From 1d622bb121d59d4c0197e38603fa9592259ac397 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:40:37 +0200 Subject: [PATCH 01/13] Update agent.go --- cli/packages/cmd/agent.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cli/packages/cmd/agent.go b/cli/packages/cmd/agent.go index e29895570..f485f76a5 100644 --- a/cli/packages/cmd/agent.go +++ b/cli/packages/cmd/agent.go @@ -900,7 +900,7 @@ var agentCmd = &cobra.Command{ return } - authMethodValid, authStrategy := util.IsAuthMethodValid(agentConfig.Auth.Type) + authMethodValid, authStrategy := util.IsAuthMethodValid(agentConfig.Auth.Type, false) if !authMethodValid { util.PrintErrorMessageAndExit(fmt.Sprintf("The auth method '%s' is not supported.", agentConfig.Auth.Type)) From 4d194052b58d17b6c29503aaf561ab91b40260b4 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:40:58 +0200 Subject: [PATCH 02/13] Feat: Login support for all auth methods --- cli/packages/cmd/login.go | 134 +++++++++++++++++++++++++++++--------- 1 file changed, 104 insertions(+), 30 deletions(-) diff --git a/cli/packages/cmd/login.go b/cli/packages/cmd/login.go index a81a903a8..60721503b 100644 --- a/cli/packages/cmd/login.go +++ b/cli/packages/cmd/login.go @@ -34,6 +34,8 @@ import ( "github.com/spf13/cobra" "golang.org/x/crypto/argon2" "golang.org/x/term" + + infisicalSdk "github.com/infisical/go-sdk" ) type params struct { @@ -44,6 +46,86 @@ type params struct { keyLength uint32 } +func handleUniversalAuthLogin(cmd *cobra.Command, infisicalClient infisicalSdk.InfisicalClientInterface) (credential infisicalSdk.MachineIdentityCredential, e error) { + + clientId, err := util.GetCmdFlagOrEnv(cmd, "client-id", util.INFISICAL_UNIVERSAL_AUTH_CLIENT_ID_NAME) + + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + clientSecret, err := util.GetCmdFlagOrEnv(cmd, "client-secret", util.INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET_NAME) + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + return infisicalClient.Auth().UniversalAuthLogin(clientId, clientSecret) +} + +func handleKubernetesAuthLogin(cmd *cobra.Command, infisicalClient infisicalSdk.InfisicalClientInterface) (credential infisicalSdk.MachineIdentityCredential, e error) { + + identityId, err := util.GetCmdFlagOrEnv(cmd, "machine-identity-id", util.INFISICAL_MACHINE_IDENTITY_ID_NAME) + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + serviceAccountTokenPath, err := util.GetCmdFlagOrEnv(cmd, "service-account-token-path", util.INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_NAME) + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + return infisicalClient.Auth().KubernetesAuthLogin(identityId, serviceAccountTokenPath) +} + +func handleAzureAuthLogin(cmd *cobra.Command, infisicalClient infisicalSdk.InfisicalClientInterface) (credential infisicalSdk.MachineIdentityCredential, e error) { + + identityId, err := util.GetCmdFlagOrEnv(cmd, "machine-identity-id", util.INFISICAL_MACHINE_IDENTITY_ID_NAME) + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + return infisicalClient.Auth().AzureAuthLogin(identityId) +} + +func handleGcpIdTokenAuthLogin(cmd *cobra.Command, infisicalClient infisicalSdk.InfisicalClientInterface) (credential infisicalSdk.MachineIdentityCredential, e error) { + + identityId, err := util.GetCmdFlagOrEnv(cmd, "machine-identity-id", util.INFISICAL_MACHINE_IDENTITY_ID_NAME) + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + return infisicalClient.Auth().GcpIdTokenAuthLogin(identityId) +} + +func handleGcpIamAuthLogin(cmd *cobra.Command, infisicalClient infisicalSdk.InfisicalClientInterface) (credential infisicalSdk.MachineIdentityCredential, e error) { + + identityId, err := util.GetCmdFlagOrEnv(cmd, "machine-identity-id", util.INFISICAL_MACHINE_IDENTITY_ID_NAME) + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + serviceAccountKeyFilePath, err := util.GetCmdFlagOrEnv(cmd, "service-account-key-file-path", util.INFISICAL_GCP_IAM_SERVICE_ACCOUNT_KEY_FILE_PATH_NAME) + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + return infisicalClient.Auth().GcpIamAuthLogin(identityId, serviceAccountKeyFilePath) +} + +func handleAwsIamAuthLogin(cmd *cobra.Command, infisicalClient infisicalSdk.InfisicalClientInterface) (credential infisicalSdk.MachineIdentityCredential, e error) { + + identityId, err := util.GetCmdFlagOrEnv(cmd, "machine-identity-id", util.INFISICAL_MACHINE_IDENTITY_ID_NAME) + if err != nil { + return infisicalSdk.MachineIdentityCredential{}, err + } + + return infisicalClient.Auth().AwsIamAuthLogin(identityId) +} + +func FormatAuthMethod(authMethod string) string { + return strings.ReplaceAll(authMethod, "-", " ") +} + const ADD_USER = "Add a new account login" const REPLACE_USER = "Override current logged in user" const EXIT_USER_MENU = "Exit" @@ -56,6 +138,11 @@ var loginCmd = &cobra.Command{ DisableFlagsInUseLine: true, Run: func(cmd *cobra.Command, args []string) { + infisicalClient := infisicalSdk.NewInfisicalClient(infisicalSdk.Config{ + SiteUrl: config.INFISICAL_URL, + UserAgent: api.USER_AGENT, + }) + loginMethod, err := cmd.Flags().GetString("method") if err != nil { util.HandleError(err) @@ -65,12 +152,13 @@ var loginCmd = &cobra.Command{ util.HandleError(err) } - if loginMethod != "user" && loginMethod != "universal-auth" { - util.PrintErrorMessageAndExit("Invalid login method. Please use either 'user' or 'universal-auth'") + authMethodValid, strategy := IsAuthMethodValid(loginMethod, true) + if !authMethodValid { + util.PrintErrorMessageAndExit(fmt.Sprintf("Invalid login method: %s", loginMethod)) } + // standalone user auth if loginMethod == "user" { - currentLoggedInUserDetails, err := util.GetCurrentLoggedInUserDetails() // if the key can't be found or there is an error getting current credentials from key ring, allow them to override if err != nil && (strings.Contains(err.Error(), "we couldn't find your logged in details")) { @@ -133,7 +221,7 @@ var loginCmd = &cobra.Command{ err = util.StoreUserCredsInKeyRing(&userCredentialsToBeStored) if err != nil { - log.Error().Msgf("Unable to store your credentials in system vault [%s]") + log.Error().Msgf("Unable to store your credentials in system vault") log.Error().Msgf("\nTo trouble shoot further, read https://infisical.com/docs/cli/faq") log.Debug().Err(err) //return here @@ -160,47 +248,33 @@ var loginCmd = &cobra.Command{ fmt.Println("- Learn to inject secrets into your application at https://infisical.com/docs/cli/usage") fmt.Println("- Stuck? Join our slack for quick support https://infisical.com/slack") Telemetry.CaptureEvent("cli-command:login", posthog.NewProperties().Set("infisical-backend", config.INFISICAL_URL).Set("version", util.CLI_VERSION)) - } else if loginMethod == "universal-auth" { + } else { - clientId, err := cmd.Flags().GetString("client-id") - if err != nil { - util.HandleError(err) + authStrategies := map[util.AuthStrategyType]func(cmd *cobra.Command, infisicalClient infisicalSdk.InfisicalClientInterface) (credential infisicalSdk.MachineIdentityCredential, e error){ + util.AuthStrategy.UNIVERSAL_AUTH: handleUniversalAuthLogin, + util.AuthStrategy.KUBERNETES_AUTH: handleKubernetesAuthLogin, + util.AuthStrategy.AZURE_AUTH: handleAzureAuthLogin, + util.AuthStrategy.GCP_ID_TOKEN_AUTH: handleGcpIdTokenAuthLogin, + util.AuthStrategy.GCP_IAM_AUTH: handleGcpIamAuthLogin, + util.AuthStrategy.AWS_IAM_AUTH: handleAwsIamAuthLogin, } - clientSecret, err := cmd.Flags().GetString("client-secret") - if err != nil { - util.HandleError(err) - } - - if clientId == "" { - clientId = os.Getenv(util.INFISICAL_UNIVERSAL_AUTH_CLIENT_ID_NAME) - if clientId == "" { - util.PrintErrorMessageAndExit("Please provide client-id") - } - } - if clientSecret == "" { - clientSecret = os.Getenv(util.INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET_NAME) - if clientSecret == "" { - util.PrintErrorMessageAndExit("Please provide client-secret") - } - } - - res, err := util.UniversalAuthLogin(clientId, clientSecret) + credential, err := authStrategies[strategy](cmd, infisicalClient) if err != nil { util.HandleError(err) } if plainOutput { - fmt.Println(res.AccessToken) + fmt.Println(credential.AccessToken) return } boldGreen := color.New(color.FgGreen).Add(color.Bold) boldPlain := color.New(color.Bold) time.Sleep(time.Second * 1) - boldGreen.Printf(">>>> Successfully authenticated with Universal Auth!\n\n") - boldPlain.Printf("Universal Auth Access Token:\n%v", res.AccessToken) + boldGreen.Printf(">>>> Successfully authenticated with %s!\n\n", FormatAuthMethod(loginMethod)) + boldPlain.Printf("Access Token:\n%v", credential.AccessToken) plainBold := color.New(color.Bold) plainBold.Println("\n\nYou can use this access token to authenticate through other commands in the CLI.") From 44a898fb15ae46aebda94dd5729797f825395081 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:41:01 +0200 Subject: [PATCH 03/13] Update auth.go --- cli/packages/util/auth.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/cli/packages/util/auth.go b/cli/packages/util/auth.go index 75ffe9344..d27bbc2c8 100644 --- a/cli/packages/util/auth.go +++ b/cli/packages/util/auth.go @@ -27,9 +27,9 @@ var AVAILABLE_AUTH_STRATEGIES = []AuthStrategyType{ AuthStrategy.AWS_IAM_AUTH, } -func IsAuthMethodValid(authMethod string) (isValid bool, strategy AuthStrategyType) { +func IsAuthMethodValid(authMethod string, allowUserAuth bool) (isValid bool, strategy AuthStrategyType) { - if authMethod == "user" { + if authMethod == "user" && allowUserAuth { return true, "" } From 2ae45dc1cc1dcdca410eab6fd9f9dc7118aee97c Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:41:07 +0200 Subject: [PATCH 04/13] Feat: Login support for all auth methods --- cli/packages/util/constants.go | 3 +++ cli/packages/util/helper.go | 14 ++++++++++++++ 2 files changed, 17 insertions(+) diff --git a/cli/packages/util/constants.go b/cli/packages/util/constants.go index bff3c3ab0..57ea836d2 100644 --- a/cli/packages/util/constants.go +++ b/cli/packages/util/constants.go @@ -22,6 +22,9 @@ const ( // Generic env variable used for auth methods that require a machine identity ID INFISICAL_MACHINE_IDENTITY_ID_NAME = "INFISICAL_MACHINE_IDENTITY_ID" + // For auth methods that require a machine identity ID + INFISICAL_MACHINE_IDENTITY_ID_NAME = "INFISICAL_MACHINE_IDENTITY_ID" + SECRET_TYPE_PERSONAL = "personal" SECRET_TYPE_SHARED = "shared" KEYRING_SERVICE_NAME = "infisical" diff --git a/cli/packages/util/helper.go b/cli/packages/util/helper.go index b8eb66027..9ce8c4a1d 100644 --- a/cli/packages/util/helper.go +++ b/cli/packages/util/helper.go @@ -273,3 +273,17 @@ func GetEnvVarOrFileContent(envName string, filePath string) (string, error) { return fileContent, nil } + +func GetCmdFlagOrEnv(cmd *cobra.Command, flag, envName string) (string, error) { + value, flagsErr := cmd.Flags().GetString(flag) + if flagsErr != nil { + return "", flagsErr + } + if value == "" { + value = os.Getenv(envName) + } + if value == "" { + return "", fmt.Errorf("please provide %s flag", flag) + } + return value, nil +} From 08d3436217e2bfd230db960d8b87fa82b25274d1 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:47:22 +0200 Subject: [PATCH 05/13] Update login.go --- cli/packages/cmd/login.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cli/packages/cmd/login.go b/cli/packages/cmd/login.go index 60721503b..da05365be 100644 --- a/cli/packages/cmd/login.go +++ b/cli/packages/cmd/login.go @@ -152,7 +152,7 @@ var loginCmd = &cobra.Command{ util.HandleError(err) } - authMethodValid, strategy := IsAuthMethodValid(loginMethod, true) + authMethodValid, strategy := util.IsAuthMethodValid(loginMethod, true) if !authMethodValid { util.PrintErrorMessageAndExit(fmt.Sprintf("Invalid login method: %s", loginMethod)) } From 32609b95a0af4b337f667dcd275684412d678c2c Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:48:13 +0200 Subject: [PATCH 06/13] Update constants.go --- cli/packages/util/constants.go | 3 --- 1 file changed, 3 deletions(-) diff --git a/cli/packages/util/constants.go b/cli/packages/util/constants.go index 57ea836d2..bff3c3ab0 100644 --- a/cli/packages/util/constants.go +++ b/cli/packages/util/constants.go @@ -22,9 +22,6 @@ const ( // Generic env variable used for auth methods that require a machine identity ID INFISICAL_MACHINE_IDENTITY_ID_NAME = "INFISICAL_MACHINE_IDENTITY_ID" - // For auth methods that require a machine identity ID - INFISICAL_MACHINE_IDENTITY_ID_NAME = "INFISICAL_MACHINE_IDENTITY_ID" - SECRET_TYPE_PERSONAL = "personal" SECRET_TYPE_SHARED = "shared" KEYRING_SERVICE_NAME = "infisical" From a8ccfd9c92816b5c5541dba70b8b1f6feb9eea08 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:41:07 +0200 Subject: [PATCH 07/13] Feat: Login support for all auth methods --- cli/packages/util/constants.go | 3 +++ 1 file changed, 3 insertions(+) diff --git a/cli/packages/util/constants.go b/cli/packages/util/constants.go index bff3c3ab0..57ea836d2 100644 --- a/cli/packages/util/constants.go +++ b/cli/packages/util/constants.go @@ -22,6 +22,9 @@ const ( // Generic env variable used for auth methods that require a machine identity ID INFISICAL_MACHINE_IDENTITY_ID_NAME = "INFISICAL_MACHINE_IDENTITY_ID" + // For auth methods that require a machine identity ID + INFISICAL_MACHINE_IDENTITY_ID_NAME = "INFISICAL_MACHINE_IDENTITY_ID" + SECRET_TYPE_PERSONAL = "personal" SECRET_TYPE_SHARED = "shared" KEYRING_SERVICE_NAME = "infisical" From 1906896e566da6529164be6c28d090cabe2dad4b Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:50:45 +0200 Subject: [PATCH 08/13] Update constants.go --- cli/packages/util/constants.go | 3 --- 1 file changed, 3 deletions(-) diff --git a/cli/packages/util/constants.go b/cli/packages/util/constants.go index 57ea836d2..bff3c3ab0 100644 --- a/cli/packages/util/constants.go +++ b/cli/packages/util/constants.go @@ -22,9 +22,6 @@ const ( // Generic env variable used for auth methods that require a machine identity ID INFISICAL_MACHINE_IDENTITY_ID_NAME = "INFISICAL_MACHINE_IDENTITY_ID" - // For auth methods that require a machine identity ID - INFISICAL_MACHINE_IDENTITY_ID_NAME = "INFISICAL_MACHINE_IDENTITY_ID" - SECRET_TYPE_PERSONAL = "personal" SECRET_TYPE_SHARED = "shared" KEYRING_SERVICE_NAME = "infisical" From 8067df821ea8a49120b2ccf6851f5f3b588a4522 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 07:59:45 +0200 Subject: [PATCH 09/13] Update login.go --- cli/packages/cmd/login.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/cli/packages/cmd/login.go b/cli/packages/cmd/login.go index da05365be..186accd1c 100644 --- a/cli/packages/cmd/login.go +++ b/cli/packages/cmd/login.go @@ -122,7 +122,7 @@ func handleAwsIamAuthLogin(cmd *cobra.Command, infisicalClient infisicalSdk.Infi return infisicalClient.Auth().AwsIamAuthLogin(identityId) } -func FormatAuthMethod(authMethod string) string { +func formatAuthMethod(authMethod string) string { return strings.ReplaceAll(authMethod, "-", " ") } @@ -262,7 +262,7 @@ var loginCmd = &cobra.Command{ credential, err := authStrategies[strategy](cmd, infisicalClient) if err != nil { - util.HandleError(err) + util.HandleError(fmt.Errorf("unable to authenticate with %s [err=%v]", formatAuthMethod(loginMethod), err)) } if plainOutput { @@ -273,7 +273,7 @@ var loginCmd = &cobra.Command{ boldGreen := color.New(color.FgGreen).Add(color.Bold) boldPlain := color.New(color.Bold) time.Sleep(time.Second * 1) - boldGreen.Printf(">>>> Successfully authenticated with %s!\n\n", FormatAuthMethod(loginMethod)) + boldGreen.Printf(">>>> Successfully authenticated with %s!\n\n", formatAuthMethod(loginMethod)) boldPlain.Printf("Access Token:\n%v", credential.AccessToken) plainBold := color.New(color.Bold) From c042bafba30709dc27f312bb3e6d8e39265a1d13 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 08:27:06 +0200 Subject: [PATCH 10/13] Add flags --- cli/packages/cmd/login.go | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/cli/packages/cmd/login.go b/cli/packages/cmd/login.go index 186accd1c..0efe7af9e 100644 --- a/cli/packages/cmd/login.go +++ b/cli/packages/cmd/login.go @@ -450,9 +450,12 @@ func init() { rootCmd.AddCommand(loginCmd) loginCmd.Flags().BoolP("interactive", "i", false, "login via the command line") loginCmd.Flags().String("method", "user", "login method [user, universal-auth]") - loginCmd.Flags().String("client-id", "", "client id for universal auth") loginCmd.Flags().Bool("plain", false, "only output the token without any formatting") + loginCmd.Flags().String("client-id", "", "client id for universal auth") loginCmd.Flags().String("client-secret", "", "client secret for universal auth") + loginCmd.Flags().String("machine-identity-id", "", "machine identity id for kubernetes, azure, gcp-id-token, gcp-iam, and aws-iam auth methods") + loginCmd.Flags().String("service-account-token-path", "", "service account token path for kubernetes auth") + loginCmd.Flags().String("service-account-key-file-path", "", "service account key file path for GCP IAM auth") } func DomainOverridePrompt() (bool, error) { From 6df90fa8254efb743ddfcacb5451b35fd68d3035 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Sun, 16 Jun 2024 08:27:18 +0200 Subject: [PATCH 11/13] Docs: Improve and update infisical login cmd docs --- docs/cli/commands/login.mdx | 99 +++++++++++++++++++++++++++++++------ 1 file changed, 85 insertions(+), 14 deletions(-) diff --git a/docs/cli/commands/login.mdx b/docs/cli/commands/login.mdx index 2758ced00..636e5672c 100644 --- a/docs/cli/commands/login.mdx +++ b/docs/cli/commands/login.mdx @@ -14,6 +14,13 @@ To change where the login credentials are stored, visit the [vaults command](./v If you have added multiple users, you can switch between the users by using the [user command](./user). + + When you authenticate with **any other method than `user`**, an access token will be printed to the console upon successful login. This token can be used to authenticate with the Infisical API and the CLI by passing it in the `--token` flag when applicable. + + Use flag `--plain` along with `--silent` to print only the token in plain text when using a machine identity auth method. + + + ### Flags @@ -22,17 +29,13 @@ If you have added multiple users, you can switch between the users by using the ``` #### Valid values for the `method` flag are: - - `user`: Login using email and password. + - `user`: Login using email and password. (default) - `universal-auth`: Login using a universal auth client ID and client secret. - - - When `method` is set to `universal-auth`, the `client-id` and `client-secret` flags are required. Optionally you can set the `INFISICAL_UNIVERSAL_AUTH_CLIENT_ID` and `INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET` environment variables instead of using the flags. - - When you authenticate with universal auth, an access token will be printed to the console upon successful login. This token can be used to authenticate with the Infisical API and the CLI by passing it in the `--token` flag when applicable. - - Use flag `--plain` along with `--silent` to print only the token in plain text when using the `universal-auth` method. - - + - `kubernetes`: Login using a Kubernetes native auth. + - `azure`: Login using an Azure native auth. + - `gcp-id-token`: Login using a GCP ID token native auth. + - `gcp-iam`: Login using a GCP IAM. + - `aws-iam`: Login using an AWS IAM native auth. @@ -41,7 +44,7 @@ If you have added multiple users, you can switch between the users by using the ``` #### Description - The client ID of the universal auth client. This is required if the `--method` flag is set to `universal-auth`. + The client ID of the universal auth machine identity. This is required if the `--method` flag is set to `universal-auth`. The `client-id` flag can be substituted with the `INFISICAL_UNIVERSAL_AUTH_CLIENT_ID` environment variable. @@ -52,13 +55,81 @@ If you have added multiple users, you can switch between the users by using the infisical login --client-secret= # Optional, required if --method=universal-auth. ``` #### Description - The client secret of the universal auth client. This is required if the `--method` flag is set to `universal-auth`. + The client secret of the universal auth machine identity. This is required if the `--method` flag is set to `universal-auth`. The `client-secret` flag can be substituted with the `INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET` environment variable. - + + + ```bash + infisical login --machine-identity-id= # Optional, required if --method=kubernetes, azure, gcp-id-token, gcp-iam, or aws-iam. + ``` + + #### Description + The ID of the machine identity. This is required if the `--method` flag is set to `kubernetes`, `azure`, `gcp-id-token`, `gcp-iam`, or `aws-iam`. + + + The `machine-identity-id` flag can be substituted with the `INFISICAL_MACHINE_IDENTITY_ID` environment variable. + + + + ```bash + infisical login --service-account-token-path= # Optional Will default to '/var/run/secrets/kubernetes.io/serviceaccount/token'. + ``` + + #### Description + The path to the Kubernetes service account token to use for authentication. + This is optional and will default to `/var/run/secrets/kubernetes.io/serviceaccount/token`. + + + The `service-account-token-path` flag can be substituted with the `INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH` environment variable. + + + + ```bash + infisical login --service-account-key-file-path= # Optional, but required if --method=gcp-iam. + ``` + + #### Description + The path to your GCP service account key file. This is required if the `--method` flag is set to `gcp-iam`. + + + The `service-account-key-path` flag can be substituted with the `INFISICAL_GCP_IAM_SERVICE_ACCOUNT_KEY_FILE_PATH` environment variable. + - \ No newline at end of file +### Machine Identity Authentication Quick Start +In this example we'll be using the `universal-auth` method to login to obtain an Infisical access token, which we will then use to fetch secrets with. + + + + ```bash + export INFISICAL_TOKEN=$(infisical login --method=universal-auth --client-id= --client-secret= --silent --plain) # silent and plain is important to ensure only the token itself is printed, so we can easily set it as an environment variable. + ``` + + Now that we've set the `INFISICAL_TOKEN` environment variable, we can use the CLI to interact with Infisical. The CLI will automatically check for the presence of the `INFISICAL_TOKEN` environment variable and use it for authentication. + + + Alternatively, if you would rather use the `--token` flag to pass the token directly, you can do so by running the following command: + + ```bash + infisical [command] --token= # The token output from the login command. + ``` + + + + ```bash + infisical secrets --projectId= + The `--recursive`, and `--env` flag is optional and will fetch all secrets in subfolders. The default environment is `dev` if no `--env` flag is provided. + + + + +And that's it! Now you're ready to start using the Infisical CLI to interact with your secrets, with the use of Machine Identities. From 7d380f9b43e98031aa42a9125829cf16916b773d Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Wed, 19 Jun 2024 19:34:12 +0200 Subject: [PATCH 12/13] fix: documentation improvements --- docs/cli/commands/login.mdx | 169 +++++++++++++++++++++++++++++++++++- 1 file changed, 168 insertions(+), 1 deletion(-) diff --git a/docs/cli/commands/login.mdx b/docs/cli/commands/login.mdx index 636e5672c..9e011324f 100644 --- a/docs/cli/commands/login.mdx +++ b/docs/cli/commands/login.mdx @@ -7,7 +7,7 @@ description: "Login into Infisical from the CLI" infisical login ``` -## Description +### Description The CLI uses authentication to verify your identity. When you enter the correct email and password for your account, a token is generated and saved in your system Keyring to allow you to make future interactions with the CLI. To change where the login credentials are stored, visit the [vaults command](./vault). @@ -23,6 +23,9 @@ If you have added multiple users, you can switch between the users by using the ### Flags +The login command supports a number of flags that you can use for different authentication methods. Below is a list of all the flags that can be used with the login command. + + ```bash infisical login --method= # Optional, will default to 'user'. @@ -98,8 +101,172 @@ If you have added multiple users, you can switch between the users by using the The `service-account-key-path` flag can be substituted with the `INFISICAL_GCP_IAM_SERVICE_ACCOUNT_KEY_FILE_PATH` environment variable. + +### Authentication Methods + +The Infisical CLI supports multiple authentication methods. Below are the available authentication methods, with their respective flags. + + + + The Universal Auth method is a simple and secure way to authenticate with Infisical. It requires a client ID and a client secret to authenticate with Infisical. + + + + + Your machine identity client ID. + + + Your machine identity client secret. + + + + + + + To create a universal auth machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/universal-auth). + + + Run the `login` command with the following flags to obtain an access token: + + ```bash + infisical login --method=universal-auth --client-id= --client-secret= + ``` + + + + + The Native Kubernetes method is used to authenticate with Infisical when running in a Kubernetes environment. It requires a service account token to authenticate with Infisical. + + + + + Your machine identity ID. + + + Path to the Kubernetes service account token to use. Default: `/var/run/secrets/kubernetes.io/serviceaccount/token`. + + + + + + + To create a Kubernetes machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/kubernetes-auth). + + + Run the `login` command with the following flags to obtain an access token: + + ```bash + # --service-account-token-path is optional, and will default to '/var/run/secrets/kubernetes.io/serviceaccount/token' if not provided. + infisical login --method=kubernetes --machine-identity-id= --service-account-token-path= + ``` + + + + + + The Native Azure method is used to authenticate with Infisical when running in an Azure environment. + + + + + Your machine identity ID. + + + + + + + To create an Azure machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/azure-auth). + + + Run the `login` command with the following flags to obtain an access token: + + ```bash + infisical login --method=azure --machine-identity-id= + ``` + + + + + + The Native GCP ID Token method is used to authenticate with Infisical when running in a GCP environment. + + + + + Your machine identity ID. + + + + + + + To create a GCP machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/gcp-auth). + + + Run the `login` command with the following flags to obtain an access token: + + ```bash + infisical login --method=gcp-id-token --machine-identity-id= + ``` + + + + + The GCP IAM method is used to authenticate with Infisical with a GCP service account key. + + + + + Your machine identity ID. + + + Path to your GCP service account key file _(Must be in JSON format!)_ + + + + + + + To create a GCP machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/gcp-auth). + + + Run the `login` command with the following flags to obtain an access token: + + ```bash + infisical login --method=gcp-iam --machine-identity-id= --service-account-key-file-path= + ``` + + + + + The AWS IAM method is used to authenticate with Infisical with an AWS IAM role while running in an AWS environment like EC2, Lambda, etc. + + + + + Your machine identity ID. + + + + + + + To create an AWS machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/aws-auth). + + + Run the `login` command with the following flags to obtain an access token: + + ```bash + infisical login --method=aws-iam --machine-identity-id= + ``` + + + + + ### Machine Identity Authentication Quick Start In this example we'll be using the `universal-auth` method to login to obtain an Infisical access token, which we will then use to fetch secrets with. From fe6dc248b61dd3fc961aed500f2ab509fb4adedb Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Wed, 19 Jun 2024 19:40:27 +0200 Subject: [PATCH 13/13] Update login.mdx --- docs/cli/commands/login.mdx | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/cli/commands/login.mdx b/docs/cli/commands/login.mdx index 9e011324f..d97cb4c2b 100644 --- a/docs/cli/commands/login.mdx +++ b/docs/cli/commands/login.mdx @@ -112,7 +112,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa The Universal Auth method is a simple and secure way to authenticate with Infisical. It requires a client ID and a client secret to authenticate with Infisical. - + Your machine identity client ID. @@ -139,7 +139,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa The Native Kubernetes method is used to authenticate with Infisical when running in a Kubernetes environment. It requires a service account token to authenticate with Infisical. - + Your machine identity ID. @@ -168,7 +168,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa The Native Azure method is used to authenticate with Infisical when running in an Azure environment. - + Your machine identity ID. @@ -193,7 +193,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa The Native GCP ID Token method is used to authenticate with Infisical when running in a GCP environment. - + Your machine identity ID. @@ -217,7 +217,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa The GCP IAM method is used to authenticate with Infisical with a GCP service account key. - + Your machine identity ID. @@ -244,7 +244,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa The AWS IAM method is used to authenticate with Infisical with an AWS IAM role while running in an AWS environment like EC2, Lambda, etc. - + Your machine identity ID.