CRD, you should notice that the secrets y
DATABASE_URL: postgres://127.0.0.1:5432 DATABASE_URL: postgres://127.0.0.1:5432
ENCRYPTION_KEY: fabcc12-a22-facbaa4-11aa568aab ENCRYPTION_KEY: fabcc12-a22-facbaa4-11aa568aab
``` ```
</Accordion>
<Accordion title="generators[]">
The `generators[]` field is used to define the generators you want to use for your InfisicalPushSecret CRD.
You can follow the guide for [using generators to push secrets](#using-generators-to-push-secrets) for more information.
Example:
```yaml
push:
generators:
- destinationSecretName: password-generator-test
generatorRef:
kind: Password
name: password-generator
```
</Accordion> </Accordion>
</Accordion> </Accordion>
@@ -475,8 +489,10 @@ For this reason you may want to disable automatic reconciliation of the Infisica
To use a generator, you must specify at least one generator in the `push.generators[]` field. An example of a generator usage can be seen here: To use a generator, you must specify at least one generator in the `push.generators[]` field. An example of a generator usage can be seen here:
<Accordion title="push.generators[]"> <Accordion title="push.generators[]">
Define a generator in the `push.generators[]` field. This field holds an array of the generators you want to use for your InfisicalPushSecret CRD.
</Accordion>
<Accordion title="push.generators[].destinationSecretName"> <Accordion title="push.generators[].destinationSecretName">
The name of the secret that will be created in Infisical. The name of the secret that will be created in Infisical.
@@ -489,8 +505,20 @@ To use a generator, you must specify at least one generator in the `push.generat
- `kind`: The kind of the generator resource, must match the generator kind. - `kind`: The kind of the generator resource, must match the generator kind.
- `name`: The name of the generator resource. - `name`: The name of the generator resource.
</Accordion> </Accordion>
<Accordion title="push.generators[].generatorRef.kind">
The kind of the generator resource, must match the generator kind.
Valid values:
- `Password`
- `UUID`
</Accordion> </Accordion>
<Accordion title="push.generators[].generatorRef.name">
The name of the generator resource.
</Accordion>
```yaml ```yaml
push: push:
secret: secret:
@@ -503,15 +531,20 @@ To use a generator, you must specify at least one generator in the `push.generat
name: custom-generator # Name of the generator resource name: custom-generator # Name of the generator resource
``` ```
<Tabs>
<Tab title="Password Generator"> ### Supported Generators
Below are the currently supported generators for the InfisicalPushSecret CRD. Each generator has its own spec that can be used to customize the generated secret.
<Accordion title="Password Generator">
### Password Generator
The Password generator is a custom resource that is installed on the cluster that defines the logic for generating a password. The Password generator is a custom resource that is installed on the cluster that defines the logic for generating a password.
<Accordion title="Spec definition">
- `kind`: The kind of the generator resource, must match the generator kind. For the Password generator, the kind is `Password`. - `kind`: The kind of the generator resource, must match the generator kind. For the Password generator, the kind is `Password`.
- `generator.passwordSpec`: The spec of the password generator. - `generator.passwordSpec`: The spec of the password generator.
<Accordion title="generator.kind">
The `generator.kind` field must match the kind of the generator resource. For the Password generator, the kind should always be set to `Password`.
</Accordion>
<Accordion title="generator.passwordSpec"> <Accordion title="generator.passwordSpec">
- `length`: The length of the password. - `length`: The length of the password.
- `digits`: The number of digits in the password. - `digits`: The number of digits in the password.
@@ -520,7 +553,6 @@ To use a generator, you must specify at least one generator in the `push.generat
- `noUpper`: Whether to include uppercase letters in the password. - `noUpper`: Whether to include uppercase letters in the password.
- `allowRepeat`: Whether to allow repeating characters in the password. - `allowRepeat`: Whether to allow repeating characters in the password.
</Accordion> </Accordion>
</Accordion>
```yaml password-cluster-generator.yaml ```yaml password-cluster-generator.yaml
apiVersion: secrets.infisical.com/v1alpha1 apiVersion: secrets.infisical.com/v1alpha1
@@ -548,12 +580,20 @@ To use a generator, you must specify at least one generator in the `push.generat
kind: Password kind: Password
name: password-generator name: password-generator
``` ```
</Tab> </Accordion>
<Tab title="UUID Generator"> <Accordion title="UUID Generator">
### UUID Generator
The UUID generator is a custom resource that is installed on the cluster that defines the logic for generating a UUID. The UUID generator is a custom resource that is installed on the cluster that defines the logic for generating a UUID.
<Accordion title="Spec definition">
- `kind`: The kind of the generator resource, must match the generator kind. For the UUID generator, the kind is `UUID`. - `kind`: The kind of the generator resource, must match the generator kind. For the UUID generator, the kind is `UUID`.
- `generator.uuidSpec`: The spec of the UUID generator. For UUID's, this can be left empty. - `generator.uuidSpec`: The spec of the UUID generator. For UUID's, this can be left empty.
<Accordion title="generator.kind">
The `generator.kind` field must match the kind of the generator resource. For the UUID generator, the kind should always be set to `UUID`.
</Accordion>
<Accordion title="generator.uuidSpec">
The spec of the UUID generator. For UUID's, this can be left empty.
</Accordion> </Accordion>
```yaml uuid-cluster-generator.yaml ```yaml uuid-cluster-generator.yaml
@@ -568,6 +608,7 @@ To use a generator, you must specify at least one generator in the `push.generat
``` ```
Example InfisicalPushSecret CRD using the UUID generator: Example InfisicalPushSecret CRD using the UUID generator:
```yaml infisical-push-secret-crd.yaml ```yaml infisical-push-secret-crd.yaml
push: push:
generators: generators:
@@ -576,8 +617,8 @@ To use a generator, you must specify at least one generator in the `push.generat
kind: UUID kind: UUID
name: uuid-generator name: uuid-generator
``` ```
</Tab> </Accordion>
</Tabs>