From caea055281402d1b5608441f3152f504b8c16d4f Mon Sep 17 00:00:00 2001 From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> Date: Mon, 18 Mar 2024 16:45:59 +0100 Subject: [PATCH] Feat: Improve K8 docs --- docs/integrations/platforms/kubernetes.mdx | 42 +++++++++++----------- 1 file changed, 21 insertions(+), 21 deletions(-) diff --git a/docs/integrations/platforms/kubernetes.mdx b/docs/integrations/platforms/kubernetes.mdx index d603c4a47..079830f99 100644 --- a/docs/integrations/platforms/kubernetes.mdx +++ b/docs/integrations/platforms/kubernetes.mdx @@ -70,9 +70,9 @@ spec: hostAPI: https://app.infisical.com/api resyncInterval: 10 authentication: - # Make sure to only have 1 authentication method defined, serviceAccount/serviceToken/universalAuthMachineIdentity. + # Make sure to only have 1 authentication method defined, serviceToken/universalAuth. # If you have multiple authentication methods defined, it may cause issues. - universalAuthMachineIdentity: + universalAuth: secretsScope: projectSlug: envSlug: # "dev", "staging", "prod", etc.. @@ -81,13 +81,6 @@ spec: secretName: universal-auth-credentials secretNamespace: default - serviceAccount: - serviceAccountSecretReference: - secretName: service-account - secretNamespace: default - projectId: "" - environmentName: "" - serviceToken: serviceTokenSecretReference: secretName: service-token @@ -130,23 +123,30 @@ Default re-sync interval is every 1 minute. This block defines the method that will be used to authenticate with Infisical so that secrets can be fetched - + The universal machine identity authentication method is used to authenticate with Infisical. The client ID and client secret needs to be stored in a Kubernetes secret. This block defines the reference to the name and namespace of secret that stores these credentials. - #### 1. Create a machine identity - You need to create a machine identity, and give it access to the project(s) you want to interact with. You can [read more about machine identities here](/documentation/platform/identities/universal-auth). + + + You need to create a machine identity, and give it access to the project(s) you want to interact with. You can [read more about machine identities here](/documentation/platform/identities/universal-auth). + + + Once you have created your machine identity and added it to your project(s), you will need to create a Kubernetes secret containing the identity credentials. + To quickly create a Kubernetes secret containing the identity credentials, you can run the command below. + + Make sure you replace `` with the identity client ID and `` with the identity client secret. - #### 2. Create Kubernetes secret containing machine identity credentials + ``` bash + kubectl create secret generic universal-auth-credentials --from-literal=clientId="" --from-literal=clientSecret="" + ``` + - Once you have created your machine identity and added it to your project(s), you will need to create a Kubernetes secret containing the identity credentials. - To quickly create a Kubernetes secret containing the identity credentials, you can run the command below. Make sure you replace `` with the identity client ID and `` with the identity client secret. + + Once the secret is created, add the `secretName` and `secretNamespace` of the secret that was just created under `authentication.universalAuth.credentials` field in the InfisicalSecret resource. + + - ``` bash - kubectl create secret generic universal-auth-credentials --from-literal=clientId="" --from-literal=clientSecret="" - ``` - #### 3. Add reference for the Kubernetes secret containing the identity credentials - Once the secret is created, add the name and namespace of the secret that was just created under `authentication.serviceToken.universalAuthMachineIdentity` field in the InfisicalSecret resource. Make sure to also populate the `secretsScope` field with the project slug _`projectSlug`_, environment slug _`envSlug`_, and secrets path _`secretsPath`_ that you want to fetch secrets from. Please see the example below. @@ -160,7 +160,7 @@ Default re-sync interval is every 1 minute. name: infisicalsecret-sample-crd spec: authentication: - universalAuthMachineIdentity: + universalAuth: secretsScope: projectSlug: # <-- project slug envSlug: # "dev", "staging", "prod", etc..