mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 10:29:17 +00:00
Remove extra tx in ssh nullable ca defaults migration, update ssh docs
This commit is contained in:
@@ -7,25 +7,17 @@ export async function up(knex: Knex): Promise<void> {
|
||||
const hasDefaultHostCaCol = await knex.schema.hasColumn(TableName.ProjectSshConfig, "defaultHostSshCaId");
|
||||
|
||||
if (hasDefaultUserCaCol && hasDefaultHostCaCol) {
|
||||
await knex.transaction(async (trx) => {
|
||||
await trx.schema.alterTable(TableName.ProjectSshConfig, (t) => {
|
||||
await knex.schema.alterTable(TableName.ProjectSshConfig, (t) => {
|
||||
t.dropForeign(["defaultUserSshCaId"]);
|
||||
t.dropForeign(["defaultHostSshCaId"]);
|
||||
});
|
||||
await trx.schema.alterTable(TableName.ProjectSshConfig, (t) => {
|
||||
await knex.schema.alterTable(TableName.ProjectSshConfig, (t) => {
|
||||
// allow nullable (does not wipe existing values)
|
||||
t.uuid("defaultUserSshCaId").nullable().alter();
|
||||
t.uuid("defaultHostSshCaId").nullable().alter();
|
||||
// re-add with SET NULL behavior (previously CASCADE)
|
||||
t.foreign("defaultUserSshCaId")
|
||||
.references("id")
|
||||
.inTable(TableName.SshCertificateAuthority)
|
||||
.onDelete("SET NULL");
|
||||
t.foreign("defaultHostSshCaId")
|
||||
.references("id")
|
||||
.inTable(TableName.SshCertificateAuthority)
|
||||
.onDelete("SET NULL");
|
||||
});
|
||||
t.foreign("defaultUserSshCaId").references("id").inTable(TableName.SshCertificateAuthority).onDelete("SET NULL");
|
||||
t.foreign("defaultHostSshCaId").references("id").inTable(TableName.SshCertificateAuthority).onDelete("SET NULL");
|
||||
});
|
||||
}
|
||||
|
||||
|
||||
@@ -139,7 +139,8 @@ Once Infisical SSH is configured by an administrator, users can SSH to the remot
|
||||
<Step title="Connect to the remote host">
|
||||
The `infisical ssh connect` command can be used in either interactive or non-interactive mode to connect to a remote host.
|
||||
|
||||
### Interactive Mode
|
||||
<Tabs>
|
||||
<Tab title="Interactive Mode">
|
||||
In interactive mode, you'll first need to authenticate with Infisical by running:
|
||||
|
||||
```bash
|
||||
@@ -176,8 +177,8 @@ Once Infisical SSH is configured by an administrator, users can SSH to the remot
|
||||
✔ SSH credentials successfully added to agent
|
||||
Connecting to [email protected]...
|
||||
```
|
||||
|
||||
### Non-Interactive Mode
|
||||
</Tab>
|
||||
<Tab title="Non-Interactive Mode">
|
||||
For CI/CD pipelines or automation scenarios, you can use the non-interactive mode with an Infisical token:
|
||||
|
||||
```bash
|
||||
@@ -193,6 +194,8 @@ Once Infisical SSH is configured by an administrator, users can SSH to the remot
|
||||
- Use the specified login user
|
||||
- Write the SSH credentials to the specified path instead of adding them to the SSH agent
|
||||
- Authenticate using the provided Infisical token
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
|
||||
</Steps>
|
||||
|
||||
Reference in New Issue
Block a user