diff --git a/docs/documentation/platform/dynamic-secrets/kubernetes.mdx b/docs/documentation/platform/dynamic-secrets/kubernetes.mdx index f1e5948fa..d6d051ff7 100644 --- a/docs/documentation/platform/dynamic-secrets/kubernetes.mdx +++ b/docs/documentation/platform/dynamic-secrets/kubernetes.mdx @@ -47,7 +47,7 @@ The RBAC configuration serves a crucial security purpose: it creates a dedicated The following RBAC configuration creates the necessary permissions for generating service account tokens: -```yaml +```yaml rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: @@ -75,6 +75,10 @@ subjects: namespace: default ``` +```bash +kubectl apply -f rbac.yaml +``` + This configuration: 1. Creates a `ClusterRole` named `tokenrequest` that allows: @@ -132,6 +136,22 @@ kubectl get secret infisical-token-requester-token -n default -o=jsonpath='{.dat This token will be used as the "Cluster Token" in the dynamic secret configuration. +## Obtaining the Cluster URL + +The cluster URL is the address of your Kubernetes API server. The simplest way to find it is to use the `kubectl cluster-info` command: + +```bash +kubectl cluster-info +``` + +This command works for all Kubernetes environments (managed services like GKE, EKS, AKS, or self-hosted clusters) and will show you the Kubernetes control plane address, which is your cluster URL. + + + Make sure the cluster URL is accessible from where you're running Infisical. + If you're using a private cluster, you'll need to configure a [Gateway](/documentation/platform/gateways/overview) to + access it. + + ## Set up Dynamic Secrets with Kubernetes @@ -157,7 +177,7 @@ This token will be used as the "Cluster Token" in the dynamic secret configurati Select a gateway for private cluster access. If not specified, the Internet Gateway will be used. - + Kubernetes API server URL (e.g., https://kubernetes.default.svc) diff --git a/docs/images/platform/dynamic-secrets/dynamic-secret-setup-modal-kubernetes.png b/docs/images/platform/dynamic-secrets/dynamic-secret-setup-modal-kubernetes.png index 418da1d7a..011dfadc7 100644 Binary files a/docs/images/platform/dynamic-secrets/dynamic-secret-setup-modal-kubernetes.png and b/docs/images/platform/dynamic-secrets/dynamic-secret-setup-modal-kubernetes.png differ