I recently opened an issue in the Agent Injector repository regarding the inability to trust private/internal certificate authorities:
Related issue: infisical-agent-injector#19
I'm opening this issue here because the Agent Injector uses the Infisical CLI image for its injected init container, and the root cause appears to be related to TLS trust handling within the CLI container itself.
Problem
When using a self-hosted Infisical instance secured by a certificate issued from a private/internal CA, the injected init container fails during Kubernetes Auth login with:
tls: failed to verify certificate:
x509: certificate signed by unknown authority
The Agent Injector currently does not appear to provide a way to:
- Inject custom CA certificates
- Reference a CA bundle from a Kubernetes Secret
- Configure a trusted CA path
- Pass through common trust configuration mechanisms
Because the injected container is based on the CLI image, it may be necessary for the CLI to support one or more of the following:
SSL_CERT_FILE
SSL_CERT_DIR
NODE_EXTRA_CA_CERTS
- CLI-specific CA bundle configuration
- Additional trusted CA mounting/documentation
Request
Can the CLI team clarify:
- Does the Infisical CLI currently support trusting additional/private certificate authorities?
- Are any of the standard trust-related environment variables supported?
- Is there a recommended mechanism for supplying custom CA certificates when running in Kubernetes?
- If not currently supported, would support for custom trust stores be considered?
Many enterprise Kubernetes environments use private PKI, and support for custom certificate authorities is often required when connecting to self-hosted services.
Thanks for taking a look. The related Agent Injector issue contains additional context and reproduction details:
infisical-agent-injector#19
I recently opened an issue in the Agent Injector repository regarding the inability to trust private/internal certificate authorities:
Related issue: infisical-agent-injector#19
I'm opening this issue here because the Agent Injector uses the Infisical CLI image for its injected init container, and the root cause appears to be related to TLS trust handling within the CLI container itself.
Problem
When using a self-hosted Infisical instance secured by a certificate issued from a private/internal CA, the injected init container fails during Kubernetes Auth login with:
The Agent Injector currently does not appear to provide a way to:
Because the injected container is based on the CLI image, it may be necessary for the CLI to support one or more of the following:
SSL_CERT_FILESSL_CERT_DIRNODE_EXTRA_CA_CERTSRequest
Can the CLI team clarify:
Many enterprise Kubernetes environments use private PKI, and support for custom certificate authorities is often required when connecting to self-hosted services.
Thanks for taking a look. The related Agent Injector issue contains additional context and reproduction details:
infisical-agent-injector#19