mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
139 lines
6.4 KiB
Plaintext
139 lines
6.4 KiB
Plaintext
---
|
|
title: "GCP Secret Manager"
|
|
description: "How to sync secrets from Infisical to GCP Secret Manager"
|
|
---
|
|
|
|
<Tabs>
|
|
<Tab title="Usage">
|
|
|
|
<AccordionGroup>
|
|
<Accordion title="Connect with OAuth2">
|
|
|
|
Prerequisites:
|
|
|
|
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
|
## Navigate to your project's integrations tab
|
|
|
|

|
|
|
|
## Authorize Infisical for GCP
|
|
|
|
Press on the GCP Secret Manager tile and select **Continue with OAuth**
|
|
|
|

|
|
|
|
Grant Infisical access to GCP.
|
|
|
|

|
|
|
|
<Info>
|
|
If this is your project's first cloud integration, then you'll have to grant
|
|
Infisical access to your project's environment variables. Although this step
|
|
breaks E2EE, it's necessary for Infisical to sync the environment variables to
|
|
the cloud platform.
|
|
</Info>
|
|
|
|
## Start integration
|
|
|
|
Select which Infisical environment secrets you want to sync to which GCP secret manager project. Lastly, press create integration to start syncing secrets to GCP secret manager.
|
|
|
|

|
|

|
|
|
|
<Note>
|
|
Secrets synced from Infisical to GCP Secret Manager are automatically labeled `managed-by:infisical` to avoid overwriting existing values in GCP Secret Manager.
|
|
</Note>
|
|
|
|
<Warning>
|
|
Using Infisical to sync secrets to GCP Secret Manager requires that you enable
|
|
the Service Usage API and Cloud Resource Manager API in the Google Cloud project you want to sync secrets to. More on that [here](https://cloud.google.com/service-usage/docs/set-up-development-environment).
|
|
</Warning>
|
|
</Accordion>
|
|
<Accordion title="Connect with Service Account JSON">
|
|
Prerequisites:
|
|
|
|
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
|
|
- Have a GCP project and have/create a [service account](https://cloud.google.com/iam/docs/service-account-overview) in it
|
|
|
|
## Grant the service account permissions for GCP Secret Manager
|
|
|
|
Navigate to **IAM & Admin** page in GCP and add the **Secret Manager Admin** and **Service Usage Admin** roles to the service account.
|
|
|
|

|
|
|
|
<Info>
|
|
For enhanced security, you may want to assign more granular permissions to the service account. At minimum,
|
|
the service account should be able to read/write secrets from/to GCP Secret Manager (e.g. **Secret Manager Admin** role)
|
|
and list which GCP services are enabled/disabled (e.g. **Service Usage Admin** role).
|
|
</Info>
|
|
|
|
## Navigate to your project's integrations tab
|
|
|
|

|
|
|
|
## Authorize Infisical for GCP
|
|
|
|
Press on the GCP Secret Manager tile and paste in your **GCP Service Account JSON** (you can create and download the JSON for your
|
|
service account in IAM & Admin > Service Accounts > Service Account > Keys).
|
|
|
|

|
|
|
|

|
|
|
|
<Info>
|
|
If this is your project's first cloud integration, then you'll have to grant
|
|
Infisical access to your project's environment variables. Although this step
|
|
breaks E2EE, it's necessary for Infisical to sync the environment variables to
|
|
the cloud platform.
|
|
</Info>
|
|
|
|
## Start integration
|
|
|
|
Select which Infisical environment secrets you want to sync to the GCP secret manager project. Lastly, press create integration to start syncing secrets to GCP secret manager.
|
|
|
|

|
|

|
|
|
|
<Note>
|
|
Secrets synced from Infisical to GCP Secret Manager are automatically labeled `managed-by:infisical` to avoid overwriting existing values in GCP Secret Manager.
|
|
</Note>
|
|
|
|
<Warning>
|
|
Using Infisical to sync secrets to GCP Secret Manager requires that you enable
|
|
the Service Usage API and Cloud Resource Manager API in the Google Cloud project you want to sync secrets to. More on that [here](https://cloud.google.com/service-usage/docs/set-up-development-environment).
|
|
</Warning>
|
|
</Accordion>
|
|
</AccordionGroup>
|
|
</Tab>
|
|
<Tab title="Self-Hosted Setup">
|
|
Using the GCP Secret Manager integration (via the OAuth2 method) on a self-hosted instance of Infisical requires configuring an OAuth2 application in GCP
|
|
and registering your instance with it.
|
|
|
|
## Create an OAuth2 application in GCP
|
|
|
|
Navigate to your project API & Services > Credentials to create a new OAuth2 application.
|
|
|
|

|
|

|
|
|
|
Create the application. As part of the form, add to **Authorized redirect URIs**: `https://your-domain.com/integrations/gcp-secret-manager/oauth2/callback`.
|
|
|
|

|
|
|
|
## Add your OAuth2 application credentials to Infisical
|
|
|
|
Obtain the **Client ID** and **Client Secret** for your GCP OAuth2 application.
|
|
|
|

|
|
|
|
Back in your Infisical instance, add two new environment variables for the credentials of your GCP OAuth2 application:
|
|
|
|
- `CLIENT_ID_GCP_SECRET_MANAGER`: The **Client ID** of your GCP OAuth2 application.
|
|
- `CLIENT_SECRET_GCP_SECRET_MANAGER`: The **Client Secret** of your GCP OAuth2 application.
|
|
|
|
Once added, restart your Infisical instance and use the GCP Secret Manager integration.
|
|
|
|
</Tab>
|
|
</Tabs>
|
|
|