feat: add docs
195
docs/documentation/platform/dynamic-secrets/azure-entra-id.mdx
Normal file
@@ -0,0 +1,195 @@
|
||||
---
|
||||
title: "Azure Entra Id"
|
||||
description: "Learn how to dynamically generate Azure Entra Id user credentials."
|
||||
---
|
||||
|
||||
The Infisical Azure Entra Id dynamic secret allows you to generate Azure Entra Id credentials on demand based on configured role.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
<Steps>
|
||||
<Step>
|
||||
Login to [Microsoft Entra ID](https://entra.microsoft.com/)
|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Go to Overview, Copy and store `Tenant Id`
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Go to Applications > App registrations. Click on New Registration.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Enter an application name. Click Register.
|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Copy and store `Application Id`.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Go to Clients and Secrets. Click on New Client Secret.
|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Enter a description, select expiry and click Add.
|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Copy and store `Client Secret` value.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Go to API Permissions. Click on Add a permission.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Click on Microsoft Graph.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Click on Application Permissions. Search and select `User.ReadWrite.All` and click Add permissions.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Click on Grant admin consent for app. Click yes to confirm.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Go to Dashboard. Click on show more.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Click on Roles & admins. Search for User Administrator and click on it.
|
||||

|
||||
</Step>
|
||||
|
||||
<Step>
|
||||
Click on Add assignments. Search for the application name you created and select it. Click on Add.
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
<Note>
|
||||
For testing purposes, you can also use a highly privileged role like `superuser`, that will have full control over the cluster. This is not recommended in production environments following the principle of least privilege.
|
||||
</Note>
|
||||
|
||||
## Set up Dynamic Secrets with Azure Entra ID
|
||||
|
||||
<Steps>
|
||||
<Step title="Open Secret Overview Dashboard">
|
||||
Open the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret.
|
||||
</Step>
|
||||
<Step title="Click on the 'Add Dynamic Secret' button">
|
||||

|
||||
</Step>
|
||||
<Step title="Select 'Elasticsearch'">
|
||||

|
||||
</Step>
|
||||
<Step title="Provide the inputs for dynamic secret parameters">
|
||||
<ParamField path="Secret Name" type="string" required>
|
||||
Name by which you want the secret to be referenced
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="Default TTL" type="string" required>
|
||||
Default time-to-live for a generated secret (it is possible to modify this value when a secret is generate)
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="Max TTL" type="string" required>
|
||||
Maximum time-to-live for a generated secret.
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="Host" type="string" required>
|
||||
Your Elasticsearch host. This is the endpoint that your instance runs on. _(Example: https://your-cluster-ip)_
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="Port" type="string" required>
|
||||
The port that your Elasticsearch instance is running on. _(Example: 9200)_
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="Roles" type="string[]" required>
|
||||
The roles that the new user that is created when a lease is provisioned will be assigned to. This is a required field. This defaults to `superuser`, which is highly privileged. It is recommended to create a new role with the least privileges required for the lease.
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="Authentication Method" type="API Key | Username/Password" required>
|
||||
Select the authentication method you want to use to connect to your Elasticsearch instance.
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="Username" type="string" required>
|
||||
The username of the user that will be used to provision new dynamic secret leases. Only required if you selected the `Username/Password` authentication method.
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="Password" type="string" required>
|
||||
The password of the user that will be used to provision new dynamic secret leases. Only required if you selected the `Username/Password` authentication method.
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="API Key ID" required>
|
||||
The ID of the API key that will be used to provision new dynamic secret leases. Only required if you selected the `API Key` authentication method.
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="API Key" required>
|
||||
The API key that will be used to provision new dynamic secret leases. Only required if you selected the `API Key` authentication method.
|
||||
</ParamField>
|
||||
|
||||
<ParamField path="CA(SSL)" type="string">
|
||||
A CA may be required if your DB requires it for incoming connections. This is often the case when connecting to a managed service.
|
||||
</ParamField>
|
||||
|
||||

|
||||
|
||||
|
||||
</Step>
|
||||
<Step title="Click `Submit`">
|
||||
After submitting the form, you will see a dynamic secret created in the dashboard.
|
||||
|
||||
<Note>
|
||||
If this step fails, you may have to add the CA certificate.
|
||||
</Note>
|
||||
|
||||
</Step>
|
||||
<Step title="Generate dynamic secrets">
|
||||
Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials.
|
||||
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
|
||||
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
|
||||
|
||||

|
||||

|
||||
|
||||
When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for.
|
||||
|
||||

|
||||
|
||||
<Tip>
|
||||
Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret.
|
||||
</Tip>
|
||||
|
||||
|
||||
Once you click the `Submit` button, a new secret lease will be generated and the credentials from it will be shown to you.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
## Audit or Revoke Leases
|
||||
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
|
||||
This will allow you see the expiration time of the lease or delete a lease before it's set time to live.
|
||||
|
||||

|
||||
|
||||
## Renew Leases
|
||||
To extend the life of the generated dynamic secret leases past its initial time to live, simply click on the **Renew** as illustrated below.
|
||||

|
||||
|
||||
<Warning>
|
||||
Lease renewals cannot exceed the maximum TTL set when configuring the dynamic secret
|
||||
</Warning>
|
||||
|
After Width: | Height: | Size: 432 KiB |
|
After Width: | Height: | Size: 501 KiB |
|
After Width: | Height: | Size: 584 KiB |
|
After Width: | Height: | Size: 603 KiB |
|
After Width: | Height: | Size: 724 KiB |
|
After Width: | Height: | Size: 395 KiB |
|
After Width: | Height: | Size: 772 KiB |
|
After Width: | Height: | Size: 186 KiB |
|
After Width: | Height: | Size: 681 KiB |
|
After Width: | Height: | Size: 565 KiB |
|
After Width: | Height: | Size: 524 KiB |
@@ -167,7 +167,8 @@
|
||||
"documentation/platform/dynamic-secrets/rabbit-mq",
|
||||
"documentation/platform/dynamic-secrets/aws-iam",
|
||||
"documentation/platform/dynamic-secrets/mongo-atlas",
|
||||
"documentation/platform/dynamic-secrets/mongo-db"
|
||||
"documentation/platform/dynamic-secrets/mongo-db",
|
||||
"documentation/platform/dynamic-secrets/azure-entra-id"
|
||||
]
|
||||
},
|
||||
{
|
||||
|
||||