improvement: finish address changes
4
docs/api-reference/endpoints/kms/keys/create.mdx
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Create Key"
|
||||
openapi: "POST /api/v1/kms/keys"
|
||||
---
|
||||
4
docs/api-reference/endpoints/kms/keys/decrypt.mdx
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Decrypt Data"
|
||||
openapi: "POST /api/v1/kms/keys/{keyId}/decrypt"
|
||||
---
|
||||
4
docs/api-reference/endpoints/kms/keys/delete.mdx
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Delete Key"
|
||||
openapi: "DELETE /api/v1/kms/keys/{keyId}"
|
||||
---
|
||||
4
docs/api-reference/endpoints/kms/keys/encrypt.mdx
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Encrypt Data"
|
||||
openapi: "POST /api/v1/kms/keys/{keyId}/encrypt"
|
||||
---
|
||||
4
docs/api-reference/endpoints/kms/keys/list.mdx
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "List Keys"
|
||||
openapi: "Get /api/v1/kms/keys"
|
||||
---
|
||||
4
docs/api-reference/endpoints/kms/keys/update.mdx
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Update Key"
|
||||
openapi: "PATCH /api/v1/kms/keys/{keyId}"
|
||||
---
|
||||
@@ -1,5 +1,5 @@
|
||||
---
|
||||
title: "Key Management Service (KMS)"
|
||||
title: "Key Management Service (KMS) Configuration"
|
||||
sidebarTitle: "Overview"
|
||||
description: "Learn how to configure your project's encryption"
|
||||
---
|
||||
@@ -26,3 +26,8 @@ For existing projects, you can configure the KMS from the Project Settings page.
|
||||
## External KMS
|
||||
|
||||
Infisical supports the use of external KMS solutions to enhance security and compliance. You can configure your project to use services like [AWS Key Management Service](./aws-kms) for managing encryption.
|
||||
|
||||
## Infisical KMS
|
||||
|
||||
Infisical exposes it's internal KMS solution, [Infisical KMS](../kms), enabling you to create and manage keys to perform cryptographic operations with.
|
||||
|
||||
200
docs/documentation/platform/kms.mdx
Normal file
@@ -0,0 +1,200 @@
|
||||
---
|
||||
title: "Key Management Service (KMS)"
|
||||
sidebarTitle: "Key Management (KMS)"
|
||||
description: "Learn how to manage and use cryptographic keys with Infisical."
|
||||
---
|
||||
|
||||
## Introduction
|
||||
|
||||
Infisical's <strong>Key Management System (KMS)</strong> allows you to create, store and manage cryptographic keys.
|
||||
These keys can be used to perform cryptographic operations such as data encryption. You can access
|
||||
Infisical's KMS from the [project](./project) sidebar.
|
||||
|
||||
## Features
|
||||
|
||||
1. <strong>Centralized Key Storage:</strong> Securely store all your organization's cryptographic keys in one location.
|
||||
2. <strong>Encryption and
|
||||
Decryption:</strong> Provide on-demand encryption and decryption services without exposing the keys to
|
||||
external applications.
|
||||
3. <strong>Audit
|
||||
Trails:</strong> Maintain detailed logs of all key-related activities for compliance and security analysis.
|
||||
|
||||
<Note>
|
||||
Your keys will never be used or viewable outside of Infisical KMS.
|
||||
In addition, no data is stored when performing cryptographic operations.
|
||||
</Note>
|
||||
|
||||
## Guide to Encrypting Data
|
||||
|
||||
In the following steps, we'll explore how to generate a cryptographic key and encrypt data.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
<Steps>
|
||||
<Step title="Creating a key">
|
||||
Navigate to Project > Key Management and tap on the Add Key button.
|
||||

|
||||
|
||||
Specify your key details. Here's some guidance on each field:
|
||||
|
||||
- Name: A slug-friendly name for the key.
|
||||
- Type: The encryption algorithm associated with this key. By default symmetric `AES-GCM-256` is selected,
|
||||
but
|
||||
Infisical will continue to add more options down the road.
|
||||
- Description: An optional description of what this key is used for.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Encrypting your data">
|
||||
Once your key is generated, open the options menu for the newly created key and select encrypt data.
|
||||

|
||||
|
||||
Populate the text area with your data and tap on the Encrypt button.
|
||||

|
||||
|
||||
<Note>
|
||||
If your data is already Base64 encoded make sure to toggle the respective switch on to avoid
|
||||
redundant encoding.
|
||||
</Note>
|
||||
|
||||
Copy and store the encrypted data.
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
<Steps>
|
||||
<Step title="Creating a key">
|
||||
To create a cryptographic key, make an API request to the [Create KMS
|
||||
Key](/api-reference/endpoints/kms/keys/create) API endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/kms/keys \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"projectId": "<project-id>",
|
||||
"name": "my-secret-key",
|
||||
"description": "...",
|
||||
"encryptionAlgorithm": "aes-256-gcm"
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"key": {
|
||||
"id": "<key-id>",
|
||||
"description": "...",
|
||||
"isDisabled": false,
|
||||
"isReserved": false,
|
||||
"orgId": "<org-id>",
|
||||
"name": "my-secret-key",
|
||||
"createdAt": "2023-11-07T05:31:56Z",
|
||||
"updatedAt": "2023-11-07T05:31:56Z",
|
||||
"projectId": "<project-id>"
|
||||
}
|
||||
}
|
||||
```
|
||||
</Step>
|
||||
<Step title="Encrypting data">
|
||||
To encrypt data, make an API request to the [Encrypt
|
||||
Data](/api-reference/endpoints/kms/keys/encrypt) API endpoint,
|
||||
specifying the key to use.
|
||||
|
||||
<Note>
|
||||
Make sure your data is Base64 encoded
|
||||
</Note>
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/kms/keys/<key-id>/encrypt \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"plaintext": "lUFHM5Ggwo6TOfpuN1S==" // base64 encoded plaintext
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"ciphertext": "HwFHwSFHwlMF6TOfp==" // base64 encoded ciphertext
|
||||
}
|
||||
```
|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
## Guide to Decrypting Data
|
||||
|
||||
In the following steps, we'll explore how to decrypt data.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
<Steps>
|
||||
<Step title="Accessing your key">
|
||||
Navigate to Project > Key Management and open the options menu for the key used to encrypt the data
|
||||
you want to decrypt.
|
||||

|
||||
|
||||
|
||||
</Step>
|
||||
<Step title="Decrypting your data">
|
||||
Paste your encrypted data into the text area and tap on the Decrypt button. Optionally, if your data was
|
||||
originally plain text, enable the decode Base64 switch.
|
||||

|
||||
|
||||
Your decrypted data will be displayed and can be copied for use.
|
||||

|
||||
|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
<Steps>
|
||||
<Step title="Decrypting data">
|
||||
To decrypt data, make an API request to the [Decrypt
|
||||
Data](/api-reference/endpoints/kms/keys/decrypt) API endpoint,
|
||||
specifying the key to use.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/kms/keys/<key-id>/decrypt \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"ciphertext": "HwFHwSFHwlMF6TOfp==" // base64 encoded ciphertext
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"plaintext": "lUFHM5Ggwo6TOfpuN1S==" // base64 encoded plaintext
|
||||
}
|
||||
```
|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
## FAQ
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Is my data stored in Infisical KMS?">
|
||||
No. Infisical's KMS only provides cryptographic services and does not store any encrypted or decrypted data.
|
||||
</Accordion>
|
||||
<Accordion title="Can key material be accessed outside of Infisical KMS?">
|
||||
No. Infisical's KMS will never expose your keys, encrypted or decrypted, to external sources.
|
||||
</Accordion>
|
||||
</AccordionGroup>
|
||||
BIN
docs/images/platform/kms/infisical-kms/kms-add-key-modal.png
Normal file
|
After Width: | Height: | Size: 535 KiB |
BIN
docs/images/platform/kms/infisical-kms/kms-add-key.png
Normal file
|
After Width: | Height: | Size: 702 KiB |
BIN
docs/images/platform/kms/infisical-kms/kms-decrypt-data.png
Normal file
|
After Width: | Height: | Size: 624 KiB |
BIN
docs/images/platform/kms/infisical-kms/kms-decrypt-options.png
Normal file
|
After Width: | Height: | Size: 942 KiB |
BIN
docs/images/platform/kms/infisical-kms/kms-decrypted-data.png
Normal file
|
After Width: | Height: | Size: 585 KiB |
BIN
docs/images/platform/kms/infisical-kms/kms-encrypt-data.png
Normal file
|
After Width: | Height: | Size: 558 KiB |
BIN
docs/images/platform/kms/infisical-kms/kms-encrypted-data.png
Normal file
|
After Width: | Height: | Size: 586 KiB |
BIN
docs/images/platform/kms/infisical-kms/kms-key-options.png
Normal file
|
After Width: | Height: | Size: 734 KiB |
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "Infisical",
|
||||
"openapi": "https://app.infisical.com/api/docs/json",
|
||||
"openapi": "http://localhost:8080/api/docs/json",
|
||||
"logo": {
|
||||
"dark": "/logo/dark.svg",
|
||||
"light": "/logo/light.svg",
|
||||
@@ -113,6 +113,15 @@
|
||||
"documentation/platform/pki/alerting"
|
||||
]
|
||||
},
|
||||
"documentation/platform/kms",
|
||||
{
|
||||
"group": "KMS Configuration",
|
||||
"pages": [
|
||||
"documentation/platform/kms-configuration/overview",
|
||||
"documentation/platform/kms-configuration/aws-kms",
|
||||
"documentation/platform/kms-configuration/aws-hsm"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Identities",
|
||||
"pages": [
|
||||
@@ -171,14 +180,6 @@
|
||||
"documentation/platform/dynamic-secrets/azure-entra-id"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Key Management (KMS)",
|
||||
"pages": [
|
||||
"documentation/platform/kms/overview",
|
||||
"documentation/platform/kms/aws-kms",
|
||||
"documentation/platform/kms/aws-hsm"
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Workflow Integrations",
|
||||
"pages": [
|
||||
@@ -789,6 +790,22 @@
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Infisical KMS",
|
||||
"pages": [
|
||||
{
|
||||
"group": "Keys",
|
||||
"pages": [
|
||||
"api-reference/endpoints/kms/keys/list",
|
||||
"api-reference/endpoints/kms/keys/create",
|
||||
"api-reference/endpoints/kms/keys/update",
|
||||
"api-reference/endpoints/kms/keys/delete",
|
||||
"api-reference/endpoints/kms/keys/encrypt",
|
||||
"api-reference/endpoints/kms/keys/decrypt"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Internals",
|
||||
"pages": [
|
||||
|
||||