feat(docs): Hashicorp Vault App Connection & Secret Sync Docs

This commit is contained in:
x
2025-04-24 21:22:44 -04:00
parent 92084ccd47
commit fab385fdd9
55 changed files with 450 additions and 159 deletions

View File

@@ -0,0 +1,190 @@
---
title: "Hashicorp Vault Connection"
description: "Learn how to configure a Hashicorp Vault Connection for Infisical."
---
<Note>
The Hashicorp Vault UI may vary based on whether you're self-hosting or using HCP, but the written directions should still be universal.
</Note>
Infisical supports two methods for connecting to Hashicorp Vault.
<Tabs>
<Tab title="App Role (Recommended)">
<Steps>
<Step title="Navigate to Vault Access">
![Vault Access](/images/app-connections/hashicorp-vault/vault-access.png)
</Step>
<Step title="Enable New Method">
In the **Authentication Methods** tab, click on **Enable new method**.
![Vault Enable Method](/images/app-connections/hashicorp-vault/vault-authentication-methods.png)
</Step>
<Step title="Select AppRole">
![Vault AppRole](/images/app-connections/hashicorp-vault/vault-approle.png)
</Step>
<Step title="Enable Method">
You may change the name of the method, but we suggest keeping it as `approle`.
![Vault Enable Method](/images/app-connections/hashicorp-vault/vault-enable-method.png)
</Step>
<Step title="Navigate to Vault Policies">
From the home page, navigate to **Policies**.
![Vault Policies Navigate](/images/app-connections/hashicorp-vault/vault-policies-navigate.png)
</Step>
<Step title="Create ACL Policy">
![Vault Policies Page](/images/app-connections/hashicorp-vault/vault-policies-page.png)
</Step>
<Step title="Create Policy">
You may name your policy whatever you want, but remember the name as it will be used in future steps.
<Note>
Ensure that you replace the policy path so that it matches with an existing KV Secrets Engine mount and path.
</Note>
```hcl
path "demo_mount/data/demo_path/demo_subpath" {
capabilities = [ "create", "read", "update" ]
}
path "sys/mounts" {
capabilities = ["read"]
}
```
![Vault Create Policy](/images/app-connections/hashicorp-vault/vault-create-policy.png)
</Step>
<Step title="Run Shell Commands">
**Open Vault Shell**
![Vault Shell](/images/app-connections/hashicorp-vault/vault-shell.png)
<Note>
If you used custom approle or policy names in previous steps, you'll need to customize the following commands.
</Note>
**Create Infisical Role**
```hcl
vault write auth/approle/role/infisical token_policies="infisical-policy" token_ttl=30s token_max_ttl=2m
```
**Read RoleID**
```hcl
vault read auth/approle/role/infisical/role-id
```
**Generate New SecretID**
```hcl
vault write -force auth/approle/role/infisical/secret-id
```
Your shell output should look similar to the image below. Save the RoleID and SecretID values for later steps.
![Vault Shell Output](/images/app-connections/hashicorp-vault/vault-shell-output.png)
</Step>
</Steps>
</Tab>
<Tab title="Access Token">
## Get a Hashicorp Vault Access Token
Open your profile dropdown and click **Copy token**. This token will be used in later steps.
![Vault Profile Copy Token](/images/app-connections/hashicorp-vault/vault-profile-token.png)
</Tab>
</Tabs>
## Getting Vault Instance URL
<Tabs>
<Tab title="Self Hosted">
On self-hosted instances, simply copy your vault's base URL. (Ex. `https://vault.mycompany.com`)
Save this value for later steps.
</Tab>
<Tab title="HCP">
On HCP instances, you may need to navigate to **Cluster Overview** to see your cluster URL. Save this value for later steps.
![Vault Cluster URLs](/images/app-connections/hashicorp-vault/vault-cluster-urls.png)
</Tab>
</Tabs>
## Setup Vault Connection in Infisical
<Tabs>
<Tab title="Infisical UI">
<Steps>
<Step title="Navigate to App Connections">
In your Infisical dashboard, go to **Organization Settings** and select the **App Connections** tab.
![App Connections Tab](/images/app-connections/general/add-connection.png)
</Step>
<Step title="Add Connection">
Click the **+ Add Connection** button and select the **Hashicorp Vault Connection** option.
![Select Vault Connection](/images/app-connections/hashicorp-vault/vault-infisical-connect-page.png)
</Step>
<Step title="Configure Connection">
Configure your Vault Connection using the Instance URL and credentials from the steps above. **Depending on if you chose to authenticate with an Access Token or AppRole, you may need to input different information.**
![Vault Configure Connection](/images/app-connections/hashicorp-vault/vault-infisical-connect-modal.png)
- **Name**: The name of the connection being created. Must be slug-friendly.
- **Description**: An optional description to provide details about this connection.
- **Instance URL**: The URL of your Hashicorp Vault instance.
- **Access Token**: The Access Token generated in the steps above (if using Access Token authentication method).
- **Role ID**: The Role ID generated in the steps above (if using AppRole authentication method).
- **Secret ID**: The Secret ID generated in the steps above (if using AppRole authentication method).
</Step>
<Step title="Connection Created">
Your Vault Connection is now available for use.
![Vault Connection Created](/images/app-connections/hashicorp-vault/vault-infisical-connect-success.png)
</Step>
</Steps>
</Tab>
<Tab title="API">
To create a Vault Connection, make an API request to the [Create Hashicorp Vault
Connection](/api-reference/endpoints/app-connections/hashicorp-vault/create) API endpoint.
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/app-connections/hashicorp-vault \
--header 'Content-Type: application/json' \
--data '{
"name": "my-vault-connection",
"method": "app-role",
"credentials": {
"instanceUrl": "https://vault.mycompany.com",
"roleId": "4797c4fa-7794-71f0-c8b1-7c87759df5bf",
"secretId": "ad24df93-19c8-c865-9997-6b8513253d3a"
}
}'
```
### Sample response
```bash Response
{
"appConnection": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "my-vault-connection",
"version": 1,
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2025-04-01T05:31:56Z",
"updatedAt": "2025-04-01T05:31:56Z",
"app": "hashicorp-vault",
"method": "app-role",
"credentials": {
"instanceUrl": "https://vault.mycompany.com",
"roleId": "4797c4fa-7794-71f0-c8b1-7c87759df5bf"
}
}
}
```
</Tab>
</Tabs>