⚠️ HISTORICAL — Infisical e stato completamente decommissionato da TazLab. Tutti i secret sono stati migrati a HashiCorp Vault (VSO) e gopass. Questa pagina e mantenuta come riferimento storico.
Infisical
⚠️ DECOMMISSIONED — Infisical has been fully decommissioned from the TazLab cluster (2026-06-01). All secrets migrated to HashiCorp Vault. Retained for historical reference only.
Scope
Infisical was the previous secret backend, superseded by HashiCorp Vault (tazlab-secrets-vault). It was retained as a legacy fallback for external consumers (TazPod, setup scripts) until decommission, tracked in 20-infisical-decommission.
Current Status
- All cluster ExternalSecrets → migrated to
tazlab-secrets-vault(HashiCorp Vault) ✅ tazlab-secretsstore → was still deployed by Terraform engine layer (empty credentials, no cluster consumers) until removed- External consumers (setup.sh, TazPod) → used Infisical until decommission
- Bootstrap → no longer depends on Infisical (secrets read from
~/secrets/local files) ✅
Decommission Timeline
Completed as tracked in CRISP project 20-infisical-decommission. All prerequisites resolved:
- ✅ All ExternalSecrets migrated to Vault
- ✅ Bootstrap chain Infisical-free
- ✅
secrets-fetchermigrated to Vault - ✅ Confirmed no external consumers still depend on Infisical
Relationships
- central to TazLab Secret And Identity Flow
- central to TazLab Infrastructure Tech Stack
- visible in TazLab K8s Configs
Source Basis
AGENTS.ctx/tazlab-k8s/CONTEXT.mdAGENTS.ctx/ephemeral-castle/CONTEXT.md