mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
92 lines
4.4 KiB
YAML
92 lines
4.4 KiB
YAML
apiVersion: secrets.infisical.com/v1alpha1
|
|
kind: InfisicalPushSecret
|
|
metadata:
|
|
name: infisical-api-secret-sample-push
|
|
spec:
|
|
resyncInterval: 1m
|
|
hostAPI: https://app.infisical.com/api # This is the default hostAPI for the Infisical API
|
|
|
|
# Optional, defaults to replacement.
|
|
updatePolicy: Replace # If set to replace, existing secrets inside Infisical will be replaced by the value of the PushSecret on sync.
|
|
|
|
# Optional, defaults to no deletion.
|
|
deletionPolicy: Delete # If set to delete, the secret(s) inside Infisical managed by the operator, will be deleted if the InfisicalPushSecret CRD is deleted.
|
|
|
|
destination:
|
|
projectId: <project-id>
|
|
environmentSlug: <env-slug>
|
|
secretsPath: <secret-path>
|
|
|
|
push:
|
|
secret:
|
|
secretName: push-secret-demo-with-templating
|
|
secretNamespace: default
|
|
template:
|
|
includeAllSecrets: false
|
|
data:
|
|
PKCS12_CERT_NO_PASSWORD: "{{ .PKCS12_CONTENT_NO_PASSWORD.Value | decodeBase64ToBytes | pkcs12cert }}"
|
|
PKCS12_KEY_NO_PASSWORD: "{{ .PKCS12_CONTENT_NO_PASSWORD.Value | decodeBase64ToBytes | pkcs12key }}"
|
|
|
|
PKCS12_CERT_WITH_PASSWORD: '{{ .PKCS12_CONTENT_WITH_PASSWORD.Value | decodeBase64ToBytes | pkcs12certPass "123456" }}'
|
|
PKCS12_KEY_WITH_PASSWORD: '{{ .PKCS12_CONTENT_WITH_PASSWORD.Value | decodeBase64ToBytes | pkcs12keyPass "123456" }}'
|
|
|
|
PEM_TO_PKCS12_PASS: '{{ pemToPkcs12Pass
|
|
(.PKCS12_CONTENT_WITH_PASSWORD.Value | decodeBase64ToBytes | pkcs12certPass "123456")
|
|
(.PKCS12_CONTENT_WITH_PASSWORD.Value | decodeBase64ToBytes | pkcs12keyPass "123456")
|
|
"123456" }}'
|
|
PEM_TO_PKCS12_NO_PASSWORD: "{{ pemToPkcs12
|
|
(.PKCS12_CONTENT_NO_PASSWORD.Value | decodeBase64ToBytes | pkcs12cert)
|
|
(.PKCS12_CONTENT_NO_PASSWORD.Value | decodeBase64ToBytes | pkcs12key)
|
|
}}"
|
|
|
|
FULL_PEM_TO_PKCS12_PASS: '{{ fullPemToPkcs12Pass
|
|
(.PKCS12_CONTENT_WITH_PASSWORD.Value | decodeBase64ToBytes | pkcs12certPass "123456")
|
|
(.PKCS12_CONTENT_WITH_PASSWORD.Value | decodeBase64ToBytes | pkcs12keyPass "123456")
|
|
"123456" }}'
|
|
FULL_PEM_TO_PKCS12_NO_PASSWORD: "{{ fullPemToPkcs12
|
|
(.PKCS12_CONTENT_NO_PASSWORD.Value | decodeBase64ToBytes | pkcs12cert)
|
|
(.PKCS12_CONTENT_NO_PASSWORD.Value | decodeBase64ToBytes | pkcs12key)
|
|
}}"
|
|
|
|
FILTERED_PEM_CERT: '{{ filterPEM "CERTIFICATE" (printf "-----BEGIN CERTIFICATE-----\n%s\n-----END CERTIFICATE-----\n-----BEGIN CERTIFICATE-----\n%s\n-----END CERTIFICATE-----" .JWK_PRIVATE_RSA_PKCS8.Value .PKCS12_CONTENT_NO_PASSWORD.Value) }}'
|
|
FILTERED_PEM_KEY: '{{ filterPEM "PRIVATE KEY" (printf "-----BEGIN PRIVATE KEY-----\n%s\n-----END PRIVATE KEY-----\n-----BEGIN PRIVATE KEY-----\n%s\n-----END PRIVATE KEY-----" .JWK_PRIVATE_RSA_PKCS8.Value .PKCS12_CONTENT_NO_PASSWORD.Value) }}'
|
|
|
|
# Will be empty with our current test data as there is no chain
|
|
CERT_CHAIN: '{{ filterCertChain "CERTIFICATE" (.PKCS12_CONTENT_NO_PASSWORD.Value | decodeBase64ToBytes | pkcs12cert) }}'
|
|
|
|
JWK_RSA_PUBLIC_PEM: "{{ jwkPublicKeyPem .JWK_PUB_RSA.Value }}"
|
|
JWK_ECDSA_PUBLIC_PEM: "{{ jwkPublicKeyPem .JWK_PUB_ECDSA.Value }}"
|
|
|
|
JWK_ECDSA_PRIVATE_PEM: "{{ jwkPrivateKeyPem .JWK_PRIV_ECDSA.Value }}"
|
|
JWK_RSA_PRIVATE_PEM: "{{ jwkPrivateKeyPem .JWK_PRIV_RSA.Value }}"
|
|
|
|
JSON_STR_TO_YAML: "{{ .TEST_JSON_DATA.Value | fromJsonStringToJson | toYaml }}"
|
|
|
|
FROM_YAML_TO_JSON: "{{ .TEST_YAML_STRING.Value | fromYaml | toJson }}"
|
|
YAML_ROUNDTRIP: "{{ .TEST_YAML_STRING.Value | fromYaml | toYaml }}"
|
|
|
|
TEST_LOWERCASE_STRING: "{{ .TEST_LOWERCASE_STRING.Value | upper }}"
|
|
|
|
# Only have one authentication method defined or you are likely to run into authentication issues.
|
|
# Remove all except one authentication method.
|
|
authentication:
|
|
awsIamAuth:
|
|
identityId: <machine-identity-id>
|
|
azureAuth:
|
|
identityId: <machine-identity-id>
|
|
gcpIamAuth:
|
|
identityId: <machine-identity-id>
|
|
serviceAccountKeyFilePath: </path-to-service-account-key-file.json>
|
|
gcpIdTokenAuth:
|
|
identityId: <machine-identity-id>
|
|
kubernetesAuth:
|
|
identityId: <machine-identity-id>
|
|
serviceAccountRef:
|
|
name: <secret-name>
|
|
namespace: <secret-namespace>
|
|
universalAuth:
|
|
credentialsRef:
|
|
secretName: <secret-name> # universal-auth-credentials
|
|
secretNamespace: <secret-namespace> # default
|
|
|