mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 05:28:29 +00:00
Update sample.yaml
This commit is contained in:
@@ -12,26 +12,84 @@ spec:
|
|||||||
authentication:
|
authentication:
|
||||||
# Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
|
# Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
|
||||||
# If you have multiple authentication methods defined, it may cause issues.
|
# If you have multiple authentication methods defined, it may cause issues.
|
||||||
|
|
||||||
|
# (Deprecated) Service Token Auth
|
||||||
serviceToken:
|
serviceToken:
|
||||||
serviceTokenSecretReference:
|
serviceTokenSecretReference:
|
||||||
secretName: service-token
|
secretName: service-token
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
secretsScope:
|
secretsScope:
|
||||||
envSlug: <env-slug>
|
envSlug: <env-slug>
|
||||||
secretsPath: <secrets-path> # Root is "/"
|
secretsPath: <secrets-path>
|
||||||
recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
|
recursive: true
|
||||||
|
|
||||||
|
# Universal Auth
|
||||||
universalAuth:
|
universalAuth:
|
||||||
secretsScope:
|
secretsScope:
|
||||||
projectSlug: <project-slug>
|
projectSlug: new-ob-em
|
||||||
envSlug: <env-slug> # "dev", "staging", "prod", etc..
|
envSlug: dev # "dev", "staging", "prod", etc..
|
||||||
secretsPath: "<secrets-path>" # Root is "/"
|
secretsPath: "/" # Root is "/"
|
||||||
recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
|
recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
|
||||||
|
|
||||||
credentialsRef:
|
credentialsRef:
|
||||||
secretName: universal-auth-credentials
|
secretName: universal-auth-credentials
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
|
|
||||||
|
# Native Kubernetes Auth
|
||||||
|
kubernetesAuth:
|
||||||
|
identityId: <machine-identity-id>
|
||||||
|
serviceAccountTokenPath: "/path/to/your/service-account/token" # Optional, defaults to /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
|
||||||
|
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
||||||
|
secretsScope:
|
||||||
|
projectSlug: your-project-slug
|
||||||
|
envSlug: prod
|
||||||
|
secretsPath: "/path"
|
||||||
|
recursive: true
|
||||||
|
|
||||||
|
# AWS IAM Auth
|
||||||
|
awsIamAuth:
|
||||||
|
identityId: <your-machine-identity-id>
|
||||||
|
|
||||||
|
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
||||||
|
secretsScope:
|
||||||
|
projectSlug: your-project-slug
|
||||||
|
envSlug: prod
|
||||||
|
secretsPath: "/path"
|
||||||
|
recursive: true
|
||||||
|
|
||||||
|
# Azure Auth
|
||||||
|
azureAuth:
|
||||||
|
identityId: <your-machine-identity-id>
|
||||||
|
|
||||||
|
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
||||||
|
secretsScope:
|
||||||
|
projectSlug: your-project-slug
|
||||||
|
envSlug: prod
|
||||||
|
secretsPath: "/path"
|
||||||
|
recursive: true
|
||||||
|
|
||||||
|
# GCP ID Token Auth
|
||||||
|
gcpIdTokenAuth:
|
||||||
|
identityId: <your-machine-identity-id>
|
||||||
|
|
||||||
|
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
||||||
|
secretsScope:
|
||||||
|
projectSlug: your-project-slug
|
||||||
|
envSlug: prod
|
||||||
|
secretsPath: "/path"
|
||||||
|
recursive: true
|
||||||
|
|
||||||
|
# GCP IAM Auth
|
||||||
|
gcpIamAuth:
|
||||||
|
identityId: <your-machine-identity-id>
|
||||||
|
|
||||||
|
# secretsScope is identical to the secrets scope in the universalAuth field in this sample.
|
||||||
|
secretsScope:
|
||||||
|
projectSlug: your-project-slug
|
||||||
|
envSlug: prod
|
||||||
|
secretsPath: "/path"
|
||||||
|
recursive: true
|
||||||
|
|
||||||
managedSecretReference:
|
managedSecretReference:
|
||||||
secretName: managed-secret
|
secretName: managed-secret
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
|
|||||||
Reference in New Issue
Block a user