Merge pull request #4706 from Infisical/improve-relay-docs

Improve relay docs
This commit is contained in:
Andre
2025-10-21 02:12:07 -04:00
committed by GitHub
5 changed files with 71 additions and 48 deletions
+12
View File
@@ -31,6 +31,7 @@ If you are moving from Gateway v1 to Gateway v2, this is NOT a drop-in switch. G
## Subcommands & flags ## Subcommands & flags
<AccordionGroup>
<Accordion title="infisical gateway start" defaultOpen="true"> <Accordion title="infisical gateway start" defaultOpen="true">
Run the Infisical gateway component within your the network where your target resources are located. The gateway establishes an SSH reverse tunnel to the specified relay server and provides secure access to private resources within your network. Run the Infisical gateway component within your the network where your target resources are located. The gateway establishes an SSH reverse tunnel to the specified relay server and provides secure access to private resources within your network.
@@ -245,6 +246,7 @@ The Relay supports multiple authentication methods. Below are the available auth
### Other Flags ### Other Flags
<AccordionGroup>
<Accordion title="--relay"> <Accordion title="--relay">
The name of the relay that this gateway should connect to. The relay must be running and registered before starting the gateway. The name of the relay that this gateway should connect to. The relay must be running and registered before starting the gateway.
@@ -276,6 +278,7 @@ The Relay supports multiple authentication methods. Below are the available auth
``` ```
</Accordion> </Accordion>
</AccordionGroup>
</Accordion> </Accordion>
<Accordion title="infisical gateway systemd install"> <Accordion title="infisical gateway systemd install">
@@ -293,6 +296,7 @@ sudo infisical gateway systemd install --token=<token> --domain=<domain> --name=
### Flags ### Flags
<AccordionGroup>
<Accordion title="--token"> <Accordion title="--token">
The machine identity access token to authenticate with Infisical. The machine identity access token to authenticate with Infisical.
@@ -334,6 +338,7 @@ sudo infisical gateway systemd install --token=<token> --domain=<domain> --name=
``` ```
</Accordion> </Accordion>
</AccordionGroup>
### Service Details ### Service Details
@@ -360,9 +365,11 @@ sudo systemctl disable infisical-gateway # Disable auto-start on boot
``` ```
</Accordion> </Accordion>
</AccordionGroup>
## Legacy Gateway Commands ## Legacy Gateway Commands
<AccordionGroup>
<Accordion title="infisical gateway (deprecated)"> <Accordion title="infisical gateway (deprecated)">
<Warning> <Warning>
**This command is deprecated and will be removed in a future release.** **This command is deprecated and will be removed in a future release.**
@@ -579,6 +586,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa
### Other Flags ### Other Flags
<AccordionGroup>
<Accordion title="--domain"> <Accordion title="--domain">
Domain of your self-hosted Infisical instance. Domain of your self-hosted Infisical instance.
@@ -588,6 +596,7 @@ The Infisical CLI supports multiple authentication methods. Below are the availa
``` ```
</Accordion> </Accordion>
</AccordionGroup>
</Accordion> </Accordion>
<Accordion title="infisical gateway install (deprecated)"> <Accordion title="infisical gateway install (deprecated)">
@@ -614,6 +623,7 @@ sudo infisical gateway install --token=<token> --domain=<domain>
### Flags ### Flags
<AccordionGroup>
<Accordion title="--token"> <Accordion title="--token">
The machine identity access token to authenticate with Infisical. The machine identity access token to authenticate with Infisical.
@@ -635,6 +645,7 @@ sudo infisical gateway install --token=<token> --domain=<domain>
``` ```
</Accordion> </Accordion>
</AccordionGroup>
### Service Details ### Service Details
@@ -659,3 +670,4 @@ sudo systemctl disable infisical-gateway # Disable auto-start on boot
``` ```
</Accordion> </Accordion>
</AccordionGroup>
+8
View File
@@ -26,6 +26,7 @@ Relay-related commands for Infisical that provide identity-aware relay infrastru
## Subcommands & flags ## Subcommands & flags
<AccordionGroup>
<Accordion title="infisical relay start" defaultOpen="true"> <Accordion title="infisical relay start" defaultOpen="true">
Run the Infisical relay component. The relay handles network traffic routing between Infisical and your gateways. Run the Infisical relay component. The relay handles network traffic routing between Infisical and your gateways.
@@ -35,6 +36,7 @@ infisical relay start --host=<host> --name=<name> --auth-method=<auth-method>
### Flags ### Flags
<AccordionGroup>
<Accordion title="--host"> <Accordion title="--host">
The host (IP address or hostname) of the instance where the relay is deployed. This must be a static public IP or resolvable hostname that gateways can reach. The host (IP address or hostname) of the instance where the relay is deployed. This must be a static public IP or resolvable hostname that gateways can reach.
@@ -57,6 +59,7 @@ infisical relay start --host=<host> --name=<name> --auth-method=<auth-method>
``` ```
</Accordion> </Accordion>
</AccordionGroup>
### Authentication ### Authentication
@@ -280,6 +283,7 @@ infisical relay systemd <subcommand>
### Subcommands ### Subcommands
<AccordionGroup>
<Accordion title="install"> <Accordion title="install">
Install and enable systemd service for the relay. Must be run with sudo on Linux systems. Install and enable systemd service for the relay. Must be run with sudo on Linux systems.
@@ -289,6 +293,7 @@ sudo infisical relay systemd install --host=<host> --name=<name> --token=<token>
#### Flags #### Flags
<AccordionGroup>
<Accordion title="--host"> <Accordion title="--host">
The host (IP address or hostname) of the instance where the relay is deployed. This must be a static public IP or resolvable hostname that gateways can reach. The host (IP address or hostname) of the instance where the relay is deployed. This must be a static public IP or resolvable hostname that gateways can reach.
@@ -331,6 +336,7 @@ sudo infisical relay systemd install --domain=http://localhost:8080 --token=<tok
``` ```
</Accordion> </Accordion>
</AccordionGroup>
#### Examples #### Examples
@@ -386,5 +392,7 @@ sudo infisical relay systemd uninstall
- Cleans up the service configuration - Cleans up the service configuration
</Accordion> </Accordion>
</AccordionGroup>
</Accordion> </Accordion>
</AccordionGroup>
@@ -100,6 +100,7 @@ Configure security groups to allow:
## Frequently Asked Questions ## Frequently Asked Questions
<AccordionGroup>
<Accordion title="What happens if there is a network interruption?"> <Accordion title="What happens if there is a network interruption?">
The gateway is designed to handle network interruptions gracefully: The gateway is designed to handle network interruptions gracefully:
@@ -166,3 +167,4 @@ No, relay servers cannot decrypt any traffic passing through them:
The relay infrastructure is designed as a secure forwarding mechanism, similar to a VPN tunnel, where the relay provider cannot see the contents of the traffic flowing through it. The relay infrastructure is designed as a secure forwarding mechanism, similar to a VPN tunnel, where the relay provider cannot see the contents of the traffic flowing through it.
</Accordion> </Accordion>
</AccordionGroup>
@@ -185,10 +185,9 @@ To successfully deploy an Infisical Gateway for use, follow these steps in order
</Step> </Step>
</Steps> </Steps>
## Frequently Asked Questions ## Frequently Asked Questions
<AccordionGroup>
<Accordion title="Do I need to open any inbound ports on my firewall?"> <Accordion title="Do I need to open any inbound ports on my firewall?">
No inbound ports need to be opened for gateways. The gateway only makes outbound connections: No inbound ports need to be opened for gateways. The gateway only makes outbound connections:
@@ -263,3 +262,4 @@ The gateway is designed to handle network interruptions gracefully:
No manual intervention is typically required during network interruptions. No manual intervention is typically required during network interruptions.
</Accordion> </Accordion>
</AccordionGroup>
@@ -168,7 +168,6 @@ To successfully deploy an Infisical Relay for use, follow these steps in order.
```bash ```bash
infisical relay start \ infisical relay start \
--type=<type> \
--host=<host> \ --host=<host> \
--name=<name> \ --name=<name> \
--auth-method=<auth-method> --auth-method=<auth-method>
@@ -185,6 +184,7 @@ To successfully deploy an Infisical Relay for use, follow these steps in order.
## Frequently Asked Questions ## Frequently Asked Questions
<AccordionGroup>
<Accordion title="Can the relay servers decrypt traffic going through them?"> <Accordion title="Can the relay servers decrypt traffic going through them?">
No, relay servers cannot decrypt any traffic passing through them due to end-to-end encryption: No, relay servers cannot decrypt any traffic passing through them due to end-to-end encryption:
@@ -241,3 +241,4 @@ Relay server outages affect gateway connectivity:
For production environments, consider deploying multiple relay servers to avoid single points of failure. For production environments, consider deploying multiple relay servers to avoid single points of failure.
</Accordion> </Accordion>
</AccordionGroup>