deconflict merge
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Available"
|
||||
openapi: "GET /api/v1/app-connections/teamcity/available"
|
||||
---
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
title: "Create"
|
||||
openapi: "POST /api/v1/app-connections/teamcity"
|
||||
---
|
||||
|
||||
<Note>
|
||||
Check out the configuration docs for [TeamCity Connections](/integrations/app-connections/teamcity) to learn how to obtain
|
||||
the required credentials.
|
||||
</Note>
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Delete"
|
||||
openapi: "DELETE /api/v1/app-connections/teamcity/{connectionId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by ID"
|
||||
openapi: "GET /api/v1/app-connections/teamcity/{connectionId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by Name"
|
||||
openapi: "GET /api/v1/app-connections/teamcity/connection-name/{connectionName}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "List"
|
||||
openapi: "GET /api/v1/app-connections/teamcity"
|
||||
---
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
title: "Update"
|
||||
openapi: "PATCH /api/v1/app-connections/teamcity/{connectionId}"
|
||||
---
|
||||
|
||||
<Note>
|
||||
Check out the configuration docs for [TeamCity Connections](/integrations/app-connections/teamcity) to learn how to obtain
|
||||
the required credentials.
|
||||
</Note>
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
title: "Create"
|
||||
openapi: "POST /api/v2/secret-rotations/aws-iam-user-secret"
|
||||
---
|
||||
|
||||
<Note>
|
||||
Check out the configuration docs for [AWS IAM User Secret Rotations](/documentation/platform/secret-rotation/aws-iam-user-secret) to learn how to obtain the
|
||||
required parameters.
|
||||
</Note>
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Delete"
|
||||
openapi: "DELETE /api/v2/secret-rotations/aws-iam-user-secret/{rotationId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by ID"
|
||||
openapi: "GET /api/v2/secret-rotations/aws-iam-user-secret/{rotationId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by Name"
|
||||
openapi: "GET /api/v2/secret-rotations/aws-iam-user-secret/rotation-name/{rotationName}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get Credentials by ID"
|
||||
openapi: "GET /api/v2/secret-rotations/aws-iam-user-secret/{rotationId}/generated-credentials"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "List"
|
||||
openapi: "GET /api/v2/secret-rotations/aws-iam-user-secret"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Rotate Secrets"
|
||||
openapi: "POST /api/v2/secret-rotations/aws-iam-user-secret/{rotationId}/rotate-secrets"
|
||||
---
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
title: "Update"
|
||||
openapi: "PATCH /api/v2/secret-rotations/aws-iam-user-secret/{rotationId}"
|
||||
---
|
||||
|
||||
<Note>
|
||||
Check out the configuration docs for [AWS IAM User Secret Rotations](/documentation/platform/secret-rotation/aws-iam-user-secret) to learn how to obtain the
|
||||
required parameters.
|
||||
</Note>
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Create"
|
||||
openapi: "POST /api/v1/secret-syncs/teamcity"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Delete"
|
||||
openapi: "DELETE /api/v1/secret-syncs/teamcity/{syncId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by ID"
|
||||
openapi: "GET /api/v1/secret-syncs/teamcity/{syncId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by Name"
|
||||
openapi: "GET /api/v1/secret-syncs/teamcity/sync-name/{syncName}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Import Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/teamcity/{syncId}/import-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "List"
|
||||
openapi: "GET /api/v1/secret-syncs/teamcity"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Remove Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/teamcity/{syncId}/remove-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Sync Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/teamcity/{syncId}/sync-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Update"
|
||||
openapi: "PATCH /api/v1/secret-syncs/teamcity/{syncId}"
|
||||
---
|
||||
@@ -7,10 +7,38 @@ description: "Generate SSH credentials with the CLI"
|
||||
|
||||
[Infisical SSH](/documentation/platform/ssh) lets you issue SSH credentials to clients to provide short-lived, secure SSH access to infrastructure.
|
||||
|
||||
This command enables you to obtain SSH credentials used to access a remote host; we recommend using the `issue-credentials` sub-command to generate dynamic SSH credentials for each SSH session.
|
||||
This command enables you to obtain SSH credentials used to access a remote host. We recommend using the `connect` sub-command which handles the full workflow of issuing credentials and establishing an SSH connection in one step.
|
||||
|
||||
### Sub-commands
|
||||
|
||||
<Accordion title="infisical ssh connect">
|
||||
This command is used to connect to an SSH host using issued credentials. It will automatically issue credentials and either add them to your SSH agent or write them to disk before establishing an SSH connection.
|
||||
|
||||
```bash
|
||||
$ infisical ssh connect
|
||||
```
|
||||
|
||||
### Flags
|
||||
<Accordion title="--hostname">
|
||||
The hostname of the SSH host to connect to. If not provided, you will be prompted to select from available hosts.
|
||||
</Accordion>
|
||||
<Accordion title="--loginUser">
|
||||
The login user for the SSH connection. If not provided, you will be prompted to select from available login users.
|
||||
</Accordion>
|
||||
<Accordion title="--writeHostCaToFile">
|
||||
Whether to write the Host CA public key to `~/.ssh/known_hosts` if it doesn't already exist.
|
||||
|
||||
Default value: `true`
|
||||
</Accordion>
|
||||
<Accordion title="--outFilePath">
|
||||
The path to write the SSH credentials to such as `~/.ssh`, `./some_folder`, `./some_folder/id_rsa-cert.pub`. If not provided, the credentials will be added to the SSH agent and used to establish an interactive SSH connection.
|
||||
</Accordion>
|
||||
<Accordion title="--token">
|
||||
An authenticated token to use to authenticate with Infisical.
|
||||
</Accordion>
|
||||
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="infisical ssh issue-credentials">
|
||||
This command is used to issue SSH credentials (SSH certificate, public key, and private key) against a certificate template.
|
||||
|
||||
@@ -29,43 +57,44 @@ This command enables you to obtain SSH credentials used to access a remote host;
|
||||
</Accordion>
|
||||
<Accordion title="--addToAgent">
|
||||
Whether to add issued SSH credentials to the SSH agent.
|
||||
|
||||
|
||||
Default value: `false`
|
||||
|
||||
|
||||
Note that either the `--outFilePath` or `--addToAgent` flag must be set for the sub-command to execute successfully.
|
||||
</Accordion>
|
||||
<Accordion title="--outFilePath">
|
||||
The path to write the SSH credentials to such as `~/.ssh`, `./some_folder`, `./some_folder/id_rsa-cert.pub`. If not provided, the credentials will be saved to the current working directory where the command is run.
|
||||
|
||||
|
||||
Note that either the `--outFilePath` or `--addToAgent` flag must be set for the sub-command to execute successfully.
|
||||
</Accordion>
|
||||
<Accordion title="--keyAlgorithm">
|
||||
The key algorithm to issue SSH credentials for.
|
||||
|
||||
|
||||
Default value: `RSA_2048`
|
||||
|
||||
|
||||
Available options: `RSA_2048`, `RSA_4096`, `EC_prime256v1`, `EC_secp384r1`.
|
||||
</Accordion>
|
||||
<Accordion title="--certType">
|
||||
The certificate type to issue SSH credentials for.
|
||||
|
||||
|
||||
Default value: `user`
|
||||
|
||||
|
||||
Available options: `user` or `host`
|
||||
</Accordion>
|
||||
<Accordion title="--ttl">
|
||||
The time-to-live (TTL) for the issued SSH certificate (e.g. `2 days`, `1d`, `2h`, `1y`).
|
||||
|
||||
|
||||
Defaults to the Default TTL value set in the certificate template.
|
||||
</Accordion>
|
||||
<Accordion title="--keyId">
|
||||
A custom Key ID to issue SSH credentials for.
|
||||
|
||||
|
||||
Defaults to the autogenerated Key ID by Infisical.
|
||||
</Accordion>
|
||||
<Accordion title="--token">
|
||||
An authenticated token to use to issue SSH credentials.
|
||||
</Accordion>
|
||||
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="infisical ssh sign-key">
|
||||
@@ -95,22 +124,23 @@ This command enables you to obtain SSH credentials used to access a remote host;
|
||||
</Accordion>
|
||||
<Accordion title="--certType">
|
||||
The certificate type to issue SSH credentials for.
|
||||
|
||||
|
||||
Default value: `user`
|
||||
|
||||
|
||||
Available options: `user` or `host`
|
||||
</Accordion>
|
||||
<Accordion title="--ttl">
|
||||
The time-to-live (TTL) for the issued SSH certificate (e.g. `2 days`, `1d`, `2h`, `1y`).
|
||||
|
||||
|
||||
Defaults to the Default TTL value set in the certificate template.
|
||||
</Accordion>
|
||||
<Accordion title="--keyId">
|
||||
A custom Key ID to issue SSH credentials for.
|
||||
|
||||
|
||||
Defaults to the autogenerated Key ID by Infisical.
|
||||
</Accordion>
|
||||
<Accordion title="--token">
|
||||
An authenticated token to use to issue SSH credentials.
|
||||
</Accordion>
|
||||
</Accordion>
|
||||
|
||||
</Accordion>
|
||||
|
||||
@@ -8,22 +8,46 @@ infisical user
|
||||
```
|
||||
|
||||
## Description
|
||||
|
||||
This command allows you to manage the current logged in users on the CLI
|
||||
|
||||
### Sub-commands
|
||||
### Sub-commands
|
||||
|
||||
<Accordion title="infisical user switch" defaultOpen="true">
|
||||
Use this command to switch between profiles that are currently logged into the CLI
|
||||
Use this command to switch between profiles that are currently logged into the CLI
|
||||
|
||||
```bash
|
||||
infisical user switch
|
||||
```
|
||||
|
||||
```bash
|
||||
infisical user switch
|
||||
```
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="infisical user update domain">
|
||||
With this command, you can modify the backend API that is utilized for all requests associated with a specific profile.
|
||||
For instance, you have the option to point the profile to use either the Infisical Cloud or your own self-hosted Infisical instance.
|
||||
|
||||
```bash
|
||||
infisical user update domain
|
||||
```bash
|
||||
infisical user update domain
|
||||
```
|
||||
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="infisical user get token">
|
||||
Use this command to get your current Infisical access token and session information. This command requires you to be logged in.
|
||||
|
||||
The command will display:
|
||||
|
||||
- Your session ID
|
||||
- Your full JWT access token
|
||||
|
||||
```bash
|
||||
infisical user get token
|
||||
```
|
||||
|
||||
Example output:
|
||||
|
||||
```bash
|
||||
Session ID: abc123-xyz-456
|
||||
Token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
|
||||
```
|
||||
</Accordion>
|
||||
|
||||
@@ -6,40 +6,55 @@ description: "Learn how to structure your projects, secrets, and other resources
|
||||
|
||||
Infisical is designed to provide comprehensive, centralized, and efficient management of secrets, certificates, and encryption keys within organizations. Below is an overview of Infisical's structured components, which developers and administrators can leverage for optimal project management and security posture.
|
||||
|
||||
### 1. Projects
|
||||
### 0. Cluster/Instance
|
||||
|
||||
- **Best Practice**: In most cases, a single Infisical instance or cluster is sufficient. Multiple clusters are typically only necessary for large, globally distributed organizations.
|
||||
- **Use Cases**:
|
||||
- **Cloud-hosted** deployments typically use a single cluster. While technically possible, using multiple clusters is not a common practice and is generally unnecessary.
|
||||
- **Self-hosted** deployments can be configured with multiple clusters if needed.
|
||||
|
||||
|
||||
### 1. Organization
|
||||
|
||||
- **Definition**: An Infisical [organization](/documentation/platform/organization) is a set of projects that use the same billing.
|
||||
- **Use Cases**:
|
||||
- In **self-hosted** setups, you can create multiple organizations (e.g., one for each department or business unit).
|
||||
- In **cloud-hosted deployments**, it's standard to use a single organization.
|
||||
|
||||
### 2. Projects
|
||||
|
||||
- **Definition and Role**: [Projects](/documentation/platform/project) are the highest-level construct within an [organization](/documentation/platform/organization) in Infisical. They serve as the primary container for all functionalities.
|
||||
- **Correspondence to Code Repositories**: Projects typically align with specific code repositories.
|
||||
- **Functional Capabilities**: Each project encompasses features for managing secrets, certificates, and encryption keys, serving as the central hub for these resources.
|
||||
|
||||
### 2. Environments
|
||||
### 3. Environments
|
||||
|
||||
- **Purpose**: Environments are designed for organizing and compartmentalizing secrets within projects.
|
||||
- **Customization Options**: Environments can be tailored to align with existing infrastructure setups of any project. Default options include **Development**, **Staging**, and **Production**.
|
||||
- **Structure**: Each environment inherently has a root level for storing secrets, but additional sub-organizations can be created through [folders](/documentation/platform/folder) for better secret management.
|
||||
|
||||
### 3. Folders
|
||||
### 4. Folders
|
||||
|
||||
- **Use Case**: Folders are available for more advanced organizational needs, allowing logical separation of secrets.
|
||||
- **Typical Structure**: Folders can correspond to specific logical units, such as microservices or different layers of an application, providing refined control over secrets.
|
||||
|
||||
### 4. Imports
|
||||
### 5. Imports
|
||||
|
||||
- **Purpose and Benefits**: To promote reusability and avoid redundancy, Infisical supports the use of imports. This allows secrets, folders, or entire environments to be referenced across multiple projects as needed.
|
||||
- **Best Practice**: Utilizing [secret imports](/documentation/platform/secret-reference#secret-imports) or [references](/documentation/platform/secret-reference#secret-referencing) ensures consistency and minimizes manual overhead.
|
||||
|
||||
### 5. Approval Workflows
|
||||
### 6. Approval Workflows
|
||||
|
||||
- **Importance**: Implementing approval workflows is recommended for organizations aiming to enhance efficiency and strengthen their security posture.
|
||||
- **Types of Workflows**:
|
||||
- **[Access Requests](/documentation/platform/pr-workflows)**: This workflow allows developers to request access to sensitive resources. Such access can be configured for temporary use, a practice known as "just-in-time" access.
|
||||
- **[Change Requests](/documentation/platform/access-controls/access-requests)**: Facilitates reviews and approvals when changes are proposed for sensitive environments or specific folders, ensuring proper oversight.
|
||||
|
||||
### 6. Access Controls
|
||||
### 7. Access Controls
|
||||
|
||||
Infisical’s access control framework is unified for both human users and machine identities, ensuring consistent management across the board.
|
||||
|
||||
### 6.1 Roles
|
||||
### 7.1 Roles
|
||||
|
||||
- **2 Role Types**:
|
||||
- **Organization-Level Roles**: Provide broad access across the organization (e.g., ability to manage billing, configure settings, etc.).
|
||||
@@ -49,17 +64,17 @@ Infisical’s access control framework is unified for both human users and machi
|
||||
|
||||
<Note>Project access is defined not via an organization-level role, but rather through specific project memberships of both human and machine identities. Admin roles bypass this by default. </Note>
|
||||
|
||||
### 6.2 Additional Privileges
|
||||
### 7.2 Additional Privileges
|
||||
|
||||
[Additional privileges](/documentation/platform/access-controls/additional-privileges) can be assigned to users and machines on an ad-hoc basis for specific scenarios where roles alone are insufficient. If you find yourself using additional privileges too much, it is recommended to create custom roles. Additional privileges can be temporary or permanent.
|
||||
|
||||
|
||||
|
||||
### 6.3 Attribute-Based Access Control (ABAC)
|
||||
### 7.3 Attribute-Based Access Control (ABAC)
|
||||
|
||||
[Attribute-based Access Controls](/documentation/platform/access-controls/attribute-based-access-controls) allow restrictions based on tags or attributes linked to secrets. These can be integrated with SAML assertions and other security frameworks for dynamic access management.
|
||||
|
||||
### 6.4 User Groups
|
||||
### 7.4 User Groups
|
||||
|
||||
- **Application**: Organizations should use users groups in situations when they have a lot of developers with the same level of access (e.g., separated by team, department, seniority, etc.).
|
||||
- **Synchronization**: [User groups](/documentation/platform/groups) can be synced with an identity provider to maintain consistency and reduce manual management.
|
||||
|
||||
@@ -41,3 +41,16 @@ Dynamic secrets are particularly useful in environments with stringent security
|
||||
4. [Oracle](./oracle)
|
||||
6. [Redis](./redis)
|
||||
5. [AWS IAM](./aws-iam)
|
||||
|
||||
**FAQ**
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Why is my SQL dynamic secret failing when I generate a lease?">
|
||||
This usually happens when the SQL statements defined for creating or revoking the secret are not compatible with your database provider.
|
||||
|
||||
Different SQL engines have different expectations for quoting identifiers and values. For example, some use backticks (`` `username` ``), others use single quotes (`'username'`), and some expect double quotes (`"username"`). A statement that works on one provider might fail on another.
|
||||
|
||||
**Recommendation:**
|
||||
Make sure to adjust your SQL statements to follow the syntax required by your specific database provider. Always test them directly on your target database to ensure they execute without errors.
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
|
||||
@@ -19,7 +19,7 @@ Before you begin, you'll first need to choose a method of authentication with AW
|
||||

|
||||
|
||||
2. Select **AWS Account** as the **Trusted Entity Type**.
|
||||
3. Choose **Another AWS Account** and enter **381492033652** (Infisical AWS Account ID). This restricts the role to be assumed only by Infisical. If you are self-hosting, provide the AWS account number where Infisical is hosted.
|
||||
3. Select **Another AWS Account** and provide the appropriate Infisical AWS Account ID: use **381492033652** for the **US region**, and **345594589636** for the **EU region**. This restricts the role to be assumed only by Infisical. If you are self-hosting, provide the AWS account number where Infisical is hosted.
|
||||
4. Optionally, enable **Require external ID** and enter your Infisical **project ID** to further enhance security.
|
||||
</Step>
|
||||
<Step title="Add Required Permissions for the IAM Role">
|
||||
|
||||
@@ -0,0 +1,191 @@
|
||||
---
|
||||
title: "AWS IAM User"
|
||||
description: "Learn how to automatically rotate Access Key Id and Secret Key of AWS IAM Users."
|
||||
---
|
||||
|
||||
Infisical's AWS IAM User secret rotation capability lets you update the **Access key** and **Secret access key** credentials of a target IAM user from within Infisical
|
||||
at a specified interval or on-demand.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Create an [AWS Connection](/integrations/app-connections/aws) with the required **Secret Rotation** permissions
|
||||
- Make sure to add the following permissions to your IAM Role/IAM User Permission policy set used by your AWS Connection:
|
||||
|
||||
```json
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Effect": "Allow",
|
||||
"Action": [
|
||||
"iam:ListAccessKeys",
|
||||
"iam:CreateAccessKey",
|
||||
"iam:UpdateAccessKey",
|
||||
"iam:DeleteAccessKey",
|
||||
"iam:ListUsers"
|
||||
],
|
||||
"Resource": "*"
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
## Workflow
|
||||
|
||||
The typical workflow for using the AWS IAM User rotation strategy consists of four steps:
|
||||
|
||||
1. Creating the target IAM user whose credentials you wish to rotate.
|
||||
2. Configuring the rotation strategy in Infisical with the credentials of the managing IAM user.
|
||||
3. Pressing the **Rotate** button in the Infisical dashboard to trigger the rotation of the target IAM user's credentials. The strategy can also be configured to rotate the credentials automatically at a specified interval.
|
||||
|
||||
In the following steps, we explore the end-to-end workflow for setting up this strategy in Infisical.
|
||||
|
||||
<Steps>
|
||||
<Step title="Create the target IAM user">
|
||||
To begin, create an IAM user whose credentials you wish to rotate. If you already have an IAM user,
|
||||
then you can skip this step.
|
||||
</Step>
|
||||
<Step title="Configure the AWS IAM User secret rotation strategy in Infisical">
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
1. Navigate to your Secret Manager Project's Dashboard and select **Add Secret Rotation** from the actions dropdown.
|
||||

|
||||
|
||||
2. Select the **AWS IAM User Secret** option.
|
||||

|
||||
|
||||
3. Select the **AWS Connection** to use and configure the rotation behavior. Then click **Next**.
|
||||

|
||||
|
||||
- **AWS Connection** - the connection that will perform the rotation of the specified application's Client Secret.
|
||||
- **Rotation Interval** - the interval, in days, that once elapsed will trigger a rotation.
|
||||
- **Rotate At** - the local time of day when rotation should occur once the interval has elapsed.
|
||||
- **Auto-Rotation Enabled** - whether secrets should automatically be rotated once the rotation interval has elapsed. Disable this option to manually rotate secrets or pause secret rotation.
|
||||
|
||||
4. Select the AWS IAM user and the region of the user whose credentials you want to rotate. Then click **Next**.
|
||||

|
||||
|
||||
5. Specify the secret names that the AWS IAM access key credentials should be mapped to. Then click **Next**.
|
||||

|
||||
|
||||
- **Access Key ID** - the name of the secret that the AWS access key ID will be mapped to.
|
||||
- **Secret Access Key** - the name of the secret that the rotated secret access key will be mapped to.
|
||||
|
||||
6. Give your rotation a name and description (optional). Then click **Next**.
|
||||

|
||||
|
||||
- **Name** - the name of the secret rotation configuration. Must be slug-friendly.
|
||||
- **Description** (optional) - a description of this rotation configuration.
|
||||
|
||||
7. Review your configuration, then click **Create Secret Rotation**.
|
||||

|
||||
|
||||
8. Your **AWS IAM User** credentials are now available for use via the mapped secrets.
|
||||

|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create an AWS IAM User Rotation, make an API request to the [Create AWS IAM User Rotation](/api-reference/endpoints/secret-rotations/aws-iam-user-secret/create) API endpoint.
|
||||
|
||||
You will first need the **User Name** of the AWS IAM user you want to rotate the secret for. This can be obtained from the IAM console, on Users tab.
|
||||

|
||||
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://us.infisical.com/api/v2/secret-rotations/aws-iam-user-secret \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-aws-rotation",
|
||||
"projectId": "9602cfc5-20b9-4c35-a056-dd7372db0f25",
|
||||
"description": "My rotation strategy description",
|
||||
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"environment": "dev",
|
||||
"secretPath": "/",
|
||||
"isAutoRotationEnabled": true,
|
||||
"rotationInterval": 2,
|
||||
"rotateAtUtc": {
|
||||
"hours": 11.5,
|
||||
"minutes": 29.5
|
||||
},
|
||||
"parameters": {
|
||||
"userName": "testUser",
|
||||
"region": "us-east-1"
|
||||
},
|
||||
"secretsMapping": {
|
||||
"accessKeyId": "AWS_ACCESS_KEY_ID",
|
||||
"secretAccessKey": "AWS_SECRET_ACCESS_KEY"
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"secretRotation": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"name": "my-aws-rotation",
|
||||
"description": "My rotation strategy description",
|
||||
"secretsMapping": {
|
||||
"accessKeyId": "AWS_ACCESS_KEY_ID",
|
||||
"secretAccessKey": "AWS_SECRET_ACCESS_KEY"
|
||||
},
|
||||
"isAutoRotationEnabled": true,
|
||||
"activeIndex": 0,
|
||||
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"createdAt": "2023-11-07T05:31:56Z",
|
||||
"updatedAt": "2023-11-07T05:31:56Z",
|
||||
"rotationInterval": 123,
|
||||
"rotationStatus": "success",
|
||||
"lastRotationAttemptedAt": "2023-11-07T05:31:56Z",
|
||||
"lastRotatedAt": "2023-11-07T05:31:56Z",
|
||||
"lastRotationJobId": null,
|
||||
"nextRotationAt": "2023-11-07T05:31:56Z",
|
||||
"isLastRotationManual": true,
|
||||
"connection": {
|
||||
"app": "aws",
|
||||
"name": "my-aws-connection",
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||
},
|
||||
"environment": {
|
||||
"slug": "dev",
|
||||
"name": "Development",
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||
},
|
||||
"projectId": "9602cfc5-20b9-4c35-a056-dd7372db0f25",
|
||||
"folder": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"path": "/"
|
||||
},
|
||||
"rotateAtUtc": {
|
||||
"hours": 11.5,
|
||||
"minutes": 29.5
|
||||
},
|
||||
"lastRotationMessage": null,
|
||||
"type": "aws-iam-user-secret",
|
||||
"parameters": {
|
||||
"userName": "testUser",
|
||||
"region": "us-east-1"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
**FAQ**
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Why are my AWS IAM credentials not rotating?">
|
||||
There are a few reasons for why this might happen:
|
||||
- The strategy configuration is invalid (e.g. the managing IAM user's credentials are incorrect, the target AWS region is incorrect, etc.)
|
||||
- The managing IAM user is insufficently permissioned to rotate the credentials of the target IAM user. For instance, you may have setup
|
||||
[paths](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/) for the managing IAM user and the policy does not have the necessary
|
||||
permissions to rotate the credentials.
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
@@ -1,143 +0,0 @@
|
||||
---
|
||||
title: "AWS IAM User"
|
||||
description: "Learn how to automatically rotate Access Key Id and Secret Key of AWS IAM Users."
|
||||
---
|
||||
|
||||
Infisical's AWS IAM User secret rotation capability lets you update the **Access key** and **Secret access key** credentials of a target IAM user from within Infisical
|
||||
at a specified interval or on-demand.
|
||||
|
||||
## Workflow
|
||||
|
||||
The typical workflow for using the AWS IAM User rotation strategy consists of four steps:
|
||||
|
||||
1. Creating the target IAM user whose credentials you wish to rotate.
|
||||
2. Creating the managing IAM user used by Infisical to rotate the credentials of the target IAM user.
|
||||
3. Configuring the rotation strategy in Infisical with the credentials of the managing IAM user.
|
||||
4. Pressing the **Rotate** button in the Infisical dashboard to trigger the rotation of the target IAM user's credentials. The strategy can also be configured to rotate the credentials automatically at a specified interval.
|
||||
|
||||
In the following steps, we explore the end-to-end workflow for setting up this strategy in Infisical.
|
||||
|
||||
<Steps>
|
||||
<Step title="Create the target IAM user">
|
||||
To begin, create an IAM user whose credentials you wish to rotate. If you already have an IAM user,
|
||||
then you can skip this step.
|
||||
</Step>
|
||||
<Step title="Create the managing IAM user">
|
||||
Next, create another IAM user to be used by Infisical to rotate the credentials of the IAM user in the previous step.
|
||||
|
||||
2.1. In your AWS console, head to IAM > Access management > Users and press **Create user**.
|
||||
|
||||

|
||||
|
||||
2.2. Next, give the user a username like **infisical-rotation-manager** and press **Next**.
|
||||
|
||||

|
||||
|
||||
2.3. Next, in the **Set permissions** step, select **Attach policies directly** and then press **Create policy**.
|
||||
|
||||

|
||||
|
||||
2.4. Next, in the **Policy editor**, paste the following JSON and press **Next**:
|
||||
|
||||
```json
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Sid": "VisualEditor0",
|
||||
"Effect": "Allow",
|
||||
"Action": [
|
||||
"iam:DeleteAccessKey",
|
||||
"iam:GetAccessKeyLastUsed",
|
||||
"iam:CreateAccessKey"
|
||||
],
|
||||
"Resource": "*"
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
<Note>
|
||||
The IAM policy above uses the wildcard option in Resource: "*".
|
||||
|
||||
You may want to restrict the policy to a specific path, and make any adjustments as necessary, to control access for the managing user in production.
|
||||
|
||||
Read more about this [here](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/).
|
||||
</Note>
|
||||
|
||||
In the **Review and create** step, give the policy a name like **infisical-rotation-manager**, press **Create policy** to finish creating the policy.
|
||||
|
||||

|
||||
|
||||
2.5. Back in the **Set permissions** step from step 2.3, refresh the policy list and search for the policy you just created from step 2.4.
|
||||
|
||||
Select the policy and press **Next**.
|
||||
|
||||

|
||||
|
||||
In the **Review and create** step, press **Create user** to finish creating the IAM user.
|
||||
|
||||

|
||||
|
||||
2.5. Having created the user, head to its Security credentials > Access keys and press **Create access key**.
|
||||
|
||||
Follow the subsequent steps to create the **access key** and **secret access key** credential pair for the user.
|
||||
|
||||

|
||||
|
||||
At the end of the flow, copy the **Access key** and **Secret access key** to use when configuring the AWS IAM User rotation strategy back in Infisical next.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Configure the AWS IAM User secret rotation strategy in Infisical">
|
||||
3.1. Back in Infisical, head to the Project > Secrets > Environment and path where you want the rotated AWS IAM credentials to appear and create two placeholder secrets.
|
||||
|
||||
In this example, we'll create two secrets called `AWS_ACCESS_KEY` and `AWS_SECRET_ACCESS_KEY`.
|
||||
|
||||

|
||||
|
||||
3.2. Next, in the **Secret Rotation** tab, press on the **AWS IAM** tile to configure the AWS IAM User rotation strategy.
|
||||
|
||||

|
||||
|
||||
3.3. Input the configuration details for the AWS IAM User rotation strategy obtained from steps 1 and 2:
|
||||
|
||||

|
||||
|
||||
Here's some guidance on each field:
|
||||
|
||||
- Manager User Access Key: The managing IAM user's access key from step 2.5.
|
||||
- Manager User Secret Key: The managing IAM user's secret access key from step 2.5.
|
||||
- Manager User AWS Region: The [AWS region](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Concepts.RegionsAndAvailabilityZones.html) for Infisical to make requests to such as `us-east-1`.
|
||||
- IAM Username: The IAM username of the user from step 1.
|
||||
|
||||
Next, specify the output secret mappings configuration for the rotated AWS IAM credentials; this is the secrets whose values will be replaced with new credentials after each rotation.
|
||||
Here, you can also specify a rotation interval for the credentials to be automatically rotated periodically.
|
||||
|
||||
In this example, we want to map the output of the rotated AWS IAM credentials to the secrets that we created in step 3.1 (i.e. `AWS_ACCESS_KEY` and `AWS_SECRET_ACCESS_KEY`).
|
||||
|
||||

|
||||
|
||||
Finally, press **Submit** to create the secret rotation strategy.
|
||||
</Step>
|
||||
<Step title="Rotate secrets in Infisical">
|
||||
You should now see the AWS IAM User rotation strategy listed in the **Secret Rotation** tab.
|
||||
|
||||
To manually trigger a rotation, you can press the **Rotate** button on the strategy.
|
||||
Once triggered, the secrets in step 3.1 should be updated with new rotated credential values.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
**FAQ**
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Why are my AWS IAM credentials not rotating?">
|
||||
There are a few reasons for why this might happen:
|
||||
|
||||
- The strategy configuration is invalid (e.g. the managing IAM user's credentials are incorrect, the target IAM username is incorrect, etc.).
|
||||
- The managing IAM user is insufficently permissioned to rotate the credentials of the target IAM user. For instance, you may have setup [paths](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/) for the managing IAM user and the policy does not have the necessary permissions to rotate the credentials.
|
||||
- The target IAM user already has 2 access keys configured in AWS; you should delete one of the access keys to allow for rotation.
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
@@ -10,10 +10,10 @@ Infisical SSH can be configured to provide users on your team short-lived, secur
|
||||
and improves upon traditional SSH key-based authentication by mitigating private key compromise, static key management,
|
||||
unauthorized access, and SSH key sprawl.
|
||||
|
||||
The following entities and concepts are important to understand when using Infisical SSH:
|
||||
The following entities are important to understand when configuring and using Infisical SSH:
|
||||
|
||||
- Administrator: An individual on your team who is responsible for configuring Infisical SSH.
|
||||
- Users: Other individuals on your team that need access to the remote host.
|
||||
- Users: Other individuals that gain access to remote hosts through Infisical SSH.
|
||||
- Host: A remote machine (e.g. EC2 instance, GCP VM, Azure VM, on-prem Linux server, Raspberry Pi, VMware VM, etc.) that users need SSH access to that is registered with Infisical SSH.
|
||||
|
||||
## Workflow
|
||||
@@ -72,7 +72,7 @@ we will register a remote host with Infisical through a [machine identity](/docu
|
||||
Next, use the `infisical ssh add-host` command to register the remote host with Infisical. As part of this command, input the ID of the Infisical SSH project you created in step 1 for the `--projectId` flag and the hostname of the remote host for the `--hostname` flag.
|
||||
|
||||
```bash
|
||||
sudo infisical ssh add-host --projectId=<project-id> --hostname=<hostname> --token="$INFISICAL_TOKEN" --writeUserCaToFile --writeHostCertToFile --configureSshd
|
||||
sudo infisical ssh add-host --projectId=<project-id> --hostname=<hostname> --token="$INFISICAL_TOKEN" --write-user-ca-to-file --write-host-cert-to-file --configure-sshd
|
||||
```
|
||||
|
||||
<Tip>
|
||||
@@ -136,44 +136,66 @@ Once Infisical SSH is configured by an administrator, users can SSH to the remot
|
||||
<Step title="Install the Infisical CLI">
|
||||
Follow the instructions [here](/cli/overview) to install the Infisical CLI onto your local machine.
|
||||
</Step>
|
||||
<Step title="Log in with the CLI">
|
||||
Run the `infisical login` command to authenticate with Infisical.
|
||||
|
||||
```bash
|
||||
infisical login
|
||||
```
|
||||
</Step>
|
||||
<Step title="Connect to the remote host">
|
||||
Run the `infisical ssh connect` command to connect to a remote host.
|
||||
The `infisical ssh connect` command can be used in either interactive or non-interactive mode to connect to a remote host.
|
||||
|
||||
```bash
|
||||
infisical ssh connect
|
||||
```
|
||||
<Tabs>
|
||||
<Tab title="Interactive Mode">
|
||||
In interactive mode, you'll first need to authenticate with Infisical by running:
|
||||
|
||||
You'll be prompted to select an SSH Host from a list of accessible hosts; this is based on project membership and login mappings configured on hosts by
|
||||
the administrator.
|
||||
```bash
|
||||
infisical login
|
||||
```
|
||||
|
||||
```bash
|
||||
Use the arrow keys to navigate: ↓ ↑ → ←
|
||||
? Select an SSH Host:
|
||||
▸ ec2-12-345-678-910.ap-northeast-1.compute.amazonaws.com
|
||||
```
|
||||
Then simply run:
|
||||
|
||||
After selecting a host, you'll be prompted to select a login user from a list of allowed login users:
|
||||
```bash
|
||||
infisical ssh connect
|
||||
```
|
||||
|
||||
```bash
|
||||
? Select Login User:
|
||||
▸ ec2-user
|
||||
```
|
||||
You'll be prompted to select an SSH Host from a list of accessible hosts; this is based on project membership and login mappings configured on hosts by
|
||||
the administrator.
|
||||
|
||||
If successful, you should be able to SSH to the remote host.
|
||||
```bash
|
||||
Use the arrow keys to navigate: ↓ ↑ → ←
|
||||
? Select an SSH Host:
|
||||
▸ ec2-12-345-678-910.ap-northeast-1.compute.amazonaws.com
|
||||
```
|
||||
|
||||
```bash
|
||||
✔ ec2-54-199-104-116.ap-northeast-1.compute.amazonaws.com
|
||||
✔ ec2-user
|
||||
✔ SSH credentials successfully added to agent
|
||||
Connecting to [email protected]...
|
||||
```
|
||||
After selecting a host, you'll be prompted to select a login user from a list of allowed login users:
|
||||
|
||||
```bash
|
||||
? Select Login User:
|
||||
▸ ec2-user
|
||||
```
|
||||
|
||||
If successful, you should be able to SSH to the remote host.
|
||||
|
||||
```bash
|
||||
✔ ec2-54-199-104-116.ap-northeast-1.compute.amazonaws.com
|
||||
✔ ec2-user
|
||||
✔ SSH credentials successfully added to agent
|
||||
Connecting to [email protected]...
|
||||
```
|
||||
</Tab>
|
||||
<Tab title="Non-Interactive Mode">
|
||||
For CI/CD pipelines or automation scenarios, you can use the non-interactive mode with an Infisical token:
|
||||
|
||||
```bash
|
||||
infisical ssh connect \
|
||||
--hostname ec2-12-345-678-910.ap-northeast-1.compute.amazonaws.com \
|
||||
--login-user ec2-user \
|
||||
--out-file-path ~/.ssh/id_rsa-cert.pub \
|
||||
--token <your-infisical-token>
|
||||
```
|
||||
|
||||
This will:
|
||||
- Connect to the specified hostname
|
||||
- Use the specified login user
|
||||
- Write the SSH credentials to the specified path instead of adding them to the SSH agent
|
||||
- Authenticate using the provided Infisical token
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
|
||||
</Steps>
|
||||
|
||||
|
After Width: | Height: | Size: 308 KiB |
|
Before Width: | Height: | Size: 974 KiB After Width: | Height: | Size: 1.1 MiB |
|
After Width: | Height: | Size: 1.1 MiB |
|
After Width: | Height: | Size: 698 KiB |
|
After Width: | Height: | Size: 727 KiB |
|
After Width: | Height: | Size: 252 KiB |
|
After Width: | Height: | Size: 326 KiB |
|
After Width: | Height: | Size: 296 KiB |
|
After Width: | Height: | Size: 239 KiB |
|
After Width: | Height: | Size: 435 KiB |
|
After Width: | Height: | Size: 622 KiB |
|
After Width: | Height: | Size: 637 KiB |
|
After Width: | Height: | Size: 999 KiB |
|
After Width: | Height: | Size: 590 KiB |
|
After Width: | Height: | Size: 582 KiB |
|
After Width: | Height: | Size: 584 KiB |
|
After Width: | Height: | Size: 238 KiB |
|
After Width: | Height: | Size: 338 KiB |
|
Before Width: | Height: | Size: 950 KiB After Width: | Height: | Size: 1.1 MiB |
|
After Width: | Height: | Size: 696 KiB |
|
After Width: | Height: | Size: 1.1 MiB |
|
After Width: | Height: | Size: 678 KiB |
|
After Width: | Height: | Size: 640 KiB |
|
After Width: | Height: | Size: 656 KiB |
|
After Width: | Height: | Size: 664 KiB |
|
After Width: | Height: | Size: 628 KiB |
|
After Width: | Height: | Size: 196 KiB |
|
After Width: | Height: | Size: 203 KiB |
|
After Width: | Height: | Size: 217 KiB |
@@ -55,7 +55,7 @@ Infisical supports two methods for connecting to AWS.
|
||||

|
||||
|
||||
2. Select **AWS Account** as the **Trusted Entity Type**.
|
||||
3. Choose **Another AWS Account** and enter **381492033652** (Infisical AWS Account ID). This restricts the role to be assumed only by Infisical. If self-hosting, provide your AWS account number instead.
|
||||
3. Select **Another AWS Account** and provide the appropriate Infisical AWS Account ID: use **381492033652** for the **US region**, and **345594589636** for the **EU region**. This restricts the role to be assumed only by Infisical. If self-hosting, provide your AWS account number instead.
|
||||
4. (Recommended) <strong>Enable "Require external ID"</strong> and input your **Organization ID** to strengthen security and mitigate the [confused deputy problem](https://docs.aws.amazon.com/IAM/latest/UserGuide/confused-deputy.html).
|
||||
|
||||
<Warning type="warning" title="Security Best Practice: Use External ID to Prevent Confused Deputy Attacks">
|
||||
@@ -146,6 +146,34 @@ Infisical supports two methods for connecting to AWS.
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
</Tab>
|
||||
<Tab title="Secret Rotation">
|
||||
<AccordionGroup>
|
||||
<Accordion title="AWS IAM">
|
||||
Use the following custom policy to grant the minimum permissions required by Infisical to rotate secrets to AWS Access Keys:
|
||||
|
||||

|
||||
|
||||
```json
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Effect": "Allow",
|
||||
"Action": [
|
||||
"iam:ListAccessKeys",
|
||||
"iam:CreateAccessKey",
|
||||
"iam:UpdateAccessKey",
|
||||
"iam:DeleteAccessKey",
|
||||
"iam:ListUsers"
|
||||
],
|
||||
"Resource": "*"
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
|
||||
@@ -293,6 +321,34 @@ Infisical supports two methods for connecting to AWS.
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
</Tab>
|
||||
<Tab title="Secret Rotation">
|
||||
<AccordionGroup>
|
||||
<Accordion title="AWS IAM">
|
||||
Use the following custom policy to grant the minimum permissions required by Infisical to rotate secrets to AWS Access Keys:
|
||||
|
||||

|
||||
|
||||
```json
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Effect": "Allow",
|
||||
"Action": [
|
||||
"iam:ListAccessKeys",
|
||||
"iam:CreateAccessKey",
|
||||
"iam:UpdateAccessKey",
|
||||
"iam:DeleteAccessKey",
|
||||
"iam:ListUsers"
|
||||
],
|
||||
"Resource": "*"
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
<Step title="Obtain Access Key ID and Secret Access Key">
|
||||
@@ -362,4 +418,5 @@ Infisical supports two methods for connecting to AWS.
|
||||
</Steps>
|
||||
|
||||
</Tab>
|
||||
|
||||
</Tabs>
|
||||
|
||||
@@ -0,0 +1,119 @@
|
||||
---
|
||||
title: "TeamCity Connection"
|
||||
description: "Learn how to configure a TeamCity Connection for Infisical."
|
||||
---
|
||||
|
||||
Infisical supports connecting to TeamCity using an Access Token to securely sync your secrets to TeamCity.
|
||||
|
||||
## Setup TeamCity Connection in Infisical
|
||||
|
||||
<Steps>
|
||||
<Step title="Navigate to your profile on TeamCity">
|
||||
Navigate to the TeamCity **Profile** page by clicking on your profile icon in the bottom-left corner.
|
||||

|
||||
</Step>
|
||||
<Step title="Select Access Tokens Tab">
|
||||
Select the **Access Tokens** tab from the left sidebar navigation menu.
|
||||

|
||||
</Step>
|
||||
<Step title="Create the Access Token">
|
||||
Click the **Create access token** button and provide a name for your token (e.g., "Infisical Integration"). You may set an expiration date or leave it blank for no expiry.
|
||||
The permission scope can either be **Same as current user** or **Limit per project**.
|
||||
|
||||
If you're choosing **Limit per project**, make sure you select the relevant project and enable the permissions relevant to your use case:
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Secret Sync Permissions">
|
||||
- View build configuration settings
|
||||
- Edit project
|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||

|
||||
|
||||
<Note>
|
||||
Setting your permission scope to **Same as current user** will allow your integration to access multiple projects as long as the current user has read and write access to them.
|
||||
</Note>
|
||||
<Note>
|
||||
If you configure an expiry date for your access token, you must manually rotate to a new token before the expiration date to prevent service interruption.
|
||||
</Note>
|
||||
</Step>
|
||||
<Step title="Copy the Access Token">
|
||||
After creation, a modal with the Access Token will be displayed. Copy this token immediately and store it securely, as you won't be able to view it again after closing this dialog.
|
||||

|
||||
</Step>
|
||||
<Step title="Token Created">
|
||||
You should now see your newly created token in the list of access tokens.
|
||||

|
||||
</Step>
|
||||
<Step title="Setup TeamCity Connection in Infisical">
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
1. Navigate to App Connections
|
||||
|
||||
In your Infisical dashboard, go to **Organization Settings** and select the [**App Connections**](https://app.infisical.com/organization/app-connections) tab.
|
||||

|
||||
2. Add Connection
|
||||
|
||||
Click the **+ Add Connection** button and select the **TeamCity Connection** option from the available integrations.
|
||||

|
||||
3. Fill the TeamCity Connection Modal
|
||||
|
||||
Complete the TeamCity Connection form by entering:
|
||||
- A descriptive name for the connection
|
||||
- The Access Token you generated in steps 3-4
|
||||
- The URL of your TeamCity instance
|
||||
- An optional description for future reference
|
||||
|
||||

|
||||
4. Connection Created
|
||||
|
||||
After clicking Create, your **TeamCity Connection** is established and ready to use with your Infisical projects.
|
||||

|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create a TeamCity Connection, make an API request to the [Create TeamCity
|
||||
Connection](/api-reference/endpoints/app-connections/teamcity/create) API endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/app-connections/teamcity \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-teamcity-connection",
|
||||
"method": "access-token",
|
||||
"credentials": {
|
||||
"accessToken": "...",
|
||||
"instanceUrl": "https://yourcompany.teamcity.com"
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"appConnection": {
|
||||
"id": "e5d18aca-86f7-4026-a95e-efb8aeb0d8e6",
|
||||
"name": "my-teamcity-connection",
|
||||
"description": null,
|
||||
"version": 1,
|
||||
"orgId": "6f03caa1-a5de-43ce-b127-95a145d3464c",
|
||||
"createdAt": "2025-04-23T19:46:34.831Z",
|
||||
"updatedAt": "2025-04-23T19:46:34.831Z",
|
||||
"isPlatformManagedCredentials": false,
|
||||
"credentialsHash": "7c2d371dec195f82a6a0d5b41c970a229cfcaf88e894a5b6395e2dbd0280661f",
|
||||
"app": "teamcity",
|
||||
"method": "access-token",
|
||||
"credentials": {
|
||||
"instanceUrl": "https://yourcompany.teamcity.com"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
</Steps>
|
||||
@@ -3,43 +3,6 @@ title: "TeamCity"
|
||||
description: "How to sync secrets from Infisical to TeamCity"
|
||||
---
|
||||
|
||||
Prerequisites:
|
||||
|
||||
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
||||
|
||||
<Steps>
|
||||
<Step title="Authorize Infisical for TeamCity">
|
||||
Obtain a TeamCity Access Token in Profile > Access Tokens
|
||||
|
||||

|
||||

|
||||
|
||||
<Note>
|
||||
For this integration to work, the TeamCity Access Token must either have the
|
||||
**Same as current user** account-wide permission enabled or, if **Limit per project**
|
||||
is selected, then it must at minimum have the **View build configuration settings** and **Edit project** permissions enabled.
|
||||
</Note>
|
||||
|
||||
Navigate to your project's integrations tab in Infisical.
|
||||
|
||||

|
||||
|
||||
Press on the TeamCity tile and input your TeamCity Access Token and Server URL to grant Infisical access to your TeamCity account.
|
||||
|
||||

|
||||
|
||||
</Step>
|
||||
<Step title="Start integration">
|
||||
Select which Infisical environment secrets you want to sync to which TeamCity project (and optionally build configuration) and press create integration to start syncing secrets to TeamCity.
|
||||
|
||||

|
||||
|
||||
<Note>
|
||||
Infisical integrates with both TeamCity's project-level and build configuration-level environment variables.
|
||||
|
||||
To sync secrets to a specific build configuration in a TeamCity project, you can select a build configuration from the **TeamCity Build Config** dropdown; otherwise, leaving it empty will sync secrets to TeamCity at the project-level.
|
||||
</Note>
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
<Note>
|
||||
The TeamCity Native Integration will be deprecated in 2026. Please migrate to our new [TeamCity Sync](../secret-syncs/teamcity).
|
||||
</Note>
|
||||
|
||||
@@ -3,39 +3,6 @@ title: "Windmill"
|
||||
description: "How to sync secrets from Infisical to Windmill"
|
||||
---
|
||||
|
||||
Prerequisites:
|
||||
|
||||
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
||||
|
||||
<Steps>
|
||||
<Step title="Authorize Infisical for Windmill">
|
||||
Obtain a [Windmill](https://www.windmill.dev/) access token in Access Tokens
|
||||
|
||||

|
||||

|
||||
|
||||
Navigate to your project's integrations tab in Infisical.
|
||||
|
||||

|
||||
|
||||
Press on the Windmill tile and input your Windmill access token to grant Infisical access to your Windmill account.
|
||||
|
||||

|
||||
|
||||
</Step>
|
||||
<Step title="Start integration">
|
||||
Select which Infisical environment secrets you want to sync to which Windmill workspace and press create integration to start syncing secrets to Windmill.
|
||||
|
||||

|
||||

|
||||
|
||||
<Warning>
|
||||
Secrets synced to Windmill are subject to the [ownership path
|
||||
prefix](https://www.windmill.dev/docs/core_concepts/roles_and_permissions)
|
||||
convention of Windmill. Accordingly, all secrets must be prefixed with either
|
||||
`u/` or `f/` for user-based and folder-based secret along with the name of the
|
||||
secret. Put differently, you must use the full path of the secret as its name
|
||||
in Infisical to be considered valid such as `u/user/FOO/BAR`.
|
||||
</Warning>
|
||||
</Step>
|
||||
</Steps>
|
||||
<Note>
|
||||
The Windmill Native Integration will be deprecated in 2026. Please migrate to our new [Windmill Sync](../secret-syncs/windmill).
|
||||
</Note>
|
||||
|
||||
@@ -0,0 +1,147 @@
|
||||
---
|
||||
title: "TeamCity Sync"
|
||||
description: "Learn how to configure a TeamCity Sync for Infisical."
|
||||
---
|
||||
|
||||
**Prerequisites:**
|
||||
|
||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||
- Create a [TeamCity Connection](/integrations/app-connections/teamcity) with the required **Secret Sync** permissions
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
1. Navigate to **Project** > **Integrations** and select the **Secret Syncs** tab. Click on the **Add Sync** button.
|
||||

|
||||
|
||||
2. Select the **TeamCity** option.
|
||||

|
||||
|
||||
3. Configure the **Source** from where secrets should be retrieved, then click **Next**.
|
||||

|
||||
|
||||
- **Environment**: The project environment to retrieve secrets from.
|
||||
- **Secret Path**: The folder path to retrieve secrets from.
|
||||
|
||||
<Tip>
|
||||
If you need to sync secrets from multiple folder locations, check out [secret imports](/documentation/platform/secret-reference#secret-imports).
|
||||
</Tip>
|
||||
|
||||
4. Configure the **Destination** to where secrets should be deployed, then click **Next**.
|
||||

|
||||
|
||||
- **TeamCity Connection**: The TeamCity Connection to authenticate with.
|
||||
- **Project**: The TeamCity project to sync secrets to.
|
||||
- **Build Configuration**: The build configuration to sync secrets to.
|
||||
|
||||
<Note>
|
||||
Not including a Build Configuration will sync secrets to the entire project.
|
||||
</Note>
|
||||
|
||||
5. Configure the **Sync Options** to specify how secrets should be synced, then click **Next**.
|
||||

|
||||
|
||||
- **Initial Sync Behavior**: Determines how Infisical should resolve the initial sync.
|
||||
- **Overwrite Destination Secrets**: Removes any secrets at the destination endpoint not present in Infisical.
|
||||
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over TeamCity when keys conflict.
|
||||
- **Import Secrets (Prioritize TeamCity)**: Imports secrets from the destination endpoint before syncing, prioritizing values from TeamCity over Infisical when keys conflict.
|
||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||
|
||||
6. Configure the **Details** of your TeamCity Sync, then click **Next**.
|
||||

|
||||
|
||||
- **Name**: The name of your sync. Must be slug-friendly.
|
||||
- **Description**: An optional description for your sync.
|
||||
|
||||
7. Review your TeamCity Sync configuration, then click **Create Sync**.
|
||||

|
||||
|
||||
8. If enabled, your TeamCity Sync will begin syncing your secrets to the destination endpoint.
|
||||

|
||||
|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create a **TeamCity Sync**, make an API request to the [Create TeamCity Sync](/api-reference/endpoints/secret-syncs/teamcity/create) API endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/secret-syncs/teamcity \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-teamcity-sync",
|
||||
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"description": "an example sync",
|
||||
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"environment": "dev",
|
||||
"secretPath": "/my-secrets",
|
||||
"isEnabled": true,
|
||||
"syncOptions": {
|
||||
"initialSyncBehavior": "overwrite-destination"
|
||||
},
|
||||
"destinationConfig": {
|
||||
"project": "TestProject",
|
||||
"buildConfig": "TestBuildConfig"
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
<Note>
|
||||
The **Project** and **Build Config** parameters must use project and build configuration IDs, not their names.
|
||||
</Note>
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"secretSync": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"name": "my-teamcity-sync",
|
||||
"description": "an example sync",
|
||||
"isEnabled": true,
|
||||
"version": 1,
|
||||
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"createdAt": "2023-11-07T05:31:56Z",
|
||||
"updatedAt": "2023-11-07T05:31:56Z",
|
||||
"syncStatus": "succeeded",
|
||||
"lastSyncJobId": "123",
|
||||
"lastSyncMessage": null,
|
||||
"lastSyncedAt": "2023-11-07T05:31:56Z",
|
||||
"importStatus": null,
|
||||
"lastImportJobId": null,
|
||||
"lastImportMessage": null,
|
||||
"lastImportedAt": null,
|
||||
"removeStatus": null,
|
||||
"lastRemoveJobId": null,
|
||||
"lastRemoveMessage": null,
|
||||
"lastRemovedAt": null,
|
||||
"syncOptions": {
|
||||
"initialSyncBehavior": "overwrite-destination"
|
||||
},
|
||||
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"connection": {
|
||||
"app": "teamcity",
|
||||
"name": "my-teamcity-connection",
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||
},
|
||||
"environment": {
|
||||
"slug": "dev",
|
||||
"name": "Development",
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||
},
|
||||
"folder": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"path": "/my-secrets"
|
||||
},
|
||||
"destination": "teamcity",
|
||||
"destinationConfig": {
|
||||
"project": "TestProject",
|
||||
"buildConfig": "TestBuildConfig"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
@@ -179,6 +179,7 @@
|
||||
"pages": [
|
||||
"documentation/platform/secret-rotation/overview",
|
||||
"documentation/platform/secret-rotation/auth0-client-secret",
|
||||
"documentation/platform/secret-rotation/aws-iam-user-secret",
|
||||
"documentation/platform/secret-rotation/ldap-password",
|
||||
"documentation/platform/secret-rotation/mssql-credentials",
|
||||
"documentation/platform/secret-rotation/postgres-credentials"
|
||||
@@ -314,6 +315,13 @@
|
||||
"self-hosting/deployment-options/kubernetes-helm"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Linux Package",
|
||||
"pages": [
|
||||
"self-hosting/deployment-options/native/linux-package/installation",
|
||||
"self-hosting/deployment-options/native/linux-package/commands-configuration"
|
||||
]
|
||||
},
|
||||
"self-hosting/guides/upgrading-infisical",
|
||||
"self-hosting/configuration/envars",
|
||||
"self-hosting/configuration/requirements",
|
||||
@@ -330,7 +338,8 @@
|
||||
"pages": [
|
||||
"self-hosting/reference-architectures/aws-ecs",
|
||||
"self-hosting/reference-architectures/linux-deployment-ha",
|
||||
"self-hosting/reference-architectures/on-prem-k8s-ha"
|
||||
"self-hosting/reference-architectures/on-prem-k8s-ha",
|
||||
"self-hosting/reference-architectures/google-cloud-run"
|
||||
]
|
||||
},
|
||||
"self-hosting/ee",
|
||||
@@ -428,6 +437,7 @@
|
||||
"integrations/app-connections/ldap",
|
||||
"integrations/app-connections/mssql",
|
||||
"integrations/app-connections/postgres",
|
||||
"integrations/app-connections/teamcity",
|
||||
"integrations/app-connections/terraform-cloud",
|
||||
"integrations/app-connections/vercel",
|
||||
"integrations/app-connections/windmill"
|
||||
@@ -451,6 +461,7 @@
|
||||
"integrations/secret-syncs/gcp-secret-manager",
|
||||
"integrations/secret-syncs/github",
|
||||
"integrations/secret-syncs/humanitec",
|
||||
"integrations/secret-syncs/teamcity",
|
||||
"integrations/secret-syncs/terraform-cloud",
|
||||
"integrations/secret-syncs/vercel",
|
||||
"integrations/secret-syncs/windmill"
|
||||
@@ -560,9 +571,7 @@
|
||||
},
|
||||
{
|
||||
"group": "Others",
|
||||
"pages": [
|
||||
"integrations/external/backstage"
|
||||
]
|
||||
"pages": ["integrations/external/backstage"]
|
||||
},
|
||||
{
|
||||
"group": "",
|
||||
@@ -864,8 +873,21 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "LDAP Password",
|
||||
"group": "AWS IAM User Secret",
|
||||
"pages": [
|
||||
"api-reference/endpoints/secret-rotations/aws-iam-user-secret/create",
|
||||
"api-reference/endpoints/secret-rotations/aws-iam-user-secret/delete",
|
||||
"api-reference/endpoints/secret-rotations/aws-iam-user-secret/get-by-id",
|
||||
"api-reference/endpoints/secret-rotations/aws-iam-user-secret/get-by-name",
|
||||
"api-reference/endpoints/secret-rotations/aws-iam-user-secret/get-generated-credentials-by-id",
|
||||
"api-reference/endpoints/secret-rotations/aws-iam-user-secret/list",
|
||||
"api-reference/endpoints/secret-rotations/aws-iam-user-secret/rotate-secrets",
|
||||
"api-reference/endpoints/secret-rotations/aws-iam-user-secret/update"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "LDAP Password",
|
||||
"pages": [
|
||||
"api-reference/endpoints/secret-rotations/ldap-password/create",
|
||||
"api-reference/endpoints/secret-rotations/ldap-password/delete",
|
||||
"api-reference/endpoints/secret-rotations/ldap-password/get-by-id",
|
||||
@@ -1064,6 +1086,18 @@
|
||||
"api-reference/endpoints/app-connections/postgres/delete"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "TeamCity",
|
||||
"pages": [
|
||||
"api-reference/endpoints/app-connections/teamcity/list",
|
||||
"api-reference/endpoints/app-connections/teamcity/available",
|
||||
"api-reference/endpoints/app-connections/teamcity/get-by-id",
|
||||
"api-reference/endpoints/app-connections/teamcity/get-by-name",
|
||||
"api-reference/endpoints/app-connections/teamcity/create",
|
||||
"api-reference/endpoints/app-connections/teamcity/update",
|
||||
"api-reference/endpoints/app-connections/teamcity/delete"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Terraform Cloud",
|
||||
"pages": [
|
||||
@@ -1229,6 +1263,20 @@
|
||||
"api-reference/endpoints/secret-syncs/humanitec/remove-secrets"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "TeamCity",
|
||||
"pages": [
|
||||
"api-reference/endpoints/secret-syncs/teamcity/list",
|
||||
"api-reference/endpoints/secret-syncs/teamcity/get-by-id",
|
||||
"api-reference/endpoints/secret-syncs/teamcity/get-by-name",
|
||||
"api-reference/endpoints/secret-syncs/teamcity/create",
|
||||
"api-reference/endpoints/secret-syncs/teamcity/update",
|
||||
"api-reference/endpoints/secret-syncs/teamcity/delete",
|
||||
"api-reference/endpoints/secret-syncs/teamcity/sync-secrets",
|
||||
"api-reference/endpoints/secret-syncs/teamcity/import-secrets",
|
||||
"api-reference/endpoints/secret-syncs/teamcity/remove-secrets"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Terraform Cloud",
|
||||
"pages": [
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
---
|
||||
title: "Configurations"
|
||||
description: "Learn how to configure and manage the Infisical Linux package"
|
||||
---
|
||||
|
||||
## Configuration Overview
|
||||
|
||||
All configuration for the Infisical Linux package is managed through a single file called `infisical.rb`, located in the `/etc/infisical` directory.
|
||||
This file defines all necessary settings, including encryption keys, database connections, and environment-specific settings.
|
||||
|
||||
<Info> After making any changes to the `infisical.rb` file, always run `infisical-ctl reconfigure` to apply them. </Info>
|
||||
|
||||
### Example Configuration
|
||||
|
||||
```ruby infisical.rb
|
||||
# Important: Replace these values with secure keys in production
|
||||
infisical_core['ENCRYPTION_KEY'] = '6c1fe4e407b8911c104518103505b218'
|
||||
infisical_core['AUTH_SECRET'] = '5lrMXKKWCVocS/uerPsl7V+TX/aaUaI7iDkgl3tSmLE='
|
||||
|
||||
# Database connection strings
|
||||
infisical_core['DB_CONNECTION_URI'] = 'postgres://<username>:<password>@<host>:5432/<database>'
|
||||
infisical_core['REDIS_URL'] = 'redis://<host>:6379'
|
||||
```
|
||||
|
||||
For a full list of supported configuration variables, refer to the [configuration variables documentation](/self-hosting/configuration/envars).
|
||||
|
||||
## All `infisical-ctl` Commands
|
||||
|
||||
The Infisical Linux package includes the `infisical-ctl` command-line tool, which allows you to manage your deployment.
|
||||
The available commands are listed below.
|
||||
|
||||
| Command | Description |
|
||||
|-----------------------------|-----------------------------------------------------------------------------|
|
||||
| `infisical-ctl reconfigure` | Applies changes from `infisical.rb` and restarts the Infisical services. |
|
||||
| `infisical-ctl start` | Starts the Infisical services. |
|
||||
| `infisical-ctl stop` | Stops all running Infisical services. |
|
||||
| `infisical-ctl status` | Displays the current status of the Infisical services. |
|
||||
| `infisical-ctl tail` | Streams real-time logs from the Infisical application. |
|
||||
@@ -0,0 +1,122 @@
|
||||
---
|
||||
title: "Installation"
|
||||
description: "Learn how to deploy Infisical using the Linux package"
|
||||
---
|
||||
|
||||
Infisical can be deployed on Linux virtual machines without the need for containers using our standalone Linux packages.
|
||||
These packages are available in both .deb (for Debian-based systems) and .rpm (for RHEL-based systems) formats.
|
||||
The installation includes the Infisical service, along with a CLI tool (infisical-ctl) to help you manage configurations, startup, and application logging.
|
||||
This approach is ideal for environments where containerization isn't desired, while still providing a lightweight deployment option.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
This installation method only provides the Infisical application. You are responsible for configuring both PostgreSQL and Redis, either by using managed services (e.g., AWS RDS, Azure Database, GCP Cloud SQL/Memorystore) or by deploying them manually in your on-prem environment.
|
||||
Please ensure you have the following before beginning installation of Infisical:
|
||||
|
||||
- A Linux server running a Debian/Ubuntu or RHEL-based distribution
|
||||
- A running PostgreSQL database instance (version 14 and up)
|
||||
- A running Redis database instance (versions 6.x or 7.x)
|
||||
|
||||
## Installation Steps
|
||||
|
||||
<Steps>
|
||||
|
||||
<Step title="Install the Infisical Package">
|
||||
Select your Linux distribution to get started. Only AMD64-based systems are supported at this time, ARM support is coming soon.
|
||||
|
||||
<Tabs>
|
||||
|
||||
<Tab title="Debian/Ubuntu">
|
||||
Add the Infisical repository:
|
||||
```bash
|
||||
curl -1sLf 'https://dl.cloudsmith.io/public/infisical/infisical-core/setup.deb.sh' | sudo -E bash
|
||||
```
|
||||
|
||||
Install Infisical:
|
||||
```bash
|
||||
sudo apt-get update && sudo apt-get install -y infisical-core
|
||||
```
|
||||
|
||||
> **Note**: For production use, we recommend locking to a specific version to ensure consistency. [View available versions](https://cloudsmith.io/~infisical/repos/infisical-core/packages/).
|
||||
</Tab>
|
||||
|
||||
<Tab title="RedHat/CentOS/Amazon Linux">
|
||||
Add the Infisical repository:
|
||||
```bash
|
||||
curl -1sLf 'https://dl.cloudsmith.io/public/infisical/infisical-core/setup.rpm.sh' | sudo -E bash
|
||||
```
|
||||
|
||||
Install Infisical:
|
||||
```bash
|
||||
sudo yum install infisical-core
|
||||
```
|
||||
|
||||
> **Note**: For production use, we recommend locking to a specific version to ensure consistency. [View available versions](https://cloudsmith.io/~infisical/repos/infisical-core/packages/).
|
||||
</Tab>
|
||||
|
||||
</Tabs>
|
||||
|
||||
Verify the installation:
|
||||
```bash
|
||||
infisical-ctl help
|
||||
```
|
||||
</Step>
|
||||
|
||||
<Step title="Create the Configuration File">
|
||||
Create an `infisical.rb` file at `/etc/infisical`. This file contains your database connection strings and other runtime settings.
|
||||
|
||||
```ruby
|
||||
# Important: Replace with secure values in production
|
||||
infisical_core['ENCRYPTION_KEY'] = '6c1fe4e407b8911c104518103505b218'
|
||||
infisical_core['AUTH_SECRET'] = '5lrMXKKWCVocS/uerPsl7V+TX/aaUaI7iDkgl3tSmLE='
|
||||
|
||||
# Example database connection strings
|
||||
infisical_core['DB_CONNECTION_URI'] = 'postgres://<db-username>:<db-password>@<db-host>:<db-port>/<db-name>'
|
||||
infisical_core['REDIS_URL'] = 'redis://<redis-host>:<redis-port>'
|
||||
```
|
||||
|
||||
See the full list of options in our [configuration documentation](/self-hosting/configuration/envars).
|
||||
</Step>
|
||||
|
||||
<Step title="Start Infisical">
|
||||
1. Start the Infisical service:
|
||||
```bash
|
||||
infisical-ctl reconfigure
|
||||
```
|
||||
The server runs on port `8080` by default (customizable in `infisical.rb`).
|
||||
|
||||
2. Check the service status:
|
||||
```bash
|
||||
infisical-ctl status
|
||||
```
|
||||
|
||||
View the service logs in real-time:
|
||||
```bash
|
||||
infisical-ctl tail
|
||||
```
|
||||
</Step>
|
||||
|
||||
</Steps>
|
||||
|
||||
## Platform Support
|
||||
|
||||
### Microsoft Windows
|
||||
Infisical is built for Linux-based systems. It is not supported on Microsoft Windows, and we do not plan to support it in the near future. For Windows users, consider running Infisical in a virtual machine or WSL2 environment.
|
||||
|
||||
### Unsupported Linux Distributions and Unix-like Systems
|
||||
Infisical is not tested or officially supported on the following:
|
||||
|
||||
- Arch Linux
|
||||
- Fedora
|
||||
- FreeBSD
|
||||
- Gentoo
|
||||
- macOS
|
||||
|
||||
We recommend sticking to officially supported distributions for the best experience.
|
||||
|
||||
## Linux vs Containerized Deployments
|
||||
|
||||
Infisical is a stateless application, which means it can be easily scaled and redeployed without maintaining internal state between instances.
|
||||
|
||||
If your use case requires rolling updates, self-healing, or auto-scaling, we recommend deploying Infisical in a containerized environment such as Kubernetes/OpenShift, or using managed container orchestration services like AWS ECS or Google Cloud Run.
|
||||
These platforms offer built-in capabilities for high availability and help simplify operational overhead for your deployment.
|
||||
@@ -33,21 +33,10 @@ Choose from a number of deployment options listed below to get started.
|
||||
Use our Helm chart to Install Infisical on your Kubernetes cluster.
|
||||
</Card>
|
||||
</CardGroup>
|
||||
{/* <CardGroup cols={2}>
|
||||
<Card
|
||||
title="Native Deployment"
|
||||
<Card
|
||||
title="Linux package"
|
||||
color="#000000"
|
||||
icon="box"
|
||||
href="deployment-options/native/standalone-binary"
|
||||
href="deployment-options/native/linux-package/installation"
|
||||
>
|
||||
Install Infisical on your Debian-based system without containers using our standalone binary.
|
||||
</Card>
|
||||
<Card
|
||||
title="Native Deployment, High Availability"
|
||||
color="#000000"
|
||||
icon="boxes-stacked"
|
||||
href="deployment-options/native/high-availability"
|
||||
>
|
||||
Install Infisical on your Debian-based instances without containers using our standalone binary with high availability out of the box.
|
||||
</Card>
|
||||
</CardGroup> */}
|
||||
Install Infisical on your system without containers using our Linux package.
|
||||
</Card>
|
||||
|
||||
@@ -0,0 +1,114 @@
|
||||
---
|
||||
title: "Google Cloud Run"
|
||||
description: "Reference architecture for self-hosting Infisical on Google Cloud Run."
|
||||
---
|
||||
|
||||
## Overview
|
||||
This guide outlines a reference architecture for deploying Infisical in a self-hosted configuration using Google Cloud Run.
|
||||
It is intended to provide a scalable, secure, and production-ready baseline for organizations choosing Google Cloud Platform (GCP) as their infrastructure provider.
|
||||
|
||||
## Core Components
|
||||
|
||||
- **Cloud Run:** Infisical service is containerized and deployed as fully managed Cloud Run services.
|
||||
|
||||
- **Cloud SQL:** Infisical uses Postgres as its persistence layer. As such, Cloud SQL for PostgreSQL is used.
|
||||
|
||||
- **MemoryStore for Redis:** To schedule jobs, process audit logs and cache performance, Infisical requires Redis.
|
||||
|
||||
## Securing Infisical's root credential
|
||||
|
||||
- **Secrets Manager:** To secure Infisical’s root credentials (database connection string, encryption key, etc.),
|
||||
we highly recommend that you use Google Secrets Manager and only allow the tasks running Infisical to access them.
|
||||
|
||||
## High Availability and Scalability
|
||||
|
||||
This architecture leverages Google Cloud's managed services to achieve high availability and scalability out of the box:
|
||||
|
||||
**Cloud Run:**
|
||||
|
||||
- Automatically scales the number of container instances up or down based on incoming request volume.
|
||||
- Supports rapid scaling during traffic spikes, ensuring low latency.
|
||||
- Configurable minimum and maximum instances to handle baseline and peak loads.
|
||||
|
||||
**Cloud SQL:**
|
||||
|
||||
- Provides high availability configurations (regional instances with automatic failover) to ensure database uptime.
|
||||
- Automated backups, point-in-time recovery, and maintenance.
|
||||
|
||||
**MemoryStore:**
|
||||
|
||||
- Offers highly available Redis configurations with replication.
|
||||
- Fully managed with automatic scaling and patching.
|
||||
|
||||
**Cloud Load Balancer:**
|
||||
|
||||
- Distributes user traffic across available Cloud Run instances.
|
||||
- Provides SSL termination, global load balancing, and health checks.
|
||||
|
||||
<Info>
|
||||
**Note:** To further improve performance and availability, consider enabling multi-region deployment strategies,
|
||||
regional VPC Connectors, and database replicas for read-heavy workloads.
|
||||
</Info>
|
||||
|
||||
## Configuration
|
||||
|
||||
<Steps>
|
||||
<Step title="Provision Core Infrastructure">
|
||||
**Cloud SQL (PostgreSQL):**
|
||||
- Create a Cloud SQL instance.
|
||||
- Under `Zonal availability`, select the `Multiple zones` option to ensure High Availability.
|
||||
- Configure private IP access.
|
||||
|
||||
**MemoryStore (Redis):**
|
||||
- Deploy a Redis instance.
|
||||
- Configure VPC access.
|
||||
|
||||
</Step>
|
||||
<Step title="Get the Infisical Docker image">
|
||||
Visit [Docker Hub](https://hub.docker.com/r/infisical/infisical/tags) and select a version of Infisical image you would like to deploy.
|
||||
Then, within Cloud Run, paste the URL of the specific Infisical Docker image you would like to use within the `Container image URL` field.
|
||||
|
||||

|
||||
|
||||
Remember to replace `<version>` with the docker image tag of your choice.
|
||||
</Step>
|
||||
<Step title="Set the environment variables">
|
||||
For a minimal installation of Infisical, you must configure the following environment variables:
|
||||
|
||||
```bash
|
||||
ENCRYPTION_KEY=<your_encryption_key>
|
||||
AUTH_SECRET=<your_auth_secret>
|
||||
DB_CONNECTION_URI="<your_db_connection_uri>"
|
||||
SITE_URL="<your_site_url>"
|
||||
REDIS_URL="<your_redis_url>"
|
||||
```
|
||||
[View all available configurations](/self-hosting/configuration/envars).
|
||||
|
||||
You will want to setup Postgres and Redis within Google Cloud Platform to connect to Infisical.
|
||||
|
||||
Once you have added the required environment variables to the `Environment Variables` section within Cloud Run,
|
||||
create the container to get Infisical up and running.
|
||||
|
||||

|
||||
|
||||
<Warning>
|
||||
The above environment variable values are only to be used as an example and should not be used in production
|
||||
</Warning>
|
||||
|
||||
</Step>
|
||||
<Step title="Network Configuration">
|
||||
|
||||
Enable `Connect to a VPC for outbound traffic`: This enables the service to talk to private resources (e.g., a Cloud SQL database, Redis instance on a private IP) inside your Google Cloud VPC network.
|
||||
|
||||
Select `Send traffic directly to a VPC`: It gives lower latency and better performance, but uses more IPs from the subnet.
|
||||
|
||||
<Info>
|
||||
Your Cloud Run revision must be in the same VPC network
|
||||
</Info>
|
||||
|
||||

|
||||
|
||||
Once the container is running, verify the installation by opening your web browser and navigating to the Site URL.
|
||||
|
||||
</Step>
|
||||
</Steps>
|
||||