mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat(docs): PAM docs & small UI change
This commit is contained in:
@@ -773,6 +773,15 @@
|
|||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"item": "Infisical PAM",
|
||||||
|
"groups": [
|
||||||
|
{
|
||||||
|
"group": "Infisical PAM",
|
||||||
|
"pages": ["documentation/platform/pam/overview"]
|
||||||
|
}
|
||||||
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -38,3 +38,4 @@ Infisical consists of several tightly integrated products, each designed to solv
|
|||||||
- [Infisical PKI](/documentation/platform/pki/overview): Issue and manage X.509 certificates using protocols like EST, with support for internal and external CAs.
|
- [Infisical PKI](/documentation/platform/pki/overview): Issue and manage X.509 certificates using protocols like EST, with support for internal and external CAs.
|
||||||
- [Infisical SSH](/documentation/platform/ssh/overview): Provide short-lived SSH access to servers using certificate-based authentication, replacing static keys with policy-driven, time-bound control.
|
- [Infisical SSH](/documentation/platform/ssh/overview): Provide short-lived SSH access to servers using certificate-based authentication, replacing static keys with policy-driven, time-bound control.
|
||||||
- [Infisical KMS](/documentation/platform/kms/overview): Encrypt and decrypt data using centrally managed keys with enforced access policies and full audit visibility.
|
- [Infisical KMS](/documentation/platform/kms/overview): Encrypt and decrypt data using centrally managed keys with enforced access policies and full audit visibility.
|
||||||
|
- [Infisical PAM](/documentation/platform/pam/overview): Manage access to resources like databases, servers, and accounts with policy-based controls and approvals.
|
||||||
|
|||||||
@@ -40,6 +40,12 @@ description: "The open source platform for managing secrets, certificates, and s
|
|||||||
>
|
>
|
||||||
Replace static SSH keys with short-lived SSH certificates to simplify access and improve security.
|
Replace static SSH keys with short-lived SSH certificates to simplify access and improve security.
|
||||||
</Card>
|
</Card>
|
||||||
|
<Card
|
||||||
|
title="Infisical PAM"
|
||||||
|
href="/documentation/platform/pam/overview"
|
||||||
|
>
|
||||||
|
Manage access to resources like databases, servers, and accounts with policy-based controls and approvals.
|
||||||
|
</Card>
|
||||||
</Columns>
|
</Columns>
|
||||||
|
|
||||||
<Columns cols="1">
|
<Columns cols="1">
|
||||||
|
|||||||
53
docs/documentation/platform/pam/overview.mdx
Normal file
53
docs/documentation/platform/pam/overview.mdx
Normal file
@@ -0,0 +1,53 @@
|
|||||||
|
---
|
||||||
|
title: "Infisical PAM"
|
||||||
|
sidebarTitle: "Overview"
|
||||||
|
description: "Learn how to manage access to resources like databases, servers, and accounts with policy-based controls and approvals."
|
||||||
|
---
|
||||||
|
|
||||||
|
Infisical Privileged Access Management (PAM) provides a centralized way to manage and secure access to your critical infrastructure. It allows you to enforce fine-grained, policy-based controls over resources like databases, servers, and more, ensuring that only authorized users can access sensitive systems, and only when they need to.
|
||||||
|
|
||||||
|
### How it Works
|
||||||
|
|
||||||
|
Infisical PAM employs a resource-based model to organize and manage access. This model is designed to be intuitive and scalable.
|
||||||
|
|
||||||
|
#### 1. Create a Resource
|
||||||
|
|
||||||
|
The first step is to define a resource you want to manage. A resource represents a target system, such as a PostgreSQL database. When creating a resource, you'll provide the necessary connection details, like the host and port.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
#### 2. Add Accounts to the Resource
|
||||||
|
|
||||||
|
Once a resource is created, you can add accounts to it. An account represents a specific set of credentials (e.g., a username and password) that can be used to access the resource. This allows you to manage multiple sets of credentials for a single database or server from one place.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
### Infisical PAM Features
|
||||||
|
|
||||||
|
#### Session Logging and Auditing
|
||||||
|
|
||||||
|
- **Session Logging**: All user sessions are extensively logged, providing a detailed and searchable record of activities performed during a session.
|
||||||
|
- **Audit Logging**: Every significant event, such as a user starting a session or accessing an account's credentials, is recorded in audit logs. This gives you complete visibility over your project.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
#### Automated Credential Rotation
|
||||||
|
|
||||||
|
Infisical PAM can automatically rotate account credentials to enhance your security posture.
|
||||||
|
|
||||||
|
Here’s how it works:
|
||||||
|
1. **Add a Rotation Account**: On the resource level, you configure a "rotation account." This is a master or privileged account that has the necessary permissions to change the passwords of other accounts on that same resource.
|
||||||
|

|
||||||
|
|
||||||
|
2. **Configure Rotation on Accounts**: For each individual account you want to rotate, you can simply enable rotation and set a desired interval (e.g., every 30 days).
|
||||||
|

|
||||||
|
|
||||||
|
Infisical will then use the rotation account on the resource to automatically update the credentials of the target account at the specified interval, eliminating credential staleness.
|
||||||
|
|
||||||
|
## FAQ
|
||||||
|
|
||||||
|
<AccordionGroup>
|
||||||
|
<Accordion title="What resources does Infisical PAM currently support?">
|
||||||
|
Infisical PAM currently supports PostgreSQL, with support for more databases, RDP, Kubernetes, social media accounts, and more coming soon.
|
||||||
|
</Accordion>
|
||||||
|
</AccordionGroup>
|
||||||
@@ -22,6 +22,7 @@ The supported project types are:
|
|||||||
- [Infisical PKI](/documentation/platform/pki/overview): Issue and manage X.509 certificates using protocols like EST, with support for internal and external CAs.
|
- [Infisical PKI](/documentation/platform/pki/overview): Issue and manage X.509 certificates using protocols like EST, with support for internal and external CAs.
|
||||||
- [Infisical SSH](/documentation/platform/ssh/overview): Provide short-lived SSH access to servers using certificate-based authentication, replacing static keys with policy-driven, time-bound control.
|
- [Infisical SSH](/documentation/platform/ssh/overview): Provide short-lived SSH access to servers using certificate-based authentication, replacing static keys with policy-driven, time-bound control.
|
||||||
- [Infisical KMS](/documentation/platform/kms/overview): Encrypt and decrypt data using centrally managed keys with enforced access policies and full audit visibility.
|
- [Infisical KMS](/documentation/platform/kms/overview): Encrypt and decrypt data using centrally managed keys with enforced access policies and full audit visibility.
|
||||||
|
- [Infisical PAM](/documentation/platform/pam/overview): Manage access to resources like databases, servers, and accounts with policy-based controls and approvals.
|
||||||
|
|
||||||
## Roles and Access Control
|
## Roles and Access Control
|
||||||
|
|
||||||
|
|||||||
BIN
docs/images/pam/overview/create-account.png
Normal file
BIN
docs/images/pam/overview/create-account.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 136 KiB |
BIN
docs/images/pam/overview/create-resource.png
Normal file
BIN
docs/images/pam/overview/create-resource.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 148 KiB |
BIN
docs/images/pam/overview/credential-rotation-account.png
Normal file
BIN
docs/images/pam/overview/credential-rotation-account.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 598 KiB |
BIN
docs/images/pam/overview/rotate-credentials-account.png
Normal file
BIN
docs/images/pam/overview/rotate-credentials-account.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 577 KiB |
BIN
docs/images/pam/overview/session-page.png
Normal file
BIN
docs/images/pam/overview/session-page.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 1.1 MiB |
@@ -55,7 +55,7 @@ export const RotateAccountFields = () => {
|
|||||||
dropdownContainerClassName="max-w-none"
|
dropdownContainerClassName="max-w-none"
|
||||||
isDisabled={!rotationEnabled}
|
isDisabled={!rotationEnabled}
|
||||||
dropdownContainerStyle={{
|
dropdownContainerStyle={{
|
||||||
width: "120px"
|
width: "130px"
|
||||||
}}
|
}}
|
||||||
>
|
>
|
||||||
<SelectItem value="2592000">30 Days</SelectItem>
|
<SelectItem value="2592000">30 Days</SelectItem>
|
||||||
|
|||||||
Reference in New Issue
Block a user