mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feature: secret scanning architecture and github data source (wip)
This commit is contained in:
120
docs/integrations/app-connections/github-radar.mdx
Normal file
120
docs/integrations/app-connections/github-radar.mdx
Normal file
@@ -0,0 +1,120 @@
|
||||
---
|
||||
title: "GitHub Radar Connection"
|
||||
description: "Learn how to configure a GitHub Radar Connection for Infisical."
|
||||
---
|
||||
|
||||
Infisical supports GitHub App installation for creating a GitHub Radar Connection.
|
||||
|
||||
<Accordion title="Self-Hosted Instance">
|
||||
Using a GitHub Radar Connection with app authentication on a self-hosted instance of Infisical requires configuring an application on GitHub
|
||||
and registering your instance with it.
|
||||
|
||||
<Steps>
|
||||
<Step title="Create an application on GitHub">
|
||||
Navigate to the GitHub App Settings [here](https://github.com/settings/apps). Click **New GitHub App**.
|
||||
|
||||
<Note>
|
||||
If you have a GitHub organization, you can create an application under it
|
||||
in your organization Settings > Developer settings > GitHub Apps > New GitHub App.
|
||||
</Note>
|
||||
|
||||

|
||||
|
||||
Configure the following fields:
|
||||
|
||||
1. **Name** - give your app a name
|
||||
2. **Homepage URL** - your self-hosted domain (i.e. `https://your-domain.com`)
|
||||
3. **Callback URL** - the callback URL for your domain (i.e. `https://your-domain.com/organization/app-connections/github-radar/oauth/callback`)
|
||||
4. **User Authorization** - enable request user authorization on app installation
|
||||
|
||||

|
||||
|
||||
Enable and configure the Webhook fields:
|
||||
|
||||
- **Webhook URL** - the webhook URL for your domain (i.e. `https://your-domain.com/secret-scanning/webhooks/github`)
|
||||
- **Webhook Secret** - a strong, generated secret to verify webhook payloads
|
||||
- **SSL Verification** - enable SSL verification
|
||||
|
||||

|
||||
|
||||
Set the following repository permissions:
|
||||
1. **Checks**: `Read and Write`
|
||||
2. **Content**: `Read-only`
|
||||
3. **Issues**: `Read and Write`
|
||||
4. **Metadata**: `Read-only`
|
||||
5. **Pull Requests**: `Read and Write`
|
||||
|
||||

|
||||

|
||||
|
||||
Subscribe to the following events:
|
||||
1. **Check run**
|
||||
2. **Pull request**
|
||||
3. **Push**
|
||||
|
||||

|
||||
|
||||
Create the Github application.
|
||||

|
||||
</Step>
|
||||
<Step title="Add your application credentials to Infisical">
|
||||
Generate a new **Client Secret** for your GitHub application.
|
||||

|
||||
|
||||
Generate a new **Private Key** for your Github application.
|
||||
|
||||
<Info>You will need to copy the contents of the .pem file downloaded</Info>
|
||||
|
||||

|
||||
|
||||
Obtain the following credentials:
|
||||
|
||||
1. **Slug** - the slug of your application found in the URL
|
||||
2. **App ID** - the ID of your application
|
||||
3. **Client ID** - the client ID of your application
|
||||
4. **Client Secret** - the client secret generated above
|
||||
5. **Private Key** - the contents of the private key .pem file generated above
|
||||
6. **Webhook Secret** - the secret generated in the previous step when configuring the webhook
|
||||
|
||||

|
||||
|
||||
Back in your Infisical instance, add the six new environment variables for the credentials of your GitHub Radar application:
|
||||
|
||||
- `INF_APP_CONNECTION_GITHUB_RADAR_APP_CLIENT_ID`: The **Client ID** of your GitHub application.
|
||||
- `INF_APP_CONNECTION_GITHUB_RADAR_APP_CLIENT_SECRET`: The **Client Secret** of your GitHub application.
|
||||
- `INF_APP_CONNECTION_GITHUB_RADAR_APP_SLUG`: The **Slug** of your GitHub application. This is the one found in the URL.
|
||||
- `INF_APP_CONNECTION_GITHUB_RADAR_APP_ID`: The **App ID** of your GitHub application.
|
||||
- `INF_APP_CONNECTION_GITHUB_RADAR_APP_PRIVATE_KEY`: The **Private Key** of your GitHub application.
|
||||
- `INF_APP_CONNECTION_GITHUB_RADAR_APP_WEBHOOK_SECRET`: The **Webhook Secret** of your GitHub application.
|
||||
|
||||
Once added, restart your Infisical instance and use the GitHub integration via app authentication.
|
||||
</Step>
|
||||
</Steps>
|
||||
</Accordion>
|
||||
|
||||
## Setup GitHub Connection in Infisical
|
||||
|
||||
<Steps>
|
||||
<Step title="Navigate to App Connections">
|
||||
Navigate to the **App Connections** tab on the **Organization Settings** page.
|
||||

|
||||
</Step>
|
||||
<Step title="Add Connection">
|
||||
Select the **GitHub Connection** option from the connection options modal.
|
||||

|
||||
</Step>
|
||||
<Step title="Authorize Connection">
|
||||
Select the **GitHub App** method and click **Connect to GitHub**.
|
||||

|
||||
</Step>
|
||||
<Step title="Install GitHub App">
|
||||
You will then be redirected to the GitHub App installation page.
|
||||
|
||||
Install and authorize the GitHub application. This will redirect you back to Infisical's App Connections page.
|
||||

|
||||
</Step>
|
||||
<Step title="Connection Created">
|
||||
Your **GitHub Radar Connection** is now available for use.
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
@@ -3,7 +3,7 @@ title: "TeamCity Connection"
|
||||
description: "Learn how to configure a TeamCity Connection for Infisical."
|
||||
---
|
||||
|
||||
Infisical supports connecting to TeamCity using an Access Token to securely sync your secrets to TeamCity.
|
||||
Infisical supports connecting to TeamCity using Access Tokens.
|
||||
|
||||
## Setup TeamCity Connection in Infisical
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ title: "Vercel Connection"
|
||||
description: "Learn how to configure a Vercel Connection for Infisical."
|
||||
---
|
||||
|
||||
Infisical supports connecting to Vercel using an API Token to securely sync your secrets to Vercel.
|
||||
Infisical supports connecting to Vercel using API Tokens.
|
||||
|
||||
## Setup Vercel Connection in Infisical
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ title: "Windmill Connection"
|
||||
description: "Learn how to configure a Windmill Connection for Infisical."
|
||||
---
|
||||
|
||||
Infisical supports connecting to Windmill using an **Access Token** to securely sync your secrets to Windmill.
|
||||
Infisical supports connecting to Windmill using Access Tokens.
|
||||
|
||||
## Get a Windmill Access Token
|
||||
|
||||
|
||||
Reference in New Issue
Block a user