mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat: made review changed
This commit is contained in:
@@ -111,7 +111,7 @@ kind: Secret
|
|||||||
|
|
||||||
<Accordion title="hostAPI">
|
<Accordion title="hostAPI">
|
||||||
If you are fetching secrets from a self-hosted instance of Infisical set the value of `hostAPI` to
|
If you are fetching secrets from a self-hosted instance of Infisical set the value of `hostAPI` to
|
||||||
` https://your-self-hosted-instace.com/api`
|
`https://your-self-hosted-instace.com/api`
|
||||||
|
|
||||||
When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
||||||
|
|
||||||
@@ -322,11 +322,11 @@ The available authentication methods are `universalAuth`, `kubernetesAuth`, `aws
|
|||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="ldapAuth">
|
<Accordion title="ldapAuth">
|
||||||
The ldap machine identity authentication method is used to authenticate with a configured LDAP directory. [Read more about LDAP Auth](/documentation/platform/identities/ldap-auth).
|
The LDAP machine identity authentication method is used to authenticate with a configured LDAP directory. [Read more about LDAP Auth](/documentation/platform/identities/ldap-auth).
|
||||||
|
|
||||||
Valid fields:
|
Valid fields:
|
||||||
- `identityId`: The identity ID of the machine identity you created.
|
- `identityId`: The identity ID of the machine identity you created.
|
||||||
- `credentialsRef`: The name and namespace of the Kubernetes secret that stores the ldap credentials.
|
- `credentialsRef`: The name and namespace of the Kubernetes secret that stores the LDAP credentials.
|
||||||
- `credentialsRef.secretName`: The name of the Kubernetes secret.
|
- `credentialsRef.secretName`: The name of the Kubernetes secret.
|
||||||
- `credentialsRef.secretNamespace`: The namespace of the Kubernetes secret.
|
- `credentialsRef.secretNamespace`: The namespace of the Kubernetes secret.
|
||||||
|
|
||||||
|
|||||||
@@ -110,7 +110,7 @@ After applying the InfisicalPushSecret CRD, you should notice that the secrets y
|
|||||||
|
|
||||||
<Accordion title="hostAPI">
|
<Accordion title="hostAPI">
|
||||||
If you are fetching secrets from a self-hosted instance of Infisical set the value of `hostAPI` to
|
If you are fetching secrets from a self-hosted instance of Infisical set the value of `hostAPI` to
|
||||||
` https://your-self-hosted-instace.com/api`
|
`https://your-self-hosted-instace.com/api`
|
||||||
|
|
||||||
When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
||||||
|
|
||||||
@@ -330,11 +330,11 @@ After applying the InfisicalPushSecret CRD, you should notice that the secrets y
|
|||||||
```
|
```
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="ldapAuth">
|
<Accordion title="ldapAuth">
|
||||||
The ldap machine identity authentication method is used to authenticate with a configured LDAP directory. [Read more about LDAP Auth](/documentation/platform/identities/ldap-auth).
|
The LDAP machine identity authentication method is used to authenticate with a configured LDAP directory. [Read more about LDAP Auth](/documentation/platform/identities/ldap-auth).
|
||||||
|
|
||||||
Valid fields:
|
Valid fields:
|
||||||
- `identityId`: The identity ID of the machine identity you created.
|
- `identityId`: The identity ID of the machine identity you created.
|
||||||
- `credentialsRef`: The name and namespace of the Kubernetes secret that stores the ldap credentials.
|
- `credentialsRef`: The name and namespace of the Kubernetes secret that stores the LDAP credentials.
|
||||||
- `credentialsRef.secretName`: The name of the Kubernetes secret.
|
- `credentialsRef.secretName`: The name of the Kubernetes secret.
|
||||||
- `credentialsRef.secretNamespace`: The namespace of the Kubernetes secret.
|
- `credentialsRef.secretNamespace`: The namespace of the Kubernetes secret.
|
||||||
|
|
||||||
|
|||||||
@@ -705,7 +705,7 @@ spec:
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication.ldapAuth">
|
<Accordion title="authentication.ldapAuth">
|
||||||
The ldap machine identity authentication method is used to authenticate with Infisical using the configured LDAP directory. The username and password needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores these credentials.
|
The LDAP machine identity authentication method is used to authenticate with Infisical using the configured LDAP directory. The username and password needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores these credentials.
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Create a machine identity">
|
<Step title="Create a machine identity">
|
||||||
@@ -715,7 +715,7 @@ spec:
|
|||||||
Once you have created your machine identity and added it to your project(s), you will need to create a Kubernetes secret containing the identity credentials.
|
Once you have created your machine identity and added it to your project(s), you will need to create a Kubernetes secret containing the identity credentials.
|
||||||
To quickly create a Kubernetes secret containing the identity credentials, you can run the command below.
|
To quickly create a Kubernetes secret containing the identity credentials, you can run the command below.
|
||||||
|
|
||||||
Make sure you replace `<your-identity-ldap-username>` with the identity ldap username and `<your-identity-ldap-password>` with the identity ldap password.
|
Make sure you replace `<your-identity-ldap-username>` with the identity LDAP username and `<your-identity-ldap-password>` with the identity LDAP password.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
kubectl create secret generic ldap-auth-credentials --from-literal=username="<your-identity-ldap-username>" --from-literal=password="<your-identity-ldap-password>"
|
kubectl create secret generic ldap-auth-credentials --from-literal=username="<your-identity-ldap-username>" --from-literal=password="<your-identity-ldap-password>"
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ type ServiceAccountDetails struct {
|
|||||||
PrivateKey string
|
PrivateKey string
|
||||||
}
|
}
|
||||||
|
|
||||||
type MachineIdentityDetails struct {
|
type UniversalAuthIdentityDetails struct {
|
||||||
ClientId string
|
ClientId string
|
||||||
ClientSecret string
|
ClientSecret string
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -41,7 +41,7 @@ func GetKubeConfigMapByNamespacedName(ctx context.Context, reconcilerClient clie
|
|||||||
return kubeConfigMap, err
|
return kubeConfigMap, err
|
||||||
}
|
}
|
||||||
|
|
||||||
func GetInfisicalUniversalAuthFromKubeSecret(ctx context.Context, reconcilerClient client.Client, universalAuthRef v1alpha1.KubeSecretReference) (machineIdentityDetails model.MachineIdentityDetails, err error) {
|
func GetInfisicalUniversalAuthFromKubeSecret(ctx context.Context, reconcilerClient client.Client, universalAuthRef v1alpha1.KubeSecretReference) (machineIdentityDetails model.UniversalAuthIdentityDetails, err error) {
|
||||||
|
|
||||||
universalAuthCredsFromKubeSecret, err := GetKubeSecretByNamespacedName(ctx, reconcilerClient, types.NamespacedName{
|
universalAuthCredsFromKubeSecret, err := GetKubeSecretByNamespacedName(ctx, reconcilerClient, types.NamespacedName{
|
||||||
Namespace: universalAuthRef.SecretNamespace,
|
Namespace: universalAuthRef.SecretNamespace,
|
||||||
@@ -51,17 +51,17 @@ func GetInfisicalUniversalAuthFromKubeSecret(ctx context.Context, reconcilerClie
|
|||||||
})
|
})
|
||||||
|
|
||||||
if k8Errors.IsNotFound(err) {
|
if k8Errors.IsNotFound(err) {
|
||||||
return model.MachineIdentityDetails{}, nil
|
return model.UniversalAuthIdentityDetails{}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return model.MachineIdentityDetails{}, fmt.Errorf("something went wrong when fetching your machine identity credentials [err=%s]", err)
|
return model.UniversalAuthIdentityDetails{}, fmt.Errorf("something went wrong when fetching your machine identity credentials [err=%s]", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
clientIdFromSecret := universalAuthCredsFromKubeSecret.Data[INFISICAL_MACHINE_IDENTITY_CLIENT_ID]
|
clientIdFromSecret := universalAuthCredsFromKubeSecret.Data[INFISICAL_MACHINE_IDENTITY_CLIENT_ID]
|
||||||
clientSecretFromSecret := universalAuthCredsFromKubeSecret.Data[INFISICAL_MACHINE_IDENTITY_CLIENT_SECRET]
|
clientSecretFromSecret := universalAuthCredsFromKubeSecret.Data[INFISICAL_MACHINE_IDENTITY_CLIENT_SECRET]
|
||||||
|
|
||||||
return model.MachineIdentityDetails{ClientId: string(clientIdFromSecret), ClientSecret: string(clientSecretFromSecret)}, nil
|
return model.UniversalAuthIdentityDetails{ClientId: string(clientIdFromSecret), ClientSecret: string(clientSecretFromSecret)}, nil
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user