mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 17:26:36 +00:00
Merge branch 'main' into feature/north-flank-app-connection
This commit is contained in:
+219
-16
@@ -9,22 +9,93 @@ infisical login
|
||||
|
||||
### Description
|
||||
|
||||
The CLI uses authentication to verify your identity. When you enter the correct email and password for your account, a token is generated and saved in your system Keyring to allow you to make future interactions with the CLI.
|
||||
The CLI uses authentication to verify your identity. You can authenticate using:
|
||||
- **Browser Login** (default): Opens a browser for authentication
|
||||
- **Direct Login**: Provide email and password via flags or environment variables for non-interactive workflows
|
||||
- **Interactive CLI Login**: Use the `--interactive` flag to enter credentials via CLI prompts
|
||||
|
||||
When authenticated, a token is generated and saved in your system Keyring to allow you to make future interactions with the CLI.
|
||||
|
||||
To change where the login credentials are stored, visit the [vaults command](./vault).
|
||||
|
||||
If you have added multiple users, you can switch between the users by using the [user command](./user).
|
||||
|
||||
<Info>
|
||||
When you authenticate with **any other method than `user`**, an access token will be printed to the console upon successful login. This token can be used to authenticate with the Infisical API and the CLI by passing it in the `--token` flag when applicable.
|
||||
|
||||
Use flag `--plain` along with `--silent` to print only the token in plain text when using a machine identity auth method.
|
||||
|
||||
**JWT Token Output:**
|
||||
- For **user authentication** with the `--plain --silent` flags: outputs only the JWT access token (useful for scripting)
|
||||
- For **machine identity authentication**: an access token is always printed to the console
|
||||
|
||||
Use the `--plain` flag to print only the token in plain text and the `--silent` flag to disable update alerts.
|
||||
|
||||
Both flags are ideal for capturing the token in environment variables or CI/CD pipelines.
|
||||
</Info>
|
||||
|
||||
### Authentication Methods
|
||||
|
||||
The Infisical CLI supports multiple authentication methods. Below are the available authentication methods, with their respective flags.
|
||||
The Infisical CLI supports two main categories of authentication: User Authentication and Machine Identity Authentication.
|
||||
|
||||
#### User Authentication
|
||||
|
||||
User authentication is designed for individual developers and supports multiple login flows.
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="User">
|
||||
The User authentication method allows you to log in with your email and password. This method supports three different login flows:
|
||||
|
||||
- **Browser Login** (default): Opens a browser for authentication
|
||||
- **Direct Login**: Provide credentials via flags or environment variables for CI/CD
|
||||
- **Interactive CLI Login**: Enter credentials via CLI prompts using `--interactive`
|
||||
|
||||
<ParamField query="Flags">
|
||||
<Expandable title="properties">
|
||||
<ParamField query="email" type="string" optional>
|
||||
Your email address. Required for direct login along with `--password`.
|
||||
</ParamField>
|
||||
<ParamField query="password" type="string" optional>
|
||||
Your password. Required for direct login along with `--email`.
|
||||
</ParamField>
|
||||
<ParamField query="interactive" type="boolean" optional>
|
||||
Force interactive CLI login instead of browser-based authentication.
|
||||
</ParamField>
|
||||
<ParamField query="plain" type="boolean" optional>
|
||||
Output only the JWT token (useful for scripting and CI/CD).
|
||||
</ParamField>
|
||||
</Expandable>
|
||||
</ParamField>
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Browser Login (Default)">
|
||||
```bash
|
||||
infisical login
|
||||
```
|
||||
</Accordion>
|
||||
<Accordion title="Direct Login (CI/CD)">
|
||||
```bash
|
||||
infisical login [email protected] --password=your-password
|
||||
|
||||
# Or using environment variables
|
||||
export INFISICAL_EMAIL="[email protected]"
|
||||
export INFISICAL_PASSWORD="your-password"
|
||||
infisical login
|
||||
```
|
||||
</Accordion>
|
||||
<Accordion title="Interactive CLI Login">
|
||||
```bash
|
||||
infisical login --interactive
|
||||
```
|
||||
</Accordion>
|
||||
<Accordion title="Plain Token Output (Useful for scripting and CI/CD)">
|
||||
```bash
|
||||
export INFISICAL_TOKEN=$(infisical login [email protected] --password=your-password --plain --silent)
|
||||
```
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
|
||||
#### Machine Identity Authentication
|
||||
|
||||
Machine identity authentication methods are designed for automated systems, services, and CI/CD pipelines.
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Universal Auth">
|
||||
@@ -237,7 +308,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa
|
||||
Run the `login` command with the following flags to obtain an access token:
|
||||
|
||||
```bash
|
||||
infisical login --method=jwt-auth --jwt=<jwt> --machine-identity-id=<machine-identity-id>
|
||||
infisical login --method=jwt-auth --jwt=<jwt-token> --machine-identity-id=<machine-identity-id>
|
||||
```
|
||||
</Step>
|
||||
</Steps>
|
||||
@@ -262,7 +333,8 @@ The login command supports a number of flags that you can use for different auth
|
||||
- `gcp-id-token`: Login using a GCP ID token native auth.
|
||||
- `gcp-iam`: Login using a GCP IAM.
|
||||
- `aws-iam`: Login using an AWS IAM native auth.
|
||||
- `oidc-auth`: Login using oidc auth.
|
||||
- `oidc-auth`: Login using OIDC auth.
|
||||
- `jwt-auth`: Login using a plain JWT token.
|
||||
|
||||
</Accordion>
|
||||
<Accordion title="--client-id">
|
||||
@@ -330,22 +402,153 @@ The login command supports a number of flags that you can use for different auth
|
||||
</Tip>
|
||||
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
|
||||
<Accordion title="--oidc-jwt">
|
||||
<Accordion title="--email">
|
||||
```bash
|
||||
infisical login --oidc-jwt=<oidc-jwt-token>
|
||||
infisical login --email=<email> --password=<password>
|
||||
```
|
||||
|
||||
#### Description
|
||||
The JWT provided by an identity provider for OIDC authentication.
|
||||
User email address. Required if you want to do a non-interactive login when the **--method** flag is set to **user**. Must be used together with the `--password` flag.
|
||||
|
||||
<Tip>
|
||||
The `oidc-jwt` flag can be substituted with the `INFISICAL_OIDC_AUTH_JWT` environment variable.
|
||||
You can omit the **--method=user** if you want as it's the default method.
|
||||
</Tip>
|
||||
|
||||
<Tip>
|
||||
The `email` flag can be substituted with the `INFISICAL_EMAIL` environment variable.
|
||||
</Tip>
|
||||
|
||||
</Accordion>
|
||||
<Accordion title="--password">
|
||||
```bash
|
||||
infisical login --email=<email> --password=<password>
|
||||
```
|
||||
|
||||
#### Description
|
||||
User password. Required if you want to do a non-interactive login when the **--method** flag is set to **user**. Must be used together with the `--email` flag.
|
||||
|
||||
<Warning>
|
||||
For security in CI/CD environments, prefer using the `INFISICAL_PASSWORD` environment variable instead of passing the password as a command-line flag.
|
||||
</Warning>
|
||||
|
||||
<Tip>
|
||||
You can omit the **--method=user** if you want as it's the default method.
|
||||
</Tip>
|
||||
|
||||
<Tip>
|
||||
The `password` flag can be substituted with the `INFISICAL_PASSWORD` environment variable.
|
||||
</Tip>
|
||||
|
||||
</Accordion>
|
||||
<Accordion title="--interactive">
|
||||
```bash
|
||||
infisical login --interactive
|
||||
```
|
||||
|
||||
#### Description
|
||||
Forces interactive CLI login where you'll be prompted to enter your email and password in the terminal, instead of opening a browser.
|
||||
|
||||
</Accordion>
|
||||
<Accordion title="--plain">
|
||||
```bash
|
||||
infisical login --email=<email> --password=<password> --plain
|
||||
```
|
||||
|
||||
#### Description
|
||||
When used with direct user login or machine identity authentication, outputs only the JWT access token without any additional formatting. This is useful for scripting and CI/CD pipelines where you need to capture the token.
|
||||
|
||||
```bash
|
||||
# Example: Capture token in a variable
|
||||
export INFISICAL_TOKEN=$(infisical login --email=<email> --password=<password> --plain --silent)
|
||||
```
|
||||
|
||||
<Tip>
|
||||
Use it alongside the `silent` flag to disable all messages in the console except from the access token.
|
||||
</Tip>
|
||||
|
||||
</Accordion>
|
||||
<Accordion title="--jwt">
|
||||
```bash
|
||||
infisical login --jwt=<jwt-token> --machine-identity-id=<machine-identity-id>
|
||||
```
|
||||
|
||||
#### Description
|
||||
The JWT provided by an identity provider for OIDC or plain JWT authentication. This is required if the `--method` flag is set to `oidc-auth` or `jwt-auth`.
|
||||
|
||||
<Tip>
|
||||
The `jwt` flag can be substituted with the `INFISICAL_JWT` environment variable.
|
||||
</Tip>
|
||||
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
|
||||
### User Authentication Examples
|
||||
|
||||
The following examples demonstrate different ways to authenticate as a user with the Infisical CLI.
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Browser Login (Default)">
|
||||
By default, running `infisical login` without any flags opens your browser for authentication.
|
||||
|
||||
```bash
|
||||
# Opens browser for authentication
|
||||
infisical login
|
||||
```
|
||||
|
||||
The browser will open to the Infisical login page, and upon successful authentication, the CLI will be automatically authenticated.
|
||||
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Direct Login (Non-Interactive)">
|
||||
Direct login is ideal for CI/CD pipelines and automation scripts where browser-based authentication is not possible.
|
||||
|
||||
#### Using Command-Line Flags
|
||||
|
||||
```bash
|
||||
# Basic direct login (defaults to US Cloud)
|
||||
infisical login --email [email protected] --password "your-password"
|
||||
|
||||
# EU Cloud (Custom domain)
|
||||
infisical login --email [email protected] --password "your-password" --domain https://eu.infisical.com
|
||||
|
||||
# Output only JWT token for scripting
|
||||
export INFISICAL_TOKEN=$(infisical login --email [email protected] --password "your-password" --plain --silent)
|
||||
```
|
||||
|
||||
#### Using Environment Variables (Recommended for CI/CD)
|
||||
|
||||
```bash
|
||||
# Set credentials as environment variables
|
||||
export INFISICAL_EMAIL="[email protected]"
|
||||
export INFISICAL_PASSWORD="your-password"
|
||||
|
||||
# Login without additional flags
|
||||
infisical login
|
||||
|
||||
# Or with plain output for token capture
|
||||
export INFISICAL_TOKEN=$(infisical login --plain --silent)
|
||||
```
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Interactive CLI Login">
|
||||
Interactive login prompts you to enter credentials in the terminal instead of opening a browser.
|
||||
|
||||
```bash
|
||||
# Force interactive CLI login
|
||||
infisical login --interactive
|
||||
```
|
||||
|
||||
You'll be prompted to enter:
|
||||
- Email address
|
||||
- Password
|
||||
|
||||
</Accordion>
|
||||
|
||||
</AccordionGroup>
|
||||
|
||||
<Tip>
|
||||
If you have SSO enabled, we recommend using the default browser login.
|
||||
</Tip>
|
||||
|
||||
### Machine Identity Authentication Quick Start
|
||||
|
||||
@@ -367,9 +570,9 @@ In this example we'll be using the `universal-auth` method to login to obtain an
|
||||
```
|
||||
</Step>
|
||||
|
||||
<Step title="Fetch all secrets from an evironment">
|
||||
<Step title="Fetch all secrets from an environment">
|
||||
```bash
|
||||
infisical secrets --projectId=<your-project-id --env=dev --recursive
|
||||
infisical secrets --projectId=<your-project-id> --env=dev --recursive
|
||||
```
|
||||
|
||||
This command will fetch all secrets from the `dev` environment in your project, including all secrets in subfolders.
|
||||
|
||||
@@ -7,20 +7,20 @@ To set a strong foundation, this section outlines how we, the community and memb
|
||||
should approach the development and contribution process.
|
||||
|
||||
## Code-bases
|
||||
|
||||
Infisical has two major code-bases. One for the platform code, and one for SDKs. The contribution process has some key differences between the two, so we've split the documentation into two sections:
|
||||
|
||||
- The [Infisical Platform](https://github.com/Infisical/infisical), the Infisical platform itself.
|
||||
- The [Infisical SDK](https://infisical.com/docs/sdks/overview), the official Infisical client SDKs.
|
||||
|
||||
|
||||
<CardGroup cols={2}>
|
||||
<Card title="Infisical Platform" href="/contributing/platform/developing" icon="layer-group" color="#A1B659">
|
||||
The Infisical platform is the core of the Infisical ecosystem.
|
||||
</Card>
|
||||
<Card href="/contributing/sdk/developing" title="Infisical SDK" icon="code" color="#A1B659">
|
||||
The SDKs are the official Infisical client libraries, used by developers to easily interact with the Infisical platform.
|
||||
</Card>
|
||||
</CardGroup>
|
||||
- The <b>Infisical SDKs</b>, please refer to each individual SDK repositories for more information.
|
||||
- [Node.js SDK](https://github.com/Infisical/node-sdk-v2)
|
||||
- [Python SDK](https://github.com/Infisical/python-sdk-official)
|
||||
- [Java SDK](https://github.com/Infisical/java-sdk)
|
||||
- [.NET SDK](https://github.com/Infisical/infisical-dotnet-sdk)
|
||||
- [Go SDK](https://github.com/Infisical/go-sdk)
|
||||
- [C++ SDK](https://github.com/Infisical/infisical-cpp-sdk)
|
||||
- [PHP SDK](https://github.com/Infisical/php-sdk)
|
||||
- [Rust SDK](https://github.com/Infisical/rust-sdk)
|
||||
- [Ruby SDK](https://github.com/infisical/sdk)
|
||||
|
||||
## Community
|
||||
|
||||
@@ -45,15 +45,12 @@ If you're ever in doubt about whether or not a proposed feature aligns with Infi
|
||||
|
||||
## Writing and submitting code
|
||||
|
||||
Anyone can contribute code to Infisical. To get started, check out the local development guides for each language.
|
||||
|
||||
- Local development guide for Platform is [here](/contributing/platform/developing).
|
||||
- Local development guide for SDK is [here](/contributing/sdk/developing).
|
||||
Anyone can contribute code to Infisical. To get started, check out the local development guide for the platform:
|
||||
|
||||
- Local development guide for Platform is [here](/contributing/platform/developing).
|
||||
|
||||
## Licensing
|
||||
|
||||
Most of Infisical's code is under the MIT license, though some paid feature restrictions are covered by a proprietary license.
|
||||
|
||||
Any third party components incorporated into our code are licensed under the original license provided by the applicable component owner.
|
||||
|
||||
|
||||
@@ -778,6 +778,15 @@
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"item": "Infisical PAM",
|
||||
"groups": [
|
||||
{
|
||||
"group": "Infisical PAM",
|
||||
"pages": ["documentation/platform/pam/overview"]
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
|
||||
@@ -38,3 +38,4 @@ Infisical consists of several tightly integrated products, each designed to solv
|
||||
- [Infisical PKI](/documentation/platform/pki/overview): Issue and manage X.509 certificates using protocols like EST, with support for internal and external CAs.
|
||||
- [Infisical SSH](/documentation/platform/ssh/overview): Provide short-lived SSH access to servers using certificate-based authentication, replacing static keys with policy-driven, time-bound control.
|
||||
- [Infisical KMS](/documentation/platform/kms/overview): Encrypt and decrypt data using centrally managed keys with enforced access policies and full audit visibility.
|
||||
- [Infisical PAM](/documentation/platform/pam/overview): Manage access to resources like databases, servers, and accounts with policy-based controls and approvals.
|
||||
|
||||
@@ -40,6 +40,12 @@ description: "The open source platform for managing secrets, certificates, and s
|
||||
>
|
||||
Replace static SSH keys with short-lived SSH certificates to simplify access and improve security.
|
||||
</Card>
|
||||
<Card
|
||||
title="Infisical PAM"
|
||||
href="/documentation/platform/pam/overview"
|
||||
>
|
||||
Manage access to resources like databases, servers, and accounts with policy-based controls and approvals.
|
||||
</Card>
|
||||
</Columns>
|
||||
|
||||
<Columns cols="1">
|
||||
|
||||
@@ -13,7 +13,7 @@ Each identity must authenticate with the Infisical API using a supported authent
|
||||
|
||||
Key Features:
|
||||
|
||||
- Role Assignment: Identities must be assigned [roles](/documentation/platform/role-based-access-controls). These roles determine the scope of access to resources, either at the organization level or project level.
|
||||
- Role Assignment: Identities must be assigned [roles](/documentation/platform/access-controls/role-based-access-controls). These roles determine the scope of access to resources, either at the organization level or project level.
|
||||
- Auth/Token Configuration: Identities must be configured with corresponding authentication methods and access token properties to securely interact with the Infisical API.
|
||||
|
||||
## Workflow
|
||||
|
||||
@@ -0,0 +1,45 @@
|
||||
---
|
||||
title: "Infisical PAM"
|
||||
sidebarTitle: "Overview"
|
||||
description: "Learn how to manage access to resources like databases, servers, and accounts with policy-based controls and approvals."
|
||||
---
|
||||
|
||||
Infisical Privileged Access Management (PAM) provides a centralized way to manage and secure access to your critical infrastructure. It allows you to enforce fine-grained, policy-based controls over resources like databases, servers, and more, ensuring that only authorized users can access sensitive systems, and only when they need to.
|
||||
|
||||
### How it Works
|
||||
|
||||
Infisical PAM employs a resource-based model to organize and manage access. This model is designed to be intuitive and scalable.
|
||||
|
||||
#### 1. Create a Resource
|
||||
|
||||
The first step is to define a resource you want to manage. A resource represents a target system, such as a PostgreSQL database. When creating a resource, you'll provide the necessary connection details, like the host and port.
|
||||
|
||||

|
||||
|
||||
#### 2. Add Accounts to the Resource
|
||||
|
||||
Once a resource is created, you can add accounts to it. An account represents a specific set of credentials (e.g., a username and password) that can be used to access the resource. This allows you to manage multiple sets of credentials for a single database or server from one place.
|
||||
|
||||

|
||||
|
||||
### Infisical PAM Features
|
||||
|
||||
#### Session Logging and Auditing
|
||||
|
||||
- **Session Logging**: All user sessions are extensively logged, providing a detailed and searchable record of activities performed during a session.
|
||||
- **Audit Logging**: Every significant event, such as a user starting a session or accessing an account's credentials, is recorded in audit logs. This gives you complete visibility over your project.
|
||||
|
||||

|
||||
|
||||
#### Automated Credential Rotation
|
||||
|
||||
Infisical PAM can automatically rotate account credentials to enhance your security posture.
|
||||
|
||||
Here’s how it works:
|
||||
1. **Add a Rotation Account**: On the resource level, you configure a "rotation account." This is a master or privileged account that has the necessary permissions to change the passwords of other accounts on that same resource.
|
||||

|
||||
|
||||
2. **Configure Rotation on Accounts**: For each individual account you want to rotate, you can simply enable rotation and set a desired interval (e.g., every 30 days).
|
||||

|
||||
|
||||
Infisical will then use the rotation account on the resource to automatically update the credentials of the target account at the specified interval, eliminating credential staleness.
|
||||
@@ -22,6 +22,7 @@ The supported project types are:
|
||||
- [Infisical PKI](/documentation/platform/pki/overview): Issue and manage X.509 certificates using protocols like EST, with support for internal and external CAs.
|
||||
- [Infisical SSH](/documentation/platform/ssh/overview): Provide short-lived SSH access to servers using certificate-based authentication, replacing static keys with policy-driven, time-bound control.
|
||||
- [Infisical KMS](/documentation/platform/kms/overview): Encrypt and decrypt data using centrally managed keys with enforced access policies and full audit visibility.
|
||||
- [Infisical PAM](/documentation/platform/pam/overview): Manage access to resources like databases, servers, and accounts with policy-based controls and approvals.
|
||||
|
||||
## Roles and Access Control
|
||||
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 136 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 148 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 598 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 577 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 1.1 MiB |
Reference in New Issue
Block a user