This commit is contained in:
Fang-Pen Lin
2025-11-24 14:04:04 -08:00
parent c3fda7d20d
commit 64f7a83212
@@ -21,7 +21,7 @@ A typical workflow for using the Infisical PKI Issuer to issue certificates for
1. Creating a certificate profile with ACME as the enrollment method in Infisical. 1. Creating a certificate profile with ACME as the enrollment method in Infisical.
2. Creating a Kubernetes secret to store the EAB (External Account Binding) credentials of the ACME certificate profile. 2. Creating a Kubernetes secret to store the EAB (External Account Binding) credentials of the ACME certificate profile.
3. Installing `cert-manager` into your Kubernetes cluster. 3. Installing `cert-manager` into your Kubernetes cluster.
4. Creating an `Issuer` or `ClusterIssuer` resource in your Kubernetes cluster to represent the Infisical PKI issuer you wish to use. 4. Creating an `Issuer` or `ClusterIssuer` resource in your Kubernetes cluster to connect to the Infisical PKI certificate profile you wish to use.
5. Create the approver policy to accept certificate request. 5. Create the approver policy to accept certificate request.
6. Creating a `Certificate` resource in your Kubernetes cluster to represent a certificate you wish to issue. As part of this step, you specify the Kubernetes `Secret` to create and store the issued certificate and private key. 6. Creating a `Certificate` resource in your Kubernetes cluster to represent a certificate you wish to issue. As part of this step, you specify the Kubernetes `Secret` to create and store the issued certificate and private key.
7. Consuming the issued certificate across your Kubernetes resources from the specified Kubernetes `Secret`. 7. Consuming the issued certificate across your Kubernetes resources from the specified Kubernetes `Secret`.
@@ -35,7 +35,7 @@ In the following steps, we explore how to install the Infisical PKI Issuer using
Follow the instructions [here](/documentation/platform/pki/enrollment-methods/acme) to create a certificate profile with ACME as the enrollment method. Follow the instructions [here](/documentation/platform/pki/enrollment-methods/acme) to create a certificate profile with ACME as the enrollment method.
By the end of this step, you should have a **ACME Directory URL**, **EAB KID** and **EAB Secret** on hand as part of the credentials for the Infisical PKI ACME service to authenticate with Infisical; this will be useful in steps 4 and 5. By the end of this step, you should have a **ACME Directory URL**, **EAB KID** and **EAB Secret** on hand as part of the credentials for the Infisical PKI ACME server to authenticate with Infisical; this will be useful in steps 4 and 5.
<Note> <Note>
Currently, the Infisical PKI ACME service only supports authenticating with Infisical via the dedicated EAB credentials generated for each certificate profile as the authentication method. Currently, the Infisical PKI ACME service only supports authenticating with Infisical via the dedicated EAB credentials generated for each certificate profile as the authentication method.
@@ -50,30 +50,30 @@ In the following steps, we explore how to install the Infisical PKI Issuer using
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.15.3/cert-manager.yaml kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.15.3/cert-manager.yaml
``` ```
</Step> </Step>
<Step title="Create Kubernetes Secret for Infisical PKI Issuer"> <Step title="Create Kubernetes Secret for the EAB secret of Infisical ACME server">
Start by creating a Kubernetes `Secret` containing the **Client Secret** from step 1. As mentioned previously, this will be used by the Infisical PKI issuer to authenticate with Infisical. Start by creating a Kubernetes `Secret` containing the **Client Secret** from step 1. As mentioned previously, this will be used by the Infisical PKI issuer to authenticate with Infisical.
<Tabs> <Tabs>
<Tab title="kubectl command"> <Tab title="kubectl command">
```bash ```bash
kubectl create secret generic issuer-infisical-client-secret \ kubectl create secret generic infisical-acme-eab-secret \
--namespace <namespace_you_want_to_issue_certificates_in> \ --namespace <namespace_you_want_to_issue_certificates_in> \
--from-literal=clientSecret=<client_secret> --from-literal=eabSecret=<eab_secret>
``` ```
</Tab> </Tab>
<Tab title="Configuration file"> <Tab title="Configuration file">
```yaml secret-issuer.yaml ```yaml acme-eab-secret.yaml
apiVersion: v1 apiVersion: v1
kind: Secret kind: Secret
metadata: metadata:
name: issuer-infisical-client-secret name: infisical-acme-eab-secret
namespace: <namespace_you_want_to_issue_certificates_in> namespace: <namespace_you_want_to_issue_certificates_in>
data: data:
clientSecret: <client_secret> eabSecret: <eab_secret>
``` ```
```bash ```bash
kubectl apply -f secret-issuer.yaml kubectl apply -f acme-eab-secret.yaml
``` ```
</Tab> </Tab>
</Tabs> </Tabs>