diff --git a/docs/pages/includes/configure-event-handler.mdx b/docs/pages/includes/configure-event-handler.mdx index da85db14ca5..a56b6e4895c 100644 --- a/docs/pages/includes/configure-event-handler.mdx +++ b/docs/pages/includes/configure-event-handler.mdx @@ -64,6 +64,7 @@ Teleport event handler (=teleport.version=) [2] Generated sample teleport-event-handler role and user file teleport-event-handler-role.yaml [3] Generated sample fluentd configuration file fluent.conf [4] Generated plugin configuration file teleport-event-handler.toml +[5] Generated plugin helm configuration file teleport-plugin-event-handler-values.yaml ``` The plugin generates several setup files: @@ -79,6 +80,7 @@ $ ls -l # -rw------- 1 bob bob 1766 Jul 1 11:14 server.key # -rw------- 1 bob bob 260 Jul 1 11:14 teleport-event-handler-role.yaml # -rw------- 1 bob bob 343 Jul 1 11:14 teleport-event-handler.toml +# -rw------- 1 bob bob 343 Jul 1 11:14 teleport-plugin-event-handler-values.yaml ``` | File(s) | Purpose | @@ -87,6 +89,8 @@ $ ls -l | `server.crt` and `server.key` | Fluentd server certificate and key | | `client.crt` and `client.key` | Fluentd client certificate and key, all signed by the generated CA | | `teleport-event-handler-role.yaml` | `user` and `role` resource definitions for Teleport's event handler | +| `teleport-event-handler.toml` | Example event handler configuration | +| `teleport-plugin-event-handler-values.yaml` | Example event handler helm configuration | | `fluent.conf` | Fluentd plugin configuration |
diff --git a/integrations/event-handler/configure_cmd.go b/integrations/event-handler/configure_cmd.go index bc76427cae0..e1689764259 100644 --- a/integrations/event-handler/configure_cmd.go +++ b/integrations/event-handler/configure_cmd.go @@ -76,6 +76,9 @@ type ConfigureCmd struct { // confPath path to target plugin configuration file which contains an example plugin configuration confPath string + // helmConfPath path to target plugin helm configuration file which contains an example plugin configuration + helmConfPath string + // mtls is the struct with generated mTLS certificates mtls *MTLSCerts } @@ -90,6 +93,9 @@ var ( //go:embed tpl/teleport-event-handler.toml.tpl confTpl string + //go:embed tpl/teleport-plugin-event-handler-values.yaml.tpl + helmConfTpl string + //go:embed tpl/fluent.conf.tpl fluentdConfTpl string ) @@ -110,6 +116,9 @@ const ( // confFileName is plugin configuration file name confFileName = "teleport-event-handler.toml" + // helmConfFileName is plugin helm configuration file name + helmConfFileName = "teleport-plugin-event-handler-values.yaml" + // guideURL is getting started guide URL guideURL = "https://goteleport.com/docs/management/export-audit-events/fluentd/" ) @@ -127,6 +136,7 @@ func RunConfigureCmd(cfg *ConfigureCmdConfig) error { roleDefPath: filepath.Join(cfg.Out, roleDefFileName), fluentdConfPath: filepath.Join(cfg.Out, fluentdConfFileName), confPath: filepath.Join(cfg.Out, confFileName), + helmConfPath: filepath.Join(cfg.Out, helmConfFileName), } g, err := GenerateMTLSCerts(cfg.DNSNames, cfg.IP, cfg.TTL, cfg.Length) @@ -205,6 +215,19 @@ func (c *ConfigureCmd) Run() error { c.printStep("Generated plugin configuration file %v", path) + // Write the helm configuration file + err = c.writeHelmConf() + if err != nil { + return trace.Wrap(err) + } + + path, err = c.cleanupPath(c.helmConfPath) + if err != nil { + return trace.Wrap(err) + } + + c.printStep("Generated plugin helm configuration file %v", path) + fmt.Println() fmt.Println("Follow-along with our getting started guide:") fmt.Println() @@ -360,7 +383,7 @@ func (c *ConfigureCmd) writeFluentdConf(pwd string) error { return c.writeFile(c.fluentdConfPath, b.Bytes()) } -// writeFluentdConf writes fluentd config file +// writeConf writes plugin config file func (c *ConfigureCmd) writeConf() error { var b bytes.Buffer var pipeline = struct { @@ -378,6 +401,21 @@ func (c *ConfigureCmd) writeConf() error { return c.writeFile(c.confPath, b.Bytes()) } +// writeHelmConf writes plugin helm config file +func (c *ConfigureCmd) writeHelmConf() error { + var b bytes.Buffer + var pipeline = struct { + Addr string + }{c.Addr} + + err := lib.RenderTemplate(helmConfTpl, pipeline, &b) + if err != nil { + return trace.Wrap(err) + } + + return c.writeFile(c.helmConfPath, b.Bytes()) +} + // askOverwrite asks question if the user wants to overwrite specified file if it exists func (c *ConfigureCmd) askOverwrite(path string) bool { _, err := os.Stat(path) diff --git a/integrations/event-handler/main.go b/integrations/event-handler/main.go index 693b5bb24e0..df33e96c396 100644 --- a/integrations/event-handler/main.go +++ b/integrations/event-handler/main.go @@ -36,7 +36,7 @@ var cli CLI const ( // pluginName is the plugin name - pluginName = "Teleport event handler" + pluginName = "teleport-event-handler" // pluginDescription is the plugin description pluginDescription = "Forwards Teleport AuditLog to external sources" diff --git a/integrations/event-handler/tpl/teleport-plugin-event-handler-values.yaml.tpl b/integrations/event-handler/tpl/teleport-plugin-event-handler-values.yaml.tpl new file mode 100644 index 00000000000..77f023ee0ae --- /dev/null +++ b/integrations/event-handler/tpl/teleport-plugin-event-handler-values.yaml.tpl @@ -0,0 +1,21 @@ +eventHandler: + storagePath: "./storage" + timeout: "10s" + batch: 20 + +teleport: + address: "{{.Addr}}" + identitySecretName: teleport-event-handler-identity + identitySecretPath: identity + +fluentd: + url: "https://fluentd.fluentd.svc.cluster.local/events.log" + sessionUrl: "https://fluentd.fluentd.svc.cluster.local/session.log" + certificate: + secretName: "teleport-event-handler-client-tls" + caPath: "ca.crt" + certPath: "client.crt" + keyPath: "client.key" + +persistentVolumeClaim: + enabled: true