review fixes

This commit is contained in:
x032205
2025-05-06 16:26:51 -04:00
parent 45c84d4936
commit bd7c4fc4eb
16 changed files with 147 additions and 153 deletions
@@ -114,12 +114,12 @@ The Infisical AWS ElastiCache dynamic secret allows you to generate AWS ElastiCa
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
@@ -131,7 +131,7 @@ The Infisical AWS ElastiCache dynamic secret allows you to generate AWS ElastiCa
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -123,7 +123,7 @@ Click on Add assignments. Search for the application name you created and select
</Step> </Step>
<Step title="Click `Submit`"> <Step title="Click `Submit`">
After submitting the form, you will see a dynamic secrets for each user created in the dashboard. After submitting the form, you will see a dynamic secret for each user created in the dashboard.
</Step> </Step>
<Step title="Generate dynamic secrets"> <Step title="Generate dynamic secrets">
@@ -134,12 +134,12 @@ Click on Add assignments. Search for the application name you created and select
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
@@ -151,7 +151,7 @@ Click on Add assignments. Search for the application name you created and select
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -97,12 +97,12 @@ The Infisical Elasticsearch dynamic secret allows you to generate Elasticsearch
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
@@ -114,7 +114,7 @@ The Infisical Elasticsearch dynamic secret allows you to generate Elasticsearch
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -97,28 +97,28 @@ The Infisical GCP IAM dynamic secret allows you to generate GCP service account
</ParamField> </ParamField>
</Step> </Step>
<Step title="Click `Submit`"> <Step title="Click `Submit`">
After submitting the form, you will see a dynamic secrets for each user created in the dashboard. After submitting the form, you will see a dynamic secret created in the dashboard.
</Step> </Step>
<Step title="Generate dynamic secrets"> <Step title="Generate dynamic secrets">
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
Once you click the `Submit` button, a new secret lease will be generated and the credentials from it will be shown to you. Once you click the `Submit` button, a new secret lease will be generated and the credentials from it will be shown to you.
![Dynamic Secret Lease](/images/platform/dynamic-secrets/dynamic-secret-gcp-iam-lease.png) ![Dynamic Secret Lease](/images/platform/dynamic-secrets/dynamic-secret-gcp-iam-lease.png)
</Step> </Step>
</Steps> </Steps>
@@ -126,7 +126,7 @@ The Infisical GCP IAM dynamic secret allows you to generate GCP service account
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Lease Data](/images/platform/dynamic-secrets/lease-data.png) ![Lease Data](/images/platform/dynamic-secrets/lease-data.png)
@@ -136,12 +136,12 @@ The Infisical LDAP dynamic secret allows you to generate user credentials on dem
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
@@ -239,12 +239,12 @@ The Infisical LDAP dynamic secret allows you to generate user credentials on dem
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
@@ -68,17 +68,17 @@ Create a project scopped API Key with the required permission in your Mongo Atla
- **Type**: Category of resource that this database user can access. - **Type**: Category of resource that this database user can access.
</Step> </Step>
<Step title="Click 'Submit'"> <Step title="Click 'Submit'">
After submitting the form, you will see a dynamic secret created in the dashboard. After submitting the form, you will see a dynamic secret created in the dashboard.
<Note> <Note>
If this step fails, you may have to add the CA certficate. If this step fails, you may have to add the CA certficate.
</Note> </Note>
![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png) ![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png)
</Step> </Step>
<Step title="Generate dynamic secrets"> <Step title="Generate dynamic secrets">
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
@@ -89,19 +89,19 @@ Create a project scopped API Key with the required permission in your Mongo Atla
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you. Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you.
![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png)
</Step> </Step>
</Steps> </Steps>
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -62,7 +62,7 @@ Create a user with the required permission in your MongoDB instance. This user w
Human-readable label that identifies a group of privileges assigned to a database user. This value can either be a built-in role or a custom role. Human-readable label that identifies a group of privileges assigned to a database user. This value can either be a built-in role or a custom role.
- Enum: `atlasAdmin` `backup` `clusterMonitor` `dbAdmin` `dbAdminAnyDatabase` `enableSharding` `read` `readAnyDatabase` `readWrite` `readWriteAnyDatabase` `<a custom role name>`. - Enum: `atlasAdmin` `backup` `clusterMonitor` `dbAdmin` `dbAdminAnyDatabase` `enableSharding` `read` `readAnyDatabase` `readWrite` `readWriteAnyDatabase` `<a custom role name>`.
</ParamField> </ParamField>
<ParamField path="CA(SSL)" type="string"> <ParamField path="CA(SSL)" type="string">
A CA may be required if your DB requires it for incoming connections. A CA may be required if your DB requires it for incoming connections.
</ParamField> </ParamField>
@@ -71,39 +71,39 @@ Create a user with the required permission in your MongoDB instance. This user w
</Step> </Step>
<Step title="Click `Submit`"> <Step title="Click `Submit`">
After submitting the form, you will see a dynamic secret created in the dashboard. After submitting the form, you will see a dynamic secret created in the dashboard.
<Note> <Note>
If this step fails, you may have to add the CA certificate. If this step fails, you may have to add the CA certificate.
</Note> </Note>
</Step> </Step>
<Step title="Generate dynamic secrets"> <Step title="Generate dynamic secrets">
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
Once you click the `Submit` button, a new secret lease will be generated and the credentials from it will be shown to you. Once you click the `Submit` button, a new secret lease will be generated and the credentials from it will be shown to you.
![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png)
</Step> </Step>
</Steps> </Steps>
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -62,7 +62,7 @@ Create a user with the required permission in your SQL instance. This user will
<ParamField path="Database Name" type="string" required> <ParamField path="Database Name" type="string" required>
Name of the database for which you want to create dynamic secrets Name of the database for which you want to create dynamic secrets
</ParamField> </ParamField>
<ParamField path="CA(SSL)" type="string"> <ParamField path="CA(SSL)" type="string">
A CA may be required if your DB requires it for incoming connections. AWS RDS instances with default settings will requires a CA which can be downloaded [here](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions). A CA may be required if your DB requires it for incoming connections. AWS RDS instances with default settings will requires a CA which can be downloaded [here](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions).
</ParamField> </ParamField>
@@ -76,17 +76,17 @@ Create a user with the required permission in your SQL instance. This user will
![Modify SQL Statements Modal](../../../images/platform/dynamic-secrets/modify-sql-statements-mssql.png) ![Modify SQL Statements Modal](../../../images/platform/dynamic-secrets/modify-sql-statements-mssql.png)
</Step> </Step>
<Step title="Click 'Submit'"> <Step title="Click 'Submit'">
After submitting the form, you will see a dynamic secret created in the dashboard. After submitting the form, you will see a dynamic secret created in the dashboard.
<Note> <Note>
If this step fails, you may have to add the CA certficate. If this step fails, you may have to add the CA certficate.
</Note> </Note>
![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png) ![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png)
</Step> </Step>
<Step title="Generate dynamic secrets"> <Step title="Generate dynamic secrets">
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
@@ -97,18 +97,18 @@ Create a user with the required permission in your SQL instance. This user will
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you. Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you.
![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png)
</Step> </Step>
</Steps> </Steps>
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete the lease before it's set time to live. This will allow you to see the expiration time of the lease or delete the lease before it's set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -61,7 +61,7 @@ Create a user with the required permission in your SQL instance. This user will
<ParamField path="Database Name" type="string" required> <ParamField path="Database Name" type="string" required>
Name of the database for which you want to create dynamic secrets Name of the database for which you want to create dynamic secrets
</ParamField> </ParamField>
<ParamField path="CA(SSL)" type="string"> <ParamField path="CA(SSL)" type="string">
A CA may be required if your DB requires it for incoming connections. AWS RDS instances with default settings will requires a CA which can be downloaded [here](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions). A CA may be required if your DB requires it for incoming connections. AWS RDS instances with default settings will requires a CA which can be downloaded [here](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions).
</ParamField> </ParamField>
@@ -73,40 +73,40 @@ Create a user with the required permission in your SQL instance. This user will
![Modify SQL Statements Modal](/images/platform/dynamic-secrets/modify-sql-statement-mysql.png) ![Modify SQL Statements Modal](/images/platform/dynamic-secrets/modify-sql-statement-mysql.png)
</Step> </Step>
<Step title="Click `Submit`"> <Step title="Click `Submit`">
After submitting the form, you will see a dynamic secret created in the dashboard. After submitting the form, you will see a dynamic secret created in the dashboard.
<Note> <Note>
If this step fails, you may have to add the CA certificate. If this step fails, you may have to add the CA certificate.
</Note> </Note>
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret.png)
</Step> </Step>
<Step title="Generate dynamic secrets"> <Step title="Generate dynamic secrets">
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
Once you click the `Submit` button, a new secret lease will be generated and the credentials from it will be shown to you. Once you click the `Submit` button, a new secret lease will be generated and the credentials from it will be shown to you.
![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png)
</Step> </Step>
</Steps> </Steps>
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -116,4 +116,4 @@ To extend the life of the generated dynamic secret leases past its initial time
<Warning> <Warning>
Lease renewals cannot exceed the maximum TTL set when configuring the dynamic secret Lease renewals cannot exceed the maximum TTL set when configuring the dynamic secret
</Warning> </Warning>
@@ -61,7 +61,7 @@ Create a user with the required permission in your SQL instance. This user will
<ParamField path="Database Name" type="string" required> <ParamField path="Database Name" type="string" required>
Name of the database for which you want to create dynamic secrets Name of the database for which you want to create dynamic secrets
</ParamField> </ParamField>
<ParamField path="CA(SSL)" type="string"> <ParamField path="CA(SSL)" type="string">
A CA may be required if your DB requires it for incoming connections. AWS RDS instances with default settings will requires a CA which can be downloaded [here](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions). A CA may be required if your DB requires it for incoming connections. AWS RDS instances with default settings will requires a CA which can be downloaded [here](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions).
</ParamField> </ParamField>
@@ -73,17 +73,17 @@ Create a user with the required permission in your SQL instance. This user will
If you want to provide specific privileges for the generated dynamic credentials, you can modify the SQL statement to your needs. This is useful if you want to only give access to a specific table(s). If you want to provide specific privileges for the generated dynamic credentials, you can modify the SQL statement to your needs. This is useful if you want to only give access to a specific table(s).
</Step> </Step>
<Step title="Click 'Submit'"> <Step title="Click 'Submit'">
After submitting the form, you will see a dynamic secret created in the dashboard. After submitting the form, you will see a dynamic secret created in the dashboard.
<Note> <Note>
If this step fails, you may have to add the CA certficate. If this step fails, you may have to add the CA certficate.
</Note> </Note>
![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png) ![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png)
</Step> </Step>
<Step title="Generate dynamic secrets"> <Step title="Generate dynamic secrets">
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
@@ -94,19 +94,19 @@ Create a user with the required permission in your SQL instance. This user will
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you. Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you.
![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png)
</Step> </Step>
</Steps> </Steps>
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -116,4 +116,4 @@ To extend the life of the generated dynamic secret leases past its initial time
<Warning> <Warning>
Lease renewals cannot exceed the maximum TTL set when configuring the dynamic secret Lease renewals cannot exceed the maximum TTL set when configuring the dynamic secret
</Warning> </Warning>
@@ -62,7 +62,7 @@ Create a user with the required permission in your SQL instance. This user will
<ParamField path="Database Name" type="string" required> <ParamField path="Database Name" type="string" required>
Name of the database for which you want to create dynamic secrets Name of the database for which you want to create dynamic secrets
</ParamField> </ParamField>
<ParamField path="CA(SSL)" type="string"> <ParamField path="CA(SSL)" type="string">
A CA may be required if your DB requires it for incoming connections. AWS RDS instances with default settings will requires a CA which can be downloaded [here](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions). A CA may be required if your DB requires it for incoming connections. AWS RDS instances with default settings will requires a CA which can be downloaded [here](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions).
</ParamField> </ParamField>
@@ -76,17 +76,17 @@ Create a user with the required permission in your SQL instance. This user will
![Modify SQL Statements Modal](../../../images/platform/dynamic-secrets/modify-sql-statements.png) ![Modify SQL Statements Modal](../../../images/platform/dynamic-secrets/modify-sql-statements.png)
</Step> </Step>
<Step title="Click 'Submit'"> <Step title="Click 'Submit'">
After submitting the form, you will see a dynamic secret created in the dashboard. After submitting the form, you will see a dynamic secret created in the dashboard.
<Note> <Note>
If this step fails, you may have to add the CA certficate. If this step fails, you may have to add the CA certficate.
</Note> </Note>
![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png) ![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png)
</Step> </Step>
<Step title="Generate dynamic secrets"> <Step title="Generate dynamic secrets">
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
@@ -97,18 +97,18 @@ Create a user with the required permission in your SQL instance. This user will
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you. Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you.
![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png)
</Step> </Step>
</Steps> </Steps>
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete the lease before it's set time to live. This will allow you to see the expiration time of the lease or delete the lease before it's set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -86,12 +86,12 @@ The Infisical RabbitMQ dynamic secret allows you to generate RabbitMQ credential
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
@@ -103,7 +103,7 @@ The Infisical RabbitMQ dynamic secret allows you to generate RabbitMQ credential
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -76,12 +76,12 @@ Create a user with the required permission in your Redis instance. This user wil
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png)
![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png)
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png)
<Tip> <Tip>
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. Ensure that the TTL for the lease falls within the maximum TTL defined when configuring the dynamic secret.
</Tip> </Tip>
@@ -93,7 +93,7 @@ Create a user with the required permission in your Redis instance. This user wil
## Audit or Revoke Leases ## Audit or Revoke Leases
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
This will allow you to see the expiration time of the lease or delete a lease before it's set time to live. This will allow you to see the expiration time of the lease or delete a lease before its set time to live.
![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) ![Provision Lease](/images/platform/dynamic-secrets/lease-data.png)
@@ -10,34 +10,33 @@ import { useCreateDynamicSecret } from "@app/hooks/api";
import { DynamicSecretProviders } from "@app/hooks/api/dynamicSecret/types"; import { DynamicSecretProviders } from "@app/hooks/api/dynamicSecret/types";
import { WorkspaceEnv } from "@app/hooks/api/types"; import { WorkspaceEnv } from "@app/hooks/api/types";
const formSchema = z.object({ const validateTTL = (val: string, ctx: z.RefinementCtx) => {
provider: z.object({ if (!val) return;
serviceAccountEmail: z.string().email().trim().min(1, "Service account email required") const valMs = ms(val);
}), if (valMs === undefined) {
defaultTTL: z.string().superRefine((val, ctx) => { ctx.addIssue({ code: z.ZodIssueCode.custom, message: "Invalid TTL format" });
const valMs = ms(val); return;
if (valMs < 1000) }
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be a greater than 1 second" }); if (valMs < 1000)
if (valMs > 60 * 60 * 1000) ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be a greater than 1 second" });
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than 1 hour" }); if (valMs > 60 * 60 * 1000)
}), ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than 1 hour" });
maxTTL: z };
.string()
.optional() const formSchema = z
.superRefine((val, ctx) => { .object({
if (!val) return; provider: z.object({
const valMs = ms(val); serviceAccountEmail: z.string().email().trim().min(1, "Service account email required")
if (valMs < 1000)
ctx.addIssue({
code: z.ZodIssueCode.custom,
message: "TTL must be a greater than 1 second"
});
if (valMs > 60 * 60 * 1000)
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than 1 hour" });
}), }),
name: z.string().refine((val) => val.toLowerCase() === val, "Must be lowercase"), defaultTTL: z.string().superRefine(validateTTL),
environment: z.object({ name: z.string(), slug: z.string() }) maxTTL: z.string().optional().superRefine(validateTTL),
}); name: z.string().refine((val) => val.toLowerCase() === val, "Must be lowercase"),
environment: z.object({ name: z.string(), slug: z.string() })
})
.refine((d) => !d.maxTTL || ms(d.maxTTL)! >= ms(d.defaultTTL)!, {
path: ["maxTTL"],
message: "Max TTL must be greater than or equal to Default TTL"
});
type TForm = z.infer<typeof formSchema>; type TForm = z.infer<typeof formSchema>;
type Props = { type Props = {
@@ -64,7 +63,7 @@ export const GcpIamInputForm = ({
} = useForm<TForm>({ } = useForm<TForm>({
resolver: zodResolver(formSchema), resolver: zodResolver(formSchema),
defaultValues: { defaultValues: {
environment: isSingleEnvironmentMode ? environments[0] : undefined environment: isSingleEnvironmentMode && environments.length > 0 ? environments[0] : undefined
} }
}); });
@@ -77,8 +76,6 @@ export const GcpIamInputForm = ({
defaultTTL, defaultTTL,
environment environment
}: TForm) => { }: TForm) => {
console.log("handleCreateDynamicSecret called");
// wait till previous request is finished // wait till previous request is finished
if (createDynamicSecret.isPending) return; if (createDynamicSecret.isPending) return;
try { try {
@@ -9,33 +9,37 @@ import { Button, FormControl, Input } from "@app/components/v2";
import { useUpdateDynamicSecret } from "@app/hooks/api"; import { useUpdateDynamicSecret } from "@app/hooks/api";
import { TDynamicSecret } from "@app/hooks/api/dynamicSecret/types"; import { TDynamicSecret } from "@app/hooks/api/dynamicSecret/types";
const formSchema = z.object({ const validateTTL = (val: string, ctx: z.RefinementCtx) => {
inputs: z.object({ if (!val) return;
serviceAccountEmail: z.string().email().trim().min(1, "Service account email required") const valMs = ms(val);
}), if (valMs === undefined) {
defaultTTL: z.string().superRefine((val, ctx) => { ctx.addIssue({ code: z.ZodIssueCode.custom, message: "Invalid TTL format" });
const valMs = ms(val); return;
if (valMs < 1000) }
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be a greater than 1 second" }); if (valMs < 1000)
if (valMs > 60 * 60 * 1000) ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be a greater than 1 second" });
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than 1 hour" }); if (valMs > 60 * 60 * 1000)
}), ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than 1 hour" });
maxTTL: z };
.string()
.optional() const formSchema = z
.superRefine((val, ctx) => { .object({
if (!val) return; inputs: z.object({
const valMs = ms(val); serviceAccountEmail: z.string().email().trim().min(1, "Service account email required")
if (valMs < 1000)
ctx.addIssue({
code: z.ZodIssueCode.custom,
message: "TTL must be a greater than 1 second"
});
if (valMs > 60 * 60 * 1000)
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than 1 hour" });
}), }),
newName: z.string().refine((val) => val.toLowerCase() === val, "Must be lowercase") defaultTTL: z.string().superRefine(validateTTL),
}); maxTTL: z
.string()
.optional()
.superRefine((val, ctx) => {
if (val) validateTTL(val, ctx);
}),
newName: z.string().refine((val) => val.toLowerCase() === val, "Must be lowercase")
})
.refine((d) => !d.maxTTL || ms(d.maxTTL)! >= ms(d.defaultTTL)!, {
path: ["maxTTL"],
message: "Max TTL must be greater than or equal to Default TTL"
});
type TForm = z.infer<typeof formSchema>; type TForm = z.infer<typeof formSchema>;
type Props = { type Props = {
@@ -107,7 +111,6 @@ export const EditDynamicSecretGcpIamForm = ({
<div className="flex-grow"> <div className="flex-grow">
<Controller <Controller
control={control} control={control}
defaultValue=""
name="newName" name="newName"
render={({ field, fieldState: { error } }) => ( render={({ field, fieldState: { error } }) => (
<FormControl <FormControl
@@ -124,7 +127,6 @@ export const EditDynamicSecretGcpIamForm = ({
<Controller <Controller
control={control} control={control}
name="defaultTTL" name="defaultTTL"
defaultValue="1h"
render={({ field, fieldState: { error } }) => ( render={({ field, fieldState: { error } }) => (
<FormControl <FormControl
label={<TtlFormLabel label="Default TTL" />} label={<TtlFormLabel label="Default TTL" />}
@@ -140,7 +142,6 @@ export const EditDynamicSecretGcpIamForm = ({
<Controller <Controller
control={control} control={control}
name="maxTTL" name="maxTTL"
defaultValue="24h"
render={({ field, fieldState: { error } }) => ( render={({ field, fieldState: { error } }) => (
<FormControl <FormControl
label={<TtlFormLabel label="Max TTL" />} label={<TtlFormLabel label="Max TTL" />}
@@ -161,7 +162,6 @@ export const EditDynamicSecretGcpIamForm = ({
<Controller <Controller
control={control} control={control}
name="inputs.serviceAccountEmail" name="inputs.serviceAccountEmail"
defaultValue=""
render={({ field, fieldState: { error } }) => ( render={({ field, fieldState: { error } }) => (
<FormControl <FormControl
label="Service Account Email" label="Service Account Email"
@@ -21,9 +21,6 @@ type Props = {
projectSlug: string; projectSlug: string;
environment: string; environment: string;
secretPath: string; secretPath: string;
minTtl?: string; // Optional minimum TTL, defaults to 1min
maxTtl?: string; // Optional maximum TTL, defaults to 1day
defaultTtl?: string; // Optional default TTL, defaults to 1h
}; };
export const RenewDynamicSecretLease = ({ export const RenewDynamicSecretLease = ({
@@ -41,7 +38,7 @@ export const RenewDynamicSecretLease = ({
ttl: z.string().superRefine((val, ctx) => { ttl: z.string().superRefine((val, ctx) => {
if (!val) return; if (!val) return;
const valMs = ms(val); const valMs = ms(val);
if (valMs < 60) if (valMs < 1000)
ctx.addIssue({ ctx.addIssue({
code: z.ZodIssueCode.custom, code: z.ZodIssueCode.custom,
message: "TTL must be greater than 1 second" message: "TTL must be greater than 1 second"