diff --git a/docs/documentation/platform/pki/pki-issuer.mdx b/docs/documentation/platform/pki/pki-issuer.mdx index c02e477c6..9f6d6595b 100644 --- a/docs/documentation/platform/pki/pki-issuer.mdx +++ b/docs/documentation/platform/pki/pki-issuer.mdx @@ -21,20 +21,21 @@ A typical workflow for using the Infisical PKI Issuer to issue certificates for 3. Installing `cert-manager` into your Kubernetes cluster. 4. Installing the Infisical PKI Issuer controller into your Kubernetes cluster. 5. Creating an `Issuer` or `ClusterIssuer` resource in your Kubernetes cluster to represent the Infisical PKI issuer you wish to use. -6. Creating a `Certificate` resource in your Kubernetes cluster to represent a certificate you wish to issue. As part of this step, you specify the Kubernetes `Secret` to create and store the issued certificate and private key. -7. Consuming the issued certificate across your Kubernetes resources from the specified Kubernetes `Secret`. +6. Create an the approver policy to accept certificate request. +7. Creating a `Certificate` resource in your Kubernetes cluster to represent a certificate you wish to issue. As part of this step, you specify the Kubernetes `Secret` to create and store the issued certificate and private key. +8. Consuming the issued certificate across your Kubernetes resources from the specified Kubernetes `Secret`. ## Guide -In the following steps, we explore how to install the Infisical PKI Issuer using [kubectl](https://github.com/kubernetes/kubectl) and use it to obtain certificates for your Kubernetes resources. +In the following steps, we explore how to install the Infisical PKI Issuer using [kubectl](https://github.com/kubernetes/kubectl) and use it to obtain certificates for your Kubernetes resources. - + Follow the instructions [here](/documentation/platform/identities/universal-auth) to configure a [machine identity](/documentation/platform/identities/machine-identities) in Infisical with Universal Auth. - + By the end of this step, you should have a **Client ID** and **Client Secret** on hand as part of the Universal Auth configuration for the Infisical PKI Issuer to authenticate with Infisical; this will be useful in steps 4 and 5. - + Currently, the Infisical PKI Issuer only supports authenticating with Infisical via the [Universal Auth](/documentation/platform/identities/universal-auth) authentication method. @@ -43,14 +44,14 @@ In the following steps, we explore how to install the Infisical PKI Issuer using Install `cert-manager` into your Kubernetes cluster by following the instructions [here](https://cert-manager.io/docs/installation/) or by running the following command: - + ```bash kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.15.3/cert-manager.yaml ``` Install the Infisical PKI Issuer controller into your Kubernetes cluster by running the following command: - + ```bash kubectl apply -f https://raw.githubusercontent.com/Infisical/infisical-issuer/main/build/install.yaml ``` @@ -76,7 +77,7 @@ In the following steps, we explore how to install the Infisical PKI Issuer using data: clientSecret: ``` - + ```bash kubectl apply -f secret-issuer.yaml ``` @@ -84,7 +85,7 @@ In the following steps, we explore how to install the Infisical PKI Issuer using - Next, create the Infisical PKI Issuer by filling out `url`, `clientId`, either `caId` or `certificateTemplateId`, and applying the following configuration file for the `Issuer` resource. + Next, create the Infisical PKI Issuer by filling out `url`, `clientId`, `projectId` or `certificateTemplateName`, and applying the following configuration file for the `Issuer` resource. This configuration file specifies the connection details to your Infisical PKI CA to be used for issuing certificates. ```yaml infisical-issuer.yaml @@ -95,8 +96,8 @@ In the following steps, we explore how to install the Infisical PKI Issuer using namespace: spec: url: "https://app.infisical.com" # the URL of your Infisical instance - caId: # the ID of the CA you want to use to issue certificates - certificateTemplateId: # the ID of the certificate template you want to use to issue certificates against + projectId: # the ID of the project you want to use to issue certificates + certificateTemplateName: # the name of the certificate template you want to use to issue certificates against authentication: universalAuth: clientId: # the Client ID from step 1 @@ -104,20 +105,11 @@ In the following steps, we explore how to install the Infisical PKI Issuer using name: "issuer-infisical-client-secret" key: "clientSecret" ``` - + ``` kubectl apply -f infisical-issuer.yaml ``` - - - The Infisical PKI Issuer supports issuing certificates against a specific CA or a specific certificate template. - - For this reason, you should only fill in the `caId` or the `certificateTemplateId` field but not both. - - We recommend using the `certificateTemplateId` field to issue certificates against a specific [certificate template](/documentation/platform/pki/certificate-templates) - since templates let you enforce constraints on issued certificates and may have alerting policies bound to them. - - + You can check that the issuer was created successfully by running the following command: ```bash @@ -128,16 +120,60 @@ In the following steps, we explore how to install the Infisical PKI Issuer using NAME AGE issuer-infisical 21h ``` - + An `Issuer` is a namespaced resource, and it is not possible to issue certificates from an `Issuer` in a different namespace. This means you will need to create an `Issuer` in each namespace you wish to obtain `Certificates` in. If you want to create a single `Issuer` that can be consumed in multiple namespaces, you should consider creating a `ClusterIssuer` resource. This is almost identical to the `Issuer` resource, however is non-namespaced so it can be used to issue `Certificates` across all namespaces. - + You can read more about the `Issuer` and `ClusterIssuer` resources [here](https://cert-manager.io/docs/configuration/). + + If you create a `CertificateRequest` now, you'll notice it's neither approved nor denied. This is expected because by default cert-manager approver controller requires an approver-policy. + + To enable approval, create the following YAML file and apply it: + + ```yaml infisical-approver-policy.yaml + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: infisical-issuer-approver + rules: + # Permission to approve or deny CertificateRequests for signers in cert-manager.io API group + - apiGroups: ['cert-manager.io'] + resources: ['signers'] + verbs: ['approve'] + resourceNames: + # Grant approval permissions for namespaced issuers + - "issuers.infisical-issuer.infisical.com/default.issuer-infisical" + # Grant approval permissions for cluster-scoped issuers + - "clusterissuers.infisical-issuer.infisical.com/clusterissuer-infisical" + --- + # Bind the cert-manager service account to the new role + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: infisical-issuer-approver-binding + subjects: + - kind: ServiceAccount + name: cert-manager + namespace: cert-manager + roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: infisical-issuer-approver + ``` + + ``` + kubectl apply -f infisical-approver-policy.yaml + ``` + + This configuration creates a `ClusterRole` named `infisical-issuer-approver` that grants approval permissions for specific Infisical issuer types. It then binds this role to the cert-manager service account, allowing it to approve certificate requests from your Infisical issuers. + + For information, check out [cert manager approval policy doc](https://cert-manager.io/docs/policy/approval/approver-policy/). + Finally, create a `Certificate` by applying the following configuration file. @@ -162,7 +198,7 @@ In the following steps, we explore how to install the Infisical PKI Issuer using duration: 48h # the ttl for the certificate renewBefore: 12h # the time before the certificate expiry that the certificate should be automatically renewed ``` - + The above sample configuration file specifies a certificate to be issued with the common name `certificate-by-issuer.example.com` and ECDSA private key using the P-256 curve, valid for 48 hours; the certificate will be automatically renewed by `cert-manager` 12 hours before expiry. The certificate is issued by the issuer `issuer-infisical` created in the previous step and the resulting certificate and private key will be stored in a secret named `certificate-by-issuer`. @@ -181,7 +217,7 @@ In the following steps, we explore how to install the Infisical PKI Issuer using Since the actual certificate and private key are stored in a Kubernetes secret, we can check that the secret was created successfully by running the following command: - + ```bash kubectl get secret certificate-by-issuer -n ``` @@ -190,9 +226,9 @@ In the following steps, we explore how to install the Infisical PKI Issuer using NAME TYPE DATA AGE certificate-by-issuer kubernetes.io/tls 2 26h ``` - + We can `describe` the secret to get more information about it: - + ```bash kubectl describe secret certificate-by-issuer -n default ``` @@ -201,14 +237,14 @@ In the following steps, we explore how to install the Infisical PKI Issuer using Name: certificate-by-issuer Namespace: default Labels: controller.cert-manager.io/fao=true - Annotations: cert-manager.io/alt-names: + Annotations: cert-manager.io/alt-names: cert-manager.io/certificate-name: certificate-by-issuer cert-manager.io/common-name: certificate-by-issuer.example.com - cert-manager.io/ip-sans: + cert-manager.io/ip-sans: cert-manager.io/issuer-group: infisical-issuer.infisical.com cert-manager.io/issuer-kind: Issuer cert-manager.io/issuer-name: issuer-infisical - cert-manager.io/uri-sans: + cert-manager.io/uri-sans: Type: kubernetes.io/tls @@ -218,17 +254,18 @@ In the following steps, we explore how to install the Infisical PKI Issuer using tls.crt: 2380 bytes tls.key: 227 bytes ``` - + Here, `ca.crt` is the Root CA certificate, `tls.crt` is the requested certificate followed by the certificate chain, and `tls.key` is the private key for the certificate. - + We can decode the certificate and print it out using `openssl`: ```bash kubectl get secret certificate-by-issuer -n default -o jsonpath='{.data.tls\.crt}' | base64 --decode | openssl x509 -text -noout ``` - + In any case, the certificate is ready to be used as Kubernetes Secret by your Kubernetes resources. + ## FAQ @@ -236,15 +273,24 @@ In the following steps, we explore how to install the Infisical PKI Issuer using The full list of the fields supported on the `Certificate` resource can be found in the API reference documentation [here](https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec). - + Currently, not all fields are supported by the Infisical PKI Issuer. + Yes. `cert-manager` will automatically renew certificates according to the `renewBefore` threshold of expiry as specified in the corresponding `Certificate` resource. - + You can read more about the `renewBefore` field [here](https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec). + - \ No newline at end of file + + If you see log messages similar to: + ``` + "CertificateRequest has not been approved yet. Ignoring.","controller":"certificaterequest","controllerGroup":"cert-manager.io","controllerKind":"CertificateRequest","CertificateRequest":{"name":"skynet-infisical-rta-rsa2048-1","namespace":"infisical-system"},"namespace":"infisical-system","name":"skynet-infisical-rta-rsa2048-1","reconcileID":"bfb7cad9-d867-45b5-b3a3-0139e731b7a6"} + ``` + This indicates that the `CertificateRequest` has been created, but `cert-manager` has not yet approved it. This typically occurs because a necessary approver policy is missing. Refer to the documentation above to create an approver policy. + + diff --git a/frontend/src/pages/cert-manager/CertAuthDetailsByIDPage/CertAuthDetailsByIDPage.tsx b/frontend/src/pages/cert-manager/CertAuthDetailsByIDPage/CertAuthDetailsByIDPage.tsx index e76720275..dd202f981 100644 --- a/frontend/src/pages/cert-manager/CertAuthDetailsByIDPage/CertAuthDetailsByIDPage.tsx +++ b/frontend/src/pages/cert-manager/CertAuthDetailsByIDPage/CertAuthDetailsByIDPage.tsx @@ -23,7 +23,6 @@ import { usePopUp } from "@app/hooks/usePopUp"; import { CaInstallCertModal } from "../CertificateAuthoritiesPage/components/CaInstallCertModal"; import { CaModal } from "../CertificateAuthoritiesPage/components/CaModal"; -import { CertificateTemplatesSection } from "../CertificatesPage/components/CertificateTemplatesSection"; import { CaCertificatesSection, CaCrlsSection, @@ -126,7 +125,6 @@ const Page = () => {
-
diff --git a/frontend/src/pages/cert-manager/PkiTemplateListPage/PkiTemplateListPage.tsx b/frontend/src/pages/cert-manager/PkiTemplateListPage/PkiTemplateListPage.tsx index 7bbb08008..7adf86bc7 100644 --- a/frontend/src/pages/cert-manager/PkiTemplateListPage/PkiTemplateListPage.tsx +++ b/frontend/src/pages/cert-manager/PkiTemplateListPage/PkiTemplateListPage.tsx @@ -2,7 +2,6 @@ import { useState } from "react"; import { Helmet } from "react-helmet"; import { useTranslation } from "react-i18next"; import { - faArrowUpRightFromSquare, faCertificate, faEllipsis, faPencil, @@ -107,15 +106,6 @@ export const PkiTemplateListPage = () => {

Templates

- - - Documentation{" "} - - -