Snowflake Prerequisites
Infisical requires a Snowflake user in your account with the USERADMIN role.
This user will act as a service account for Infisical and facilitate the
creation of new users as needed.
1
Navigate to Snowflake's User Dashboard and press the '+ User' button
2
Create a Snowflake user with the USERADMIN role for Infisical
3
Click on the Account Menu in the bottom left and take note of your Account and Organization identifiers
Set up Dynamic Secrets with Snowflake
1
Open the Secret Overview Dashboard
Open the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret.
2
Click on the 'Add Dynamic Secret' button
3
Select the Snowflake option in the grid list
4
Provide the required parameters for the Snowflake dynamic secret
string
required
The name you want to reference this secret by
string
required
Default time-to-live for a generated secret (it is possible to modify this value when generating a secret)
string
required
Maximum time-to-live for a generated secret
string
required
Snowflake account identifier
string
required
Snowflake organization identifier
string
required
Username of the Infisical Service User
string
required
Password of the Infisical Service User
5
(Optional) Modify SQL Statements
string
default:"{{randomUsername}}"
Specifies a template for generating usernames. This field allows customization of how usernames are automatically created.Allowed template variables are:
{{randomUsername}}: Random username string.{{unixTimestamp}}: Current Unix timestamp at the time of lease creation.{{identity.name}}: Name of the identity that is generating the lease.{{dynamicSecret.name}}: Name of the associated dynamic secret.{{dynamicSecret.type}}: Type of the associated dynamic secret.{{random N}}: Random string of N characters.
truncate: Truncates a string to a specified length.replace: Replaces a substring with another value.uppercase: Converts a string to uppercase.lowercase: Converts a string to lowercase.
string
If you want to provide specific privileges for the generated dynamic credentials, you can modify the SQL
statement to your needs.
6
Click 'Submit'
After submitting the form, you will see a dynamic secret created in the dashboard.
7
Generate dynamic secrets
Once you’ve successfully configured the dynamic secret, you’re ready to generate on-demand credentials.
To do this, simply click on the ‘Generate’ button which appears when hovering over the dynamic secret item.
Alternatively, you can initiate the creation of a new lease by selecting ‘New Lease’ from the dynamic secret
lease list section.When generating these secrets, it’s important to specify a Time-to-Live (TTL) duration. This will dictate how
long the credentials are valid for.Once you click the
Submit button, a new secret lease will be generated and the credentials for it will be
shown to you.