← Back
Christian Lempa July 14, 2026 31m

Better HomeLab Secret Management // Infisical Tutorial

Read full transcript 25 segments
  1. This is Infracode. It's an open-source This is Infracode. It's an open-source platform where you can manage secrets, platform where you can manage secrets, platform where you can manage secrets, environment variables, certificates, environment variables, certificates, environment variables, certificates, access controls, and a lot more in one access controls, and a lot more in one access controls, and a lot more in one central place. And I think this is central place. And I think this is central place. And I think this is absolutely amazing because it solves one absolutely amazing because it solves one absolutely amazing because it solves one of the biggest problems we have in IT, of the biggest problems we have in IT, of the biggest problems we have in IT, managing and securing the most critical managing and securing the most critical managing and securing the most critical values in our infrastructure, such as values in our infrastructure, such as values in our infrastructure, such as passwords, API keys, database passwords, API keys, database passwords, API keys, database credentials, and access tokens. Because credentials, and access tokens. Because credentials, and access tokens. Because one thing is clear, you frequently have one thing is clear, you frequently have one thing is clear, you frequently have to use them in all different kinds of to use them in all different kinds of to use them in all different kinds of environments, such as your Git environments, such as your Git environments, such as your Git platforms, running them in CI/CD platforms, running them in CI/CD platforms, running them in CI/CD pipelines, or injecting them into pipelines, or injecting them into pipelines, or injecting them into different application deployments. And different application deployments. And different application deployments. And Infracode helps you to define who has Infracode helps you to define who has Infracode helps you to define who has access, which environment a secret access, which environment a secret access, which environment a secret belongs to, and how those values are belongs to, and how those values are belongs to, and how those values are securely delivered to the system that securely delivered to the system that securely delivered to the system that actually needs them. So, in this video, actually needs them. So, in this video, actually needs them. So, in this video, we'll take a look at Infracode and how we'll take a look at Infracode and how we'll take a look at Infracode and how you can easily run this in your own you can easily run this in your own you can easily run this in your own self-hosted environment using Docker self-hosted environment using Docker self-hosted environment using Docker Compose, and we'll create a simple demo Compose, and we'll create a simple demo Compose, and we'll create a simple demo project where I can show you how to project where I can show you how to project where I can show you how to inject secrets using the Infracode CLI inject secrets using the Infracode CLI inject secrets using the Infracode CLI in Docker Compose stacks, so that you in Docker Compose stacks, so that you in Docker Compose stacks, so that you don't have to use .env files on all of don't have to use .env files on all of don't have to use .env files on all of your Home Lab servers. Before we jump your Home Lab servers. Before we jump your Home Lab servers. Before we jump right into this, though, I quickly want right into this, though, I quickly want right into this, though, I quickly want to talk about secure access to your to talk about secure access to your to talk about secure access to your environment because secret management is environment because secret management is environment because secret management is only one part of keeping your only one part of keeping your only one part of keeping your infrastructure safe. Of course, you also infrastructure safe. Of course, you also infrastructure safe. Of course, you also need a secure way to reach your servers, need a secure way to reach your servers, need a secure way to reach your servers, your admin dashboards, and internal your admin dashboards, and internal your admin dashboards, and internal tools without exposing them directly to tools without exposing them directly to tools without exposing them directly to the public internet. And for that, my the public internet. And for that, my the public internet. And for that, my first choice is Twingate, the sponsor of first choice is Twingate, the sponsor of first choice is Twingate, the sponsor of today's video. Twingate is what we call

  2. today's video. Twingate is what we call today's video. Twingate is what we call a ZTNA in tech, a zero-trust network a ZTNA in tech, a zero-trust network a ZTNA in tech, a zero-trust network access platform. And that means instead access platform. And that means instead access platform. And that means instead of opening ports or setting up a of opening ports or setting up a of opening ports or setting up a traditional VPN, Twingate creates secure traditional VPN, Twingate creates secure traditional VPN, Twingate creates secure connections between all of your devices connections between all of your devices connections between all of your devices and your private resources, and every and your private resources, and every and your private resources, and every request has to be verified and request has to be verified and request has to be verified and authorized before it can go through. authorized before it can go through. authorized before it can go through. That makes it super useful for your Home That makes it super useful for your Home That makes it super useful for your Home Lab, but also enterprise workflows Lab, but also enterprise workflows Lab, but also enterprise workflows because you can easily log into your because you can easily log into your because you can easily log into your servers over SSH or reach your internal servers over SSH or reach your internal servers over SSH or reach your internal dashboards, your Kubernetes or databases dashboards, your Kubernetes or databases dashboards, your Kubernetes or databases management tools, and this even works management tools, and this even works management tools, and this even works through NAT devices and firewalls through NAT devices and firewalls through NAT devices and firewalls without any port forwardings or firewall without any port forwardings or firewall without any port forwardings or firewall exceptions. So, you can securely access exceptions. So, you can securely access exceptions. So, you can securely access all of your systems no matter where you all of your systems no matter where you all of your systems no matter where you are or where you're connecting from. If are or where you're connecting from. If are or where you're connecting from. If you would like to try it out, then check you would like to try it out, then check you would like to try it out, then check out my tutorials on how to install out my tutorials on how to install out my tutorials on how to install TwinGate in your network and how to TwinGate in your network and how to TwinGate in your network and how to integrate this into Docker, Kubernetes, integrate this into Docker, Kubernetes, integrate this into Docker, Kubernetes, or your DevOps environments using or your DevOps environments using or your DevOps environments using Terraform. It is also free for up to Terraform. It is also free for up to Terraform. It is also free for up to five users and connects to 10 different five users and connects to 10 different five users and connects to 10 different remote networks, which is already a remote networks, which is already a remote networks, which is already a great fit for many home lab setups. So, great fit for many home lab setups. So, great fit for many home lab setups. So, start making your network more secure start making your network more secure start making your network more secure and accessible with TwinGate. Of course, and accessible with TwinGate. Of course, and accessible with TwinGate. Of course, I'll leave you a link to their website I'll leave you a link to their website I'll leave you a link to their website in the description box down below.

  3. All right, guys. So, now let's get All right, guys. So, now let's get started with Infracloud, the all-in-one started with Infracloud, the all-in-one started with Infracloud, the all-in-one platform for securely manage your app platform for securely manage your app platform for securely manage your app secrets, certificates, SSH keys, or secrets, certificates, SSH keys, or secrets, certificates, SSH keys, or control privileged access to your entire control privileged access to your entire control privileged access to your entire infrastructure. I'm sorry for the light infrastructure. I'm sorry for the light infrastructure. I'm sorry for the light mode website because for whatever reason mode website because for whatever reason mode website because for whatever reason Infracloud doesn't have a dark mode Infracloud doesn't have a dark mode Infracloud doesn't have a dark mode website and dark reader unfortunately website and dark reader unfortunately website and dark reader unfortunately did not work great on this. So, I'm did not work great on this. So, I'm did not work great on this. So, I'm sorry for this, but as you can see, this sorry for this, but as you can see, this sorry for this, but as you can see, this is a pretty big and sophisticated is a pretty big and sophisticated is a pretty big and sophisticated application that is used and trusted by application that is used and trusted by application that is used and trusted by many big enterprise companies. You can many big enterprise companies. You can many big enterprise companies. You can see some impressive names here like see some impressive names here like see some impressive names here like Nvidia, Volkswagen, LG, and many, many Nvidia, Volkswagen, LG, and many, many Nvidia, Volkswagen, LG, and many, many more. And it has a vast feature set more. And it has a vast feature set more. And it has a vast feature set across secret management, secret across secret management, secret across secret management, secret scanning, synchronization, and so many scanning, synchronization, and so many scanning, synchronization, and so many more. But it is not only useful for more. But it is not only useful for more. But it is not only useful for these enterprise companies because you these enterprise companies because you these enterprise companies because you can find the source code of the open can find the source code of the open can find the source code of the open source version here on GitHub. You can source version here on GitHub. You can source version here on GitHub. You can also very easily self-host this on your also very easily self-host this on your also very easily self-host this on your home lab environment without any costs home lab environment without any costs home lab environment without any costs at all. And you can securely store all at all. And you can securely store all at all. And you can securely store all of your critical secrets on your own of your critical secrets on your own of your critical secrets on your own controlled on-prem environment. I think controlled on-prem environment. I think controlled on-prem environment. I think this is pretty cool. You can also find this is pretty cool. You can also find this is pretty cool. You can also find more about that in the official more about that in the official more about that in the official documentation. So, this tells you documentation. So, this tells you documentation. So, this tells you everything. This is the CLI reference, everything. This is the CLI reference, everything. This is the CLI reference, the API reference, SDKs. Now, we want to the API reference, SDKs. Now, we want to the API reference, SDKs. Now, we want to go here to the self-host in physical go here to the self-host in physical go here to the self-host in physical section. You can install the in physical section. You can install the in physical section. You can install the in physical platform using a variety of different platform using a variety of different platform using a variety of different deployment options such as running this deployment options such as running this deployment options such as running this in a container on Docker Kubernetes or in a container on Docker Kubernetes or in a container on Docker Kubernetes or using Docker Compose on AWS, GCP, and a using Docker Compose on AWS, GCP, and a using Docker Compose on AWS, GCP, and a simple Linux package if you prefer that.

  4. simple Linux package if you prefer that. simple Linux package if you prefer that. Of course, as you might know, I'm a big Of course, as you might know, I'm a big Of course, as you might know, I'm a big fan of Docker Compose, so we'll use fan of Docker Compose, so we'll use fan of Docker Compose, so we'll use that. Uh but, I can also tell you in my that. Uh but, I can also tell you in my that. Uh but, I can also tell you in my own environment, I'm actually running own environment, I'm actually running own environment, I'm actually running this in my Kubernetes cluster. So, this this in my Kubernetes cluster. So, this this in my Kubernetes cluster. So, this is also pretty easy. You just have to is also pretty easy. You just have to is also pretty easy. You just have to follow a couple of installation steps, follow a couple of installation steps, follow a couple of installation steps, install the Helm repository, and then install the Helm repository, and then install the Helm repository, and then it's basically setting up everything it's basically setting up everything it's basically setting up everything completely for you. The Docker Compose completely for you. The Docker Compose completely for you. The Docker Compose section, that is what we're using for section, that is what we're using for section, that is what we're using for this quick demo, and I think that's the this quick demo, and I think that's the this quick demo, and I think that's the easier way to quickly get an in physical easier way to quickly get an in physical easier way to quickly get an in physical setup up and running so you can test it setup up and running so you can test it setup up and running so you can test it in your own environment and find out in your own environment and find out in your own environment and find out whether this is something for you. So, whether this is something for you. So, whether this is something for you. So, you just need a Linux server or a Mac a you just need a Linux server or a Mac a you just need a Linux server or a Mac a Windows machine with Docker Desktop, Windows machine with Docker Desktop, Windows machine with Docker Desktop, Docker Engine, Docker Compose. I think Docker Engine, Docker Compose. I think Docker Engine, Docker Compose. I think that should be clear, and the system that should be clear, and the system that should be clear, and the system requirements are also quite low. So, requirements are also quite low. So, requirements are also quite low. So, it's running a database, it's running a it's running a database, it's running a it's running a database, it's running a Redis container. So, that of course Redis container. So, that of course Redis container. So, that of course needs a few resources, but it's not needs a few resources, but it's not needs a few resources, but it's not really hungry. This is a version that really hungry. This is a version that really hungry. This is a version that I've used to create my own boilerplate I've used to create my own boilerplate I've used to create my own boilerplate template for the in physical setup on template for the in physical setup on template for the in physical setup on Docker Compose, which you can also find Docker Compose, which you can also find Docker Compose, which you can also find in the description of this video. I will in the description of this video. I will in the description of this video. I will link this. So, let's just go to my link this. So, let's just go to my link this. So, let's just go to my terminal, and let's quickly set this up.

  5. terminal, and let's quickly set this up. terminal, and let's quickly set this up. First of all, I want to run a repository First of all, I want to run a repository First of all, I want to run a repository update so I get the latest version from update so I get the latest version from update so I get the latest version from my Git repository for the templates, and my Git repository for the templates, and my Git repository for the templates, and then let's take a look at the Compose in then let's take a look at the Compose in then let's take a look at the Compose in physical template. So, here you can physical template. So, here you can physical template. So, here you can configure this service name, um the site configure this service name, um the site configure this service name, um the site URL. This is quite important. If you're URL. This is quite important. If you're URL. This is quite important. If you're not using a correct site URL, in not using a correct site URL, in not using a correct site URL, in physical will not start. Make sure that physical will not start. Make sure that physical will not start. Make sure that this should start with HTTPS or HTTP, this should start with HTTPS or HTTP, this should start with HTTPS or HTTP, depending on what you're using. You need depending on what you're using. You need depending on what you're using. You need of course an encryption key. This is of course an encryption key. This is of course an encryption key. This is quite important because this is a secure quite important because this is a secure quite important because this is a secure key to encrypt all of the secrets. Of key to encrypt all of the secrets. Of key to encrypt all of the secrets. Of course, these secrets are not stored in course, these secrets are not stored in course, these secrets are not stored in clear text and you also need an auth clear text and you also need an auth clear text and you also need an auth secret for the authentication. And what secret for the authentication. And what secret for the authentication. And what is also quite important there's a is also quite important there's a is also quite important there's a setting for synchronizing the secrets to setting for synchronizing the secrets to setting for synchronizing the secrets to your Git platform. And I had the problem your Git platform. And I had the problem your Git platform. And I had the problem that I was running a self-hosted GitLab that I was running a self-hosted GitLab that I was running a self-hosted GitLab platform. By default, this is not platform. By default, this is not platform. By default, this is not allowed, so you need to add an allowed, so you need to add an allowed, so you need to add an environment variable to your Docker environment variable to your Docker environment variable to your Docker Compose stack. I have by default enabled Compose stack. I have by default enabled Compose stack. I have by default enabled this for you, so when you're using my this for you, so when you're using my this for you, so when you're using my Boilerplates templates, you can also Boilerplates templates, you can also Boilerplates templates, you can also synchronize In Physical to your synchronize In Physical to your synchronize In Physical to your self-hosted GitLab platform that is self-hosted GitLab platform that is self-hosted GitLab platform that is running in your own home lab running in your own home lab running in your own home lab environment. And of course, I've also environment. And of course, I've also environment. And of course, I've also added variables to configure Traefik for added variables to configure Traefik for added variables to configure Traefik for running this behind a secure reverse running this behind a secure reverse running this behind a secure reverse proxy with trusted TLS certificates and proxy with trusted TLS certificates and proxy with trusted TLS certificates and you can also use it to set up your email you can also use it to set up your email you can also use it to set up your email account. All right, so now that we know account. All right, so now that we know account. All right, so now that we know all the variables, I want to create a all the variables, I want to create a all the variables, I want to create a new Boilerplates Compose In Physical new Boilerplates Compose In Physical new Boilerplates Compose In Physical template. First of all, I want to set template. First of all, I want to set template. First of all, I want to set the In Physical site URL and I want to the In Physical site URL and I want to the In Physical site URL and I want to run this on my server

  6. run this on my server run this on my server test1.home.secreative.ee. test1.home.secreative.ee. test1.home.secreative.ee. Then, I also want to enable Traefik, of Then, I also want to enable Traefik, of Then, I also want to enable Traefik, of course, so we got trusted TLS course, so we got trusted TLS course, so we got trusted TLS certificates. Therefore, I will also certificates. Therefore, I will also certificates. Therefore, I will also enable the TLS variables and I think I enable the TLS variables and I think I enable the TLS variables and I think I need to set the host. Yeah, this is need to set the host. Yeah, this is need to set the host. Yeah, this is currently set to just In Physical. Of currently set to just In Physical. Of currently set to just In Physical. Of course, I need to set the host to In course, I need to set the host to In course, I need to set the host to In Physical server test one. All these Physical server test one. All these Physical server test one. All these other default values should be fine. So, other default values should be fine. So, other default values should be fine. So, let us just generate this and no, I let us just generate this and no, I let us just generate this and no, I don't want to customize any settings. don't want to customize any settings. don't want to customize any settings. And yep, just store this here in that And yep, just store this here in that And yep, just store this here in that directory. So, now we should see a new directory. So, now we should see a new directory. So, now we should see a new compose.yaml file that has been compose.yaml file that has been compose.yaml file that has been generated by my Boilerplates tool. You generated by my Boilerplates tool. You generated by my Boilerplates tool. You can see all the correct Traefik labels can see all the correct Traefik labels can see all the correct Traefik labels are added in here. There's a PostgreSQL are added in here. There's a PostgreSQL are added in here. There's a PostgreSQL database container with a health check, database container with a health check, database container with a health check, the Redis container with a health check, the Redis container with a health check, the Redis container with a health check, a network, and this is connected to my a network, and this is connected to my a network, and this is connected to my proxy network where traffic is running. proxy network where traffic is running. proxy network where traffic is running. The volumes are created correctly and of The volumes are created correctly and of The volumes are created correctly and of course you can see the environment course you can see the environment course you can see the environment variables, the site URL, encryption key, variables, the site URL, encryption key, variables, the site URL, encryption key, and all of that stuff. Of course, I've and all of that stuff. Of course, I've and all of that stuff. Of course, I've also created a .env file, so here I've also created a .env file, so here I've also created a .env file, so here I've auto-generated a secure password for all auto-generated a secure password for all auto-generated a secure password for all of these um database credentials and the of these um database credentials and the of these um database credentials and the encryption and the authorization key.

  7. encryption and the authorization key. encryption and the authorization key. Make sure to securely store these values Make sure to securely store these values Make sure to securely store these values and do not show them to anyone because and do not show them to anyone because and do not show them to anyone because with the encryption key someone can with the encryption key someone can with the encryption key someone can easily decrypt information from the easily decrypt information from the easily decrypt information from the database. So, that is quite important. database. So, that is quite important. database. So, that is quite important. Again, if you're using this for Again, if you're using this for Again, if you're using this for production, I probably would use my production, I probably would use my production, I probably would use my boilerplate's template for the Helm boilerplate's template for the Helm boilerplate's template for the Helm deployment on Kubernetes. Basically, a deployment on Kubernetes. Basically, a deployment on Kubernetes. Basically, a quite similar template, but that of quite similar template, but that of quite similar template, but that of course creates a Helm release with course creates a Helm release with course creates a Helm release with proper values. You can use the secrets proper values. You can use the secrets proper values. You can use the secrets being secured in the Kubernetes etcd being secured in the Kubernetes etcd being secured in the Kubernetes etcd database. All right. So, but we'll focus database. All right. So, but we'll focus database. All right. So, but we'll focus on Docker Compose. Let's quickly check on Docker Compose. Let's quickly check on Docker Compose. Let's quickly check what Docker context I'm using because I what Docker context I'm using because I what Docker context I'm using because I want to run this on my test server one. want to run this on my test server one. want to run this on my test server one. Oh, yeah, that's right. So, we should Oh, yeah, that's right. So, we should Oh, yeah, that's right. So, we should now go into this directory and simply now go into this directory and simply now go into this directory and simply just run a Docker Compose up -d, which just run a Docker Compose up -d, which just run a Docker Compose up -d, which will pull the image on the uh external will pull the image on the uh external will pull the image on the uh external Docker context and start up the Docker context and start up the Docker context and start up the container. Now, this can take a while up container. Now, this can take a while up container. Now, this can take a while up to a few minutes, so don't be worried to a few minutes, so don't be worried to a few minutes, so don't be worried because InfluxDB needs to populate the because InfluxDB needs to populate the because InfluxDB needs to populate the database and create the Redis and database and create the Redis and database and create the Redis and Postgres containers and seed them with Postgres containers and seed them with Postgres containers and seed them with the credentials and tables and stuff the credentials and tables and stuff the credentials and tables and stuff like that. That usually takes quite a like that. That usually takes quite a like that. That usually takes quite a long time actually. In my environment, long time actually. In my environment, long time actually. In my environment, it took up to six or seven minutes for it took up to six or seven minutes for it took up to six or seven minutes for the first startup. So, you'll have to be the first startup. So, you'll have to be the first startup. So, you'll have to be a bit patient with that. By the way, a bit patient with that. By the way, a bit patient with that. By the way, some of you might wonder what some of you might wonder what some of you might wonder what application I'm currently using to run application I'm currently using to run application I'm currently using to run the terminal and open the files. I'm not the terminal and open the files. I'm not the terminal and open the files. I'm not using Warp Terminal as you might have using Warp Terminal as you might have using Warp Terminal as you might have seen. In the next video, I'm going to seen. In the next video, I'm going to seen. In the next video, I'm going to show you this tool in a lot more detail.

  8. show you this tool in a lot more detail. show you this tool in a lot more detail. So, stay tuned. All right, so now So, stay tuned. All right, so now So, stay tuned. All right, so now InfluxDB is healthy after 7 minutes. So, InfluxDB is healthy after 7 minutes. So, InfluxDB is healthy after 7 minutes. So, yeah, Took quite a long time opening new yeah, Took quite a long time opening new yeah, Took quite a long time opening new browser window and head over to in browser window and head over to in browser window and head over to in physical.server.test.one. physical.server.test.one. physical.server.test.one. First of all, we need to add our First of all, we need to add our First of all, we need to add our credentials here and create an admin credentials here and create an admin credentials here and create an admin account. I'm just quickly doing this. account. I'm just quickly doing this. account. I'm just quickly doing this. All right, pick a secure password and All right, pick a secure password and All right, pick a secure password and continue. So, now this will lock you continue. So, now this will lock you continue. So, now this will lock you into the general server console. So, into the general server console. So, into the general server console. So, this is like an admin console where you this is like an admin console where you this is like an admin console where you first of all need to set up some general first of all need to set up some general first of all need to set up some general settings. For example, if you want to settings. For example, if you want to settings. For example, if you want to allow external users to sign up freely allow external users to sign up freely allow external users to sign up freely to your in physical instance. If you're to your in physical instance. If you're to your in physical instance. If you're using that in a company, yes, it might using that in a company, yes, it might using that in a company, yes, it might be useful to allow this to anyone, but be useful to allow this to anyone, but be useful to allow this to anyone, but restrict this by your secured company restrict this by your secured company restrict this by your secured company email domains. However, in a home lab, I email domains. However, in a home lab, I email domains. However, in a home lab, I certainly would disable this. You can certainly would disable this. You can certainly would disable this. You can control this and configure this control this and configure this control this and configure this according to your preferences. Here you according to your preferences. Here you according to your preferences. Here you can also set up a few other things. For can also set up a few other things. For can also set up a few other things. For example, the organization, because in example, the organization, because in example, the organization, because in physical supports multi-tenancy, so you physical supports multi-tenancy, so you physical supports multi-tenancy, so you can add multiple organizations. You can can add multiple organizations. You can can add multiple organizations. You can also use in physical with SSO from also use in physical with SSO from also use in physical with SSO from Google, GitHub, GitLab, and a couple of Google, GitHub, GitLab, and a couple of Google, GitHub, GitLab, and a couple of other SSO identities. However, I wanted other SSO identities. However, I wanted other SSO identities. However, I wanted to connect this to authentic, but this to connect this to authentic, but this to connect this to authentic, but this is, as you can probably guess, behind a is, as you can probably guess, behind a is, as you can probably guess, behind a paywall. So, paywall. So, paywall. So, I do not need any of these login methods I do not need any of these login methods I do not need any of these login methods except email, of course. So, just going except email, of course. So, just going except email, of course. So, just going to set this here. And then you can also to set this here. And then you can also to set this here. And then you can also integrate this into Slack, Microsoft integrate this into Slack, Microsoft integrate this into Slack, Microsoft Teams. Yeah, let's not mess around with Teams. Yeah, let's not mess around with Teams. Yeah, let's not mess around with that. So, now, let's go back to the that. So, now, let's go back to the that. So, now, let's go back to the organization. So, here on the top you

  9. organization. So, here on the top you organization. So, here on the top you can see the admin organization. If you can see the admin organization. If you can see the admin organization. If you want to return to the server console, want to return to the server console, want to return to the server console, you can find it here. But here we can you can find it here. But here we can you can find it here. But here we can make these general settings for the make these general settings for the make these general settings for the organization, like giving this a name, organization, like giving this a name, organization, like giving this a name, for example, see creative, the for example, see creative, the for example, see creative, the organization slug, and also manage user organization slug, and also manage user organization slug, and also manage user accounts, credentials, and other accounts, credentials, and other accounts, credentials, and other settings for this specific tenant. And settings for this specific tenant. And settings for this specific tenant. And also manage application connections. also manage application connections. also manage application connections. We'll talk about this later. First of We'll talk about this later. First of We'll talk about this later. First of all, I want to create a new project. And all, I want to create a new project. And all, I want to create a new project. And there are six types of projects. The there are six types of projects. The there are six types of projects. The first one is secrets management. So, first one is secrets management. So, first one is secrets management. So, this is the one I would certainly start this is the one I would certainly start this is the one I would certainly start with for a small home lab. It stores the with for a small home lab. It stores the with for a small home lab. It stores the application secrets like passwords, API application secrets like passwords, API application secrets like passwords, API keys, tokens, and stuff like that. And keys, tokens, and stuff like that. And keys, tokens, and stuff like that. And then you can use this in your then you can use this in your then you can use this in your application environments, CI/CD application environments, CI/CD application environments, CI/CD pipelines, whatever you're using. You pipelines, whatever you're using. You pipelines, whatever you're using. You can also create a certificate manager can also create a certificate manager can also create a certificate manager project. So, this is useful if you want project. So, this is useful if you want project. So, this is useful if you want Invidious to manage certificates. Of Invidious to manage certificates. Of Invidious to manage certificates. Of course, I wanted to know if you could course, I wanted to know if you could course, I wanted to know if you could also use this as a certificate manager also use this as a certificate manager also use this as a certificate manager with the ACME protocol for something with the ACME protocol for something with the ACME protocol for something like Traefik or cert-manager. However, like Traefik or cert-manager. However, like Traefik or cert-manager. However, there's one small caveat I need to tell there's one small caveat I need to tell there's one small caveat I need to tell you. Unfortunately, this only supports you. Unfortunately, this only supports you. Unfortunately, this only supports the HTTP one challenge and not DNS one.

  10. the HTTP one challenge and not DNS one. the HTTP one challenge and not DNS one. So, you cannot directly integrate this So, you cannot directly integrate this So, you cannot directly integrate this with your favorite DNS provider. It's with your favorite DNS provider. It's with your favorite DNS provider. It's not a direct drop-in replacement for not a direct drop-in replacement for not a direct drop-in replacement for something like cert-manager or also. something like cert-manager or also. something like cert-manager or also. But, you could technically also obtain But, you could technically also obtain But, you could technically also obtain certificates and manage them securely certificates and manage them securely certificates and manage them securely here, import your CA or your here, import your CA or your here, import your CA or your certificate, or use the ACME challenge certificate, or use the ACME challenge certificate, or use the ACME challenge with the HTTP protocol. That would also with the HTTP protocol. That would also with the HTTP protocol. That would also work. Now, you can also set up an KMS. work. Now, you can also set up an KMS. work. Now, you can also set up an KMS. This is central key management for This is central key management for This is central key management for encryption decryption. It's quite encryption decryption. It's quite encryption decryption. It's quite powerful in companies, I'd say, but for powerful in companies, I'd say, but for powerful in companies, I'd say, but for home labs, I don't know if that's home labs, I don't know if that's home labs, I don't know if that's interesting. Also, secret scanning. That interesting. Also, secret scanning. That interesting. Also, secret scanning. That might be useful in bigger environments might be useful in bigger environments might be useful in bigger environments because that is used to catch leaked because that is used to catch leaked because that is used to catch leaked secrets in configs or code. So, if your secrets in configs or code. So, if your secrets in configs or code. So, if your developers for any reason put developers for any reason put developers for any reason put credentials in clear text in Docker credentials in clear text in Docker credentials in clear text in Docker Compose files or any other environment Compose files or any other environment Compose files or any other environment variables and upload them to Git variables and upload them to Git variables and upload them to Git repositories, the secret scanning will repositories, the secret scanning will repositories, the secret scanning will notify you about there is a problem and notify you about there is a problem and notify you about there is a problem and then you can easily react on this and then you can easily react on this and then you can easily react on this and properly store the secrets in Invidious.

  11. properly store the secrets in Invidious. properly store the secrets in Invidious. And then there's also PAM, privileged And then there's also PAM, privileged And then there's also PAM, privileged access management for sensitive systems access management for sensitive systems access management for sensitive systems like databases, servers, accounts. I like databases, servers, accounts. I like databases, servers, accounts. I think we don't mess around with this. think we don't mess around with this. think we don't mess around with this. And Agent Sentinel. This is governance And Agent Sentinel. This is governance And Agent Sentinel. This is governance for AI agents and MCP tools. Again, for AI agents and MCP tools. Again, for AI agents and MCP tools. Again, might also be an enterprise feature, not might also be an enterprise feature, not might also be an enterprise feature, not so interesting for us home lab people. so interesting for us home lab people. so interesting for us home lab people. So, let us start with creating a new So, let us start with creating a new So, let us start with creating a new project. I'm just going to call this project. I'm just going to call this project. I'm just going to call this home lab secrets, for example. So, now home lab secrets, for example. So, now home lab secrets, for example. So, now you can see that we switch from the you can see that we switch from the you can see that we switch from the tenant in the actual project. If you're tenant in the actual project. If you're tenant in the actual project. If you're creating multiple projects within your creating multiple projects within your creating multiple projects within your tenant, you can easily switch between tenant, you can easily switch between tenant, you can easily switch between these projects here. However, I these projects here. However, I these projects here. However, I certainly would not in my own home lab certainly would not in my own home lab certainly would not in my own home lab create too many multiple projects, then create too many multiple projects, then create too many multiple projects, then it's making things more complicated it's making things more complicated it's making things more complicated because inside a project you can also because inside a project you can also because inside a project you can also manage certain settings and organize manage certain settings and organize manage certain settings and organize your secrets in different environments your secrets in different environments your secrets in different environments or different directories. For example, or different directories. For example, or different directories. For example, if you want to create a secret, you can if you want to create a secret, you can if you want to create a secret, you can create a new directory and call this, create a new directory and call this, create a new directory and call this, for example, I don't know, home lab, or for example, I don't know, home lab, or for example, I don't know, home lab, or you can create you can create you can create folders for certain applications and so folders for certain applications and so folders for certain applications and so on. Note, the folders are not security on. Note, the folders are not security on. Note, the folders are not security boundaries themselves. They are mostly boundaries themselves. They are mostly boundaries themselves. They are mostly just for organizing. So, access to the just for organizing. So, access to the just for organizing. So, access to the credentials is not managed in the credentials is not managed in the credentials is not managed in the directories.

  12. directories. directories. Uh make sure to keep that in mind. Now, Uh make sure to keep that in mind. Now, Uh make sure to keep that in mind. Now, here you can also go into this directory here you can also go into this directory here you can also go into this directory and create new secrets. You can manage and create new secrets. You can manage and create new secrets. You can manage three different environments. three different environments. three different environments. Development for, yeah, I'd say local Development for, yeah, I'd say local Development for, yeah, I'd say local testing or throwaway test stacks, yeah. testing or throwaway test stacks, yeah. testing or throwaway test stacks, yeah. Staging, this is more close to Staging, this is more close to Staging, this is more close to production, but also for testing production, but also for testing production, but also for testing updates. Production is, of course, then updates. Production is, of course, then updates. Production is, of course, then used by your real production home lab or used by your real production home lab or used by your real production home lab or enterprise services. So, when you create enterprise services. So, when you create enterprise services. So, when you create a new secret, you can enable or disable a new secret, you can enable or disable a new secret, you can enable or disable this secret for these different this secret for these different this secret for these different environments as well. So, that's pretty environments as well. So, that's pretty environments as well. So, that's pretty cool. I will show you a couple of things cool. I will show you a couple of things cool. I will show you a couple of things here, for example, if you want to create here, for example, if you want to create here, for example, if you want to create a new application like Nextcloud, yeah. a new application like Nextcloud, yeah. a new application like Nextcloud, yeah. And Nextcloud needs a database and it And Nextcloud needs a database and it And Nextcloud needs a database and it needs an admin user that you can needs an admin user that you can needs an admin user that you can provision via environment variables. provision via environment variables. provision via environment variables. Then these secrets you do not want to Then these secrets you do not want to Then these secrets you do not want to store in your Git repository or in your store in your Git repository or in your store in your Git repository or in your application itself or using a .env file, application itself or using a .env file, application itself or using a .env file, you want to create them here in you want to create them here in you want to create them here in Infracloud. So, then you can start, for Infracloud. So, then you can start, for Infracloud. So, then you can start, for example, using database user and store example, using database user and store example, using database user and store this, for example this is going to be this, for example this is going to be this, for example this is going to be Nextcloud and I want to use this here Nextcloud and I want to use this here Nextcloud and I want to use this here not only for production but also for all not only for production but also for all not only for production but also for all the different environments I want to use the different environments I want to use the different environments I want to use that specific user here and you can see that specific user here and you can see that specific user here and you can see this directly in here. I think this is this directly in here. I think this is this directly in here. I think this is currently not created in this directory currently not created in this directory currently not created in this directory I suppose but you can I suppose but you can I suppose but you can of course edit the secret you can copy of course edit the secret you can copy of course edit the secret you can copy the secret if you select this you can the secret if you select this you can the secret if you select this you can also move this into a different location also move this into a different location also move this into a different location for example home lab I want to put this for example home lab I want to put this for example home lab I want to put this here. You can by the way also override

  13. here. You can by the way also override here. You can by the way also override existing secrets with the same name and existing secrets with the same name and existing secrets with the same name and then you can easily organize that as then you can easily organize that as then you can easily organize that as well. So now it's in the home lab well. So now it's in the home lab well. So now it's in the home lab directory and you can see that's enabled directory and you can see that's enabled directory and you can see that's enabled and present in all these environments. and present in all these environments. and present in all these environments. You can also reveal these specific You can also reveal these specific You can also reveal these specific values here and copy them edit them and values here and copy them edit them and values here and copy them edit them and delete them as well. All right, so let's delete them as well. All right, so let's delete them as well. All right, so let's add a new secret here for example if we add a new secret here for example if we add a new secret here for example if we have a database user we should also have a database user we should also have a database user we should also store a database password. So this one I store a database password. So this one I store a database password. So this one I want to generate with this button here want to generate with this button here want to generate with this button here you can create a secure credential for you can create a secure credential for you can create a secure credential for example 32 characters just random secure example 32 characters just random secure example 32 characters just random secure password and I want to enable this for password and I want to enable this for password and I want to enable this for the production environment only. Yeah, the production environment only. Yeah, the production environment only. Yeah, you can by the way then create other you can by the way then create other you can by the way then create other secrets for example a different secrets for example a different secrets for example a different credential but with the same name and credential but with the same name and credential but with the same name and use this for example for staging and use this for example for staging and use this for example for staging and development. Then you can see it's development. Then you can see it's development. Then you can see it's actually using the same name but when we actually using the same name but when we actually using the same name but when we go in here and reveal the values you can go in here and reveal the values you can go in here and reveal the values you can see it has different values for the see it has different values for the see it has different values for the different types of environments. All different types of environments. All different types of environments. All right, let's also create one or two right, let's also create one or two right, let's also create one or two more. I need a Nextcloud admin user more. I need a Nextcloud admin user more. I need a Nextcloud admin user that's going to be admin and that's that's going to be admin and that's that's going to be admin and that's enabled for all the three environments enabled for all the three environments enabled for all the three environments and I'm going to create a new Nextcloud and I'm going to create a new Nextcloud and I'm going to create a new Nextcloud admin password. This of course I again admin password. This of course I again admin password. This of course I again generate generate generate and put this into the production and put this into the production and put this into the production environment only. And, yeah. So, that environment only. And, yeah. So, that environment only. And, yeah. So, that should be all. All right. So, now we should be all. All right. So, now we should be all. All right. So, now we have all the credentials stored. And of

  14. have all the credentials stored. And of have all the credentials stored. And of course, you can then also share these course, you can then also share these course, you can then also share these credentials with your team. You can credentials with your team. You can credentials with your team. You can manage approvals. You can synchronize manage approvals. You can synchronize manage approvals. You can synchronize them between different types of them between different types of them between different types of platforms, add new users to your platforms, add new users to your platforms, add new users to your project, and you can very specifically project, and you can very specifically project, and you can very specifically define what users and what groups should define what users and what groups should define what users and what groups should have access to what type of credentials have access to what type of credentials have access to what type of credentials or environments. also have audit logs or environments. also have audit logs or environments. also have audit logs here, which is unfortunately not part of here, which is unfortunately not part of here, which is unfortunately not part of the open source plan, but for enterprise the open source plan, but for enterprise the open source plan, but for enterprise companies might be useful to see who had companies might be useful to see who had companies might be useful to see who had retrieved what type of secret. I don't retrieved what type of secret. I don't retrieved what type of secret. I don't want to go through all of the different want to go through all of the different want to go through all of the different features. As you can imagine, this is a features. As you can imagine, this is a features. As you can imagine, this is a pretty powerful platform used by pretty powerful platform used by pretty powerful platform used by enterprise companies, and it has all the enterprise companies, and it has all the enterprise companies, and it has all the stuff like webhooks, API, and workflow stuff like webhooks, API, and workflow stuff like webhooks, API, and workflow integration, and whatnot. One thing that integration, and whatnot. One thing that integration, and whatnot. One thing that I for example want to implement in my I for example want to implement in my I for example want to implement in my home lab is a synchronization between home lab is a synchronization between home lab is a synchronization between GitHub and some other applications GitHub and some other applications GitHub and some other applications because currently, my secrets, I have because currently, my secrets, I have because currently, my secrets, I have stored them in a password manager, but stored them in a password manager, but stored them in a password manager, but when I'm storing them in a password when I'm storing them in a password when I'm storing them in a password manager, I still need to add them to all manager, I still need to add them to all manager, I still need to add them to all the different environments, yeah? I need the different environments, yeah? I need the different environments, yeah? I need to add them to my local.env files on my to add them to my local.env files on my to add them to my local.env files on my Mac. I need to update them on.env files Mac. I need to update them on.env files Mac. I need to update them on.env files on my server production or my server on my server production or my server on my server production or my server test. And I also, if I want to use this test. And I also, if I want to use this test. And I also, if I want to use this in CICD pipelines for automated in CICD pipelines for automated in CICD pipelines for automated deployment and updating, I also need to deployment and updating, I also need to deployment and updating, I also need to store them in GitLab secrets or maybe store them in GitLab secrets or maybe store them in GitLab secrets or maybe GitHub. I'm using both so currently my GitHub. I'm using both so currently my GitHub. I'm using both so currently my credential system is credential system is credential system is really fractured and I want to really fractured and I want to really fractured and I want to centralize this in a platform like centralize this in a platform like centralize this in a platform like Infracloud because this is much much

  15. Infracloud because this is much much Infracloud because this is much much better. I can better control and store better. I can better control and store better. I can better control and store this in a secure way, but I still need this in a secure way, but I still need this in a secure way, but I still need the credentials or access to these the credentials or access to these the credentials or access to these credentials of course in other credentials of course in other credentials of course in other platforms. What you can very easily do platforms. What you can very easily do platforms. What you can very easily do in Infracloud. This is a really amazing in Infracloud. This is a really amazing in Infracloud. This is a really amazing feature because you can have different feature because you can have different feature because you can have different types of integrations for secret types of integrations for secret types of integrations for secret synchronization synchronization synchronization and infrastructure integration. So, if and infrastructure integration. So, if and infrastructure integration. So, if you're using this in Docker, in Ansible, you're using this in Docker, in Ansible, you're using this in Docker, in Ansible, Kubernetes, Terraform, you can set up Kubernetes, Terraform, you can set up Kubernetes, Terraform, you can set up these infrastructure integrations. By these infrastructure integrations. By these infrastructure integrations. By the way, we will talk about Docker the way, we will talk about Docker the way, we will talk about Docker integration in a second. It's integration in a second. It's integration in a second. It's unfortunately not as easy as it sounds unfortunately not as easy as it sounds unfortunately not as easy as it sounds here. But, for Ansible, for example, here. But, for Ansible, for example, here. But, for Ansible, for example, this is quite interesting. There's an this is quite interesting. There's an this is quite interesting. There's an Ansible Galaxy collection to install the Ansible Galaxy collection to install the Ansible Galaxy collection to install the also test this out and show it to you in also test this out and show it to you in also test this out and show it to you in a future video. Maybe we'll a future video. Maybe we'll a future video. Maybe we'll second second second just for project or infrastructure just for project or infrastructure just for project or infrastructure integrations of Infisical. I think that integrations of Infisical. I think that integrations of Infisical. I think that might be useful. Let me quickly show you might be useful. Let me quickly show you might be useful. Let me quickly show you the secret synchronization. That's what the secret synchronization. That's what the secret synchronization. That's what I've already tested and I certainly will I've already tested and I certainly will I've already tested and I certainly will adapt this to my workflow as well. If adapt this to my workflow as well. If adapt this to my workflow as well. If you're managing your credentials or you're managing your credentials or you're managing your credentials or secrets and you want to store them in secrets and you want to store them in secrets and you want to store them in one password or Cloudflare Pages, one password or Cloudflare Pages, one password or Cloudflare Pages, Cloudflare Workers, maybe Digital Ocean, Cloudflare Workers, maybe Digital Ocean, Cloudflare Workers, maybe Digital Ocean, or you want to synchronize them to your or you want to synchronize them to your or you want to synchronize them to your GitHub, your GitLab, and it supports GitHub, your GitLab, and it supports GitHub, your GitLab, and it supports also a couple of others. Yeah, Terraform also a couple of others. Yeah, Terraform also a couple of others. Yeah, Terraform Cloud is here. couple of other Cloud is here. couple of other Cloud is here. couple of other environments as well. But, I want to environments as well. But, I want to environments as well. But, I want to show you this here, GitLab secret. So, show you this here, GitLab secret. So, show you this here, GitLab secret. So, then you can synchronize one specific then you can synchronize one specific then you can synchronize one specific environment or maybe more.

  16. environment or maybe more. environment or maybe more. For example, I want to synchronize my For example, I want to synchronize my For example, I want to synchronize my production secrets of the homelab production secrets of the homelab production secrets of the homelab directory and I want to synchronize this directory and I want to synchronize this directory and I want to synchronize this to my self-hosted GitLab platform. First to my self-hosted GitLab platform. First to my self-hosted GitLab platform. First of all, I need to create a new of all, I need to create a new of all, I need to create a new connection and I'm just going to call connection and I'm just going to call connection and I'm just going to call this self-hosted, for example. Yeah, I this self-hosted, for example. Yeah, I this self-hosted, for example. Yeah, I think that's fine. And then we need to think that's fine. And then we need to think that's fine. And then we need to add the URL git.home.secrecy. add the URL git.home.secrecy. add the URL git.home.secrecy. de and authenticate with a personal de and authenticate with a personal de and authenticate with a personal access token. And let's connect to access token. And let's connect to access token. And let's connect to GitLab. All right. So, now I can set a GitLab. All right. So, now I can set a GitLab. All right. So, now I can set a specific destination because maybe you specific destination because maybe you specific destination because maybe you want to synchronize this with just one want to synchronize this with just one want to synchronize this with just one repository or maybe a group of repository or maybe a group of repository or maybe a group of repositories. Here you can set the repositories. Here you can set the repositories. Here you can set the scope. For example, what might be pretty scope. For example, what might be pretty scope. For example, what might be pretty useful in my setup, I certainly will do useful in my setup, I certainly will do useful in my setup, I certainly will do this is synchronize this to my homelab this is synchronize this to my homelab this is synchronize this to my homelab group. So, there I've added all the group. So, there I've added all the group. So, there I've added all the repositories. Oh, wait, I can show it to repositories. Oh, wait, I can show it to repositories. Oh, wait, I can show it to you. So, here this group Home Lab, there you. So, here this group Home Lab, there you. So, here this group Home Lab, there are all of my platforms like the GitLab are all of my platforms like the GitLab are all of my platforms like the GitLab platform, traffic, Proxmox, Open Sense. platform, traffic, Proxmox, Open Sense. platform, traffic, Proxmox, Open Sense. So, everywhere where I need my secrets, So, everywhere where I need my secrets, So, everywhere where I need my secrets, I can easily synchronize this to the I can easily synchronize this to the I can easily synchronize this to the entire group. Or what I'm showing you in entire group. Or what I'm showing you in entire group. Or what I'm showing you in this demo environment, I'm just going to this demo environment, I'm just going to this demo environment, I'm just going to synchronize this to an example synchronize this to an example synchronize this to an example repository. And here you can also set repository. And here you can also set repository. And here you can also set the GitLab environment scope if you need the GitLab environment scope if you need the GitLab environment scope if you need that. Mark secrets as protected, masked, that. Mark secrets as protected, masked, that. Mark secrets as protected, masked, or hidden. I'm not going to use this or hidden. I'm not going to use this or hidden. I'm not going to use this right now, but you can certainly do right now, but you can certainly do right now, but you can certainly do this. And then you also should choose this. And then you also should choose this. And then you also should choose the synchronization behavior. So, if it the synchronization behavior. So, if it the synchronization behavior. So, if it should overwrite secrets or if it should should overwrite secrets or if it should should overwrite secrets or if it should have a prefix like in have a prefix like in have a prefix like in physical_secret_key.

  17. physical_secret_key. physical_secret_key. In my example, [snorts] I don't want In my example, [snorts] I don't want In my example, [snorts] I don't want this. So, secret_key alone should be this. So, secret_key alone should be this. So, secret_key alone should be enough. I don't want in physical_ enough. I don't want in physical_ enough. I don't want in physical_ because I'm using the credentials because I'm using the credentials because I'm using the credentials already in my project, so that would already in my project, so that would already in my project, so that would require a huge renaming. And disable require a huge renaming. And disable require a huge renaming. And disable secret deletion. This will disable the secret deletion. This will disable the secret deletion. This will disable the override function of the secret. So, override function of the secret. So, override function of the secret. So, when the secret is already existing, it when the secret is already existing, it when the secret is already existing, it would be overwritten with a value that would be overwritten with a value that would be overwritten with a value that you have in in physical. And then you you have in in physical. And then you you have in in physical. And then you need to add a job name. I'm just going need to add a job name. I'm just going need to add a job name. I'm just going to go with the default here. I think to go with the default here. I think to go with the default here. I think that's fine. Here you can see in the that's fine. Here you can see in the that's fine. Here you can see in the status it's actually syncing. So, let's status it's actually syncing. So, let's status it's actually syncing. So, let's go back to my GitLab platform and let's go back to my GitLab platform and let's go back to my GitLab platform and let's go to my example project. So, this go to my example project. So, this go to my example project. So, this should be in here personal example apps. should be in here personal example apps. should be in here personal example apps. All right. And then if we go to All right. And then if we go to All right. And then if we go to settings, CI/CD variables, the secrets settings, CI/CD variables, the secrets settings, CI/CD variables, the secrets arrived at the Git repository. And then arrived at the Git repository. And then arrived at the Git repository. And then you basically just have to add all of you basically just have to add all of you basically just have to add all of your integrations and you have your integrations and you have your integrations and you have distributed your secrets managed in in distributed your secrets managed in in distributed your secrets managed in in physical across all your platforms physical across all your platforms physical across all your platforms environments where you need them. That's environments where you need them. That's environments where you need them. That's pretty cool. All right. So, now the next pretty cool. All right. So, now the next pretty cool. All right. So, now the next step is how do you actually get access step is how do you actually get access step is how do you actually get access to these secrets? Because it's fine that to these secrets? Because it's fine that to these secrets? Because it's fine that we have them in the platform. That's the we have them in the platform. That's the we have them in the platform. That's the step one, but maybe you want to get your step one, but maybe you want to get your step one, but maybe you want to get your secrets from a machine like a server or secrets from a machine like a server or secrets from a machine like a server or maybe your workstation where you are maybe your workstation where you are maybe your workstation where you are running uh your application and you need running uh your application and you need running uh your application and you need the credentials from the InPhySec the credentials from the InPhySec the credentials from the InPhySec platform. Now, what you should use for platform. Now, what you should use for platform. Now, what you should use for this is the InPhySec CLI. You can this is the InPhySec CLI. You can this is the InPhySec CLI. You can install this on your Mac, on Windows, install this on your Mac, on Windows, install this on your Mac, on Windows, can use NPM, Alpine Linux distributions

  18. can use NPM, Alpine Linux distributions can use NPM, Alpine Linux distributions like Red Hat, Debian, Ubuntu, Arch like Red Hat, Debian, Ubuntu, Arch like Red Hat, Debian, Ubuntu, Arch Linux, and then log into your Linux, and then log into your Linux, and then log into your Self-Hosted platform. Let's just go Self-Hosted platform. Let's just go Self-Hosted platform. Let's just go through this process together. So, then through this process together. So, then through this process together. So, then I think you can better see how that's I think you can better see how that's I think you can better see how that's working. So, uh I should have access to working. So, uh I should have access to working. So, uh I should have access to InPhySec already, so now I just need to InPhySec already, so now I just need to InPhySec already, so now I just need to log in and then select Self-Hosted log in and then select Self-Hosted log in and then select Self-Hosted instance InPhySec server test one. Oh, instance InPhySec server test one. Oh, instance InPhySec server test one. Oh, yeah, I already have that. And this yeah, I already have that. And this yeah, I already have that. And this opens a browser window where we need to opens a browser window where we need to opens a browser window where we need to authenticate. And this should then show authenticate. And this should then show authenticate. And this should then show a token that we need to copy and go back a token that we need to copy and go back a token that we need to copy and go back to the terminal and paste here. So, now to the terminal and paste here. So, now to the terminal and paste here. So, now you should see browser successfully you should see browser successfully you should see browser successfully logged in. Now, we can start managing logged in. Now, we can start managing logged in. Now, we can start managing InPhySec through the CLI. And there are InPhySec through the CLI. And there are InPhySec through the CLI. And there are a couple of commands that you probably a couple of commands that you probably a couple of commands that you probably should know. First of all, if we want to should know. First of all, if we want to should know. First of all, if we want to inject secrets or get the values, we inject secrets or get the values, we inject secrets or get the values, we should initialize the local folder to should initialize the local folder to should initialize the local folder to the HomeLab project. For example, if we the HomeLab project. For example, if we the HomeLab project. For example, if we want to use the credentials to install a want to use the credentials to install a want to use the credentials to install a new Nextcloud container. Let's Let's do new Nextcloud container. Let's Let's do new Nextcloud container. Let's Let's do that together. So, first of all, I want that together. So, first of all, I want that together. So, first of all, I want to create a new directory called to create a new directory called to create a new directory called Nextcloud and CD into this.

  19. Nextcloud and CD into this. Nextcloud and CD into this. And then run InPhySec init. So, connect And then run InPhySec init. So, connect And then run InPhySec init. So, connect the local repository to the InPhySec the local repository to the InPhySec the local repository to the InPhySec platform. Now, we need to select the platform. Now, we need to select the platform. Now, we need to select the organization Seal Creative and the organization Seal Creative and the organization Seal Creative and the InPhySec project HomeLab Secrets. And InPhySec project HomeLab Secrets. And InPhySec project HomeLab Secrets. And now, we need to choose an environment now, we need to choose an environment now, we need to choose an environment here. So, environment is uh prod, I here. So, environment is uh prod, I here. So, environment is uh prod, I think. And the path is the directory. think. And the path is the directory. think. And the path is the directory. Note, this is case sensitive, so Note, this is case sensitive, so Note, this is case sensitive, so [snorts] that's quite important. And [snorts] that's quite important. And [snorts] that's quite important. And yeah, so this should retrieve all the yeah, so this should retrieve all the yeah, so this should retrieve all the secrets. You can see that you secrets. You can see that you secrets. You can see that you immediately see the secrets in here, but immediately see the secrets in here, but immediately see the secrets in here, but you can also get one specific secret. you can also get one specific secret. you can also get one specific secret. For example, if you want to only get the For example, if you want to only get the For example, if you want to only get the database password, then you can also use database password, then you can also use database password, then you can also use this and you get the single secret this and you get the single secret this and you get the single secret value. All right, so that's already value. All right, so that's already value. All right, so that's already great to get access to this, but how do great to get access to this, but how do great to get access to this, but how do you inject them into your application? you inject them into your application? you inject them into your application? Of course, you do not want to copy and Of course, you do not want to copy and Of course, you do not want to copy and paste them. In physical has a pretty paste them. In physical has a pretty paste them. In physical has a pretty cool command for this and this is called cool command for this and this is called cool command for this and this is called In physical run. This will run any In physical run. This will run any In physical run. This will run any command that you want and automatically command that you want and automatically command that you want and automatically inject them into environment variables.

  20. inject them into environment variables. inject them into environment variables. The path is again home lab and then dash The path is again home lab and then dash The path is again home lab and then dash dash and then we can run any command dash and then we can run any command dash and then we can run any command that we want. You can run any deploy that we want. You can run any deploy that we want. You can run any deploy script, you can run a docker compose up, script, you can run a docker compose up, script, you can run a docker compose up, you can run a docker command, you can you can run a docker command, you can you can run a docker command, you can run a an npm command. Now, of course, run a an npm command. Now, of course, run a an npm command. Now, of course, there's one caveat here that does not there's one caveat here that does not there's one caveat here that does not directly integrate this into docker directly integrate this into docker directly integrate this into docker management platforms. If you might be management platforms. If you might be management platforms. If you might be using Portainer or Dockhand or Arcane or using Portainer or Dockhand or Arcane or using Portainer or Dockhand or Arcane or something like this, this does not work something like this, this does not work something like this, this does not work because you cannot easily inject the because you cannot easily inject the because you cannot easily inject the secrets automatically in third-party secrets automatically in third-party secrets automatically in third-party applications. That's not possible. But applications. That's not possible. But applications. That's not possible. But just to demonstrate this quickly to you just to demonstrate this quickly to you just to demonstrate this quickly to you what would happen if we want to run a what would happen if we want to run a what would happen if we want to run a docker container for this, I'm just docker container for this, I'm just docker container for this, I'm just going to use my boiler plates to quickly going to use my boiler plates to quickly going to use my boiler plates to quickly spin up a compose stack for Nextcloud, spin up a compose stack for Nextcloud, spin up a compose stack for Nextcloud, generate this with a database using a generate this with a database using a generate this with a database using a traffic host and all of that stuff. So, traffic host and all of that stuff. So, traffic host and all of that stuff. So, this will create a new directory. Okay, this will create a new directory. Okay, this will create a new directory. Okay, it created a subdirectory, it created a subdirectory, it created a subdirectory, unfortunately, but yeah, that's that's unfortunately, but yeah, that's that's unfortunately, but yeah, that's that's not really important. It can be in not really important. It can be in not really important. It can be in subdirectories as well. subdirectories as well. subdirectories as well. So, here you can see the compose file.

  21. So, here you can see the compose file. So, here you can see the compose file. It's using a couple of credentials here It's using a couple of credentials here It's using a couple of credentials here that are currently stored as .env file. that are currently stored as .env file. that are currently stored as .env file. You can see database user, database You can see database user, database You can see database user, database password, Nextcloud admin, Nextcloud password, Nextcloud admin, Nextcloud password, Nextcloud admin, Nextcloud admin password. These are currently admin password. These are currently admin password. These are currently auto-generated from the boiler plates auto-generated from the boiler plates auto-generated from the boiler plates project, but of course I do not want project, but of course I do not want project, but of course I do not want this in the future. I want to load them this in the future. I want to load them this in the future. I want to load them from in physical instead. So, I'm just from in physical instead. So, I'm just from in physical instead. So, I'm just going to delete this environment going to delete this environment going to delete this environment variable file because we do not need variable file because we do not need variable file because we do not need this. Now, we need to run the same in this. Now, we need to run the same in this. Now, we need to run the same in physical run command with the production physical run command with the production physical run command with the production environment path home lab and now we environment path home lab and now we environment path home lab and now we just going to run docker compose up just going to run docker compose up just going to run docker compose up {dash} d. All right, that's it. Now, you {dash} d. All right, that's it. Now, you {dash} d. All right, that's it. Now, you can also see in the log it's injecting can also see in the log it's injecting can also see in the log it's injecting four in physical secrets into your four in physical secrets into your four in physical secrets into your application process and it's starting application process and it's starting application process and it's starting the container. It's currently using my the container. It's currently using my the container. It's currently using my server test one docker context. So, it's server test one docker context. So, it's server test one docker context. So, it's even not running on my local machine. even not running on my local machine. even not running on my local machine. All right, so yeah, Nextcloud was All right, so yeah, Nextcloud was All right, so yeah, Nextcloud was successfully installed. So, I think now successfully installed. So, I think now successfully installed. So, I think now it should be ready. Let's open a new it should be ready. Let's open a new it should be ready. Let's open a new browser tab and let's go to Nextcloud browser tab and let's go to Nextcloud browser tab and let's go to Nextcloud server test one and yeah, so that's it.

  22. server test one and yeah, so that's it. server test one and yeah, so that's it. Now, we can return back to the in Now, we can return back to the in Now, we can return back to the in physical secrets, go into home lab and physical secrets, go into home lab and physical secrets, go into home lab and the password for the production the password for the production the password for the production environment we'll just copy and go back environment we'll just copy and go back environment we'll just copy and go back here. Admin password. Log in and yeah, here. Admin password. Log in and yeah, here. Admin password. Log in and yeah, so that's it. We are logged into so that's it. We are logged into so that's it. We are logged into Nextcloud. And yeah, so this is Nextcloud. And yeah, so this is Nextcloud. And yeah, so this is basically how you can easily inject the basically how you can easily inject the basically how you can easily inject the secrets from in physical into docker secrets from in physical into docker secrets from in physical into docker compose. Of course, it works well for compose. Of course, it works well for compose. Of course, it works well for these simple commands, but as I've told these simple commands, but as I've told these simple commands, but as I've told you it does not work with third-party you it does not work with third-party you it does not work with third-party applications like Portainer or so. But applications like Portainer or so. But applications like Portainer or so. But there is still a solution how you can there is still a solution how you can there is still a solution how you can make this possible. Let's go back to the make this possible. Let's go back to the make this possible. Let's go back to the in physical documentation because there in physical documentation because there in physical documentation because there is an integration to docker compose by is an integration to docker compose by is an integration to docker compose by injecting the in physical CLI into every injecting the in physical CLI into every injecting the in physical CLI into every service where you want to load the service where you want to load the service where you want to load the environment variables. So, you will have environment variables. So, you will have environment variables. So, you will have to update the docker file, modify the to update the docker file, modify the to update the docker file, modify the start command in your docker file, and start command in your docker file, and start command in your docker file, and then obtain an access token for the then obtain an access token for the then obtain an access token for the secure connection and feed the access secure connection and feed the access secure connection and feed the access token into the docker container, and token into the docker container, and token into the docker container, and then the docker container itself can then the docker container itself can then the docker container itself can retrieve the secure secrets from in retrieve the secure secrets from in retrieve the secure secrets from in physical. Now, of course, this is a physical. Now, of course, this is a physical. Now, of course, this is a little more complicated, yeah, and it little more complicated, yeah, and it little more complicated, yeah, and it can be usable for custom applications, can be usable for custom applications, can be usable for custom applications, but for running third-party but for running third-party but for running third-party applications, I know that you do not applications, I know that you do not applications, I know that you do not want to modify or rebuild the Docker want to modify or rebuild the Docker want to modify or rebuild the Docker image of the vendor. It is still image of the vendor. It is still image of the vendor. It is still possible, so maybe if you want to see possible, so maybe if you want to see possible, so maybe if you want to see that, I can make a tutorial about this, that, I can make a tutorial about this, that, I can make a tutorial about this, but this requires a couple of things in but this requires a couple of things in but this requires a couple of things in your setup like your CI/CD pipeline to

  23. your setup like your CI/CD pipeline to your setup like your CI/CD pipeline to automatically rebuild the Docker automatically rebuild the Docker automatically rebuild the Docker container with a specific command, so container with a specific command, so container with a specific command, so you can certainly automate this. you can certainly automate this. you can certainly automate this. But, it's a a little more complicated. But, it's a a little more complicated. But, it's a a little more complicated. Yeah, I don't know. I think the better Yeah, I don't know. I think the better Yeah, I don't know. I think the better way how I personally will use this in my way how I personally will use this in my way how I personally will use this in my home lab is when we return back to my home lab is when we return back to my home lab is when we return back to my Git platform, you can see that I'm Git platform, you can see that I'm Git platform, you can see that I'm mostly managing my Docker containers or mostly managing my Docker containers or mostly managing my Docker containers or the Docker Compose stacks in GitLab the Docker Compose stacks in GitLab the Docker Compose stacks in GitLab CI/CD, at least right now. I will change CI/CD, at least right now. I will change CI/CD, at least right now. I will change that in future to another system as that in future to another system as that in future to another system as well, but we'll do a separate tutorial well, but we'll do a separate tutorial well, but we'll do a separate tutorial about this. But, currently, how I'm for about this. But, currently, how I'm for about this. But, currently, how I'm for example deploying my Traefik container, example deploying my Traefik container, example deploying my Traefik container, I'm running a CI/CD pipeline, and this I'm running a CI/CD pipeline, and this I'm running a CI/CD pipeline, and this CI/CD pipeline will run a Docker stack CI/CD pipeline will run a Docker stack CI/CD pipeline will run a Docker stack component or a Docker deploy component. component or a Docker deploy component. component or a Docker deploy component. To show you this, I need to go back. By To show you this, I need to go back. By To show you this, I need to go back. By the way, I've done tutorials on this, so the way, I've done tutorials on this, so the way, I've done tutorials on this, so if you want to see the details how if you want to see the details how if you want to see the details how exactly that's working, I'll link you exactly that's working, I'll link you exactly that's working, I'll link you this in the description, but here you this in the description, but here you this in the description, but here you can see that is the automation pipeline can see that is the automation pipeline can see that is the automation pipeline that actually runs this. Yeah, so here that actually runs this. Yeah, so here that actually runs this. Yeah, so here in the templates, you can see deploy in the templates, you can see deploy in the templates, you can see deploy compose. So, here I've created an compose. So, here I've created an compose. So, here I've created an automation pipeline that will basically automation pipeline that will basically automation pipeline that will basically pull the Docker Compose stack from my pull the Docker Compose stack from my pull the Docker Compose stack from my repository and then simply just run repository and then simply just run repository and then simply just run Docker Compose up. And now, I could Docker Compose up. And now, I could Docker Compose up. And now, I could technically just go in here, modify the technically just go in here, modify the technically just go in here, modify the component, and add in the in physical component, and add in the in physical component, and add in the in physical run command, yeah. So, then I could run command, yeah. So, then I could run command, yeah. So, then I could securely inject the in physical secrets securely inject the in physical secrets securely inject the in physical secrets into my CI/CD pipeline and automatically into my CI/CD pipeline and automatically into my CI/CD pipeline and automatically deploy or run container updates with

  24. deploy or run container updates with deploy or run container updates with this as well. So, yeah, it's maybe a bit this as well. So, yeah, it's maybe a bit this as well. So, yeah, it's maybe a bit more complicated, but it is certainly more complicated, but it is certainly more complicated, but it is certainly possible to automate this. Anyways, even possible to automate this. Anyways, even possible to automate this. Anyways, even with that limitation, I think In with that limitation, I think In with that limitation, I think In Physical is absolutely amazing, Physical is absolutely amazing, Physical is absolutely amazing, especially once you start using especially once you start using especially once you start using automation scripts, build scripts, automation scripts, build scripts, automation scripts, build scripts, deploy scripts, CI/CD, GitLab Runners, deploy scripts, CI/CD, GitLab Runners, deploy scripts, CI/CD, GitLab Runners, or repeatable deployment workflows. or repeatable deployment workflows. or repeatable deployment workflows. Again, I might probably follow up on Again, I might probably follow up on Again, I might probably follow up on this as well, because there are a few this as well, because there are a few this as well, because there are a few interesting ways how you can actually interesting ways how you can actually interesting ways how you can actually solve this. There are some nice solve this. There are some nice solve this. There are some nice alternatives as well to secret alternatives as well to secret alternatives as well to secret management, like we might have a look at management, like we might have a look at management, like we might have a look at the Open Bower project or stuff like the Open Bower project or stuff like the Open Bower project or stuff like that. So, if you want to follow this and that. So, if you want to follow this and that. So, if you want to follow this and if you're interested about secret if you're interested about secret if you're interested about secret management and DevOps processes, then management and DevOps processes, then management and DevOps processes, then please give this video thumbs up, please give this video thumbs up, please give this video thumbs up, subscribe to the channel. I'll do more subscribe to the channel. I'll do more subscribe to the channel. I'll do more videos about this. And please tell me videos about this. And please tell me videos about this. And please tell me your feedback. What do you think about your feedback. What do you think about your feedback. What do you think about In Physical? Do you already use it or In Physical? Do you already use it or In Physical? Do you already use it or another tool? Then please let me know in another tool? Then please let me know in another tool? Then please let me know in the comments. And as always, thank you the comments. And as always, thank you the comments. And as always, thank you so much for watching. A big thanks goes so much for watching. A big thanks goes so much for watching. A big thanks goes out to all of my supporters and members out to all of my supporters and members out to all of my supporters and members of my channel. You guys are really of my channel. You guys are really of my channel. You guys are really amazing. You make all of this possible.

  25. amazing. You make all of this possible. amazing. You make all of this possible. And of course, I'm going to catch you in And of course, I'm going to catch you in And of course, I'm going to catch you in the next video. Take care. Bye-bye.

Summary

The main theme is managing and securing critical infrastructure secrets using the Infracode platform. Key subjects include secrets, environment variables, certificates, access controls, and their injection into CI/CD pipelines and application deployments. The practical takeaway is that Infracode, while a key solution for secret management, should be used in conjunction with secure access solutions like Twingate for overall infrastructure safety.

View original episode ↗