mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 21:27:31 +00:00
feat: doc for assume aws iam
This commit is contained in:
@@ -50,110 +50,261 @@ Replace **\<account id\>** with your AWS account id and **\<aws-scope-path\>** w
|
|||||||
|
|
||||||
## Set up Dynamic Secrets with AWS IAM
|
## Set up Dynamic Secrets with AWS IAM
|
||||||
|
|
||||||
<Steps>
|
<Tabs>
|
||||||
<Step title="Secret Overview Dashboard">
|
<Tab title="Assume Role (Recommended)">
|
||||||
Navigate to the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret to.
|
Infisical will assume the provided role in your AWS account securely, without the need to share any credentials.
|
||||||
</Step>
|
<Accordion title="Self-Hosted Instance">
|
||||||
<Step title="Click on the 'Add Dynamic Secret' button">
|
To connect your self-hosted Infisical instance with AWS, you need to set up an AWS IAM User account that can assume the configured AWS IAM Role.
|
||||||

|
|
||||||
</Step>
|
|
||||||
<Step title="Select AWS IAM">
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
<Step title="Provide the inputs for dynamic secret parameters">
|
|
||||||
<ParamField path="Secret Name" type="string" required>
|
|
||||||
Name by which you want the secret to be referenced
|
|
||||||
</ParamField>
|
|
||||||
|
|
||||||
<ParamField path="Default TTL" type="string" required>
|
If your instance is deployed on AWS, the aws-sdk will automatically retrieve the credentials. Ensure that you assign the provided permission policy to your deployed instance, such as ECS or EC2.
|
||||||
Default time-to-live for a generated secret (it is possible to modify this value after a secret is generated)
|
|
||||||
</ParamField>
|
|
||||||
|
|
||||||
<ParamField path="Max TTL" type="string" required>
|
The following steps are for instances not deployed on AWS:
|
||||||
Maximum time-to-live for a generated secret
|
<Steps>
|
||||||
</ParamField>
|
<Step title="Create an IAM User">
|
||||||
|
Navigate to [Create IAM User](https://console.aws.amazon.com/iamv2/home#/users/create) in your AWS Console.
|
||||||
|
</Step>
|
||||||
|
<Step title="Create an Inline Policy">
|
||||||
|
Attach the following inline permission policy to the IAM User to allow it to assume any IAM Roles:
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"Version": "2012-10-17",
|
||||||
|
"Statement": [
|
||||||
|
{
|
||||||
|
"Sid": "AllowAssumeAnyRole",
|
||||||
|
"Effect": "Allow",
|
||||||
|
"Action": "sts:AssumeRole",
|
||||||
|
"Resource": "arn:aws:iam::*:role/*"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
```
|
||||||
|
</Step>
|
||||||
|
<Step title="Obtain the IAM User Credentials">
|
||||||
|
Obtain the AWS access key ID and secret access key for your IAM User by navigating to **IAM > Users > [Your User] > Security credentials > Access keys**.
|
||||||
|
|
||||||
<ParamField path="AWS Access Key" type="string" required>
|

|
||||||
The managing AWS IAM User Access Key
|

|
||||||
</ParamField>
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Set Up Connection Keys">
|
||||||
|
1. Set the access key as **DYNAMIC_SECRET_AWS_ACCESS_KEY_ID**.
|
||||||
|
2. Set the secret key as **DYNAMIC_SECRET_AWS_SECRET_ACCESS_KEY**.
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
<ParamField path="AWS Secret Key" type="string" required>
|
<Steps>
|
||||||
The managing AWS IAM User Secret Key
|
<Step title="Secret Overview Dashboard">
|
||||||
</ParamField>
|
Navigate to the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret to.
|
||||||
|
</Step>
|
||||||
|
<Step title="Click on the 'Add Dynamic Secret' button">
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Select AWS IAM">
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Provide the inputs for dynamic secret parameters">
|
||||||
|

|
||||||
|
<ParamField path="Secret Name" type="string" required>
|
||||||
|
Name by which you want the secret to be referenced
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
<ParamField path="AWS IAM Path" type="string">
|
<ParamField path="Default TTL" type="string" required>
|
||||||
[IAM AWS Path](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/) to scope created IAM User resource access.
|
Default time-to-live for a generated secret (it is possible to modify this value after a secret is generated)
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField path="AWS Region" type="string" required>
|
<ParamField path="Max TTL" type="string" required>
|
||||||
The AWS data center region.
|
Maximum time-to-live for a generated secret
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField path="IAM User Permission Boundary" type="string" required>
|
<ParamField path="Method" type="string" required>
|
||||||
The IAM Policy ARN of the [AWS Permissions Boundary](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html) to attach to IAM users created in the role.
|
Select *Assume Role* method.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField path="AWS IAM Groups" type="string">
|
<ParamField path="Aws Role ARN" type="string" required>
|
||||||
The AWS IAM groups that should be assigned to the created users. Multiple values can be provided by separating them with commas
|
The ARN of the AWS Role to assume.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField path="AWS Policy ARNs" type="string">
|
<ParamField path="AWS IAM Path" type="string">
|
||||||
The AWS IAM managed policies that should be attached to the created users. Multiple values can be provided by separating them with commas
|
[IAM AWS Path](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/) to scope created IAM User resource access.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField path="AWS IAM Policy Document" type="string">
|
<ParamField path="AWS Region" type="string" required>
|
||||||
The AWS IAM inline policy that should be attached to the created users. Multiple values can be provided by separating them with commas
|
The AWS data center region.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField path="Username Template" type="string" default="{{randomUsername}}">
|
<ParamField path="IAM User Permission Boundary" type="string" required>
|
||||||
Specifies a template for generating usernames. This field allows customization of how usernames are automatically created.
|
The IAM Policy ARN of the [AWS Permissions Boundary](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html) to attach to IAM users created in the role.
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
Allowed template variables are
|
<ParamField path="AWS IAM Groups" type="string">
|
||||||
- `{{randomUsername}}`: Random username string
|
The AWS IAM groups that should be assigned to the created users. Multiple values can be provided by separating them with commas
|
||||||
- `{{unixTimestamp}}`: Current Unix timestamp
|
</ParamField>
|
||||||
</ParamField>
|
|
||||||
|
|
||||||

|
<ParamField path="AWS Policy ARNs" type="string">
|
||||||
|
The AWS IAM managed policies that should be attached to the created users. Multiple values can be provided by separating them with commas
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
</Step>
|
<ParamField path="AWS IAM Policy Document" type="string">
|
||||||
<Step title="Click 'Submit'">
|
The AWS IAM inline policy that should be attached to the created users.
|
||||||
After submitting the form, you will see a dynamic secret created in the dashboard.
|
Multiple values can be provided by separating them with commas
|
||||||
|
</ParamField>
|
||||||
|
|
||||||

|
<ParamField path="Username Template" type="string" default="{{randomUsername}}">
|
||||||
</Step>
|
Specifies a template for generating usernames. This field allows customization of how usernames are automatically created.
|
||||||
<Step title="Generate dynamic secrets">
|
|
||||||
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
|
|
||||||
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
|
|
||||||
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
|
|
||||||
|
|
||||||

|
Allowed template variables are
|
||||||

|
|
||||||
|
|
||||||
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
|
- `{{randomUsername}}`: Random username string
|
||||||
|
- `{{unixTimestamp}}`: Current Unix timestamp
|
||||||
|
</ParamField>
|
||||||
|
</Step>
|
||||||
|
|
||||||

|
<Step title="Click 'Submit'">
|
||||||
|
After submitting the form, you will see a dynamic secret created in the dashboard.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
|
||||||
<Tip>
|
<Step title="Generate dynamic secrets">
|
||||||
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret in step 4.
|
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
|
||||||
</Tip>
|
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
|
||||||
|
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
|
||||||
|
|
||||||
|

|
||||||
|

|
||||||
|
|
||||||
Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you.
|
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
|
||||||
|
|
||||||

|

|
||||||
</Step>
|
|
||||||
</Steps>
|
<Tip>
|
||||||
|
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret in step 4.
|
||||||
|
</Tip>
|
||||||
|
|
||||||
|
Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
<Tab title="Access Key">
|
||||||
|
Infisical will use the provided **Access Key ID** and **Secret Key** to connect to your AWS instance.
|
||||||
|
<Steps>
|
||||||
|
<Step title="Secret Overview Dashboard">
|
||||||
|
Navigate to the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret to.
|
||||||
|
</Step>
|
||||||
|
<Step title="Click on the 'Add Dynamic Secret' button">
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Select AWS IAM">
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Provide the inputs for dynamic secret parameters">
|
||||||
|

|
||||||
|
<ParamField path="Secret Name" type="string" required>
|
||||||
|
Name by which you want the secret to be referenced
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="Default TTL" type="string" required>
|
||||||
|
Default time-to-live for a generated secret (it is possible to modify this value after a secret is generated)
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="Max TTL" type="string" required>
|
||||||
|
Maximum time-to-live for a generated secret
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="Method" type="string" required>
|
||||||
|
Select *Access Key* method.
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="AWS Access Key" type="string" required>
|
||||||
|
The managing AWS IAM User Access Key
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="AWS Secret Key" type="string" required>
|
||||||
|
The managing AWS IAM User Secret Key
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="AWS IAM Path" type="string">
|
||||||
|
[IAM AWS Path](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/) to scope created IAM User resource access.
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="AWS Region" type="string" required>
|
||||||
|
The AWS data center region.
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="IAM User Permission Boundary" type="string" required>
|
||||||
|
The IAM Policy ARN of the [AWS Permissions Boundary](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html) to attach to IAM users created in the role.
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="AWS IAM Groups" type="string">
|
||||||
|
The AWS IAM groups that should be assigned to the created users. Multiple values can be provided by separating them with commas
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="AWS Policy ARNs" type="string">
|
||||||
|
The AWS IAM managed policies that should be attached to the created users. Multiple values can be provided by separating them with commas
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="AWS IAM Policy Document" type="string">
|
||||||
|
The AWS IAM inline policy that should be attached to the created users.
|
||||||
|
Multiple values can be provided by separating them with commas
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField path="Username Template" type="string" default="{{randomUsername}}">
|
||||||
|
Specifies a template for generating usernames. This field allows customization of how usernames are automatically created.
|
||||||
|
|
||||||
|
Allowed template variables are
|
||||||
|
|
||||||
|
- `{{randomUsername}}`: Random username string
|
||||||
|
- `{{unixTimestamp}}`: Current Unix timestamp
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
|
</Step>
|
||||||
|
|
||||||
|
<Step title="Click 'Submit'">
|
||||||
|
After submitting the form, you will see a dynamic secret created in the dashboard.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
|
||||||
|
<Step title="Generate dynamic secrets">
|
||||||
|
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
|
||||||
|
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
|
||||||
|
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
|
||||||
|
|
||||||
|

|
||||||
|

|
||||||
|
|
||||||
|
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
<Tip>
|
||||||
|
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret in step 4.
|
||||||
|
</Tip>
|
||||||
|
|
||||||
|
Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
</Tabs>
|
||||||
|
|
||||||
## Audit or Revoke Leases
|
## Audit or Revoke Leases
|
||||||
|
|
||||||
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
|
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
|
||||||
This will allow you to see the lease details and delete the lease ahead of its expiration time.
|
This will allow you to see the lease details and delete the lease ahead of its expiration time.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
## Renew Leases
|
## Renew Leases
|
||||||
|
|
||||||
To extend the life of the generated dynamic secret lease past its initial time to live, simply click on the **Renew** button as illustrated below.
|
To extend the life of the generated dynamic secret lease past its initial time to live, simply click on the **Renew** button as illustrated below.
|
||||||

|

|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Lease renewals cannot exceed the maximum TTL set when configuring the dynamic secret
|
Lease renewals cannot exceed the maximum TTL set when configuring the dynamic
|
||||||
|
secret
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|||||||
BIN
Binary file not shown.
|
After Width: | Height: | Size: 526 KiB |
BIN
Binary file not shown.
|
After Width: | Height: | Size: 526 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 532 KiB |
Reference in New Issue
Block a user