feat: updated doc for the function name

This commit is contained in:
=
2025-01-20 00:08:22 +05:30
parent 5ef2be1a9c
commit 5cc5a4f03d
@@ -31,15 +31,16 @@ spec:
secretNamespace: default secretNamespace: default
creationPolicy: "Orphan" creationPolicy: "Orphan"
template: template:
includeAllSecrets: true includeAllSecrets: true
data: data:
NEW_KEY_NAME: "{{ .KEY.SecretPath }} {{ .KEY.Value }}" NEW_KEY_NAME: "{{ .KEY.SecretPath }} {{ .KEY.Value }}"
KEY_WITH_BINARY_VALUE: "{{ .KEY.SecretPath }} {{ .KEY.Value }}" KEY_WITH_BINARY_VALUE: "{{ .KEY.SecretPath }} {{ .KEY.Value }}"
``` ```
## CRD properties ## CRD properties
### Generic ### Generic
The following properties help define what instance of Infisical the operator will interact with, the interval it will sync secrets and any CA certificates that may be required to connect. The following properties help define what instance of Infisical the operator will interact with, the interval it will sync secrets and any CA certificates that may be required to connect.
<Accordion title="hostAPI"> <Accordion title="hostAPI">
@@ -93,11 +94,11 @@ When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
</Accordion> </Accordion>
### Authentication methods ### Authentication methods
To retrieve the requested secrets, the operator must first authenticate with Infisical. To retrieve the requested secrets, the operator must first authenticate with Infisical.
The list of available authentication methods are shown below. The list of available authentication methods are shown below.
<Accordion title="authentication"> <Accordion title="authentication"></Accordion>
</Accordion>
<Accordion title="authentication.universalAuth"> <Accordion title="authentication.universalAuth">
The universal machine identity authentication method is used to authenticate with Infisical. The client ID and client secret needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores these credentials. The universal machine identity authentication method is used to authenticate with Infisical. The client ID and client secret needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores these credentials.
@@ -535,6 +536,7 @@ spec:
</Accordion> </Accordion>
### Operator managed secrets ### Operator managed secrets
The managed secret properties specify where to store the secrets retrieved from your Infisical project. The managed secret properties specify where to store the secrets retrieved from your Infisical project.
This includes defining the name and namespace of the Kubernetes secret that will hold these secrets. This includes defining the name and namespace of the Kubernetes secret that will hold these secrets.
The Infisical operator will automatically create the Kubernetes secret in the specified name/namespace and ensure it stays up-to-date. The Infisical operator will automatically create the Kubernetes secret in the specified name/namespace and ensure it stays up-to-date.
@@ -567,6 +569,7 @@ This is useful for tools such as ArgoCD, where every resource requires an owner
</Accordion> </Accordion>
### Manged secret templating ### Manged secret templating
Fetching secrets from Infisical as is via the operator may not be enough. This is where templating functionality may be helpful. Fetching secrets from Infisical as is via the operator may not be enough. This is where templating functionality may be helpful.
Using Go templates, you can format, combine, and create new key-value pairs from secrets fetched from Infisical before storing them as Kubernetes Secrets. Using Go templates, you can format, combine, and create new key-value pairs from secrets fetched from Infisical before storing them as Kubernetes Secrets.
@@ -577,8 +580,9 @@ Using Go templates, you can format, combine, and create new key-value pairs from
When set to `true`, all secrets fetched from your Infisical project will be added into your managed Kubernetes secret resource. When set to `true`, all secrets fetched from your Infisical project will be added into your managed Kubernetes secret resource.
**Use this option when you would like to sync all secrets from Infisical to Kubernetes but want to template a subset of them.** **Use this option when you would like to sync all secrets from Infisical to Kubernetes but want to template a subset of them.**
When set to `false`, only secrets defined in the `managedSecretReference.template.data` field of the template will be included in the managed secret. When set to `false`, only secrets defined in the `managedSecretReference.template.data` field of the template will be included in the managed secret.
Use this option when you would like to sync **only** a subset of secrets from Infisical to Kubernetes. Use this option when you would like to sync **only** a subset of secrets from Infisical to Kubernetes.
</Accordion> </Accordion>
<Accordion title="managedSecretReference.template.data"> <Accordion title="managedSecretReference.template.data">
Define secret keys and their corresponding templates. Define secret keys and their corresponding templates.
@@ -609,6 +613,7 @@ managedSecretReference:
``` ```
For this example, let's assume the following secrets exist in your Infisical project: For this example, let's assume the following secrets exist in your Infisical project:
``` ```
DB_PASSWORD = "secret123" DB_PASSWORD = "secret123"
COMPANY_NAME = "acme" COMPANY_NAME = "acme"
@@ -617,6 +622,7 @@ API_URL = "old-url" # This will be overridden
``` ```
The resulting managed Kubernetes secret will then contain: The resulting managed Kubernetes secret will then contain:
``` ```
# Original secrets (from includeAllSecrets: true) # Original secrets (from includeAllSecrets: true)
DB_PASSWORD = "secret123" DB_PASSWORD = "secret123"
@@ -632,28 +638,29 @@ To help transform your secrets further, the operator provides a set of built-in
### Available templating functions ### Available templating functions
<Accordion title="toBase64DecodedString"> <Accordion title="decodeBase64ToBytes">
**Function name**: toBase64DecodedString **Function name**: decodeBase64ToBytes
**Description**: **Description**:
Given a base64 encoded string, this function will decodes the base64-encoded string. Given a base64 encoded string, this function will decodes the base64-encoded string.
This function is useful when your secrets are already stored as base64 encoded value in Infisical. This function is useful when your secrets are already stored as base64 encoded value in Infisical.
**Returns**: The decoded base64 string **Returns**: The decoded base64 string as bytes.
**Example**: **Example**:
The example below assumes that the `BINARY_KEY_BASE64` secret is stored as a base64 encoded value in Infisical. The example below assumes that the `BINARY_KEY_BASE64` secret is stored as a base64 encoded value in Infisical.
The resulting managed secret will contain the decoded value of `BINARY_KEY_BASE64`. The resulting managed secret will contain the decoded value of `BINARY_KEY_BASE64`.
```yaml
managedSecretReference:
secretName: managed-secret
secretNamespace: default
template:
includeAllSecrets: true
data:
BINARY_KEY: "{{ decodeBase64ToBytes .BINARY_KEY_BASE64.Value }}"
```
```yaml
managedSecretReference:
secretName: managed-secret
secretNamespace: default
template:
includeAllSecrets: true
data:
BINARY_KEY: "{{ toBase64DecodedString .BINARY_KEY_BASE64.Value }}"
```
</Accordion> </Accordion>
</Accordion> </Accordion>
@@ -928,4 +935,3 @@ type: Opaque
``` ```
</Accordion> </Accordion>