From bc4885b0985508ad1134c80859528c9c04d6a1b7 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard Date: Thu, 28 Aug 2025 21:12:00 +0200 Subject: [PATCH 1/2] Update ansible.mdx --- docs/integrations/platforms/ansible.mdx | 48 ++++++++++++++++++++++++- 1 file changed, 47 insertions(+), 1 deletion(-) diff --git a/docs/integrations/platforms/ansible.mdx b/docs/integrations/platforms/ansible.mdx index 5c4f34784..69219318a 100644 --- a/docs/integrations/platforms/ansible.mdx +++ b/docs/integrations/platforms/ansible.mdx @@ -34,8 +34,54 @@ $ pip install infisicalsdk You can either call modules by their Fully Qualified Collection Name (FQCN), such as `infisical.vault.read_secrets`, or you can call modules by their short name if you list the `infisical.vault` collection in the playbook's collections keyword: +### Authentication -```bash +The Infisical Ansible Collection supports [Universal Auth](/documentation/platform/identities/universal-auth) and [OIDC](/documentation/platform/identities/oidc-auth/general) for authenticating against Infisical. + + + + + Using Universal Auth for authentication is the most straight-forward way to get started with using the Ansible collection. + + To use Universal Auth, you need to provide the Client ID and Client Secret of your Infisical Machine Identity. + + ```yaml + lookup('infisical.vault.read_secrets', auth_method="universal-auth" universal_auth_client_id='', universal_auth_client_secret='' ...rest) + ``` + + You can also provide the `auth_method`, `universal_auth_client_id`, and `universal_auth_client_secret` parameters through environment variables: + + | Parameter Name | Environment Variable Name | + | ------------------------------ | ---------------------------------------- | + | `auth_method` | `INFISICAL_AUTH_METHOD` | + | `universal_auth_client_id` | `INFISICAL_UNIVERSAL_AUTH_CLIENT_ID` | + | `universal_auth_client_secret` | `INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET` | + + + + To use OIDC Auth, you'll need to provide the ID of your machine identity, and the OIDC JWT to be used for authentication. + + + Please note that in order to use OIDC Auth, you must have `1.0.10` or newer of the `infisicalsdk` package installed. + + + ```yaml + lookup('infisical.vault.read_secrets', auth_method="oidc-auth" identity_id='', jwt='' ...rest) + ``` + You can also provide the `auth_method`, `identity_id`, and `jwt` parameters through environment variables: + + | Parameter Name | Environment Variable Name | + | --------------- | ------------------------- | + | auth_method | `INFISICAL_AUTH_METHOD` | + | identity_id | `INFISICAL_IDENTITY_ID` | + | jwt | `INFISICAL_JWT` | + + + + +### Examples + +```yaml --- vars: read_all_secrets_within_scope: "{{ lookup('infisical.vault.read_secrets', universal_auth_client_id='<>', universal_auth_client_secret='<>', project_id='<>', path='/', env_slug='dev', url='https://spotify.infisical.com') }}" From 1159b74bdbf87430ff732f66ff970f74739228b8 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard Date: Thu, 28 Aug 2025 21:20:00 +0200 Subject: [PATCH 2/2] Update ansible.mdx --- docs/integrations/platforms/ansible.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/integrations/platforms/ansible.mdx b/docs/integrations/platforms/ansible.mdx index 69219318a..85f63079f 100644 --- a/docs/integrations/platforms/ansible.mdx +++ b/docs/integrations/platforms/ansible.mdx @@ -46,7 +46,7 @@ The Infisical Ansible Collection supports [Universal Auth](/documentation/platfo To use Universal Auth, you need to provide the Client ID and Client Secret of your Infisical Machine Identity. ```yaml - lookup('infisical.vault.read_secrets', auth_method="universal-auth" universal_auth_client_id='', universal_auth_client_secret='' ...rest) + lookup('infisical.vault.read_secrets', auth_method="universal-auth", universal_auth_client_id='', universal_auth_client_secret='' ...rest) ``` You can also provide the `auth_method`, `universal_auth_client_id`, and `universal_auth_client_secret` parameters through environment variables: @@ -66,7 +66,7 @@ The Infisical Ansible Collection supports [Universal Auth](/documentation/platfo ```yaml - lookup('infisical.vault.read_secrets', auth_method="oidc-auth" identity_id='', jwt='' ...rest) + lookup('infisical.vault.read_secrets', auth_method="oidc-auth", identity_id='', jwt='' ...rest) ``` You can also provide the `auth_method`, `identity_id`, and `jwt` parameters through environment variables: