From 7116c85f2cb1f339ad2b9b5f5c856630da8e3455 Mon Sep 17 00:00:00 2001 From: Maidul Islam Date: Tue, 9 Apr 2024 20:51:19 -0400 Subject: [PATCH] remove note --- .../overview/examples/integration.mdx | 2 +- docs/api-reference/overview/examples/note.mdx | 54 ------------------- docs/mint.json | 1 - 3 files changed, 1 insertion(+), 56 deletions(-) delete mode 100644 docs/api-reference/overview/examples/note.mdx diff --git a/docs/api-reference/overview/examples/integration.mdx b/docs/api-reference/overview/examples/integration.mdx index e8da5ea49..71f5b6de4 100644 --- a/docs/api-reference/overview/examples/integration.mdx +++ b/docs/api-reference/overview/examples/integration.mdx @@ -1,5 +1,5 @@ --- -title: "Configure native integrations programmatically" +title: "Configure native integrations via API" description: "How to use Infisical API to sync secrets to external secret managers" --- diff --git a/docs/api-reference/overview/examples/note.mdx b/docs/api-reference/overview/examples/note.mdx deleted file mode 100644 index 8491dfaae..000000000 --- a/docs/api-reference/overview/examples/note.mdx +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Note on E2EE" ---- - -Each project in Infisical can have **End-to-End Encryption (E2EE)** enabled or disabled. - -By default, all projects have **E2EE** enabled which means the server is not able to decrypt any values because all secret encryption/decryption operations occur on the client-side; this can be (optionally) disabled. However, this has limitations around functionality and ease-of-use: - -- You cannot make HTTP calls to Infisical to read/write secrets in plaintext. -- You cannot leverage non-E2EE features like native integrations and in-platform automations like dynamic secrets and secret rotation. - - - - Example read/write secrets without client-side encryption/decryption - - - Example read/write secrets with client-side encryption/decryption - - - -## FAQ - - - - We recommend starting with having **E2EE** enabled and disabling it if: - - - You're self-hosting Infisical, so having your instance of Infisical be able to read your secrets isn't an issue. - - You want an easier way to read/write secrets with Infisical. - - You need more power out of non-E2EE features such as secret rotation, dynamic secrets, etc. - - - - You can enable/disable E2EE for your project in Infisical in the Project Settings. - - - It is secure and in fact how most vendors in our industry are able to offer features like secret rotation. In this mode, secrets are encrypted at rest by - a series of keys, secured ultimately by a top-level `ROOT_ENCRYPTION_KEY` located on the server. - - If you're concerned about Infisical Cloud's ability to read your secrets, then you may wish to - use it with **E2EE** enabled or self-host Infisical on your own infrastructure and disable E2EE there. - - As an organization, we do not read any customer secrets without explicit permission; access to the `ROOT_ENCRYPTION_KEY` is restricted to one individual in the organization. - - \ No newline at end of file diff --git a/docs/mint.json b/docs/mint.json index 5f3836e49..4ab246f83 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -387,7 +387,6 @@ { "group": "Examples", "pages": [ - "api-reference/overview/examples/note", "api-reference/overview/examples/integration" ] }