diff --git a/docs/integrations/platforms/kubernetes.mdx b/docs/integrations/platforms/kubernetes.mdx
index bf72122b8..f742a5525 100644
--- a/docs/integrations/platforms/kubernetes.mdx
+++ b/docs/integrations/platforms/kubernetes.mdx
@@ -10,7 +10,9 @@ It uses an `InfisicalSecret` resource to specify authentication and storage meth
The operator continuously updates secrets and can also reload dependent deployments automatically.
- If you are already using the External Secrets operator, you can view the integration documentation for it [here](https://external-secrets.io/latest/provider/infisical/).
+ If you are already using the External Secrets operator, you can view the
+ integration documentation for it
+ [here](https://external-secrets.io/latest/provider/infisical/).
## Install Operator
@@ -31,7 +33,7 @@ The operator can be install via [Helm](https://helm.sh) or [kubectl](https://git
To select a specific version, view the application versions [here](https://hub.docker.com/r/infisical/kubernetes-operator/tags) and chart versions [here](https://cloudsmith.io/~infisical/repos/helm-charts/packages/detail/helm/secrets-operator/#versions)
```bash
- helm install --generate-name infisical-helm-charts/secrets-operator
+ helm install --generate-name infisical-helm-charts/secrets-operator
```
```bash
@@ -61,109 +63,106 @@ Once you apply the manifest, the operator will be installed in `infisical-operat
Once you have installed the operator to your cluster, you'll need to create a `InfisicalSecret` custom resource definition (CRD).
```yaml example-infisical-secret-crd.yaml
-
apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret
metadata:
- name: infisicalsecret-sample
- labels:
- label-to-be-passed-to-managed-secret: sample-value
- annotations:
- example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
+ name: infisicalsecret-sample
+ labels:
+ label-to-be-passed-to-managed-secret: sample-value
+ annotations:
+ example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
spec:
- hostAPI: https://app.infisical.com/api
- resyncInterval: 10
- authentication:
- # Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
- # If you have multiple authentication methods defined, it may cause issues.
+ hostAPI: https://app.infisical.com/api
+ resyncInterval: 10
+ authentication:
+ # Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
+ # If you have multiple authentication methods defined, it may cause issues.
- # (Deprecated) Service Token Auth
- serviceToken:
- serviceTokenSecretReference:
- secretName: service-token
- secretNamespace: default
- secretsScope:
- envSlug:
- secretsPath:
- recursive: true
-
- # Universal Auth
- universalAuth:
- secretsScope:
- projectSlug: new-ob-em
- envSlug: dev # "dev", "staging", "prod", etc..
- secretsPath: "/" # Root is "/"
- recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
- credentialsRef:
- secretName: universal-auth-credentials
- secretNamespace: default
-
- # Native Kubernetes Auth
- kubernetesAuth:
- identityId:
- serviceAccountRef:
- name:
- namespace:
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- # AWS IAM Auth
- awsIamAuth:
- identityId:
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- # Azure Auth
- azureAuth:
- identityId:
- resource: https://management.azure.com/&client_id=CLIENT_ID # (Optional) This is the Azure resource that you want to access. For example, "https://management.azure.com/". If no value is provided, it will default to "https://management.azure.com/"
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- # GCP ID Token Auth
- gcpIdTokenAuth:
- identityId:
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- # GCP IAM Auth
- gcpIamAuth:
- identityId:
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- managedSecretReference:
- secretName: managed-secret
+ # (Deprecated) Service Token Auth
+ serviceToken:
+ serviceTokenSecretReference:
+ secretName: service-token
secretNamespace: default
- creationPolicy: "Orphan" ## Owner | Orphan
- # secretType: kubernetes.io/dockerconfigjson
+ secretsScope:
+ envSlug:
+ secretsPath:
+ recursive: true
+ # Universal Auth
+ universalAuth:
+ secretsScope:
+ projectSlug: new-ob-em
+ envSlug: dev # "dev", "staging", "prod", etc..
+ secretsPath: "/" # Root is "/"
+ recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
+ credentialsRef:
+ secretName: universal-auth-credentials
+ secretNamespace: default
+ # Native Kubernetes Auth
+ kubernetesAuth:
+ identityId:
+ serviceAccountRef:
+ name:
+ namespace:
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ # AWS IAM Auth
+ awsIamAuth:
+ identityId:
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ # Azure Auth
+ azureAuth:
+ identityId:
+ resource: https://management.azure.com/&client_id=CLIENT_ID # (Optional) This is the Azure resource that you want to access. For example, "https://management.azure.com/". If no value is provided, it will default to "https://management.azure.com/"
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ # GCP ID Token Auth
+ gcpIdTokenAuth:
+ identityId:
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ # GCP IAM Auth
+ gcpIamAuth:
+ identityId:
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ managedSecretReference:
+ secretName: managed-secret
+ secretNamespace: default
+ creationPolicy: "Orphan" ## Owner | Orphan
+ # secretType: kubernetes.io/dockerconfigjson
```
### InfisicalSecret CRD properties
@@ -193,6 +192,31 @@ When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
available on paid plans. Default re-sync interval is every 1 minute.
+
+ This block defines the TLS settings to use for connecting to the Infisical
+ instance.
+
+
+
+ This block defines the reference to the CA certificate to use for connecting
+ to the Infisical instance with SSL/TLS.
+
+
+
+ The name of the Kubernetes secret containing the CA certificate to use for
+ connecting to the Infisical instance with SSL/TLS.
+
+
+
+ The namespace of the Kubernetes secret containing the CA certificate to use
+ for connecting to the Infisical instance with SSL/TLS.
+
+
+
+ The name of the key in the Kubernetes secret which contains the value of the
+ CA certificate to use for connecting to the Infisical instance with SSL/TLS.
+
+
This block defines the method that will be used to authenticate with Infisical
so that secrets can be fetched
@@ -222,8 +246,6 @@ When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
-
-
Make sure to also populate the `secretsScope` field with the project slug
_`projectSlug`_, environment slug _`envSlug`_, and secrets path
@@ -365,15 +387,15 @@ spec:
- Once you have created your machine identity and added it to your project(s), you will need to add the identity ID to your InfisicalSecret resource.
- In the `authentication.kubernetesAuth.identityId` field, add the identity ID of the machine identity you created.
+ Once you have created your machine identity and added it to your project(s), you will need to add the identity ID to your InfisicalSecret resource.
+ In the `authentication.kubernetesAuth.identityId` field, add the identity ID of the machine identity you created.
See the example below for more details.
- Add the service account details from the previous steps under `authentication.kubernetesAuth.serviceAccountRef`.
- Here you will need to enter the name and namespace of the service account.
+ Add the service account details from the previous steps under `authentication.kubernetesAuth.serviceAccountRef`.
+ Here you will need to enter the name and namespace of the service account.
The example below shows a complete InfisicalSecret resource with all required fields defined.
-
+
@@ -539,8 +561,6 @@ spec:
-
-
The GCP IAM machine identity authentication method is used to authenticate with Infisical. The identity ID is stored in a field in the InfisicalSecret resource. This authentication method can only be used both within and outside GCP environments.
@@ -877,6 +897,42 @@ spec:
+### Connecting to instances with private/self-signed certificate
+
+To connect to Infisical instances with private/self-signed certificates, you can configure the TLS settings in the `InfisicalSecret` CRD
+to point to a CA certificate stored in a Kubernetes secret resource.
+
+```yaml
+---
+spec:
+ hostAPI: https://app.infisical.com/api
+ resyncInterval: 10
+ tls:
+ caRef:
+ secretName: custom-ca-certificate
+ secretNamespace: default
+ key: ca.crt
+ authentication:
+---
+```
+
+The definition file of the Kubernetes secret for the CA certificate can be structured like the following:
+
+```yaml
+apiVersion: v1
+kind: Secret
+metadata:
+ name: custom-ca-certificate
+type: Opaque
+stringData:
+ ca.crt: |
+ -----BEGIN CERTIFICATE-----
+ MIIEZzCCA0+gAwIBAgIUDk9+HZcMHppiNy0TvoBg8/aMEqIwDQYJKoZIhvcNAQEL
+ ...
+ BQAwDTELMAkGA1UEChMCUEgwHhcNMjQxMDI1MTU0MjAzWhcNMjUxMDI1MjE0MjAz
+ -----END CERTIFICATE-----
+```
+
## Auto redeployment
Deployments using managed secrets don't reload automatically on updates, so they may use outdated secrets unless manually redeployed.
@@ -889,6 +945,7 @@ To enable auto redeployment you simply have to add the following annotation to t
```yaml
secrets.infisical.com/auto-reload: "true"
```
+
```yaml
apiVersion: apps/v1
diff --git a/k8-operator/config/samples/customCaCertificate.yaml b/k8-operator/config/samples/customCaCertificate.yaml
new file mode 100644
index 000000000..67aac4743
--- /dev/null
+++ b/k8-operator/config/samples/customCaCertificate.yaml
@@ -0,0 +1,33 @@
+apiVersion: v1
+kind: Secret
+metadata:
+ name: custom-ca-certificate
+type: Opaque
+stringData:
+ ca.crt: |
+ -----BEGIN CERTIFICATE-----
+ MIIEZzCCA0+gAwIBAgIUDk9+HZcMHppiNy0TvoBg8/aMEqIwDQYJKoZIhvcNAQEL
+ BQAwDTELMAkGA1UEChMCUEgwHhcNMjQxMDI1MTU0MjAzWhcNMjUxMDI1MjE0MjAz
+ WjAfMR0wGwYDVQQDExRob3N0LmRvY2tlci5pbnRlcm5hbDCCASIwDQYJKoZIhvcN
+ AQEBBQADggEPADCCAQoCggEBALPBCPhZHCizZWbyGI0LzTLYprsvTMoeZBeR84lj
+ hv/VDUkH3K6jw5g2o2eXg4Aisb/GcQkTxHjmGlUKymhrLBH9zUHjh1yFKPUJdSy1
+ X4YCG+ABNQ8obrTZM/ry5WRHF/KcFIELt/4JpY8OWkxEIisYfe98vObsGH39spcN
+ c3x3Oo4vsBd6ETQOjrXL81kXLoNZoHdsVIU0ZwNpXR1geI477ce3eHOuEhBvKfUR
+ ugRdmX6xUhFNZcKRYiv3RRkm/vnuxWx2CxsecJ0BRoB7nT00gJkkxbt1b5MrPFF4
+ XIdhWIdxSMdMUwtnEo9hT2mzUCkJohLEeqwivZfewghLo88CAwEAAaOCAaswggGn
+ MAkGA1UdEwQCMAAwXgYDVR0fBFcwVTBToFGgT4ZNaHR0cDovL2xvY2FsaG9zdDo4
+ MDgwL2FwaS92MS9wa2kvY3JsLzY2ZDk3OTNkLWMzMTYtNDNhZS05N2RiLTkzNDBj
+ ZmJkNTYxNy9kZXIwHwYDVR0jBBgwFoAU3+CiMP0BF+BnjXBYawENOrnQ+q8wHQYD
+ VR0OBBYEFKUIOV5qAwf0Bd1dMnxIYYglcZT1MIGdBggrBgEFBQcBAQSBkDCBjTCB
+ igYIKwYBBQUHMAKGfmh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9hcGkvdjEvcGtpL2Nh
+ L2EyNDIyZTdlLTAwZWYtNDlhZC1iY2ZhLTUxMzZhODQxNjEyZC9jZXJ0aWZpY2F0
+ ZXMvYWJhNTRjNGEtNjYxOS00MDFlLTk2YTYtN2UwN2MxNzdjOTI4L2RlcjARBgNV
+ HSAECjAIMAYGBFUdIAAwDgYDVR0PAQH/BAQDAgWgMBYGA1UdJQEB/wQMMAoGCCsG
+ AQUFBwMBMB8GA1UdEQQYMBaCFGhvc3QuZG9ja2VyLmludGVybmFsMA0GCSqGSIb3
+ DQEBCwUAA4IBAQAtUUloE1xU+BNF2Fjc/PSOesHz6dFCzGWvCc0QZceK/6v4EWuZ
+ vEU07brGrufhwJ3UnOXO4zxIl3UplQ1S14Xrba4R69Fp3dggFV39ON8R5lpL9hZe
+ cSRywBycKil2C7SytPsjJtvCXY6RXb6YxFse6rDk0qoMwD/g/ou3JIEpgtB2cPuX
+ Blg9ZWAsaOtKhtmi1IyLjwgHDd86XhMzd9osOna1iuARZMZs80ek5b5H4cdFIBTl
+ rwIQc6b9ZbHAD56NttCIE18YmLWbYBCdvga0Qmqwr2fRPg2DE9qoyF1ZJVbwisOc
+ cJ23MFdpsXKiIoQyDmpZl5jg8aKD/jh0wdUx
+ -----END CERTIFICATE-----
diff --git a/k8-operator/config/samples/sample.yaml b/k8-operator/config/samples/sample.yaml
index b27d1208a..43ec5a7e4 100644
--- a/k8-operator/config/samples/sample.yaml
+++ b/k8-operator/config/samples/sample.yaml
@@ -1,104 +1,109 @@
apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret
metadata:
- name: infisicalsecret-sample
- labels:
- label-to-be-passed-to-managed-secret: sample-value
- annotations:
- example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
+ name: infisicalsecret-sample
+ labels:
+ label-to-be-passed-to-managed-secret: sample-value
+ annotations:
+ example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
spec:
- hostAPI: https://app.infisical.com/api
- resyncInterval: 10
- authentication:
- # Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
- # If you have multiple authentication methods defined, it may cause issues.
+ hostAPI: https://app.infisical.com/api
+ resyncInterval: 10
+ # tls:
+ # caRef:
+ # secretName: custom-ca-certificate
+ # secretNamespace: default
+ # key: ca.crt
+ authentication:
+ # Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
+ # If you have multiple authentication methods defined, it may cause issues.
- # (Deprecated) Service Token Auth
- serviceToken:
- serviceTokenSecretReference:
- secretName: service-token
- secretNamespace: default
- secretsScope:
- envSlug:
- secretsPath:
- recursive: true
-
- # Universal Auth
- universalAuth:
- secretsScope:
- projectSlug: new-ob-em
- envSlug: dev # "dev", "staging", "prod", etc..
- secretsPath: "/" # Root is "/"
- recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
- credentialsRef:
- secretName: universal-auth-credentials
- secretNamespace: default
-
- # Native Kubernetes Auth
- kubernetesAuth:
- identityId:
- serviceAccountTokenPath: "/path/to/your/service-account/token" # Optional, defaults to /var/run/secrets/kubernetes.io/serviceaccount/token
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- # AWS IAM Auth
- awsIamAuth:
- identityId:
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- # Azure Auth
- azureAuth:
- identityId:
- resource: https://management.azure.com/&client_id=your_client_id # This field is optional, and will default to "https://management.azure.com/" if nothing is provided.
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- # GCP ID Token Auth
- gcpIdTokenAuth:
- identityId:
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- # GCP IAM Auth
- gcpIamAuth:
- identityId:
- serviceAccountKeyFilePath: "/path/to-service-account-key-file-path.json"
-
- # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
- secretsScope:
- projectSlug: your-project-slug
- envSlug: prod
- secretsPath: "/path"
- recursive: true
-
- managedSecretReference:
- secretName: managed-secret
+ # (Deprecated) Service Token Auth
+ serviceToken:
+ serviceTokenSecretReference:
+ secretName: service-token
secretNamespace: default
- creationPolicy: "Orphan" ## Owner | Orphan
- # secretType: kubernetes.io/dockerconfigjson
+ secretsScope:
+ envSlug:
+ secretsPath:
+ recursive: true
- # # To be depreciated soon
- # tokenSecretReference:
- # secretName: service-token
- # secretNamespace: default
+ # Universal Auth
+ universalAuth:
+ secretsScope:
+ projectSlug: new-ob-em
+ envSlug: dev # "dev", "staging", "prod", etc..
+ secretsPath: "/" # Root is "/"
+ recursive: true # Wether or not to use recursive mode (Fetches all secrets in an environment from a given secret path, and all folders inside the path) / defaults to false
+ credentialsRef:
+ secretName: universal-auth-credentials
+ secretNamespace: default
+
+ # Native Kubernetes Auth
+ kubernetesAuth:
+ identityId:
+ serviceAccountTokenPath: "/path/to/your/service-account/token" # Optional, defaults to /var/run/secrets/kubernetes.io/serviceaccount/token
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ # AWS IAM Auth
+ awsIamAuth:
+ identityId:
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ # Azure Auth
+ azureAuth:
+ identityId:
+ resource: https://management.azure.com/&client_id=your_client_id # This field is optional, and will default to "https://management.azure.com/" if nothing is provided.
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ # GCP ID Token Auth
+ gcpIdTokenAuth:
+ identityId:
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ # GCP IAM Auth
+ gcpIamAuth:
+ identityId:
+ serviceAccountKeyFilePath: "/path/to-service-account-key-file-path.json"
+
+ # secretsScope is identical to the secrets scope in the universalAuth field in this sample.
+ secretsScope:
+ projectSlug: your-project-slug
+ envSlug: prod
+ secretsPath: "/path"
+ recursive: true
+
+ managedSecretReference:
+ secretName: managed-secret
+ secretNamespace: default
+ creationPolicy: "Orphan" ## Owner | Orphan
+ # secretType: kubernetes.io/dockerconfigjson
+
+ # # To be depreciated soon
+ # tokenSecretReference:
+ # secretName: service-token
+ # secretNamespace: default