Merge branch 'main' of https://github.com/Infisical/infisical into feat/chef-data-bag-app-connection-secret-sync
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Available"
|
||||
openapi: "GET /api/v1/app-connections/northflank/available"
|
||||
---
|
||||
@@ -0,0 +1,8 @@
|
||||
---
|
||||
title: "Create"
|
||||
openapi: "POST /api/v1/app-connections/northflank"
|
||||
---
|
||||
|
||||
<Note>
|
||||
Check out the configuration docs for [Northflank Connections](/integrations/app-connections/northflank) to learn how to obtain the required credentials.
|
||||
</Note>
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Delete"
|
||||
openapi: "DELETE /api/v1/app-connections/northflank/{connectionId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by ID"
|
||||
openapi: "GET /api/v1/app-connections/northflank/{connectionId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by Name"
|
||||
openapi: "GET /api/v1/app-connections/northflank/connection-name/{connectionName}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "List"
|
||||
openapi: "GET /api/v1/app-connections/northflank"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Update"
|
||||
openapi: "PATCH /api/v1/app-connections/northflank/{connectionId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Create"
|
||||
openapi: "POST /api/v1/secret-syncs/northflank"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Delete"
|
||||
openapi: "DELETE /api/v1/secret-syncs/northflank/{syncId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by ID"
|
||||
openapi: "GET /api/v1/secret-syncs/northflank/{syncId}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Get by Name"
|
||||
openapi: "GET /api/v1/secret-syncs/northflank/sync-name/{syncName}"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Import Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/northflank/{syncId}/import-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "List"
|
||||
openapi: "GET /api/v1/secret-syncs/northflank"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Remove Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/northflank/{syncId}/remove-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Sync Secrets"
|
||||
openapi: "POST /api/v1/secret-syncs/northflank/{syncId}/sync-secrets"
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Update"
|
||||
openapi: "PATCH /api/v1/secret-syncs/northflank/{syncId}"
|
||||
---
|
||||
@@ -131,6 +131,7 @@
|
||||
"integrations/app-connections/mssql",
|
||||
"integrations/app-connections/mysql",
|
||||
"integrations/app-connections/netlify",
|
||||
"integrations/app-connections/northflank",
|
||||
"integrations/app-connections/oci",
|
||||
"integrations/app-connections/okta",
|
||||
"integrations/app-connections/oracledb",
|
||||
@@ -554,6 +555,7 @@
|
||||
"integrations/secret-syncs/humanitec",
|
||||
"integrations/secret-syncs/laravel-forge",
|
||||
"integrations/secret-syncs/netlify",
|
||||
"integrations/secret-syncs/northflank",
|
||||
"integrations/secret-syncs/oci-vault",
|
||||
"integrations/secret-syncs/railway",
|
||||
"integrations/secret-syncs/render",
|
||||
@@ -1862,6 +1864,18 @@
|
||||
"api-reference/endpoints/app-connections/netlify/delete"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Northflank",
|
||||
"pages": [
|
||||
"api-reference/endpoints/app-connections/northflank/list",
|
||||
"api-reference/endpoints/app-connections/northflank/available",
|
||||
"api-reference/endpoints/app-connections/northflank/get-by-id",
|
||||
"api-reference/endpoints/app-connections/northflank/get-by-name",
|
||||
"api-reference/endpoints/app-connections/northflank/create",
|
||||
"api-reference/endpoints/app-connections/northflank/update",
|
||||
"api-reference/endpoints/app-connections/northflank/delete"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "OCI",
|
||||
"pages": [
|
||||
@@ -2335,6 +2349,20 @@
|
||||
"api-reference/endpoints/secret-syncs/netlify/remove-secrets"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Northflank",
|
||||
"pages": [
|
||||
"api-reference/endpoints/secret-syncs/northflank/list",
|
||||
"api-reference/endpoints/secret-syncs/northflank/get-by-id",
|
||||
"api-reference/endpoints/secret-syncs/northflank/get-by-name",
|
||||
"api-reference/endpoints/secret-syncs/northflank/create",
|
||||
"api-reference/endpoints/secret-syncs/northflank/update",
|
||||
"api-reference/endpoints/secret-syncs/northflank/delete",
|
||||
"api-reference/endpoints/secret-syncs/northflank/sync-secrets",
|
||||
"api-reference/endpoints/secret-syncs/northflank/import-secrets",
|
||||
"api-reference/endpoints/secret-syncs/northflank/remove-secrets"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "OCI",
|
||||
"pages": [
|
||||
|
||||
|
After Width: | Height: | Size: 124 KiB |
|
After Width: | Height: | Size: 98 KiB |
|
After Width: | Height: | Size: 167 KiB |
BIN
docs/images/app-connections/northflank/step-1.png
Normal file
|
After Width: | Height: | Size: 254 KiB |
BIN
docs/images/app-connections/northflank/step-2.png
Normal file
|
After Width: | Height: | Size: 174 KiB |
BIN
docs/images/app-connections/northflank/step-3.png
Normal file
|
After Width: | Height: | Size: 207 KiB |
BIN
docs/images/app-connections/northflank/step-4-1.png
Normal file
|
After Width: | Height: | Size: 194 KiB |
BIN
docs/images/app-connections/northflank/step-4-2.png
Normal file
|
After Width: | Height: | Size: 178 KiB |
BIN
docs/images/app-connections/northflank/step-5.png
Normal file
|
After Width: | Height: | Size: 172 KiB |
BIN
docs/images/app-connections/northflank/step-6.png
Normal file
|
After Width: | Height: | Size: 178 KiB |
BIN
docs/images/app-connections/northflank/step-7.png
Normal file
|
After Width: | Height: | Size: 154 KiB |
BIN
docs/images/secret-syncs/northflank/configure-destination.png
Normal file
|
After Width: | Height: | Size: 129 KiB |
BIN
docs/images/secret-syncs/northflank/configure-details.png
Normal file
|
After Width: | Height: | Size: 114 KiB |
BIN
docs/images/secret-syncs/northflank/configure-source.png
Normal file
|
After Width: | Height: | Size: 107 KiB |
BIN
docs/images/secret-syncs/northflank/configure-sync-options.png
Normal file
|
After Width: | Height: | Size: 132 KiB |
BIN
docs/images/secret-syncs/northflank/review-configuration.png
Normal file
|
After Width: | Height: | Size: 131 KiB |
BIN
docs/images/secret-syncs/northflank/select-option.png
Normal file
|
After Width: | Height: | Size: 142 KiB |
BIN
docs/images/secret-syncs/northflank/sync-created.png
Normal file
|
After Width: | Height: | Size: 105 KiB |
125
docs/integrations/app-connections/northflank.mdx
Normal file
@@ -0,0 +1,125 @@
|
||||
---
|
||||
title: "Northflank Connection"
|
||||
description: "Learn how to configure a Northflank Connection for Infisical."
|
||||
---
|
||||
|
||||
Infisical supports the use of [API Tokens](https://northflank.com/docs/v1/api/use-the-api) to connect with Northflank.
|
||||
|
||||
<Tip>
|
||||
Infisical recommends creating a specific API role for the app connection and only giving access to projects that will use the integration.
|
||||
</Tip>
|
||||
|
||||
## Create a Northflank API Token
|
||||
|
||||
<Steps>
|
||||
<Step title="Create an API Role">
|
||||
Navigate to your team page and click **Create token**.
|
||||
|
||||

|
||||
|
||||
Click on **Create API role**.
|
||||
|
||||

|
||||
|
||||
Select all the projects you want this role to have access to, or leave this unchecked if you want to give access to all projects.
|
||||
|
||||

|
||||
|
||||
Add the **Projects** -> **Manage** -> **Read** permission.
|
||||
|
||||

|
||||
|
||||
Add the **Config & Secrets** -> **Secret Groups** -> **List**, **Update** and **Read Values** permissions.
|
||||
|
||||

|
||||
|
||||
Scroll to the bottom and save the API role.
|
||||
</Step>
|
||||
<Step title="Create an API Token">
|
||||
Click on the **API** -> **Tokens** menu on the left and then click the **Create API token** button.
|
||||
|
||||

|
||||
|
||||
Give a name to the API token and click the **Use role** button for the new API role you just created.
|
||||
|
||||

|
||||
|
||||
Click the **View API token** icon to view and copy your token.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
## Create a Northflank Connection in Infisical
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
<Steps>
|
||||
<Step title="Navigate to App Connections">
|
||||
In your Infisical dashboard, navigate to the **App Connections** page in the desired project.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Select Northflank Connection">
|
||||
Click **+ Add Connection** and choose **Northflank Connection** from the list of integrations.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Fill out the Northflank Connection form">
|
||||
Complete the form by providing:
|
||||
- A descriptive name for the connection
|
||||
- An optional description
|
||||
- The API Token from the previous step
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Connection created">
|
||||
After submitting the form, your **Northflank Connection** will be successfully created and ready to use with your Infisical project.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
|
||||
<Tab title="API">
|
||||
To create a Northflank Connection via API, send a request to the [Create Northflank Connection](/api-reference/endpoints/app-connections/northflank/create) endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/app-connections/northflank \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-northflank-connection",
|
||||
"method": "api-token",
|
||||
"projectId": "abcdef12-3456-7890-abcd-ef1234567890",
|
||||
"credentials": {
|
||||
"apiToken": "[API TOKEN]"
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"appConnection": {
|
||||
"id": "a1b2c3d4-5678-90ab-cdef-1234567890ab",
|
||||
"name": "my-northflank-connection",
|
||||
"description": null,
|
||||
"projectId": "abcdef12-3456-7890-abcd-ef1234567890",
|
||||
"version": 1,
|
||||
"orgId": "abcdef12-3456-7890-abcd-ef1234567890",
|
||||
"createdAt": "2025-01-23T10:15:00.000Z",
|
||||
"updatedAt": "2025-01-23T10:15:00.000Z",
|
||||
"isPlatformManagedCredentials": false,
|
||||
"credentialsHash": "d41d8cd98f00b204e9800998ecf8427e",
|
||||
"app": "northflank",
|
||||
"method": "api-token",
|
||||
"credentials": {}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
@@ -63,6 +63,7 @@ The Infisical Agent Injector supports the following annotations:
|
||||
|
||||
- `init`: The init method will create an init container for the pod that will render the secrets into a shared volume mount within the pod. The agent init container will run before any other containers in the pod runs, including other init containers.
|
||||
- `sidecar`: The sidecar method will create a sidecar container for the pod that will render the secrets into a shared volume mount within the pod. The agent sidecar container will run alongside the main container in the pod. This means that the secrets rendered will always be in sync with your Infisical secrets.
|
||||
- `sidecar-init`: The sidecar-init method will create the init container and the sidecar container from the other two methods. The init container will run before any other container and fetch the secrets from the start and the sidecar container will keep the secrets in sync throughout the lifecycle of the deployment.
|
||||
</Accordion>
|
||||
<Accordion title="org.infisical.com/agent-config-map">
|
||||
The agent config map annotation is used to specify the name of the config map that contains the configuration for the injector. The config map must be in the same namespace as the pod.
|
||||
|
||||
@@ -41,6 +41,29 @@ If you require stronger isolation and stricter access controls, a namespace-scop
|
||||
```bash
|
||||
helm install --generate-name infisical-helm-charts/secrets-operator
|
||||
```
|
||||
|
||||
<Accordion title="Using your own service account">
|
||||
By default a service account is created for the operator based on the operator release name.
|
||||
You can bring your own service account by setting `controllerManager.serviceAccount.create` to `false` and setting `controllerManager.serviceAccount.name` to the name of the service account you want to use in your values.yaml file.
|
||||
|
||||
Example values.yaml file:
|
||||
|
||||
```yaml values.yaml
|
||||
controllerManager:
|
||||
serviceAccount:
|
||||
create: false
|
||||
name: my-service-account
|
||||
# other values...
|
||||
```
|
||||
|
||||
<Note>
|
||||
Please note that if you set `controllerManager.serviceAccount.create` to `false`, the service account needs to already exist in the namespace you are installing the operator in.
|
||||
</Note>
|
||||
|
||||
<Tip>
|
||||
Custom service accounts are supported in chart version `0.10.11` and above. Please upgrade your helm chart to `0.10.11` or above before attempting to use custom service accounts.
|
||||
</Tip>
|
||||
</Accordion>
|
||||
</Tab>
|
||||
<Tab title="Namespace Scoped Installation">
|
||||
The operator can be configured to watch and manage secrets in a specific namespace instead of having cluster-wide access. This is useful for:
|
||||
@@ -67,6 +90,29 @@ If you require stronger isolation and stricter access controls, a namespace-scop
|
||||
--set installCRDs=false
|
||||
```
|
||||
|
||||
<Accordion title="Using your own service account">
|
||||
By default a service account is created for the operator based on the operator release name.
|
||||
You can bring your own service account by setting `controllerManager.serviceAccount.create` to `false` and setting `controllerManager.serviceAccount.name` to the name of the service account you want to use in your values.yaml file.
|
||||
|
||||
Example values.yaml file:
|
||||
|
||||
```yaml values.yaml
|
||||
controllerManager:
|
||||
serviceAccount:
|
||||
create: false
|
||||
name: my-service-account
|
||||
# other values...
|
||||
```
|
||||
|
||||
<Note>
|
||||
Please note that if you set `controllerManager.serviceAccount.create` to `false`, the service account needs to already exist in the namespace you are installing the operator in.
|
||||
</Note>
|
||||
|
||||
<Tip>
|
||||
Custom service accounts are supported in chart version `0.10.11` and above. Please upgrade your helm chart to `0.10.11` or above before attempting to use custom service accounts.
|
||||
</Tip>
|
||||
</Accordion>
|
||||
|
||||
When scoped to a namespace, the operator will:
|
||||
|
||||
- Only watch InfisicalSecrets in the specified namespace
|
||||
@@ -158,14 +204,17 @@ The Infisical Secrets Operator integrates with the [Sprig library](https://githu
|
||||
|
||||
## Global configuration
|
||||
|
||||
To configure global settings that will apply to all instances of `InfisicalSecret`, you can define these configurations in a Kubernetes ConfigMap.
|
||||
For example, you can configure all `InfisicalSecret` instances to fetch secrets from a single backend API without specifying the `hostAPI` parameter for each instance.
|
||||
To configure global settings that will apply to all CRD instances (`InfisicalSecret`, `InfisicalPushSecret`, and `InfisicalDynamicSecret`), you can define these configurations in a Kubernetes ConfigMap.
|
||||
For example, you can configure all CRD instances to fetch secrets from a single backend API without specifying the `hostAPI` parameter for each instance.
|
||||
|
||||
### Available global properties
|
||||
|
||||
| Property | Description | Default value |
|
||||
| -------- | --------------------------------------------------------------------------------- | ----------------------------- |
|
||||
| hostAPI | If `hostAPI` in `InfisicalSecret` instance is left empty, this value will be used | https://app.infisical.com/api |
|
||||
| hostAPI | If `hostAPI` in a CRD instance is left empty, this value will be used | https://app.infisical.com/api |
|
||||
| tls.caRef.secretName | If `tls.caRef.secretName` in a CRD instance is left empty, this value will be used | - |
|
||||
| tls.caRef.secretNamespace | If `tls.caRef.secretNamespace` in a CRD instance is left empty, this value will be used | - |
|
||||
| tls.caRef.key | If `tls.caRef.key` in a CRD instance is left empty, this value will be used | - |
|
||||
|
||||
### Applying global configurations
|
||||
|
||||
@@ -185,6 +234,9 @@ metadata:
|
||||
namespace: infisical-operator-system
|
||||
data:
|
||||
hostAPI: https://example.com/api # <-- global hostAPI
|
||||
tls.caRef.secretName: custom-ca-certificate # <-- global TLS CA secret name
|
||||
tls.caRef.secretNamespace: default # <-- global TLS CA secret namespace
|
||||
tls.caRef.key: ca.crt # <-- global TLS CA secret key
|
||||
```
|
||||
|
||||
Then apply this change via kubectl by running the following
|
||||
|
||||
160
docs/integrations/secret-syncs/northflank.mdx
Normal file
@@ -0,0 +1,160 @@
|
||||
---
|
||||
title: "Northflank Sync"
|
||||
description: "Learn how to configure a Northflank Sync for Infisical."
|
||||
---
|
||||
|
||||
**Prerequisites:**
|
||||
- Create a [Northflank Connection](/integrations/app-connections/northflank)
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
<Steps>
|
||||
<Step title="Add Sync">
|
||||
Navigate to **Project** > **Integrations** and select the **Secret Syncs** tab. Click on the **Add Sync** button.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Select 'Northflank'">
|
||||

|
||||
</Step>
|
||||
<Step title="Configure source">
|
||||
Configure the **Source** from where secrets should be retrieved, then click **Next**.
|
||||
|
||||

|
||||
|
||||
- **Environment**: The project environment to retrieve secrets from.
|
||||
- **Secret Path**: The folder path to retrieve secrets from.
|
||||
|
||||
<Tip>
|
||||
If you need to sync secrets from multiple folder locations, check out [secret imports](/documentation/platform/secret-reference#secret-imports).
|
||||
</Tip>
|
||||
</Step>
|
||||
<Step title="Configure destination">
|
||||
Configure the **Destination** to where secrets should be deployed, then click **Next**.
|
||||
|
||||

|
||||
|
||||
- **Northflank Connection**: The Northflank Connection to authenticate with.
|
||||
- **Project**: The Northflank project to sync secrets to.
|
||||
- **Secret Group**: The Northflank secret group to sync secrets to.
|
||||
</Step>
|
||||
<Step title="Configure sync options">
|
||||
Configure the **Sync Options** to specify how secrets should be synced, then click **Next**.
|
||||
|
||||

|
||||
|
||||
- **Initial Sync Behavior**: Determines how Infisical should resolve the initial sync.
|
||||
- **Overwrite Destination Secrets**: Removes any secrets at the destination endpoint not present in Infisical.
|
||||
- **Import Destination Secrets - Prioritize Infisical Values**: Imports any secrets present in the Northflank destination prior to syncing, prioritizing values from Infisical over Northflank when keys conflict.
|
||||
- **Import Destination Secrets - Prioritize Northflank Values**: Imports any secrets present in the Northflank destination prior to syncing, prioritizing values from Northflank over Infisical when keys conflict.
|
||||
- **Key Schema**: Template that determines how secret names are transformed when syncing, using `{{secretKey}}` as a placeholder for the original secret name and `{{environment}}` for the environment.
|
||||
<Note>
|
||||
We highly recommend using a Key Schema to ensure that Infisical only manages the specific keys you intend, keeping everything else untouched.
|
||||
</Note>
|
||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||
</Step>
|
||||
<Step title="Configure details">
|
||||
Configure the **Details** of your Northflank Sync, then click **Next**.
|
||||
|
||||

|
||||
|
||||
- **Name**: The name of your sync. Must be slug-friendly.
|
||||
- **Description**: An optional description for your sync.
|
||||
</Step>
|
||||
<Step title="Review configuration">
|
||||
Review your Northflank Sync configuration, then click **Create Sync**.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Sync created">
|
||||
If enabled, your Northflank Sync will begin syncing your secrets to the destination endpoint.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create a **Northflank Sync**, make an API request to the [Create Northflank Sync](/api-reference/endpoints/secret-syncs/northflank/create) API endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/secret-syncs/northflank \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-northflank-sync",
|
||||
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"description": "an example sync",
|
||||
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"environment": "dev",
|
||||
"secretPath": "/my-secrets",
|
||||
"isAutoSyncEnabled": true,
|
||||
"syncOptions": {
|
||||
"initialSyncBehavior": "overwrite-destination",
|
||||
"keySchema": "INFISICAL_{{secretKey}}"
|
||||
},
|
||||
"destinationConfig": {
|
||||
"projectId": "my-project-id",
|
||||
"secretGroupId": "my-secret-group-id"
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```json Response
|
||||
{
|
||||
"secretSync": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"name": "my-northflank-sync",
|
||||
"description": "an example sync",
|
||||
"isAutoSyncEnabled": true,
|
||||
"version": 1,
|
||||
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"createdAt": "2023-11-07T05:31:56Z",
|
||||
"updatedAt": "2023-11-07T05:31:56Z",
|
||||
"syncStatus": "succeeded",
|
||||
"lastSyncJobId": "123",
|
||||
"lastSyncMessage": null,
|
||||
"lastSyncedAt": "2023-11-07T05:31:56Z",
|
||||
"importStatus": null,
|
||||
"lastImportJobId": null,
|
||||
"lastImportMessage": null,
|
||||
"lastImportedAt": null,
|
||||
"removeStatus": null,
|
||||
"lastRemoveJobId": null,
|
||||
"lastRemoveMessage": null,
|
||||
"lastRemovedAt": null,
|
||||
"syncOptions": {
|
||||
"initialSyncBehavior": "overwrite-destination",
|
||||
"keySchema": "INFISICAL_{{secretKey}}",
|
||||
"disableSecretDeletion": false
|
||||
},
|
||||
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"connection": {
|
||||
"app": "northflank",
|
||||
"name": "my-northflank-connection",
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||
},
|
||||
"environment": {
|
||||
"slug": "dev",
|
||||
"name": "Development",
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||
},
|
||||
"folder": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"path": "/my-secrets"
|
||||
},
|
||||
"destination": "northflank",
|
||||
"destinationConfig": {
|
||||
"projectId": "my-project-id",
|
||||
"secretGroupId": "my-secret-group-id"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
@@ -72,6 +72,7 @@ The SDK methods are organized into the following high-level categories:
|
||||
1. `auth`: Handles authentication methods.
|
||||
2. `secrets`: Manages CRUD operations for secrets.
|
||||
3. `kms`: Perform cryptographic operations with Infisical KMS.
|
||||
4. `folders`: Manages folder-related operations.
|
||||
|
||||
### `auth`
|
||||
|
||||
@@ -415,4 +416,66 @@ decrypted_data = client.kms.decrypt_data(
|
||||
- `ciphertext` (str): The ciphertext returned from the encrypt operation.
|
||||
|
||||
**Returns:**
|
||||
- `str`: The base64 encoded plaintext.
|
||||
- `str`: The base64 encoded plaintext.
|
||||
|
||||
### `folders`
|
||||
|
||||
This sub-class handles operations related to folders:
|
||||
|
||||
#### List Folders
|
||||
|
||||
```python
|
||||
folders = client.folders.list_folders(
|
||||
project_id="<project-id>",
|
||||
environment_slug="dev",
|
||||
path="/",
|
||||
recursive=False, # Optional
|
||||
last_secret_modified=None # Optional
|
||||
)
|
||||
```
|
||||
|
||||
**Parameters:**
|
||||
- `project_id` (str): The ID of your project.
|
||||
- `environment_slug` (str): The environment in which to list folders.
|
||||
- `path` (str): The path to list folders from.
|
||||
- `recursive` (bool, optional): Whether to list folders recursively from the specified path and downwards. Defaults to `False`.
|
||||
- `last_secret_modified` (datetime, optional): The timestamp used to filter folders with secrets modified after the specified date. Defaults to `None`.
|
||||
|
||||
**Returns:**
|
||||
- `ListFoldersResponse`: The response containing the list of folders.
|
||||
|
||||
#### Create Folder
|
||||
|
||||
```python
|
||||
new_folder = client.folders.create_folder(
|
||||
name="my-folder",
|
||||
environment_slug="dev",
|
||||
project_id="<project-id>",
|
||||
path="/", # Optional
|
||||
description=None # Optional
|
||||
)
|
||||
```
|
||||
|
||||
**Parameters:**
|
||||
- `name` (str): The name of the folder to create.
|
||||
- `environment_slug` (str): The slug of the environment to create the folder in.
|
||||
- `project_id` (str): The ID of your project to create the folder in.
|
||||
- `path` (str, optional): The path to create the folder in. Defaults to `/`.
|
||||
- `description` (str, optional): An optional description label for the folder. Defaults to `None`.
|
||||
|
||||
**Returns:**
|
||||
- `CreateFolderResponseItem`: The response containing the created folder.
|
||||
|
||||
#### Get Folder by ID
|
||||
|
||||
```python
|
||||
folder = client.folders.get_folder_by_id(
|
||||
id="<folder-id>"
|
||||
)
|
||||
```
|
||||
|
||||
**Parameters:**
|
||||
- `id` (str): The ID of the folder to retrieve.
|
||||
|
||||
**Returns:**
|
||||
- `SingleFolderResponseItem`: The response containing the folder details.
|
||||
@@ -319,80 +319,137 @@ helm install otel-collector open-telemetry/opentelemetry-collector \
|
||||
--set config.exporters.prometheus.endpoint=0.0.0.0:8889
|
||||
```
|
||||
|
||||
## Alternative Backends
|
||||
|
||||
Since Infisical exports in OpenTelemetry format, you can easily configure the collector to send metrics to other backends instead of (or in addition to) Prometheus:
|
||||
|
||||
### Cloud-Native Examples
|
||||
|
||||
```yaml
|
||||
# Add to your otel-collector-config.yaml exporters section
|
||||
exporters:
|
||||
# AWS CloudWatch
|
||||
awsemf:
|
||||
region: us-west-2
|
||||
log_group_name: /aws/emf/infisical
|
||||
log_stream_name: metrics
|
||||
|
||||
# Google Cloud Monitoring
|
||||
googlecloud:
|
||||
project_id: your-project-id
|
||||
|
||||
# Azure Monitor
|
||||
azuremonitor:
|
||||
connection_string: "your-connection-string"
|
||||
|
||||
# Datadog
|
||||
datadog:
|
||||
api:
|
||||
key: "your-api-key"
|
||||
site: "datadoghq.com"
|
||||
|
||||
# New Relic
|
||||
newrelic:
|
||||
apikey: "your-api-key"
|
||||
host_override: "otlp.nr-data.net"
|
||||
```
|
||||
|
||||
### Multi-Backend Configuration
|
||||
|
||||
```yaml
|
||||
service:
|
||||
pipelines:
|
||||
metrics:
|
||||
receivers: [otlp]
|
||||
processors: [batch]
|
||||
exporters: [prometheus, awsemf, datadog] # Send to multiple backends
|
||||
```
|
||||
|
||||
## Setting Up Grafana
|
||||
|
||||
1. **Access Grafana**: Navigate to your Grafana instance
|
||||
2. **Login**: Use your configured credentials
|
||||
3. **Add Prometheus Data Source**:
|
||||
- Go to Configuration → Data Sources
|
||||
- Click "Add data source"
|
||||
- Select "Prometheus"
|
||||
- Set URL to your Prometheus endpoint
|
||||
- Click "Save & Test"
|
||||
|
||||
## Available Metrics
|
||||
|
||||
Infisical exposes the following key metrics in OpenTelemetry format:
|
||||
|
||||
### API Performance Metrics
|
||||
### Core API Metrics
|
||||
|
||||
- `API_latency` - API request latency histogram in milliseconds
|
||||
These metrics track all HTTP API requests to Infisical, including request counts, latency, and errors. Use these to monitor overall API health, identify performance bottlenecks, and track usage patterns across users and machine identities.
|
||||
|
||||
- **Labels**: `route`, `method`, `statusCode`
|
||||
- **Example**: Monitor response times for specific endpoints
|
||||
#### Total API Requests
|
||||
|
||||
- `API_errors` - API error count histogram
|
||||
- **Labels**: `route`, `method`, `type`, `name`
|
||||
- **Example**: Track error rates by endpoint and error type
|
||||
- **Metric Name**: `infisical.http.server.request.count`
|
||||
- **Type**: Counter
|
||||
- **Unit**: `{request}`
|
||||
- **Description**: Total number of API requests to Infisical (covers both human users and machine identities)
|
||||
- **Attributes**:
|
||||
- `infisical.organization.id` (string): Organization ID
|
||||
- `infisical.organization.name` (string): Organization name (e.g., "Platform Engineering Team")
|
||||
- `infisical.user.id` (string, optional): User ID if human user
|
||||
- `infisical.user.email` (string, optional): User email (e.g., "jane.doe@cisco.com")
|
||||
- `infisical.identity.id` (string, optional): Machine identity ID
|
||||
- `infisical.identity.name` (string, optional): Machine identity name (e.g., "prod-k8s-operator")
|
||||
- `infisical.auth.method` (string, optional): Auth method used
|
||||
- `http.request.method` (string): HTTP method (GET, POST, PUT, DELETE)
|
||||
- `http.route` (string): API endpoint route pattern
|
||||
- `http.response.status_code` (int): HTTP status code
|
||||
- `infisical.project.id` (string, optional): Project ID
|
||||
- `infisical.project.name` (string, optional): Project name
|
||||
- `user_agent.original` (string, optional): User agent string
|
||||
- `client.address` (string, optional): IP address
|
||||
|
||||
#### Request Duration
|
||||
|
||||
- **Metric Name**: `infisical.http.server.request.duration`
|
||||
- **Type**: Histogram
|
||||
- **Unit**: `s` (seconds)
|
||||
- **Description**: API request latency
|
||||
- **Buckets**: [0.005, 0.01, 0.025, 0.05, 0.1, 0.25, 0.5, 1, 2.5, 5, 10]
|
||||
- **Attributes**:
|
||||
- `infisical.organization.id` (string): Organization ID
|
||||
- `infisical.organization.name` (string): Organization name
|
||||
- `infisical.user.id` (string, optional): User ID if human user
|
||||
- `infisical.user.email` (string, optional): User email
|
||||
- `infisical.identity.id` (string, optional): Machine identity ID
|
||||
- `infisical.identity.name` (string, optional): Machine identity name
|
||||
- `http.request.method` (string): HTTP method
|
||||
- `http.route` (string): API endpoint route pattern
|
||||
- `http.response.status_code` (int): HTTP status code
|
||||
- `infisical.project.id` (string, optional): Project ID
|
||||
- `infisical.project.name` (string, optional): Project name
|
||||
|
||||
#### API Errors by Actor
|
||||
|
||||
- **Metric Name**: `infisical.http.server.error.count`
|
||||
- **Type**: Counter
|
||||
- **Unit**: `{error}`
|
||||
- **Description**: API errors grouped by actor (for identifying misconfigured services)
|
||||
- **Attributes**:
|
||||
- `infisical.organization.id` (string): Organization ID
|
||||
- `infisical.organization.name` (string): Organization name
|
||||
- `infisical.user.id` (string, optional): User ID if human
|
||||
- `infisical.user.email` (string, optional): User email
|
||||
- `infisical.identity.id` (string, optional): Identity ID if machine
|
||||
- `infisical.identity.name` (string, optional): Identity name
|
||||
- `http.route` (string): API endpoint where error occurred
|
||||
- `http.request.method` (string): HTTP method
|
||||
- `error.type` (string): Error category/type (client_error, server_error, auth_error, rate_limit_error, etc.)
|
||||
- `infisical.project.id` (string, optional): Project ID
|
||||
- `infisical.project.name` (string, optional): Project name
|
||||
- `client.address` (string, optional): IP address
|
||||
- `user_agent.original` (string, optional): User agent information
|
||||
|
||||
### Secret Operations Metrics
|
||||
|
||||
These metrics provide visibility into secret access patterns, helping you understand which secrets are being accessed, by whom, and from where. Essential for security auditing and access pattern analysis.
|
||||
|
||||
#### Secret Read Operations
|
||||
|
||||
- **Metric Name**: `infisical.secret.read.count`
|
||||
- **Type**: Counter
|
||||
- **Unit**: `{operation}`
|
||||
- **Description**: Number of secret read operations
|
||||
- **Attributes**:
|
||||
- `infisical.organization.id` (string): Organization ID
|
||||
- `infisical.organization.name` (string): Organization name
|
||||
- `infisical.project.id` (string): Project ID
|
||||
- `infisical.project.name` (string): Project name (e.g., "payment-service-secrets")
|
||||
- `infisical.environment` (string): Environment (dev, staging, prod)
|
||||
- `infisical.secret.path` (string): Path to secrets (e.g., "/microservice-a/database")
|
||||
- `infisical.secret.name` (string, optional): Name of secret
|
||||
- `infisical.user.id` (string, optional): User ID if human
|
||||
- `infisical.user.email` (string, optional): User email
|
||||
- `infisical.identity.id` (string, optional): Machine identity ID
|
||||
- `infisical.identity.name` (string, optional): Machine identity name
|
||||
- `user_agent.original` (string, optional): User agent/SDK information
|
||||
- `client.address` (string, optional): IP address
|
||||
|
||||
### Authentication Metrics
|
||||
|
||||
These metrics track authentication attempts and outcomes, enabling you to monitor login success rates, detect potential security threats, and identify authentication issues.
|
||||
|
||||
#### Login Attempts
|
||||
|
||||
- **Metric Name**: `infisical.auth.attempt.count`
|
||||
- **Type**: Counter
|
||||
- **Unit**: `{attempt}`
|
||||
- **Description**: Authentication attempts (both successful and failed)
|
||||
- **Attributes**:
|
||||
- `infisical.organization.id` (string): Organization ID
|
||||
- `infisical.organization.name` (string): Organization name
|
||||
- `infisical.user.id` (string, optional): User ID if human (if identifiable)
|
||||
- `infisical.user.email` (string, optional): User email (if identifiable)
|
||||
- `infisical.identity.id` (string, optional): Identity ID if machine (if identifiable)
|
||||
- `infisical.identity.name` (string, optional): Identity name (if identifiable)
|
||||
- `infisical.auth.method` (string): Authentication method attempted
|
||||
- `infisical.auth.result` (string): success or failure
|
||||
- `error.type` (string, optional): Reason for failure if failed (invalid_credentials, expired_token, invalid_token, etc.)
|
||||
- `client.address` (string): IP address
|
||||
- `user_agent.original` (string, optional): User agent/client information
|
||||
- `infisical.auth.attempt.username` (string, optional): Attempted username/email (if available)
|
||||
|
||||
### Legacy Metrics
|
||||
|
||||
These metrics are from the previous instrumentation and may be deprecated in future versions. Consider migrating to the new Core API Metrics for more comprehensive observability.
|
||||
|
||||
- `API_latency` - API request latency histogram in milliseconds (Labels: `route`, `method`, `statusCode`)
|
||||
- `API_errors` - API error count histogram (Labels: `route`, `method`, `type`, `name`)
|
||||
|
||||
### Integration & Secret Sync Metrics
|
||||
|
||||
These metrics monitor secret synchronization operations between Infisical and external systems, helping you track sync health, identify integration failures, and troubleshoot connectivity issues.
|
||||
|
||||
- `integration_secret_sync_errors` - Integration secret sync error count
|
||||
|
||||
- **Labels**: `version`, `integration`, `integrationId`, `type`, `status`, `name`, `projectId`
|
||||
@@ -414,16 +471,11 @@ Infisical exposes the following key metrics in OpenTelemetry format:
|
||||
|
||||
### System Metrics
|
||||
|
||||
These metrics are automatically collected by OpenTelemetry's HTTP instrumentation:
|
||||
These low-level HTTP metrics are automatically collected by OpenTelemetry's instrumentation layer, providing baseline performance data for all HTTP traffic.
|
||||
|
||||
- `http_server_duration` - HTTP server request duration metrics (histogram buckets, count, sum)
|
||||
- `http_client_duration` - HTTP client request duration metrics (histogram buckets, count, sum)
|
||||
|
||||
### Custom Business Metrics
|
||||
|
||||
- `infisical_secret_operations_total` - Total secret operations
|
||||
- `infisical_secrets_processed_total` - Total secrets processed
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Common Issues
|
||||
|
||||
@@ -48,6 +48,7 @@ export const AppConnectionsBrowser = () => {
|
||||
{"name": "Okta", "slug": "okta", "path": "/integrations/app-connections/okta", "description": "Learn how to connect your Okta to pull secrets from Infisical.", "category": "Identity & Auth"},
|
||||
{"name": "Laravel Forge", "slug": "laravel-forge", "path": "/integrations/app-connections/laravel-forge", "description": "Learn how to connect your Laravel Forge to pull secrets from Infisical.", "category": "Hosting"},
|
||||
{"name": "Chef", "slug": "chef", "path": "/integrations/app-connections/chef", "description": "Learn how to connect your Chef to pull secrets from Infisical.", "category": "DevOps Tools"},
|
||||
{"name": "Northflank", "slug": "northflank", "path": "/integrations/app-connections/northflank", "description": "Learn how to connect your Northflank projects to pull secrets from Infisical.", "category": "Hosting"}
|
||||
].sort(function(a, b) {
|
||||
return a.name.toLowerCase().localeCompare(b.name.toLowerCase());
|
||||
});
|
||||
|
||||
@@ -38,7 +38,8 @@ export const SecretSyncsBrowser = () => {
|
||||
{"name": "OCI Vault", "slug": "oci-vault", "path": "/integrations/secret-syncs/oci-vault", "description": "Learn how to sync secrets from Infisical to OCI Vault.", "category": "Cloud Providers"},
|
||||
{"name": "Zabbix", "slug": "zabbix", "path": "/integrations/secret-syncs/zabbix", "description": "Learn how to sync secrets from Infisical to Zabbix.", "category": "Monitoring"},
|
||||
{"name": "Laravel Forge", "slug": "laravel-forge", "path": "/integrations/secret-syncs/laravel-forge", "description": "Learn how to sync secrets from Infisical to Laravel Forge.", "category": "Hosting"},
|
||||
{"name": "Chef", "slug": "chef", "path": "/integrations/secret-syncs/chef", "description": "Learn how to sync secrets from Infisical to Chef.", "category": "DevOps Tools"}
|
||||
{"name": "Chef", "slug": "chef", "path": "/integrations/secret-syncs/chef", "description": "Learn how to sync secrets from Infisical to Chef.", "category": "DevOps Tools"},
|
||||
{"name": "Northflank", "slug": "northflank", "path": "/integrations/secret-syncs/northflank", "description": "Learn how to sync secrets from Infisical to Northflank projects.", "category": "Hosting"}
|
||||
].sort(function(a, b) {
|
||||
return a.name.toLowerCase().localeCompare(b.name.toLowerCase());
|
||||
});
|
||||
|
||||