mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 08:27:36 +00:00
docs
This commit is contained in:
@@ -14,7 +14,7 @@ ACME is a protocol that automates the process of certificate issuance and renewa
|
|||||||
```mermaid
|
```mermaid
|
||||||
graph TD
|
graph TD
|
||||||
A[ACME CA Provider<br>e.g., Let's Encrypt] <-->|ACME v2 Protocol| B[Infisical]
|
A[ACME CA Provider<br>e.g., Let's Encrypt] <-->|ACME v2 Protocol| B[Infisical]
|
||||||
B -->|Creates TXT Records<br>via Route53| C[DNS Validation]
|
B -->|Creates TXT Records<br>via Route53/Cloudflare| C[DNS Validation]
|
||||||
B -->|Manages Certificates| D[Subscribers]
|
B -->|Manages Certificates| D[Subscribers]
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -28,8 +28,8 @@ We recommend reading about [ACME protocol](https://tools.ietf.org/html/rfc8555)
|
|||||||
|
|
||||||
A typical workflow for using Infisical with ACME Certificate Authorities consists of the following steps:
|
A typical workflow for using Infisical with ACME Certificate Authorities consists of the following steps:
|
||||||
|
|
||||||
1. Setting up AWS Route53 credentials with appropriate DNS permissions.
|
1. Setting up AWS Route53 or Cloudflare credentials with appropriate DNS permissions.
|
||||||
2. Creating an AWS connection in Infisical to store the Route53 credentials.
|
2. Creating an AWS connection in Infisical to store the Route53/Cloudflare credentials.
|
||||||
3. Registering an ACME Certificate Authority (like Let's Encrypt) with Infisical.
|
3. Registering an ACME Certificate Authority (like Let's Encrypt) with Infisical.
|
||||||
4. Creating subscribers that use the ACME CA as their issuing authority.
|
4. Creating subscribers that use the ACME CA as their issuing authority.
|
||||||
5. Managing certificate lifecycle events such as issuance, renewal, and revocation through Infisical.
|
5. Managing certificate lifecycle events such as issuance, renewal, and revocation through Infisical.
|
||||||
@@ -55,59 +55,75 @@ This automated process eliminates the need for manual intervention in domain val
|
|||||||
In the following steps, we explore how to set up ACME Certificate Authority integration with Infisical using Let's Encrypt as an example.
|
In the following steps, we explore how to set up ACME Certificate Authority integration with Infisical using Let's Encrypt as an example.
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Set Up AWS Connection with Required Permissions">
|
<Step title="Create App Connection with Required Permissions">
|
||||||
Before proceeding with the ACME CA registration, you need to set up an AWS connection with the appropriate permissions for DNS validation:
|
Before proceeding with the ACME CA registration, you need to set up an App Connection with the appropriate permissions for DNS validation:
|
||||||
|
|
||||||
1. Navigate to your Organization Settings > App Connections and create a new AWS connection.
|
<Tabs>
|
||||||
|
<Tab title="Route53">
|
||||||
|
1. Navigate to your Organization Settings > App Connections and create a new AWS connection.
|
||||||
|
|
||||||
2. Ensure your AWS connection has the following minimum permissions for Route53 DNS validation:
|
2. Ensure your AWS connection has the following minimum permissions for Route53 DNS validation:
|
||||||
|
|
||||||
```json
|
```json
|
||||||
{
|
{
|
||||||
"Version": "2012-10-17",
|
"Version": "2012-10-17",
|
||||||
"Statement": [
|
"Statement": [
|
||||||
{
|
{
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Action": "route53:GetChange",
|
"Action": "route53:GetChange",
|
||||||
"Resource": "arn:aws:route53:::change/*"
|
"Resource": "arn:aws:route53:::change/*"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Action": "route53:ListHostedZonesByName",
|
"Action": "route53:ListHostedZonesByName",
|
||||||
"Resource": "*"
|
"Resource": "*"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Action": [
|
"Action": [
|
||||||
"route53:ListResourceRecordSets"
|
"route53:ListResourceRecordSets"
|
||||||
],
|
],
|
||||||
"Resource": [
|
"Resource": [
|
||||||
"arn:aws:route53:::hostedzone/YOUR_HOSTED_ZONE_ID"
|
"arn:aws:route53:::hostedzone/YOUR_HOSTED_ZONE_ID"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Action": [
|
"Action": [
|
||||||
"route53:ChangeResourceRecordSets"
|
"route53:ChangeResourceRecordSets"
|
||||||
],
|
],
|
||||||
"Resource": [
|
"Resource": [
|
||||||
"arn:aws:route53:::hostedzone/YOUR_HOSTED_ZONE_ID"
|
"arn:aws:route53:::hostedzone/YOUR_HOSTED_ZONE_ID"
|
||||||
],
|
],
|
||||||
"Condition": {
|
"Condition": {
|
||||||
"ForAllValues:StringEquals": {
|
"ForAllValues:StringEquals": {
|
||||||
"route53:ChangeResourceRecordSetsRecordTypes": [
|
"route53:ChangeResourceRecordSetsRecordTypes": [
|
||||||
"TXT"
|
"TXT"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
}
|
```
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
Replace `YOUR_HOSTED_ZONE_ID` with your actual Route53 hosted zone ID.
|
Replace `YOUR_HOSTED_ZONE_ID` with your actual Route53 hosted zone ID.
|
||||||
|
|
||||||
For detailed instructions on setting up an AWS connection, see the [AWS Connection](/integrations/app-connections/aws) documentation.
|
For detailed instructions on setting up an AWS connection, see the [AWS Connection](/integrations/app-connections/aws) documentation.
|
||||||
|
</Tab>
|
||||||
|
<Tab title="Cloudflare">
|
||||||
|
1. Navigate to your Organization Settings > App Connections and create a new Cloudflare connection.
|
||||||
|
|
||||||
|
2. Ensure your Cloudflare token has the following minimum permissions for DNS validation:
|
||||||
|
|
||||||
|
```
|
||||||
|
Account:Account Settings:Read
|
||||||
|
Zone:DNS:Edit
|
||||||
|
```
|
||||||
|
|
||||||
|
For detailed instructions on setting up a Cloudflare connection, see the [Cloudflare Connection](/integrations/app-connections/cloudflare) documentation.
|
||||||
|
</Tab>
|
||||||
|
</Tabs>
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Register ACME Certificate Authority">
|
<Step title="Register ACME Certificate Authority">
|
||||||
<Tabs>
|
<Tabs>
|
||||||
@@ -127,7 +143,7 @@ In the following steps, we explore how to set up ACME Certificate Authority inte
|
|||||||
- **Type**: Select "ACME" as the External CA type.
|
- **Type**: Select "ACME" as the External CA type.
|
||||||
- **Name**: Enter a name for the ACME CA (e.g., "lets-encrypt-production").
|
- **Name**: Enter a name for the ACME CA (e.g., "lets-encrypt-production").
|
||||||
- **DNS App Connection**: Select from available DNS app connections or configure a new one. This connection provides Infisical with the credentials needed to create and remove DNS records for ACME validation.
|
- **DNS App Connection**: Select from available DNS app connections or configure a new one. This connection provides Infisical with the credentials needed to create and remove DNS records for ACME validation.
|
||||||
- **Hosted Zone ID**: Enter your Route53 hosted zone ID (e.g., Z04044I124N1GOOMCOYX1) for the domain(s) you'll be requesting certificates for.
|
- **Zone ID**: Enter your Route53 hosted zone ID (e.g., Z04044I124N1GOOMCOYX1) or select your Cloudflare Zone for the domain(s) you'll be requesting certificates for.
|
||||||
- **Directory URL**: Enter the ACME v2 directory URL for your chosen CA provider (e.g., `https://acme-v02.api.letsencrypt.org/directory` for Let's Encrypt).
|
- **Directory URL**: Enter the ACME v2 directory URL for your chosen CA provider (e.g., `https://acme-v02.api.letsencrypt.org/directory` for Let's Encrypt).
|
||||||
- **Account Email**: Email address to associate with your ACME account. This email will receive important notifications about your certificates.
|
- **Account Email**: Email address to associate with your ACME account. This email will receive important notifications about your certificates.
|
||||||
- **Enable Direct Issuance**: Toggle on to allow direct certificate issuance without requiring subscribers.
|
- **Enable Direct Issuance**: Toggle on to allow direct certificate issuance without requiring subscribers.
|
||||||
@@ -226,7 +242,7 @@ In the following steps, we explore how to set up ACME Certificate Authority inte
|
|||||||
1. Infisical generates a key pair for the certificate
|
1. Infisical generates a key pair for the certificate
|
||||||
2. Sends a Certificate Signing Request (CSR) to the ACME CA
|
2. Sends a Certificate Signing Request (CSR) to the ACME CA
|
||||||
3. Receives a DNS-01 challenge from the ACME provider
|
3. Receives a DNS-01 challenge from the ACME provider
|
||||||
4. Creates a TXT record in Route53 to satisfy the challenge
|
4. Creates a TXT record in Route53/Cloudflare to satisfy the challenge
|
||||||
5. Notifies the ACME provider that the challenge is ready for validation
|
5. Notifies the ACME provider that the challenge is ready for validation
|
||||||
6. Once validated, the ACME provider issues the certificate
|
6. Once validated, the ACME provider issues the certificate
|
||||||
7. Infisical stores and manages the certificate for your subscriber
|
7. Infisical stores and manages the certificate for your subscriber
|
||||||
@@ -265,7 +281,7 @@ Let's Encrypt is a free, automated, and open Certificate Authority that provides
|
|||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="What DNS validation methods are supported?">
|
<Accordion title="What DNS validation methods are supported?">
|
||||||
Currently, Infisical supports DNS-01 validation through AWS Route53. The DNS-01 challenge method is preferred for ACME integrations because it:
|
Currently, Infisical supports DNS-01 validation through AWS Route53 or Cloudflare. The DNS-01 challenge method is preferred for ACME integrations because it:
|
||||||
|
|
||||||
- Works with wildcard certificates
|
- Works with wildcard certificates
|
||||||
- Doesn't require your servers to be publicly accessible
|
- Doesn't require your servers to be publicly accessible
|
||||||
|
|||||||
@@ -142,7 +142,7 @@ Get started with External CA integration:
|
|||||||
- **Enterprise CAs**: HashiCorp Vault PKI, Step CA
|
- **Enterprise CAs**: HashiCorp Vault PKI, Step CA
|
||||||
- **Cloud CAs**: ACME-compatible managed services
|
- **Cloud CAs**: ACME-compatible managed services
|
||||||
|
|
||||||
Integration uses DNS-01 validation through Route53. Learn more about [supported DNS validation methods](/documentation/platform/pki/acme-ca#what-dns-validation-methods-are-supported).
|
Integration uses DNS-01 validation through Route53 or Cloudflare. Learn more about [supported DNS validation methods](/documentation/platform/pki/acme-ca#what-dns-validation-methods-are-supported).
|
||||||
|
|
||||||
Support for additional integration protocols (EST, SCEP, direct APIs) is planned for future releases.
|
Support for additional integration protocols (EST, SCEP, direct APIs) is planned for future releases.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 330 KiB |
@@ -50,6 +50,17 @@ Infisical supports connecting to Cloudflare using API tokens and Account ID for
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
</Tab>
|
</Tab>
|
||||||
|
<Tab title="PKI">
|
||||||
|
Use the following permissions to grant Infisical access to verify certificates using DNS TXT records with ACME:
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
**Required Permissions:**
|
||||||
|
- **Account** - **Account Settings** - **Read**
|
||||||
|
- **Zone** - **DNS** - **Edit**
|
||||||
|
|
||||||
|
Add these permissions to your API token and click **Continue to summary**, then **Create Token** to generate your API token.
|
||||||
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
|
|||||||
Reference in New Issue
Block a user