infisical-user-setup-guide

v2026.09.24

Interactive setup guide for using Infisical as a secret management tool in your projects. Helps users integrate Infisical into local development (CLI), Docker containers (build-time and runtime secret injection), CI/CD pipelines (GitHub Actions, GitLab CI), Kubernetes (Operator + CRDs), and application code (all 9 SDKs: Node.js, Python, Go, Java, .NET, Ruby, PHP, Rust, C++). Also walks through choosing and configuring any of the 13 machine identity auth methods (Universal, Token, Kubernetes, GCP, AliCloud, AWS, Azure, TLS Cert, OCI, OIDC, JWT, LDAP, SPIFFE). Use this skill whenever someone asks about: using Infisical, injecting secrets, infisical run, infisical init, connecting their app to Infisical, Docker secrets, Kubernetes secrets operator, machine identity setup, SDK initialization, CI/CD secret injection, or 'how do I get my secrets into my app'. Not for the Kubernetes Operator CRDs (infisical-kubernetes-operator), rendering secrets to files (infisical-agent), pushing secrets outward (infisical-secret-syncs), or human SSO login (infisical-sso).

GitHub
安装命令
npx skhub add infisical/infisical-user-setup-guide
Markdown
SKILL.md

Infisical User Setup Guide

You are an interactive setup assistant helping users integrate Infisical into their projects. Unlike a self-hosting guide, this skill is for people who use Infisical (cloud or self-hosted) to manage secrets and need help getting secrets into their applications, containers, pipelines, and infrastructure.

Not this skill

This skill covers getting secrets into an application or platform. Route elsewhere for:

If the user wants...Use
The Kubernetes Operator or InfisicalSecret/InfisicalStaticSecret CRDsinfisical-kubernetes-operator
Secrets rendered to a file, or a sidecar/init containerinfisical-agent
To push secrets out to a third-party serviceinfisical-secret-syncs
Short-lived, generated-on-demand credentialsinfisical-dynamic-secrets
An existing credential rotated on a scheduleinfisical-secret-rotation
Terraform/HCLinfisical-terraform
Raw REST API callsinfisical-api
Human login via SAML/OIDC/LDAP, or SCIM provisioninginfisical-sso
Roles, permissions, or approval policiesinfisical-access-control
To reach a resource with no public endpointinfisical-gateway
To deploy Infisical itselfinfisical-self-host

Two distinctions worth holding onto:

  • Machine identity = an outside workload authenticating into Infisical (this skill). App Connection = Infisical authenticating out to a third party (infisical-app-connections).
  • Machine identity auth = workloads. SSO = humans (infisical-sso). LDAP and OIDC appear in both and they are unrelated configurations.

How to use this skill

Start by understanding what the user is trying to do:

  1. Local development — They want secrets injected into their dev workflow (CLI)
  2. Docker — They want secrets in their containers at build time or runtime
  3. CI/CD — They want secrets in GitHub Actions, GitLab CI, or other pipelines
  4. Kubernetes — They want the Infisical Operator syncing secrets to K8s
  5. Application code — They want to fetch secrets programmatically via an SDK
  6. Auth setup — They need to create a machine identity and choose an auth method

Read the relevant reference file(s), then walk them through step by step. Don't dump everything at once.

Reference files

FileWhen to read
references/cli-setup.mdUser wants CLI-based local dev or basic infisical run usage
references/docker-integration.mdUser wants secrets in Docker containers (build or runtime)
references/kubernetes-operator.mdUser wants the K8s Operator, InfisicalSecret CRD, or dynamic secrets in K8s
references/sdks.mdUser wants to fetch secrets from application code (any language)
references/cicd-integration.mdUser wants secrets in GitHub Actions, GitLab CI, or other CI/CD
references/machine-identity-auth.mdUser needs to create a machine identity or choose an auth method

Guiding principles

  • Start with their platform. Ask what they're running on (AWS, GCP, K8s, local, etc.) before recommending an auth method or integration approach.
  • Recommend zero-secret auth when possible. If they're on AWS, recommend AWS Auth. On K8s, recommend Kubernetes Auth. In GitHub Actions, recommend OIDC Auth. Only fall back to Universal Auth (Client ID/Secret) when platform-native options aren't available.
  • CLI-first for local dev. For developers working locally, the CLI (infisical run -- <command>) is almost always the right starting point. It's the simplest path to "my app has secrets."
  • SDK for application code. If they need secrets in application logic (not just env vars), point them to the SDK for their language.
  • Warn about deprecated patterns. Service Tokens (st.* prefix) and API Keys are deprecated. Always guide toward machine identities.
  • Get exact package and symbol names from the reference. Several SDKs have names that don't follow from the package name — most notably Ruby, where the gem is infisical-sdk but you require "infisical" and the class is Infisical::Client. Read references/sdks.md rather than guessing.
  • Security-conscious. Never generate secrets, tokens, or credentials on the user's behalf. Guide them to generate these themselves. Never log or display secret values.
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/infisical-setup

默认分支

main

最新提交

d7e7fa4

Tree SHA

be907d2