跳到主内容
智客 ZICQ

技能库 智客分类:运维与云 infisical-self-host

Infisical Self Host

与多克、多克·康普斯和库伯内特斯一起部署和操作非宗教自主办实例。 涵盖架构,环境变量,ENCRYPTION_KEY管理,PostgreSQL设置,Redis配置(包括需要的节能政策),生产硬化,FIPS 140-3合规,缩放,以及高可用模式. 为部署"非"平台本身. 既不是作为单独的赫尔姆图(inficial-kubernetes-operator)的Kubernetes运算器,也不是使用inficial一经运行(inficial-setup).

576 安装量

官方网址:skills.sh

技能介绍

先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。

做什么

与多克、多克·康普斯和库伯内特斯一起部署和操作非宗教自主办实例。 涵盖架构,环境变量,ENCRYPTION_KEY管理,PostgreSQL设置,Redis配置(包括需要的节能政策),生产硬化,FIPS 140-3合规,缩放,以及高可用模式. 为部署"非"平台本身. 既不是作为单独的赫尔姆图(inficial-kubernetes-operator)的Kubernetes运算器,也不是使用inficial一经运行(inficial-setup).

何时用

官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。

代理如何加载

按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Infisical Self-Hosted Deployment、Not this skill、Guiding Principles、Quick Start、Reference Guides、[Environment Variables](./references/environment-variables.md)。

文件分析

文件分析:除 SKILL.md 外,正文引用了 references/environment-variables.md、references/docker-deployment.md、references/kubernetes-deployment.md、references/scaling-and-ha.md,属于带资源的技能包,这些文件按需再读。

官方 description(原文)

Deploy and operate Infisical self-hosted instances with Docker, Docker Compose, and Kubernetes. Covers architecture, environment variables, ENCRYPTION_KEY management, PostgreSQL setup, Redis configuration (including the required noeviction policy), production hardening, FIPS 140-3 compliance, scaling, and high availability patterns. For deploying the Infisical platform itself. Not for the Kubernetes Operator, which is a separate Helm chart (infisical-kubernetes-operator), nor for using Infisical once running (infisical-setup).

Infisical Self-Hosted DeploymentNot this skillGuiding PrinciplesQuick StartReference Guides[Environment Variables](./references/environment-variables.md)[Docker Deployment](./references/docker-deployment.md)[Kubernetes Deployment](./references/kubernetes-deployment.md)[Scaling and High Availability](./references/scaling-and-ha.md)

来源分类:skills.sh agent-skill

SKILL.md 与 Agent 调用

官方规范 ↗
name
infisical-self-host
description
Deploy and operate Infisical self-hosted instances with Docker, Docker Compose, and Kubernetes. Covers architecture, environment variables, ENCRYPTION_KEY management, PostgreSQL setup, Redis configuration (including the required noeviction policy), production hardening, FIPS 140-3 compliance, scaling, and high availability patterns. For deploying the Infisical platform itself. Not for the Kubernetes Operator, which is a separate Helm chart (infisical-kubernetes-operator), nor for using Infisical once running (infisical-setup).
  1. 发现技能客户端向 Agent 提供名称与描述目录。
  2. 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
  3. 按需加载按步骤读取参考文档、使用脚本与素材。
指令中引用的文件 · 4
  • references/environment-variables.md
  • references/docker-deployment.md
  • references/kubernetes-deployment.md
  • references/scaling-and-ha.md

以下路径提取自原文;文件是否齐全请以来源仓库中的完整目录为准。

具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗

安装这个技能

Skills CLI ↗

先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。

该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。

交给 Agent 安装

复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。

把 Agent Skill「infisical-self-host」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-a3183359bdad1535-Infisical-Self-Host.html
请存为 .cursor/skills/infisical-self-host/SKILL.md 或 .claude/skills/infisical-self-host/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
该技能还带 scripts/、references/、assets/ 等文件,请从 https://github.com/infisical/ai-skills 取完整目录,不要只建一个 SKILL.md。

GitHub 完整包 ↗

终端安装 · Skills CLI

需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。

npx skills add 'https://github.com/infisical/ai-skills' --list

npx skills add 'https://github.com/infisical/ai-skills' --skill 'infisical-self-host'

CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。

阅读排版
--- name: infisical-self-host description: Deploy and operate Infisical self-hosted instances with Docker, Docker Compose, and Kubernetes. Covers architecture, environment variables, ENCRYPTION_KEY management, PostgreSQL setup, Redis configuration (including the required noeviction policy), production hardening, FIPS 140-3 compliance, scaling, and high availability patterns. For deploying the Infisical platform itself. Not for the Kubernetes Operator, which is a separate Helm chart (infisical-kubernetes-operator), nor for using Infisical once running (infisical-setup). triggers: - self-host infisical - deploy infisical - docker compose infisical - infisical docker - helm chart infisical - kubernetes infisical - ENCRYPTION_KEY - infisical environment variables - production deployment infisical - FIPS infisical - scale infisical - ha infisical --- # Infisical Self-Hosted Deployment This skill guides you through deploying, configuring, and operating Infisical in self-hosted environments. Whether you are running Infisical on Docker, Docker Compose, or Kubernetes, this resource covers essential setup, security hardening, scaling, and maintenance patterns. ## Not this skill | If the user wants... | Use | |----------------------|-----| | To deploy the **Kubernetes Operator** (also a Helm chart, different thing) | `infisical-kubernetes-operator` | | To reach a private resource from Infisical | `infisical-gateway` | | To configure SSO or SCIM on their instance | `infisical-sso` | | Roles, permissions, audit log streams | `infisical-access-control` | | To use Infisical once it is running | `infisical-setup` | | An external KMS or HSM backing the root key | `infisical-kms` | The Helm confusion is worth pre-empting: the `secrets-operator` chart installs the **operator**; this skill covers the chart that installs the **platform**. Both come from the same Cloudsmith repo. ## Guiding Principles 1. **ENCRYPTION_KEY is Critical**: This key encrypts all secrets at rest and **cannot be recovered if lost**. Back it up and rotate it carefully following Infisical's rotation procedures. - Standard deployments: a random 16-byte hex string — `openssl rand -hex 16` - **FIPS-enabled deployments: a 256-bit base64 key instead** — `openssl rand -base64 32` 2. **AUTH_SECRET is Required**: This key is used for session and JWT signing. It is 32 bytes (base64), generated with `openssl rand -base64 32`, and must be stable across restarts. 3. **Database Requirements**: PostgreSQL is the only supported database. Use 14+ for compatibility; Infisical is extensively tested on 16. Always backup your database before upgrading Infisical. Schema migrations run automatically on boot (since v0.111.0-postgres). 4. **Redis is a hard dependency, not just a cache**: Beyond caching it holds the background job queue, distributed locks, cross-instance coordination state, and rate-limit counters. **The instance will not start unless one of `REDIS_URL`, `REDIS_SENTINEL_HOSTS`, or `REDIS_CLUSTER_HOSTS` is set**, and a running instance is degraded while Redis is unreachable. - Use Redis 6.x or 7.x; at least 6.2 is advised - All three topologies are supported: standalone, Sentinel, and Cluster - **Active-passive is recommended.** Active-active has not been tested and may behave in undocumented ways - **Set the eviction policy to `noeviction`.** This is required, not a tuning suggestion — evicting keys under memory pressure would silently drop queued work - Enable persistence (AOF, or at minimum RDB snapshots) and back Redis up. Pending secret rotations, syncs, and webhook deliveries live there; a Redis that comes back empty loses them - Give Redis the same availability target as the app instances — an unreplicated Redis is a single point of failure for the whole deployment 5. **Stateless Architecture**: Infisical is stateless. Scale horizontally by adding more replicas. All state lives in PostgreSQL and Redis. Each instance needs no more than 2–4 CPU cores and 4–8 GB memory; add containers rather than growing one. 6. **FIPS Compliance**: Infisical is compliant with **FIPS 140-3**. Deploy the separate **`infisical/infisical-fips`** Docker image (an Enterprise-only image, not a tag on the standard repo) and set `FIPS_ENABLED=true`. Remember the `ENCRYPTION_KEY` format changes to 256-bit base64 in FIPS mode. ## Quick Start - **Docker Standalone**: Pull `infisical/infisical:`, set environment variables, run on port 8080. - **Docker Compose**: Use `docker-compose.prod.yml` from the repository with PostgreSQL and Redis services. - **Kubernetes**: Deploy via Helm chart `infisical-standalone-postgres` from Cloudsmith registry with optional managed databases. ## Reference Guides ### [Environment Variables](./references/environment-variables.md) Complete reference for all configuration environment variables, including: - Required keys (ENCRYPTION_KEY, AUTH_SECRET, database, Redis) - Database and replication setup - Redis with Sentinel support - SMTP configuration - OAuth/SSO providers - FIPS and telemetry settings - Security options ### [Docker Deployment](./references/docker-deployment.md) Docker and Docker Compose deployment patterns, including: - Standalone container setup - Docker Compose production stack - Image variants (standard and FIPS) - Production hardening with security capabilities and read-only filesystems - Health checks ### [Kubernetes Deployment](./references/kubernetes-deployment.md) Kubernetes and Helm deployment guide, including: - Helm chart installation and configuration - Secret creation and management - Optional PostgreSQL and Redis (Bitnami charts) - Pod security and RBAC - Networking policies and Ingress/TLS ### [Scaling and High Availability](./references/scaling-and-ha.md) Production scaling patterns and HA architecture, including: - Horizontal scaling (adding replicas) - Sizing guidelines for Infisical, PostgreSQL, and Redis - Database read replicas - Redis Sentinel for HA - Backup and upgrade procedures - License server firewall rules

相关技能

运维与云

Docker Essentials

用于容器管理,图像操作,调试的基本道克命令和工作流程.

运维与云

Find Skills

从开放的代理技能生态系统中发现并安装技能. 使用时:(1)用户问"我如何做X",X可能拥有现有技能,(2)用户说"为X找到技能"或"是否为X有技能",(3)用户问"你能否做X",X是专门能力,(4)用户想扩展代理能力,(5)用户想搜索工具,模板,或工作流程,(6)用户提到他们希望…

运维与云

Azure Diagnostics

Azure上使用AppLens,AzureMonitor,资源健康,安全分型的调试Azure生产问题. 当:调试生产问题,故障解答应用服务,应用服务高CPU,应用服务部署失败,故障解答容器应用,故障解答功能,故障解答AKS,VM RDP,Linux SSH,VM黑屏幕,无法连接到…

运维与云

Azure Prepare

准备 azd 用于部署的Azure项目:为Azure开发者CLI(azd)工作流程生成azure.yaml,基础设施(Bicep/Terraform)和多克文件. 仅当用户明确想要使用 azd 作为部署工具时使用, 或项目已经有一个 azure 。 雅姆尔文件。 不使用: 非az…