mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 20:28:31 +00:00
Update docs
This commit is contained in:
@@ -51,7 +51,7 @@ infisical export --template=<path to template>
|
|||||||
<Info>
|
<Info>
|
||||||
Alternatively, you may use service tokens.
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
Please note, however, that service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities). They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
|
|||||||
@@ -54,7 +54,7 @@ $ infisical run -- npm run dev
|
|||||||
<Info>
|
<Info>
|
||||||
Alternatively, you may use service tokens.
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
Please note, however, that service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities). They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
|
|||||||
@@ -33,7 +33,7 @@ $ infisical secrets
|
|||||||
<Info>
|
<Info>
|
||||||
Alternatively, you may use service tokens.
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
Please note, however, that service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities). They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
|
|||||||
+1
-1
@@ -206,7 +206,7 @@ infisical <any-command> --domain="https://your-self-hosted-infisical.com/api"
|
|||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="Can I use the CLI with service tokens?">
|
<Accordion title="Can I use the CLI with service tokens?">
|
||||||
Yes. Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
Yes. Please note, however, that service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities). They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
To use Infisical for non local development scenarios, please create a service token. The service token will allow you to authenticate and interact with Infisical. Once you have created a service token with the required permissions, you’ll need to feed the token to the CLI.
|
To use Infisical for non local development scenarios, please create a service token. The service token will allow you to authenticate and interact with Infisical. Once you have created a service token with the required permissions, you’ll need to feed the token to the CLI.
|
||||||
|
|
||||||
|
|||||||
@@ -1,104 +0,0 @@
|
|||||||
---
|
|
||||||
title: "Kubernetes"
|
|
||||||
---
|
|
||||||
|
|
||||||
The Infisical Secrets Operator fetches secrets from Infisical and saves them as Kubernetes secrets using the custom `InfisicalSecret` resource to define authentication and storage methods.
|
|
||||||
The operator updates secrets continuously and can reload dependent deployments automatically on secret changes.
|
|
||||||
|
|
||||||
Prerequisites:
|
|
||||||
|
|
||||||
- Connected to your cluster via kubectl
|
|
||||||
- Have a project with secrets ready in [Infisical Cloud](https://app.infisical.com).
|
|
||||||
- Create an [Infisical Token](/documentation/platform/token) scoped to an environment in your project in Infisical.
|
|
||||||
|
|
||||||
## Installation
|
|
||||||
|
|
||||||
Follow the instructions for either [Helm](https://helm.sh/) or [kubectl](https://github.com/kubernetes/kubectl) to install the Infisical Secrets Operator.
|
|
||||||
|
|
||||||
<Tabs>
|
|
||||||
<Tab title="Helm">
|
|
||||||
Install the Infisical Helm repository
|
|
||||||
|
|
||||||
```console
|
|
||||||
helm repo add infisical-helm-charts 'https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/'
|
|
||||||
|
|
||||||
helm repo update
|
|
||||||
```
|
|
||||||
|
|
||||||
Install the Helm chart
|
|
||||||
```console
|
|
||||||
helm install --generate-name infisical-helm-charts/secrets-operator
|
|
||||||
```
|
|
||||||
|
|
||||||
</Tab>
|
|
||||||
<Tab title="Kubectl">
|
|
||||||
The operator will be installed in `infisical-operator-system` namespace
|
|
||||||
```
|
|
||||||
kubectl apply -f https://raw.githubusercontent.com/Infisical/infisical/main/k8-operator/kubectl-install/install-secrets-operator.yaml
|
|
||||||
```
|
|
||||||
</Tab>
|
|
||||||
</Tabs>
|
|
||||||
|
|
||||||
|
|
||||||
## Usage
|
|
||||||
|
|
||||||
<Tabs>
|
|
||||||
<Tab title="Machine Identities (Recommended)">
|
|
||||||
### Machine Identities
|
|
||||||
</Tab>
|
|
||||||
<Tab title="Service Tokens (Deprecated)">
|
|
||||||
### Service Tokens
|
|
||||||
<Warning>
|
|
||||||
Service tokens are deprecated and will be removed in the near future. Please switch to [Machine Identities](/documentation/platform/identities/machine-identities) for authenticating with Infisical.
|
|
||||||
</Warning>
|
|
||||||
|
|
||||||
|
|
||||||
</Tab>
|
|
||||||
</Tabs>
|
|
||||||
|
|
||||||
**Step 1: Create Kubernetes secret containing machine identity**
|
|
||||||
|
|
||||||
Once you have created your machine identity, create a Kubernetes secret containing the machine identity you generated by running the command below.
|
|
||||||
|
|
||||||
``` bash
|
|
||||||
kubectl create secret generic universal-auth-credentials --from-literal=clientId=<your-client-id> --from-literal=clientSecret=<your-client-secret>
|
|
||||||
```
|
|
||||||
|
|
||||||
**Step 2: Fill out the InfisicalSecrets CRD and apply it to your cluster**
|
|
||||||
|
|
||||||
```yaml infisical-secrets-config.yaml
|
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
|
||||||
kind: InfisicalSecret
|
|
||||||
metadata:
|
|
||||||
# Name of of this InfisicalSecret resource
|
|
||||||
name: infisicalsecret-sample
|
|
||||||
spec:
|
|
||||||
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
|
|
||||||
hostAPI: https://app.infisical.com/api
|
|
||||||
resyncInterval:
|
|
||||||
authentication:
|
|
||||||
universalAuth:
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: <project-slug>
|
|
||||||
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
|
||||||
secretsPath: "<secrets-path>" # Root is "/"
|
|
||||||
|
|
||||||
credentialsRef:
|
|
||||||
secretName: universal-auth-credentials
|
|
||||||
secretNamespace: default
|
|
||||||
|
|
||||||
managedSecretReference:
|
|
||||||
secretName: managed-secret # <-- the name of kubernetes secret that will be created
|
|
||||||
secretNamespace: default # <-- where the kubernetes secret should be created
|
|
||||||
```
|
|
||||||
|
|
||||||
```
|
|
||||||
kubectl apply -f infisical-secrets-config.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
You should now see a new kubernetes secret automatically created in the namespace you defined in the `managedSecretReference` property above.
|
|
||||||
|
|
||||||
See also:
|
|
||||||
|
|
||||||
- [Documentation for the Infisical Kubernetes Operator](../../integrations/platforms/kubernetes)
|
|
||||||
|
|
||||||
@@ -26,13 +26,12 @@ This step also involves configuring an authentication method for it such as [Uni
|
|||||||
3. Authenticating the identity with the Infisical API based on the configured authentication method on it and receiving a short-lived access token back.
|
3. Authenticating the identity with the Infisical API based on the configured authentication method on it and receiving a short-lived access token back.
|
||||||
4. Authenticating subsequent requests with the Infisical API using the short-lived access token.
|
4. Authenticating subsequent requests with the Infisical API using the short-lived access token.
|
||||||
|
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Currently, identities can only be used to make authenticated requests to the Infisical API, SDKs, Terraform, Kubernetes Operator, and Infisical Agent. They do not work with clients such as CLI, Ansible look up plugin, etc.
|
Currently, identities can only be used to make authenticated requests to the Infisical API, SDKs, Terraform, Kubernetes Operator, and Infisical Agent. They do not work with clients such as CLI, Ansible look up plugin, etc.
|
||||||
|
|
||||||
Machine Identity support for the rest of the clients is planned to be released in the current quarter.
|
Machine Identity support for the rest of the clients is planned to be released in the current quarter.
|
||||||
</Note>
|
|
||||||
|
|
||||||
|
</Note>
|
||||||
|
|
||||||
## Authentication Methods
|
## Authentication Methods
|
||||||
|
|
||||||
@@ -43,24 +42,16 @@ To interact with various resources in Infisical, Machine Identities are able to
|
|||||||
## FAQ
|
## FAQ
|
||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="How do I use Machine Identities with the CLI?">
|
<Accordion title="Can I use machine identities with the CLI?">
|
||||||
To use Machine Identities with the CLI, you need to authenticate with the Infisical API using the identity's access token. Here's how you can do it.
|
|
||||||
|
|
||||||
```bash
|
Yes - Identities can be used with the CLI.
|
||||||
export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id=<your-identity-client-id> --client-secret=<your-identity-client-secret> --silent --plain)
|
|
||||||
infisical secrets --env dev --projectId=<your-project-id>
|
You can learn more about how to do this in the CLI quickstart [here](/cli/usage).
|
||||||
```
|
|
||||||
|
|
||||||
The CLI is built to look for the `INFISICAL_TOKEN` environment variable. You can also pass the universal auth token as a `--token` flag to most commands.
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
|
||||||
<Accordion title="What is the difference between an identity and service token?">
|
<Accordion title="What is the difference between an identity and service token?">
|
||||||
<Warning>
|
A service token is a project-level authentication method that is being deprecated in favor of identities. The service token method will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
Service tokens are deprecated and will be removed in the near future. Please switch to Machine Identities for authenticating with Infisical.
|
|
||||||
</Warning>
|
|
||||||
|
|
||||||
A service token is a project-level authentication method that is being phased out in favor of identities.
|
|
||||||
|
|
||||||
Amongst many differences, identities provide broader access over the Infisical API, utilizes the same
|
Amongst many differences, identities provide broader access over the Infisical API, utilizes the same
|
||||||
permission system as user identities, and come with a significantly larger number of configurable authentication and security features.
|
permission system as user identities, and come with a significantly larger number of configurable authentication and security features.
|
||||||
|
|||||||
@@ -4,7 +4,10 @@ description: "Infisical service tokens allow users to programmatically interact
|
|||||||
---
|
---
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Service tokens are deprecated and will be removed in the near future. Please switch to [Machine Identities](/documentation/platform/identities/machine-identities) for authenticating with Infisical.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
Service tokens are authentication credentials that services can use to access designated endpoints in the Infisical API to manage project resources like secrets.
|
Service tokens are authentication credentials that services can use to access designated endpoints in the Infisical API to manage project resources like secrets.
|
||||||
@@ -48,7 +51,8 @@ In the above screenshot, you can see that we are creating a token token with `re
|
|||||||
of the `/common` path within the development environment of the project; the token expires in 6 months and can be used from any IP address.
|
of the `/common` path within the development environment of the project; the token expires in 6 months and can be used from any IP address.
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
For a deeper understanding of service tokens, it is recommended to read [this guide](https://infisical.com/docs/internals/service-tokens).
|
For a deeper understanding of service tokens, it is recommended to read [this
|
||||||
|
guide](https://infisical.com/docs/internals/service-tokens).
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
**FAQ**
|
**FAQ**
|
||||||
@@ -62,6 +66,7 @@ For a deeper understanding of service tokens, it is recommended to read [this gu
|
|||||||
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
|
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
|
||||||
- (If using ST V3) The service token has not been activated yet.
|
- (If using ST V3) The service token has not been activated yet.
|
||||||
- (If using ST V3) The service token is being used from an untrusted IP.
|
- (If using ST V3) The service token is being used from an untrusted IP.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="Can you provide examples for using glob patterns?">
|
<Accordion title="Can you provide examples for using glob patterns?">
|
||||||
1. `/**`: This pattern matches all folders at any depth in the directory structure. For example, it would match folders like `/folder1/`, `/folder1/subfolder/`, and so on.
|
1. `/**`: This pattern matches all folders at any depth in the directory structure. For example, it would match folders like `/folder1/`, `/folder1/subfolder/`, and so on.
|
||||||
@@ -71,5 +76,6 @@ For a deeper understanding of service tokens, it is recommended to read [this gu
|
|||||||
3. `/*/*`: This pattern matches all subfolders at a depth of two levels in the current directory. It does not match any folders at a shallower or deeper level. For example, it would match folders like `/folder1/subfolder/`, `/folder2/subfolder/`, but not `/folder1/` or `/folder1/subfolder/subsubfolder/`.
|
3. `/*/*`: This pattern matches all subfolders at a depth of two levels in the current directory. It does not match any folders at a shallower or deeper level. For example, it would match folders like `/folder1/subfolder/`, `/folder2/subfolder/`, but not `/folder1/` or `/folder1/subfolder/subsubfolder/`.
|
||||||
|
|
||||||
4. `/folder1/*`: This pattern matches all immediate subfolders within the `/folder1/` directory. It does not match any folders outside of `/folder1/`, nor does it match any subfolders within those immediate subfolders. For example, it would match folders like `/folder1/subfolder1/`, `/folder1/subfolder2/`, but not `/folder2/subfolder/`.
|
4. `/folder1/*`: This pattern matches all immediate subfolders within the `/folder1/` directory. It does not match any folders outside of `/folder1/`, nor does it match any subfolders within those immediate subfolders. For example, it would match folders like `/folder1/subfolder1/`, `/folder1/subfolder2/`, but not `/folder2/subfolder/`.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
|
|||||||
@@ -16,8 +16,6 @@ Prerequisites:
|
|||||||
- You have a working Jenkins installation with the [credentials plugin](https://plugins.jenkins.io/credentials/) installed.
|
- You have a working Jenkins installation with the [credentials plugin](https://plugins.jenkins.io/credentials/) installed.
|
||||||
- You have the [Infisical CLI](/cli/overview) installed on your Jenkins executor nodes or container images.
|
- You have the [Infisical CLI](/cli/overview) installed on your Jenkins executor nodes or container images.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
<Tabs>
|
<Tabs>
|
||||||
|
|
||||||
<Tab title="Machine Identity (Recommended)">
|
<Tab title="Machine Identity (Recommended)">
|
||||||
@@ -145,14 +143,18 @@ Prerequisites:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
|
|
||||||
<Tab title="Service Token (Deprecated)">
|
<Tab title="Service Token (Deprecated)">
|
||||||
## Add Infisical Service Token to Jenkins
|
## Add Infisical Service Token to Jenkins
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Service tokens are deprecated and will be removed in the future.
|
|
||||||
Please use machine identity authentication instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
After setting up your project in Infisical and installing the Infisical CLI to the environment where your Jenkins builds will run, you will need to add the Infisical Service Token to Jenkins.
|
After setting up your project in Infisical and installing the Infisical CLI to the environment where your Jenkins builds will run, you will need to add the Infisical Service Token to Jenkins.
|
||||||
@@ -270,11 +272,11 @@ Prerequisites:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
|
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|
||||||
The example provided above serves as an initial guide. It shows how Jenkins adds the `INFISICAL_TOKEN` environment variable, which is configured in the pipeline, into the shell for executing commands.
|
The example provided above serves as an initial guide. It shows how Jenkins adds the `INFISICAL_TOKEN` environment variable, which is configured in the pipeline, into the shell for executing commands.
|
||||||
There may be instances where this doesn't work as expected in the context of running Docker commands.
|
There may be instances where this doesn't work as expected in the context of running Docker commands.
|
||||||
However, the list of working examples should provide some insight into how this can be handled properly.
|
However, the list of working examples should provide some insight into how this can be handled properly.
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ description: "Learn how to sync secrets from Infisical to AWS Amplify."
|
|||||||
---
|
---
|
||||||
|
|
||||||
Prerequisites:
|
Prerequisites:
|
||||||
|
|
||||||
- Infisical Cloud account
|
- Infisical Cloud account
|
||||||
- Add the secrets you wish to sync to Amplify to [Infisical Cloud](https://app.infisical.com)
|
- Add the secrets you wish to sync to Amplify to [Infisical Cloud](https://app.infisical.com)
|
||||||
|
|
||||||
@@ -63,7 +64,9 @@ This approach enables you to fetch secrets from Infisical during Amplify build t
|
|||||||
<Tab title="Service Token (Deprecated)">
|
<Tab title="Service Token (Deprecated)">
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
The service token approach is deprecated and will be removed in the future. Please use the machine identity approach instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
@@ -123,11 +126,12 @@ This approach enables you to fetch secrets from Infisical during Amplify build t
|
|||||||
You need to set the path in the format `/amplify/[amplify_app_id]/[your-amplify-environment-name]` as the path option in AWS SSM Parameter Infisical Integration.
|
You need to set the path in the format `/amplify/[amplify_app_id]/[your-amplify-environment-name]` as the path option in AWS SSM Parameter Infisical Integration.
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Accessing an environment secret during a build is similar to accessing environment variables, except that environment secrets are stored in `process.env.secrets` as a JSON string.
|
Accessing an environment secret during a build is similar to accessing
|
||||||
|
environment variables, except that environment secrets are stored in
|
||||||
|
`process.env.secrets` as a JSON string.
|
||||||
</Info>
|
</Info>
|
||||||
|
|||||||
@@ -8,6 +8,7 @@ Prerequisites:
|
|||||||
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
||||||
|
|
||||||
## Configure the Infisical CLI for each service
|
## Configure the Infisical CLI for each service
|
||||||
|
|
||||||
Follow this [guide](./docker) to configure the Infisical CLI for each service that you wish to inject environment variables into; you'll have to update the Dockerfile of each service.
|
Follow this [guide](./docker) to configure the Infisical CLI for each service that you wish to inject environment variables into; you'll have to update the Dockerfile of each service.
|
||||||
|
|
||||||
<Tabs>
|
<Tabs>
|
||||||
@@ -60,11 +61,15 @@ Follow this [guide](./docker) to configure the Infisical CLI for each service th
|
|||||||
# Then run your compose file in the same terminal.
|
# Then run your compose file in the same terminal.
|
||||||
docker-compose ...
|
docker-compose ...
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Service Token (Deprecated)">
|
<Tab title="Service Token (Deprecated)">
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
The service token approach is deprecated and will be removed in the future. Please use the machine identity approach instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
## Generate service token
|
## Generate service token
|
||||||
@@ -109,5 +114,6 @@ Follow this [guide](./docker) to configure the Infisical CLI for each service th
|
|||||||
# Then run your compose file in the same terminal.
|
# Then run your compose file in the same terminal.
|
||||||
docker-compose ...
|
docker-compose ...
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|||||||
@@ -37,20 +37,24 @@ This is achieved by installing the Infisical CLI into your docker image and modi
|
|||||||
We recommend you to set the version of the CLI to a specific version. This will help keep your CLI version consistent across reinstalls. [View versions](https://cloudsmith.io/~infisical/repos/infisical-cli/packages/)
|
We recommend you to set the version of the CLI to a specific version. This will help keep your CLI version consistent across reinstalls. [View versions](https://cloudsmith.io/~infisical/repos/infisical-cli/packages/)
|
||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
|
|
||||||
## Modify the start command in your Dockerfile
|
## Modify the start command in your Dockerfile
|
||||||
|
|
||||||
Starting your service with the Infisical CLI pulls your secrets from Infisical and injects them into your service.
|
Starting your service with the Infisical CLI pulls your secrets from Infisical and injects them into your service.
|
||||||
|
|
||||||
<Tabs>
|
<Tabs>
|
||||||
<Tab title="Machine Identity (Recommended)">
|
<Tab title="Machine Identity (Recommended)">
|
||||||
```dockerfile
|
```dockerfile
|
||||||
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--", "[your service start command]"]
|
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--", "[your service start command]"]
|
||||||
|
|
||||||
# example with single single command
|
# example with single single command
|
||||||
|
|
||||||
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--", "npm", "run", "start"]
|
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--", "npm", "run", "start"]
|
||||||
|
|
||||||
# example with multiple commands
|
# example with multiple commands
|
||||||
|
|
||||||
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--command", "npm run start && ..."]
|
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--command", "npm run start && ..."]
|
||||||
```
|
|
||||||
|
````
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Generate a machine identity">
|
<Step title="Generate a machine identity">
|
||||||
@@ -80,7 +84,10 @@ Starting your service with the Infisical CLI pulls your secrets from Infisical a
|
|||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Service Token (Deprecated)">
|
<Tab title="Service Token (Deprecated)">
|
||||||
<Warning>
|
<Warning>
|
||||||
The service token approach is deprecated and will be removed in the future. Please use the machine identity approach instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
```dockerfile
|
```dockerfile
|
||||||
CMD ["infisical", "run", "--", "[your service start command]"]
|
CMD ["infisical", "run", "--", "[your service start command]"]
|
||||||
@@ -90,7 +97,7 @@ Starting your service with the Infisical CLI pulls your secrets from Infisical a
|
|||||||
|
|
||||||
# example with multiple commands
|
# example with multiple commands
|
||||||
CMD ["infisical", "run", "--command", "npm run start && ..."]
|
CMD ["infisical", "run", "--command", "npm run start && ..."]
|
||||||
```
|
````
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Generate a service token">
|
<Step title="Generate a service token">
|
||||||
@@ -107,8 +114,7 @@ Starting your service with the Infisical CLI pulls your secrets from Infisical a
|
|||||||
docker run --env INFISICAL_TOKEN=[token] [DOCKER-IMAGE]...
|
docker run --env INFISICAL_TOKEN=[token] [DOCKER-IMAGE]...
|
||||||
```
|
```
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -1,11 +1,10 @@
|
|||||||
---
|
---
|
||||||
title: 'Kubernetes'
|
title: "Kubernetes"
|
||||||
description: "How to use Infisical to inject secrets into Kubernetes clusters."
|
description: "How to use Infisical to inject secrets into Kubernetes clusters."
|
||||||
---
|
---
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|
||||||
The Infisical Secrets Operator is a Kubernetes controller that retrieves secrets from Infisical and stores them in a designated cluster.
|
The Infisical Secrets Operator is a Kubernetes controller that retrieves secrets from Infisical and stores them in a designated cluster.
|
||||||
It uses an `InfisicalSecret` resource to specify authentication and storage methods.
|
It uses an `InfisicalSecret` resource to specify authentication and storage methods.
|
||||||
The operator continuously updates secrets and can also reload dependent deployments automatically.
|
The operator continuously updates secrets and can also reload dependent deployments automatically.
|
||||||
@@ -42,7 +41,6 @@ The operator can be install via [Helm](https://helm.sh) or [kubectl](https://git
|
|||||||
For production deployments, it is highly recommended to set the version of the Kubernetes operator manually instead of pointing to the latest version.
|
For production deployments, it is highly recommended to set the version of the Kubernetes operator manually instead of pointing to the latest version.
|
||||||
Doing so will help you avoid accidental updates to the newest release which may introduce unintended breaking changes. View all application versions [here](https://hub.docker.com/r/infisical/kubernetes-operator/tags).
|
Doing so will help you avoid accidental updates to the newest release which may introduce unintended breaking changes. View all application versions [here](https://hub.docker.com/r/infisical/kubernetes-operator/tags).
|
||||||
|
|
||||||
|
|
||||||
The command below will install the most recent version of the Kubernetes operator.
|
The command below will install the most recent version of the Kubernetes operator.
|
||||||
However, to set the version manually, download the manifest and set the image tag version of `infisical/kubernetes-operator` according to your desired version.
|
However, to set the version manually, download the manifest and set the image tag version of `infisical/kubernetes-operator` according to your desired version.
|
||||||
|
|
||||||
@@ -51,10 +49,12 @@ The operator can be install via [Helm](https://helm.sh) or [kubectl](https://git
|
|||||||
```
|
```
|
||||||
kubectl apply -f https://raw.githubusercontent.com/Infisical/infisical/main/k8-operator/kubectl-install/install-secrets-operator.yaml
|
kubectl apply -f https://raw.githubusercontent.com/Infisical/infisical/main/k8-operator/kubectl-install/install-secrets-operator.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
## Sync Infisical Secrets to your cluster
|
## Sync Infisical Secrets to your cluster
|
||||||
|
|
||||||
Once you have installed the operator to your cluster, you'll need to create a `InfisicalSecret` custom resource definition (CRD).
|
Once you have installed the operator to your cluster, you'll need to create a `InfisicalSecret` custom resource definition (CRD).
|
||||||
|
|
||||||
```yaml example-infisical-secret-crd.yaml
|
```yaml example-infisical-secret-crd.yaml
|
||||||
@@ -81,8 +81,6 @@ spec:
|
|||||||
secretName: universal-auth-credentials
|
secretName: universal-auth-credentials
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
# Service tokens are deprecated and will be removed in the near future. Please use Machine Identities for authenticating with Infisical.
|
# Service tokens are deprecated and will be removed in the near future. Please use Machine Identities for authenticating with Infisical.
|
||||||
serviceToken:
|
serviceToken:
|
||||||
serviceTokenSecretReference:
|
serviceTokenSecretReference:
|
||||||
@@ -98,6 +96,7 @@ spec:
|
|||||||
creationPolicy: "Orphan" ## Owner | Orphan (default)
|
creationPolicy: "Orphan" ## Owner | Orphan (default)
|
||||||
# secretType: kubernetes.io/dockerconfigjson
|
# secretType: kubernetes.io/dockerconfigjson
|
||||||
```
|
```
|
||||||
|
|
||||||
### InfisicalSecret CRD properties
|
### InfisicalSecret CRD properties
|
||||||
|
|
||||||
<Accordion title="hostAPI">
|
<Accordion title="hostAPI">
|
||||||
@@ -115,16 +114,19 @@ spec:
|
|||||||
```
|
```
|
||||||
|
|
||||||
Make sure to replace `<backend-svc-name>` and `<namespace>` with the appropriate values for your backend service and namespace.
|
Make sure to replace `<backend-svc-name>` and `<namespace>` with the appropriate values for your backend service and namespace.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="resyncInterval">
|
<Accordion title="resyncInterval">
|
||||||
This property defines the time in seconds between each secret re-sync from Infisical. Shorter time between re-syncs will require higher rate limits only available on paid plans.
|
This property defines the time in seconds between each secret re-sync from
|
||||||
Default re-sync interval is every 1 minute.
|
Infisical. Shorter time between re-syncs will require higher rate limits only
|
||||||
|
available on paid plans. Default re-sync interval is every 1 minute.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication">
|
<Accordion title="authentication">
|
||||||
This block defines the method that will be used to authenticate with Infisical so that secrets can be fetched
|
This block defines the method that will be used to authenticate with Infisical
|
||||||
|
so that secrets can be fetched
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication.universalAuth">
|
<Accordion title="authentication.universalAuth">
|
||||||
@@ -148,15 +150,20 @@ Default re-sync interval is every 1 minute.
|
|||||||
<Step title="Add reference for the Kubernetes secret containing the identity credentials">
|
<Step title="Add reference for the Kubernetes secret containing the identity credentials">
|
||||||
Once the secret is created, add the `secretName` and `secretNamespace` of the secret that was just created under `authentication.universalAuth.credentialsRef` field in the InfisicalSecret resource.
|
Once the secret is created, add the `secretName` and `secretNamespace` of the secret that was just created under `authentication.universalAuth.credentialsRef` field in the InfisicalSecret resource.
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Make sure to also populate the `secretsScope` field with the project slug _`projectSlug`_, environment slug _`envSlug`_, and secrets path _`secretsPath`_ that you want to fetch secrets from. Please see the example below.
|
Make sure to also populate the `secretsScope` field with the project slug
|
||||||
|
_`projectSlug`_, environment slug _`envSlug`_, and secrets path
|
||||||
|
_`secretsPath`_ that you want to fetch secrets from. Please see the example
|
||||||
|
below.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
## Example
|
## Example
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
kind: InfisicalSecret
|
kind: InfisicalSecret
|
||||||
@@ -174,11 +181,15 @@ Default re-sync interval is every 1 minute.
|
|||||||
secretNamespace: default # <-- namespace of the Kubernetes secret that stores our machine identity credentials
|
secretNamespace: default # <-- namespace of the Kubernetes secret that stores our machine identity credentials
|
||||||
...
|
...
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication.serviceToken">
|
<Accordion title="authentication.serviceToken">
|
||||||
<Warning>
|
<Warning>
|
||||||
Service tokens are deprecated and will be removed in the near future. Please use Machine Identities (Universal Auth) for authenticating with Infisical.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
The service token required to authenticate with Infisical needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores this service token.
|
The service token required to authenticate with Infisical needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores this service token.
|
||||||
@@ -201,11 +212,16 @@ Default re-sync interval is every 1 minute.
|
|||||||
|
|
||||||
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
|
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Make sure to also populate the `secretsScope` field with the, environment slug _`envSlug`_, and secrets path _`secretsPath`_ that you want to fetch secrets from. Please see the example below.
|
Make sure to also populate the `secretsScope` field with the, environment slug
|
||||||
|
_`envSlug`_, and secrets path _`secretsPath`_ that you want to fetch secrets
|
||||||
|
from. Please see the example below.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
## Example
|
## Example
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
kind: InfisicalSecret
|
kind: InfisicalSecret
|
||||||
@@ -222,6 +238,7 @@ Default re-sync interval is every 1 minute.
|
|||||||
secretsPath: <secrets-path> # Root is "/"
|
secretsPath: <secrets-path> # Root is "/"
|
||||||
...
|
...
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="managedSecretReference">
|
<Accordion title="managedSecretReference">
|
||||||
@@ -246,11 +263,13 @@ Creation polices allow you to control whether or not owner references should be
|
|||||||
This is useful for tools such as ArgoCD, where every resource requires an owner reference; otherwise, it will be pruned automatically.
|
This is useful for tools such as ArgoCD, where every resource requires an owner reference; otherwise, it will be pruned automatically.
|
||||||
|
|
||||||
#### Available options
|
#### Available options
|
||||||
|
|
||||||
- `Orphan` (default)
|
- `Orphan` (default)
|
||||||
- `Owner`
|
- `Owner`
|
||||||
|
|
||||||
<Tip>
|
<Tip>
|
||||||
When creation policy is set to `Owner`, the `InfisicalSecret` CRD must be in the same namespace as where the managed kubernetes secret.
|
When creation policy is set to `Owner`, the `InfisicalSecret` CRD must be in
|
||||||
|
the same namespace as where the managed kubernetes secret.
|
||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
@@ -282,8 +301,7 @@ This would result in the following managed secret to be created:
|
|||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
data:
|
data: ...
|
||||||
...
|
|
||||||
kind: Secret
|
kind: Secret
|
||||||
metadata:
|
metadata:
|
||||||
annotations:
|
annotations:
|
||||||
@@ -295,10 +313,11 @@ metadata:
|
|||||||
namespace: default
|
namespace: default
|
||||||
type: Opaque
|
type: Opaque
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
|
||||||
### Apply the Infisical CRD to your cluster
|
### Apply the Infisical CRD to your cluster
|
||||||
|
|
||||||
Once you have configured the Infisical CRD with the required fields, you can apply it to your cluster.
|
Once you have configured the Infisical CRD with the required fields, you can apply it to your cluster.
|
||||||
After applying, you should notice that the managed secret has been created in the desired namespace your specified.
|
After applying, you should notice that the managed secret has been created in the desired namespace your specified.
|
||||||
|
|
||||||
@@ -321,13 +340,14 @@ kubectl get secrets -n <namespace of managed secret>
|
|||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
### Using managed secret in your deployment
|
### Using managed secret in your deployment
|
||||||
|
|
||||||
Incorporating the managed secret created by the operator into your deployment can be achieved through several methods.
|
Incorporating the managed secret created by the operator into your deployment can be achieved through several methods.
|
||||||
Here, we will highlight three of the most common ways to utilize it. Learn more about Kubernetes secrets [here](https://kubernetes.io/docs/concepts/configuration/secret/)
|
Here, we will highlight three of the most common ways to utilize it. Learn more about Kubernetes secrets [here](https://kubernetes.io/docs/concepts/configuration/secret/)
|
||||||
|
|
||||||
<Accordion title="envFrom">
|
<Accordion title="envFrom">
|
||||||
This will take all the secrets from your managed secret and expose them to your container
|
This will take all the secrets from your managed secret and expose them to your container
|
||||||
|
|
||||||
```yaml
|
````yaml
|
||||||
envFrom:
|
envFrom:
|
||||||
- secretRef:
|
- secretRef:
|
||||||
name: managed-secret # managed secret name
|
name: managed-secret # managed secret name
|
||||||
@@ -359,9 +379,9 @@ Here, we will highlight three of the most common ways to utilize it. Learn more
|
|||||||
name: managed-secret # <- name of managed secret
|
name: managed-secret # <- name of managed secret
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 80
|
- containerPort: 80
|
||||||
```
|
````
|
||||||
</Accordion>
|
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="env">
|
<Accordion title="env">
|
||||||
This will allow you to select individual secrets by key name from your managed secret and expose them to your container
|
This will allow you to select individual secrets by key name from your managed secret and expose them to your container
|
||||||
@@ -376,6 +396,7 @@ Here, we will highlight three of the most common ways to utilize it. Learn more
|
|||||||
```
|
```
|
||||||
|
|
||||||
Example usage in a deployment
|
Example usage in a deployment
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
@@ -393,18 +414,17 @@ Here, we will highlight three of the most common ways to utilize it. Learn more
|
|||||||
labels:
|
labels:
|
||||||
app: nginx
|
app: nginx
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers: - name: nginx
|
||||||
- name: nginx
|
|
||||||
image: nginx:1.14.2
|
image: nginx:1.14.2
|
||||||
env:
|
env: - name: STRIPE_API_SECRET
|
||||||
- name: STRIPE_API_SECRET
|
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: managed-secret # <- name of managed secret
|
name: managed-secret # <- name of managed secret
|
||||||
key: STRIPE_API_SECRET
|
key: STRIPE_API_SECRET
|
||||||
ports:
|
ports: - containerPort: 80
|
||||||
- containerPort: 80
|
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="volumes">
|
<Accordion title="volumes">
|
||||||
@@ -414,9 +434,10 @@ Here, we will highlight three of the most common ways to utilize it. Learn more
|
|||||||
- name: secrets-volume-name # The name of the volume under which secrets will be stored
|
- name: secrets-volume-name # The name of the volume under which secrets will be stored
|
||||||
secret:
|
secret:
|
||||||
secretName: managed-secret # managed secret name
|
secretName: managed-secret # managed secret name
|
||||||
```
|
````
|
||||||
|
|
||||||
You can then mount this volume to the container's filesystem so that your deployment can access the files containing the managed secrets
|
You can then mount this volume to the container's filesystem so that your deployment can access the files containing the managed secrets
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: secrets-volume-name
|
- name: secrets-volume-name
|
||||||
@@ -425,6 +446,7 @@ Here, we will highlight three of the most common ways to utilize it. Learn more
|
|||||||
```
|
```
|
||||||
|
|
||||||
Example usage in a deployment
|
Example usage in a deployment
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
@@ -456,14 +478,18 @@ Here, we will highlight three of the most common ways to utilize it. Learn more
|
|||||||
secret:
|
secret:
|
||||||
secretName: managed-secret # <- managed secrets
|
secretName: managed-secret # <- managed secrets
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
## Auto redeployment
|
## Auto redeployment
|
||||||
|
|
||||||
Deployments using managed secrets don't reload automatically on updates, so they may use outdated secrets unless manually redeployed.
|
Deployments using managed secrets don't reload automatically on updates, so they may use outdated secrets unless manually redeployed.
|
||||||
To address this, we added functionality to automatically redeploy your deployment when its managed secret updates.
|
To address this, we added functionality to automatically redeploy your deployment when its managed secret updates.
|
||||||
|
|
||||||
### Enabling auto redeploy
|
### Enabling auto redeploy
|
||||||
|
|
||||||
To enable auto redeployment you simply have to add the following annotation to the deployment that consumes a managed secret
|
To enable auto redeployment you simply have to add the following annotation to the deployment that consumes a managed secret
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
secrets.infisical.com/auto-reload: "true"
|
secrets.infisical.com/auto-reload: "true"
|
||||||
```
|
```
|
||||||
@@ -500,16 +526,18 @@ spec:
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
## Global configuration
|
## Global configuration
|
||||||
|
|
||||||
To configure global settings that will apply to all instances of `InfisicalSecret`, you can define these configurations in a Kubernetes ConfigMap.
|
To configure global settings that will apply to all instances of `InfisicalSecret`, you can define these configurations in a Kubernetes ConfigMap.
|
||||||
For example, you can configure all `InfisicalSecret` instances to fetch secrets from a single backend API without specifying the `hostAPI` parameter for each instance.
|
For example, you can configure all `InfisicalSecret` instances to fetch secrets from a single backend API without specifying the `hostAPI` parameter for each instance.
|
||||||
|
|
||||||
### Available global properties
|
### Available global properties
|
||||||
| Property | Description | Default value
|
|
||||||
| -------- | ------------------------------------- |------------------------
|
|
||||||
| hostAPI | If `hostAPI` in `InfisicalSecret` instance is left empty, this value will be used | https://app.infisical.com/api
|
|
||||||
|
|
||||||
|
| Property | Description | Default value |
|
||||||
|
| -------- | --------------------------------------------------------------------------------- | ----------------------------- |
|
||||||
|
| hostAPI | If `hostAPI` in `InfisicalSecret` instance is left empty, this value will be used | https://app.infisical.com/api |
|
||||||
|
|
||||||
### Applying global configurations
|
### Applying global configurations
|
||||||
|
|
||||||
All global configurations must reside in a Kubernetes ConfigMap named `infisical-config` in the namespace `infisical-operator-system`.
|
All global configurations must reside in a Kubernetes ConfigMap named `infisical-config` in the namespace `infisical-operator-system`.
|
||||||
To apply global configuration to the operator, copy the following yaml into `infisical-config.yaml` file.
|
To apply global configuration to the operator, copy the following yaml into `infisical-config.yaml` file.
|
||||||
|
|
||||||
@@ -534,7 +562,6 @@ Then apply this change via kubectl by running the following
|
|||||||
kubectl apply -f infisical-config.yaml
|
kubectl apply -f infisical-config.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
## Troubleshoot operator
|
## Troubleshoot operator
|
||||||
|
|
||||||
If the operator is unable to fetch secrets from the API, it will not affect the managed Kubernetes secret.
|
If the operator is unable to fetch secrets from the API, it will not affect the managed Kubernetes secret.
|
||||||
@@ -583,7 +610,6 @@ The managed secret created by the operator will not be deleted when the operator
|
|||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|
||||||
## Useful Articles
|
## Useful Articles
|
||||||
|
|
||||||
- [Managing secrets in OpenShift with Infisical](https://xphyr.net/post/infisical_ocp/)
|
- [Managing secrets in OpenShift with Infisical](https://xphyr.net/post/infisical_ocp/)
|
||||||
|
|||||||
@@ -4,7 +4,10 @@ description: "Understanding service tokens and their best practices."
|
|||||||
---
|
---
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Service tokens are deprecated and will be removed in the future. Please use the [machine identity](/documentation/platform/identities/machine-identities) approach instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
Many clients use service tokens to authenticate and read/write secrets from/to Infisical; they can be created in your project settings.
|
Many clients use service tokens to authenticate and read/write secrets from/to Infisical; they can be created in your project settings.
|
||||||
@@ -32,6 +35,7 @@ Consider the token `st.abc.def.ghi`. Here, `st.abc.def` can be used to authentic
|
|||||||
|
|
||||||
Note that when using service tokens via select client methods like SDK or CLI, cryptographic operations are abstracted for you that is the token is parsed and encryption/decryption operations are handled. If using service tokens with the REST API and end-to-end encryption enabled, then you will have to handle the encryption/decryption operations yourself.
|
Note that when using service tokens via select client methods like SDK or CLI, cryptographic operations are abstracted for you that is the token is parsed and encryption/decryption operations are handled. If using service tokens with the REST API and end-to-end encryption enabled, then you will have to handle the encryption/decryption operations yourself.
|
||||||
|
|
||||||
|
|
||||||
## Recommendations
|
## Recommendations
|
||||||
|
|
||||||
### Issuance
|
### Issuance
|
||||||
|
|||||||
+9
-30
@@ -32,10 +32,7 @@
|
|||||||
"thumbsRating": true
|
"thumbsRating": true
|
||||||
},
|
},
|
||||||
"api": {
|
"api": {
|
||||||
"baseUrl": [
|
"baseUrl": ["https://app.infisical.com", "http://localhost:8080"]
|
||||||
"https://app.infisical.com",
|
|
||||||
"http://localhost:8080"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
"topbarLinks": [
|
"topbarLinks": [
|
||||||
{
|
{
|
||||||
@@ -76,11 +73,7 @@
|
|||||||
"documentation/getting-started/introduction",
|
"documentation/getting-started/introduction",
|
||||||
{
|
{
|
||||||
"group": "Quickstart",
|
"group": "Quickstart",
|
||||||
"pages": [
|
"pages": ["documentation/guides/local-development"]
|
||||||
"documentation/guides/local-development",
|
|
||||||
"documentation/guides/staging",
|
|
||||||
"documentation/guides/production"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Guides",
|
"group": "Guides",
|
||||||
@@ -374,15 +367,11 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Build Tool Integrations",
|
"group": "Build Tool Integrations",
|
||||||
"pages": [
|
"pages": ["integrations/build-tools/gradle"]
|
||||||
"integrations/build-tools/gradle"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "",
|
"group": "",
|
||||||
"pages": [
|
"pages": ["sdks/overview"]
|
||||||
"sdks/overview"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "SDK's",
|
"group": "SDK's",
|
||||||
@@ -400,9 +389,7 @@
|
|||||||
"api-reference/overview/authentication",
|
"api-reference/overview/authentication",
|
||||||
{
|
{
|
||||||
"group": "Examples",
|
"group": "Examples",
|
||||||
"pages": [
|
"pages": ["api-reference/overview/examples/integration"]
|
||||||
"api-reference/overview/examples/integration"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -531,15 +518,11 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Service Tokens",
|
"group": "Service Tokens",
|
||||||
"pages": [
|
"pages": ["api-reference/endpoints/service-tokens/get"]
|
||||||
"api-reference/endpoints/service-tokens/get"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Audit Logs",
|
"group": "Audit Logs",
|
||||||
"pages": [
|
"pages": ["api-reference/endpoints/audit-logs/export-audit-log"]
|
||||||
"api-reference/endpoints/audit-logs/export-audit-log"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -555,9 +538,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "",
|
"group": "",
|
||||||
"pages": [
|
"pages": ["changelog/overview"]
|
||||||
"changelog/overview"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Contributing",
|
"group": "Contributing",
|
||||||
@@ -581,9 +562,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Contributing to SDK",
|
"group": "Contributing to SDK",
|
||||||
"pages": [
|
"pages": ["contributing/sdk/developing"]
|
||||||
"contributing/sdk/developing"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user