mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 07:28:21 +00:00
kms and hsm doc updates
This commit is contained in:
@@ -3,48 +3,47 @@ title: "AWS CloudHSM"
|
|||||||
description: "Learn how to manage encryption using AWS CloudHSM"
|
description: "Learn how to manage encryption using AWS CloudHSM"
|
||||||
---
|
---
|
||||||
|
|
||||||
You can configure your projects to use AWS CloudHSM for encryption, enhancing the security of your secrets. This guide will demonstrate the use of AWS CloudHSM as a custom key store for AWS KMS.
|
This guide provides instructions on securing Infisical project secrets using AWS CloudHSM.
|
||||||
|
Integration with AWS CloudHSM is achieved by configuring it as a custom key store for AWS KMS.
|
||||||
|
Follow the steps below to set up AWS KMS with AWS CloudHSM as the custom key store.
|
||||||
|
|
||||||
### Prepare AWS CloudHSM Cluster
|
## Prepare AWS CloudHSM Cluster
|
||||||
|
|
||||||
The AWS CloudHSM cluster should meet the following criteria:
|
Before you get started, you'll need to configure a AWS CloudHSM cluster which meets the following criteria:
|
||||||
|
|
||||||
- The cluster must be active.
|
- The cluster must be active.
|
||||||
- The cluster must not be associated with any other AWS KMS custom key store.
|
- The cluster must not be associated with any other AWS KMS custom key store.
|
||||||
- The cluster must be configured with private subnets in at least two Availability Zones in the Region.
|
- The cluster must be configured with private subnets in at least two Availability Zones in the Region.
|
||||||
- The security group for the cluster must include inbound rules and outbound rules that allow TCP traffic on ports 2223-2225
|
- The security group for the cluster must include inbound and outbound rules that allow TCP traffic on ports 2223-2225.
|
||||||
- The cluster must contain at least two active HSMs in different Availability Zones.
|
- The cluster must contain at least two active HSMs in different Availability Zones.
|
||||||
|
|
||||||
For more details on setting up your cluster, refer to the following [AWS documentation](https://docs.aws.amazon.com/kms/latest/developerguide/create-keystore.html#before-keystore).
|
For more details on setting up your cluster, refer to the following [AWS documentation](https://docs.aws.amazon.com/kms/latest/developerguide/create-keystore.html#before-keystore).
|
||||||
|
|
||||||
### Setup AWS KMS Custom Key Store
|
## Set Up AWS KMS Custom Key Store
|
||||||
|
|
||||||
To setup an AWS KMS custom key store with AWS CloudHSM, you will need the following:
|
To set up an AWS KMS custom key store with AWS CloudHSM, you will need the following:
|
||||||
|
|
||||||
- The trust anchor certificate of your AWS CloudHSM cluster.
|
- The trust anchor certificate of your AWS CloudHSM cluster.
|
||||||
- A `kmsuser` user in the AWS CloudHSM cluster with the crypto-user role.
|
- A `kmsuser` user in the AWS CloudHSM cluster with the crypto-user role.
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Navigate to Key store creation page">
|
<Step title="Navigate to Key store creation page">
|
||||||
Proceed to AWS KMS > AWS CloudHSM key stores and click **Create key store**.
|
In the AWS console, head over to `AWS KMS` > `AWS CloudHSM key stores` and click **Create key store**.
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Add key store name">
|
<Step title="Add key store name">
|
||||||
Input custom key store name. 
|
||||||
name](../../../images/platform/kms/aws-hsm/create-key-store-name.png)
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Select HSM cluster">
|
<Step title="Select HSM cluster">
|
||||||
Select the AWS CloudHSM cluster. You should be able to select the cluster if
|
Select the AWS CloudHSM cluster. You should be able to select the cluster if it meets the required criteria mentioned above.
|
||||||
it meets the required criteria. 
|
||||||
cluster](../../../images/platform/kms/aws-hsm/create-key-store-cluster.png)
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Upload trust anchor certificate">
|
<Step title="Upload trust anchor certificate">
|
||||||
Upload your CloudHSM's cluster trust anchor certificate file. 
|

|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Provide cluster user password">
|
<Step title="Provide cluster user password">
|
||||||
Input the password of the `kmsuser` crypto-user in your cluster. 
|
||||||
password](../../../images/platform/kms/aws-hsm/create-key-store-password.png)
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Finish key store creation">
|
<Step title="Finish key store creation">
|
||||||
Proceed with creating the AWS CloudHSM key store.
|
Proceed with creating the AWS CloudHSM key store.
|
||||||
@@ -53,31 +52,31 @@ To setup an AWS KMS custom key store with AWS CloudHSM, you will need the follow
|
|||||||
|
|
||||||
For more details, refer to the following [AWS documentation](https://docs.aws.amazon.com/kms/latest/developerguide/create-keystore.html#create-keystore-console).
|
For more details, refer to the following [AWS documentation](https://docs.aws.amazon.com/kms/latest/developerguide/create-keystore.html#create-keystore-console).
|
||||||
|
|
||||||
### Create AWS KMS Key
|
## Create AWS KMS Key
|
||||||
|
Next, you'll need to create a AWS KMS key where you will set the key store you created previously.
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Navigate to AWS KMS key creation page">
|
<Step title="Navigate to AWS KMS key creation page">
|
||||||
Proceed to AWS KMS > Customer managed keys and click Create.
|
In your AWS console, proceed to `AWS KMS` > `Customer managed keys` and click **Create**.
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Set key options">
|
<Step title="Set key options">
|
||||||
Set Key type to **Symmetric** and Key usage to **Encrypt and decrypt**.
|
Set Key type to `Symmetric` and Key usage to `Encrypt and decrypt`.
|
||||||

|
||||||
1](../../../images/platform/kms/aws-hsm/create-kms-key-1.png)
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Select key material origin">
|
<Step title="Select key material origin">
|
||||||
In the advanced options, for the Key material origin field, select **AWS
|
In the advanced options, for the Key material origin field, select `AWS CloudHSM key store`. Then, click next.
|
||||||
CloudHSM key store**. Click next. 
|
||||||
2](../../../images/platform/kms/aws-hsm/create-kms-key-2.png)
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Choose key store">
|
<Step title="Choose key store">
|
||||||
Select the AWS CloudHSM key store. 
|

|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Finish KMS key creation">
|
<Step title="Finish KMS key creation">
|
||||||
Proceed with creating the AWS KMS Key.
|
Proceed with creating the AWS KMS Key.
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
### Connect Infisical to AWS KMS Key
|
## Connect Infisical to AWS KMS Key
|
||||||
|
|
||||||
Now all that's left is to connect the AWS KMS key to your Infisical organization. Refer to the documentation [here](./aws-kms).
|
You should now have an AWS KMS that has a custom key store set to AWS CloudHSM.
|
||||||
|
To secure project resources, you will need to add this AWS KMS to your Infisical organization. To learn how, refer to the documentation [here](./aws-kms).
|
||||||
@@ -4,8 +4,8 @@ description: "Learn how to manage encryption using AWS KMS"
|
|||||||
---
|
---
|
||||||
|
|
||||||
To enhance the security of your Infisical projects, you can now encrypt your secrets using an external Key Management Service (KMS).
|
To enhance the security of your Infisical projects, you can now encrypt your secrets using an external Key Management Service (KMS).
|
||||||
When external KMS is configured for your project, all encryption and decryption operations will be handled by the chosen KMS, providing you with complete control.
|
When external KMS is configured for your project, all encryption and decryption operations will be handled by the chosen KMS.
|
||||||
This guide will walk you through the steps needed to configure AWS KMS.
|
This guide will walk you through the steps needed to configure external KMS support with AWS KMS.
|
||||||
|
|
||||||
## Prerequisites
|
## Prerequisites
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user