mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
docs(k8s): added better templating docs
This commit is contained in:
@@ -451,30 +451,7 @@ Using Go templates, you can format, combine, and create new key-value pairs of s
|
|||||||
To help transform your config map data further, the operator provides a set of built-in functions that you can use in your templates.
|
To help transform your config map data further, the operator provides a set of built-in functions that you can use in your templates.
|
||||||
|
|
||||||
### Available templating functions
|
### Available templating functions
|
||||||
|
Please refer to the [templating functions documentation](/integrations/platforms/kubernetes/overview#available-helper-functions) for more information.
|
||||||
<Accordion title="encodeBase64">
|
|
||||||
**Function name**: encodeBase64
|
|
||||||
|
|
||||||
**Description**:
|
|
||||||
Given a string, this function will encode the string as a base64 encoded string.
|
|
||||||
This function is useful when you want to store a string as a base64 encoded value in Infisical.
|
|
||||||
|
|
||||||
**Returns**: The base64 encoded string.
|
|
||||||
|
|
||||||
**Example**:
|
|
||||||
The example below assumes that the `PLAIN_KEY` secret is stored in your source secret as a plaintext string.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
push:
|
|
||||||
secret:
|
|
||||||
secretName: push-secret-demo
|
|
||||||
secretNamespace: default
|
|
||||||
template:
|
|
||||||
includeAllSecrets: true
|
|
||||||
data:
|
|
||||||
PLAIN_KEY: "{{ encodeBase64 .PLAIN_KEY.Value }}" # Will be stored in Infisical as a base64 encoded string
|
|
||||||
```
|
|
||||||
</Accordion>
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
## Applying the InfisicalPushSecret CRD to your cluster
|
## Applying the InfisicalPushSecret CRD to your cluster
|
||||||
|
|||||||
@@ -654,30 +654,7 @@ To help transform your secrets further, the operator provides a set of built-in
|
|||||||
|
|
||||||
### Available templating functions
|
### Available templating functions
|
||||||
|
|
||||||
<Accordion title="decodeBase64ToBytes">
|
Please refer to the [templating functions documentation](/integrations/platforms/kubernetes/overview#available-helper-functions) for more information.
|
||||||
**Function name**: decodeBase64ToBytes
|
|
||||||
|
|
||||||
**Description**:
|
|
||||||
Given a base64 encoded string, this function will decodes the base64-encoded string.
|
|
||||||
This function is useful when your secrets are already stored as base64 encoded value in Infisical.
|
|
||||||
|
|
||||||
**Returns**: The decoded base64 string as bytes.
|
|
||||||
|
|
||||||
**Example**:
|
|
||||||
The example below assumes that the `BINARY_KEY_BASE64` secret is stored as a base64 encoded value in Infisical.
|
|
||||||
The resulting managed secret will contain the decoded value of `BINARY_KEY_BASE64`.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
managedKubeSecretReferences:
|
|
||||||
secretName: managed-secret
|
|
||||||
secretNamespace: default
|
|
||||||
template:
|
|
||||||
includeAllSecrets: true
|
|
||||||
data:
|
|
||||||
BINARY_KEY: "{{ decodeBase64ToBytes .BINARY_KEY_BASE64.Value }}"
|
|
||||||
```
|
|
||||||
|
|
||||||
</Accordion>
|
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
@@ -784,30 +761,7 @@ Using Go templates, you can format, combine, and create new key-value pairs from
|
|||||||
|
|
||||||
### Available templating functions
|
### Available templating functions
|
||||||
|
|
||||||
<Accordion title="decodeBase64ToBytes">
|
Please refer to the [templating functions documentation](/integrations/platforms/kubernetes/overview#available-helper-functions) for more information.
|
||||||
**Function name**: decodeBase64ToBytes
|
|
||||||
|
|
||||||
**Description**:
|
|
||||||
Given a base64 encoded string, this function will decodes the base64-encoded string.
|
|
||||||
This function is useful when your Infisical secrets are already stored as base64 encoded value in Infisical.
|
|
||||||
|
|
||||||
**Returns**: The decoded base64 string as bytes.
|
|
||||||
|
|
||||||
**Example**:
|
|
||||||
The example below assumes that the `BINARY_KEY_BASE64` secret is stored as a base64 encoded value in Infisical.
|
|
||||||
The resulting managed config map will contain the decoded value of `BINARY_KEY_BASE64`.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
managedKubeConfigMapReferences:
|
|
||||||
- configMapName: managed-configmap
|
|
||||||
configMapNamespace: default
|
|
||||||
template:
|
|
||||||
includeAllSecrets: true
|
|
||||||
data:
|
|
||||||
BINARY_KEY: "{{ decodeBase64ToBytes .BINARY_KEY_BASE64.Value }}"
|
|
||||||
```
|
|
||||||
|
|
||||||
</Accordion>
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
## Applying CRD
|
## Applying CRD
|
||||||
@@ -933,7 +887,6 @@ spec:
|
|||||||
ports:
|
ports:
|
||||||
- containerPort: 80
|
- containerPort: 80
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="volumes">
|
<Accordion title="volumes">
|
||||||
@@ -1202,7 +1155,6 @@ spec:
|
|||||||
configMap:
|
configMap:
|
||||||
name: managed-configmap # <- managed configmap
|
name: managed-configmap # <- managed configmap
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
The definition file of the Kubernetes secret for the CA certificate can be structured like the following:
|
The definition file of the Kubernetes secret for the CA certificate can be structured like the following:
|
||||||
|
|||||||
@@ -114,6 +114,48 @@ spec:
|
|||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
|
## Advanced Templating
|
||||||
|
|
||||||
|
With the Infisical Secrets Operator, you can use templating to dynamically generate secrets in Kubernetes. The templating is built on top of [Go templates](https://pkg.go.dev/text/template), which is a powerful and flexible template engine built into Go.
|
||||||
|
|
||||||
|
Please be aware that trying to reference non-existing keys will result in an error. Additionally, each template field is processed individually, which means one template field cannot reference another template field.
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Please note that templating is currently only supported for the `InfisicalPushSecret` and `InfisicalSecret` CRDs.
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
### Available helper functions
|
||||||
|
|
||||||
|
The Infisical Secrets Operator exposes a wide range of helper functions to make it easier to work with secrets in Kubernetes.
|
||||||
|
|
||||||
|
| Function | Description | Signature |
|
||||||
|
| -------- | ----------- | --------- |
|
||||||
|
| `decodeBase64ToBytes` | Given a base64 encoded string, this function will decode the base64-encoded string. | `decodeBase64ToBytes(encodedString string) string` |
|
||||||
|
| `encodeBase64` | Given a string, this function will encode the string to a base64 encoded string. | `encodeBase64(plainString string) string` |
|
||||||
|
| `pkcs12key`| Extracts all private keys from a PKCS#12 archive and encodes them in PKCS#8 PEM format. | `pkcs12key(input string) string` |
|
||||||
|
| `pkcs12keyPass`|Same as pkcs12key. Uses the provided password to decrypt the PKCS#12 archive. | `pkcs12keyPass(pass string, input string) string` |
|
||||||
|
| `pkcs12cert` | Extracts all certificates from a PKCS#12 archive and orders them if possible. If disjunct or multiple leaf certs are provided they are returned as-is. Sort order: `leaf / intermediate(s) / root`. | `pkcs12cert(input string) string` |
|
||||||
|
| `pkcs12certPass` | Same as `pkcs12cert`. Uses the provided password to decrypt the PKCS#12 archive. | `pkcs12certPass(pass string, input string) string` |
|
||||||
|
| `pemToPkcs12` | Takes a PEM encoded certificate and key and creates a base64 encoded PKCS#12 archive. | `pemToPkcs12(cert string, key string) string` |
|
||||||
|
| `pemToPkcs12Pass` | Same as `pemToPkcs12`. Uses the provided password to encrypt the PKCS#12 archive. | `pemToPkcs12Pass(cert string, key string, pass string) string` |
|
||||||
|
| `fullPemToPkcs12` | Takes a PEM encoded certificates chain and key and creates a base64 encoded PKCS#12 archive. | `fullPemToPkcs12(cert string, key string) string` |
|
||||||
|
| `fullPemToPkcs12Pass` | Same as `fullPemToPkcs12`. Uses the provided password to encrypt the PKCS#12 archive. | `fullPemToPkcs12Pass(cert string, key string, pass string) string` |
|
||||||
|
| `filterPEM` | Filters PEM blocks with a specific type from a list of PEM blocks.. | `filterPEM(pemType string, input string) string` |
|
||||||
|
| `filterCertChain` | Filters PEM block(s) with a specific certificate type (`leaf`, `intermediate` or `root`) from a certificate chain of PEM blocks (PEM blocks with type `CERTIFICATE`). | `filterCertChain(certType string, input string) string` |
|
||||||
|
| `jwkPublicKeyPem` | Takes an json-serialized JWK and returns an PEM block of type `PUBLIC KEY` that contains the public key. [See here](https://golang.org/pkg/crypto/x509/#MarshalPKIXPublicKey) for details. | `jwkPublicKeyPem(jwkjson string) string` |
|
||||||
|
| `jwkPrivateKeyPem` | Takes an json-serialized JWK and returns an PEM block of type `PRIVATE KEY` that contains the private key. [See here](https://pkg.go.dev/crypto/x509#MarshalPKCS8PrivateKey) for details. | `jwkPrivateKeyPem(jwkjson string) string` |
|
||||||
|
| `toYaml` | Takes an interface, marshals it to yaml. It returns a string, even on marshal error (empty string). | `toYaml(v any) string` |
|
||||||
|
| `fromYaml` | Function converts a YAML document into a `map[string]any`. | `fromYaml(str string) map[string]any` |
|
||||||
|
|
||||||
|
### Sprig functions
|
||||||
|
|
||||||
|
The Infisical Secrets Operator integrates with the [Sprig library](https://github.com/Masterminds/sprig) to provide additional helper functions.
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
We've removed `expandEnv` and `env` from the supported functions for security reasons.
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
|
||||||
## Global configuration
|
## Global configuration
|
||||||
|
|
||||||
To configure global settings that will apply to all instances of `InfisicalSecret`, you can define these configurations in a Kubernetes ConfigMap.
|
To configure global settings that will apply to all instances of `InfisicalSecret`, you can define these configurations in a Kubernetes ConfigMap.
|
||||||
|
|||||||
Reference in New Issue
Block a user