Merge remote-tracking branch 'origin' into secrets-mgmt-docs
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Project Events"
|
||||
openapi: "POST /api/v1/events/subscribe/project-events"
|
||||
---
|
||||
@@ -41,6 +41,8 @@
|
||||
"group": "Platform Reference",
|
||||
"pages": [
|
||||
"documentation/platform/organization",
|
||||
"documentation/platform/event-subscriptions",
|
||||
"documentation/platform/folder",
|
||||
{
|
||||
"group": "Projects",
|
||||
"pages": [
|
||||
@@ -777,6 +779,10 @@
|
||||
"group": "Admin",
|
||||
"pages": ["api-reference/endpoints/admin/bootstrap-instance"]
|
||||
},
|
||||
{
|
||||
"group": "Events",
|
||||
"pages": ["api-reference/endpoints/events/project-events"]
|
||||
},
|
||||
{
|
||||
"group": "Identities",
|
||||
"pages": [
|
||||
|
||||
@@ -0,0 +1,118 @@
|
||||
---
|
||||
title: "Event Subscriptions"
|
||||
sidebarTitle: "Events"
|
||||
description: "Subscribe to events in Infisical for real-time updates"
|
||||
---
|
||||
|
||||
<Info>
|
||||
**Note:** Event Subscriptions is a paid feature. - **Infisical Cloud users:** Event Subscriptions is available under
|
||||
the **Enterprise Tier**. - **Self-Hosted Infisical:** Please contact [[email protected]](mailto:[email protected])
|
||||
to purchase an enterprise license.
|
||||
</Info>
|
||||
|
||||
Event Subscriptions in Infisical allow you to receive real-time notifications when specific actions occur within your account or organization. These notifications include changes to secrets, users, teams, and many more **coming soon**.
|
||||
|
||||
## How It Works
|
||||
|
||||
- Server receives message over pubsub connection indicating changes have occurred
|
||||
- Server processes the change notification
|
||||
- Updated data is synchronized across all connected Infisical instances
|
||||
- Client applications receive real-time updates through [Server-Sent Events (SSE)](https://developer.mozilla.org/en-US/docs/Web/API/Server-sent_events)
|
||||
- All servers maintain consistent state without manual intervention
|
||||
|
||||
This ensures your infrastructure stays up-to-date automatically, without requiring restarts or manual synchronization.
|
||||
|
||||
<Note>
|
||||
Event Subscriptions are designed for real-time communication and do not include persistence or replay
|
||||
capabilities—events are delivered once and are not stored for future retrieval.
|
||||
</Note>
|
||||
|
||||
## Supported Resources
|
||||
|
||||
You can currently subscribe to notifications for the following resources and event types:
|
||||
|
||||
- **Secrets**
|
||||
- `secret:created`: Triggered when a secret is created
|
||||
- `secret:updated`: Triggered when a secret is updated
|
||||
- `secret:deleted`: Triggered when a secret is deleted
|
||||
|
||||
## Permissions Setup
|
||||
|
||||
To receive events on a supported resource, the identity must have `Subscribe` action permission on that resource.
|
||||
|
||||
Follow these steps to set up the necessary permissions:
|
||||
|
||||
<Steps>
|
||||
<Step title="Select a project and copy the Project ID">
|
||||

|
||||
|
||||
On your project page, open **Project Settings** from the sidebar.
|
||||
|
||||
In the Project name section, click **Copy Project ID** to copy your Project ID, or extract it from the URL:
|
||||
`https://app.infisical.com/project/<your_project_id>/settings`
|
||||
|
||||
</Step>
|
||||
|
||||
<Step title="Navigate to Access Management and open Project Roles">
|
||||
  Navigate to **Access Management**, then select **Project Roles**.
|
||||
</Step>
|
||||
|
||||
<Step title="Select an existing role or create a new one">
|
||||
 You can either edit an existing role or create a new role
|
||||
for event subscriptions.
|
||||
</Step>
|
||||
|
||||
<Step title="Assign policies to the role">
|
||||
 Select the specific resources that the role should have access
|
||||
to. 
|
||||
</Step>
|
||||
|
||||
<Step title="Enable the Subscribe action in permissions">
|
||||

|
||||
|
||||
Ensure the **Subscribe** action is selected for the relevant resources and events.
|
||||
|
||||
## Conditions
|
||||
|
||||
By default, the role will have access to all events for the selected resources in this project.
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Full Access">
|
||||

|
||||
</Accordion>
|
||||
<Accordion title="Path Prefix">
|
||||

|
||||
</Accordion>
|
||||
<Accordion title="Environment">
|
||||

|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
## Getting Started
|
||||
|
||||
Currently, events are only available via [API](/api-reference/endpoints/events) but will soon be available in our SDKs, Kubernetes Operator, and more.
|
||||
|
||||
### API Usage
|
||||
|
||||
You need an auth token to use this API. To get an authentication token, follow the authentication guide for one of our supported auth methods from the [machine identities documentation](/documentation/platform/identities/machine-identities#authentication-methods).
|
||||
|
||||
#### Creating a Subscription
|
||||
|
||||

|
||||
|
||||
**Request Parameters:**
|
||||
|
||||
- `projectId`: Project whose events you want to subscribe to
|
||||
- `register`: List of event filters
|
||||
- `conditions`: Conditions to filter events on
|
||||
- `environmentSlug`: Project environment
|
||||
- `secretPath`: Path of the secrets
|
||||
|
||||

|
||||
|
||||
The subscribe endpoint responds with a `text/event-stream` content type to initiate SSE streaming.
|
||||
|
||||
For more specific details, please refer to our [API Reference](/api-reference/endpoints/events).
|
||||
@@ -6,6 +6,7 @@ description: "Learn how to automatically rotate Azure Client Secrets."
|
||||
## Prerequisites
|
||||
|
||||
- Create an [Azure Client Secret Connection](/integrations/app-connections/azure-client-secrets).
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this rotation provider, if network restrictions apply.
|
||||
|
||||
## Create an Azure Client Secret Rotation in Infisical
|
||||
|
||||
|
||||
@@ -14,6 +14,7 @@ description: "Learn how to automatically rotate LDAP passwords."
|
||||
## Prerequisites
|
||||
|
||||
- Create an [LDAP Connection](/integrations/app-connections/ldap) with the **Secret Rotation** requirements
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this rotation provider, if network restrictions apply.
|
||||
|
||||
## Create an LDAP Password Rotation in Infisical
|
||||
|
||||
|
||||
@@ -30,6 +30,7 @@ An example creation statement might look like:
|
||||
To learn more about Microsoft SQL Server's permission system, please visit their [documentation](https://learn.microsoft.com/en-us/sql/t-sql/statements/grant-transact-sql?view=sql-server-ver16).
|
||||
</Tip>
|
||||
|
||||
3. Ensure your network security policies allow incoming requests from Infisical to this rotation provider, if network restrictions apply.
|
||||
|
||||
## Create a Microsoft SQL Server Credentials Rotation in Infisical
|
||||
|
||||
|
||||
@@ -25,7 +25,7 @@ description: "Learn how to automatically rotate MySQL credentials."
|
||||
<Tip>
|
||||
To learn more about the MySQL permission system, please visit their [documentation](https://dev.mysql.com/doc/refman/8.4/en/grant.html).
|
||||
</Tip>
|
||||
|
||||
3. Ensure your network security policies allow incoming requests from Infisical to this rotation provider, if network restrictions apply.
|
||||
|
||||
## Create a MySQL Credentials Rotation in Infisical
|
||||
|
||||
|
||||
@@ -31,6 +31,7 @@ description: "Learn how to automatically rotate Oracle Database credentials."
|
||||
To learn more about the Oracle Database permission system, please visit their [documentation](https://docs.oracle.com/en/database/oracle/oracle-database/19/dbseg/configuring-privilege-and-role-authorization.html).
|
||||
</Tip>
|
||||
|
||||
3. Ensure your network security policies allow incoming requests from Infisical to this rotation provider, if network restrictions apply.
|
||||
|
||||
## Create an Oracle Database Credentials Rotation in Infisical
|
||||
|
||||
|
||||
@@ -27,6 +27,7 @@ description: "Learn how to automatically rotate PostgreSQL credentials."
|
||||
To learn more about PostgreSQL's permission system, please visit their [documentation](https://www.postgresql.org/docs/current/sql-grant.html).
|
||||
</Tip>
|
||||
|
||||
3. Ensure your network security policies allow incoming requests from Infisical to this rotation provider, if network restrictions apply.
|
||||
|
||||
## Create a PostgreSQL Credentials Rotation in Infisical
|
||||
|
||||
|
||||
|
After Width: | Height: | Size: 96 KiB |
|
After Width: | Height: | Size: 60 KiB |
|
After Width: | Height: | Size: 96 KiB |
|
After Width: | Height: | Size: 476 KiB |
|
After Width: | Height: | Size: 747 KiB |
|
After Width: | Height: | Size: 910 KiB |
|
After Width: | Height: | Size: 531 KiB |
|
After Width: | Height: | Size: 401 KiB |
|
After Width: | Height: | Size: 484 KiB |
|
After Width: | Height: | Size: 397 KiB |
|
After Width: | Height: | Size: 734 KiB |
|
After Width: | Height: | Size: 441 KiB |
|
After Width: | Height: | Size: 735 KiB |
|
After Width: | Height: | Size: 697 KiB |
|
After Width: | Height: | Size: 704 KiB |
|
After Width: | Height: | Size: 879 KiB |
|
After Width: | Height: | Size: 273 KiB |
|
After Width: | Height: | Size: 168 KiB |
|
After Width: | Height: | Size: 858 KiB |
|
After Width: | Height: | Size: 866 KiB |
|
After Width: | Height: | Size: 895 KiB |
|
After Width: | Height: | Size: 834 KiB |
|
After Width: | Height: | Size: 678 KiB |
@@ -7,6 +7,7 @@ description: "Learn how to configure an AWS Parameter Store Sync for Infisical."
|
||||
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create an [AWS Connection](/integrations/app-connections/aws) with the required **Secret Sync** permissions
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
|
||||
@@ -7,6 +7,7 @@ description: "Learn how to configure an AWS Secrets Manager Sync for Infisical."
|
||||
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create an [AWS Connection](/integrations/app-connections/aws) with the required **Secret Sync** permissions
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
|
||||
@@ -7,6 +7,7 @@ description: "Learn how to configure an Azure App Configuration Sync for Infisic
|
||||
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create an [Azure App Configuration Connection](/integrations/app-connections/azure-app-configuration)
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Note>
|
||||
The Azure App Configuration Secret Sync requires the following permissions to be set on the user / service principal
|
||||
|
||||
@@ -7,6 +7,7 @@ description: "Learn how to configure a Azure DevOps Sync for Infisical."
|
||||
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create an [Azure DevOps Connection](/integrations/app-connections/azure-devops)
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
|
||||
@@ -7,6 +7,7 @@ description: "Learn how to configure a Azure Key Vault Sync for Infisical."
|
||||
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create an [Azure Key Vault Connection](/integrations/app-connections/azure-key-vault)
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Note>
|
||||
The Azure Key Vault Secret Sync requires the following secrets permissions to be set on the user / service principal
|
||||
|
||||
@@ -11,6 +11,7 @@ description: "Learn how to configure a GCP Secret Manager Sync for Infisical."
|
||||

|
||||

|
||||

|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
|
||||
@@ -7,6 +7,7 @@ description: "Learn how to configure a GitHub Sync for Infisical."
|
||||
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create a [GitHub Connection](/integrations/app-connections/github)
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
|
||||
@@ -7,6 +7,7 @@ description: "Learn how to configure a GitLab Sync for Infisical."
|
||||
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create a [GitLab Connection](/integrations/app-connections/gitlab)
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
|
||||
@@ -14,6 +14,7 @@ description: "Learn how to configure an Oracle Cloud Infrastructure Vault Sync f
|
||||
- Create an [OCI Connection](/integrations/app-connections/oci) with the required **Secret Sync** permissions
|
||||
- [Create](https://docs.oracle.com/en-us/iaas/Content/Identity/compartments/To_create_a_compartment.htm) or use an existing OCI Compartment (which the OCI Connection is authorized to access)
|
||||
- [Create](https://docs.oracle.com/en-us/iaas/Content/KeyManagement/Tasks/managingvaults_topic-To_create_a_new_vault.htm#createnewvault) or use an existing OCI Vault
|
||||
- Ensure your network security policies allow incoming requests from Infisical to this secret sync provider, if network restrictions apply.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
|
||||