mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
address reviews
This commit is contained in:
@@ -4,13 +4,15 @@ sidebarTitle: "Accounts"
|
||||
description: "Learn how to create and manage accounts in PAM to control access to resources like databases and servers."
|
||||
---
|
||||
|
||||
An **Account** represents a specific identity or set of credentials (username/password) used to authenticate against a [Resource](/documentation/platform/pam/getting-started/resources).
|
||||
An **Account** contains the credentials (such as a username and password) used to connect to a [Resource](/documentation/platform/pam/getting-started/resources).
|
||||
|
||||
## Relationship to Resources
|
||||
|
||||
Accounts are children of Resources. A single Resource can have multiple Accounts associated with it, each with different permission levels.
|
||||
Accounts belong to Resources. A single Resource can have multiple Accounts associated with it, each with different permission levels.
|
||||
|
||||
For example:
|
||||
For example, your database would normally have multiple accounts. You might have a superuser account for admins, a standard read/write account for applications, and a read-only account for reporting.
|
||||
|
||||
In PAM, these are represented as:
|
||||
- **Resource**: `Production Database` (PostgreSQL)
|
||||
- **Account 1**: `postgres` (Superuser)
|
||||
- **Account 2**: `app_user` (Read/Write)
|
||||
@@ -40,10 +42,6 @@ Clicking **Create Account** will trigger a validation check. Infisical will atte
|
||||
|
||||
## Automated Credential Rotation
|
||||
|
||||
Accounts for certain resources, such as PostgreSQL, support automated credential rotation. This feature automatically changes the password for the account at a set interval.
|
||||
Infisical supports automated credential rotation for some accounts on select resources, allowing you to automatically change passwords at set intervals to enhance security.
|
||||
|
||||
**Requirements:**
|
||||
1. The parent Resource must have a [Rotation Account](/documentation/platform/pam/getting-started/resources#automated-credential-rotation) configured (a master account with permission to change other users' passwords).
|
||||
2. You must enable rotation in the Account settings.
|
||||
|
||||

|
||||
To learn more about how to configure this, please refer to the [Credential Rotation guide](/documentation/platform/pam/product-reference/credential-rotation).
|
||||
|
||||
@@ -12,7 +12,7 @@ A resource represents a target system, such as a database, server, or applicatio
|
||||
|
||||
## Prerequisites
|
||||
|
||||
Before you can create a resource, you must have an **Infisical Gateway** deployed and running on the same network as the target resource.
|
||||
Before you can create a resource, you must have an **Infisical Gateway** deployed that is able to reach the target resource over the network.
|
||||
|
||||
The Gateway acts as a secure bridge, allowing Infisical to reach your private infrastructure without exposing it to the public internet. When creating a resource, you will be asked to specify which Gateway should be used to connect to it.
|
||||
|
||||
@@ -40,15 +40,6 @@ Clicking **Create Resource** will trigger a connection test from the selected Ga
|
||||
|
||||
## Automated Credential Rotation
|
||||
|
||||
Some resources, such as PostgreSQL, support automated credential rotation to enhance your security posture. This requires configuration on both the resource and the accounts that use it.
|
||||
Some resources, such as PostgreSQL, support automated credential rotation to enhance your security posture. This feature requires configuring a privileged "Rotation Account" on the resource.
|
||||
|
||||
<Steps>
|
||||
<Step title="Configure Rotation Account on Resource">
|
||||
When creating or editing a resource, configure a "rotation account." This is a master or privileged account that has the necessary permissions to change the passwords of other accounts on that same resource.
|
||||

|
||||
</Step>
|
||||
<Step title="Enable Rotation on Account">
|
||||
For each individual account you want to rotate, enable rotation in the account's settings and set a desired interval (e.g., every 30 days). This option is only available if the account's resource has a rotation account configured.
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
To learn more about how to configure this, please refer to the [Credential Rotation guide](/documentation/platform/pam/product-reference/credential-rotation).
|
||||
|
||||
Reference in New Issue
Block a user