add docs for k8 secret refs

This commit is contained in:
Maidul Islam
2023-07-07 18:56:38 -04:00
parent 83aa6127ec
commit c5aae44249
+51 -35
View File
@@ -39,9 +39,8 @@ The operator can be install via [Helm](helm.sh) or [kubectl](https://github.com/
## Sync Infisical Secrets to your cluster ## Sync Infisical Secrets to your cluster
To retrieve secrets from an Infisical project and save them as native Kubernetes secrets within a specific namespace, utilize the `InfisicalSecret` custom resource definition (CRD). To retrieve secrets from an Infisical project and save them as native Kubernetes secrets within a specific namespace, utilize the `InfisicalSecret` custom resource definition (CRD).
This resource can be created after installing the Infisical operator. For each new managed secret, you will need to create a new InfisicalSecret CRD.
```yaml ```yaml example-infisical-secret-crd.yaml
apiVersion: secrets.infisical.com/v1alpha1 apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret kind: InfisicalSecret
metadata: metadata:
@@ -50,15 +49,18 @@ metadata:
spec: spec:
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used # The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
hostAPI: https://app.infisical.com/api hostAPI: https://app.infisical.com/api
resyncInterval: 60 # <-- the time in seconds between secret re-sync. Faster re-syncs will require higher rate limits resyncInterval:
authentication: authentication:
serviceToken: serviceToken:
serviceTokenSecretReference: serviceTokenSecretReference:
secretName: service-token secretName: service-token
secretNamespace: option secretNamespace: option
secretsScope:
envSlug: dev
secretsPath: "/"
managedSecretReference: managedSecretReference:
secretName: managed-secret # <-- the name of kubernetes secret that will be created secretName: managed-secret # <-- the name of kubernetes secret that will be created
secretNamespace: default # <-- where the kubernetes secret that will be created secretNamespace: default # <-- where the kubernetes secret should be created
``` ```
### InfisicalSecret CRD properties ### InfisicalSecret CRD properties
@@ -86,45 +88,59 @@ Default re-sync interval is every 1 minute.
</Accordion> </Accordion>
<Accordion title="authentication"> <Accordion title="authentication">
The `authentication` property tells the operator where it should look to find credentials needed to fetch secrets from Infisical. This block defines the method that will be used to authenticate with Infisical so that secrets can be fetched. Currently, only [Service Tokens](../../documentation/platform/token) can be used to authenticate with Infisical.
</Accordion>
<Tabs> <Accordion title="authentication.serviceToken.serviceTokenSecretReference">
<Tab title="Service Token"> The service token required to authenticate with Infisical needs to be stored in a Kubernetes secret. This block defines the reference to the name and name space of secret that stores this service token.
Authenticating with service tokens is a great option when you have a small number of services you'd like to fetch secrets for and are looking for the least amount of setup. Follow the instructions below to create and store the service token in a Kubernetes secrets and reference it in your CRD.
#### 1. Generate service token
You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings. #### 1. Generate service token
#### 2. Create Kubernetes secret containing service token You can generate a [service token](../../documentation/platform/token) for an Infisical project by heading over to the Infisical dashboard then to Project Settings.
Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated. #### 2. Create Kubernetes secret containing service token
To quickly create a Kubernetes secret containing the generated service token, you can run the command below.
``` bash Once you have generated the service token, you will need to create a Kubernetes secret containing the service token you generated.
kubectl create secret generic service-token --from-literal=infisicalToken=<your-service-token-here> To quickly create a Kubernetes secret containing the generated service token, you can run the command below. Make sure you replace `<your-service-token-here>` with your service token.
```
#### 3. Add reference for the Kubernetes secret containing service token ``` bash
kubectl create secret generic service-token --from-literal=infisicalToken=<your-service-token-here>
```
Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource. #### 3. Add reference for the Kubernetes secret containing service token
## Example Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.serviceTokenSecretReference` field in the InfisicalSecret resource.
```yaml
apiVersion: secrets.infisical.com/v1alpha1 ## Example
kind: InfisicalSecret ```yaml
metadata: apiVersion: secrets.infisical.com/v1alpha1
name: infisicalsecret-sample-crd kind: InfisicalSecret
spec: metadata:
authentication: name: infisicalsecret-sample-crd
serviceToken: spec:
serviceTokenSecretReference: authentication:
secretName: service-token # <-- name of the Kubernetes secret that stores our service token serviceToken:
secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token serviceTokenSecretReference:
... secretName: service-token # <-- name of the Kubernetes secret that stores our service token
``` secretNamespace: option # <-- namespace of the Kubernetes secret that stores our service token
</Tab> ...
</Tabs> ```
</Accordion>
<Accordion title="authentication.serviceToken.secretsScope">
This block defines the scope of what secrets should be fetched. This is needed as your service token can have access to multiple folders and environments.
A scope is defined by `envSlug` and `secretsPath`.
#### envSlug
This refers to the short hand name of an environment. For example for the `development` environment the environment slug is `dev`. You can locate the slug of your environment by heading to your project settings in the Infisical dashboard.
#### secretsPath
secretsPath is the path to the secret in the given environment. For example a path of `/` would refer to the root of the environment whereas `/folder1` would refer to the secrets in folder1 from the root.
Both fields are required.
</Accordion> </Accordion>
<Accordion title="managedSecretReference"> <Accordion title="managedSecretReference">