mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 13:28:27 +00:00
misc: documentation and samples
This commit is contained in:
@@ -10,7 +10,9 @@ It uses an `InfisicalSecret` resource to specify authentication and storage meth
|
|||||||
The operator continuously updates secrets and can also reload dependent deployments automatically.
|
The operator continuously updates secrets and can also reload dependent deployments automatically.
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
If you are already using the External Secrets operator, you can view the integration documentation for it [here](https://external-secrets.io/latest/provider/infisical/).
|
If you are already using the External Secrets operator, you can view the
|
||||||
|
integration documentation for it
|
||||||
|
[here](https://external-secrets.io/latest/provider/infisical/).
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
## Install Operator
|
## Install Operator
|
||||||
@@ -61,7 +63,6 @@ Once you apply the manifest, the operator will be installed in `infisical-operat
|
|||||||
Once you have installed the operator to your cluster, you'll need to create a `InfisicalSecret` custom resource definition (CRD).
|
Once you have installed the operator to your cluster, you'll need to create a `InfisicalSecret` custom resource definition (CRD).
|
||||||
|
|
||||||
```yaml example-infisical-secret-crd.yaml
|
```yaml example-infisical-secret-crd.yaml
|
||||||
|
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
kind: InfisicalSecret
|
kind: InfisicalSecret
|
||||||
metadata:
|
metadata:
|
||||||
@@ -162,8 +163,6 @@ spec:
|
|||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
creationPolicy: "Orphan" ## Owner | Orphan
|
creationPolicy: "Orphan" ## Owner | Orphan
|
||||||
# secretType: kubernetes.io/dockerconfigjson
|
# secretType: kubernetes.io/dockerconfigjson
|
||||||
|
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### InfisicalSecret CRD properties
|
### InfisicalSecret CRD properties
|
||||||
@@ -193,6 +192,31 @@ When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
|||||||
available on paid plans. Default re-sync interval is every 1 minute.
|
available on paid plans. Default re-sync interval is every 1 minute.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="tls">
|
||||||
|
This block defines the TLS settings to use for connecting to the Infisical
|
||||||
|
instance.
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="tls.caRef">
|
||||||
|
This block defines the reference to the CA certificate to use for connecting
|
||||||
|
to the Infisical instance with SSL/TLS.
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="tls.caRef.secretName">
|
||||||
|
The name of the Kubernetes secret containing the CA certificate to use for
|
||||||
|
connecting to the Infisical instance with SSL/TLS.
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="tls.caRef.secretNamespace">
|
||||||
|
The namespace of the Kubernetes secret containing the CA certificate to use
|
||||||
|
for connecting to the Infisical instance with SSL/TLS.
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="tls.caRef.key">
|
||||||
|
The name of the key in the Kubernetes secret which contains the value of the
|
||||||
|
CA certificate to use for connecting to the Infisical instance with SSL/TLS.
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication">
|
<Accordion title="authentication">
|
||||||
This block defines the method that will be used to authenticate with Infisical
|
This block defines the method that will be used to authenticate with Infisical
|
||||||
so that secrets can be fetched
|
so that secrets can be fetched
|
||||||
@@ -222,8 +246,6 @@ When `hostAPI` is not defined the operator fetches secrets from Infisical Cloud.
|
|||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Make sure to also populate the `secretsScope` field with the project slug
|
Make sure to also populate the `secretsScope` field with the project slug
|
||||||
_`projectSlug`_, environment slug _`envSlug`_, and secrets path
|
_`projectSlug`_, environment slug _`envSlug`_, and secrets path
|
||||||
@@ -539,8 +561,6 @@ spec:
|
|||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
<Accordion title="authentication.gcpIamAuth">
|
<Accordion title="authentication.gcpIamAuth">
|
||||||
The GCP IAM machine identity authentication method is used to authenticate with Infisical. The identity ID is stored in a field in the InfisicalSecret resource. This authentication method can only be used both within and outside GCP environments.
|
The GCP IAM machine identity authentication method is used to authenticate with Infisical. The identity ID is stored in a field in the InfisicalSecret resource. This authentication method can only be used both within and outside GCP environments.
|
||||||
|
|
||||||
@@ -877,6 +897,42 @@ spec:
|
|||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
### Connecting to instances with private/self-signed certificate
|
||||||
|
|
||||||
|
To connect to Infisical instances with private/self-signed certificates, you can configure the TLS settings in the `InfisicalSecret` CRD
|
||||||
|
to point to a CA certificate stored in a Kubernetes secret resource.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
spec:
|
||||||
|
hostAPI: https://app.infisical.com/api
|
||||||
|
resyncInterval: 10
|
||||||
|
tls:
|
||||||
|
caRef:
|
||||||
|
secretName: custom-ca-certificate
|
||||||
|
secretNamespace: default
|
||||||
|
key: ca.crt
|
||||||
|
authentication:
|
||||||
|
---
|
||||||
|
```
|
||||||
|
|
||||||
|
The definition file of the Kubernetes secret for the CA certificate can be structured like the following:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: custom-ca-certificate
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
ca.crt: |
|
||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIEZzCCA0+gAwIBAgIUDk9+HZcMHppiNy0TvoBg8/aMEqIwDQYJKoZIhvcNAQEL
|
||||||
|
...
|
||||||
|
BQAwDTELMAkGA1UEChMCUEgwHhcNMjQxMDI1MTU0MjAzWhcNMjUxMDI1MjE0MjAz
|
||||||
|
-----END CERTIFICATE-----
|
||||||
|
```
|
||||||
|
|
||||||
## Auto redeployment
|
## Auto redeployment
|
||||||
|
|
||||||
Deployments using managed secrets don't reload automatically on updates, so they may use outdated secrets unless manually redeployed.
|
Deployments using managed secrets don't reload automatically on updates, so they may use outdated secrets unless manually redeployed.
|
||||||
@@ -889,6 +945,7 @@ To enable auto redeployment you simply have to add the following annotation to t
|
|||||||
```yaml
|
```yaml
|
||||||
secrets.infisical.com/auto-reload: "true"
|
secrets.infisical.com/auto-reload: "true"
|
||||||
```
|
```
|
||||||
|
|
||||||
<Accordion title="Deployment example with auto redeploy enabled">
|
<Accordion title="Deployment example with auto redeploy enabled">
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
|
|||||||
@@ -0,0 +1,33 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: custom-ca-certificate
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
ca.crt: |
|
||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIEZzCCA0+gAwIBAgIUDk9+HZcMHppiNy0TvoBg8/aMEqIwDQYJKoZIhvcNAQEL
|
||||||
|
BQAwDTELMAkGA1UEChMCUEgwHhcNMjQxMDI1MTU0MjAzWhcNMjUxMDI1MjE0MjAz
|
||||||
|
WjAfMR0wGwYDVQQDExRob3N0LmRvY2tlci5pbnRlcm5hbDCCASIwDQYJKoZIhvcN
|
||||||
|
AQEBBQADggEPADCCAQoCggEBALPBCPhZHCizZWbyGI0LzTLYprsvTMoeZBeR84lj
|
||||||
|
hv/VDUkH3K6jw5g2o2eXg4Aisb/GcQkTxHjmGlUKymhrLBH9zUHjh1yFKPUJdSy1
|
||||||
|
X4YCG+ABNQ8obrTZM/ry5WRHF/KcFIELt/4JpY8OWkxEIisYfe98vObsGH39spcN
|
||||||
|
c3x3Oo4vsBd6ETQOjrXL81kXLoNZoHdsVIU0ZwNpXR1geI477ce3eHOuEhBvKfUR
|
||||||
|
ugRdmX6xUhFNZcKRYiv3RRkm/vnuxWx2CxsecJ0BRoB7nT00gJkkxbt1b5MrPFF4
|
||||||
|
XIdhWIdxSMdMUwtnEo9hT2mzUCkJohLEeqwivZfewghLo88CAwEAAaOCAaswggGn
|
||||||
|
MAkGA1UdEwQCMAAwXgYDVR0fBFcwVTBToFGgT4ZNaHR0cDovL2xvY2FsaG9zdDo4
|
||||||
|
MDgwL2FwaS92MS9wa2kvY3JsLzY2ZDk3OTNkLWMzMTYtNDNhZS05N2RiLTkzNDBj
|
||||||
|
ZmJkNTYxNy9kZXIwHwYDVR0jBBgwFoAU3+CiMP0BF+BnjXBYawENOrnQ+q8wHQYD
|
||||||
|
VR0OBBYEFKUIOV5qAwf0Bd1dMnxIYYglcZT1MIGdBggrBgEFBQcBAQSBkDCBjTCB
|
||||||
|
igYIKwYBBQUHMAKGfmh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9hcGkvdjEvcGtpL2Nh
|
||||||
|
L2EyNDIyZTdlLTAwZWYtNDlhZC1iY2ZhLTUxMzZhODQxNjEyZC9jZXJ0aWZpY2F0
|
||||||
|
ZXMvYWJhNTRjNGEtNjYxOS00MDFlLTk2YTYtN2UwN2MxNzdjOTI4L2RlcjARBgNV
|
||||||
|
HSAECjAIMAYGBFUdIAAwDgYDVR0PAQH/BAQDAgWgMBYGA1UdJQEB/wQMMAoGCCsG
|
||||||
|
AQUFBwMBMB8GA1UdEQQYMBaCFGhvc3QuZG9ja2VyLmludGVybmFsMA0GCSqGSIb3
|
||||||
|
DQEBCwUAA4IBAQAtUUloE1xU+BNF2Fjc/PSOesHz6dFCzGWvCc0QZceK/6v4EWuZ
|
||||||
|
vEU07brGrufhwJ3UnOXO4zxIl3UplQ1S14Xrba4R69Fp3dggFV39ON8R5lpL9hZe
|
||||||
|
cSRywBycKil2C7SytPsjJtvCXY6RXb6YxFse6rDk0qoMwD/g/ou3JIEpgtB2cPuX
|
||||||
|
Blg9ZWAsaOtKhtmi1IyLjwgHDd86XhMzd9osOna1iuARZMZs80ek5b5H4cdFIBTl
|
||||||
|
rwIQc6b9ZbHAD56NttCIE18YmLWbYBCdvga0Qmqwr2fRPg2DE9qoyF1ZJVbwisOc
|
||||||
|
cJ23MFdpsXKiIoQyDmpZl5jg8aKD/jh0wdUx
|
||||||
|
-----END CERTIFICATE-----
|
||||||
@@ -9,6 +9,11 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
hostAPI: https://app.infisical.com/api
|
hostAPI: https://app.infisical.com/api
|
||||||
resyncInterval: 10
|
resyncInterval: 10
|
||||||
|
# tls:
|
||||||
|
# caRef:
|
||||||
|
# secretName: custom-ca-certificate
|
||||||
|
# secretNamespace: default
|
||||||
|
# key: ca.crt
|
||||||
authentication:
|
authentication:
|
||||||
# Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
|
# Make sure to only have 1 authentication method defined, serviceToken/universalAuth.
|
||||||
# If you have multiple authentication methods defined, it may cause issues.
|
# If you have multiple authentication methods defined, it may cause issues.
|
||||||
|
|||||||
Reference in New Issue
Block a user