Infisical
Scope
Infisical is the current secret backend used by TazLab for GitOps-aligned secret delivery.
Current Synthesis
TazLab currently uses Infisical as the live secret source behind the tazlab-secrets contract. Cluster workloads still consume secrets through ExternalSecret resources, but the backing store is Infisical rather than SOPS-managed files.
Why It Matters
It is the present-day bridge between GitOps manifests and runtime secret material.
Key Characteristics
- current live backend for ESO-driven secret delivery
- supports machine identity and bootstrap-time secret retrieval
- keeps secrets out of Git while preserving declarative consumption
Relationships
- central to TazLab Secret And Identity Flow
- central to TazLab Infrastructure Tech Stack
- visible in TazLab K8s Configs
Source Basis
AGENTS.ctx/tazlab-k8s/CONTEXT.mdAGENTS.ctx/ephemeral-castle/CONTEXT.md