Skip to content

Agent Injector does not provide a mechanism to trust private/self-hosted CAs for Infisical endpoint TLS validation #405

Description

@EnzoDotjs

I recently opened an issue in the Agent Injector repository regarding the inability to trust private/internal certificate authorities:

Related issue: infisical-agent-injector#19

I'm opening this issue here because the Agent Injector uses the Infisical CLI image for its injected init container, and the root cause appears to be related to TLS trust handling within the CLI container itself.

Problem

When using a self-hosted Infisical instance secured by a certificate issued from a private/internal CA, the injected init container fails during Kubernetes Auth login with:

tls: failed to verify certificate:
x509: certificate signed by unknown authority

The Agent Injector currently does not appear to provide a way to:

  • Inject custom CA certificates
  • Reference a CA bundle from a Kubernetes Secret
  • Configure a trusted CA path
  • Pass through common trust configuration mechanisms

Because the injected container is based on the CLI image, it may be necessary for the CLI to support one or more of the following:

  • SSL_CERT_FILE
  • SSL_CERT_DIR
  • NODE_EXTRA_CA_CERTS
  • CLI-specific CA bundle configuration
  • Additional trusted CA mounting/documentation

Request

Can the CLI team clarify:

  1. Does the Infisical CLI currently support trusting additional/private certificate authorities?
  2. Are any of the standard trust-related environment variables supported?
  3. Is there a recommended mechanism for supplying custom CA certificates when running in Kubernetes?
  4. If not currently supported, would support for custom trust stores be considered?

Many enterprise Kubernetes environments use private PKI, and support for custom certificate authorities is often required when connecting to self-hosted services.

Thanks for taking a look. The related Agent Injector issue contains additional context and reproduction details:

infisical-agent-injector#19

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions