add docs for new k8 oper with service account

This commit is contained in:
Maidul Islam
2023-04-16 21:04:28 -07:00
parent df2e0e03ff
commit 92df5e1a2f
+96 -27
View File
@@ -38,12 +38,10 @@ The operator can be install via [Helm](helm.sh) or [kubectl](https://github.com/
</Tabs> </Tabs>
## Sync Infisical Secrets to your cluster ## Sync Infisical Secrets to your cluster
To retrieve secrets from an Infisical project and save them as a native Kubernetes secret within a specific namespace, utilize the `InfisicalSecret` custom resource.
To retrieve secrets from an Infisical project and store them in your Kubernetes cluster, you can use the InfisicalSecret custom resource. This resource can be created after installing the Infisical operator.
This resource is available after installing the Infisical operator. In order to specify the Infisical Token location and the location where the retrieved secrets should be stored, you can use the `tokenSecretReference` and `managedSecretReference` fields within the InfisicalSecret resource.
```yaml ```yaml
apiVersion: secrets.infisical.com/v1alpha1 apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret kind: InfisicalSecret
metadata: metadata:
@@ -52,39 +50,110 @@ metadata:
spec: spec:
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used # The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
hostAPI: https://app.infisical.com/api hostAPI: https://app.infisical.com/api
authentication:
# The Kubernetes secret the stores the Infisical token serviceToken: # <-- option 1
tokenSecretReference: serviceTokenSecretReference:
# Kubernetes secret name secretName: service-token
secretName: service-token secretNamespace: option
# The secret namespace serviceAccount: # <-- method 2
secretNamespace: default serviceAccountSecretReference:
secretName: service-account
# The Kubernetes secret that Infisical Operator will create and populate with secrets from the above project secretNamespace: default
projectId: "6439ec224cfbf7ea2a95b651"
environmentName: "dev"
managedSecretReference: managedSecretReference:
# The name of managed Kubernetes secret that should be created
secretName: managed-secret secretName: managed-secret
# The namespace the managed secret should be installed in
secretNamespace: default secretNamespace: default
``` ```
### InfisicalSecret CRD properties
<Accordion title="tokenSecretReference"> <Accordion title="hostAPI">
The `tokenSecretReference` field in the InfisicalSecret resource is used to specify the location of the Infisical Token, which is required for authenticating and retrieving secrets from an Infisical project. If you are fetching secrets from a self hosted instance of Infisical set the value of `hostAPI` to
` https://your-self-hosted-instace.com/api`
To create a Kubernetes secret containing an [Infisical Token](../../getting-started/dashboard/token), you can run the command below. When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
``` bash </Accordion>
kubectl create secret generic service-token --from-literal=infisicalToken=<infisical-token-here>
```
Once the secret is created, add the name and namespace of the secret under `tokenSecretReference` field in the InfisicalSecret custom resource. <Accordion title="authentication">
The `authentication` property tells the operator where it should look to find credentials needed to fetch secrets from Infisical. You can authenticate via two methods as described below.
{' '} <Tabs>
<Tab title="Service Token">
Authenticating with service tokens is a great option when you have a small number of services you'd like to fetch secrets for and are looking for the least amount of setup.
<Info> #### 1. Generate service token
No matter what the name of the secret is or its namespace, it must contain a
key named `infisicalToken` with a valid Infisical Token as the value
</Info>
You can generate a service token for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
#### 2. Create Kubernetes secret containing service token
Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
To quickly create a Kubernetes secret containing the generated service token, you can run the command below.
``` bash
kubectl create secret generic service-token --from-literal=infisicalToken=<your-service-token-here>
```
#### 3. Add reference for the Kubernetes secret containing service token
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken` field in the InfisicalSecret resource.
## Example
```yaml
apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret
metadata:
name: infisicalsecret-sample-crd
spec:
authentication:
serviceToken:
serviceTokenSecretReference:
secretName: service-token # <-- name of the Kubernetes secret that stores our service token
secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
...
```
</Tab>
<Tab title="Service Account">
Authenticating with service tokens is a great option when you have a small number of services you'd like to fetch secrets for and are looking for the least amount of setup.
#### 1. Generate service token
You can generate a service token for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
#### 2. Create Kubernetes secret containing service token
Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
To quickly create a Kubernetes secret containing the generated service token, you can run the command below.
``` bash
kubectl create secret generic service-token --from-literal=infisicalToken=<your-service-token-here>
```
#### 3. Add reference for the Kubernetes secret containing service token
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken` field in the InfisicalSecret resource.
## Example
```yaml
apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret
metadata:
name: infisicalsecret-sample-crd
spec:
authentication:
serviceToken:
serviceTokenSecretReference:
secretName: service-token # <-- name of the Kubernetes secret that stores our service token
secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
...
```
```
kubectl create secret generic service-token --from-literal=serviceAccountAccessKey=secret123 --from-literal=serviceAccountPublicKey=123456 --from-literal=serviceAccountPrivateKey=123456
```
</Tab>
</Tabs>
</Accordion> </Accordion>
<Accordion title="managedSecretReference"> <Accordion title="managedSecretReference">