Merge branch 'main' into feat/azureClientSecretsRotation

This commit is contained in:
carlosmonastyrski
2025-04-21 10:27:56 -03:00
175 changed files with 2608 additions and 249 deletions
@@ -0,0 +1,112 @@
---
title: "Windmill Connection"
description: "Learn how to configure a Windmill Connection for Infisical."
---
Infisical supports connecting to Windmill using an **Access Token** to securely sync your secrets to Windmill.
## Get a Windmill Access Token
Ensure the user generating the access token has the required role and permissions based on your use-case:
<Tabs>
<Tab title="Secret Sync">
<Note>
The user generating the access token should be at least a `Developer` in the configured workspace and have `write` permissions for the workspace path secrets will be synced to.
</Note>
</Tab>
</Tabs>
<Steps>
<Step title="Navigate to Account Settings">
In Windmill, click on your user in the sidebar and select **Account Settings**.
![Windmill Account Settings](/images/app-connections/windmill/windmill-account-settings.png)
</Step>
<Step title="Access Token Section">
In the **Tokens** section on the drawer, click **Create token**.
![Windmill Create Token](/images/app-connections/windmill/windmill-create-token.png)
</Step>
<Step title="Create Access Token">
Give your token a name and click **New token**.
<Note>
If you configure an expiry date for your access token, you must manually rotate to a new token before the expiration date to prevent service interruption.
</Note>
![Windmill New Token](/images/app-connections/windmill/windmill-new-token.png)
</Step>
<Step title="Copy Access Token">
Copy your new access token and save it for the steps below.
![Windmill Copy Token](/images/app-connections/windmill/windmill-copy-token.png)
</Step>
</Steps>
## Setup Windmill Connection in Infisical
<Tabs>
<Tab title="Infisical UI">
<Steps>
<Step title="Navigate to App Connections">
In your Infisical dashboard, go to **Organization Settings** and select the **App Connections** tab.
![App Connections Tab](/images/app-connections/general/add-connection.png)
</Step>
<Step title="Add Connection">
Click the **+ Add Connection** button and select the **Windmill Connection** option.
![Select Windmill Connection](/images/app-connections/windmill/select-windmill-connection.png)
</Step>
<Step title="Configure Connection">
Configure your Windmill Connection using the access token generated in the steps above. Then click **Connect to Windmill**.
![Windmill Configure Connection](/images/app-connections/windmill/create-windmill-access-token.png)
- **Name**: The name of the connection to be created. Must be slug-friendly.
- **Description**: An optional description to provide details about this connection.
- **Instance URL**: The URL of your Windmill instance. If you are not self-hosting Windmill you can leave this field blank.
- **Access Token**: The access token generated in the steps above.
</Step>
<Step title="Connection Created">
Your Windmill Connection is now available for use.
![Windmill Connection Created](/images/app-connections/windmill/windmill-access-token-created.png)
</Step>
</Steps>
</Tab>
<Tab title="API">
To create a Windmill Connection, make an API request to the [Create Windmill
Connection](/api-reference/endpoints/app-connections/windmill/create) API endpoint.
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/app-connections/windmill \
--header 'Content-Type: application/json' \
--data '{
"name": "my-windmill-connection",
"method": "access-token",
"credentials": {
"token": "...",
"instanceUrl": "https://app.windmill.dev"
}
}'
```
### Sample response
```bash Response
{
"appConnection": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "my-windmill-connection",
"version": 123,
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2025-04-01T05:31:56Z",
"updatedAt": "2025-04-01T05:31:56Z",
"app": "windmill",
"method": "access-token",
"credentials": {
"instanceUrl": "https://app.windmill.dev"
}
}
}
```
</Tab>
</Tabs>
+147
View File
@@ -0,0 +1,147 @@
---
title: "Windmill Sync"
description: "Learn how to configure a Windmill Sync for Infisical."
---
**Prerequisites:**
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
- Create a [Windmill Connection](/integrations/app-connections/windmill) with the required **Secret Sync** permissions
<Tabs>
<Tab title="Infisical UI">
1. Navigate to **Project** > **Integrations** and select the **Secret Syncs** tab. Click on the **Add Sync** button.
![Secret Syncs Tab](/images/secret-syncs/general/secret-sync-tab.png)
2. Select the **Windmill** option.
![Select Windmill](/images/secret-syncs/windmill/select-windmill-option.png)
3. Configure the **Source** from where secrets should be retrieved, then click **Next**.
![Configure Source](/images/secret-syncs/windmill/windmill-sync-source.png)
- **Environment**: The project environment to retrieve secrets from.
- **Secret Path**: The folder path to retrieve secrets from.
<Tip>
If you need to sync secrets from multiple folder locations, check out [secret imports](/documentation/platform/secret-reference#secret-imports).
</Tip>
4. Configure the **Destination** to where secrets should be deployed, then click **Next**.
![Configure Destination](/images/secret-syncs/windmill/windmill-sync-destination.png)
- **Windmill Connection**: The Windmill Connection to authenticate with.
- **Workspace**: The Windmill workspace to sync secrets to.
- **Path**: The workspace path to sync secrets to.
<Note>
Workspace path must conform to Windmill's [owner path convention](https://www.windmill.dev/docs/core_concepts/roles_and_permissions#path).
</Note>
5. Configure the **Sync Options** to specify how secrets should be synced, then click **Next**.
![Configure Options](/images/secret-syncs/windmill/windmill-sync-options.png)
- **Initial Sync Behavior**: Determines how Infisical should resolve the initial sync.
- **Overwrite Destination Secrets**: Removes any secrets at the destination endpoint not present in Infisical.
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over Windmill when keys conflict.
- **Import Secrets (Prioritize Windmill)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Windmill over Infisical when keys conflict.
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
6. Configure the **Details** of your Windmill Sync, then click **Next**.
![Configure Details](/images/secret-syncs/windmill/windmill-sync-details.png)
- **Name**: The name of your sync. Must be slug-friendly.
- **Description**: An optional description for your sync.
7. Review your Windmill Sync configuration, then click **Create Sync**.
![Confirm Configuration](/images/secret-syncs/windmill/windmill-sync-review.png)
8. If enabled, your Windmill Sync will begin syncing your secrets to the destination endpoint.
![Sync Secrets](/images/secret-syncs/windmill/windmill-sync-created.png)
</Tab>
<Tab title="API">
To create an **Windmill Sync**, make an API request to the [Create Windmill Sync](/api-reference/endpoints/secret-syncs/windmill/create) API endpoint.
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/secret-syncs/windmill \
--header 'Content-Type: application/json' \
--data '{
"name": "my-windmill-sync",
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"description": "an example sync",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "dev",
"secretPath": "/my-secrets",
"isEnabled": true,
"syncOptions": {
"initialSyncBehavior": "overwrite-destination"
},
"destinationConfig": {
"workspace": "my-workspace",
"path": "f/folder/path/"
}
}'
```
<Note>
Workspace path must conform to Windmill's [owner path convention](https://www.windmill.dev/docs/core_concepts/roles_and_permissions#path).
</Note>
### Sample response
```bash Response
{
"secretSync": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "my-windmill-sync",
"description": "an example sync",
"isEnabled": true,
"version": 1,
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"syncStatus": "succeeded",
"lastSyncJobId": "123",
"lastSyncMessage": null,
"lastSyncedAt": "2023-11-07T05:31:56Z",
"importStatus": null,
"lastImportJobId": null,
"lastImportMessage": null,
"lastImportedAt": null,
"removeStatus": null,
"lastRemoveJobId": null,
"lastRemoveMessage": null,
"lastRemovedAt": null,
"syncOptions": {
"initialSyncBehavior": "overwrite-destination"
},
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connection": {
"app": "windmill",
"name": "my-windmill-connection",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"environment": {
"slug": "dev",
"name": "Development",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"folder": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"path": "/my-secrets"
},
"destination": "windmill",
"destinationConfig": {
"workspace": "my-workspace",
"path": "f/folder/path/"
}
}
}
```
</Tab>
</Tabs>