mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 08:27:36 +00:00
Merge pull request #2030 from Infisical/doc/added-guide-for-configuring-certs
doc: added guide for configuring certs
This commit is contained in:
@@ -77,11 +77,12 @@ description: "How to sync secrets from Infisical to GitLab"
|
|||||||
</Steps>
|
</Steps>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Self-Hosted Setup">
|
<Tab title="Self-Hosted Setup">
|
||||||
Using the GitLab integration on a self-hosted instance of Infisical requires configuring an application in GitLab
|
Using the GitLab integration on a self-hosted instance of Infisical requires configuring an application in GitLab
|
||||||
and registering your instance with it.
|
and registering your instance with it.
|
||||||
|
<Tip>If you're self-hosting Gitlab with custom certificates, you will have to configure your Infisical instance to trust these certificates. To learn how, please follow [this guide](../../self-hosting/guides/custom-certificates).</Tip>
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Create an OAuth application in GitLab">
|
<Step title="Create an OAuth application in GitLab">
|
||||||
Navigate to your user Settings > Applications to create a new GitLab application.
|
Navigate to your user Settings > Applications to create a new GitLab application.
|
||||||
@@ -91,8 +92,8 @@ description: "How to sync secrets from Infisical to GitLab"
|
|||||||
|
|
||||||
Create the application. As part of the form, set the **Redirect URI** to `https://your-domain.com/integrations/gitlab/oauth2/callback`.
|
Create the application. As part of the form, set the **Redirect URI** to `https://your-domain.com/integrations/gitlab/oauth2/callback`.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
If you have a GitLab group, you can create an OAuth application under it
|
If you have a GitLab group, you can create an OAuth application under it
|
||||||
in your group Settings > Applications.
|
in your group Settings > Applications.
|
||||||
@@ -100,17 +101,17 @@ description: "How to sync secrets from Infisical to GitLab"
|
|||||||
</Step>
|
</Step>
|
||||||
<Step title="Add your OAuth application credentials to Infisical">
|
<Step title="Add your OAuth application credentials to Infisical">
|
||||||
Obtain the **Application ID** and **Secret** for your GitLab application.
|
Obtain the **Application ID** and **Secret** for your GitLab application.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
Back in your Infisical instance, add two new environment variables for the credentials of your GitLab application:
|
Back in your Infisical instance, add two new environment variables for the credentials of your GitLab application:
|
||||||
|
|
||||||
- `CLIENT_ID_GITLAB`: The **Client ID** of your GitLab application.
|
- `CLIENT_ID_GITLAB`: The **Client ID** of your GitLab application.
|
||||||
- `CLIENT_SECRET_GITLAB`: The **Secret** of your GitLab application.
|
- `CLIENT_SECRET_GITLAB`: The **Secret** of your GitLab application.
|
||||||
|
|
||||||
Once added, restart your Infisical instance and use the GitLab integration.
|
Once added, restart your Infisical instance and use the GitLab integration.
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
|
|||||||
+2
-1
@@ -222,7 +222,8 @@
|
|||||||
"group": "Guides",
|
"group": "Guides",
|
||||||
"pages": [
|
"pages": [
|
||||||
"self-hosting/configuration/schema-migrations",
|
"self-hosting/configuration/schema-migrations",
|
||||||
"self-hosting/guides/mongo-to-postgres"
|
"self-hosting/guides/mongo-to-postgres",
|
||||||
|
"self-hosting/guides/custom-certificates"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
---
|
||||||
|
title: "Adding Custom Certificates"
|
||||||
|
description: "Learn how to configure Infisical with custom certificates"
|
||||||
|
---
|
||||||
|
|
||||||
|
By default, the Infisical Docker image includes certificates from well-known public certificate authorities.
|
||||||
|
However, some integrations with Infisical may need to communicate with your internal services that use private certificate authorities.
|
||||||
|
To configure trust for custom certificates, follow these steps. This is particularly useful for connecting Infisical with self-hosted services like GitLab.
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
- Docker
|
||||||
|
- Standalone [Infisical image](https://hub.docker.com/r/infisical/infisical)
|
||||||
|
- Certificate public key `.pem` files
|
||||||
|
|
||||||
|
## Setup
|
||||||
|
|
||||||
|
1. Place all your public key `.pem` files into a single directory.
|
||||||
|
2. Mount the directory containing the `.pem` files to the `usr/local/share/ca-certificates/` path in the Infisical container.
|
||||||
|
3. Set the following environment variable on your Infisical container:
|
||||||
|
```
|
||||||
|
NODE_EXTRA_CA_CERTS=/etc/ssl/certs/ca-certificates.crt
|
||||||
|
```
|
||||||
|
4. Start the Infisical container.
|
||||||
|
|
||||||
|
By following these steps, your Infisical container will trust the specified certificates, allowing you to securely connect Infisical to your internal services.
|
||||||
Reference in New Issue
Block a user