mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 13:27:46 +00:00
Merge pull request #1319 from Infisical/daniel/better-sdk-docs
(Docs): Improve SDK docs
This commit is contained in:
@@ -16,5 +16,6 @@ Follow the instructions for your language use the SDK for it:
|
|||||||
- [Node SDK](https://infisical.com/docs/sdks/languages/node)
|
- [Node SDK](https://infisical.com/docs/sdks/languages/node)
|
||||||
- [Python SDK](https://infisical.com/docs/sdks/languages/python)
|
- [Python SDK](https://infisical.com/docs/sdks/languages/python)
|
||||||
- [Java SDK](https://infisical.com/docs/sdks/languages/java)
|
- [Java SDK](https://infisical.com/docs/sdks/languages/java)
|
||||||
|
- [.NET SDK](https://infisical.com/docs/sdks/languages/csharp)
|
||||||
|
|
||||||
Missing a language? [Throw in a request](https://github.com/Infisical/infisical/issues).
|
Missing a language? [Throw in a request](https://github.com/Infisical/infisical/issues).
|
||||||
@@ -5,7 +5,7 @@ title: "Node"
|
|||||||
This guide demonstrates how to use Infisical to manage secrets for your Node stack from local development to production. It uses:
|
This guide demonstrates how to use Infisical to manage secrets for your Node stack from local development to production. It uses:
|
||||||
|
|
||||||
- Infisical (you can use [Infisical Cloud](https://app.infisical.com) or a [self-hosted instance of Infisical](https://infisical.com/docs/self-hosting/overview)) to store your secrets.
|
- Infisical (you can use [Infisical Cloud](https://app.infisical.com) or a [self-hosted instance of Infisical](https://infisical.com/docs/self-hosting/overview)) to store your secrets.
|
||||||
- The [infisical-node](https://github.com/Infisical/infisical-node) client SDK to fetch secrets back to your Node application on demand.
|
- The [@infisical/sdk](https://github.com/Infisical/sdk/tree/main/languages/node) Node.js client SDK to fetch secrets back to your Node application on demand.
|
||||||
|
|
||||||
## Project Setup
|
## Project Setup
|
||||||
|
|
||||||
@@ -17,13 +17,11 @@ To begin, we need to set up a project in Infisical and add secrets to an environ
|
|||||||
|
|
||||||
2. Add a secret to the development environment of this project so we can pull it back for local development. In the **Secrets Overview** page, press **Explore Development** and add a secret with the key `NAME` and value `YOUR_NAME`.
|
2. Add a secret to the development environment of this project so we can pull it back for local development. In the **Secrets Overview** page, press **Explore Development** and add a secret with the key `NAME` and value `YOUR_NAME`.
|
||||||
|
|
||||||
### Create an Infisical Token
|
### Create a Machine Identity
|
||||||
|
|
||||||
Now that we've created a project and added a secret to its development environment, we need to provision an Infisical Token that our Node application can use to access the secret.
|
Now that we've created a project and added a secret to its development environment, we need to configure an Infisical Machine Identity that our Node application can use to access the secret.
|
||||||
|
|
||||||
1. Head to the **Project Settings > Service Tokens** and press **Add New Token**.
|
- [How to setup machine identities](/documentation/platform/identities/overview)
|
||||||
2. Call the token anything like **My App Token** and select **Development** under **Environment**.
|
|
||||||
3. Copy the token and keep it handy.
|
|
||||||
|
|
||||||
|
|
||||||
## Create a Node app
|
## Create a Node app
|
||||||
@@ -41,27 +39,43 @@ npm init -y
|
|||||||
Install `express` and [infisical-node](https://github.com/Infisical/infisical-node), the client Node SDK for Infisical.
|
Install `express` and [infisical-node](https://github.com/Infisical/infisical-node), the client Node SDK for Infisical.
|
||||||
|
|
||||||
```console
|
```console
|
||||||
npm install express infisical-node
|
npm install express @infisical/sdk
|
||||||
```
|
```
|
||||||
|
|
||||||
Finally, create an index.js file containing the application code.
|
Finally, create an index.js file containing the application code.
|
||||||
|
|
||||||
```js
|
```js
|
||||||
const express = require("express");
|
const express = require('express');
|
||||||
|
const { InfisicalClient, LogLevel } = require("@infisical/sdk");
|
||||||
|
|
||||||
const app = express();
|
const app = express();
|
||||||
|
|
||||||
const PORT = 3000;
|
const PORT = 3000;
|
||||||
|
|
||||||
const client = new InfisicalClient({
|
const client = new InfisicalClient({
|
||||||
token: "YOUR_INFISICAL_TOKEN"
|
clientId: "YOUR_CLIENT_ID",
|
||||||
|
clientSecret: "YOUR_CLIENT_SECRET",
|
||||||
|
logLevel: LogLevel.Error
|
||||||
});
|
});
|
||||||
|
|
||||||
app.get("/", async (req, res) => {
|
app.get("/", async (req, res) => {
|
||||||
const name = (await client.getSecret("NAME")).secretValue;
|
// access value
|
||||||
res.send(`Hello, ${name}!`);
|
|
||||||
|
const name = await client.getSecret({
|
||||||
|
environment: "dev",
|
||||||
|
projectId: "PROJECT_ID",
|
||||||
|
path: "/",
|
||||||
|
type: "shared",
|
||||||
|
secretName: "NAME"
|
||||||
|
});
|
||||||
|
|
||||||
|
res.send(`Hello! My name is: ${name.secretValue}`);
|
||||||
});
|
});
|
||||||
|
|
||||||
app.listen(PORT, () => {
|
app.listen(PORT, async () => {
|
||||||
console.log(`Example app listening on port ${PORT}`);
|
// initialize client
|
||||||
|
|
||||||
|
console.log(`App listening on port ${port}`);
|
||||||
});
|
});
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -82,13 +96,6 @@ At this stage, you know how to fetch secrets from Infisical back to your Node ap
|
|||||||
## FAQ
|
## FAQ
|
||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="Are my secrets exposed in transit every time the SDK fetches them?">
|
|
||||||
No. Infisical uses end-to-end encryption which ensures that secrets are always encrypted in transit
|
|
||||||
and decrypted on the client side. In fact, not even the server can decrypt your secrets (unless
|
|
||||||
that permission is explicitly granted from within the platform).
|
|
||||||
|
|
||||||
Check out the [security guide](/security/overview).
|
|
||||||
</Accordion>
|
|
||||||
<Accordion title="Isn't it inefficient if my app makes a request every time it needs a secret?">
|
<Accordion title="Isn't it inefficient if my app makes a request every time it needs a secret?">
|
||||||
The client SDK caches every secret and implements a 5-minute waiting period before
|
The client SDK caches every secret and implements a 5-minute waiting period before
|
||||||
re-requesting it. The waiting period can be controlled by setting the `cacheTTL` parameter at
|
re-requesting it. The waiting period can be controlled by setting the `cacheTTL` parameter at
|
||||||
@@ -98,10 +105,6 @@ At this stage, you know how to fetch secrets from Infisical back to your Node ap
|
|||||||
The SDK caches every secret and falls back to the cached value if a request fails. If no cached
|
The SDK caches every secret and falls back to the cached value if a request fails. If no cached
|
||||||
value ever-existed, the SDK falls back to whatever value is on `process.env`.
|
value ever-existed, the SDK falls back to whatever value is on `process.env`.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="Can I still use process.env with the SDK?">
|
|
||||||
Yes. If no `token` parameter is passed in at the time of initializing the client or nothing is found when requesting for a secret,
|
|
||||||
then the SDK falls back to whatever value is on `process.env`.
|
|
||||||
</Accordion>
|
|
||||||
<Accordion title="What's the point if I still have to manage a token for the SDK?">
|
<Accordion title="What's the point if I still have to manage a token for the SDK?">
|
||||||
The token enables the SDK to authenticate with Infisical to fetch back your secrets.
|
The token enables the SDK to authenticate with Infisical to fetch back your secrets.
|
||||||
Although the SDK requires you to pass in a token, it enables greater efficiency and security
|
Although the SDK requires you to pass in a token, it enables greater efficiency and security
|
||||||
@@ -118,4 +121,4 @@ At this stage, you know how to fetch secrets from Infisical back to your Node ap
|
|||||||
|
|
||||||
See also:
|
See also:
|
||||||
|
|
||||||
- Explore the [Node SDK](https://github.com/Infisical/infisical-node)
|
- Explore the [Node SDK](https://github.com/Infisical/sdk/tree/main/languages/node)
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ title: "Python"
|
|||||||
This guide demonstrates how to use Infisical to manage secrets for your Python stack from local development to production. It uses:
|
This guide demonstrates how to use Infisical to manage secrets for your Python stack from local development to production. It uses:
|
||||||
|
|
||||||
- Infisical (you can use [Infisical Cloud](https://app.infisical.com) or a [self-hosted instance of Infisical](https://infisical.com/docs/self-hosting/overview)) to store your secrets.
|
- Infisical (you can use [Infisical Cloud](https://app.infisical.com) or a [self-hosted instance of Infisical](https://infisical.com/docs/self-hosting/overview)) to store your secrets.
|
||||||
- The [infisical-python](https://github.com/Infisical/infisical-python) client SDK to fetch secrets back to your Python application on demand.
|
- The [infisical-python](https://github.com/Infisical/sdk/tree/main/crates/infisical-py) Python client SDK to fetch secrets back to your Python application on demand.
|
||||||
|
|
||||||
## Project Setup
|
## Project Setup
|
||||||
|
|
||||||
@@ -17,13 +17,11 @@ To begin, we need to set up a project in Infisical and add secrets to an environ
|
|||||||
|
|
||||||
2. Add a secret to the development environment of this project so we can pull it back for local development. In the **Secrets Overview** page, press **Explore Development** and add a secret with the key `NAME` and value `YOUR_NAME`.
|
2. Add a secret to the development environment of this project so we can pull it back for local development. In the **Secrets Overview** page, press **Explore Development** and add a secret with the key `NAME` and value `YOUR_NAME`.
|
||||||
|
|
||||||
### Create an Infisical Token
|
### Create a Machine Identity
|
||||||
|
|
||||||
Now that we've created a project and added a secret to its development environment, we need to provision an Infisical Token that our Node application can use to access the secret.
|
Now that we've created a project and added a secret to its development environment, we need to configure an Infisical Machine Identity that our Python application can use to access the secret.
|
||||||
|
|
||||||
1. Head to the **Project Settings > Service Tokens** and press **Add New Token**.
|
- [How to setup machine identities](/documentation/platform/identities/overview)
|
||||||
2. Call the token anything like **My App Token** and select **Development** under **Environment**.
|
|
||||||
3. Copy the token and keep it handy.
|
|
||||||
|
|
||||||
## Create a Python app
|
## Create a Python app
|
||||||
|
|
||||||
@@ -38,27 +36,36 @@ python3 -m venv env
|
|||||||
source env/bin/activate
|
source env/bin/activate
|
||||||
```
|
```
|
||||||
|
|
||||||
Install Flask and [infisical-python](https://github.com/Infisical/infisical-python), the client Python SDK for Infisical.
|
Install Flask and [infisical-python](https://github.com/Infisical/sdk/tree/main/crates/infisical-py), the client Python SDK for Infisical.
|
||||||
|
|
||||||
```console
|
```console
|
||||||
pip install Flask infisical
|
pip install Flask infisical-python
|
||||||
```
|
```
|
||||||
|
|
||||||
Finally, create an `app.py` file containing the application code.
|
Finally, create an `app.py` file containing the application code.
|
||||||
|
|
||||||
```python
|
```py
|
||||||
from flask import Flask
|
from flask import Flask
|
||||||
from infisical import InfisicalClient
|
from infisical_client import ClientSettings, InfisicalClient, GetSecretOptions
|
||||||
|
|
||||||
app = Flask(__name__)
|
app = Flask(__name__)
|
||||||
|
|
||||||
client = InfisicalClient(token="your_infisical_token")
|
client = InfisicalClient(ClientSettings(
|
||||||
|
client_id="MACHINE_IDENTITY_CLIENT_ID",
|
||||||
|
client_secret="MACHINE_IDENTITY_CLIENT_SECRET",
|
||||||
|
))
|
||||||
|
|
||||||
@app.route("/")
|
@app.route("/")
|
||||||
def hello_world():
|
def hello_world():
|
||||||
# access value
|
# access value
|
||||||
name = client.get_secret("NAME")
|
|
||||||
return f"Hello, {name.secret_value}!"
|
name = client.getSecret(options=GetSecretOptions(
|
||||||
|
environment="dev",
|
||||||
|
project_id="PROJECT_ID",
|
||||||
|
secret_name="NAME"
|
||||||
|
))
|
||||||
|
|
||||||
|
return f"Hello! My name is: {name.secret_value}"
|
||||||
```
|
```
|
||||||
|
|
||||||
Here, we initialized a `client` instance of the Infisical Python SDK with the Infisical Token
|
Here, we initialized a `client` instance of the Infisical Python SDK with the Infisical Token
|
||||||
@@ -78,13 +85,6 @@ At this stage, you know how to fetch secrets from Infisical back to your Python
|
|||||||
## FAQ
|
## FAQ
|
||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="Are my secrets exposed in transit every time the SDK fetches them?">
|
|
||||||
No. Infisical uses end-to-end encryption which ensures that secrets are always encrypted in transit
|
|
||||||
and decrypted on the client side. In fact, not even the server can decrypt your secrets (unless
|
|
||||||
that permission is explicitly granted from within the platform).
|
|
||||||
|
|
||||||
Check out the [security guide](/security/overview).
|
|
||||||
</Accordion>
|
|
||||||
<Accordion title="Isn't it inefficient if my app makes a request every time it needs a secret?">
|
<Accordion title="Isn't it inefficient if my app makes a request every time it needs a secret?">
|
||||||
The client SDK caches every secret and implements a 5-minute waiting period before
|
The client SDK caches every secret and implements a 5-minute waiting period before
|
||||||
re-requesting it. The waiting period can be controlled by setting the `cacheTTL` parameter at
|
re-requesting it. The waiting period can be controlled by setting the `cacheTTL` parameter at
|
||||||
@@ -94,10 +94,6 @@ At this stage, you know how to fetch secrets from Infisical back to your Python
|
|||||||
The SDK caches every secret and falls back to the cached value if a request fails. If no cached
|
The SDK caches every secret and falls back to the cached value if a request fails. If no cached
|
||||||
value ever-existed, the SDK falls back to whatever value is on `process.env`.
|
value ever-existed, the SDK falls back to whatever value is on `process.env`.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="Can I still use process.env with the SDK?">
|
|
||||||
Yes. If no `token` parameter is passed in at the time of initializing the client or nothing is found when requesting for a secret,
|
|
||||||
then the SDK falls back to whatever value is on `process.env`.
|
|
||||||
</Accordion>
|
|
||||||
<Accordion title="What's the point if I still have to manage a token for the SDK?">
|
<Accordion title="What's the point if I still have to manage a token for the SDK?">
|
||||||
The token enables the SDK to authenticate with Infisical to fetch back your secrets.
|
The token enables the SDK to authenticate with Infisical to fetch back your secrets.
|
||||||
Although the SDK requires you to pass in a token, it enables greater efficiency and security
|
Although the SDK requires you to pass in a token, it enables greater efficiency and security
|
||||||
@@ -114,6 +110,6 @@ At this stage, you know how to fetch secrets from Infisical back to your Python
|
|||||||
|
|
||||||
See also:
|
See also:
|
||||||
|
|
||||||
- Explore the [Python SDK](https://github.com/Infisical/infisical-python)
|
- Explore the [Python SDK](https://github.com/Infisical/sdk/tree/main/crates/infisical-py)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -32,6 +32,10 @@ From local development to production, Infisical SDKs provide the easiest way for
|
|||||||
|
|
||||||
Note: The exact parameter name may differ depending on the language.
|
Note: The exact parameter name may differ depending on the language.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
<Accordion title="What if a request for a secret fails?">
|
||||||
|
The SDK caches every secret and falls back to the cached value if a request fails. If no cached
|
||||||
|
value ever-existed, the SDK falls back to whatever value is on the process environment.
|
||||||
|
</Accordion>
|
||||||
<Accordion title="Can I attach the environment variables to my process environment?">
|
<Accordion title="Can I attach the environment variables to my process environment?">
|
||||||
Yes you can! The client SDK provides a method to attach the secrets to your process environment. When using the `listSecrets()` method, you
|
Yes you can! The client SDK provides a method to attach the secrets to your process environment. When using the `listSecrets()` method, you
|
||||||
can pass a `attachToProcessEnv` parameter, which tells the SDK to attach all the found secrets to your process environment.
|
can pass a `attachToProcessEnv` parameter, which tells the SDK to attach all the found secrets to your process environment.
|
||||||
|
|||||||
Reference in New Issue
Block a user