mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 22:27:48 +00:00
misc: doc improvements
This commit is contained in:
@@ -73,127 +73,130 @@ This feature is ideal for scenarios where you need to:
|
|||||||
|
|
||||||
Choose your authentication method:
|
Choose your authentication method:
|
||||||
|
|
||||||
#### Option 1: Token (API) Authentication
|
<AccordionGroup>
|
||||||
This method uses a service account token to authenticate with the Kubernetes cluster. It's suitable when:
|
<Accordion title="Token (API) Authentication">
|
||||||
- You want to use a specific service account token that you've created
|
This method uses a service account token to authenticate with the Kubernetes cluster. It's suitable when:
|
||||||
- You're working with a public cluster or have network access to the cluster's API server
|
- You want to use a specific service account token that you've created
|
||||||
- You want to explicitly control which service account is used for operations
|
- You're working with a public cluster or have network access to the cluster's API server
|
||||||
|
- You want to explicitly control which service account is used for operations
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
With Token (API) authentication, Infisical uses the provided service account token
|
With Token (API) authentication, Infisical uses the provided service account token
|
||||||
to make API calls to your Kubernetes cluster. This token must have the necessary
|
to make API calls to your Kubernetes cluster. This token must have the necessary
|
||||||
permissions to generate tokens for the target service account.
|
permissions to generate tokens for the target service account.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
1. Create a service account:
|
1. Create a service account:
|
||||||
```yaml infisical-service-account.yaml
|
```yaml infisical-service-account.yaml
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
name: infisical-token-requester
|
name: infisical-token-requester
|
||||||
namespace: default
|
namespace: default
|
||||||
```
|
```
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
kubectl apply -f infisical-service-account.yaml
|
kubectl apply -f infisical-service-account.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
2. Set up RBAC permissions:
|
2. Set up RBAC permissions:
|
||||||
```yaml rbac.yaml
|
```yaml rbac.yaml
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: tokenrequest
|
name: tokenrequest
|
||||||
rules:
|
rules:
|
||||||
- apiGroups: [""]
|
- apiGroups: [""]
|
||||||
resources:
|
resources:
|
||||||
- "serviceaccounts/token"
|
- "serviceaccounts/token"
|
||||||
- "serviceaccounts"
|
- "serviceaccounts"
|
||||||
verbs:
|
verbs:
|
||||||
- "create"
|
- "create"
|
||||||
- "get"
|
- "get"
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: tokenrequest
|
name: tokenrequest
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: tokenrequest
|
name: tokenrequest
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: infisical-token-requester
|
name: infisical-token-requester
|
||||||
namespace: default
|
namespace: default
|
||||||
```
|
```
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
kubectl apply -f rbac.yaml
|
kubectl apply -f rbac.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
3. Create and obtain the token:
|
3. Create and obtain the token:
|
||||||
```yaml service-account-token.yaml
|
```yaml service-account-token.yaml
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Secret
|
kind: Secret
|
||||||
type: kubernetes.io/service-account-token
|
type: kubernetes.io/service-account-token
|
||||||
metadata:
|
metadata:
|
||||||
name: infisical-token-requester-token
|
name: infisical-token-requester-token
|
||||||
annotations:
|
annotations:
|
||||||
kubernetes.io/service-account.name: "infisical-token-requester"
|
kubernetes.io/service-account.name: "infisical-token-requester"
|
||||||
```
|
```
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
kubectl apply -f service-account-token.yaml
|
kubectl apply -f service-account-token.yaml
|
||||||
kubectl patch serviceaccount infisical-token-requester -p '{"secrets": [{"name": "infisical-token-requester-token"}]}' -n default
|
kubectl patch serviceaccount infisical-token-requester -p '{"secrets": [{"name": "infisical-token-requester-token"}]}' -n default
|
||||||
kubectl get secret infisical-token-requester-token -n default -o=jsonpath='{.data.token}' | base64 --decode
|
kubectl get secret infisical-token-requester-token -n default -o=jsonpath='{.data.token}' | base64 --decode
|
||||||
```
|
```
|
||||||
|
</Accordion>
|
||||||
|
<Accordion title="Gateway Authentication">
|
||||||
|
This method uses an Infisical Gateway deployed in your Kubernetes cluster. It's ideal when:
|
||||||
|
- You want to avoid storing static service account tokens
|
||||||
|
- You prefer to use the Gateway's pre-configured service account
|
||||||
|
- You want centralized management of cluster operations
|
||||||
|
|
||||||
#### Option 2: Gateway Authentication
|
<Note>
|
||||||
This method uses an Infisical Gateway deployed in your Kubernetes cluster. It's ideal when:
|
With Gateway authentication, Infisical communicates with the Gateway, which then
|
||||||
- You want to avoid storing static service account tokens
|
uses its own service account to make API calls to the Kubernetes API server.
|
||||||
- You prefer to use the Gateway's pre-configured service account
|
The Gateway's service account must have the necessary permissions to generate
|
||||||
- You want centralized management of cluster operations
|
tokens for the target service account.
|
||||||
|
</Note>
|
||||||
|
|
||||||
<Note>
|
1. Deploy the Infisical Gateway in your cluster
|
||||||
With Gateway authentication, Infisical communicates with the Gateway, which then
|
2. Set up RBAC permissions for the Gateway's service account:
|
||||||
uses its own service account to make API calls to the Kubernetes API server.
|
```yaml rbac.yaml
|
||||||
The Gateway's service account must have the necessary permissions to generate
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
tokens for the target service account.
|
kind: ClusterRole
|
||||||
</Note>
|
metadata:
|
||||||
|
name: tokenrequest
|
||||||
|
rules:
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- "serviceaccounts/token"
|
||||||
|
- "serviceaccounts"
|
||||||
|
verbs:
|
||||||
|
- "create"
|
||||||
|
- "get"
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: tokenrequest
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: tokenrequest
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: infisical-gateway
|
||||||
|
namespace: infisical
|
||||||
|
```
|
||||||
|
|
||||||
1. Deploy the Infisical Gateway in your cluster
|
```bash
|
||||||
2. Set up RBAC permissions for the Gateway's service account:
|
kubectl apply -f rbac.yaml
|
||||||
```yaml rbac.yaml
|
```
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
</Accordion>
|
||||||
kind: ClusterRole
|
</AccordionGroup>
|
||||||
metadata:
|
|
||||||
name: tokenrequest
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources:
|
|
||||||
- "serviceaccounts/token"
|
|
||||||
- "serviceaccounts"
|
|
||||||
verbs:
|
|
||||||
- "create"
|
|
||||||
- "get"
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: tokenrequest
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: tokenrequest
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: infisical-gateway
|
|
||||||
namespace: infisical
|
|
||||||
```
|
|
||||||
|
|
||||||
```bash
|
|
||||||
kubectl apply -f rbac.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
|
|
||||||
@@ -214,201 +217,163 @@ This feature is ideal for scenarios where you need to:
|
|||||||
|
|
||||||
Choose your authentication method:
|
Choose your authentication method:
|
||||||
|
|
||||||
#### Option 1: Token (API) Authentication
|
<AccordionGroup>
|
||||||
This method uses a service account token to authenticate with the Kubernetes cluster. It's suitable when:
|
<Accordion title="Token (API) Authentication">
|
||||||
- You want to use a specific service account token that you've created
|
This method uses a service account token to authenticate with the Kubernetes cluster. It's suitable when:
|
||||||
- You're working with a public cluster or have network access to the cluster's API server
|
- You want to use a specific service account token that you've created
|
||||||
- You want to explicitly control which service account is used for operations
|
- You're working with a public cluster or have network access to the cluster's API server
|
||||||
|
- You want to explicitly control which service account is used for operations
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
With Token (API) authentication, Infisical uses the provided service account token
|
With Token (API) authentication, Infisical uses the provided service account token
|
||||||
to make API calls to your Kubernetes cluster. This token must have the necessary
|
to make API calls to your Kubernetes cluster. This token must have the necessary
|
||||||
permissions to create and manage service accounts, their tokens, and RBAC resources.
|
permissions to create and manage service accounts, their tokens, and RBAC resources.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
1. Create a service account:
|
1. Create a service account:
|
||||||
```yaml service-account.yaml
|
```yaml service-account.yaml
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
name: infisical-token-requester
|
name: infisical-token-requester
|
||||||
namespace: default
|
namespace: default
|
||||||
---
|
---
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Secret
|
kind: Secret
|
||||||
type: kubernetes.io/service-account-token
|
type: kubernetes.io/service-account-token
|
||||||
metadata:
|
metadata:
|
||||||
name: infisical-token-requester-token
|
name: infisical-token-requester-token
|
||||||
annotations:
|
annotations:
|
||||||
kubernetes.io/service-account.name: "infisical-token-requester"
|
kubernetes.io/service-account.name: "infisical-token-requester"
|
||||||
```
|
```
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
kubectl apply -f service-account.yaml
|
kubectl apply -f service-account.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
2. Set up RBAC permissions:
|
2. Set up RBAC permissions:
|
||||||
```yaml rbac.yaml
|
```yaml rbac.yaml
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: tokenrequest
|
name: tokenrequest
|
||||||
rules:
|
rules:
|
||||||
- apiGroups: [""]
|
- apiGroups: [""]
|
||||||
resources:
|
resources:
|
||||||
- "serviceaccounts/token"
|
- "serviceaccounts/token"
|
||||||
- "serviceaccounts"
|
- "serviceaccounts"
|
||||||
verbs:
|
verbs:
|
||||||
- "create"
|
- "create"
|
||||||
- "get"
|
- "get"
|
||||||
- "delete"
|
- "delete"
|
||||||
- apiGroups: ["rbac.authorization.k8s.io"]
|
- apiGroups: ["rbac.authorization.k8s.io"]
|
||||||
resources:
|
resources:
|
||||||
- "rolebindings"
|
- "rolebindings"
|
||||||
- "clusterrolebindings"
|
- "clusterrolebindings"
|
||||||
verbs:
|
verbs:
|
||||||
- "create"
|
- "create"
|
||||||
- "delete"
|
- "delete"
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: tokenrequest
|
name: tokenrequest
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: tokenrequest
|
name: tokenrequest
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: infisical-token-requester
|
name: infisical-token-requester
|
||||||
namespace: default
|
namespace: default
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: infisical-dynamic-role-binding-sa
|
name: infisical-dynamic-role-binding-sa
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: infisical-dynamic-role
|
name: infisical-dynamic-role
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: infisical-token-requester
|
name: infisical-token-requester
|
||||||
namespace: default
|
namespace: default
|
||||||
```
|
```
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
kubectl apply -f rbac.yaml
|
kubectl apply -f rbac.yaml
|
||||||
```
|
```
|
||||||
|
</Accordion>
|
||||||
|
<Accordion title="Gateway Authentication">
|
||||||
|
This method uses an Infisical Gateway deployed in your Kubernetes cluster. It's ideal when:
|
||||||
|
- You want to avoid storing static service account tokens
|
||||||
|
- You prefer to use the Gateway's pre-configured service account
|
||||||
|
- You want centralized management of cluster operations
|
||||||
|
|
||||||
#### Option 2: Gateway Authentication
|
<Note>
|
||||||
This method uses an Infisical Gateway deployed in your Kubernetes cluster. It's ideal when:
|
With Gateway authentication, Infisical communicates with the Gateway, which then
|
||||||
- You want to avoid storing static service account tokens
|
uses its own service account to make API calls to the Kubernetes API server.
|
||||||
- You prefer to use the Gateway's pre-configured service account
|
The Gateway's service account must have the necessary permissions to create and
|
||||||
- You want centralized management of cluster operations
|
manage service accounts, their tokens, and RBAC resources.
|
||||||
|
</Note>
|
||||||
|
|
||||||
<Note>
|
1. Deploy the Infisical Gateway in your cluster
|
||||||
With Gateway authentication, Infisical communicates with the Gateway, which then
|
2. Set up RBAC permissions for the Gateway's service account:
|
||||||
uses its own service account to make API calls to the Kubernetes API server.
|
```yaml rbac.yaml
|
||||||
The Gateway's service account must have the necessary permissions to create and
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
manage service accounts, their tokens, and RBAC resources.
|
kind: ClusterRole
|
||||||
</Note>
|
metadata:
|
||||||
|
name: tokenrequest
|
||||||
|
rules:
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- "serviceaccounts/token"
|
||||||
|
- "serviceaccounts"
|
||||||
|
verbs:
|
||||||
|
- "create"
|
||||||
|
- "get"
|
||||||
|
- "delete"
|
||||||
|
- apiGroups: ["rbac.authorization.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- "rolebindings"
|
||||||
|
- "clusterrolebindings"
|
||||||
|
verbs:
|
||||||
|
- "create"
|
||||||
|
- "delete"
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: tokenrequest
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: tokenrequest
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: infisical-gateway
|
||||||
|
namespace: infisical
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: infisical-dynamic-role-binding-sa
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: infisical-dynamic-role
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: infisical-gateway
|
||||||
|
namespace: infisical
|
||||||
|
```
|
||||||
|
|
||||||
1. Deploy the Infisical Gateway in your cluster
|
```bash
|
||||||
2. Set up RBAC permissions for the Gateway's service account:
|
kubectl apply -f rbac.yaml
|
||||||
```yaml rbac.yaml
|
```
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
</Accordion>
|
||||||
kind: ClusterRole
|
</AccordionGroup>
|
||||||
metadata:
|
|
||||||
name: tokenrequest
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources:
|
|
||||||
- "serviceaccounts/token"
|
|
||||||
- "serviceaccounts"
|
|
||||||
verbs:
|
|
||||||
- "create"
|
|
||||||
- "get"
|
|
||||||
- "delete"
|
|
||||||
- apiGroups: ["rbac.authorization.k8s.io"]
|
|
||||||
resources:
|
|
||||||
- "rolebindings"
|
|
||||||
- "clusterrolebindings"
|
|
||||||
verbs:
|
|
||||||
- "create"
|
|
||||||
- "delete"
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: tokenrequest
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: tokenrequest
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: infisical-gateway
|
|
||||||
namespace: infisical
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: infisical-dynamic-role-binding-sa
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: infisical-dynamic-role
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: infisical-gateway
|
|
||||||
namespace: infisical
|
|
||||||
```
|
|
||||||
|
|
||||||
```bash
|
|
||||||
kubectl apply -f rbac.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
### Example Role Configuration
|
|
||||||
|
|
||||||
Here's an example of a role that can be assigned to dynamically created service accounts:
|
|
||||||
|
|
||||||
```yaml test-role.yaml
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: infisical-dynamic-role
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources:
|
|
||||||
- "pods"
|
|
||||||
- "configmaps"
|
|
||||||
- "secrets"
|
|
||||||
verbs:
|
|
||||||
- "get"
|
|
||||||
- "list"
|
|
||||||
- "watch"
|
|
||||||
- apiGroups: ["apps"]
|
|
||||||
resources:
|
|
||||||
- "deployments"
|
|
||||||
- "statefulsets"
|
|
||||||
verbs:
|
|
||||||
- "get"
|
|
||||||
- "list"
|
|
||||||
- "watch"
|
|
||||||
- apiGroups: ["batch"]
|
|
||||||
resources:
|
|
||||||
- "jobs"
|
|
||||||
- "cronjobs"
|
|
||||||
verbs:
|
|
||||||
- "get"
|
|
||||||
- "list"
|
|
||||||
- "watch"
|
|
||||||
```
|
|
||||||
|
|
||||||
```bash
|
|
||||||
kubectl apply -f test-role.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
In Kubernetes RBAC, a service account can only create role bindings for resources that it has access to.
|
In Kubernetes RBAC, a service account can only create role bindings for resources that it has access to.
|
||||||
|
|||||||
Reference in New Issue
Block a user