Infisical

Scope

Infisical is the current secret backend used by TazLab for GitOps-aligned secret delivery.

Current Synthesis

TazLab currently uses Infisical as the live secret source behind the tazlab-secrets contract. Cluster workloads still consume secrets through ExternalSecret resources, but the backing store is Infisical rather than SOPS-managed files.

Why It Matters

It is the present-day bridge between GitOps manifests and runtime secret material.

Key Characteristics

  • current live backend for ESO-driven secret delivery
  • supports machine identity and bootstrap-time secret retrieval
  • keeps secrets out of Git while preserving declarative consumption

Relationships

Source Basis

  • AGENTS.ctx/tazlab-k8s/CONTEXT.md
  • AGENTS.ctx/ephemeral-castle/CONTEXT.md