mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
misc: doc updates
This commit is contained in:
@@ -11,7 +11,7 @@ The Infisical Gateway provides secure access to private resources within your ne
|
||||
**Architecture Components:**
|
||||
|
||||
- **Gateway**: Lightweight agent deployed within your VPCs that provides access to private resources
|
||||
- **Proxy**: Identity-aware relay infrastructure that routes encrypted traffic (instance-wide or organization-specific)
|
||||
- **Relay**: Infrastructure that routes encrypted traffic (instance-wide or organization-specific)
|
||||
|
||||
Common use cases include generating dynamic credentials or rotating credentials for private databases.
|
||||
|
||||
@@ -26,8 +26,8 @@ Common use cases include generating dynamic credentials or rotating credentials
|
||||
|
||||
The Gateway system uses SSH reverse tunnels for secure, firewall-friendly connectivity:
|
||||
|
||||
1. **Gateway Registration**: The gateway establishes an outbound SSH reverse tunnel to a proxy server using SSH certificates issued by Infisical
|
||||
2. **Proxy Routing**: The proxy server acts as an identity-aware relay that routes encrypted traffic between the Infisical platform and gateways
|
||||
1. **Gateway Registration**: The gateway establishes an outbound SSH reverse tunnel to a relay server using SSH certificates issued by Infisical
|
||||
2. **Relay Routing**: The relay server routes encrypted traffic between the Infisical platform and gateways
|
||||
3. **Resource Access**: The Infisical platform connects to your private resources through the established gateway connections
|
||||
|
||||
**Key Benefits:**
|
||||
@@ -39,18 +39,18 @@ The Gateway system uses SSH reverse tunnels for secure, firewall-friendly connec
|
||||
|
||||
## Deployment
|
||||
|
||||
The Infisical Gateway is integrated into the Infisical CLI under the `network gateway` command, making it simple to deploy and manage.
|
||||
The Infisical Gateway is integrated into the Infisical CLI under the `gateway` command, making it simple to deploy and manage.
|
||||
You can install the Gateway in all the same ways you install the Infisical CLI—whether via npm, Docker, or a binary.
|
||||
For detailed installation instructions, refer to the Infisical [CLI Installation instructions](/cli/overview).
|
||||
|
||||
**Prerequisites:**
|
||||
|
||||
1. **Proxy Server**: Before deploying gateways, you need a running proxy server:
|
||||
- **Infisical Cloud**: Instance proxies are already available - no setup needed
|
||||
- **Self-hosted**: Instance admin must set up shared instance proxies, or organizations can deploy their own
|
||||
1. **Relay Server**: Before deploying gateways, you need a running relay server:
|
||||
- **Infisical Cloud**: Instance relays are already available - no setup needed
|
||||
- **Self-hosted**: Instance admin must set up shared instance relays, or organizations can deploy their own
|
||||
2. **Machine Identity**: Configure a machine identity with appropriate permissions to create and manage gateways
|
||||
|
||||
Once authenticated, the Gateway establishes an SSH reverse tunnel to the specified proxy server, allowing secure access to your private resources.
|
||||
Once authenticated, the Gateway establishes an SSH reverse tunnel to the specified relay server, allowing secure access to your private resources.
|
||||
|
||||
### Get started
|
||||
|
||||
@@ -66,25 +66,25 @@ Once authenticated, the Gateway establishes an SSH reverse tunnel to the specifi
|
||||
You'll need to choose an authentication method to initiate communication with Infisical. View the available machine identity authentication methods [here](/documentation/platform/identities/machine-identities).
|
||||
</Step>
|
||||
|
||||
<Step title="Choose Your Proxy Setup">
|
||||
You have two options for proxy infrastructure:
|
||||
<Step title="Choose Your Relay Setup">
|
||||
You have two options for relay infrastructure:
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Use Instance Proxies (Easiest)">
|
||||
**Infisical Cloud:** Instance proxies are already running and available - **no setup required**. You can immediately proceed to deploy gateways using these shared proxies.
|
||||
<Tab title="Use Instance Relays (Easiest)">
|
||||
**Infisical Cloud:** Instance relays are already running and available - **no setup required**. You can immediately proceed to deploy gateways using these shared relays.
|
||||
|
||||
**Self-hosted:** If your instance admin has set up shared instance proxies, you can use them directly. If not, the instance admin can set them up:
|
||||
**Self-hosted:** If your instance admin has set up shared instance relays, you can use them directly. If not, the instance admin can set them up:
|
||||
```bash
|
||||
# Instance admin sets up shared proxy (one-time setup)
|
||||
export INFISICAL_PROXY_AUTH_SECRET=<instance-proxy-secret>
|
||||
infisical network proxy --type=instance --ip=<public-ip> --name=<proxy-name>
|
||||
# Instance admin sets up shared relay (one-time setup)
|
||||
export INFISICAL_RELAY_AUTH_SECRET=<instance-relay-secret>
|
||||
infisical relay start --type=instance --ip=<public-ip> --name=<relay-name>
|
||||
```
|
||||
</Tab>
|
||||
<Tab title="Deploy Your Own Organization Proxy">
|
||||
**Available for all users:** Deploy your own dedicated proxy infrastructure for enhanced control:
|
||||
<Tab title="Deploy Your Own Organization Relay">
|
||||
**Available for all users:** Deploy your own dedicated relay infrastructure for enhanced control:
|
||||
```bash
|
||||
# Deploy organization-specific proxy
|
||||
infisical network proxy --type=org --ip=<public-ip> --name=<proxy-name> --auth-method=universal-auth --client-id=<client-id> --client-secret=<client-secret>
|
||||
# Deploy organization-specific relay
|
||||
infisical relay start --type=org --ip=<public-ip> --name=<relay-name> --auth-method=universal-auth --client-id=<client-id> --client-secret=<client-secret>
|
||||
```
|
||||
|
||||
**When to choose this:**
|
||||
@@ -103,7 +103,7 @@ Once authenticated, the Gateway establishes an SSH reverse tunnel to the specifi
|
||||
<Tab title="Production (systemd)">
|
||||
For production deployments on Linux, install the Gateway as a systemd service:
|
||||
```bash
|
||||
sudo infisical network gateway install --token <your-machine-identity-token> --domain <your-infisical-domain> --name <gateway-name> --proxy-name <proxy-name>
|
||||
sudo infisical gateway systemd install --token <your-machine-identity-token> --domain <your-infisical-domain> --name <gateway-name> --relay <relay-name>
|
||||
sudo systemctl start infisical-gateway
|
||||
```
|
||||
This will install and start the Gateway as a secure systemd service that:
|
||||
@@ -170,7 +170,7 @@ Once authenticated, the Gateway establishes an SSH reverse tunnel to the specifi
|
||||
--from-literal=INFISICAL_AUTH_METHOD=universal-auth \
|
||||
--from-literal=INFISICAL_UNIVERSAL_AUTH_CLIENT_ID=<client-id> \
|
||||
--from-literal=INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET=<client-secret> \
|
||||
--from-literal=INFISICAL_PROXY_NAME=<proxy-name> \
|
||||
--from-literal=INFISICAL_RELAY_NAME=<relay-name> \
|
||||
--from-literal=INFISICAL_GATEWAY_NAME=<gateway-name>
|
||||
```
|
||||
|
||||
@@ -343,8 +343,8 @@ Once authenticated, the Gateway establishes an SSH reverse tunnel to the specifi
|
||||
In addition to the authentication method above, you **must** include these required variables:
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="INFISICAL_PROXY_NAME">
|
||||
The name of the proxy server that this gateway should connect to.
|
||||
<Accordion title="INFISICAL_RELAY_NAME">
|
||||
The name of the relay server that this gateway should connect to.
|
||||
</Accordion>
|
||||
<Accordion title="INFISICAL_GATEWAY_NAME">
|
||||
The name of this gateway instance.
|
||||
@@ -357,7 +357,7 @@ Once authenticated, the Gateway establishes an SSH reverse tunnel to the specifi
|
||||
--from-literal=INFISICAL_AUTH_METHOD=universal-auth \
|
||||
--from-literal=INFISICAL_UNIVERSAL_AUTH_CLIENT_ID=<client-id> \
|
||||
--from-literal=INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET=<client-secret> \
|
||||
--from-literal=INFISICAL_PROXY_NAME=<proxy-name> \
|
||||
--from-literal=INFISICAL_RELAY_NAME=<relay-name> \
|
||||
--from-literal=INFISICAL_GATEWAY_NAME=<gateway-name>
|
||||
```
|
||||
|
||||
@@ -388,8 +388,8 @@ Once authenticated, the Gateway establishes an SSH reverse tunnel to the specifi
|
||||
INF Starting gateway
|
||||
INF Starting gateway certificate renewal goroutine
|
||||
INF Successfully registered gateway and received certificates
|
||||
INF Connecting to proxy server infisical-start on 152.42.218.156:2222...
|
||||
INF Proxy connection established for gateway
|
||||
INF Connecting to relay server infisical-start on 152.42.218.156:2222...
|
||||
INF Relay connection established for gateway
|
||||
```
|
||||
|
||||
</Tab>
|
||||
@@ -397,29 +397,29 @@ Once authenticated, the Gateway establishes an SSH reverse tunnel to the specifi
|
||||
<Tab title="Local Installation (testing)">
|
||||
For development or testing, you can run the Gateway directly. Log in with your machine identity and start the Gateway in one command:
|
||||
```bash
|
||||
infisical network gateway --token $(infisical login --method=universal-auth --client-id=<> --client-secret=<> --plain) --proxy-name=<proxy-name> --name=<gateway-name>
|
||||
infisical gateway start --token $(infisical login --method=universal-auth --client-id=<> --client-secret=<> --plain) --relay=<relay-name> --name=<gateway-name>
|
||||
```
|
||||
|
||||
Alternatively, if you already have the token, use it directly with the `--token` flag:
|
||||
```bash
|
||||
infisical network gateway --token <your-machine-identity-token> --proxy-name=<proxy-name> --name=<gateway-name>
|
||||
infisical gateway start --token <your-machine-identity-token> --relay=<relay-name> --name=<gateway-name>
|
||||
```
|
||||
|
||||
Or set it as an environment variable:
|
||||
```bash
|
||||
export INFISICAL_TOKEN=<your-machine-identity-token>
|
||||
infisical network gateway --proxy-name=<proxy-name> --name=<gateway-name>
|
||||
infisical gateway start --relay=<relay-name> --name=<gateway-name>
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
For detailed information about the network commands and their options, see the [network command documentation](/cli/commands/network).
|
||||
For detailed information about the gateway commands and their options, see the [gateway command documentation](/cli/commands/gateway).
|
||||
|
||||
<Note>
|
||||
**Requirements:**
|
||||
- Ensure the deployed Gateway has network access to the private resources you intend to connect with Infisical
|
||||
- The gateway must be able to reach the proxy server (outbound connection only)
|
||||
- Replace `<proxy-name>` with the name of your proxy server and `<gateway-name>` with a unique name for this gateway
|
||||
- The gateway must be able to reach the relay server (outbound connection only)
|
||||
- Replace `<relay-name>` with the name of your relay server and `<gateway-name>` with a unique name for this gateway
|
||||
</Note>
|
||||
|
||||
</Step>
|
||||
|
||||
Reference in New Issue
Block a user