Switch access token tracking to be persistent, add num uses, draft token renewal, update docs

This commit is contained in:
Tuan Dang
2023-12-07 00:11:16 +07:00
parent aafbe40c02
commit 69b57817d6
17 changed files with 481 additions and 209 deletions

View File

@@ -19,8 +19,10 @@ fetch secrets back from the `/` path of the `development` environment in some pr
Here's a few pointers to get you acquainted with MIs:
- Each MI has a **Client ID** for which you can generate one or more **Client Secret(s)**. Together, a **Client ID** and **Client Secret** can be exchanged for an access token to authenticate with the Infisical API.
- MIs support IP allowlisting; this means you can restrict the usage of a MI access token to a specific IP or CIDR range.
- Each MI has a **Client ID** for which you can generate one or more **Client Secret(s)**. Together, a **Client ID** and **Client Secret** can be exchanged for an access token (i.e. login operation) to authenticate with the Infisical API.
- MIs support restrictions on the number of times that the **Client Secret(s)** and access token(s) can be used.
- MIs support token renewal that is the ability to extend the lifetime of a token by its TTL up to its maximum TTL since its creation.
- MIs support IP allowlisting; this means you can restrict the usage of **Client Secret(s)** and access token to a specific IP or CIDR range.
- MIs rely on the role-based permission system to provision access to resources like secrets.
- MIs support expiration, so, if specified, the client secret of the MI will automatically be defunct after a period of time.
- MIs tracks most recent usage of their client secrets and access tokens; they also keep track of each token's usage count.
@@ -42,7 +44,9 @@ In the following steps, we explore how to create and use MIs for your applicatio
- Name (required): A friendly name for the MI
- Role (required): A role from the **Organization Roles** tab to permit the MI to access certain resources.
- Access Token TTL: The time-to-live for each acccess token in seconds.
- Access Token Max TTL (default is `7200`): The maximum lifetime for an acccess token in seconds; a value of `0` implies an infinite maximum lifetime.
- Access Token TTL (default is `7200`): The incremental lifetime for an acccess token in seconds; a value of `0` implies an infinite incremental lifetime.
- Access Token Max Number of Uses (default is `0`): The maximum number of times that an access token can be used; a value of `0` implies infinite number of uses.
- Client Secret Trusted IPs: The IPs or CIDR ranges that the **Client Secret** can be used from together with the **Client ID** to get back an access token. By default, **Client Secrets** are given the `0.0.0.0/0` entry representing all possible IPv4 addresses.
- Access Token Trusted IPs: The IPs or CIDR ranges that access tokens can be used from. By default, each token is given the `0.0.0.0/0` entry representing all possible IPv4 addresses.
@@ -66,7 +70,8 @@ In the following steps, we explore how to create and use MIs for your applicatio
Feel free to input any (optional) details for the **Client Secret** configuration:
- Description: A description for the **Client Secret**.
- TTL: The time-to-live for the **Client Secret**. By default, the TTL will be set to 0 which implies that the **Client Secret** will never expire.
- TTL (default is `0`): The time-to-live for the **Client Secret**. By default, the TTL will be set to 0 which implies that the **Client Secret** will never expire; a value of `0` implies an infinite lifetime.
- Max Number of Uses (default is `0`): The maximum number of times that the **Client Secret** can be used together with the **Client ID** to get back an access token; a value of `0` implies infinite number of uses.
</Step>
<Step title="Adding a MI to a project">
To enable the MI to access project-level resources such as secrets within a specific project, you should add it to that project.
@@ -121,8 +126,8 @@ In the following steps, we explore how to create and use MIs for your applicatio
<Accordion title="What is the difference between a machine identity and service token?">
A service token is a project-level authentication method that is being phased out in favor of MIs.
Amongst many differences, MIs provide broader access over the Infisical API with the same role-based
permission system used by users.
Amongst many differences, MIs provide broader access over the Infisical API, utilizes the same role-based
permission system used by users, and comes with ample more configurable security measures.
</Accordion>
<Accordion title="Why is the Infisical API rejecting my machine identity credentials?">
There are a few reasons for why this might happen:
@@ -132,6 +137,15 @@ In the following steps, we explore how to create and use MIs for your applicatio
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
- The client secret/access token is being used from an untrusted IP.
</Accordion>
<Accordion title="What is token renewal and TTL/Max TTL?">
A MI access token can have a time-to-live (TTL) or incremental lifetime afterwhich it expires.
In certain cases, you may want to extend the lifespan of an access token; to do so, you must use the max TTL parameter.
When TTL and max TTL are equal, a token is not renewable; when max TTL is greater than TTL, a token is renewable.
In the latter case, a token still expires at its TTL but its lifetime can be extended/renewed up until its max TLL.
Note that the max TTL cannot be less than the TTL for an access token.
</Accordion>
<Accordion title="Why can I not create, read, update, or delete a machine identity?">
There are a few reasons for why this might happen: