mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 19:28:16 +00:00
Remove extra tx in ssh nullable ca defaults migration, update ssh docs
This commit is contained in:
@@ -7,25 +7,17 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
const hasDefaultHostCaCol = await knex.schema.hasColumn(TableName.ProjectSshConfig, "defaultHostSshCaId");
|
const hasDefaultHostCaCol = await knex.schema.hasColumn(TableName.ProjectSshConfig, "defaultHostSshCaId");
|
||||||
|
|
||||||
if (hasDefaultUserCaCol && hasDefaultHostCaCol) {
|
if (hasDefaultUserCaCol && hasDefaultHostCaCol) {
|
||||||
await knex.transaction(async (trx) => {
|
await knex.schema.alterTable(TableName.ProjectSshConfig, (t) => {
|
||||||
await trx.schema.alterTable(TableName.ProjectSshConfig, (t) => {
|
t.dropForeign(["defaultUserSshCaId"]);
|
||||||
t.dropForeign(["defaultUserSshCaId"]);
|
t.dropForeign(["defaultHostSshCaId"]);
|
||||||
t.dropForeign(["defaultHostSshCaId"]);
|
});
|
||||||
});
|
await knex.schema.alterTable(TableName.ProjectSshConfig, (t) => {
|
||||||
await trx.schema.alterTable(TableName.ProjectSshConfig, (t) => {
|
// allow nullable (does not wipe existing values)
|
||||||
// allow nullable (does not wipe existing values)
|
t.uuid("defaultUserSshCaId").nullable().alter();
|
||||||
t.uuid("defaultUserSshCaId").nullable().alter();
|
t.uuid("defaultHostSshCaId").nullable().alter();
|
||||||
t.uuid("defaultHostSshCaId").nullable().alter();
|
// re-add with SET NULL behavior (previously CASCADE)
|
||||||
// re-add with SET NULL behavior (previously CASCADE)
|
t.foreign("defaultUserSshCaId").references("id").inTable(TableName.SshCertificateAuthority).onDelete("SET NULL");
|
||||||
t.foreign("defaultUserSshCaId")
|
t.foreign("defaultHostSshCaId").references("id").inTable(TableName.SshCertificateAuthority).onDelete("SET NULL");
|
||||||
.references("id")
|
|
||||||
.inTable(TableName.SshCertificateAuthority)
|
|
||||||
.onDelete("SET NULL");
|
|
||||||
t.foreign("defaultHostSshCaId")
|
|
||||||
.references("id")
|
|
||||||
.inTable(TableName.SshCertificateAuthority)
|
|
||||||
.onDelete("SET NULL");
|
|
||||||
});
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -139,60 +139,63 @@ Once Infisical SSH is configured by an administrator, users can SSH to the remot
|
|||||||
<Step title="Connect to the remote host">
|
<Step title="Connect to the remote host">
|
||||||
The `infisical ssh connect` command can be used in either interactive or non-interactive mode to connect to a remote host.
|
The `infisical ssh connect` command can be used in either interactive or non-interactive mode to connect to a remote host.
|
||||||
|
|
||||||
### Interactive Mode
|
<Tabs>
|
||||||
In interactive mode, you'll first need to authenticate with Infisical by running:
|
<Tab title="Interactive Mode">
|
||||||
|
In interactive mode, you'll first need to authenticate with Infisical by running:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
infisical login
|
infisical login
|
||||||
```
|
```
|
||||||
|
|
||||||
Then simply run:
|
Then simply run:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
infisical ssh connect
|
infisical ssh connect
|
||||||
```
|
```
|
||||||
|
|
||||||
You'll be prompted to select an SSH Host from a list of accessible hosts; this is based on project membership and login mappings configured on hosts by
|
You'll be prompted to select an SSH Host from a list of accessible hosts; this is based on project membership and login mappings configured on hosts by
|
||||||
the administrator.
|
the administrator.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
Use the arrow keys to navigate: ↓ ↑ → ←
|
Use the arrow keys to navigate: ↓ ↑ → ←
|
||||||
? Select an SSH Host:
|
? Select an SSH Host:
|
||||||
▸ ec2-12-345-678-910.ap-northeast-1.compute.amazonaws.com
|
▸ ec2-12-345-678-910.ap-northeast-1.compute.amazonaws.com
|
||||||
```
|
```
|
||||||
|
|
||||||
After selecting a host, you'll be prompted to select a login user from a list of allowed login users:
|
After selecting a host, you'll be prompted to select a login user from a list of allowed login users:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
? Select Login User:
|
? Select Login User:
|
||||||
▸ ec2-user
|
▸ ec2-user
|
||||||
```
|
```
|
||||||
|
|
||||||
If successful, you should be able to SSH to the remote host.
|
If successful, you should be able to SSH to the remote host.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
✔ ec2-54-199-104-116.ap-northeast-1.compute.amazonaws.com
|
✔ ec2-54-199-104-116.ap-northeast-1.compute.amazonaws.com
|
||||||
✔ ec2-user
|
✔ ec2-user
|
||||||
✔ SSH credentials successfully added to agent
|
✔ SSH credentials successfully added to agent
|
||||||
Connecting to [email protected]...
|
Connecting to [email protected]...
|
||||||
```
|
```
|
||||||
|
</Tab>
|
||||||
|
<Tab title="Non-Interactive Mode">
|
||||||
|
For CI/CD pipelines or automation scenarios, you can use the non-interactive mode with an Infisical token:
|
||||||
|
|
||||||
### Non-Interactive Mode
|
```bash
|
||||||
For CI/CD pipelines or automation scenarios, you can use the non-interactive mode with an Infisical token:
|
infisical ssh connect \
|
||||||
|
--hostname ec2-12-345-678-910.ap-northeast-1.compute.amazonaws.com \
|
||||||
|
--loginUser ec2-user \
|
||||||
|
--outFilePath ~/.ssh/id_rsa-cert.pub \
|
||||||
|
--token <your-infisical-token>
|
||||||
|
```
|
||||||
|
|
||||||
```bash
|
This will:
|
||||||
infisical ssh connect \
|
- Connect to the specified hostname
|
||||||
--hostname ec2-12-345-678-910.ap-northeast-1.compute.amazonaws.com \
|
- Use the specified login user
|
||||||
--loginUser ec2-user \
|
- Write the SSH credentials to the specified path instead of adding them to the SSH agent
|
||||||
--outFilePath ~/.ssh/id_rsa-cert.pub \
|
- Authenticate using the provided Infisical token
|
||||||
--token <your-infisical-token>
|
</Tab>
|
||||||
```
|
</Tabs>
|
||||||
|
|
||||||
This will:
|
|
||||||
- Connect to the specified hostname
|
|
||||||
- Use the specified login user
|
|
||||||
- Write the SSH credentials to the specified path instead of adding them to the SSH agent
|
|
||||||
- Authenticate using the provided Infisical token
|
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
Reference in New Issue
Block a user