mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 14:27:30 +00:00
add docs for k8 secret refs
This commit is contained in:
@@ -39,9 +39,8 @@ The operator can be install via [Helm](helm.sh) or [kubectl](https://github.com/
|
|||||||
|
|
||||||
## Sync Infisical Secrets to your cluster
|
## Sync Infisical Secrets to your cluster
|
||||||
To retrieve secrets from an Infisical project and save them as native Kubernetes secrets within a specific namespace, utilize the `InfisicalSecret` custom resource definition (CRD).
|
To retrieve secrets from an Infisical project and save them as native Kubernetes secrets within a specific namespace, utilize the `InfisicalSecret` custom resource definition (CRD).
|
||||||
This resource can be created after installing the Infisical operator. For each new managed secret, you will need to create a new InfisicalSecret CRD.
|
|
||||||
|
|
||||||
```yaml
|
```yaml example-infisical-secret-crd.yaml
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
kind: InfisicalSecret
|
kind: InfisicalSecret
|
||||||
metadata:
|
metadata:
|
||||||
@@ -50,15 +49,18 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
|
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
|
||||||
hostAPI: https://app.infisical.com/api
|
hostAPI: https://app.infisical.com/api
|
||||||
resyncInterval: 60 # <-- the time in seconds between secret re-sync. Faster re-syncs will require higher rate limits
|
resyncInterval:
|
||||||
authentication:
|
authentication:
|
||||||
serviceToken:
|
serviceToken:
|
||||||
serviceTokenSecretReference:
|
serviceTokenSecretReference:
|
||||||
secretName: service-token
|
secretName: service-token
|
||||||
secretNamespace: option
|
secretNamespace: option
|
||||||
|
secretsScope:
|
||||||
|
envSlug: dev
|
||||||
|
secretsPath: "/"
|
||||||
managedSecretReference:
|
managedSecretReference:
|
||||||
secretName: managed-secret # <-- the name of kubernetes secret that will be created
|
secretName: managed-secret # <-- the name of kubernetes secret that will be created
|
||||||
secretNamespace: default # <-- where the kubernetes secret that will be created
|
secretNamespace: default # <-- where the kubernetes secret should be created
|
||||||
```
|
```
|
||||||
### InfisicalSecret CRD properties
|
### InfisicalSecret CRD properties
|
||||||
|
|
||||||
@@ -86,45 +88,59 @@ Default re-sync interval is every 1 minute.
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="authentication">
|
<Accordion title="authentication">
|
||||||
The `authentication` property tells the operator where it should look to find credentials needed to fetch secrets from Infisical.
|
This block defines the method that will be used to authenticate with Infisical so that secrets can be fetched. Currently, only [Service Tokens](../../documentation/platform/token) can be used to authenticate with Infisical.
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
<Tabs>
|
<Accordion title="authentication.serviceToken.serviceTokenSecretReference">
|
||||||
<Tab title="Service Token">
|
The service token required to authenticate with Infisical needs to be stored in a Kubernetes secret. This block defines the reference to the name and name space of secret that stores this service token.
|
||||||
Authenticating with service tokens is a great option when you have a small number of services you'd like to fetch secrets for and are looking for the least amount of setup.
|
Follow the instructions below to create and store the service token in a Kubernetes secrets and reference it in your CRD.
|
||||||
|
|
||||||
#### 1. Generate service token
|
#### 1. Generate service token
|
||||||
|
|
||||||
You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
|
You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
|
||||||
|
|
||||||
#### 2. Create Kubernetes secret containing service token
|
#### 2. Create Kubernetes secret containing service token
|
||||||
|
|
||||||
Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
|
Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
|
||||||
To quickly create a Kubernetes secret containing the generated service token, you can run the command below.
|
To quickly create a Kubernetes secret containing the generated service token, you can run the command below. Make sure you replace `<your-service-token-here>` with your service token.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
kubectl create secret generic service-token --from-literal=infisicalToken=<your-service-token-here>
|
kubectl create secret generic service-token --from-literal=infisicalToken=<your-service-token-here>
|
||||||
```
|
```
|
||||||
|
|
||||||
#### 3. Add reference for the Kubernetes secret containing service token
|
#### 3. Add reference for the Kubernetes secret containing service token
|
||||||
|
|
||||||
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
|
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
|
||||||
|
|
||||||
## Example
|
## Example
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
kind: InfisicalSecret
|
kind: InfisicalSecret
|
||||||
metadata:
|
metadata:
|
||||||
name: infisicalsecret-sample-crd
|
name: infisicalsecret-sample-crd
|
||||||
spec:
|
spec:
|
||||||
authentication:
|
authentication:
|
||||||
serviceToken:
|
serviceToken:
|
||||||
serviceTokenSecretReference:
|
serviceTokenSecretReference:
|
||||||
secretName: service-token # <-- name of the Kubernetes secret that stores our service token
|
secretName: service-token # <-- name of the Kubernetes secret that stores our service token
|
||||||
secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
|
secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
|
||||||
...
|
...
|
||||||
```
|
```
|
||||||
</Tab>
|
</Accordion>
|
||||||
</Tabs>
|
|
||||||
|
<Accordion title="authentication.serviceToken.secretsScope">
|
||||||
|
This block defines the scope of what secrets should be fetched. This is needed as your service token can have access to multiple folders and environments.
|
||||||
|
A scope is defined by `envSlug` and `secretsPath`.
|
||||||
|
|
||||||
|
#### envSlug
|
||||||
|
|
||||||
|
This refers to the short hand name of an environment. For example for the `development` environment the environment slug is `dev`. You can locate the slug of your environment by heading to your project settings in the Infisical dashboard.
|
||||||
|
|
||||||
|
#### secretsPath
|
||||||
|
|
||||||
|
secretsPath is the path to the secret in the given environment. For example a path of `/` would refer to the root of the environment whereas `/folder1` would refer to the secrets in folder1 from the root.
|
||||||
|
|
||||||
|
Both fields are required.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="managedSecretReference">
|
<Accordion title="managedSecretReference">
|
||||||
|
|||||||
Reference in New Issue
Block a user