From c5aae44249669387f075c72b822e403225f0cb79 Mon Sep 17 00:00:00 2001 From: Maidul Islam Date: Fri, 7 Jul 2023 18:56:38 -0400 Subject: [PATCH] add docs for k8 secret refs --- docs/integrations/platforms/kubernetes.mdx | 86 +++++++++++++--------- 1 file changed, 51 insertions(+), 35 deletions(-) diff --git a/docs/integrations/platforms/kubernetes.mdx b/docs/integrations/platforms/kubernetes.mdx index d797293a0..62af3aca5 100644 --- a/docs/integrations/platforms/kubernetes.mdx +++ b/docs/integrations/platforms/kubernetes.mdx @@ -39,9 +39,8 @@ The operator can be install via [Helm](helm.sh) or [kubectl](https://github.com/ ## Sync Infisical Secrets to your cluster To retrieve secrets from an Infisical project and save them as native Kubernetes secrets within a specific namespace, utilize the `InfisicalSecret` custom resource definition (CRD). -This resource can be created after installing the Infisical operator. For each new managed secret, you will need to create a new InfisicalSecret CRD. -```yaml +```yaml example-infisical-secret-crd.yaml apiVersion: secrets.infisical.com/v1alpha1 kind: InfisicalSecret metadata: @@ -50,15 +49,18 @@ metadata: spec: # The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used hostAPI: https://app.infisical.com/api - resyncInterval: 60 # <-- the time in seconds between secret re-sync. Faster re-syncs will require higher rate limits + resyncInterval: authentication: serviceToken: serviceTokenSecretReference: secretName: service-token secretNamespace: option + secretsScope: + envSlug: dev + secretsPath: "/" managedSecretReference: secretName: managed-secret # <-- the name of kubernetes secret that will be created - secretNamespace: default # <-- where the kubernetes secret that will be created + secretNamespace: default # <-- where the kubernetes secret should be created ``` ### InfisicalSecret CRD properties @@ -86,45 +88,59 @@ Default re-sync interval is every 1 minute. - The `authentication` property tells the operator where it should look to find credentials needed to fetch secrets from Infisical. + This block defines the method that will be used to authenticate with Infisical so that secrets can be fetched. Currently, only [Service Tokens](../../documentation/platform/token) can be used to authenticate with Infisical. + - - - Authenticating with service tokens is a great option when you have a small number of services you'd like to fetch secrets for and are looking for the least amount of setup. - - #### 1. Generate service token + + The service token required to authenticate with Infisical needs to be stored in a Kubernetes secret. This block defines the reference to the name and name space of secret that stores this service token. + Follow the instructions below to create and store the service token in a Kubernetes secrets and reference it in your CRD. - You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings. + #### 1. Generate service token - #### 2. Create Kubernetes secret containing service token + You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings. - Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated. - To quickly create a Kubernetes secret containing the generated service token, you can run the command below. + #### 2. Create Kubernetes secret containing service token - ``` bash - kubectl create secret generic service-token --from-literal=infisicalToken= - ``` + Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated. + To quickly create a Kubernetes secret containing the generated service token, you can run the command below. Make sure you replace `` with your service token. - #### 3. Add reference for the Kubernetes secret containing service token + ``` bash + kubectl create secret generic service-token --from-literal=infisicalToken= + ``` - Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource. + #### 3. Add reference for the Kubernetes secret containing service token - ## Example - ```yaml - apiVersion: secrets.infisical.com/v1alpha1 - kind: InfisicalSecret - metadata: - name: infisicalsecret-sample-crd - spec: - authentication: - serviceToken: - serviceTokenSecretReference: - secretName: service-token # <-- name of the Kubernetes secret that stores our service token - secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token - ... - ``` - - + Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource. + + ## Example + ```yaml + apiVersion: secrets.infisical.com/v1alpha1 + kind: InfisicalSecret + metadata: + name: infisicalsecret-sample-crd + spec: + authentication: + serviceToken: + serviceTokenSecretReference: + secretName: service-token # <-- name of the Kubernetes secret that stores our service token + secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token + ... + ``` + + + + This block defines the scope of what secrets should be fetched. This is needed as your service token can have access to multiple folders and environments. + A scope is defined by `envSlug` and `secretsPath`. + + #### envSlug + + This refers to the short hand name of an environment. For example for the `development` environment the environment slug is `dev`. You can locate the slug of your environment by heading to your project settings in the Infisical dashboard. + + #### secretsPath + + secretsPath is the path to the secret in the given environment. For example a path of `/` would refer to the root of the environment whereas `/folder1` would refer to the secrets in folder1 from the root. + + Both fields are required.