diff --git a/docs/getting-started/quickstarts/kubernetes.mdx b/docs/getting-started/quickstarts/kubernetes.mdx index 5929d92e3..24d324bbc 100644 --- a/docs/getting-started/quickstarts/kubernetes.mdx +++ b/docs/getting-started/quickstarts/kubernetes.mdx @@ -2,13 +2,14 @@ title: "Kubernetes" --- -The Infisical Secrets Operator is a Kubernetes controller that retrieves secrets from Infisical and stores them in a designated cluster. -It uses an `InfisicalSecret` resource to specify authentication and storage methods. -The operator continuously updates secrets and can also reload dependent deployments automatically. +The Infisical Secrets Operator fetches secrets from Infisical and saves them as Kubernetes secrets using the custom `InfisicalSecret` resource to define authentication and storage methods. +The operator updates secrets continuously and can reloads dependent deployments automatically on secret changes. Prerequisites: +- Connected to your cluster via kubectl - Have a project with secrets ready in [Infisical Cloud](https://app.infisical.com). +- Create an [Infisical Token](/getting-started/dashboard/token) scoped to an environment in your project in Infisical. ## Installation @@ -38,11 +39,20 @@ Follow the instructions for either [Helm](https://helm.sh/) or [kubectl](https:/ -## Sync Infisical Secrets to your cluster -To retrieve secrets from an Infisical project and save them as native Kubernetes secrets within a specific namespace, utilize the `InfisicalSecret` custom resource definition (CRD). -This resource can be created after installing the Infisical operator. For each new managed secret, you will need to create a new InfisicalSecret CRD. -```yaml +## Usage + +**Step 1: Create Kubernetes secret containing service token** + +Once you have generated the service token, create a Kubernetes secret containing the service token you generated by running the command below. + +``` bash +kubectl create secret generic service-token --from-literal=infisicalToken= +``` + +**Step 2: Fill out the InfisicalSecrets CRD and apply it to your cluster** + +```yaml infisical-secrets-config.yaml apiVersion: secrets.infisical.com/v1alpha1 kind: InfisicalSecret metadata: @@ -52,19 +62,20 @@ spec: # The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used hostAPI: https://app.infisical.com/api authentication: - serviceToken: # <-- option 1 - serviceTokenSecretReference: + serviceToken: + serviceTokenSecretReference: # <-- The secret's namespaced name that holds the project token for authentication in step 1 secretName: service-token secretNamespace: option - serviceAccount: # <-- method 2 - serviceAccountSecretReference: - secretName: service-account - secretNamespace: default - projectId: "6439ec224cfbf7ea2a95b651" - environmentName: "dev" - managedSecretReference: + managedSecretReference: secretName: managed-secret # <-- the name of kubernetes secret that will be created - secretNamespace: default # <-- where the kubernetes secret that will be created + secretNamespace: default # <-- in what namespace it will be created in ``` +``` +kubectl apply -f infisical-secrets-config.yaml +``` + +You should now see a new kubernetes secret automatically created in the namespace you defined in the `managedSecretReference` property above. + +For a comprehensive guide on managing secrets in Kubernetes with Infisical, including all available options of the operator, please refer to this [link](../../integrations/platforms/kubernetes). diff --git a/docs/getting-started/quickstarts/overview.mdx b/docs/getting-started/quickstarts/overview.mdx index 14bab522a..2641f1199 100644 --- a/docs/getting-started/quickstarts/overview.mdx +++ b/docs/getting-started/quickstarts/overview.mdx @@ -31,7 +31,7 @@ title: "Overview" Inject secrets into Docker containers