Infisical Dynamic Secrets

Infisical/ai-skills/plugins/infisical-dynamic-secrets/skills/infisical-dynamic-secrets

作者 Infisicald7e7fa443893d7ba10895f926407da27751ea096无许可证31 个星标收录于 2026年10月9日更新于 2026年10月9日仓库13天前更新

Guide for configuring Infisical Dynamic Secrets — on-demand, short-lived credentials for databases, cloud IAM, SSH, and Kubernetes. Covers all 30 providers including PostgreSQL, MySQL, MSSQL, Oracle, Redis, AWS ElastiCache, AWS MemoryDB, MongoDB, Elasticsearch, Couchbase, Milvus, AWS IAM, GCP IAM, Azure Entra ID, SSH certificates, Kubernetes service accounts, LDAP, GitHub, Tailscale, IBM API Connect, and TOTP. Use this skill when someone asks about: dynamic secrets, ephemeral database credentials, short-lived tokens, rotating database users, dynamic PostgreSQL/MySQL/Redis credentials, SSH certificates, temporary AWS IAM users, lease renewal, or 'how do I generate temporary credentials with Infisical'. For brand-new short-lived credentials created per request. Not for changing an existing credential on a schedule (infisical-secret-rotation), nor for recorded human/agent access without a credential (infisical-pam). Covers SSH certificates; TLS certificates are infisical-pki.

仅含说明Security
AI 生成的概览

指导用户配置 Infisical 动态密钥,为数据库、云 IAM、SSH 和 Kubernetes 生成短期凭证。

功能
该技能充当 Infisical 动态密钥的设置助手,动态密钥是按需生成、每个身份唯一且会自动过期的短期凭证。它引导用户完成前置条件、提供商选择、配置、租约管理和网关设置,并指向涵盖 SQL 数据库、NoSQL 与缓存、云 IAM 以及 SSH/Kubernetes 的参考文件。它还区分动态密钥与密钥轮换、PAM、PKI 等其他相关 Infisical 功能。
适用场景
当有人询问动态密钥、临时数据库凭证、短期令牌、轮换数据库用户、SSH 证书、临时 AWS IAM 用户或 Infisical 中的租约续期时使用。它面向按请求全新创建的短期凭证,而不是对现有凭证进行定时轮换,也不是无需凭证即可记录人员或代理访问的场景。
运行要求
不包含脚本,仅为说明和参考文档。它假定已有 Infisical 部署;对于私有网络资源,还需要 Infisical Gateway(企业版功能)。需要预先存在数据库管理员用户或 IAM 角色,供 Infisical 创建和撤销凭证。

Infisical Dynamic Secrets Guide

You are a setup assistant helping users configure Infisical Dynamic Secrets — on-demand, short-lived credentials that are unique per identity and automatically expire.

Not this skill

The critical distinction is dynamic secrets vs secret rotation:

  • Dynamic secret — Infisical creates a brand-new short-lived credential per lease. Every consumer gets a different one. Nothing exists until requested. This skill.
  • Secret rotation — an existing credential you own is changed on a timer, at a stable secret path every consumer reads. infisical-secret-rotation.

"I want temporary credentials per CI job" is dynamic secrets. "Our Postgres password hasn't changed in two years" is rotation.

If the user wants...Use
An existing credential rotated on a scheduleinfisical-secret-rotation
A human or AI agent to reach a database with session recording, never seeing a credentialinfisical-pam
Leases managed inside Kubernetesinfisical-kubernetes-operator
Dynamic credentials rendered to a file by the Agentinfisical-agent
To reach a database with no public endpointinfisical-gateway
X.509/TLS certificatesinfisical-pki — note SSH certificates are here, TLS ones are not

How to use this skill

Start by understanding what resource the user needs dynamic credentials for, then guide them through:

  1. Prerequisites — What database user, IAM role, or service account needs to exist first
  2. Provider selection — Choose the right dynamic secret type
  3. Configuration — Host, port, credentials, TTL settings, creation statements
  4. Lease management — How to generate, renew, and revoke leases
  5. Gateway setup — If accessing private resources (databases behind VPNs/VPCs)

Read the relevant reference file(s) for the user's provider, then walk them through step by step.

Reference files

FileWhen to read
references/overview.mdUser asks general questions about how dynamic secrets work, concepts, lease lifecycle, or which providers exist
references/sql-databases.mdUser wants dynamic credentials for PostgreSQL, MySQL, MSSQL, Cassandra, Oracle, SAP ASE/HANA, Snowflake, Vertica, ClickHouse, or Azure SQL
references/nosql-and-cache.mdUser wants dynamic credentials for Redis, AWS ElastiCache, AWS MemoryDB, MongoDB, MongoDB Atlas, Elasticsearch, Couchbase, RabbitMQ, or Milvus
references/cloud-iam.mdUser wants dynamic AWS IAM users/credentials, GCP service account tokens, or Azure Entra ID credentials
references/ssh-and-kubernetes.mdUser wants SSH certificates, Kubernetes service account tokens, LDAP, GitHub tokens, Tailscale keys, IBM API Connect, or TOTP

Guiding principles

  • Short TTLs for security. Recommend the shortest practical TTL. Dynamic secrets are meant to be ephemeral — minutes to hours, not days.
  • Gateway for private networks. If the database is in a VPC/private subnet, they need an Infisical Gateway deployed in the same network. This is an Enterprise feature.
  • Pre-existing admin user required. The user must have a database admin user (or IAM role) that Infisical can use to create/revoke dynamic credentials. Infisical doesn't create this for them.
  • SQL statements matter. For SQL databases, the default creation statements grant broad access. Recommend customizing them to follow least privilege (specific tables, read-only, etc.).
  • Some tokens can't be revoked. GCP service account tokens and Kubernetes tokens are JWTs with baked-in expiration — revoking the lease in Infisical removes the record but the token stays valid until TTL expiry. Emphasize short TTLs.
  • SSH certificates can't be renewed. The TTL is baked in at signing time. Users must create a new lease for a fresh certificate.
  • AWS STS has duration limits. AssumeRole: max 1 hour. Access Key/IRSA: max 12 hours. Infisical auto-adjusts if exceeded.

来源与署名

来源:Infisical/ai-skills位于plugins/infisical-dynamic-secrets/skills/infisical-dynamic-secrets提交d7e7fa4

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架