mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 05:27:52 +00:00
Update docs
This commit is contained in:
@@ -51,7 +51,7 @@ infisical export --template=<path to template>
|
|||||||
<Info>
|
<Info>
|
||||||
Alternatively, you may use service tokens.
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
Please note, however, that service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities). They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
|
|||||||
@@ -54,7 +54,7 @@ $ infisical run -- npm run dev
|
|||||||
<Info>
|
<Info>
|
||||||
Alternatively, you may use service tokens.
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
Please note, however, that service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities). They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
|
|||||||
@@ -33,7 +33,7 @@ $ infisical secrets
|
|||||||
<Info>
|
<Info>
|
||||||
Alternatively, you may use service tokens.
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
Please note, however, that service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities). They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
|
|||||||
+1
-1
@@ -206,7 +206,7 @@ infisical <any-command> --domain="https://your-self-hosted-infisical.com/api"
|
|||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="Can I use the CLI with service tokens?">
|
<Accordion title="Can I use the CLI with service tokens?">
|
||||||
Yes. Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
Yes. Please note, however, that service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities). They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
To use Infisical for non local development scenarios, please create a service token. The service token will allow you to authenticate and interact with Infisical. Once you have created a service token with the required permissions, you’ll need to feed the token to the CLI.
|
To use Infisical for non local development scenarios, please create a service token. The service token will allow you to authenticate and interact with Infisical. Once you have created a service token with the required permissions, you’ll need to feed the token to the CLI.
|
||||||
|
|
||||||
|
|||||||
@@ -1,104 +0,0 @@
|
|||||||
---
|
|
||||||
title: "Kubernetes"
|
|
||||||
---
|
|
||||||
|
|
||||||
The Infisical Secrets Operator fetches secrets from Infisical and saves them as Kubernetes secrets using the custom `InfisicalSecret` resource to define authentication and storage methods.
|
|
||||||
The operator updates secrets continuously and can reload dependent deployments automatically on secret changes.
|
|
||||||
|
|
||||||
Prerequisites:
|
|
||||||
|
|
||||||
- Connected to your cluster via kubectl
|
|
||||||
- Have a project with secrets ready in [Infisical Cloud](https://app.infisical.com).
|
|
||||||
- Create an [Infisical Token](/documentation/platform/token) scoped to an environment in your project in Infisical.
|
|
||||||
|
|
||||||
## Installation
|
|
||||||
|
|
||||||
Follow the instructions for either [Helm](https://helm.sh/) or [kubectl](https://github.com/kubernetes/kubectl) to install the Infisical Secrets Operator.
|
|
||||||
|
|
||||||
<Tabs>
|
|
||||||
<Tab title="Helm">
|
|
||||||
Install the Infisical Helm repository
|
|
||||||
|
|
||||||
```console
|
|
||||||
helm repo add infisical-helm-charts 'https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/'
|
|
||||||
|
|
||||||
helm repo update
|
|
||||||
```
|
|
||||||
|
|
||||||
Install the Helm chart
|
|
||||||
```console
|
|
||||||
helm install --generate-name infisical-helm-charts/secrets-operator
|
|
||||||
```
|
|
||||||
|
|
||||||
</Tab>
|
|
||||||
<Tab title="Kubectl">
|
|
||||||
The operator will be installed in `infisical-operator-system` namespace
|
|
||||||
```
|
|
||||||
kubectl apply -f https://raw.githubusercontent.com/Infisical/infisical/main/k8-operator/kubectl-install/install-secrets-operator.yaml
|
|
||||||
```
|
|
||||||
</Tab>
|
|
||||||
</Tabs>
|
|
||||||
|
|
||||||
|
|
||||||
## Usage
|
|
||||||
|
|
||||||
<Tabs>
|
|
||||||
<Tab title="Machine Identities (Recommended)">
|
|
||||||
### Machine Identities
|
|
||||||
</Tab>
|
|
||||||
<Tab title="Service Tokens (Deprecated)">
|
|
||||||
### Service Tokens
|
|
||||||
<Warning>
|
|
||||||
Service tokens are deprecated and will be removed in the near future. Please switch to [Machine Identities](/documentation/platform/identities/machine-identities) for authenticating with Infisical.
|
|
||||||
</Warning>
|
|
||||||
|
|
||||||
|
|
||||||
</Tab>
|
|
||||||
</Tabs>
|
|
||||||
|
|
||||||
**Step 1: Create Kubernetes secret containing machine identity**
|
|
||||||
|
|
||||||
Once you have created your machine identity, create a Kubernetes secret containing the machine identity you generated by running the command below.
|
|
||||||
|
|
||||||
``` bash
|
|
||||||
kubectl create secret generic universal-auth-credentials --from-literal=clientId=<your-client-id> --from-literal=clientSecret=<your-client-secret>
|
|
||||||
```
|
|
||||||
|
|
||||||
**Step 2: Fill out the InfisicalSecrets CRD and apply it to your cluster**
|
|
||||||
|
|
||||||
```yaml infisical-secrets-config.yaml
|
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
|
||||||
kind: InfisicalSecret
|
|
||||||
metadata:
|
|
||||||
# Name of of this InfisicalSecret resource
|
|
||||||
name: infisicalsecret-sample
|
|
||||||
spec:
|
|
||||||
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
|
|
||||||
hostAPI: https://app.infisical.com/api
|
|
||||||
resyncInterval:
|
|
||||||
authentication:
|
|
||||||
universalAuth:
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: <project-slug>
|
|
||||||
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
|
||||||
secretsPath: "<secrets-path>" # Root is "/"
|
|
||||||
|
|
||||||
credentialsRef:
|
|
||||||
secretName: universal-auth-credentials
|
|
||||||
secretNamespace: default
|
|
||||||
|
|
||||||
managedSecretReference:
|
|
||||||
secretName: managed-secret # <-- the name of kubernetes secret that will be created
|
|
||||||
secretNamespace: default # <-- where the kubernetes secret should be created
|
|
||||||
```
|
|
||||||
|
|
||||||
```
|
|
||||||
kubectl apply -f infisical-secrets-config.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
You should now see a new kubernetes secret automatically created in the namespace you defined in the `managedSecretReference` property above.
|
|
||||||
|
|
||||||
See also:
|
|
||||||
|
|
||||||
- [Documentation for the Infisical Kubernetes Operator](../../integrations/platforms/kubernetes)
|
|
||||||
|
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: Machine Identities
|
title: Machine Identities
|
||||||
description: "Learn how to use Machine Identities to programmatically interact with Infisical."
|
description: "Learn how to use Machine Identities to programmatically interact with Infisical."
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -21,18 +21,17 @@ Key Features:
|
|||||||
A typical workflow for using identities consists of four steps:
|
A typical workflow for using identities consists of four steps:
|
||||||
|
|
||||||
1. Creating the identity with a name and [role](/documentation/platform/role-based-access-controls) in Organization Access Control > Machine Identities.
|
1. Creating the identity with a name and [role](/documentation/platform/role-based-access-controls) in Organization Access Control > Machine Identities.
|
||||||
This step also involves configuring an authentication method for it such as [Universal Auth](/documentation/platform/identities/universal-auth).
|
This step also involves configuring an authentication method for it such as [Universal Auth](/documentation/platform/identities/universal-auth).
|
||||||
2. Adding the identity to the project(s) you want it to have access to.
|
2. Adding the identity to the project(s) you want it to have access to.
|
||||||
3. Authenticating the identity with the Infisical API based on the configured authentication method on it and receiving a short-lived access token back.
|
3. Authenticating the identity with the Infisical API based on the configured authentication method on it and receiving a short-lived access token back.
|
||||||
4. Authenticating subsequent requests with the Infisical API using the short-lived access token.
|
4. Authenticating subsequent requests with the Infisical API using the short-lived access token.
|
||||||
|
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Currently, identities can only be used to make authenticated requests to the Infisical API, SDKs, Terraform, Kubernetes Operator, and Infisical Agent. They do not work with clients such as CLI, Ansible look up plugin, etc.
|
Currently, identities can only be used to make authenticated requests to the Infisical API, SDKs, Terraform, Kubernetes Operator, and Infisical Agent. They do not work with clients such as CLI, Ansible look up plugin, etc.
|
||||||
|
|
||||||
Machine Identity support for the rest of the clients is planned to be released in the current quarter.
|
Machine Identity support for the rest of the clients is planned to be released in the current quarter.
|
||||||
</Note>
|
|
||||||
|
|
||||||
|
</Note>
|
||||||
|
|
||||||
## Authentication Methods
|
## Authentication Methods
|
||||||
|
|
||||||
@@ -43,24 +42,16 @@ To interact with various resources in Infisical, Machine Identities are able to
|
|||||||
## FAQ
|
## FAQ
|
||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="How do I use Machine Identities with the CLI?">
|
<Accordion title="Can I use machine identities with the CLI?">
|
||||||
To use Machine Identities with the CLI, you need to authenticate with the Infisical API using the identity's access token. Here's how you can do it.
|
|
||||||
|
|
||||||
```bash
|
Yes - Identities can be used with the CLI.
|
||||||
export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id=<your-identity-client-id> --client-secret=<your-identity-client-secret> --silent --plain)
|
|
||||||
infisical secrets --env dev --projectId=<your-project-id>
|
You can learn more about how to do this in the CLI quickstart [here](/cli/usage).
|
||||||
```
|
|
||||||
|
|
||||||
The CLI is built to look for the `INFISICAL_TOKEN` environment variable. You can also pass the universal auth token as a `--token` flag to most commands.
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
|
||||||
<Accordion title="What is the difference between an identity and service token?">
|
<Accordion title="What is the difference between an identity and service token?">
|
||||||
<Warning>
|
A service token is a project-level authentication method that is being deprecated in favor of identities. The service token method will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
Service tokens are deprecated and will be removed in the near future. Please switch to Machine Identities for authenticating with Infisical.
|
|
||||||
</Warning>
|
|
||||||
|
|
||||||
A service token is a project-level authentication method that is being phased out in favor of identities.
|
|
||||||
|
|
||||||
Amongst many differences, identities provide broader access over the Infisical API, utilizes the same
|
Amongst many differences, identities provide broader access over the Infisical API, utilizes the same
|
||||||
permission system as user identities, and come with a significantly larger number of configurable authentication and security features.
|
permission system as user identities, and come with a significantly larger number of configurable authentication and security features.
|
||||||
|
|||||||
@@ -4,7 +4,10 @@ description: "Infisical service tokens allow users to programmatically interact
|
|||||||
---
|
---
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Service tokens are deprecated and will be removed in the near future. Please switch to [Machine Identities](/documentation/platform/identities/machine-identities) for authenticating with Infisical.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
Service tokens are authentication credentials that services can use to access designated endpoints in the Infisical API to manage project resources like secrets.
|
Service tokens are authentication credentials that services can use to access designated endpoints in the Infisical API to manage project resources like secrets.
|
||||||
@@ -21,8 +24,8 @@ Service Token (ST) is the current widely-used authentication method for managing
|
|||||||
Here's a few pointers to get you acquainted with it:
|
Here's a few pointers to get you acquainted with it:
|
||||||
|
|
||||||
- When you create a ST, you get a token prefixed with `st`. The part after the last `.` delimiter is a symmetric key; everything
|
- When you create a ST, you get a token prefixed with `st`. The part after the last `.` delimiter is a symmetric key; everything
|
||||||
before it is an access token. When authenticating with the Infisical API, it is important to send in only the access token portion
|
before it is an access token. When authenticating with the Infisical API, it is important to send in only the access token portion
|
||||||
of the token.
|
of the token.
|
||||||
- ST supports expiration; it gets deleted automatically upon expiration.
|
- ST supports expiration; it gets deleted automatically upon expiration.
|
||||||
- ST supports provisioning `read` and/or `write` permissions broadly applied to all accessible environment(s) and path(s).
|
- ST supports provisioning `read` and/or `write` permissions broadly applied to all accessible environment(s) and path(s).
|
||||||
- ST is not editable.
|
- ST is not editable.
|
||||||
@@ -39,7 +42,7 @@ the token access to. Here's some guidance for each field:
|
|||||||
- Name: A friendly name for the token.
|
- Name: A friendly name for the token.
|
||||||
- Scopes: The environment(s) and path(s) the token should have access to.
|
- Scopes: The environment(s) and path(s) the token should have access to.
|
||||||
- Permissions: You can indicate whether or not the token should have `read/write` access to the paths.
|
- Permissions: You can indicate whether or not the token should have `read/write` access to the paths.
|
||||||
Also, note that Infisical supports [glob patterns](https://www.malikbrowne.com/blog/a-beginners-guide-glob-patterns/) when defining access scopes to path(s).
|
Also, note that Infisical supports [glob patterns](https://www.malikbrowne.com/blog/a-beginners-guide-glob-patterns/) when defining access scopes to path(s).
|
||||||
- Expiration: The time when this token should be rendered inactive.
|
- Expiration: The time when this token should be rendered inactive.
|
||||||
|
|
||||||

|

|
||||||
@@ -48,28 +51,31 @@ In the above screenshot, you can see that we are creating a token token with `re
|
|||||||
of the `/common` path within the development environment of the project; the token expires in 6 months and can be used from any IP address.
|
of the `/common` path within the development environment of the project; the token expires in 6 months and can be used from any IP address.
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
For a deeper understanding of service tokens, it is recommended to read [this guide](https://infisical.com/docs/internals/service-tokens).
|
For a deeper understanding of service tokens, it is recommended to read [this
|
||||||
|
guide](https://infisical.com/docs/internals/service-tokens).
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
**FAQ**
|
**FAQ**
|
||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="Why is the Infisical API rejecting my service token?">
|
<Accordion title="Why is the Infisical API rejecting my service token?">
|
||||||
There are a few reasons for why this might happen:
|
There are a few reasons for why this might happen:
|
||||||
|
|
||||||
- The service token has expired.
|
- The service token has expired.
|
||||||
- The service token is insufficiently permissioned to interact with the secrets in the given environment and path.
|
- The service token is insufficiently permissioned to interact with the secrets in the given environment and path.
|
||||||
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
|
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
|
||||||
- (If using ST V3) The service token has not been activated yet.
|
- (If using ST V3) The service token has not been activated yet.
|
||||||
- (If using ST V3) The service token is being used from an untrusted IP.
|
- (If using ST V3) The service token is being used from an untrusted IP.
|
||||||
</Accordion>
|
|
||||||
<Accordion title="Can you provide examples for using glob patterns?">
|
|
||||||
1. `/**`: This pattern matches all folders at any depth in the directory structure. For example, it would match folders like `/folder1/`, `/folder1/subfolder/`, and so on.
|
|
||||||
|
|
||||||
2. `/*`: This pattern matches all immediate subfolders in the current directory. It does not match any folders at a deeper level. For example, it would match folders like `/folder1/`, `/folder2/`, but not `/folder1/subfolder/`.
|
</Accordion>
|
||||||
|
<Accordion title="Can you provide examples for using glob patterns?">
|
||||||
|
1. `/**`: This pattern matches all folders at any depth in the directory structure. For example, it would match folders like `/folder1/`, `/folder1/subfolder/`, and so on.
|
||||||
|
|
||||||
3. `/*/*`: This pattern matches all subfolders at a depth of two levels in the current directory. It does not match any folders at a shallower or deeper level. For example, it would match folders like `/folder1/subfolder/`, `/folder2/subfolder/`, but not `/folder1/` or `/folder1/subfolder/subsubfolder/`.
|
2. `/*`: This pattern matches all immediate subfolders in the current directory. It does not match any folders at a deeper level. For example, it would match folders like `/folder1/`, `/folder2/`, but not `/folder1/subfolder/`.
|
||||||
|
|
||||||
4. `/folder1/*`: This pattern matches all immediate subfolders within the `/folder1/` directory. It does not match any folders outside of `/folder1/`, nor does it match any subfolders within those immediate subfolders. For example, it would match folders like `/folder1/subfolder1/`, `/folder1/subfolder2/`, but not `/folder2/subfolder/`.
|
3. `/*/*`: This pattern matches all subfolders at a depth of two levels in the current directory. It does not match any folders at a shallower or deeper level. For example, it would match folders like `/folder1/subfolder/`, `/folder2/subfolder/`, but not `/folder1/` or `/folder1/subfolder/subsubfolder/`.
|
||||||
</Accordion>
|
|
||||||
|
4. `/folder1/*`: This pattern matches all immediate subfolders within the `/folder1/` directory. It does not match any folders outside of `/folder1/`, nor does it match any subfolders within those immediate subfolders. For example, it would match folders like `/folder1/subfolder1/`, `/folder1/subfolder2/`, but not `/folder2/subfolder/`.
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
|
|||||||
@@ -16,8 +16,6 @@ Prerequisites:
|
|||||||
- You have a working Jenkins installation with the [credentials plugin](https://plugins.jenkins.io/credentials/) installed.
|
- You have a working Jenkins installation with the [credentials plugin](https://plugins.jenkins.io/credentials/) installed.
|
||||||
- You have the [Infisical CLI](/cli/overview) installed on your Jenkins executor nodes or container images.
|
- You have the [Infisical CLI](/cli/overview) installed on your Jenkins executor nodes or container images.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
<Tabs>
|
<Tabs>
|
||||||
|
|
||||||
<Tab title="Machine Identity (Recommended)">
|
<Tab title="Machine Identity (Recommended)">
|
||||||
@@ -145,15 +143,19 @@ Prerequisites:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
|
|
||||||
<Tab title="Service Token (Deprecated)">
|
<Tab title="Service Token (Deprecated)">
|
||||||
## Add Infisical Service Token to Jenkins
|
## Add Infisical Service Token to Jenkins
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Service tokens are deprecated and will be removed in the future.
|
|
||||||
Please use machine identity authentication instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
</Warning>
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
|
</Warning>
|
||||||
|
|
||||||
After setting up your project in Infisical and installing the Infisical CLI to the environment where your Jenkins builds will run, you will need to add the Infisical Service Token to Jenkins.
|
After setting up your project in Infisical and installing the Infisical CLI to the environment where your Jenkins builds will run, you will need to add the Infisical Service Token to Jenkins.
|
||||||
|
|
||||||
@@ -270,11 +272,11 @@ Prerequisites:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
|
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|
||||||
The example provided above serves as an initial guide. It shows how Jenkins adds the `INFISICAL_TOKEN` environment variable, which is configured in the pipeline, into the shell for executing commands.
|
The example provided above serves as an initial guide. It shows how Jenkins adds the `INFISICAL_TOKEN` environment variable, which is configured in the pipeline, into the shell for executing commands.
|
||||||
There may be instances where this doesn't work as expected in the context of running Docker commands.
|
There may be instances where this doesn't work as expected in the context of running Docker commands.
|
||||||
However, the list of working examples should provide some insight into how this can be handled properly.
|
However, the list of working examples should provide some insight into how this can be handled properly.
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ description: "Learn how to sync secrets from Infisical to AWS Amplify."
|
|||||||
---
|
---
|
||||||
|
|
||||||
Prerequisites:
|
Prerequisites:
|
||||||
|
|
||||||
- Infisical Cloud account
|
- Infisical Cloud account
|
||||||
- Add the secrets you wish to sync to Amplify to [Infisical Cloud](https://app.infisical.com)
|
- Add the secrets you wish to sync to Amplify to [Infisical Cloud](https://app.infisical.com)
|
||||||
|
|
||||||
@@ -63,7 +64,9 @@ This approach enables you to fetch secrets from Infisical during Amplify build t
|
|||||||
<Tab title="Service Token (Deprecated)">
|
<Tab title="Service Token (Deprecated)">
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
The service token approach is deprecated and will be removed in the future. Please use the machine identity approach instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
@@ -123,11 +126,12 @@ This approach enables you to fetch secrets from Infisical during Amplify build t
|
|||||||
You need to set the path in the format `/amplify/[amplify_app_id]/[your-amplify-environment-name]` as the path option in AWS SSM Parameter Infisical Integration.
|
You need to set the path in the format `/amplify/[amplify_app_id]/[your-amplify-environment-name]` as the path option in AWS SSM Parameter Infisical Integration.
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Accessing an environment secret during a build is similar to accessing environment variables, except that environment secrets are stored in `process.env.secrets` as a JSON string.
|
Accessing an environment secret during a build is similar to accessing
|
||||||
|
environment variables, except that environment secrets are stored in
|
||||||
|
`process.env.secrets` as a JSON string.
|
||||||
</Info>
|
</Info>
|
||||||
|
|||||||
@@ -8,6 +8,7 @@ Prerequisites:
|
|||||||
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
||||||
|
|
||||||
## Configure the Infisical CLI for each service
|
## Configure the Infisical CLI for each service
|
||||||
|
|
||||||
Follow this [guide](./docker) to configure the Infisical CLI for each service that you wish to inject environment variables into; you'll have to update the Dockerfile of each service.
|
Follow this [guide](./docker) to configure the Infisical CLI for each service that you wish to inject environment variables into; you'll have to update the Dockerfile of each service.
|
||||||
|
|
||||||
<Tabs>
|
<Tabs>
|
||||||
@@ -60,11 +61,15 @@ Follow this [guide](./docker) to configure the Infisical CLI for each service th
|
|||||||
# Then run your compose file in the same terminal.
|
# Then run your compose file in the same terminal.
|
||||||
docker-compose ...
|
docker-compose ...
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Service Token (Deprecated)">
|
<Tab title="Service Token (Deprecated)">
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
The service token approach is deprecated and will be removed in the future. Please use the machine identity approach instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
## Generate service token
|
## Generate service token
|
||||||
@@ -109,5 +114,6 @@ Follow this [guide](./docker) to configure the Infisical CLI for each service th
|
|||||||
# Then run your compose file in the same terminal.
|
# Then run your compose file in the same terminal.
|
||||||
docker-compose ...
|
docker-compose ...
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|||||||
@@ -37,60 +37,67 @@ This is achieved by installing the Infisical CLI into your docker image and modi
|
|||||||
We recommend you to set the version of the CLI to a specific version. This will help keep your CLI version consistent across reinstalls. [View versions](https://cloudsmith.io/~infisical/repos/infisical-cli/packages/)
|
We recommend you to set the version of the CLI to a specific version. This will help keep your CLI version consistent across reinstalls. [View versions](https://cloudsmith.io/~infisical/repos/infisical-cli/packages/)
|
||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
|
|
||||||
## Modify the start command in your Dockerfile
|
## Modify the start command in your Dockerfile
|
||||||
|
|
||||||
Starting your service with the Infisical CLI pulls your secrets from Infisical and injects them into your service.
|
Starting your service with the Infisical CLI pulls your secrets from Infisical and injects them into your service.
|
||||||
|
|
||||||
<Tabs>
|
<Tabs>
|
||||||
<Tab title="Machine Identity (Recommended)">
|
<Tab title="Machine Identity (Recommended)">
|
||||||
```dockerfile
|
```dockerfile
|
||||||
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--", "[your service start command]"]
|
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--", "[your service start command]"]
|
||||||
|
|
||||||
# example with single single command
|
# example with single single command
|
||||||
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--", "npm", "run", "start"]
|
|
||||||
|
|
||||||
# example with multiple commands
|
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--", "npm", "run", "start"]
|
||||||
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--command", "npm run start && ..."]
|
|
||||||
```
|
|
||||||
|
|
||||||
<Steps>
|
# example with multiple commands
|
||||||
<Step title="Generate a machine identity">
|
|
||||||
Generate a machine identity for your project by following the steps in the [Machine Identity](/documentation/platform/identities/machine-identities) guide. The machine identity will allow you to authenticate and fetch secrets from Infisical.
|
|
||||||
</Step>
|
|
||||||
<Step title="Obtain an access token for the machine identity">
|
|
||||||
Obtain an access token for the machine identity by running the following command:
|
|
||||||
```bash
|
|
||||||
export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id=<your-client-id> --client-secret=<your-client-secret> --plain --silent)
|
|
||||||
```
|
|
||||||
|
|
||||||
<Info>
|
CMD ["infisical", "run", "--projectId", "<your-project-id>", "--command", "npm run start && ..."]
|
||||||
Please note that the access token has a limited lifespan. The `infisical token renew` command can be used to renew the token if needed.
|
|
||||||
</Info>
|
|
||||||
</Step>
|
|
||||||
<Step title="Feed the access token to the docker container">
|
|
||||||
The last step is to give the Infisical CLI installed in your Docker container access to the access token. This will allow the CLI to fetch and inject the secrets into your application.
|
|
||||||
|
|
||||||
To feed the access token to the container, use the INFISICAL_TOKEN environment variable as shown below.
|
````
|
||||||
|
|
||||||
```bash
|
<Steps>
|
||||||
docker run --env INFISICAL_TOKEN=$INFISICAL_TOKEN [DOCKER-IMAGE]...
|
<Step title="Generate a machine identity">
|
||||||
```
|
Generate a machine identity for your project by following the steps in the [Machine Identity](/documentation/platform/identities/machine-identities) guide. The machine identity will allow you to authenticate and fetch secrets from Infisical.
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
<Step title="Obtain an access token for the machine identity">
|
||||||
|
Obtain an access token for the machine identity by running the following command:
|
||||||
|
```bash
|
||||||
|
export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id=<your-client-id> --client-secret=<your-client-secret> --plain --silent)
|
||||||
|
```
|
||||||
|
|
||||||
</Tab>
|
<Info>
|
||||||
<Tab title="Service Token (Deprecated)">
|
Please note that the access token has a limited lifespan. The `infisical token renew` command can be used to renew the token if needed.
|
||||||
<Warning>
|
</Info>
|
||||||
The service token approach is deprecated and will be removed in the future. Please use the machine identity approach instead.
|
</Step>
|
||||||
</Warning>
|
<Step title="Feed the access token to the docker container">
|
||||||
```dockerfile
|
The last step is to give the Infisical CLI installed in your Docker container access to the access token. This will allow the CLI to fetch and inject the secrets into your application.
|
||||||
CMD ["infisical", "run", "--", "[your service start command]"]
|
|
||||||
|
|
||||||
# example with single single command
|
To feed the access token to the container, use the INFISICAL_TOKEN environment variable as shown below.
|
||||||
CMD ["infisical", "run", "--", "npm", "run", "start"]
|
|
||||||
|
|
||||||
# example with multiple commands
|
```bash
|
||||||
CMD ["infisical", "run", "--command", "npm run start && ..."]
|
docker run --env INFISICAL_TOKEN=$INFISICAL_TOKEN [DOCKER-IMAGE]...
|
||||||
```
|
```
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
<Tab title="Service Token (Deprecated)">
|
||||||
|
<Warning>
|
||||||
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
|
</Warning>
|
||||||
|
```dockerfile
|
||||||
|
CMD ["infisical", "run", "--", "[your service start command]"]
|
||||||
|
|
||||||
|
# example with single single command
|
||||||
|
CMD ["infisical", "run", "--", "npm", "run", "start"]
|
||||||
|
|
||||||
|
# example with multiple commands
|
||||||
|
CMD ["infisical", "run", "--command", "npm run start && ..."]
|
||||||
|
````
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Generate a service token">
|
<Step title="Generate a service token">
|
||||||
@@ -107,8 +114,7 @@ Starting your service with the Infisical CLI pulls your secrets from Infisical a
|
|||||||
docker run --env INFISICAL_TOKEN=[token] [DOCKER-IMAGE]...
|
docker run --env INFISICAL_TOKEN=[token] [DOCKER-IMAGE]...
|
||||||
```
|
```
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -1,11 +1,10 @@
|
|||||||
---
|
---
|
||||||
title: 'Kubernetes'
|
title: "Kubernetes"
|
||||||
description: "How to use Infisical to inject secrets into Kubernetes clusters."
|
description: "How to use Infisical to inject secrets into Kubernetes clusters."
|
||||||
---
|
---
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|
||||||
The Infisical Secrets Operator is a Kubernetes controller that retrieves secrets from Infisical and stores them in a designated cluster.
|
The Infisical Secrets Operator is a Kubernetes controller that retrieves secrets from Infisical and stores them in a designated cluster.
|
||||||
It uses an `InfisicalSecret` resource to specify authentication and storage methods.
|
It uses an `InfisicalSecret` resource to specify authentication and storage methods.
|
||||||
The operator continuously updates secrets and can also reload dependent deployments automatically.
|
The operator continuously updates secrets and can also reload dependent deployments automatically.
|
||||||
@@ -42,69 +41,69 @@ The operator can be install via [Helm](https://helm.sh) or [kubectl](https://git
|
|||||||
For production deployments, it is highly recommended to set the version of the Kubernetes operator manually instead of pointing to the latest version.
|
For production deployments, it is highly recommended to set the version of the Kubernetes operator manually instead of pointing to the latest version.
|
||||||
Doing so will help you avoid accidental updates to the newest release which may introduce unintended breaking changes. View all application versions [here](https://hub.docker.com/r/infisical/kubernetes-operator/tags).
|
Doing so will help you avoid accidental updates to the newest release which may introduce unintended breaking changes. View all application versions [here](https://hub.docker.com/r/infisical/kubernetes-operator/tags).
|
||||||
|
|
||||||
|
The command below will install the most recent version of the Kubernetes operator.
|
||||||
|
However, to set the version manually, download the manifest and set the image tag version of `infisical/kubernetes-operator` according to your desired version.
|
||||||
|
|
||||||
The command below will install the most recent version of the Kubernetes operator.
|
Once you apply the manifest, the operator will be installed in `infisical-operator-system` namespace.
|
||||||
However, to set the version manually, download the manifest and set the image tag version of `infisical/kubernetes-operator` according to your desired version.
|
|
||||||
|
|
||||||
Once you apply the manifest, the operator will be installed in `infisical-operator-system` namespace.
|
|
||||||
|
|
||||||
```
|
```
|
||||||
kubectl apply -f https://raw.githubusercontent.com/Infisical/infisical/main/k8-operator/kubectl-install/install-secrets-operator.yaml
|
kubectl apply -f https://raw.githubusercontent.com/Infisical/infisical/main/k8-operator/kubectl-install/install-secrets-operator.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
## Sync Infisical Secrets to your cluster
|
## Sync Infisical Secrets to your cluster
|
||||||
|
|
||||||
Once you have installed the operator to your cluster, you'll need to create a `InfisicalSecret` custom resource definition (CRD).
|
Once you have installed the operator to your cluster, you'll need to create a `InfisicalSecret` custom resource definition (CRD).
|
||||||
|
|
||||||
```yaml example-infisical-secret-crd.yaml
|
```yaml example-infisical-secret-crd.yaml
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
kind: InfisicalSecret
|
kind: InfisicalSecret
|
||||||
metadata:
|
metadata:
|
||||||
name: infisicalsecret-sample
|
name: infisicalsecret-sample
|
||||||
labels:
|
labels:
|
||||||
label-to-be-passed-to-managed-secret: sample-value
|
label-to-be-passed-to-managed-secret: sample-value
|
||||||
annotations:
|
annotations:
|
||||||
example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
|
example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
|
||||||
spec:
|
spec:
|
||||||
hostAPI: https://app.infisical.com/api
|
hostAPI: https://app.infisical.com/api
|
||||||
resyncInterval: 10
|
resyncInterval: 10
|
||||||
authentication:
|
authentication:
|
||||||
# Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
|
# Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
|
||||||
# If you have multiple authentication methods defined, it may cause issues.
|
# If you have multiple authentication methods defined, it may cause issues.
|
||||||
universalAuth:
|
universalAuth:
|
||||||
secretsScope:
|
secretsScope:
|
||||||
projectSlug: <project-slug>
|
projectSlug: <project-slug>
|
||||||
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
||||||
secretsPath: "<secrets-path>" # Root is "/"
|
secretsPath: "<secrets-path>" # Root is "/"
|
||||||
credentialsRef:
|
credentialsRef:
|
||||||
secretName: universal-auth-credentials
|
secretName: universal-auth-credentials
|
||||||
secretNamespace: default
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
# Service tokens are deprecated and will be removed in the near future. Please use Machine Identities for authenticating with Infisical.
|
|
||||||
serviceToken:
|
|
||||||
serviceTokenSecretReference:
|
|
||||||
secretName: service-token
|
|
||||||
secretNamespace: default
|
|
||||||
secretsScope:
|
|
||||||
envSlug: <env-slug>
|
|
||||||
secretsPath: <secrets-path> # Root is "/"
|
|
||||||
|
|
||||||
managedSecretReference:
|
|
||||||
secretName: managed-secret
|
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
creationPolicy: "Orphan" ## Owner | Orphan (default)
|
|
||||||
# secretType: kubernetes.io/dockerconfigjson
|
# Service tokens are deprecated and will be removed in the near future. Please use Machine Identities for authenticating with Infisical.
|
||||||
|
serviceToken:
|
||||||
|
serviceTokenSecretReference:
|
||||||
|
secretName: service-token
|
||||||
|
secretNamespace: default
|
||||||
|
secretsScope:
|
||||||
|
envSlug: <env-slug>
|
||||||
|
secretsPath: <secrets-path> # Root is "/"
|
||||||
|
|
||||||
|
managedSecretReference:
|
||||||
|
secretName: managed-secret
|
||||||
|
secretNamespace: default
|
||||||
|
creationPolicy: "Orphan" ## Owner | Orphan (default)
|
||||||
|
# secretType: kubernetes.io/dockerconfigjson
|
||||||
```
|
```
|
||||||
|
|
||||||
### InfisicalSecret CRD properties
|
### InfisicalSecret CRD properties
|
||||||
|
|
||||||
<Accordion title="hostAPI">
|
<Accordion title="hostAPI">
|
||||||
If you are fetching secrets from a self hosted instance of Infisical set the value of `hostAPI` to
|
If you are fetching secrets from a self hosted instance of Infisical set the value of `hostAPI` to
|
||||||
` https://your-self-hosted-instace.com/api`
|
` https://your-self-hosted-instace.com/api`
|
||||||
|
|
||||||
When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
||||||
|
|
||||||
<Accordion title="Advanced use case">
|
<Accordion title="Advanced use case">
|
||||||
If you have installed your Infisical instance within the same cluster as the Infisical operator, you can optionally access the Infisical backend's service directly without having to route through the public internet.
|
If you have installed your Infisical instance within the same cluster as the Infisical operator, you can optionally access the Infisical backend's service directly without having to route through the public internet.
|
||||||
@@ -115,16 +114,19 @@ spec:
|
|||||||
```
|
```
|
||||||
|
|
||||||
Make sure to replace `<backend-svc-name>` and `<namespace>` with the appropriate values for your backend service and namespace.
|
Make sure to replace `<backend-svc-name>` and `<namespace>` with the appropriate values for your backend service and namespace.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="resyncInterval">
|
<Accordion title="resyncInterval">
|
||||||
This property defines the time in seconds between each secret re-sync from Infisical. Shorter time between re-syncs will require higher rate limits only available on paid plans.
|
This property defines the time in seconds between each secret re-sync from
|
||||||
Default re-sync interval is every 1 minute.
|
Infisical. Shorter time between re-syncs will require higher rate limits only
|
||||||
|
available on paid plans. Default re-sync interval is every 1 minute.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication">
|
<Accordion title="authentication">
|
||||||
This block defines the method that will be used to authenticate with Infisical so that secrets can be fetched
|
This block defines the method that will be used to authenticate with Infisical
|
||||||
|
so that secrets can be fetched
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication.universalAuth">
|
<Accordion title="authentication.universalAuth">
|
||||||
@@ -148,80 +150,95 @@ Default re-sync interval is every 1 minute.
|
|||||||
<Step title="Add reference for the Kubernetes secret containing the identity credentials">
|
<Step title="Add reference for the Kubernetes secret containing the identity credentials">
|
||||||
Once the secret is created, add the `secretName` and `secretNamespace` of the secret that was just created under `authentication.universalAuth.credentialsRef` field in the InfisicalSecret resource.
|
Once the secret is created, add the `secretName` and `secretNamespace` of the secret that was just created under `authentication.universalAuth.credentialsRef` field in the InfisicalSecret resource.
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
Make sure to also populate the `secretsScope` field with the project slug
|
||||||
|
_`projectSlug`_, environment slug _`envSlug`_, and secrets path
|
||||||
|
_`secretsPath`_ that you want to fetch secrets from. Please see the example
|
||||||
|
below.
|
||||||
|
</Info>
|
||||||
|
|
||||||
<Info>
|
## Example
|
||||||
Make sure to also populate the `secretsScope` field with the project slug _`projectSlug`_, environment slug _`envSlug`_, and secrets path _`secretsPath`_ that you want to fetch secrets from. Please see the example below.
|
|
||||||
</Info>
|
```yaml
|
||||||
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
|
kind: InfisicalSecret
|
||||||
|
metadata:
|
||||||
|
name: infisicalsecret-sample-crd
|
||||||
|
spec:
|
||||||
|
authentication:
|
||||||
|
universalAuth:
|
||||||
|
secretsScope:
|
||||||
|
projectSlug: <project-slug> # <-- project slug
|
||||||
|
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
||||||
|
secretsPath: "<secrets-path>" # Root is "/"
|
||||||
|
credentialsRef:
|
||||||
|
secretName: universal-auth-credentials # <-- name of the Kubernetes secret that stores our machine identity credentials
|
||||||
|
secretNamespace: default # <-- namespace of the Kubernetes secret that stores our machine identity credentials
|
||||||
|
...
|
||||||
|
```
|
||||||
|
|
||||||
## Example
|
|
||||||
```yaml
|
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
|
||||||
kind: InfisicalSecret
|
|
||||||
metadata:
|
|
||||||
name: infisicalsecret-sample-crd
|
|
||||||
spec:
|
|
||||||
authentication:
|
|
||||||
universalAuth:
|
|
||||||
secretsScope:
|
|
||||||
projectSlug: <project-slug> # <-- project slug
|
|
||||||
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
|
||||||
secretsPath: "<secrets-path>" # Root is "/"
|
|
||||||
credentialsRef:
|
|
||||||
secretName: universal-auth-credentials # <-- name of the Kubernetes secret that stores our machine identity credentials
|
|
||||||
secretNamespace: default # <-- namespace of the Kubernetes secret that stores our machine identity credentials
|
|
||||||
...
|
|
||||||
```
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication.serviceToken">
|
<Accordion title="authentication.serviceToken">
|
||||||
<Warning>
|
<Warning>
|
||||||
Service tokens are deprecated and will be removed in the near future. Please use Machine Identities (Universal Auth) for authenticating with Infisical.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
The service token required to authenticate with Infisical needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores this service token.
|
The service token required to authenticate with Infisical needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores this service token.
|
||||||
Follow the instructions below to create and store the service token in a Kubernetes secrets and reference it in your CRD.
|
Follow the instructions below to create and store the service token in a Kubernetes secrets and reference it in your CRD.
|
||||||
|
|
||||||
#### 1. Generate service token
|
#### 1. Generate service token
|
||||||
|
|
||||||
You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
|
You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
|
||||||
|
|
||||||
#### 2. Create Kubernetes secret containing service token
|
#### 2. Create Kubernetes secret containing service token
|
||||||
|
|
||||||
Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
|
Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
|
||||||
To quickly create a Kubernetes secret containing the generated service token, you can run the command below. Make sure you replace `<your-service-token-here>` with your service token.
|
To quickly create a Kubernetes secret containing the generated service token, you can run the command below. Make sure you replace `<your-service-token-here>` with your service token.
|
||||||
|
|
||||||
``` bash
|
```bash
|
||||||
kubectl create secret generic service-token --from-literal=infisicalToken="<your-service-token-here>"
|
kubectl create secret generic service-token --from-literal=infisicalToken="<your-service-token-here>"
|
||||||
```
|
```
|
||||||
|
|
||||||
#### 3. Add reference for the Kubernetes secret containing service token
|
#### 3. Add reference for the Kubernetes secret containing service token
|
||||||
|
|
||||||
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
|
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
|
||||||
|
|
||||||
<Info>
|
{" "}
|
||||||
Make sure to also populate the `secretsScope` field with the, environment slug _`envSlug`_, and secrets path _`secretsPath`_ that you want to fetch secrets from. Please see the example below.
|
|
||||||
</Info>
|
<Info>
|
||||||
|
Make sure to also populate the `secretsScope` field with the, environment slug
|
||||||
|
_`envSlug`_, and secrets path _`secretsPath`_ that you want to fetch secrets
|
||||||
|
from. Please see the example below.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
## Example
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
|
kind: InfisicalSecret
|
||||||
|
metadata:
|
||||||
|
name: infisicalsecret-sample-crd
|
||||||
|
spec:
|
||||||
|
authentication:
|
||||||
|
serviceToken:
|
||||||
|
serviceTokenSecretReference:
|
||||||
|
secretName: service-token # <-- name of the Kubernetes secret that stores our service token
|
||||||
|
secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
|
||||||
|
secretsScope:
|
||||||
|
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
||||||
|
secretsPath: <secrets-path> # Root is "/"
|
||||||
|
...
|
||||||
|
```
|
||||||
|
|
||||||
## Example
|
|
||||||
```yaml
|
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
|
||||||
kind: InfisicalSecret
|
|
||||||
metadata:
|
|
||||||
name: infisicalsecret-sample-crd
|
|
||||||
spec:
|
|
||||||
authentication:
|
|
||||||
serviceToken:
|
|
||||||
serviceTokenSecretReference:
|
|
||||||
secretName: service-token # <-- name of the Kubernetes secret that stores our service token
|
|
||||||
secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
|
|
||||||
secretsScope:
|
|
||||||
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
|
||||||
secretsPath: <secrets-path> # Root is "/"
|
|
||||||
...
|
|
||||||
```
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="managedSecretReference">
|
<Accordion title="managedSecretReference">
|
||||||
@@ -246,11 +263,13 @@ Creation polices allow you to control whether or not owner references should be
|
|||||||
This is useful for tools such as ArgoCD, where every resource requires an owner reference; otherwise, it will be pruned automatically.
|
This is useful for tools such as ArgoCD, where every resource requires an owner reference; otherwise, it will be pruned automatically.
|
||||||
|
|
||||||
#### Available options
|
#### Available options
|
||||||
|
|
||||||
- `Orphan` (default)
|
- `Orphan` (default)
|
||||||
- `Owner`
|
- `Owner`
|
||||||
|
|
||||||
<Tip>
|
<Tip>
|
||||||
When creation policy is set to `Owner`, the `InfisicalSecret` CRD must be in the same namespace as where the managed kubernetes secret.
|
When creation policy is set to `Owner`, the `InfisicalSecret` CRD must be in
|
||||||
|
the same namespace as where the managed kubernetes secret.
|
||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
@@ -282,8 +301,7 @@ This would result in the following managed secret to be created:
|
|||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
data:
|
data: ...
|
||||||
...
|
|
||||||
kind: Secret
|
kind: Secret
|
||||||
metadata:
|
metadata:
|
||||||
annotations:
|
annotations:
|
||||||
@@ -295,10 +313,11 @@ metadata:
|
|||||||
namespace: default
|
namespace: default
|
||||||
type: Opaque
|
type: Opaque
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
|
||||||
### Apply the Infisical CRD to your cluster
|
### Apply the Infisical CRD to your cluster
|
||||||
|
|
||||||
Once you have configured the Infisical CRD with the required fields, you can apply it to your cluster.
|
Once you have configured the Infisical CRD with the required fields, you can apply it to your cluster.
|
||||||
After applying, you should notice that the managed secret has been created in the desired namespace your specified.
|
After applying, you should notice that the managed secret has been created in the desired namespace your specified.
|
||||||
|
|
||||||
@@ -321,47 +340,48 @@ kubectl get secrets -n <namespace of managed secret>
|
|||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
### Using managed secret in your deployment
|
### Using managed secret in your deployment
|
||||||
|
|
||||||
Incorporating the managed secret created by the operator into your deployment can be achieved through several methods.
|
Incorporating the managed secret created by the operator into your deployment can be achieved through several methods.
|
||||||
Here, we will highlight three of the most common ways to utilize it. Learn more about Kubernetes secrets [here](https://kubernetes.io/docs/concepts/configuration/secret/)
|
Here, we will highlight three of the most common ways to utilize it. Learn more about Kubernetes secrets [here](https://kubernetes.io/docs/concepts/configuration/secret/)
|
||||||
|
|
||||||
<Accordion title="envFrom">
|
<Accordion title="envFrom">
|
||||||
This will take all the secrets from your managed secret and expose them to your container
|
This will take all the secrets from your managed secret and expose them to your container
|
||||||
|
|
||||||
```yaml
|
````yaml
|
||||||
envFrom:
|
envFrom:
|
||||||
- secretRef:
|
- secretRef:
|
||||||
name: managed-secret # managed secret name
|
name: managed-secret # managed secret name
|
||||||
```
|
|
||||||
|
|
||||||
Example usage in a deployment
|
|
||||||
```yaml
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: nginx-deployment
|
|
||||||
labels:
|
|
||||||
app: nginx
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: nginx
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: nginx
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: nginx
|
|
||||||
image: nginx:1.14.2
|
|
||||||
envFrom:
|
|
||||||
- secretRef:
|
|
||||||
name: managed-secret # <- name of managed secret
|
|
||||||
ports:
|
|
||||||
- containerPort: 80
|
|
||||||
```
|
```
|
||||||
</Accordion>
|
|
||||||
|
|
||||||
|
Example usage in a deployment
|
||||||
|
```yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: nginx-deployment
|
||||||
|
labels:
|
||||||
|
app: nginx
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: nginx
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: nginx
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: nginx
|
||||||
|
image: nginx:1.14.2
|
||||||
|
envFrom:
|
||||||
|
- secretRef:
|
||||||
|
name: managed-secret # <- name of managed secret
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
````
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="env">
|
<Accordion title="env">
|
||||||
This will allow you to select individual secrets by key name from your managed secret and expose them to your container
|
This will allow you to select individual secrets by key name from your managed secret and expose them to your container
|
||||||
@@ -375,95 +395,101 @@ Here, we will highlight three of the most common ways to utilize it. Learn more
|
|||||||
key: SOME_SECRET_KEY # The name of the key which exists in the managed secret
|
key: SOME_SECRET_KEY # The name of the key which exists in the managed secret
|
||||||
```
|
```
|
||||||
|
|
||||||
Example usage in a deployment
|
Example usage in a deployment
|
||||||
```yaml
|
|
||||||
apiVersion: apps/v1
|
```yaml
|
||||||
kind: Deployment
|
apiVersion: apps/v1
|
||||||
metadata:
|
kind: Deployment
|
||||||
name: nginx-deployment
|
metadata:
|
||||||
labels:
|
name: nginx-deployment
|
||||||
app: nginx
|
labels:
|
||||||
spec:
|
app: nginx
|
||||||
replicas: 1
|
spec:
|
||||||
selector:
|
replicas: 1
|
||||||
matchLabels:
|
selector:
|
||||||
app: nginx
|
matchLabels:
|
||||||
template:
|
app: nginx
|
||||||
metadata:
|
template:
|
||||||
labels:
|
metadata:
|
||||||
app: nginx
|
labels:
|
||||||
spec:
|
app: nginx
|
||||||
containers:
|
spec:
|
||||||
- name: nginx
|
containers: - name: nginx
|
||||||
image: nginx:1.14.2
|
image: nginx:1.14.2
|
||||||
env:
|
env: - name: STRIPE_API_SECRET
|
||||||
- name: STRIPE_API_SECRET
|
valueFrom:
|
||||||
valueFrom:
|
secretKeyRef:
|
||||||
secretKeyRef:
|
name: managed-secret # <- name of managed secret
|
||||||
name: managed-secret # <- name of managed secret
|
key: STRIPE_API_SECRET
|
||||||
key: STRIPE_API_SECRET
|
ports: - containerPort: 80
|
||||||
ports:
|
|
||||||
- containerPort: 80
|
```
|
||||||
```
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="volumes">
|
<Accordion title="volumes">
|
||||||
This will allow you to create a volume on your container which comprises of files holding the secrets in your managed kubernetes secret
|
This will allow you to create a volume on your container which comprises of files holding the secrets in your managed kubernetes secret
|
||||||
```yaml
|
```yaml
|
||||||
volumes:
|
volumes:
|
||||||
- name: secrets-volume-name # The name of the volume under which secrets will be stored
|
- name: secrets-volume-name # The name of the volume under which secrets will be stored
|
||||||
secret:
|
secret:
|
||||||
secretName: managed-secret # managed secret name
|
secretName: managed-secret # managed secret name
|
||||||
```
|
````
|
||||||
|
|
||||||
You can then mount this volume to the container's filesystem so that your deployment can access the files containing the managed secrets
|
You can then mount this volume to the container's filesystem so that your deployment can access the files containing the managed secrets
|
||||||
```yaml
|
|
||||||
volumeMounts:
|
|
||||||
- name: secrets-volume-name
|
|
||||||
mountPath: /etc/secrets
|
|
||||||
readOnly: true
|
|
||||||
```
|
|
||||||
|
|
||||||
Example usage in a deployment
|
```yaml
|
||||||
```yaml
|
volumeMounts:
|
||||||
apiVersion: apps/v1
|
- name: secrets-volume-name
|
||||||
kind: Deployment
|
mountPath: /etc/secrets
|
||||||
metadata:
|
readOnly: true
|
||||||
name: nginx-deployment
|
```
|
||||||
labels:
|
|
||||||
|
Example usage in a deployment
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: nginx-deployment
|
||||||
|
labels:
|
||||||
|
app: nginx
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
app: nginx
|
app: nginx
|
||||||
spec:
|
template:
|
||||||
replicas: 1
|
metadata:
|
||||||
selector:
|
labels:
|
||||||
matchLabels:
|
|
||||||
app: nginx
|
app: nginx
|
||||||
template:
|
spec:
|
||||||
metadata:
|
containers:
|
||||||
labels:
|
|
||||||
app: nginx
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: nginx
|
- name: nginx
|
||||||
image: nginx:1.14.2
|
image: nginx:1.14.2
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: secrets-volume-name
|
- name: secrets-volume-name
|
||||||
mountPath: /etc/secrets
|
mountPath: /etc/secrets
|
||||||
readOnly: true
|
readOnly: true
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 80
|
- containerPort: 80
|
||||||
volumes:
|
volumes:
|
||||||
- name: secrets-volume-name
|
- name: secrets-volume-name
|
||||||
secret:
|
secret:
|
||||||
secretName: managed-secret # <- managed secrets
|
secretName: managed-secret # <- managed secrets
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
## Auto redeployment
|
## Auto redeployment
|
||||||
|
|
||||||
Deployments using managed secrets don't reload automatically on updates, so they may use outdated secrets unless manually redeployed.
|
Deployments using managed secrets don't reload automatically on updates, so they may use outdated secrets unless manually redeployed.
|
||||||
To address this, we added functionality to automatically redeploy your deployment when its managed secret updates.
|
To address this, we added functionality to automatically redeploy your deployment when its managed secret updates.
|
||||||
|
|
||||||
### Enabling auto redeploy
|
### Enabling auto redeploy
|
||||||
|
|
||||||
To enable auto redeployment you simply have to add the following annotation to the deployment that consumes a managed secret
|
To enable auto redeployment you simply have to add the following annotation to the deployment that consumes a managed secret
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
secrets.infisical.com/auto-reload: "true"
|
secrets.infisical.com/auto-reload: "true"
|
||||||
```
|
```
|
||||||
@@ -500,16 +526,18 @@ spec:
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
## Global configuration
|
## Global configuration
|
||||||
|
|
||||||
To configure global settings that will apply to all instances of `InfisicalSecret`, you can define these configurations in a Kubernetes ConfigMap.
|
To configure global settings that will apply to all instances of `InfisicalSecret`, you can define these configurations in a Kubernetes ConfigMap.
|
||||||
For example, you can configure all `InfisicalSecret` instances to fetch secrets from a single backend API without specifying the `hostAPI` parameter for each instance.
|
For example, you can configure all `InfisicalSecret` instances to fetch secrets from a single backend API without specifying the `hostAPI` parameter for each instance.
|
||||||
|
|
||||||
### Available global properties
|
### Available global properties
|
||||||
| Property | Description | Default value
|
|
||||||
| -------- | ------------------------------------- |------------------------
|
|
||||||
| hostAPI | If `hostAPI` in `InfisicalSecret` instance is left empty, this value will be used | https://app.infisical.com/api
|
|
||||||
|
|
||||||
|
| Property | Description | Default value |
|
||||||
|
| -------- | --------------------------------------------------------------------------------- | ----------------------------- |
|
||||||
|
| hostAPI | If `hostAPI` in `InfisicalSecret` instance is left empty, this value will be used | https://app.infisical.com/api |
|
||||||
|
|
||||||
### Applying global configurations
|
### Applying global configurations
|
||||||
|
|
||||||
All global configurations must reside in a Kubernetes ConfigMap named `infisical-config` in the namespace `infisical-operator-system`.
|
All global configurations must reside in a Kubernetes ConfigMap named `infisical-config` in the namespace `infisical-operator-system`.
|
||||||
To apply global configuration to the operator, copy the following yaml into `infisical-config.yaml` file.
|
To apply global configuration to the operator, copy the following yaml into `infisical-config.yaml` file.
|
||||||
|
|
||||||
@@ -534,7 +562,6 @@ Then apply this change via kubectl by running the following
|
|||||||
kubectl apply -f infisical-config.yaml
|
kubectl apply -f infisical-config.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
## Troubleshoot operator
|
## Troubleshoot operator
|
||||||
|
|
||||||
If the operator is unable to fetch secrets from the API, it will not affect the managed Kubernetes secret.
|
If the operator is unable to fetch secrets from the API, it will not affect the managed Kubernetes secret.
|
||||||
@@ -583,7 +610,6 @@ The managed secret created by the operator will not be deleted when the operator
|
|||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|
||||||
## Useful Articles
|
## Useful Articles
|
||||||
|
|
||||||
- [Managing secrets in OpenShift with Infisical](https://xphyr.net/post/infisical_ocp/)
|
- [Managing secrets in OpenShift with Infisical](https://xphyr.net/post/infisical_ocp/)
|
||||||
|
|||||||
@@ -4,7 +4,10 @@ description: "Understanding service tokens and their best practices."
|
|||||||
---
|
---
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Service tokens are deprecated and will be removed in the future. Please use the [machine identity](/documentation/platform/identities/machine-identities) approach instead.
|
Service tokens are being deprecated in favor of [machine identities](/documentation/platform/identities/machine-identities).
|
||||||
|
|
||||||
|
They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
|
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
Many clients use service tokens to authenticate and read/write secrets from/to Infisical; they can be created in your project settings.
|
Many clients use service tokens to authenticate and read/write secrets from/to Infisical; they can be created in your project settings.
|
||||||
@@ -32,6 +35,7 @@ Consider the token `st.abc.def.ghi`. Here, `st.abc.def` can be used to authentic
|
|||||||
|
|
||||||
Note that when using service tokens via select client methods like SDK or CLI, cryptographic operations are abstracted for you that is the token is parsed and encryption/decryption operations are handled. If using service tokens with the REST API and end-to-end encryption enabled, then you will have to handle the encryption/decryption operations yourself.
|
Note that when using service tokens via select client methods like SDK or CLI, cryptographic operations are abstracted for you that is the token is parsed and encryption/decryption operations are handled. If using service tokens with the REST API and end-to-end encryption enabled, then you will have to handle the encryption/decryption operations yourself.
|
||||||
|
|
||||||
|
|
||||||
## Recommendations
|
## Recommendations
|
||||||
|
|
||||||
### Issuance
|
### Issuance
|
||||||
|
|||||||
+9
-30
@@ -32,10 +32,7 @@
|
|||||||
"thumbsRating": true
|
"thumbsRating": true
|
||||||
},
|
},
|
||||||
"api": {
|
"api": {
|
||||||
"baseUrl": [
|
"baseUrl": ["https://app.infisical.com", "http://localhost:8080"]
|
||||||
"https://app.infisical.com",
|
|
||||||
"http://localhost:8080"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
"topbarLinks": [
|
"topbarLinks": [
|
||||||
{
|
{
|
||||||
@@ -76,11 +73,7 @@
|
|||||||
"documentation/getting-started/introduction",
|
"documentation/getting-started/introduction",
|
||||||
{
|
{
|
||||||
"group": "Quickstart",
|
"group": "Quickstart",
|
||||||
"pages": [
|
"pages": ["documentation/guides/local-development"]
|
||||||
"documentation/guides/local-development",
|
|
||||||
"documentation/guides/staging",
|
|
||||||
"documentation/guides/production"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Guides",
|
"group": "Guides",
|
||||||
@@ -374,15 +367,11 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Build Tool Integrations",
|
"group": "Build Tool Integrations",
|
||||||
"pages": [
|
"pages": ["integrations/build-tools/gradle"]
|
||||||
"integrations/build-tools/gradle"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "",
|
"group": "",
|
||||||
"pages": [
|
"pages": ["sdks/overview"]
|
||||||
"sdks/overview"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "SDK's",
|
"group": "SDK's",
|
||||||
@@ -400,9 +389,7 @@
|
|||||||
"api-reference/overview/authentication",
|
"api-reference/overview/authentication",
|
||||||
{
|
{
|
||||||
"group": "Examples",
|
"group": "Examples",
|
||||||
"pages": [
|
"pages": ["api-reference/overview/examples/integration"]
|
||||||
"api-reference/overview/examples/integration"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -531,15 +518,11 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Service Tokens",
|
"group": "Service Tokens",
|
||||||
"pages": [
|
"pages": ["api-reference/endpoints/service-tokens/get"]
|
||||||
"api-reference/endpoints/service-tokens/get"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Audit Logs",
|
"group": "Audit Logs",
|
||||||
"pages": [
|
"pages": ["api-reference/endpoints/audit-logs/export-audit-log"]
|
||||||
"api-reference/endpoints/audit-logs/export-audit-log"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -555,9 +538,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "",
|
"group": "",
|
||||||
"pages": [
|
"pages": ["changelog/overview"]
|
||||||
"changelog/overview"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Contributing",
|
"group": "Contributing",
|
||||||
@@ -581,9 +562,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Contributing to SDK",
|
"group": "Contributing to SDK",
|
||||||
"pages": [
|
"pages": ["contributing/sdk/developing"]
|
||||||
"contributing/sdk/developing"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user