This commit is contained in:
Daniel Hougaard
2024-06-15 02:35:04 +02:00
parent 93638baba7
commit c119f506fd
+17 -14
View File
@@ -41,20 +41,23 @@ It then formats these secrets using the user provided templates and writes the f
To set up the authentication method for token renewal and to define secret templates, the Infisical agent requires a YAML configuration file containing properties defined below. To set up the authentication method for token renewal and to define secret templates, the Infisical agent requires a YAML configuration file containing properties defined below.
While specifying an authentication method is mandatory to start the agent, configuring sinks and secret templates are optional. While specifying an authentication method is mandatory to start the agent, configuring sinks and secret templates are optional.
| Field | Description | | Field | Description |
| ---------------------------- | ----------- | | ------------------------------------------------| ----------------------------- |
| `infisical.address` | The URL of the Infisical service. Default: `"https://app.infisical.com"`. | | `infisical.address` | The URL of the Infisical service. Default: `"https://app.infisical.com"`. |
| `auth.type` | The type of authentication method used. Only `"universal-auth"` type is currently available | | `auth.type` | The type of authentication method used. Available options: `universal-auth`, `kubernetes`, `azure`, `gcp-id-token`, `gcp-iam`, `aws-iam`|
| `auth.config.client-id` | The file path where the universal-auth client id is stored. | | `auth.config.identity-id` | The file path where the machine identity id is stored<br/><br/>This field is required when using any of the following auth types: `kubernetes`, `azure`, `gcp-id-token`, `gcp-iam`, or `aws-iam`. |
| `auth.config.client-secret` | The file path where the universal-auth client secret is stored. | | `auth.config.service-account-token` | Path to the Kubernetes service account token to use (optional)<br/><br/>Default: `/var/run/secrets/kubernetes.io/serviceaccount/token` |
| `auth.config.remove_client_secret_on_read` | This will instruct the agent to remove the client secret from disk. | | `auth.config.service-account-key` | Path to your GCP service account key file. This field is required when using `gcp-iam` auth type.<br/><br/>Please note that the file should be in JSON format. |
| `sinks[].type` | The type of sink in a list of sinks. Each item specifies a sink type. Currently, only `"file"` type is available. | | `auth.config.client-id` | The file path where the universal-auth client id is stored. |
| `sinks[].config.path` | The file path where the access token should be stored for each sink in the list. | | `auth.config.client-secret` | The file path where the universal-auth client secret is stored. |
| `templates[].source-path` | The path to the template file that should be used to render secrets. | | `auth.config.remove_client_secret_on_read` | This will instruct the agent to remove the client secret from disk. |
| `templates[].destination-path` | The path where the rendered secrets from the source template will be saved to. | | `sinks[].type` | The type of sink in a list of sinks. Each item specifies a sink type. Currently, only `"file"` type is available. |
| `templates[].config.polling-interval` | How frequently to check for secret changes. Default: `5 minutes` (optional) | | `sinks[].config.path` | The file path where the access token should be stored for each sink in the list. |
| `templates[].config.execute.command` | The command to execute when secret change is detected (optional) | | `templates[].source-path` | The path to the template file that should be used to render secrets. |
| `templates[].config.execute.timeout` | How long in seconds to wait for command to execute before timing out (optional) | | `templates[].destination-path` | The path where the rendered secrets from the source template will be saved to. |
| `templates[].config.polling-interval` | How frequently to check for secret changes. Default: `5 minutes` (optional) |
| `templates[].config.execute.command` | The command to execute when secret change is detected (optional) |
| `templates[].config.execute.timeout` | How long in seconds to wait for command to execute before timing out (optional) |
## Quick start Infisical Agent ## Quick start Infisical Agent