Merge branch 'Infisical:main' into cloudflare-workers
@@ -155,7 +155,7 @@ entropy = 3.5
|
|||||||
|
|
||||||
# Keywords are used for pre-regex check filtering.
|
# Keywords are used for pre-regex check filtering.
|
||||||
# If rule has keywords but the text fragment being scanned doesn't have at least one of it's keywords, it will be skipped for processing further.
|
# If rule has keywords but the text fragment being scanned doesn't have at least one of it's keywords, it will be skipped for processing further.
|
||||||
# Ideally these values should either be part of the idenitifer or unique strings specific to the rule's regex
|
# Ideally these values should either be part of the identifier or unique strings specific to the rule's regex
|
||||||
# (introduced in v8.6.0)
|
# (introduced in v8.6.0)
|
||||||
keywords = [
|
keywords = [
|
||||||
"auth",
|
"auth",
|
||||||
|
|||||||
@@ -22,6 +22,6 @@ Each log contains the following data:
|
|||||||
|
|
||||||
- Event: The underlying action such as create, list, read, update, or delete secret(s).
|
- Event: The underlying action such as create, list, read, update, or delete secret(s).
|
||||||
- Actor: The entity responsible for performing or causing the event; this can be a user or service.
|
- Actor: The entity responsible for performing or causing the event; this can be a user or service.
|
||||||
- Timestamp: The date and time at which point the event occured.
|
- Timestamp: The date and time at which point the event occurred.
|
||||||
- Source (User agent + IP): The software (user agent) and network address (IP) from which the event was initiated.
|
- Source (User agent + IP): The software (user agent) and network address (IP) from which the event was initiated.
|
||||||
- Metadata: Additional data to provide context for each event. For example, this could be the path at which a secret was fetched from etc.
|
- Metadata: Additional data to provide context for each event. For example, this could be the path at which a secret was fetched from etc.
|
||||||
@@ -54,7 +54,7 @@ of the `/common` path within the development environment of the project; the tok
|
|||||||
There are a few reasons for why this might happen:
|
There are a few reasons for why this might happen:
|
||||||
|
|
||||||
- The service token has expired.
|
- The service token has expired.
|
||||||
- The service token is insufficently permissioned to interact with the secrets in the given environment and path.
|
- The service token is insufficiently permissioned to interact with the secrets in the given environment and path.
|
||||||
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
|
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
|
||||||
- (If using ST V3) The service token has not been activated yet.
|
- (If using ST V3) The service token has not been activated yet.
|
||||||
- (If using ST V3) The service token is being used from an untrusted IP.
|
- (If using ST V3) The service token is being used from an untrusted IP.
|
||||||
|
|||||||
|
After Width: | Height: | Size: 608 KiB |
|
After Width: | Height: | Size: 425 KiB |
|
After Width: | Height: | Size: 147 KiB |
|
After Width: | Height: | Size: 548 KiB |
|
After Width: | Height: | Size: 274 KiB |
|
After Width: | Height: | Size: 197 KiB |
|
After Width: | Height: | Size: 235 KiB |
|
After Width: | Height: | Size: 208 KiB |
|
After Width: | Height: | Size: 292 KiB |
|
After Width: | Height: | Size: 514 KiB |
|
After Width: | Height: | Size: 408 KiB |
|
After Width: | Height: | Size: 429 KiB |
@@ -0,0 +1,122 @@
|
|||||||
|
---
|
||||||
|
title: "Jenkins"
|
||||||
|
description: "How to effectively and securely manage secrets in Jenkins using Infisical"
|
||||||
|
---
|
||||||
|
|
||||||
|
Prerequisites:
|
||||||
|
|
||||||
|
- Set up and add secrets to [Infisical](https://app.infisical.com).
|
||||||
|
- You have a working Jenkins installation with the [credentials plugin](https://plugins.jenkins.io/credentials/) installed.
|
||||||
|
- You have the Infisical CLI installed on your Jenkins executor nodes or container images.
|
||||||
|
|
||||||
|
## Add Infisical Service Token to Jenkins
|
||||||
|
|
||||||
|
After setting up your project in Infisical and adding the Infisical CLI to container images, you will need to add the Infisical Service Token to Jenkins. Once you have generated the token, browse to **Manage Jenkins > Manage Credentials** in your Jenkins installation.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Click on the credential store you want to store the Infisical Service Token in. In this case, we're using the default Jenkins global store.
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
Each of your projects will have a different INFISICAL_SERVICE_TOKEN though.
|
||||||
|
As a result, it may make sense to spread these out into separate credential domains depending on your use case.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Now, click Add Credentials.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Choose **Secret text** from the **Kind** dropdown menu, paste the Infisical Service Token into the **Secret** field, enter `INFISICAL_SERVICE_TOKEN` into the **Description** field, and click **OK**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
When you're done, you should have a credential similar to the one below:
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
|
## Use Infisical in a Freestyle Project
|
||||||
|
|
||||||
|
To use Infisical in a Freestyle Project job, you'll need to expose the credential you created above in an environment variable. First, click New Item from the dashboard navigation sidebar:
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Enter the name of the job, choose the **Freestyle Project** option, and click **OK**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Scroll down to the **Build Environment** section and enable the **Use secret text(s) or file(s)** option. Then click **Add** under the **Bindings** section and choose **Secret text** from the dropdown menu.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Enter INFISICAL_SERVICE_TOKEN in the **Variable** field, select the **Specific credentials** option from the Credentials section and choose INFISICAL_SERVICE_TOKEN from the dropdown menu.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Scroll down to the **Build** section and choose **Execute shell** from the **Add build step** menu.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
In the command field, enter the following command and click **Save**:
|
||||||
|
|
||||||
|
```
|
||||||
|
infisical run -- printenv
|
||||||
|
```
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Finally, click **Build Now** from the navigation sidebar to test your new job.
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
Running into issues? Join Infisical's [community Slack](https://infisical.com/slack) for quick support.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
## Use Infisical in a Jenkins Pipeline
|
||||||
|
|
||||||
|
To use Infisical in a Pipeline job, you'll need to expose the credential you created above as an environment variable. First, click **New Item** from the dashboard navigation sidebar:
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Enter the name of the job, choose the **Pipeline** option, and click OK.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Scroll down to the **Pipeline** section, paste the following into the **Script** field, and click **Save**.
|
||||||
|
|
||||||
|
```
|
||||||
|
pipeline {
|
||||||
|
agent any
|
||||||
|
|
||||||
|
environment {
|
||||||
|
INFISICAL_SERVICE_TOKEN = credentials('INFISICAL_SERVICE_TOKEN')
|
||||||
|
}
|
||||||
|
|
||||||
|
stages {
|
||||||
|
stage('Run Infisical') {
|
||||||
|
steps {
|
||||||
|
sh("infisical secrets")
|
||||||
|
|
||||||
|
// doesn't work
|
||||||
|
// sh("docker run --rm test-container infisical secrets")
|
||||||
|
|
||||||
|
// works
|
||||||
|
// sh("docker run -e INFISICAL_SERVICE_TOKEN=${INFISICAL_SERVICE_TOKEN} --rm test-container infisical secrets")
|
||||||
|
|
||||||
|
// doesn't work
|
||||||
|
// sh("docker-compose up -d")
|
||||||
|
|
||||||
|
// works
|
||||||
|
// sh("INFISICAL_SERVICE_TOKEN=${INFISICAL_SERVICE_TOKEN} docker-compose up -d")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
This is a very basic sample that you can work from. Jenkins injects the INFISICAL_SERVICE_TOKEN environment variable defined in the pipeline into the shell the commands execute with, but there are some situations where that won't pass through properly – notably if you're executing docker containers on the executor machine. The examples above should give you some idea for how that will work.
|
||||||
|
|
||||||
|
Finally, click **Build Now** from the navigation sidebar to test your new job.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
title: "Ansible"
|
||||||
|
description: "How to use Infisical for secret management in Ansible"
|
||||||
|
---
|
||||||
|
|
||||||
|
The documentation for using Infisical to manage secrets in Ansible is currently available [here](https://galaxy.ansible.com/ui/repo/published/infisical/vault/).
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
Have any questions? Join Infisical's [community Slack](https://infisical.com/slack) for quick support.
|
||||||
|
</Info>
|
||||||
@@ -32,6 +32,6 @@ This section covers the internals of Infisical including its technical underpinn
|
|||||||
icon="ticket"
|
icon="ticket"
|
||||||
color="#3775a9"
|
color="#3775a9"
|
||||||
>
|
>
|
||||||
Learn best practices for utilizing Infisical sevrice tokens
|
Learn best practices for utilizing Infisical service tokens
|
||||||
</Card>
|
</Card>
|
||||||
</CardGroup>
|
</CardGroup>
|
||||||
|
|||||||
@@ -60,7 +60,7 @@ This token category is used by users and included in requests made from the Infi
|
|||||||
|
|
||||||
Each token is authenticated against the API and mapped to an existing user in Infisical. If no existing user is found for the token, the request is rejected by the API. Each token assumes the permission set of the user that it is mapped to. For example, if a user corresponding to a token is not allowed access to a certain organization or project, then the token is also not be valid for any requests concerning those specific resources.
|
Each token is authenticated against the API and mapped to an existing user in Infisical. If no existing user is found for the token, the request is rejected by the API. Each token assumes the permission set of the user that it is mapped to. For example, if a user corresponding to a token is not allowed access to a certain organization or project, then the token is also not be valid for any requests concerning those specific resources.
|
||||||
|
|
||||||
In the event of compromise, an attacker could use the token to impersonate the associated user and perform actions within the permission set of that user. While they could retrieve secrets for a project that the user is part of, they could not, however, decrypt secrets if the project follows Infisical's default zero-knowlege architecture. In any case, it would be critical for the user to invalidate this token and change their password immediately to prevent further unintended actions and consequences.
|
In the event of compromise, an attacker could use the token to impersonate the associated user and perform actions within the permission set of that user. While they could retrieve secrets for a project that the user is part of, they could not, however, decrypt secrets if the project follows Infisical's default zero-knowledge architecture. In any case, it would be critical for the user to invalidate this token and change their password immediately to prevent further unintended actions and consequences.
|
||||||
|
|
||||||
### Service token
|
### Service token
|
||||||
|
|
||||||
@@ -103,7 +103,7 @@ If using [Infisical Cloud](https://app.infisical.com), snapshots of MongoDB data
|
|||||||
|
|
||||||
### Offline usage
|
### Offline usage
|
||||||
|
|
||||||
Many teams and organizations use the [Infisical CLI](https://infisical.com/docs/cli/overview) to fetch and inject secrets back from Infisical into their applications and infrastructure locally; the CLI has offline fallback capabiltiies.
|
Many teams and organizations use the [Infisical CLI](https://infisical.com/docs/cli/overview) to fetch and inject secrets back from Infisical into their applications and infrastructure locally; the CLI has offline fallback capabilities.
|
||||||
|
|
||||||
If you have previously retrieved secrets for a specific project and environment, the `run/secret` command will utilize the saved secrets, even when offline, on subsequent fetch attempts to ensure that you always have access to secrets.
|
If you have previously retrieved secrets for a specific project and environment, the `run/secret` command will utilize the saved secrets, even when offline, on subsequent fetch attempts to ensure that you always have access to secrets.
|
||||||
|
|
||||||
@@ -141,7 +141,7 @@ For example, you can define a role provisioning access to secrets in a specific
|
|||||||
|
|
||||||
### Audit logging
|
### Audit logging
|
||||||
|
|
||||||
Infisical's audit logging feature spans 25+ events, tracking everything from permissioning changes to queries and mutations applied to secrets, for security and compliance teams at enterprises to monitor information access in the event of any suspicious activity or incident review. Every event is timestamped and information about actor, source (i.e. IP address, user-agent, etc.), and relevant metadata is included.
|
Infisical's audit logging feature spans 25+ events, tracking everything from permission changes to queries and mutations applied to secrets, for security and compliance teams at enterprises to monitor information access in the event of any suspicious activity or incident review. Every event is timestamped and information about actor, source (i.e. IP address, user-agent, etc.), and relevant metadata is included.
|
||||||
|
|
||||||
### IP allowlisting
|
### IP allowlisting
|
||||||
|
|
||||||
@@ -162,7 +162,7 @@ Please email [email protected] to request any reports including a letter of
|
|||||||
Whether or not Infisical or your employees can access data in the Infisical instance and/or storage backend depends on many factors how you use Infisical:
|
Whether or not Infisical or your employees can access data in the Infisical instance and/or storage backend depends on many factors how you use Infisical:
|
||||||
|
|
||||||
- Infisical Self-Hosted: Self-hosting Infisical is common amongst organizations that prefer to keep data on their own infrastructure usually to adhere to strict regulatory and compliance requirements. In this option, organizations retain full control over their data and therefore govern the data access policy of their Infisical instance and storage backend.
|
- Infisical Self-Hosted: Self-hosting Infisical is common amongst organizations that prefer to keep data on their own infrastructure usually to adhere to strict regulatory and compliance requirements. In this option, organizations retain full control over their data and therefore govern the data access policy of their Infisical instance and storage backend.
|
||||||
- Infisical Cloud: Using Infisical's managed service, [Infisical Cloud](https://app.infisical.com) means delegating data oversight and management to Infisical. Under our policy controls, employees are only granted access to parts of infrastructure according to principle of least privilege; this is especially relevent to customer data can only be accessed currently by executive management of Infisical. Moreover, any changes to sensitive customer data is prohibited without explicit customer approval.
|
- Infisical Cloud: Using Infisical's managed service, [Infisical Cloud](https://app.infisical.com) means delegating data oversight and management to Infisical. Under our policy controls, employees are only granted access to parts of infrastructure according to principle of least privilege; this is especially relevant to customer data can only be accessed currently by executive management of Infisical. Moreover, any changes to sensitive customer data is prohibited without explicit customer approval.
|
||||||
|
|
||||||
It should be noted that, even on Infisical Cloud, it is physically impossible for employees of Infisical to view the values of secrets if users have not explicitly granted Infisical access to their project (i.e. opted out of zero-knowledge).
|
It should be noted that, even on Infisical Cloud, it is physically impossible for employees of Infisical to view the values of secrets if users have not explicitly granted Infisical access to their project (i.e. opted out of zero-knowledge).
|
||||||
|
|
||||||
|
|||||||
@@ -212,7 +212,8 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"integrations/platforms/kubernetes",
|
"integrations/platforms/kubernetes",
|
||||||
"integrations/frameworks/terraform"
|
"integrations/frameworks/terraform",
|
||||||
|
"integrations/platforms/ansible"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -240,21 +241,27 @@
|
|||||||
"integrations/cloud/northflank",
|
"integrations/cloud/northflank",
|
||||||
"integrations/cloud/hasura-cloud",
|
"integrations/cloud/hasura-cloud",
|
||||||
"integrations/cloud/terraform-cloud",
|
"integrations/cloud/terraform-cloud",
|
||||||
"integrations/cloud/teamcity",
|
|
||||||
"integrations/cloud/cloudflare-pages",
|
"integrations/cloud/cloudflare-pages",
|
||||||
"integrations/cloud/checkly",
|
|
||||||
"integrations/cloud/qovery",
|
"integrations/cloud/qovery",
|
||||||
"integrations/cloud/hashicorp-vault",
|
"integrations/cloud/hashicorp-vault",
|
||||||
"integrations/cloud/azure-key-vault",
|
"integrations/cloud/azure-key-vault",
|
||||||
"integrations/cloud/gcp-secret-manager",
|
"integrations/cloud/gcp-secret-manager",
|
||||||
"integrations/cloud/cloud-66",
|
"integrations/cloud/cloud-66",
|
||||||
"integrations/cloud/windmill",
|
"integrations/cloud/windmill"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"group": "CI/CD Integrations",
|
||||||
|
"pages": [
|
||||||
|
"integrations/cloud/teamcity",
|
||||||
|
"integrations/cloud/checkly",
|
||||||
"integrations/cicd/githubactions",
|
"integrations/cicd/githubactions",
|
||||||
"integrations/cicd/gitlab",
|
"integrations/cicd/gitlab",
|
||||||
"integrations/cicd/circleci",
|
"integrations/cicd/circleci",
|
||||||
"integrations/cicd/travisci",
|
"integrations/cicd/travisci",
|
||||||
"integrations/cicd/bitbucket",
|
"integrations/cicd/bitbucket",
|
||||||
"integrations/cicd/codefresh"
|
"integrations/cicd/codefresh",
|
||||||
|
"integrations/cicd/jenkins"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|||||||