mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 11:27:47 +00:00
feat: updated doc for the function name
This commit is contained in:
@@ -40,6 +40,7 @@ spec:
|
|||||||
## CRD properties
|
## CRD properties
|
||||||
|
|
||||||
### Generic
|
### Generic
|
||||||
|
|
||||||
The following properties help define what instance of Infisical the operator will interact with, the interval it will sync secrets and any CA certificates that may be required to connect.
|
The following properties help define what instance of Infisical the operator will interact with, the interval it will sync secrets and any CA certificates that may be required to connect.
|
||||||
|
|
||||||
<Accordion title="hostAPI">
|
<Accordion title="hostAPI">
|
||||||
@@ -93,11 +94,11 @@ When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
### Authentication methods
|
### Authentication methods
|
||||||
|
|
||||||
To retrieve the requested secrets, the operator must first authenticate with Infisical.
|
To retrieve the requested secrets, the operator must first authenticate with Infisical.
|
||||||
The list of available authentication methods are shown below.
|
The list of available authentication methods are shown below.
|
||||||
|
|
||||||
<Accordion title="authentication">
|
<Accordion title="authentication"></Accordion>
|
||||||
</Accordion>
|
|
||||||
|
|
||||||
<Accordion title="authentication.universalAuth">
|
<Accordion title="authentication.universalAuth">
|
||||||
The universal machine identity authentication method is used to authenticate with Infisical. The client ID and client secret needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores these credentials.
|
The universal machine identity authentication method is used to authenticate with Infisical. The client ID and client secret needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores these credentials.
|
||||||
@@ -535,6 +536,7 @@ spec:
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
### Operator managed secrets
|
### Operator managed secrets
|
||||||
|
|
||||||
The managed secret properties specify where to store the secrets retrieved from your Infisical project.
|
The managed secret properties specify where to store the secrets retrieved from your Infisical project.
|
||||||
This includes defining the name and namespace of the Kubernetes secret that will hold these secrets.
|
This includes defining the name and namespace of the Kubernetes secret that will hold these secrets.
|
||||||
The Infisical operator will automatically create the Kubernetes secret in the specified name/namespace and ensure it stays up-to-date.
|
The Infisical operator will automatically create the Kubernetes secret in the specified name/namespace and ensure it stays up-to-date.
|
||||||
@@ -567,6 +569,7 @@ This is useful for tools such as ArgoCD, where every resource requires an owner
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
### Manged secret templating
|
### Manged secret templating
|
||||||
|
|
||||||
Fetching secrets from Infisical as is via the operator may not be enough. This is where templating functionality may be helpful.
|
Fetching secrets from Infisical as is via the operator may not be enough. This is where templating functionality may be helpful.
|
||||||
Using Go templates, you can format, combine, and create new key-value pairs from secrets fetched from Infisical before storing them as Kubernetes Secrets.
|
Using Go templates, you can format, combine, and create new key-value pairs from secrets fetched from Infisical before storing them as Kubernetes Secrets.
|
||||||
|
|
||||||
@@ -579,6 +582,7 @@ Using Go templates, you can format, combine, and create new key-value pairs from
|
|||||||
|
|
||||||
When set to `false`, only secrets defined in the `managedSecretReference.template.data` field of the template will be included in the managed secret.
|
When set to `false`, only secrets defined in the `managedSecretReference.template.data` field of the template will be included in the managed secret.
|
||||||
Use this option when you would like to sync **only** a subset of secrets from Infisical to Kubernetes.
|
Use this option when you would like to sync **only** a subset of secrets from Infisical to Kubernetes.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="managedSecretReference.template.data">
|
<Accordion title="managedSecretReference.template.data">
|
||||||
Define secret keys and their corresponding templates.
|
Define secret keys and their corresponding templates.
|
||||||
@@ -609,6 +613,7 @@ managedSecretReference:
|
|||||||
```
|
```
|
||||||
|
|
||||||
For this example, let's assume the following secrets exist in your Infisical project:
|
For this example, let's assume the following secrets exist in your Infisical project:
|
||||||
|
|
||||||
```
|
```
|
||||||
DB_PASSWORD = "secret123"
|
DB_PASSWORD = "secret123"
|
||||||
COMPANY_NAME = "acme"
|
COMPANY_NAME = "acme"
|
||||||
@@ -617,6 +622,7 @@ API_URL = "old-url" # This will be overridden
|
|||||||
```
|
```
|
||||||
|
|
||||||
The resulting managed Kubernetes secret will then contain:
|
The resulting managed Kubernetes secret will then contain:
|
||||||
|
|
||||||
```
|
```
|
||||||
# Original secrets (from includeAllSecrets: true)
|
# Original secrets (from includeAllSecrets: true)
|
||||||
DB_PASSWORD = "secret123"
|
DB_PASSWORD = "secret123"
|
||||||
@@ -632,14 +638,14 @@ To help transform your secrets further, the operator provides a set of built-in
|
|||||||
|
|
||||||
### Available templating functions
|
### Available templating functions
|
||||||
|
|
||||||
<Accordion title="toBase64DecodedString">
|
<Accordion title="decodeBase64ToBytes">
|
||||||
**Function name**: toBase64DecodedString
|
**Function name**: decodeBase64ToBytes
|
||||||
|
|
||||||
**Description**:
|
**Description**:
|
||||||
Given a base64 encoded string, this function will decodes the base64-encoded string.
|
Given a base64 encoded string, this function will decodes the base64-encoded string.
|
||||||
This function is useful when your secrets are already stored as base64 encoded value in Infisical.
|
This function is useful when your secrets are already stored as base64 encoded value in Infisical.
|
||||||
|
|
||||||
**Returns**: The decoded base64 string
|
**Returns**: The decoded base64 string as bytes.
|
||||||
|
|
||||||
**Example**:
|
**Example**:
|
||||||
The example below assumes that the `BINARY_KEY_BASE64` secret is stored as a base64 encoded value in Infisical.
|
The example below assumes that the `BINARY_KEY_BASE64` secret is stored as a base64 encoded value in Infisical.
|
||||||
@@ -652,8 +658,9 @@ To help transform your secrets further, the operator provides a set of built-in
|
|||||||
template:
|
template:
|
||||||
includeAllSecrets: true
|
includeAllSecrets: true
|
||||||
data:
|
data:
|
||||||
BINARY_KEY: "{{ toBase64DecodedString .BINARY_KEY_BASE64.Value }}"
|
BINARY_KEY: "{{ decodeBase64ToBytes .BINARY_KEY_BASE64.Value }}"
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
@@ -928,4 +935,3 @@ type: Opaque
|
|||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user