mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 16:27:46 +00:00
Merge pull request #1882 from Infisical/daniel/azure-auth-sdk-docs
Docs: Azure & Kubernetes auth SDK documentation
This commit is contained in:
@@ -46,16 +46,19 @@ Finally, create an index.js file containing the application code.
|
|||||||
|
|
||||||
```js
|
```js
|
||||||
const express = require('express');
|
const express = require('express');
|
||||||
const { InfisicalClient, LogLevel } = require("@infisical/sdk");
|
const { InfisicalClient } = require("@infisical/sdk");
|
||||||
|
|
||||||
const app = express();
|
const app = express();
|
||||||
|
|
||||||
const PORT = 3000;
|
const PORT = 3000;
|
||||||
|
|
||||||
const client = new InfisicalClient({
|
const client = new InfisicalClient({
|
||||||
clientId: "YOUR_CLIENT_ID",
|
auth: {
|
||||||
clientSecret: "YOUR_CLIENT_SECRET",
|
universalAuth: {
|
||||||
logLevel: LogLevel.Error
|
clientId: "YOUR_CLIENT_ID",
|
||||||
|
clientSecret: "YOUR_CLIENT_SECRET",
|
||||||
|
}
|
||||||
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
app.get("/", async (req, res) => {
|
app.get("/", async (req, res) => {
|
||||||
|
|||||||
@@ -228,6 +228,61 @@ The SDK supports a variety of authentication methods. The most common authentica
|
|||||||
var infisicalClient = new InfisicalClient(settings);
|
var infisicalClient = new InfisicalClient(settings);
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
|
#### Azure Auth
|
||||||
|
<Info>
|
||||||
|
Please note that this authentication method will only work if you're running your application on Azure.
|
||||||
|
Please [read more](/documentation/platform/identities/azure-auth) about this authentication method.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Using environment variables**
|
||||||
|
- `INFISICAL_AZURE_AUTH_IDENTITY_ID` - Your Infisical Machine Identity ID.
|
||||||
|
|
||||||
|
**Using the SDK directly**
|
||||||
|
```csharp
|
||||||
|
ClientSettings settings = new ClientSettings
|
||||||
|
{
|
||||||
|
Auth = new AuthenticationOptions
|
||||||
|
{
|
||||||
|
Azure = new AzureAuthMethod
|
||||||
|
{
|
||||||
|
IdentityId = "YOUR_IDENTITY_ID",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
var infisicalClient = new InfisicalClient(settings);
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Kubernetes Auth
|
||||||
|
<Info>
|
||||||
|
Please note that this authentication method will only work if you're running your application on Kubernetes.
|
||||||
|
Please [read more](/documentation/platform/identities/kubernetes-auth) about this authentication method.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Using environment variables**
|
||||||
|
- `INFISICAL_KUBERNETES_IDENTITY_ID` - Your Infisical Machine Identity ID.
|
||||||
|
- `INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH_ENV_NAME` - The environment variable name that contains the path to the service account token. This is optional and will default to `/var/run/secrets/kubernetes.io/serviceaccount/token`.
|
||||||
|
|
||||||
|
**Using the SDK directly**
|
||||||
|
```csharp
|
||||||
|
ClientSettings settings = new ClientSettings
|
||||||
|
{
|
||||||
|
Auth = new AuthenticationOptions
|
||||||
|
{
|
||||||
|
Kubernetes = new KubernetesAuthMethod
|
||||||
|
{
|
||||||
|
ServiceAccountTokenPath = "/var/run/secrets/kubernetes.io/serviceaccount/token", // Optional
|
||||||
|
IdentityId = "YOUR_IDENTITY_ID",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
var infisicalClient = new InfisicalClient(settings);
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
### Caching
|
### Caching
|
||||||
|
|
||||||
To reduce the number of API requests, the SDK temporarily stores secrets it retrieves. By default, a secret remains cached for 5 minutes after it's first fetched. Each time it's fetched again, this 5-minute timer resets. You can adjust this caching duration by setting the "cacheTTL" option when creating the client.
|
To reduce the number of API requests, the SDK temporarily stores secrets it retrieves. By default, a secret remains cached for 5 minutes after it's first fetched. Each time it's fetched again, this 5-minute timer resets. You can adjust this caching duration by setting the "cacheTTL" option when creating the client.
|
||||||
|
|||||||
@@ -221,6 +221,55 @@ The SDK supports a variety of authentication methods. The most common authentica
|
|||||||
InfisicalClient client = new InfisicalClient(settings);
|
InfisicalClient client = new InfisicalClient(settings);
|
||||||
```
|
```
|
||||||
|
|
||||||
|
#### Azure Auth
|
||||||
|
<Info>
|
||||||
|
Please note that this authentication method will only work if you're running your application on Azure.
|
||||||
|
Please [read more](/documentation/platform/identities/azure-auth) about this authentication method.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Using environment variables**
|
||||||
|
- `INFISICAL_AZURE_AUTH_IDENTITY_ID` - Your Infisical Machine Identity ID.
|
||||||
|
|
||||||
|
**Using the SDK directly**
|
||||||
|
```java
|
||||||
|
ClientSettings settings = new ClientSettings();
|
||||||
|
AuthenticationOptions authOptions = new AuthenticationOptions();
|
||||||
|
AzureAuthMethod authMethod = new AzureAuthMethod();
|
||||||
|
|
||||||
|
authMethod.setIdentityID("YOUR_IDENTITY_ID");
|
||||||
|
|
||||||
|
authOptions.setAzure(authMethod);
|
||||||
|
settings.setAuth(authOptions);
|
||||||
|
|
||||||
|
InfisicalClient client = new InfisicalClient(settings);
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Kubernetes Auth
|
||||||
|
<Info>
|
||||||
|
Please note that this authentication method will only work if you're running your application on Kubernetes.
|
||||||
|
Please [read more](/documentation/platform/identities/kubernetes-auth) about this authentication method.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Using environment variables**
|
||||||
|
- `INFISICAL_KUBERNETES_IDENTITY_ID` - Your Infisical Machine Identity ID.
|
||||||
|
- `INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH_ENV_NAME` - The environment variable name that contains the path to the service account token. This is optional and will default to `/var/run/secrets/kubernetes.io/serviceaccount/token`.
|
||||||
|
|
||||||
|
**Using the SDK directly**
|
||||||
|
```java
|
||||||
|
ClientSettings settings = new ClientSettings();
|
||||||
|
AuthenticationOptions authOptions = new AuthenticationOptions();
|
||||||
|
KubernetesAuthMethod authMethod = new KubernetesAuthMethod();
|
||||||
|
|
||||||
|
authMethod.setIdentityID("YOUR_IDENTITY_ID");
|
||||||
|
authMethod.setServiceAccountTokenPath("/var/run/secrets/kubernetes.io/serviceaccount/token"); // Optional
|
||||||
|
|
||||||
|
authOptions.setKubernetes(authMethod);
|
||||||
|
settings.setAuth(authOptions);
|
||||||
|
|
||||||
|
InfisicalClient client = new InfisicalClient(settings);
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
### Caching
|
### Caching
|
||||||
|
|
||||||
To reduce the number of API requests, the SDK temporarily stores secrets it retrieves. By default, a secret remains cached for 5 minutes after it's first fetched. Each time it's fetched again, this 5-minute timer resets. You can adjust this caching duration by setting the "cacheTTL" option when creating the client.
|
To reduce the number of API requests, the SDK temporarily stores secrets it retrieves. By default, a secret remains cached for 5 minutes after it's first fetched. Each time it's fetched again, this 5-minute timer resets. You can adjust this caching duration by setting the "cacheTTL" option when creating the client.
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ If you're working with Node.js, the official [Infisical Node SDK](https://github
|
|||||||
```js
|
```js
|
||||||
import express from "express";
|
import express from "express";
|
||||||
|
|
||||||
import { InfisicalClient, LogLevel } from "@infisical/sdk";
|
import { InfisicalClient } from "@infisical/sdk";
|
||||||
|
|
||||||
const app = express();
|
const app = express();
|
||||||
|
|
||||||
@@ -27,8 +27,7 @@ const client = new InfisicalClient({
|
|||||||
clientId: "YOUR_CLIENT_ID",
|
clientId: "YOUR_CLIENT_ID",
|
||||||
clientSecret: "YOUR_CLIENT_SECRET"
|
clientSecret: "YOUR_CLIENT_SECRET"
|
||||||
}
|
}
|
||||||
},
|
}
|
||||||
logLevel: LogLevel.Error
|
|
||||||
});
|
});
|
||||||
|
|
||||||
app.get("/", async (req, res) => {
|
app.get("/", async (req, res) => {
|
||||||
@@ -226,7 +225,48 @@ const client = new InfisicalClient({
|
|||||||
});
|
});
|
||||||
```
|
```
|
||||||
|
|
||||||
|
#### Azure Auth
|
||||||
|
<Info>
|
||||||
|
Please note that this authentication method will only work if you're running your application on Azure.
|
||||||
|
Please [read more](/documentation/platform/identities/azure-auth) about this authentication method.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Using environment variables**
|
||||||
|
- `INFISICAL_AZURE_AUTH_IDENTITY_ID` - Your Infisical Machine Identity ID.
|
||||||
|
|
||||||
|
**Using the SDK directly**
|
||||||
|
```js
|
||||||
|
const client = new InfisicalClient({
|
||||||
|
auth: {
|
||||||
|
azure: {
|
||||||
|
identityId: "YOUR_IDENTITY_ID"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
#### Kubernetes Auth
|
||||||
|
<Info>
|
||||||
|
Please note that this authentication method will only work if you're running your application on Kubernetes.
|
||||||
|
Please [read more](/documentation/platform/identities/kubernetes-auth) about this authentication method.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Using environment variables**
|
||||||
|
- `INFISICAL_KUBERNETES_IDENTITY_ID` - Your Infisical Machine Identity ID.
|
||||||
|
- `INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH_ENV_NAME` - The environment variable name that contains the path to the service account token. This is optional and will default to `/var/run/secrets/kubernetes.io/serviceaccount/token`.
|
||||||
|
|
||||||
|
**Using the SDK directly**
|
||||||
|
```js
|
||||||
|
const client = new InfisicalClient({
|
||||||
|
auth: {
|
||||||
|
kubernetes: {
|
||||||
|
identityId: "YOUR_IDENTITY_ID",
|
||||||
|
serviceAccountTokenPathEnvName: "/var/run/secrets/kubernetes.io/serviceaccount/token" // Optional
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
### Caching
|
### Caching
|
||||||
|
|
||||||
|
|||||||
@@ -201,6 +201,53 @@ client = InfisicalClient(ClientSettings(
|
|||||||
))
|
))
|
||||||
```
|
```
|
||||||
|
|
||||||
|
#### Azure Auth
|
||||||
|
<Info>
|
||||||
|
Please note that this authentication method will only work if you're running your application on Azure.
|
||||||
|
Please [read more](/documentation/platform/identities/azure-auth) about this authentication method.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Using environment variables**
|
||||||
|
- `INFISICAL_AZURE_AUTH_IDENTITY_ID` - Your Infisical Machine Identity ID.
|
||||||
|
|
||||||
|
**Using the SDK directly**
|
||||||
|
```python
|
||||||
|
from infisical_client import InfisicalClient, ClientSettings, AuthenticationOptions, AzureAuthMethod
|
||||||
|
|
||||||
|
kubernetes_client = InfisicalClient(ClientSettings(
|
||||||
|
auth=AuthenticationOptions(
|
||||||
|
azure=AzureAuthMethod(
|
||||||
|
identity_id="YOUR_IDENTITY_ID",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
))
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
#### Kubernetes Auth
|
||||||
|
<Info>
|
||||||
|
Please note that this authentication method will only work if you're running your application on Kubernetes.
|
||||||
|
Please [read more](/documentation/platform/identities/kubernetes-auth) about this authentication method.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
**Using environment variables**
|
||||||
|
- `INFISICAL_KUBERNETES_IDENTITY_ID` - Your Infisical Machine Identity ID.
|
||||||
|
- `INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH_ENV_NAME` - The environment variable name that contains the path to the service account token. This is optional and will default to `/var/run/secrets/kubernetes.io/serviceaccount/token`.
|
||||||
|
|
||||||
|
**Using the SDK directly**
|
||||||
|
```python
|
||||||
|
from infisical_client import InfisicalClient, ClientSettings, AuthenticationOptions, KubernetesAuthMethod
|
||||||
|
|
||||||
|
kubernetes_client = InfisicalClient(ClientSettings(
|
||||||
|
auth=AuthenticationOptions(
|
||||||
|
kubernetes=KubernetesAuthMethod(
|
||||||
|
identity_id="YOUR_IDENTITY_ID",
|
||||||
|
service_account_token_path="/var/run/secrets/kubernetes.io/serviceaccount/token" # Optional
|
||||||
|
)
|
||||||
|
)
|
||||||
|
))
|
||||||
|
```
|
||||||
|
|
||||||
### Caching
|
### Caching
|
||||||
|
|
||||||
To reduce the number of API requests, the SDK temporarily stores secrets it retrieves. By default, a secret remains cached for 5 minutes after it's first fetched. Each time it's fetched again, this 5-minute timer resets. You can adjust this caching duration by setting the "cache_ttl" option when creating the client.
|
To reduce the number of API requests, the SDK temporarily stores secrets it retrieves. By default, a secret remains cached for 5 minutes after it's first fetched. Each time it's fetched again, this 5-minute timer resets. You can adjust this caching duration by setting the "cache_ttl" option when creating the client.
|
||||||
|
|||||||
Reference in New Issue
Block a user