mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 07:26:11 +00:00
add k8 quick start
This commit is contained in:
@@ -2,13 +2,14 @@
|
|||||||
title: "Kubernetes"
|
title: "Kubernetes"
|
||||||
---
|
---
|
||||||
|
|
||||||
The Infisical Secrets Operator is a Kubernetes controller that retrieves secrets from Infisical and stores them in a designated cluster.
|
The Infisical Secrets Operator fetches secrets from Infisical and saves them as Kubernetes secrets using the custom `InfisicalSecret` resource to define authentication and storage methods.
|
||||||
It uses an `InfisicalSecret` resource to specify authentication and storage methods.
|
The operator updates secrets continuously and can reloads dependent deployments automatically on secret changes.
|
||||||
The operator continuously updates secrets and can also reload dependent deployments automatically.
|
|
||||||
|
|
||||||
Prerequisites:
|
Prerequisites:
|
||||||
|
|
||||||
|
- Connected to your cluster via kubectl
|
||||||
- Have a project with secrets ready in [Infisical Cloud](https://app.infisical.com).
|
- Have a project with secrets ready in [Infisical Cloud](https://app.infisical.com).
|
||||||
|
- Create an [Infisical Token](/getting-started/dashboard/token) scoped to an environment in your project in Infisical.
|
||||||
|
|
||||||
## Installation
|
## Installation
|
||||||
|
|
||||||
@@ -38,11 +39,20 @@ Follow the instructions for either [Helm](https://helm.sh/) or [kubectl](https:/
|
|||||||
</Tab>
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|
||||||
## Sync Infisical Secrets to your cluster
|
|
||||||
To retrieve secrets from an Infisical project and save them as native Kubernetes secrets within a specific namespace, utilize the `InfisicalSecret` custom resource definition (CRD).
|
|
||||||
This resource can be created after installing the Infisical operator. For each new managed secret, you will need to create a new InfisicalSecret CRD.
|
|
||||||
|
|
||||||
```yaml
|
## Usage
|
||||||
|
|
||||||
|
**Step 1: Create Kubernetes secret containing service token**
|
||||||
|
|
||||||
|
Once you have generated the service token, create a Kubernetes secret containing the service token you generated by running the command below.
|
||||||
|
|
||||||
|
``` bash
|
||||||
|
kubectl create secret generic service-token --from-literal=infisicalToken=<your-service-token-here>
|
||||||
|
```
|
||||||
|
|
||||||
|
**Step 2: Fill out the InfisicalSecrets CRD and apply it to your cluster**
|
||||||
|
|
||||||
|
```yaml infisical-secrets-config.yaml
|
||||||
apiVersion: secrets.infisical.com/v1alpha1
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
kind: InfisicalSecret
|
kind: InfisicalSecret
|
||||||
metadata:
|
metadata:
|
||||||
@@ -52,19 +62,20 @@ spec:
|
|||||||
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
|
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
|
||||||
hostAPI: https://app.infisical.com/api
|
hostAPI: https://app.infisical.com/api
|
||||||
authentication:
|
authentication:
|
||||||
serviceToken: # <-- option 1
|
serviceToken:
|
||||||
serviceTokenSecretReference:
|
serviceTokenSecretReference: # <-- The secret's namespaced name that holds the project token for authentication in step 1
|
||||||
secretName: service-token
|
secretName: service-token
|
||||||
secretNamespace: option
|
secretNamespace: option
|
||||||
serviceAccount: # <-- method 2
|
managedSecretReference:
|
||||||
serviceAccountSecretReference:
|
|
||||||
secretName: service-account
|
|
||||||
secretNamespace: default
|
|
||||||
projectId: "6439ec224cfbf7ea2a95b651"
|
|
||||||
environmentName: "dev"
|
|
||||||
managedSecretReference:
|
|
||||||
secretName: managed-secret # <-- the name of kubernetes secret that will be created
|
secretName: managed-secret # <-- the name of kubernetes secret that will be created
|
||||||
secretNamespace: default # <-- where the kubernetes secret that will be created
|
secretNamespace: default # <-- in what namespace it will be created in
|
||||||
```
|
```
|
||||||
|
|
||||||
|
```
|
||||||
|
kubectl apply -f infisical-secrets-config.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
You should now see a new kubernetes secret automatically created in the namespace you defined in the `managedSecretReference` property above.
|
||||||
|
|
||||||
|
For a comprehensive guide on managing secrets in Kubernetes with Infisical, including all available options of the operator, please refer to this [link](../../integrations/platforms/kubernetes).
|
||||||
|
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ title: "Overview"
|
|||||||
Inject secrets into Docker containers
|
Inject secrets into Docker containers
|
||||||
</Card>
|
</Card>
|
||||||
<Card
|
<Card
|
||||||
href="/getting-started/quickstarts/k8s"
|
href="/getting-started/quickstarts/kubernetes"
|
||||||
title="Kubernetes"
|
title="Kubernetes"
|
||||||
icon="server"
|
icon="server"
|
||||||
color="#3775a9"
|
color="#3775a9"
|
||||||
|
|||||||
Reference in New Issue
Block a user