mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 14:28:20 +00:00
Start updating docs
This commit is contained in:
@@ -16,44 +16,47 @@ Export environment variables from the platform into a file format.
|
|||||||
<Accordion title="infisical export" defaultOpen="true">
|
<Accordion title="infisical export" defaultOpen="true">
|
||||||
Use this command to export environment variables from the platform into a raw file formats
|
Use this command to export environment variables from the platform into a raw file formats
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
$ infisical export
|
$ infisical export
|
||||||
|
|
||||||
# Export variables to a .env file
|
# Export variables to a .env file
|
||||||
infisical export > .env
|
infisical export > .env
|
||||||
|
|
||||||
# Export variables to a .env file (with export keyword)
|
# Export variables to a .env file (with export keyword)
|
||||||
infisical export --format=dotenv-export > .env
|
infisical export --format=dotenv-export > .env
|
||||||
|
|
||||||
# Export variables to a CSV file
|
# Export variables to a CSV file
|
||||||
infisical export --format=csv > secrets.csv
|
infisical export --format=csv > secrets.csv
|
||||||
|
|
||||||
# Export variables to a JSON file
|
# Export variables to a JSON file
|
||||||
infisical export --format=json > secrets.json
|
infisical export --format=json > secrets.json
|
||||||
|
|
||||||
# Export variables to a YAML file
|
# Export variables to a YAML file
|
||||||
infisical export --format=yaml > secrets.yaml
|
infisical export --format=yaml > secrets.yaml
|
||||||
|
|
||||||
# Render secrets using a custom template file
|
# Render secrets using a custom template file
|
||||||
infisical export --template=<path to template>
|
infisical export --template=<path to template>
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Environment variables
|
||||||
|
|
||||||
### Environment variables
|
|
||||||
<Accordion title="INFISICAL_TOKEN">
|
<Accordion title="INFISICAL_TOKEN">
|
||||||
Used to fetch secrets via a [machine identities](/documentation/platform/identities/machine-identities) apposed to logged in credentials. Simply, export this variable in the terminal before running this command.
|
Used to fetch secrets via a [machine identities](/documentation/platform/identities/machine-identities) apposed to logged in credentials. Simply, export this variable in the terminal before running this command.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id=<identity-client-id> --client-secret=<identity-client-secret> --silent --plain) # --plain flag will output only the token, so it can be fed to an environment variable. --silent will disable any update messages.
|
export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id=<identity-client-id> --client-secret=<identity-client-secret> --silent --plain) # --plain flag will output only the token, so it can be fed to an environment variable. --silent will disable any update messages.
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Alternatively you may also use service tokens. **Service tokens are legacy tokens that are a precursor to machine identities, and will be removed in the future.**
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
|
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
```
|
```
|
||||||
|
|
||||||
</Info>
|
</Info>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
@@ -63,16 +66,18 @@ Export environment variables from the platform into a file format.
|
|||||||
To use, simply export this variable in the terminal before running this command.
|
To use, simply export this variable in the terminal before running this command.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_DISABLE_UPDATE_CHECK=true
|
export INFISICAL_DISABLE_UPDATE_CHECK=true
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
### flags
|
### flags
|
||||||
|
|
||||||
<Accordion title="--template">
|
<Accordion title="--template">
|
||||||
The `--template` flag specifies the path to the template file used for rendering secrets. When using templates, you can omit the other format flags.
|
The `--template` flag specifies the path to the template file used for rendering secrets. When using templates, you can omit the other format flags.
|
||||||
|
|
||||||
```text my-template-file
|
```text my-template-file
|
||||||
{{$secrets := secret "<infisical-project-id>" "<environment-slug>" "<folder-path>"}}
|
{{$secrets := secret "<infisical-project-id>" "<environment-slug>" "<folder-path>"}}
|
||||||
{{$length := len $secrets}}
|
{{$length := len $secrets}}
|
||||||
{{- "{"}}
|
{{- "{"}}
|
||||||
@@ -82,24 +87,26 @@ Export environment variables from the platform into a file format.
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{ "}" -}}
|
{{ "}" -}}
|
||||||
```
|
```
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical export --template="/path/to/template/file"
|
infisical export --template="/path/to/template/file"
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="--env">
|
<Accordion title="--env">
|
||||||
Used to set the environment that secrets are pulled from.
|
Used to set the environment that secrets are pulled from.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical export --env=prod
|
infisical export --env=prod
|
||||||
```
|
```
|
||||||
|
|
||||||
Note: this flag only accepts environment slug names not the fully qualified name. To view the slug name of an environment, visit the project settings page.
|
Note: this flag only accepts environment slug names not the fully qualified name. To view the slug name of an environment, visit the project settings page.
|
||||||
|
|
||||||
default value: `dev`
|
default value: `dev`
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--projectId">
|
<Accordion title="--projectId">
|
||||||
@@ -107,28 +114,32 @@ Export environment variables from the platform into a file format.
|
|||||||
This flag allows you to override this behavior by explicitly defining the project to fetch your secrets from.
|
This flag allows you to override this behavior by explicitly defining the project to fetch your secrets from.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
|
|
||||||
infisical export --projectId=XXXXXXXXXXXXXX
|
infisical export --projectId=XXXXXXXXXXXXXX
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--expand">
|
<Accordion title="--expand">
|
||||||
Parse shell parameter expansions in your secrets (e.g., `${DOMAIN}`)
|
Parse shell parameter expansions in your secrets (e.g., `${DOMAIN}`)
|
||||||
|
|
||||||
Default value: `true`
|
Default value: `true`
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--format">
|
<Accordion title="--format">
|
||||||
Format of the output file. Accepted values: `dotenv`, `dotenv-export`, `csv`, `json` and `yaml`
|
Format of the output file. Accepted values: `dotenv`, `dotenv-export`, `csv`, `json` and `yaml`
|
||||||
|
|
||||||
Default value: `dotenv`
|
Default value: `dotenv`
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--secret-overriding">
|
<Accordion title="--secret-overriding">
|
||||||
Prioritizes personal secrets with the same name over shared secrets
|
Prioritizes personal secrets with the same name over shared secrets
|
||||||
|
|
||||||
Default value: `true`
|
Default value: `true`
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--path">
|
<Accordion title="--path">
|
||||||
@@ -138,19 +149,21 @@ Export environment variables from the platform into a file format.
|
|||||||
# Example
|
# Example
|
||||||
infisical export --path="/path/to/folder" --env=dev
|
infisical export --path="/path/to/folder" --env=dev
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--tags">
|
<Accordion title="--tags">
|
||||||
When working with tags, you can use this flag to filter and retrieve only secrets that are associated with a specific tag(s).
|
When working with tags, you can use this flag to filter and retrieve only secrets that are associated with a specific tag(s).
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical run --tags=tag1,tag2,tag3 -- npm run dev
|
infisical run --tags=tag1,tag2,tag3 -- npm run dev
|
||||||
```
|
```
|
||||||
|
|
||||||
Note: you must reference the tag by its slug name not its fully qualified name. Go to project settings to view all tag slugs.
|
Note: you must reference the tag by its slug name not its fully qualified name. Go to project settings to view all tag slugs.
|
||||||
|
|
||||||
By default, all secrets are fetched
|
By default, all secrets are fetched
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|||||||
+39
-24
@@ -11,6 +11,7 @@ description: "The command that injects your secrets into local environment"
|
|||||||
# Example
|
# Example
|
||||||
infisical run [options] -- npm run dev
|
infisical run [options] -- npm run dev
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
|
|
||||||
<Tab title="Chained commands">
|
<Tab title="Chained commands">
|
||||||
@@ -20,6 +21,7 @@ description: "The command that injects your secrets into local environment"
|
|||||||
# Example
|
# Example
|
||||||
infisical run [options] --command "npm run bootstrap && npm run dev start; other-bash-command"
|
infisical run [options] --command "npm run bootstrap && npm run dev start; other-bash-command"
|
||||||
```
|
```
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
@@ -27,34 +29,37 @@ description: "The command that injects your secrets into local environment"
|
|||||||
|
|
||||||
Inject secrets from Infisical into your application process.
|
Inject secrets from Infisical into your application process.
|
||||||
|
|
||||||
|
|
||||||
## Subcommands & flags
|
## Subcommands & flags
|
||||||
|
|
||||||
<Accordion title="infisical run" defaultOpen="true">
|
<Accordion title="infisical run" defaultOpen="true">
|
||||||
Use this command to inject secrets into your applications process
|
Use this command to inject secrets into your applications process
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
$ infisical run -- <your application command>
|
$ infisical run -- <your application command>
|
||||||
|
|
||||||
# Example
|
# Example
|
||||||
$ infisical run -- npm run dev
|
$ infisical run -- npm run dev
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Environment variables
|
||||||
|
|
||||||
### Environment variables
|
|
||||||
<Accordion title="INFISICAL_TOKEN">
|
<Accordion title="INFISICAL_TOKEN">
|
||||||
Used to fetch secrets via a [machine identity](/documentation/platform/identities/machine-identities) apposed to logged in credentials. Simply, export this variable in the terminal before running this command.
|
Used to fetch secrets via a [machine identity](/documentation/platform/identities/machine-identities) apposed to logged in credentials. Simply, export this variable in the terminal before running this command.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id=<identity-client-id> --client-secret=<identity-client-secret> --silent --plain) # --plain flag will output only the token, so it can be fed to an environment variable. --silent will disable any update messages.
|
export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id=<identity-client-id> --client-secret=<identity-client-secret> --silent --plain) # --plain flag will output only the token, so it can be fed to an environment variable. --silent will disable any update messages.
|
||||||
```
|
```
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Alternatively you may also use service tokens. **Service tokens are legacy tokens that are a precursor to machine identities, and will be removed in the future.**
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
|
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
```
|
```
|
||||||
|
|
||||||
</Info>
|
</Info>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
@@ -64,80 +69,90 @@ Inject secrets from Infisical into your application process.
|
|||||||
To use, simply export this variable in the terminal before running this command.
|
To use, simply export this variable in the terminal before running this command.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_DISABLE_UPDATE_CHECK=true
|
export INFISICAL_DISABLE_UPDATE_CHECK=true
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
### Flags
|
### Flags
|
||||||
|
|
||||||
<Accordion title="--project-config-dir">
|
<Accordion title="--project-config-dir">
|
||||||
Explicitly set the directory where the .infisical.json resides. This is useful for some monorepo setups.
|
Explicitly set the directory where the .infisical.json resides. This is useful for some monorepo setups.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical run --project-config-dir=/some-dir -- printenv
|
infisical run --project-config-dir=/some-dir -- printenv
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--command">
|
<Accordion title="--command">
|
||||||
Pass secrets into multiple commands at once
|
Pass secrets into multiple commands at once
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical run --command="npm run build && npm run dev; more-commands..."
|
infisical run --command="npm run build && npm run dev; more-commands..."
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--projectId">
|
<Accordion title="--projectId">
|
||||||
The project ID to fetch secrets from. This is required when using a machine identity to authenticate.
|
The project ID to fetch secrets from. This is required when using a machine identity to authenticate.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical run --projectId=<project-id> -- npm run dev
|
infisical run --projectId=<project-id> -- npm run dev
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--token">
|
<Accordion title="--token">
|
||||||
If you are using a [machine identity](/documentation/platform/identities/machine-identities) to authenticate, you can pass the token as a flag
|
If you are using a [machine identity](/documentation/platform/identities/machine-identities) to authenticate, you can pass the token as a flag
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical run --token="<universal-auth-access-token>" --projectId=<project-id> -- npm run start
|
infisical run --token="<universal-auth-access-token>" --projectId=<project-id> -- npm run start
|
||||||
```
|
```
|
||||||
|
|
||||||
You may also expose the token to the CLI by setting the environment variable `INFISICAL_TOKEN` before executing the run command. This will have the same effect as setting the token with `--token` flag
|
You may also expose the token to the CLI by setting the environment variable `INFISICAL_TOKEN` before executing the run command. This will have the same effect as setting the token with `--token` flag
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--expand">
|
<Accordion title="--expand">
|
||||||
Turn on or off the shell parameter expansion in your secrets. If you have used shell parameters in your secret(s), activating this feature will populate them before injecting them into your application process.
|
Turn on or off the shell parameter expansion in your secrets. If you have used shell parameters in your secret(s), activating this feature will populate them before injecting them into your application process.
|
||||||
|
|
||||||
Default value: `true`
|
Default value: `true`
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--env">
|
{" "}
|
||||||
This is used to specify the environment from which secrets should be retrieved. The accepted values are the environment slugs defined for your project, such as `dev`, `staging`, `test`, and `prod`.
|
|
||||||
|
<Accordion title="--env">
|
||||||
Default value: `dev`
|
This is used to specify the environment from which secrets should be
|
||||||
</Accordion>
|
retrieved. The accepted values are the environment slugs defined for your
|
||||||
|
project, such as `dev`, `staging`, `test`, and `prod`. Default value: `dev`
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--secret-overriding">
|
<Accordion title="--secret-overriding">
|
||||||
Prioritizes personal secrets with the same name over shared secrets
|
Prioritizes personal secrets with the same name over shared secrets
|
||||||
|
|
||||||
Default value: `true`
|
Default value: `true`
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--tags">
|
<Accordion title="--tags">
|
||||||
When working with tags, you can use this flag to filter and retrieve only secrets that are associated with a specific tag(s).
|
When working with tags, you can use this flag to filter and retrieve only secrets that are associated with a specific tag(s).
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical run --tags=tag1,tag2,tag3 -- npm run dev
|
infisical run --tags=tag1,tag2,tag3 -- npm run dev
|
||||||
```
|
```
|
||||||
|
|
||||||
Note: you must reference the tag by its slug name not its fully qualified name. Go to project settings to view all tag slugs.
|
Note: you must reference the tag by its slug name not its fully qualified name. Go to project settings to view all tag slugs.
|
||||||
|
|
||||||
By default, all secrets are fetched
|
By default, all secrets are fetched
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--path">
|
<Accordion title="--path">
|
||||||
|
|||||||
@@ -31,12 +31,15 @@ $ infisical secrets
|
|||||||
```
|
```
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Alternatively you may also use service tokens. **Service tokens are legacy tokens that are a precursor to machine identities, and will be removed in the future.**
|
Alternatively, you may use service tokens.
|
||||||
|
|
||||||
|
Please note, however, that service tokens are being deprecated. They will be removed in the future in accordance with the deprecation notice and timeline stated [here](https://infisical.com/blog/deprecating-api-keys).
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
export INFISICAL_TOKEN=<service-token>
|
export INFISICAL_TOKEN=<service-token>
|
||||||
```
|
```
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="INFISICAL_DISABLE_UPDATE_CHECK">
|
<Accordion title="INFISICAL_DISABLE_UPDATE_CHECK">
|
||||||
@@ -64,9 +67,10 @@ $ infisical secrets
|
|||||||
The project ID to fetch secrets from. This is required when using a machine identity to authenticate.
|
The project ID to fetch secrets from. This is required when using a machine identity to authenticate.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Example
|
# Example
|
||||||
infisical secrets --projectId=<project-id>
|
infisical secrets --projectId=<project-id>
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--env">
|
<Accordion title="--env">
|
||||||
@@ -202,7 +206,7 @@ $ infisical secrets folders
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--token">
|
<Accordion title="--token">
|
||||||
Fetch folders using an Infisical universal auth access token
|
Fetch folders using an [machine identity](/documentation/platform/identities/machine-identities) access token.
|
||||||
|
|
||||||
Default value: ``
|
Default value: ``
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|||||||
Reference in New Issue
Block a user