Agent instructions, skills, SSH host aliases and expansion triggers are worth having identical on every machine one person owns, and belong in none of the shared configuration. They live in user/ now, with a manifest saying where each piece goes and a link-user stage that puts it there. That stage does nothing unless the machine said yes. Somebody who clones Panama to try the desktop keeps their own ~/.claude/CLAUDE.md exactly where it was; the question names the destinations and defaults to no. Anything displaced goes to config/old rather than being deleted. ~/.claude/CLAUDE.md and ~/.codex/AGENTS.md were byte-identical copies of one file, which is the drift this exists to prevent. Also adds the vitals toggles for the battery and Claude usage readouts, which had preferences and no way to reach them.
4.5 KiB
4.5 KiB
Dynamic Secrets: SQL Databases
PostgreSQL
Prerequisites
- A PostgreSQL user with permissions to CREATE ROLE, GRANT, and REVOKE
- This user will be used by Infisical to create/drop temporary database users
Configuration
| Field | Required | Description |
|---|---|---|
| Secret Name | Yes | Name for this dynamic secret |
| Default TTL | Yes | Default lease duration (e.g., 1h) |
| Max TTL | Yes | Maximum lease duration (e.g., 24h) |
| Host | Yes | Database hostname or IP |
| Port | Yes | Database port (default: 5432) |
| User | Yes | Admin user for creating credentials |
| Password | Yes | Admin user password |
| Database Name | Yes | Target database |
| CA (SSL) | No | CA certificate for SSL connections (common for AWS RDS) |
SQL Statements (Customizable)
Default creation statement grants broad access. Customize for least privilege:
-- Example: Read-only access to specific tables
CREATE ROLE "{{username}}" WITH LOGIN PASSWORD '{{password}}' VALID UNTIL '{{expiration}}';
GRANT SELECT ON TABLE public.users, public.orders TO "{{username}}";
Template variables: {{username}}, {{password}}, {{expiration}}
Note: PostgreSQL uses double quotes for identifiers.
Lease Returns
DB_USERNAME— Generated usernameDB_PASSWORD— Generated password
MySQL
Prerequisites
- A MySQL user with CREATE USER, GRANT, and REVOKE privileges
- This user will be used by Infisical to create/drop temporary database users
Configuration
| Field | Required | Description |
|---|---|---|
| Secret Name | Yes | Name for this dynamic secret |
| Default TTL | Yes | Default lease duration |
| Max TTL | Yes | Maximum lease duration |
| Host | Yes | Database hostname or IP |
| Port | Yes | Database port (default: 3306) |
| User | Yes | Admin user for creating credentials |
| Password | Yes | Admin user password |
| Database Name | Yes | Target database |
| CA (SSL) | No | CA certificate for SSL connections |
SQL Statements (Customizable)
-- Example: Read-only access to specific database
CREATE USER '{{username}}'@'%' IDENTIFIED BY '{{password}}';
GRANT SELECT ON mydb.* TO '{{username}}'@'%';
Template variables: {{username}}, {{password}}, {{expiration}}
Lease Returns
DB_USERNAME— Generated usernameDB_PASSWORD— Generated password
Cassandra
Prerequisites
- A Cassandra user with privileges to create, drop, and grant roles
cassandra.yamlmust have:authenticator: PasswordAuthenticator authorizer: CassandraAuthorizer
Configuration
| Field | Required | Description |
|---|---|---|
| Secret Name | Yes | Name for this dynamic secret |
| Default TTL | Yes | Default lease duration |
| Max TTL | Yes | Maximum lease duration |
| Host | Yes | Cassandra host(s) — comma-separated for multiple nodes |
| Port | Yes | Cassandra port (default: 9042) |
| User | Yes | Admin user for creating credentials |
| Password | Yes | Admin user password |
| Local Data Center | Yes | Must match cluster data center name |
| Keyspace | No | Restrict user to specific keyspace |
| CA (SSL) | No | CA certificate for SSL connections |
CQL Statements (Customizable)
-- Example: Read-only access to specific keyspace
CREATE ROLE '{{username}}' WITH PASSWORD = '{{password}}' AND LOGIN = true;
GRANT SELECT ON KEYSPACE mykeyspace TO '{{username}}';
Lease Returns
DB_USERNAME— Generated usernameDB_PASSWORD— Generated password
Gotchas
PasswordAuthenticatorandCassandraAuthorizerMUST be set in cassandra.yamlLocal Data Centermust exactly match your cluster's DC name
Other SQL Databases
MSSQL, Oracle, SAP ASE, SAP HANA, Snowflake, Vertica, ClickHouse, and Azure SQL Database all follow the same pattern:
- Provide connection details (host, port, admin user/password, database)
- Optionally customize SQL creation/revocation statements
- Generate leases that return
DB_USERNAMEandDB_PASSWORD
Key differences:
- MSSQL: Uses
CREATE LOGIN/CREATE USERsyntax - Oracle: Uses
CREATE USER/GRANT CONNECTsyntax - Snowflake: Requires warehouse, account identifier, and organization name
- Azure SQL Database: Similar to MSSQL but requires Azure-specific connection strings
Username Template
All SQL providers support an optional Username Template field that lets you customize the format of generated usernames (e.g., adding a prefix like inf_{{random}}).