mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat(docs): Hashicorp Vault App Connection & Secret Sync Docs
This commit is contained in:
190
docs/integrations/app-connections/hashicorp-vault.mdx
Normal file
190
docs/integrations/app-connections/hashicorp-vault.mdx
Normal file
@@ -0,0 +1,190 @@
|
||||
---
|
||||
title: "Hashicorp Vault Connection"
|
||||
description: "Learn how to configure a Hashicorp Vault Connection for Infisical."
|
||||
---
|
||||
|
||||
<Note>
|
||||
The Hashicorp Vault UI may vary based on whether you're self-hosting or using HCP, but the written directions should still be universal.
|
||||
</Note>
|
||||
|
||||
Infisical supports two methods for connecting to Hashicorp Vault.
|
||||
|
||||
<Tabs>
|
||||
<Tab title="App Role (Recommended)">
|
||||
<Steps>
|
||||
<Step title="Navigate to Vault Access">
|
||||

|
||||
</Step>
|
||||
<Step title="Enable New Method">
|
||||
In the **Authentication Methods** tab, click on **Enable new method**.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Select AppRole">
|
||||

|
||||
</Step>
|
||||
<Step title="Enable Method">
|
||||
You may change the name of the method, but we suggest keeping it as `approle`.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Navigate to Vault Policies">
|
||||
From the home page, navigate to **Policies**.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Create ACL Policy">
|
||||

|
||||
</Step>
|
||||
<Step title="Create Policy">
|
||||
You may name your policy whatever you want, but remember the name as it will be used in future steps.
|
||||
|
||||
<Note>
|
||||
Ensure that you replace the policy path so that it matches with an existing KV Secrets Engine mount and path.
|
||||
</Note>
|
||||
|
||||
```hcl
|
||||
path "demo_mount/data/demo_path/demo_subpath" {
|
||||
capabilities = [ "create", "read", "update" ]
|
||||
}
|
||||
|
||||
path "sys/mounts" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
```
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Run Shell Commands">
|
||||
**Open Vault Shell**
|
||||
|
||||

|
||||
|
||||
<Note>
|
||||
If you used custom approle or policy names in previous steps, you'll need to customize the following commands.
|
||||
</Note>
|
||||
|
||||
**Create Infisical Role**
|
||||
|
||||
```hcl
|
||||
vault write auth/approle/role/infisical token_policies="infisical-policy" token_ttl=30s token_max_ttl=2m
|
||||
```
|
||||
|
||||
**Read RoleID**
|
||||
|
||||
```hcl
|
||||
vault read auth/approle/role/infisical/role-id
|
||||
```
|
||||
|
||||
**Generate New SecretID**
|
||||
|
||||
```hcl
|
||||
vault write -force auth/approle/role/infisical/secret-id
|
||||
```
|
||||
|
||||
Your shell output should look similar to the image below. Save the RoleID and SecretID values for later steps.
|
||||
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
<Tab title="Access Token">
|
||||
## Get a Hashicorp Vault Access Token
|
||||
|
||||
Open your profile dropdown and click **Copy token**. This token will be used in later steps.
|
||||
|
||||

|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
## Getting Vault Instance URL
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Self Hosted">
|
||||
On self-hosted instances, simply copy your vault's base URL. (Ex. `https://vault.mycompany.com`)
|
||||
|
||||
Save this value for later steps.
|
||||
</Tab>
|
||||
<Tab title="HCP">
|
||||
On HCP instances, you may need to navigate to **Cluster Overview** to see your cluster URL. Save this value for later steps.
|
||||
|
||||

|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
## Setup Vault Connection in Infisical
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
<Steps>
|
||||
<Step title="Navigate to App Connections">
|
||||
In your Infisical dashboard, go to **Organization Settings** and select the **App Connections** tab.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Add Connection">
|
||||
Click the **+ Add Connection** button and select the **Hashicorp Vault Connection** option.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Configure Connection">
|
||||
Configure your Vault Connection using the Instance URL and credentials from the steps above. **Depending on if you chose to authenticate with an Access Token or AppRole, you may need to input different information.**
|
||||
|
||||

|
||||
|
||||
- **Name**: The name of the connection being created. Must be slug-friendly.
|
||||
- **Description**: An optional description to provide details about this connection.
|
||||
- **Instance URL**: The URL of your Hashicorp Vault instance.
|
||||
- **Access Token**: The Access Token generated in the steps above (if using Access Token authentication method).
|
||||
- **Role ID**: The Role ID generated in the steps above (if using AppRole authentication method).
|
||||
- **Secret ID**: The Secret ID generated in the steps above (if using AppRole authentication method).
|
||||
</Step>
|
||||
<Step title="Connection Created">
|
||||
Your Vault Connection is now available for use.
|
||||

|
||||
</Step>
|
||||
</Steps>
|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create a Vault Connection, make an API request to the [Create Hashicorp Vault
|
||||
Connection](/api-reference/endpoints/app-connections/hashicorp-vault/create) API endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/app-connections/hashicorp-vault \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-vault-connection",
|
||||
"method": "app-role",
|
||||
"credentials": {
|
||||
"instanceUrl": "https://vault.mycompany.com",
|
||||
"roleId": "4797c4fa-7794-71f0-c8b1-7c87759df5bf",
|
||||
"secretId": "ad24df93-19c8-c865-9997-6b8513253d3a"
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"appConnection": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"name": "my-vault-connection",
|
||||
"version": 1,
|
||||
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"createdAt": "2025-04-01T05:31:56Z",
|
||||
"updatedAt": "2025-04-01T05:31:56Z",
|
||||
"app": "hashicorp-vault",
|
||||
"method": "app-role",
|
||||
"credentials": {
|
||||
"instanceUrl": "https://vault.mycompany.com",
|
||||
"roleId": "4797c4fa-7794-71f0-c8b1-7c87759df5bf"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
Reference in New Issue
Block a user