mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-02 17:25:44 +00:00
Add self-hosting docs for Fly.io
This commit is contained in:
Binary file not shown.
|
After Width: | Height: | Size: 568 KiB |
+2
-1
@@ -162,7 +162,8 @@
|
|||||||
"self-hosting/deployment-options/kubernetes-helm",
|
"self-hosting/deployment-options/kubernetes-helm",
|
||||||
"self-hosting/deployment-options/aws-ec2",
|
"self-hosting/deployment-options/aws-ec2",
|
||||||
"self-hosting/deployment-options/docker-compose",
|
"self-hosting/deployment-options/docker-compose",
|
||||||
"self-hosting/deployment-options/digital-ocean-marketplace"
|
"self-hosting/deployment-options/digital-ocean-marketplace",
|
||||||
|
"self-hosting/deployment-options/fly.io"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"self-hosting/configuration/envars",
|
"self-hosting/configuration/envars",
|
||||||
|
|||||||
@@ -18,15 +18,14 @@ Other environment variables are listed below to increase the functionality of yo
|
|||||||
Must be a random 32 byte base64 string. Can be generated with `openssl rand -base64 32`
|
Must be a random 32 byte base64 string. Can be generated with `openssl rand -base64 32`
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField query="MONGO_URL" type="string" default="none" required>
|
<ParamField query="MONGO_URL" type="string" default="none" required>
|
||||||
*TLS based connection string is not yet supported
|
Mongo connection string. *TLS based connection string is not yet supported
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField query="REDIS_URL" type="string" default="none" required>
|
<ParamField query="REDIS_URL" type="string" default="none" required>
|
||||||
Redis connection string
|
Redis connection string
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
</Tab>
|
||||||
</Tab>
|
|
||||||
<Tab title="Email service">
|
<Tab title="Email service">
|
||||||
<Info>When email service is not configured, Infisical will have limited functionality</Info>
|
<Info>When email service is not configured, Infisical will have limited functionality</Info>
|
||||||
|
|
||||||
|
|||||||
@@ -1,63 +1,108 @@
|
|||||||
---
|
---
|
||||||
title: "Fly.io"
|
title: "Fly.io"
|
||||||
description: "Learn to install Infisical on Fly.io"
|
description: "Deploy Infisical with Fly.io"
|
||||||
---
|
---
|
||||||
|
|
||||||
**Prerequisites**
|
Prerequisites:
|
||||||
- Familiar with Fly.io deployment
|
- Have an account with [Fly.io](https://fly.io/)
|
||||||
- Logged in via fly CLI
|
- Have installed the [Fly.io CLI](https://fly.io/docs/hands-on/install-flyctl/)
|
||||||
|
|
||||||
#### 1. Make a copy of the deployment config
|
<Steps>
|
||||||
To begin, you'll to make a copy of the following file on your local machine
|
<Step title="Create an app with Fly.io">
|
||||||
|
In your terminal, run the following command from the source directory of your project to create a new Fly.io app
|
||||||
|
with a `fly.toml` configuration file:
|
||||||
|
|
||||||
|
```
|
||||||
|
fly launch
|
||||||
|
```
|
||||||
|
</Step>
|
||||||
|
<Step title="Edit the fly.toml configuration file">
|
||||||
|
Add a **build** section to the `fly.toml` file to specify the [Infisical public Docker image](https://hub.docker.com/r/infisical/infisical):
|
||||||
|
|
||||||
```toml fly.toml
|
```
|
||||||
# fly.toml app configuration file generated for infisical on 2023-05-05T08:57:03-04:00
|
[build]
|
||||||
#
|
image = "infisical/infisical:v0.43.4"
|
||||||
# See https://fly.io/docs/reference/configuration/ for information about how to use this file.
|
```
|
||||||
#
|
|
||||||
|
|
||||||
app = "infisical"
|
Afterwards, your `fly.toml` file should look similar to:
|
||||||
primary_region = "iad"
|
|
||||||
|
|
||||||
[build]
|
```
|
||||||
image = "infisical/infisical:latest"
|
app = "infisical"
|
||||||
|
primary_region = "lax"
|
||||||
|
|
||||||
[env]
|
[http_service]
|
||||||
ENCRYPTION_KEY = <>
|
internal_port = 8080
|
||||||
JWT_AUTH_SECRET = <>
|
force_https = true
|
||||||
JWT_REFRESH_SECRET = <>
|
auto_stop_machines = true
|
||||||
JWT_SERVICE_SECRET = <>
|
auto_start_machines = true
|
||||||
JWT_SIGNUP_SECRET = <>
|
min_machines_running = 0
|
||||||
MONGO_URL = <>
|
processes = ["app"]
|
||||||
|
|
||||||
[http_service]
|
[[vm]]
|
||||||
internal_port = 8080
|
cpu_kind = "shared"
|
||||||
|
cpus = 1
|
||||||
|
memory_mb = 1024
|
||||||
|
|
||||||
```
|
[build]
|
||||||
|
image = "infisical/infisical:v0.43.4"
|
||||||
|
```
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Depending on your use-case and requirements, you may find it helpful to further configure your `fly.toml` file
|
||||||
|
with options [here](https://fly.io/docs/reference/configuration/).
|
||||||
|
|
||||||
#### 2. Add environment variables
|
For example, you may want to adjust the `primary-region` option to specify which [region](https://fly.io/docs/reference/regions/) to create the new machine for your
|
||||||
|
instance of Infisical to minimize distance and therefore latency between the instance and your infrastructure.
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
</Step>
|
||||||
|
<Step title="Set secrets for your Fly.io app">
|
||||||
|
Running Infisical requires a few environment variables to be set on the Fly.io machine.
|
||||||
|
At minimum, Infisical requires that you set the variables `ENCRYPTION_KEY`, `AUTH_SECRET`, `MONGO_URL`, and `REDIS_URL`
|
||||||
|
which you can read more about [here](/self-hosting/configuration/envars).
|
||||||
|
|
||||||
|
For this step, we recommend setting the variables as Fly.io [app secrets](https://fly.io/docs/reference/secrets/) which
|
||||||
|
are made available to the app as environment variables. You can set the variables either via the Fly.io CLI or project [dashboard](https://fly.io/dashboard).
|
||||||
|
|
||||||
|
<Tabs>
|
||||||
|
<Tab title="CLI">
|
||||||
|
Run the following command (with each `VALUE` replaced) in the source directory of your project to set the required variables:
|
||||||
|
|
||||||
Before we can deploy Infisical, we'll need to provide values for the keys under `[env]` config block. For each of the following keys
|
```
|
||||||
|
flyctl secrets set ENCRYPTION_KEY=VALUE AUTH_SECRET=VALUE MONGO_URL=VALUE REDIS_URL=VALUE...
|
||||||
|
```
|
||||||
|
</Tab>
|
||||||
|
<Tab title="Dashboard">
|
||||||
|
In Fly.io, head to your Project > Secrets and add the required variables.
|
||||||
|
|
||||||
- `ENCRYPTION_KEY`
|

|
||||||
- `JWT_AUTH_SECRET`
|
</Tab>
|
||||||
- `JWT_REFRESH_SECRET`
|
</Tabs>
|
||||||
- `JWT_SERVICE_SECRET`
|
|
||||||
- `JWT_SIGNUP_SECRET`
|
<Note>
|
||||||
|
To use more features like emailing and single sign-on, you can set additional configuration options [here](/self-hosting/configuration/envars).
|
||||||
|
</Note>
|
||||||
|
</Step>
|
||||||
|
<Step title="Deploy the Fly.io app">
|
||||||
|
Finally, run the following command in the source directory of your project to deploy your Infisical instance on Fly.io
|
||||||
|
with the updated `fly.toml` configuration file from step 2 and secrets from step 3:
|
||||||
|
|
||||||
you will need to generate a random 16 byte hex string. This can can be generated with `openssl rand -hex 16`.
|
```
|
||||||
|
fly deploy
|
||||||
|
```
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
<AccordionGroup>
|
||||||
|
<Accordion title="Do you have any recommendations for deploying Infisical with Fly.io?">
|
||||||
|
Yes, here are a few that come to mind:
|
||||||
|
- In step 2, we recommend pinning the Docker image to a specific [version of Infisical](https://hub.docker.com/r/infisical/infisical/tags)
|
||||||
|
instead of referring to the `latest` tag to avoid any unexpected version-to-version migration issues.
|
||||||
|
- In step 2, we recommend selecting a `primary_region` option that is closest to your infrastructure/clients to reduce latency; a full list of regions supported by Fly.io can be found [here](https://fly.io/docs/reference/regions/).
|
||||||
|
|
||||||
|
We're working on putting together a fuller list of deployment best practices as well as minimum resource configuration requirements for running Infisical so stay tuned!
|
||||||
|
</Accordion>
|
||||||
|
</AccordionGroup>
|
||||||
|
|
||||||
Lastly, the `MONGO_URL` environment variable requires a document database connection URL.
|
Resources:
|
||||||
You can obtain this URL by creating a document database using services such as [MongoDB](https://www.mongodb.com/), [AWS DocumentDB](https://aws.amazon.com/documentdb/), and others.
|
- [Fly.io documentation](https://fly.io/docs/)
|
||||||
|
|
||||||
#### 3. Deploy
|
|
||||||
|
|
||||||
Run `fly launch` in the directory where you have the local version of config from step 1 and follow the instructions.
|
|
||||||
Once done, your very own instance of Infisical should be up and running on Fly.io.
|
|
||||||
|
|
||||||
Please note that this version of Infisical requires at least 250MB of memory to operate smoothly.
|
|
||||||
|
|
||||||
<Info>
|
|
||||||
Once installation is complete, you will have to create the first account. No default account is provided.
|
|
||||||
</Info>
|
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
title: "GCP Cloud Run"
|
||||||
|
description: "Deploy Infisical with GCP Cloud Run"
|
||||||
|
---
|
||||||
|
|
||||||
@@ -24,25 +24,23 @@ docker pull infisical/infisical:latest
|
|||||||
## Run with docker
|
## Run with docker
|
||||||
To run Infisical, we'll need to configure the required configs listed below.
|
To run Infisical, we'll need to configure the required configs listed below.
|
||||||
Other configs can be found [here](../configuration/envars)
|
Other configs can be found [here](../configuration/envars)
|
||||||
|
|
||||||
<ParamField query="ENCRYPTION_KEY" type="string" default="none" required>
|
<ParamField query="ENCRYPTION_KEY" type="string" default="none" required>
|
||||||
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex 16`
|
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex 16`
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField query="AUTH_SECRET" type="string" default="none" required>
|
<ParamField query="AUTH_SECRET" type="string" default="none" required>
|
||||||
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex 16`
|
Must be a random 32 byte base64 string. Can be generated with `openssl rand -base64 32`
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField query="MONGO_URL" type="string" default="none" required>
|
<ParamField query="MONGO_URL" type="string" default="none" required>
|
||||||
A MongoDB connection string. Can use any MongoDB PaaS such as Mongo Atlas, AWS Document DB, etc.
|
|
||||||
*TLS based connection string is not yet supported
|
*TLS based connection string is not yet supported
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField query="REDIS_URL" type="string" default="none">
|
<ParamField query="REDIS_URL" type="string" default="none" required>
|
||||||
Redis connection string. Only required if you plan to use web integrations or secret reminders.
|
Redis connection string
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
|
||||||
Once you have added the required environment variables to your docker run command, execute it in your terminal.
|
Once you have added the required environment variables to your docker run command, execute it in your terminal.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
@@ -33,10 +33,17 @@ Choose from a variety of deployment options listed below to get started.
|
|||||||
Install Infisical using our Docker Compose template
|
Install Infisical using our Docker Compose template
|
||||||
</Card>
|
</Card>
|
||||||
<Card
|
<Card
|
||||||
title="Kubernetes"
|
title="Kubernetes"
|
||||||
color="#ea5a0c"
|
color="#ea5a0c"
|
||||||
href="deployment-options/kubernetes-helm"
|
href="deployment-options/kubernetes-helm"
|
||||||
>
|
>
|
||||||
Use our Helm chart to Install Infisical on your Kubernetes cluster
|
Use our Helm chart to Install Infisical on your Kubernetes cluster
|
||||||
</Card>
|
</Card>
|
||||||
|
<Card
|
||||||
|
title="Fly.io"
|
||||||
|
color="#ea5a0c"
|
||||||
|
href="deployment-options/fly.io"
|
||||||
|
>
|
||||||
|
Deploy Infisical with Fly.io
|
||||||
|
</Card>
|
||||||
</CardGroup>
|
</CardGroup>
|
||||||
|
|||||||
Reference in New Issue
Block a user