diff --git a/docs/integrations/platforms/kubernetes.mdx b/docs/integrations/platforms/kubernetes.mdx
index d797293a0..62af3aca5 100644
--- a/docs/integrations/platforms/kubernetes.mdx
+++ b/docs/integrations/platforms/kubernetes.mdx
@@ -39,9 +39,8 @@ The operator can be install via [Helm](helm.sh) or [kubectl](https://github.com/
## Sync Infisical Secrets to your cluster
To retrieve secrets from an Infisical project and save them as native Kubernetes secrets within a specific namespace, utilize the `InfisicalSecret` custom resource definition (CRD).
-This resource can be created after installing the Infisical operator. For each new managed secret, you will need to create a new InfisicalSecret CRD.
-```yaml
+```yaml example-infisical-secret-crd.yaml
apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret
metadata:
@@ -50,15 +49,18 @@ metadata:
spec:
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
hostAPI: https://app.infisical.com/api
- resyncInterval: 60 # <-- the time in seconds between secret re-sync. Faster re-syncs will require higher rate limits
+ resyncInterval:
authentication:
serviceToken:
serviceTokenSecretReference:
secretName: service-token
secretNamespace: option
+ secretsScope:
+ envSlug: dev
+ secretsPath: "/"
managedSecretReference:
secretName: managed-secret # <-- the name of kubernetes secret that will be created
- secretNamespace: default # <-- where the kubernetes secret that will be created
+ secretNamespace: default # <-- where the kubernetes secret should be created
```
### InfisicalSecret CRD properties
@@ -86,45 +88,59 @@ Default re-sync interval is every 1 minute.
- The `authentication` property tells the operator where it should look to find credentials needed to fetch secrets from Infisical.
+ This block defines the method that will be used to authenticate with Infisical so that secrets can be fetched. Currently, only [Service Tokens](../../documentation/platform/token) can be used to authenticate with Infisical.
+
-
-
- Authenticating with service tokens is a great option when you have a small number of services you'd like to fetch secrets for and are looking for the least amount of setup.
-
- #### 1. Generate service token
+
+ The service token required to authenticate with Infisical needs to be stored in a Kubernetes secret. This block defines the reference to the name and name space of secret that stores this service token.
+ Follow the instructions below to create and store the service token in a Kubernetes secrets and reference it in your CRD.
- You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
+ #### 1. Generate service token
- #### 2. Create Kubernetes secret containing service token
+ You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
- Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
- To quickly create a Kubernetes secret containing the generated service token, you can run the command below.
+ #### 2. Create Kubernetes secret containing service token
- ``` bash
- kubectl create secret generic service-token --from-literal=infisicalToken=
- ```
+ Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
+ To quickly create a Kubernetes secret containing the generated service token, you can run the command below. Make sure you replace `` with your service token.
- #### 3. Add reference for the Kubernetes secret containing service token
+ ``` bash
+ kubectl create secret generic service-token --from-literal=infisicalToken=
+ ```
- Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
+ #### 3. Add reference for the Kubernetes secret containing service token
- ## Example
- ```yaml
- apiVersion: secrets.infisical.com/v1alpha1
- kind: InfisicalSecret
- metadata:
- name: infisicalsecret-sample-crd
- spec:
- authentication:
- serviceToken:
- serviceTokenSecretReference:
- secretName: service-token # <-- name of the Kubernetes secret that stores our service token
- secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
- ...
- ```
-
-
+ Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
+
+ ## Example
+ ```yaml
+ apiVersion: secrets.infisical.com/v1alpha1
+ kind: InfisicalSecret
+ metadata:
+ name: infisicalsecret-sample-crd
+ spec:
+ authentication:
+ serviceToken:
+ serviceTokenSecretReference:
+ secretName: service-token # <-- name of the Kubernetes secret that stores our service token
+ secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
+ ...
+ ```
+
+
+
+ This block defines the scope of what secrets should be fetched. This is needed as your service token can have access to multiple folders and environments.
+ A scope is defined by `envSlug` and `secretsPath`.
+
+ #### envSlug
+
+ This refers to the short hand name of an environment. For example for the `development` environment the environment slug is `dev`. You can locate the slug of your environment by heading to your project settings in the Infisical dashboard.
+
+ #### secretsPath
+
+ secretsPath is the path to the secret in the given environment. For example a path of `/` would refer to the root of the environment whereas `/folder1` would refer to the secrets in folder1 from the root.
+
+ Both fields are required.