mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Update high-availability.mdx
This commit is contained in:
@@ -80,7 +80,7 @@ This is how you would run the playbook containing the roles for setting up Infis
|
|||||||
### Installing the Infisical High Availability Deployment Ansible Role
|
### Installing the Infisical High Availability Deployment Ansible Role
|
||||||
The Infisical Ansible role is available on Ansible Galaxy. You can install the role by running the following command:
|
The Infisical Ansible role is available on Ansible Galaxy. You can install the role by running the following command:
|
||||||
```bash
|
```bash
|
||||||
ansible-galaxy install infisical.infisical-core-ha-deployment
|
ansible-galaxy collection install infisical.infisical_core_ha_deployment
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
@@ -128,8 +128,10 @@ The ETCD cluster is used to store and distribute data between the PostgreSQL nod
|
|||||||
- name: Set up etcd cluster
|
- name: Set up etcd cluster
|
||||||
hosts: etcd
|
hosts: etcd
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.etcd
|
- role: etcd
|
||||||
```
|
```
|
||||||
|
|
||||||
```ini example.inventory.ini
|
```ini example.inventory.ini
|
||||||
@@ -162,8 +164,10 @@ Make sure to set the following variables in your playbook.yml file:
|
|||||||
- name: Set up PostgreSQL with Patroni
|
- name: Set up PostgreSQL with Patroni
|
||||||
hosts: postgres
|
hosts: postgres
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.postgres
|
- role: postgres
|
||||||
vars:
|
vars:
|
||||||
postgres_super_user_password: "your-super-user-password"
|
postgres_super_user_password: "your-super-user-password"
|
||||||
postgres_user: infisical-user
|
postgres_user: infisical-user
|
||||||
@@ -194,8 +198,10 @@ The Sentinel and Redis hosts will run the same role, therefore we are running th
|
|||||||
- name: Setup Redis and Sentinel
|
- name: Setup Redis and Sentinel
|
||||||
hosts: redis:sentinel
|
hosts: redis:sentinel
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.redis
|
- role: redis
|
||||||
vars:
|
vars:
|
||||||
redis_password: "REDIS_PASSWORD"
|
redis_password: "REDIS_PASSWORD"
|
||||||
```
|
```
|
||||||
@@ -239,8 +245,10 @@ internal_lb ansible_host=52.1.0.2
|
|||||||
- name: Set up HAProxy
|
- name: Set up HAProxy
|
||||||
hosts: haproxy
|
hosts: haproxy
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.haproxy
|
- role: haproxy
|
||||||
vars:
|
vars:
|
||||||
stats_user: "stats-username"
|
stats_user: "stats-username"
|
||||||
stats_password: "stats-password!"
|
stats_password: "stats-password!"
|
||||||
@@ -272,8 +280,10 @@ The `DB_CONNECTION_URI` and `REDIS_URL` variables will automatically be set if y
|
|||||||
- name: Setup Infisical
|
- name: Setup Infisical
|
||||||
hosts: infisical
|
hosts: infisical
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.infisical
|
- role: infisical
|
||||||
env_vars:
|
env_vars:
|
||||||
ENCRYPTION_KEY: "YOUR_ENCRYPTION_KEY" # openssl rand -hex 16
|
ENCRYPTION_KEY: "YOUR_ENCRYPTION_KEY" # openssl rand -hex 16
|
||||||
AUTH_SECRET: "YOUR_AUTH_SECRET" # openssl rand -base64 32
|
AUTH_SECRET: "YOUR_AUTH_SECRET" # openssl rand -base64 32
|
||||||
@@ -299,8 +309,10 @@ To bring your own database, you need to set the `DB_CONNECTION_URI` and `REDIS_U
|
|||||||
- name: Setup Infisical
|
- name: Setup Infisical
|
||||||
hosts: infisical
|
hosts: infisical
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.infisical
|
- role: infisical
|
||||||
env_vars:
|
env_vars:
|
||||||
ENCRYPTION_KEY: "YOUR_ENCRYPTION_KEY" # openssl rand -hex 16
|
ENCRYPTION_KEY: "YOUR_ENCRYPTION_KEY" # openssl rand -hex 16
|
||||||
AUTH_SECRET: "YOUR_AUTH_SECRET" # openssl rand -base64 32
|
AUTH_SECRET: "YOUR_AUTH_SECRET" # openssl rand -base64 32
|
||||||
@@ -334,7 +346,7 @@ To make it easier to get started, we've provided a full deployment example that
|
|||||||
<Step title="Install the Infisical deployment Ansible Role">
|
<Step title="Install the Infisical deployment Ansible Role">
|
||||||
Install the Infisical deployment role from Ansible Galaxy.
|
Install the Infisical deployment role from Ansible Galaxy.
|
||||||
```bash
|
```bash
|
||||||
ansible-galaxy install infisical.infisical-core-ha-deployment
|
ansible-galaxy collection install infisical.infisical_core_ha_deployment
|
||||||
```
|
```
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Setup your hosts">
|
<Step title="Setup your hosts">
|
||||||
@@ -391,14 +403,18 @@ To make it easier to get started, we've provided a full deployment example that
|
|||||||
- name: Set up etcd cluster
|
- name: Set up etcd cluster
|
||||||
hosts: etcd
|
hosts: etcd
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.etcd
|
- role: etcd
|
||||||
|
|
||||||
- name: Set up PostgreSQL with Patroni
|
- name: Set up PostgreSQL with Patroni
|
||||||
hosts: postgres
|
hosts: postgres
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.postgres
|
- role: postgres
|
||||||
vars:
|
vars:
|
||||||
postgres_super_user_password: "<ENTER_SUPERUSER_PASSWORD>" # Password for the 'postgres' database user
|
postgres_super_user_password: "<ENTER_SUPERUSER_PASSWORD>" # Password for the 'postgres' database user
|
||||||
|
|
||||||
@@ -412,16 +428,20 @@ To make it easier to get started, we've provided a full deployment example that
|
|||||||
- name: Setup Redis and Sentinel
|
- name: Setup Redis and Sentinel
|
||||||
hosts: redis:sentinel
|
hosts: redis:sentinel
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.redis
|
- role: redis
|
||||||
vars:
|
vars:
|
||||||
redis_password: "<ENTER_REDIS_PASSWORD>"
|
redis_password: "<ENTER_REDIS_PASSWORD>"
|
||||||
|
|
||||||
- name: Set up HAProxy
|
- name: Set up HAProxy
|
||||||
hosts: haproxy
|
hosts: haproxy
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.haproxy
|
- role: haproxy
|
||||||
vars:
|
vars:
|
||||||
stats_user: "<ENTER_HAPROXY_STATS_USERNAME>"
|
stats_user: "<ENTER_HAPROXY_STATS_USERNAME>"
|
||||||
stats_password: "<ENTER_HAPROXY_STATS_PASSWORD>"
|
stats_password: "<ENTER_HAPROXY_STATS_PASSWORD>"
|
||||||
@@ -432,8 +452,10 @@ To make it easier to get started, we've provided a full deployment example that
|
|||||||
- name: Setup Infisical
|
- name: Setup Infisical
|
||||||
hosts: infisical
|
hosts: infisical
|
||||||
become: true
|
become: true
|
||||||
|
collections:
|
||||||
|
- infisical.infisical_core_ha_deployment
|
||||||
roles:
|
roles:
|
||||||
- role: infisical.infisical-core-ha-deployment.infisical
|
- role: infisical
|
||||||
env_vars:
|
env_vars:
|
||||||
ENCRYPTION_KEY: "YOUR_ENCRYPTION_KEY" # openssl rand -hex 16
|
ENCRYPTION_KEY: "YOUR_ENCRYPTION_KEY" # openssl rand -hex 16
|
||||||
AUTH_SECRET: "YOUR_AUTH_SECRET" # openssl rand -base64 32
|
AUTH_SECRET: "YOUR_AUTH_SECRET" # openssl rand -base64 32
|
||||||
|
|||||||
Reference in New Issue
Block a user