From cff20eb62185a2c827360619bfc6bef9a46853be Mon Sep 17 00:00:00 2001 From: Sheen Capadngan Date: Thu, 27 Jun 2024 03:00:15 +0800 Subject: [PATCH 1/2] doc: added guide for configuring certs --- docs/integrations/cicd/gitlab.mdx | 17 ++++++------- docs/mint.json | 3 ++- .../guides/custom-certificates.mdx | 24 +++++++++++++++++++ 3 files changed, 35 insertions(+), 9 deletions(-) create mode 100644 docs/self-hosting/guides/custom-certificates.mdx diff --git a/docs/integrations/cicd/gitlab.mdx b/docs/integrations/cicd/gitlab.mdx index 976c81a6d..11b197551 100644 --- a/docs/integrations/cicd/gitlab.mdx +++ b/docs/integrations/cicd/gitlab.mdx @@ -77,11 +77,12 @@ description: "How to sync secrets from Infisical to GitLab" + Using the GitLab integration on a self-hosted instance of Infisical requires configuring an application in GitLab and registering your instance with it. - + If you're self-hosting Gitlab with custom certificates, you will have to configure your Infisical instance to [trust these certificates](../../self-hosting/guides/custom-certificates). Navigate to your user Settings > Applications to create a new GitLab application. @@ -91,8 +92,8 @@ description: "How to sync secrets from Infisical to GitLab" Create the application. As part of the form, set the **Redirect URI** to `https://your-domain.com/integrations/gitlab/oauth2/callback`. - ![integrations gitlab config](../../images/integrations/gitlab/integrations-gitlab-config-new-app-form.png) - + ![integrations gitlab config](../../images/integrations/gitlab/integrations-gitlab-config-new-app-form.png) + If you have a GitLab group, you can create an OAuth application under it in your group Settings > Applications. @@ -100,17 +101,17 @@ description: "How to sync secrets from Infisical to GitLab" Obtain the **Application ID** and **Secret** for your GitLab application. - - ![integrations gitlab config](../../images/integrations/gitlab/integrations-gitlab-config-credentials.png) - + + ![integrations gitlab config](../../images/integrations/gitlab/integrations-gitlab-config-credentials.png) + Back in your Infisical instance, add two new environment variables for the credentials of your GitLab application: - `CLIENT_ID_GITLAB`: The **Client ID** of your GitLab application. - `CLIENT_SECRET_GITLAB`: The **Secret** of your GitLab application. - + Once added, restart your Infisical instance and use the GitLab integration. + - diff --git a/docs/mint.json b/docs/mint.json index ac2a536c0..465759875 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -222,7 +222,8 @@ "group": "Guides", "pages": [ "self-hosting/configuration/schema-migrations", - "self-hosting/guides/mongo-to-postgres" + "self-hosting/guides/mongo-to-postgres", + "self-hosting/guides/custom-certificates" ] }, { diff --git a/docs/self-hosting/guides/custom-certificates.mdx b/docs/self-hosting/guides/custom-certificates.mdx new file mode 100644 index 000000000..c43d64636 --- /dev/null +++ b/docs/self-hosting/guides/custom-certificates.mdx @@ -0,0 +1,24 @@ +--- +title: "Adding Custom Certificates" +description: "Learn how to Configure Infisical with Custom Certificates" +--- + +Follow these steps to configure trust for custom certificates. This is helpful for connecting Infisical with self-hosted services like GitLab. + +## Prerequisites + +- Docker +- Standalone Infisical image +- Certificate public key `.pem` files + +## Setup + +1. Place all your public key `.pem` files in a single directory. +2. Mount the directory containing the `.pem` files to the `usr/local/share/ca-certificates/` path in the Infisical container. +3. Add the following environment variable to the Infisical container's configuration: + ``` + NODE_EXTRA_CA_CERTS=/etc/ssl/certs/ca-certificates.crt + ``` +4. Start the Infisical container. + +By following these steps, your Infisical container will trust the specified certificates, allowing you to securely connect Infisical to your other services. From 491c4259cad2f1fbe37ba72098c4f09b27440395 Mon Sep 17 00:00:00 2001 From: Maidul Islam Date: Wed, 26 Jun 2024 15:29:44 -0400 Subject: [PATCH 2/2] small rephrase for gitlab cert docs --- docs/integrations/cicd/gitlab.mdx | 2 +- docs/self-hosting/guides/custom-certificates.mdx | 14 ++++++++------ 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/docs/integrations/cicd/gitlab.mdx b/docs/integrations/cicd/gitlab.mdx index 11b197551..c6d72a11e 100644 --- a/docs/integrations/cicd/gitlab.mdx +++ b/docs/integrations/cicd/gitlab.mdx @@ -82,7 +82,7 @@ description: "How to sync secrets from Infisical to GitLab" Using the GitLab integration on a self-hosted instance of Infisical requires configuring an application in GitLab and registering your instance with it. - If you're self-hosting Gitlab with custom certificates, you will have to configure your Infisical instance to [trust these certificates](../../self-hosting/guides/custom-certificates). + If you're self-hosting Gitlab with custom certificates, you will have to configure your Infisical instance to trust these certificates. To learn how, please follow [this guide](../../self-hosting/guides/custom-certificates). Navigate to your user Settings > Applications to create a new GitLab application. diff --git a/docs/self-hosting/guides/custom-certificates.mdx b/docs/self-hosting/guides/custom-certificates.mdx index c43d64636..67b258d08 100644 --- a/docs/self-hosting/guides/custom-certificates.mdx +++ b/docs/self-hosting/guides/custom-certificates.mdx @@ -1,24 +1,26 @@ --- title: "Adding Custom Certificates" -description: "Learn how to Configure Infisical with Custom Certificates" +description: "Learn how to configure Infisical with custom certificates" --- -Follow these steps to configure trust for custom certificates. This is helpful for connecting Infisical with self-hosted services like GitLab. +By default, the Infisical Docker image includes certificates from well-known public certificate authorities. +However, some integrations with Infisical may need to communicate with your internal services that use private certificate authorities. +To configure trust for custom certificates, follow these steps. This is particularly useful for connecting Infisical with self-hosted services like GitLab. ## Prerequisites - Docker -- Standalone Infisical image +- Standalone [Infisical image](https://hub.docker.com/r/infisical/infisical) - Certificate public key `.pem` files ## Setup -1. Place all your public key `.pem` files in a single directory. +1. Place all your public key `.pem` files into a single directory. 2. Mount the directory containing the `.pem` files to the `usr/local/share/ca-certificates/` path in the Infisical container. -3. Add the following environment variable to the Infisical container's configuration: +3. Set the following environment variable on your Infisical container: ``` NODE_EXTRA_CA_CERTS=/etc/ssl/certs/ca-certificates.crt ``` 4. Start the Infisical container. -By following these steps, your Infisical container will trust the specified certificates, allowing you to securely connect Infisical to your other services. +By following these steps, your Infisical container will trust the specified certificates, allowing you to securely connect Infisical to your internal services.