- Introduction
- Requirements
- Installation
- Configuration
- Development
- Maintainers
A Drupal module providing integration between Infisical and the Key module for secrets management.
- Drupal 10 or 11
- Key module
- An Infisical instance with a Machine Identity configured using Universal Auth
composer require drupal/key_infisical- Enable the module:
drush en key_infisical
- Go to Configuration > System > Keys (
/admin/config/system/keys). - Add a new key and select Infisical as the key provider.
- Fill in the provider settings:
- Infisical URL — Your instance URL (defaults to
https://app.infisical.com). - Client ID / Client Secret — Universal Auth credentials for your Machine Identity.
- Project ID — The Infisical project (workspace) ID.
- Environment — The environment slug (e.g.
dev,staging,prod). - Secret Path — The folder path (e.g.
/for root). - Secret Name — The name of the secret to retrieve.
- Infisical URL — Your instance URL (defaults to
- Save. The key value will be fetched from Infisical on demand.
When editing an existing key, leaving the Client Secret field blank keeps the currently stored secret unchanged.
The Client Secret is stored on the key's configuration entity, which means it will appear in plain text in drush config:export output (and in any config committed to your codebase). To avoid shipping the secret in configuration, override it per environment in settings.php instead of relying on the value saved through the UI:
$config['key.key.my_key']['key_provider_settings']['client_secret'] = getenv('INFISICAL_CLIENT_SECRET');Replace my_key with the machine name of the key you configured, and set the INFISICAL_CLIENT_SECRET environment variable for each environment.
Install the development tooling with composer install. The drupal/key
dependency is served from https://packages.drupal.org/8 rather than Packagist;
composer.json declares that repository, so a standalone clone resolves without
further setup. Then:
composer lintruns PHP_CodeSniffer againstphpcs.xml.dist(Drupal and DrupalPractice).composer lint:fixrunsphpcbf. Read its diff before keeping it. Most of what it offers to auto-fix in Drupal modules is the "comment must start with a capital letter" family, and it applies that blindly to identifiers: a doc comment beginninggetSecret() returns ...is rewritten toGetSecret() returns ..., silently referring to a method that does not exist. It has also been observed mangling ternaries. Fixing violations by hand is usually safer.- PHPStan runs from
phpstan.neonat level 2. It is advisory in CI (allow_failure: true) rather than blocking.
- Pieter Van Leuven - pietervanleuven