SPIFFE X.509 issuer override: CRUD (#53088)

* SPIFFE X.509 issuer override: CRUD

* tctl support for workload_identity_x509_issuer_override

* Define audit log events

* Emit audit log events

* Add comments to point at the e implementation

* audit events fixtures

* Use DisallowUnknown in tctl
This commit is contained in:
Edoardo Spadolini
2025-03-28 13:26:09 +00:00
committed by GitHub
parent ae13b4021e
commit 2fca5820ed
28 changed files with 4281 additions and 1558 deletions
+6
View File
@@ -902,6 +902,12 @@ func (c *Client) WorkloadIdentityIssuanceClient() workloadidentityv1pb.WorkloadI
return workloadidentityv1pb.NewWorkloadIdentityIssuanceServiceClient(c.conn)
}
// WorkloadIdentityX509OverridesClient returns an unadorned client for the
// teleport.workloadidentity.v1.X509OverridesService service.
func (c *Client) WorkloadIdentityX509OverridesClient() workloadidentityv1pb.X509OverridesServiceClient {
return workloadidentityv1pb.NewX509OverridesServiceClient(c.conn)
}
// PresenceServiceClient returns an unadorned client for the presence service.
func (c *Client) PresenceServiceClient() presencepb.PresenceServiceClient {
return presencepb.NewPresenceServiceClient(c.conn)
@@ -0,0 +1,243 @@
// Copyright 2025 Gravitational, Inc.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// Code generated by protoc-gen-go. DO NOT EDIT.
// versions:
// protoc-gen-go v1.36.5
// protoc (unknown)
// source: teleport/workloadidentity/v1/x509_overrides.proto
package workloadidentityv1
import (
v1 "github.com/gravitational/teleport/api/gen/proto/go/teleport/header/v1"
protoreflect "google.golang.org/protobuf/reflect/protoreflect"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
reflect "reflect"
sync "sync"
unsafe "unsafe"
)
const (
// Verify that this generated code is sufficiently up-to-date.
_ = protoimpl.EnforceVersion(20 - protoimpl.MinVersion)
// Verify that runtime/protoimpl is sufficiently up-to-date.
_ = protoimpl.EnforceVersion(protoimpl.MaxVersion - 20)
)
// A configuration resource to override the issuers of SPIFFE X509-SVID
// credentials. This message serves as both the type used in the v1 service and
// as the canonical v1 storage format (in protojson).
type X509IssuerOverride struct {
state protoimpl.MessageState `protogen:"open.v1"`
// Fixed string, "workload_identity_x509_issuer_override".
Kind string `protobuf:"bytes,1,opt,name=kind,proto3" json:"kind,omitempty"`
// Fixed string, "".
SubKind string `protobuf:"bytes,2,opt,name=sub_kind,json=subKind,proto3" json:"sub_kind,omitempty"`
// Fixed string, "v1".
Version string `protobuf:"bytes,3,opt,name=version,proto3" json:"version,omitempty"`
Metadata *v1.Metadata `protobuf:"bytes,4,opt,name=metadata,proto3" json:"metadata,omitempty"`
Spec *X509IssuerOverrideSpec `protobuf:"bytes,5,opt,name=spec,proto3" json:"spec,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *X509IssuerOverride) Reset() {
*x = X509IssuerOverride{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_proto_msgTypes[0]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *X509IssuerOverride) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*X509IssuerOverride) ProtoMessage() {}
func (x *X509IssuerOverride) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_proto_msgTypes[0]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use X509IssuerOverride.ProtoReflect.Descriptor instead.
func (*X509IssuerOverride) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_proto_rawDescGZIP(), []int{0}
}
func (x *X509IssuerOverride) GetKind() string {
if x != nil {
return x.Kind
}
return ""
}
func (x *X509IssuerOverride) GetSubKind() string {
if x != nil {
return x.SubKind
}
return ""
}
func (x *X509IssuerOverride) GetVersion() string {
if x != nil {
return x.Version
}
return ""
}
func (x *X509IssuerOverride) GetMetadata() *v1.Metadata {
if x != nil {
return x.Metadata
}
return nil
}
func (x *X509IssuerOverride) GetSpec() *X509IssuerOverrideSpec {
if x != nil {
return x.Spec
}
return nil
}
// The spec for X509IssuerOverride.
type X509IssuerOverrideSpec struct {
state protoimpl.MessageState `protogen:"open.v1"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *X509IssuerOverrideSpec) Reset() {
*x = X509IssuerOverrideSpec{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_proto_msgTypes[1]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *X509IssuerOverrideSpec) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*X509IssuerOverrideSpec) ProtoMessage() {}
func (x *X509IssuerOverrideSpec) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_proto_msgTypes[1]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use X509IssuerOverrideSpec.ProtoReflect.Descriptor instead.
func (*X509IssuerOverrideSpec) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_proto_rawDescGZIP(), []int{1}
}
var File_teleport_workloadidentity_v1_x509_overrides_proto protoreflect.FileDescriptor
var file_teleport_workloadidentity_v1_x509_overrides_proto_rawDesc = string([]byte{
0x0a, 0x31, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2f, 0x77, 0x6f, 0x72, 0x6b, 0x6c,
0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2f, 0x76, 0x31, 0x2f, 0x78,
0x35, 0x30, 0x39, 0x5f, 0x6f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x73, 0x2e, 0x70, 0x72,
0x6f, 0x74, 0x6f, 0x12, 0x1c, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f,
0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76,
0x31, 0x1a, 0x21, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2f, 0x68, 0x65, 0x61, 0x64,
0x65, 0x72, 0x2f, 0x76, 0x31, 0x2f, 0x6d, 0x65, 0x74, 0x61, 0x64, 0x61, 0x74, 0x61, 0x2e, 0x70,
0x72, 0x6f, 0x74, 0x6f, 0x22, 0xe1, 0x01, 0x0a, 0x12, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73,
0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x12, 0x12, 0x0a, 0x04, 0x6b,
0x69, 0x6e, 0x64, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x04, 0x6b, 0x69, 0x6e, 0x64, 0x12,
0x19, 0x0a, 0x08, 0x73, 0x75, 0x62, 0x5f, 0x6b, 0x69, 0x6e, 0x64, 0x18, 0x02, 0x20, 0x01, 0x28,
0x09, 0x52, 0x07, 0x73, 0x75, 0x62, 0x4b, 0x69, 0x6e, 0x64, 0x12, 0x18, 0x0a, 0x07, 0x76, 0x65,
0x72, 0x73, 0x69, 0x6f, 0x6e, 0x18, 0x03, 0x20, 0x01, 0x28, 0x09, 0x52, 0x07, 0x76, 0x65, 0x72,
0x73, 0x69, 0x6f, 0x6e, 0x12, 0x38, 0x0a, 0x08, 0x6d, 0x65, 0x74, 0x61, 0x64, 0x61, 0x74, 0x61,
0x18, 0x04, 0x20, 0x01, 0x28, 0x0b, 0x32, 0x1c, 0x2e, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72,
0x74, 0x2e, 0x68, 0x65, 0x61, 0x64, 0x65, 0x72, 0x2e, 0x76, 0x31, 0x2e, 0x4d, 0x65, 0x74, 0x61,
0x64, 0x61, 0x74, 0x61, 0x52, 0x08, 0x6d, 0x65, 0x74, 0x61, 0x64, 0x61, 0x74, 0x61, 0x12, 0x48,
0x0a, 0x04, 0x73, 0x70, 0x65, 0x63, 0x18, 0x05, 0x20, 0x01, 0x28, 0x0b, 0x32, 0x34, 0x2e, 0x74,
0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64,
0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58, 0x35, 0x30, 0x39,
0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x53, 0x70,
0x65, 0x63, 0x52, 0x04, 0x73, 0x70, 0x65, 0x63, 0x22, 0x18, 0x0a, 0x16, 0x58, 0x35, 0x30, 0x39,
0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x53, 0x70,
0x65, 0x63, 0x42, 0x64, 0x5a, 0x62, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f, 0x6d,
0x2f, 0x67, 0x72, 0x61, 0x76, 0x69, 0x74, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x61, 0x6c, 0x2f, 0x74,
0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2f, 0x61, 0x70, 0x69, 0x2f, 0x67, 0x65, 0x6e, 0x2f,
0x70, 0x72, 0x6f, 0x74, 0x6f, 0x2f, 0x67, 0x6f, 0x2f, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72,
0x74, 0x2f, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69,
0x74, 0x79, 0x2f, 0x76, 0x31, 0x3b, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64,
0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x76, 0x31, 0x62, 0x06, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x33,
})
var (
file_teleport_workloadidentity_v1_x509_overrides_proto_rawDescOnce sync.Once
file_teleport_workloadidentity_v1_x509_overrides_proto_rawDescData []byte
)
func file_teleport_workloadidentity_v1_x509_overrides_proto_rawDescGZIP() []byte {
file_teleport_workloadidentity_v1_x509_overrides_proto_rawDescOnce.Do(func() {
file_teleport_workloadidentity_v1_x509_overrides_proto_rawDescData = protoimpl.X.CompressGZIP(unsafe.Slice(unsafe.StringData(file_teleport_workloadidentity_v1_x509_overrides_proto_rawDesc), len(file_teleport_workloadidentity_v1_x509_overrides_proto_rawDesc)))
})
return file_teleport_workloadidentity_v1_x509_overrides_proto_rawDescData
}
var file_teleport_workloadidentity_v1_x509_overrides_proto_msgTypes = make([]protoimpl.MessageInfo, 2)
var file_teleport_workloadidentity_v1_x509_overrides_proto_goTypes = []any{
(*X509IssuerOverride)(nil), // 0: teleport.workloadidentity.v1.X509IssuerOverride
(*X509IssuerOverrideSpec)(nil), // 1: teleport.workloadidentity.v1.X509IssuerOverrideSpec
(*v1.Metadata)(nil), // 2: teleport.header.v1.Metadata
}
var file_teleport_workloadidentity_v1_x509_overrides_proto_depIdxs = []int32{
2, // 0: teleport.workloadidentity.v1.X509IssuerOverride.metadata:type_name -> teleport.header.v1.Metadata
1, // 1: teleport.workloadidentity.v1.X509IssuerOverride.spec:type_name -> teleport.workloadidentity.v1.X509IssuerOverrideSpec
2, // [2:2] is the sub-list for method output_type
2, // [2:2] is the sub-list for method input_type
2, // [2:2] is the sub-list for extension type_name
2, // [2:2] is the sub-list for extension extendee
0, // [0:2] is the sub-list for field type_name
}
func init() { file_teleport_workloadidentity_v1_x509_overrides_proto_init() }
func file_teleport_workloadidentity_v1_x509_overrides_proto_init() {
if File_teleport_workloadidentity_v1_x509_overrides_proto != nil {
return
}
type x struct{}
out := protoimpl.TypeBuilder{
File: protoimpl.DescBuilder{
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
RawDescriptor: unsafe.Slice(unsafe.StringData(file_teleport_workloadidentity_v1_x509_overrides_proto_rawDesc), len(file_teleport_workloadidentity_v1_x509_overrides_proto_rawDesc)),
NumEnums: 0,
NumMessages: 2,
NumExtensions: 0,
NumServices: 0,
},
GoTypes: file_teleport_workloadidentity_v1_x509_overrides_proto_goTypes,
DependencyIndexes: file_teleport_workloadidentity_v1_x509_overrides_proto_depIdxs,
MessageInfos: file_teleport_workloadidentity_v1_x509_overrides_proto_msgTypes,
}.Build()
File_teleport_workloadidentity_v1_x509_overrides_proto = out.File
file_teleport_workloadidentity_v1_x509_overrides_proto_goTypes = nil
file_teleport_workloadidentity_v1_x509_overrides_proto_depIdxs = nil
}
@@ -0,0 +1,567 @@
// Copyright 2025 Gravitational, Inc.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// Code generated by protoc-gen-go. DO NOT EDIT.
// versions:
// protoc-gen-go v1.36.5
// protoc (unknown)
// source: teleport/workloadidentity/v1/x509_overrides_service.proto
package workloadidentityv1
import (
protoreflect "google.golang.org/protobuf/reflect/protoreflect"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
emptypb "google.golang.org/protobuf/types/known/emptypb"
reflect "reflect"
sync "sync"
unsafe "unsafe"
)
const (
// Verify that this generated code is sufficiently up-to-date.
_ = protoimpl.EnforceVersion(20 - protoimpl.MinVersion)
// Verify that runtime/protoimpl is sufficiently up-to-date.
_ = protoimpl.EnforceVersion(protoimpl.MaxVersion - 20)
)
// Request message for GetX509IssuerOverride.
type GetX509IssuerOverrideRequest struct {
state protoimpl.MessageState `protogen:"open.v1"`
Name string `protobuf:"bytes,1,opt,name=name,proto3" json:"name,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *GetX509IssuerOverrideRequest) Reset() {
*x = GetX509IssuerOverrideRequest{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[0]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *GetX509IssuerOverrideRequest) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*GetX509IssuerOverrideRequest) ProtoMessage() {}
func (x *GetX509IssuerOverrideRequest) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[0]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use GetX509IssuerOverrideRequest.ProtoReflect.Descriptor instead.
func (*GetX509IssuerOverrideRequest) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescGZIP(), []int{0}
}
func (x *GetX509IssuerOverrideRequest) GetName() string {
if x != nil {
return x.Name
}
return ""
}
// Response message for GetX509IssuerOverride.
type ListX509IssuerOverridesRequest struct {
state protoimpl.MessageState `protogen:"open.v1"`
PageSize int32 `protobuf:"varint,1,opt,name=page_size,json=pageSize,proto3" json:"page_size,omitempty"`
PageToken string `protobuf:"bytes,2,opt,name=page_token,json=pageToken,proto3" json:"page_token,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *ListX509IssuerOverridesRequest) Reset() {
*x = ListX509IssuerOverridesRequest{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[1]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *ListX509IssuerOverridesRequest) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*ListX509IssuerOverridesRequest) ProtoMessage() {}
func (x *ListX509IssuerOverridesRequest) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[1]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use ListX509IssuerOverridesRequest.ProtoReflect.Descriptor instead.
func (*ListX509IssuerOverridesRequest) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescGZIP(), []int{1}
}
func (x *ListX509IssuerOverridesRequest) GetPageSize() int32 {
if x != nil {
return x.PageSize
}
return 0
}
func (x *ListX509IssuerOverridesRequest) GetPageToken() string {
if x != nil {
return x.PageToken
}
return ""
}
// Request message for ListX509IssuerOverrides.
type ListX509IssuerOverridesResponse struct {
state protoimpl.MessageState `protogen:"open.v1"`
X509IssuerOverrides []*X509IssuerOverride `protobuf:"bytes,1,rep,name=x509_issuer_overrides,json=x509IssuerOverrides,proto3" json:"x509_issuer_overrides,omitempty"`
NextPageToken string `protobuf:"bytes,2,opt,name=next_page_token,json=nextPageToken,proto3" json:"next_page_token,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *ListX509IssuerOverridesResponse) Reset() {
*x = ListX509IssuerOverridesResponse{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[2]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *ListX509IssuerOverridesResponse) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*ListX509IssuerOverridesResponse) ProtoMessage() {}
func (x *ListX509IssuerOverridesResponse) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[2]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use ListX509IssuerOverridesResponse.ProtoReflect.Descriptor instead.
func (*ListX509IssuerOverridesResponse) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescGZIP(), []int{2}
}
func (x *ListX509IssuerOverridesResponse) GetX509IssuerOverrides() []*X509IssuerOverride {
if x != nil {
return x.X509IssuerOverrides
}
return nil
}
func (x *ListX509IssuerOverridesResponse) GetNextPageToken() string {
if x != nil {
return x.NextPageToken
}
return ""
}
// Request message for CreateX509IssuerOverride.
type CreateX509IssuerOverrideRequest struct {
state protoimpl.MessageState `protogen:"open.v1"`
X509IssuerOverride *X509IssuerOverride `protobuf:"bytes,1,opt,name=x509_issuer_override,json=x509IssuerOverride,proto3" json:"x509_issuer_override,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *CreateX509IssuerOverrideRequest) Reset() {
*x = CreateX509IssuerOverrideRequest{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[3]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *CreateX509IssuerOverrideRequest) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*CreateX509IssuerOverrideRequest) ProtoMessage() {}
func (x *CreateX509IssuerOverrideRequest) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[3]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use CreateX509IssuerOverrideRequest.ProtoReflect.Descriptor instead.
func (*CreateX509IssuerOverrideRequest) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescGZIP(), []int{3}
}
func (x *CreateX509IssuerOverrideRequest) GetX509IssuerOverride() *X509IssuerOverride {
if x != nil {
return x.X509IssuerOverride
}
return nil
}
// Request message for UpdateX509IssuerOverride.
type UpdateX509IssuerOverrideRequest struct {
state protoimpl.MessageState `protogen:"open.v1"`
X509IssuerOverride *X509IssuerOverride `protobuf:"bytes,1,opt,name=x509_issuer_override,json=x509IssuerOverride,proto3" json:"x509_issuer_override,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *UpdateX509IssuerOverrideRequest) Reset() {
*x = UpdateX509IssuerOverrideRequest{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[4]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *UpdateX509IssuerOverrideRequest) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*UpdateX509IssuerOverrideRequest) ProtoMessage() {}
func (x *UpdateX509IssuerOverrideRequest) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[4]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use UpdateX509IssuerOverrideRequest.ProtoReflect.Descriptor instead.
func (*UpdateX509IssuerOverrideRequest) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescGZIP(), []int{4}
}
func (x *UpdateX509IssuerOverrideRequest) GetX509IssuerOverride() *X509IssuerOverride {
if x != nil {
return x.X509IssuerOverride
}
return nil
}
// Request message for UpsertX509IssuerOverride.
type UpsertX509IssuerOverrideRequest struct {
state protoimpl.MessageState `protogen:"open.v1"`
X509IssuerOverride *X509IssuerOverride `protobuf:"bytes,1,opt,name=x509_issuer_override,json=x509IssuerOverride,proto3" json:"x509_issuer_override,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *UpsertX509IssuerOverrideRequest) Reset() {
*x = UpsertX509IssuerOverrideRequest{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[5]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *UpsertX509IssuerOverrideRequest) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*UpsertX509IssuerOverrideRequest) ProtoMessage() {}
func (x *UpsertX509IssuerOverrideRequest) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[5]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use UpsertX509IssuerOverrideRequest.ProtoReflect.Descriptor instead.
func (*UpsertX509IssuerOverrideRequest) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescGZIP(), []int{5}
}
func (x *UpsertX509IssuerOverrideRequest) GetX509IssuerOverride() *X509IssuerOverride {
if x != nil {
return x.X509IssuerOverride
}
return nil
}
// Request message for DeleteX509IssuerOverride.
type DeleteX509IssuerOverrideRequest struct {
state protoimpl.MessageState `protogen:"open.v1"`
Name string `protobuf:"bytes,1,opt,name=name,proto3" json:"name,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *DeleteX509IssuerOverrideRequest) Reset() {
*x = DeleteX509IssuerOverrideRequest{}
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[6]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *DeleteX509IssuerOverrideRequest) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*DeleteX509IssuerOverrideRequest) ProtoMessage() {}
func (x *DeleteX509IssuerOverrideRequest) ProtoReflect() protoreflect.Message {
mi := &file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes[6]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use DeleteX509IssuerOverrideRequest.ProtoReflect.Descriptor instead.
func (*DeleteX509IssuerOverrideRequest) Descriptor() ([]byte, []int) {
return file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescGZIP(), []int{6}
}
func (x *DeleteX509IssuerOverrideRequest) GetName() string {
if x != nil {
return x.Name
}
return ""
}
var File_teleport_workloadidentity_v1_x509_overrides_service_proto protoreflect.FileDescriptor
var file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDesc = string([]byte{
0x0a, 0x39, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2f, 0x77, 0x6f, 0x72, 0x6b, 0x6c,
0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2f, 0x76, 0x31, 0x2f, 0x78,
0x35, 0x30, 0x39, 0x5f, 0x6f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x73, 0x5f, 0x73, 0x65,
0x72, 0x76, 0x69, 0x63, 0x65, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x12, 0x1c, 0x74, 0x65, 0x6c,
0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64,
0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x1a, 0x1b, 0x67, 0x6f, 0x6f, 0x67, 0x6c,
0x65, 0x2f, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2f, 0x65, 0x6d, 0x70, 0x74, 0x79,
0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x1a, 0x31, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74,
0x2f, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74,
0x79, 0x2f, 0x76, 0x31, 0x2f, 0x78, 0x35, 0x30, 0x39, 0x5f, 0x6f, 0x76, 0x65, 0x72, 0x72, 0x69,
0x64, 0x65, 0x73, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x22, 0x32, 0x0a, 0x1c, 0x47, 0x65, 0x74,
0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69,
0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12, 0x12, 0x0a, 0x04, 0x6e, 0x61, 0x6d,
0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x04, 0x6e, 0x61, 0x6d, 0x65, 0x22, 0x5c, 0x0a,
0x1e, 0x4c, 0x69, 0x73, 0x74, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f,
0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12,
0x1b, 0x0a, 0x09, 0x70, 0x61, 0x67, 0x65, 0x5f, 0x73, 0x69, 0x7a, 0x65, 0x18, 0x01, 0x20, 0x01,
0x28, 0x05, 0x52, 0x08, 0x70, 0x61, 0x67, 0x65, 0x53, 0x69, 0x7a, 0x65, 0x12, 0x1d, 0x0a, 0x0a,
0x70, 0x61, 0x67, 0x65, 0x5f, 0x74, 0x6f, 0x6b, 0x65, 0x6e, 0x18, 0x02, 0x20, 0x01, 0x28, 0x09,
0x52, 0x09, 0x70, 0x61, 0x67, 0x65, 0x54, 0x6f, 0x6b, 0x65, 0x6e, 0x22, 0xaf, 0x01, 0x0a, 0x1f,
0x4c, 0x69, 0x73, 0x74, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76,
0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12,
0x64, 0x0a, 0x15, 0x78, 0x35, 0x30, 0x39, 0x5f, 0x69, 0x73, 0x73, 0x75, 0x65, 0x72, 0x5f, 0x6f,
0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x73, 0x18, 0x01, 0x20, 0x03, 0x28, 0x0b, 0x32, 0x30,
0x2e, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f,
0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58, 0x35,
0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65,
0x52, 0x13, 0x78, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72,
0x72, 0x69, 0x64, 0x65, 0x73, 0x12, 0x26, 0x0a, 0x0f, 0x6e, 0x65, 0x78, 0x74, 0x5f, 0x70, 0x61,
0x67, 0x65, 0x5f, 0x74, 0x6f, 0x6b, 0x65, 0x6e, 0x18, 0x02, 0x20, 0x01, 0x28, 0x09, 0x52, 0x0d,
0x6e, 0x65, 0x78, 0x74, 0x50, 0x61, 0x67, 0x65, 0x54, 0x6f, 0x6b, 0x65, 0x6e, 0x22, 0x85, 0x01,
0x0a, 0x1f, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75,
0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73,
0x74, 0x12, 0x62, 0x0a, 0x14, 0x78, 0x35, 0x30, 0x39, 0x5f, 0x69, 0x73, 0x73, 0x75, 0x65, 0x72,
0x5f, 0x6f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x0b, 0x32,
0x30, 0x2e, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c,
0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58,
0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64,
0x65, 0x52, 0x12, 0x78, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65,
0x72, 0x72, 0x69, 0x64, 0x65, 0x22, 0x85, 0x01, 0x0a, 0x1f, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65,
0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69,
0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12, 0x62, 0x0a, 0x14, 0x78, 0x35, 0x30,
0x39, 0x5f, 0x69, 0x73, 0x73, 0x75, 0x65, 0x72, 0x5f, 0x6f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64,
0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x0b, 0x32, 0x30, 0x2e, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f,
0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74,
0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65,
0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x52, 0x12, 0x78, 0x35, 0x30, 0x39, 0x49,
0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x22, 0x85, 0x01,
0x0a, 0x1f, 0x55, 0x70, 0x73, 0x65, 0x72, 0x74, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75,
0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73,
0x74, 0x12, 0x62, 0x0a, 0x14, 0x78, 0x35, 0x30, 0x39, 0x5f, 0x69, 0x73, 0x73, 0x75, 0x65, 0x72,
0x5f, 0x6f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x0b, 0x32,
0x30, 0x2e, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c,
0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58,
0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64,
0x65, 0x52, 0x12, 0x78, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65,
0x72, 0x72, 0x69, 0x64, 0x65, 0x22, 0x35, 0x0a, 0x1f, 0x44, 0x65, 0x6c, 0x65, 0x74, 0x65, 0x58,
0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64,
0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12, 0x12, 0x0a, 0x04, 0x6e, 0x61, 0x6d, 0x65,
0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x04, 0x6e, 0x61, 0x6d, 0x65, 0x32, 0xe3, 0x06, 0x0a,
0x14, 0x58, 0x35, 0x30, 0x39, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x73, 0x53, 0x65,
0x72, 0x76, 0x69, 0x63, 0x65, 0x12, 0x8a, 0x01, 0x0a, 0x15, 0x47, 0x65, 0x74, 0x58, 0x35, 0x30,
0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x12,
0x3a, 0x2e, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c,
0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x47,
0x65, 0x74, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72,
0x72, 0x69, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x30, 0x2e, 0x74, 0x65,
0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69,
0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58, 0x35, 0x30, 0x39, 0x49,
0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x22, 0x03, 0x90,
0x02, 0x01, 0x12, 0x9b, 0x01, 0x0a, 0x17, 0x4c, 0x69, 0x73, 0x74, 0x58, 0x35, 0x30, 0x39, 0x49,
0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x73, 0x12, 0x3c,
0x2e, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f,
0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69,
0x73, 0x74, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72,
0x72, 0x69, 0x64, 0x65, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x3d, 0x2e, 0x74,
0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64,
0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74,
0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69,
0x64, 0x65, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x22, 0x03, 0x90, 0x02, 0x01,
0x12, 0x8b, 0x01, 0x0a, 0x18, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x58, 0x35, 0x30, 0x39, 0x49,
0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x12, 0x3d, 0x2e,
0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61,
0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x43, 0x72, 0x65,
0x61, 0x74, 0x65, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65,
0x72, 0x72, 0x69, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x30, 0x2e, 0x74,
0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64,
0x69, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58, 0x35, 0x30, 0x39,
0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x12, 0x8b,
0x01, 0x0a, 0x18, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73,
0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x12, 0x3d, 0x2e, 0x74, 0x65,
0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69,
0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x55, 0x70, 0x64, 0x61, 0x74,
0x65, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72,
0x69, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x30, 0x2e, 0x74, 0x65, 0x6c,
0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64,
0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73,
0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x12, 0x90, 0x01, 0x0a,
0x18, 0x55, 0x70, 0x73, 0x65, 0x72, 0x74, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65,
0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x12, 0x3d, 0x2e, 0x74, 0x65, 0x6c, 0x65,
0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64, 0x65,
0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x55, 0x70, 0x73, 0x65, 0x72, 0x74, 0x58,
0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64,
0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x30, 0x2e, 0x74, 0x65, 0x6c, 0x65, 0x70,
0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e,
0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75,
0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x22, 0x03, 0x90, 0x02, 0x02, 0x12,
0x71, 0x0a, 0x18, 0x44, 0x65, 0x6c, 0x65, 0x74, 0x65, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73,
0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72, 0x69, 0x64, 0x65, 0x12, 0x3d, 0x2e, 0x74, 0x65,
0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2e, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69,
0x64, 0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x2e, 0x76, 0x31, 0x2e, 0x44, 0x65, 0x6c, 0x65, 0x74,
0x65, 0x58, 0x35, 0x30, 0x39, 0x49, 0x73, 0x73, 0x75, 0x65, 0x72, 0x4f, 0x76, 0x65, 0x72, 0x72,
0x69, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x16, 0x2e, 0x67, 0x6f, 0x6f,
0x67, 0x6c, 0x65, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2e, 0x45, 0x6d, 0x70,
0x74, 0x79, 0x42, 0x64, 0x5a, 0x62, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f, 0x6d,
0x2f, 0x67, 0x72, 0x61, 0x76, 0x69, 0x74, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x61, 0x6c, 0x2f, 0x74,
0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2f, 0x61, 0x70, 0x69, 0x2f, 0x67, 0x65, 0x6e, 0x2f,
0x70, 0x72, 0x6f, 0x74, 0x6f, 0x2f, 0x67, 0x6f, 0x2f, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72,
0x74, 0x2f, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64, 0x65, 0x6e, 0x74, 0x69,
0x74, 0x79, 0x2f, 0x76, 0x31, 0x3b, 0x77, 0x6f, 0x72, 0x6b, 0x6c, 0x6f, 0x61, 0x64, 0x69, 0x64,
0x65, 0x6e, 0x74, 0x69, 0x74, 0x79, 0x76, 0x31, 0x62, 0x06, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x33,
})
var (
file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescOnce sync.Once
file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescData []byte
)
func file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescGZIP() []byte {
file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescOnce.Do(func() {
file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescData = protoimpl.X.CompressGZIP(unsafe.Slice(unsafe.StringData(file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDesc), len(file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDesc)))
})
return file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDescData
}
var file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes = make([]protoimpl.MessageInfo, 7)
var file_teleport_workloadidentity_v1_x509_overrides_service_proto_goTypes = []any{
(*GetX509IssuerOverrideRequest)(nil), // 0: teleport.workloadidentity.v1.GetX509IssuerOverrideRequest
(*ListX509IssuerOverridesRequest)(nil), // 1: teleport.workloadidentity.v1.ListX509IssuerOverridesRequest
(*ListX509IssuerOverridesResponse)(nil), // 2: teleport.workloadidentity.v1.ListX509IssuerOverridesResponse
(*CreateX509IssuerOverrideRequest)(nil), // 3: teleport.workloadidentity.v1.CreateX509IssuerOverrideRequest
(*UpdateX509IssuerOverrideRequest)(nil), // 4: teleport.workloadidentity.v1.UpdateX509IssuerOverrideRequest
(*UpsertX509IssuerOverrideRequest)(nil), // 5: teleport.workloadidentity.v1.UpsertX509IssuerOverrideRequest
(*DeleteX509IssuerOverrideRequest)(nil), // 6: teleport.workloadidentity.v1.DeleteX509IssuerOverrideRequest
(*X509IssuerOverride)(nil), // 7: teleport.workloadidentity.v1.X509IssuerOverride
(*emptypb.Empty)(nil), // 8: google.protobuf.Empty
}
var file_teleport_workloadidentity_v1_x509_overrides_service_proto_depIdxs = []int32{
7, // 0: teleport.workloadidentity.v1.ListX509IssuerOverridesResponse.x509_issuer_overrides:type_name -> teleport.workloadidentity.v1.X509IssuerOverride
7, // 1: teleport.workloadidentity.v1.CreateX509IssuerOverrideRequest.x509_issuer_override:type_name -> teleport.workloadidentity.v1.X509IssuerOverride
7, // 2: teleport.workloadidentity.v1.UpdateX509IssuerOverrideRequest.x509_issuer_override:type_name -> teleport.workloadidentity.v1.X509IssuerOverride
7, // 3: teleport.workloadidentity.v1.UpsertX509IssuerOverrideRequest.x509_issuer_override:type_name -> teleport.workloadidentity.v1.X509IssuerOverride
0, // 4: teleport.workloadidentity.v1.X509OverridesService.GetX509IssuerOverride:input_type -> teleport.workloadidentity.v1.GetX509IssuerOverrideRequest
1, // 5: teleport.workloadidentity.v1.X509OverridesService.ListX509IssuerOverrides:input_type -> teleport.workloadidentity.v1.ListX509IssuerOverridesRequest
3, // 6: teleport.workloadidentity.v1.X509OverridesService.CreateX509IssuerOverride:input_type -> teleport.workloadidentity.v1.CreateX509IssuerOverrideRequest
4, // 7: teleport.workloadidentity.v1.X509OverridesService.UpdateX509IssuerOverride:input_type -> teleport.workloadidentity.v1.UpdateX509IssuerOverrideRequest
5, // 8: teleport.workloadidentity.v1.X509OverridesService.UpsertX509IssuerOverride:input_type -> teleport.workloadidentity.v1.UpsertX509IssuerOverrideRequest
6, // 9: teleport.workloadidentity.v1.X509OverridesService.DeleteX509IssuerOverride:input_type -> teleport.workloadidentity.v1.DeleteX509IssuerOverrideRequest
7, // 10: teleport.workloadidentity.v1.X509OverridesService.GetX509IssuerOverride:output_type -> teleport.workloadidentity.v1.X509IssuerOverride
2, // 11: teleport.workloadidentity.v1.X509OverridesService.ListX509IssuerOverrides:output_type -> teleport.workloadidentity.v1.ListX509IssuerOverridesResponse
7, // 12: teleport.workloadidentity.v1.X509OverridesService.CreateX509IssuerOverride:output_type -> teleport.workloadidentity.v1.X509IssuerOverride
7, // 13: teleport.workloadidentity.v1.X509OverridesService.UpdateX509IssuerOverride:output_type -> teleport.workloadidentity.v1.X509IssuerOverride
7, // 14: teleport.workloadidentity.v1.X509OverridesService.UpsertX509IssuerOverride:output_type -> teleport.workloadidentity.v1.X509IssuerOverride
8, // 15: teleport.workloadidentity.v1.X509OverridesService.DeleteX509IssuerOverride:output_type -> google.protobuf.Empty
10, // [10:16] is the sub-list for method output_type
4, // [4:10] is the sub-list for method input_type
4, // [4:4] is the sub-list for extension type_name
4, // [4:4] is the sub-list for extension extendee
0, // [0:4] is the sub-list for field type_name
}
func init() { file_teleport_workloadidentity_v1_x509_overrides_service_proto_init() }
func file_teleport_workloadidentity_v1_x509_overrides_service_proto_init() {
if File_teleport_workloadidentity_v1_x509_overrides_service_proto != nil {
return
}
file_teleport_workloadidentity_v1_x509_overrides_proto_init()
type x struct{}
out := protoimpl.TypeBuilder{
File: protoimpl.DescBuilder{
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
RawDescriptor: unsafe.Slice(unsafe.StringData(file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDesc), len(file_teleport_workloadidentity_v1_x509_overrides_service_proto_rawDesc)),
NumEnums: 0,
NumMessages: 7,
NumExtensions: 0,
NumServices: 1,
},
GoTypes: file_teleport_workloadidentity_v1_x509_overrides_service_proto_goTypes,
DependencyIndexes: file_teleport_workloadidentity_v1_x509_overrides_service_proto_depIdxs,
MessageInfos: file_teleport_workloadidentity_v1_x509_overrides_service_proto_msgTypes,
}.Build()
File_teleport_workloadidentity_v1_x509_overrides_service_proto = out.File
file_teleport_workloadidentity_v1_x509_overrides_service_proto_goTypes = nil
file_teleport_workloadidentity_v1_x509_overrides_service_proto_depIdxs = nil
}
@@ -0,0 +1,358 @@
// Copyright 2025 Gravitational, Inc.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// Code generated by protoc-gen-go-grpc. DO NOT EDIT.
// versions:
// - protoc-gen-go-grpc v1.5.1
// - protoc (unknown)
// source: teleport/workloadidentity/v1/x509_overrides_service.proto
package workloadidentityv1
import (
context "context"
grpc "google.golang.org/grpc"
codes "google.golang.org/grpc/codes"
status "google.golang.org/grpc/status"
emptypb "google.golang.org/protobuf/types/known/emptypb"
)
// This is a compile-time assertion to ensure that this generated file
// is compatible with the grpc package it is being compiled against.
// Requires gRPC-Go v1.64.0 or later.
const _ = grpc.SupportPackageIsVersion9
const (
X509OverridesService_GetX509IssuerOverride_FullMethodName = "/teleport.workloadidentity.v1.X509OverridesService/GetX509IssuerOverride"
X509OverridesService_ListX509IssuerOverrides_FullMethodName = "/teleport.workloadidentity.v1.X509OverridesService/ListX509IssuerOverrides"
X509OverridesService_CreateX509IssuerOverride_FullMethodName = "/teleport.workloadidentity.v1.X509OverridesService/CreateX509IssuerOverride"
X509OverridesService_UpdateX509IssuerOverride_FullMethodName = "/teleport.workloadidentity.v1.X509OverridesService/UpdateX509IssuerOverride"
X509OverridesService_UpsertX509IssuerOverride_FullMethodName = "/teleport.workloadidentity.v1.X509OverridesService/UpsertX509IssuerOverride"
X509OverridesService_DeleteX509IssuerOverride_FullMethodName = "/teleport.workloadidentity.v1.X509OverridesService/DeleteX509IssuerOverride"
)
// X509OverridesServiceClient is the client API for X509OverridesService service.
//
// For semantics around ctx use and closing/ending streaming RPCs, please refer to https://pkg.go.dev/google.golang.org/grpc/?tab=doc#ClientConn.NewStream.
//
// This service contains RPCs for the configuration resources related to X.509
// issuer overrides, and for operations that require the auth's help or
// involvement in generating overrides.
type X509OverridesServiceClient interface {
// Get a workload_identity_x509_issuer_override by name.
GetX509IssuerOverride(ctx context.Context, in *GetX509IssuerOverrideRequest, opts ...grpc.CallOption) (*X509IssuerOverride, error)
// List a page of workload_identity_x509_issuer_override items.
ListX509IssuerOverrides(ctx context.Context, in *ListX509IssuerOverridesRequest, opts ...grpc.CallOption) (*ListX509IssuerOverridesResponse, error)
// Create a new workload_identity_x509_issuer_override. An ALREADY_EXISTS
// error will be returned if an item with the same name already exists in the
// cluster state storage.
CreateX509IssuerOverride(ctx context.Context, in *CreateX509IssuerOverrideRequest, opts ...grpc.CallOption) (*X509IssuerOverride, error)
// Update a workload_identity_x509_issuer_override; an item with the same name
// must exist and the revision of the new item must match the revision of the
// existing item. A FAILED_PRECONDITION error will be returned otherwise.
UpdateX509IssuerOverride(ctx context.Context, in *UpdateX509IssuerOverrideRequest, opts ...grpc.CallOption) (*X509IssuerOverride, error)
// Create a new workload_identity_x509_issuer_override or overwrite an
// existing one with the same name.
UpsertX509IssuerOverride(ctx context.Context, in *UpsertX509IssuerOverrideRequest, opts ...grpc.CallOption) (*X509IssuerOverride, error)
// Delete an existing workload_identity_x509_issuer_override that has a given
// name. A NOT_FOUND error is returned if the item didn't exist.
DeleteX509IssuerOverride(ctx context.Context, in *DeleteX509IssuerOverrideRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
}
type x509OverridesServiceClient struct {
cc grpc.ClientConnInterface
}
func NewX509OverridesServiceClient(cc grpc.ClientConnInterface) X509OverridesServiceClient {
return &x509OverridesServiceClient{cc}
}
func (c *x509OverridesServiceClient) GetX509IssuerOverride(ctx context.Context, in *GetX509IssuerOverrideRequest, opts ...grpc.CallOption) (*X509IssuerOverride, error) {
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
out := new(X509IssuerOverride)
err := c.cc.Invoke(ctx, X509OverridesService_GetX509IssuerOverride_FullMethodName, in, out, cOpts...)
if err != nil {
return nil, err
}
return out, nil
}
func (c *x509OverridesServiceClient) ListX509IssuerOverrides(ctx context.Context, in *ListX509IssuerOverridesRequest, opts ...grpc.CallOption) (*ListX509IssuerOverridesResponse, error) {
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
out := new(ListX509IssuerOverridesResponse)
err := c.cc.Invoke(ctx, X509OverridesService_ListX509IssuerOverrides_FullMethodName, in, out, cOpts...)
if err != nil {
return nil, err
}
return out, nil
}
func (c *x509OverridesServiceClient) CreateX509IssuerOverride(ctx context.Context, in *CreateX509IssuerOverrideRequest, opts ...grpc.CallOption) (*X509IssuerOverride, error) {
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
out := new(X509IssuerOverride)
err := c.cc.Invoke(ctx, X509OverridesService_CreateX509IssuerOverride_FullMethodName, in, out, cOpts...)
if err != nil {
return nil, err
}
return out, nil
}
func (c *x509OverridesServiceClient) UpdateX509IssuerOverride(ctx context.Context, in *UpdateX509IssuerOverrideRequest, opts ...grpc.CallOption) (*X509IssuerOverride, error) {
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
out := new(X509IssuerOverride)
err := c.cc.Invoke(ctx, X509OverridesService_UpdateX509IssuerOverride_FullMethodName, in, out, cOpts...)
if err != nil {
return nil, err
}
return out, nil
}
func (c *x509OverridesServiceClient) UpsertX509IssuerOverride(ctx context.Context, in *UpsertX509IssuerOverrideRequest, opts ...grpc.CallOption) (*X509IssuerOverride, error) {
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
out := new(X509IssuerOverride)
err := c.cc.Invoke(ctx, X509OverridesService_UpsertX509IssuerOverride_FullMethodName, in, out, cOpts...)
if err != nil {
return nil, err
}
return out, nil
}
func (c *x509OverridesServiceClient) DeleteX509IssuerOverride(ctx context.Context, in *DeleteX509IssuerOverrideRequest, opts ...grpc.CallOption) (*emptypb.Empty, error) {
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
out := new(emptypb.Empty)
err := c.cc.Invoke(ctx, X509OverridesService_DeleteX509IssuerOverride_FullMethodName, in, out, cOpts...)
if err != nil {
return nil, err
}
return out, nil
}
// X509OverridesServiceServer is the server API for X509OverridesService service.
// All implementations must embed UnimplementedX509OverridesServiceServer
// for forward compatibility.
//
// This service contains RPCs for the configuration resources related to X.509
// issuer overrides, and for operations that require the auth's help or
// involvement in generating overrides.
type X509OverridesServiceServer interface {
// Get a workload_identity_x509_issuer_override by name.
GetX509IssuerOverride(context.Context, *GetX509IssuerOverrideRequest) (*X509IssuerOverride, error)
// List a page of workload_identity_x509_issuer_override items.
ListX509IssuerOverrides(context.Context, *ListX509IssuerOverridesRequest) (*ListX509IssuerOverridesResponse, error)
// Create a new workload_identity_x509_issuer_override. An ALREADY_EXISTS
// error will be returned if an item with the same name already exists in the
// cluster state storage.
CreateX509IssuerOverride(context.Context, *CreateX509IssuerOverrideRequest) (*X509IssuerOverride, error)
// Update a workload_identity_x509_issuer_override; an item with the same name
// must exist and the revision of the new item must match the revision of the
// existing item. A FAILED_PRECONDITION error will be returned otherwise.
UpdateX509IssuerOverride(context.Context, *UpdateX509IssuerOverrideRequest) (*X509IssuerOverride, error)
// Create a new workload_identity_x509_issuer_override or overwrite an
// existing one with the same name.
UpsertX509IssuerOverride(context.Context, *UpsertX509IssuerOverrideRequest) (*X509IssuerOverride, error)
// Delete an existing workload_identity_x509_issuer_override that has a given
// name. A NOT_FOUND error is returned if the item didn't exist.
DeleteX509IssuerOverride(context.Context, *DeleteX509IssuerOverrideRequest) (*emptypb.Empty, error)
mustEmbedUnimplementedX509OverridesServiceServer()
}
// UnimplementedX509OverridesServiceServer must be embedded to have
// forward compatible implementations.
//
// NOTE: this should be embedded by value instead of pointer to avoid a nil
// pointer dereference when methods are called.
type UnimplementedX509OverridesServiceServer struct{}
func (UnimplementedX509OverridesServiceServer) GetX509IssuerOverride(context.Context, *GetX509IssuerOverrideRequest) (*X509IssuerOverride, error) {
return nil, status.Errorf(codes.Unimplemented, "method GetX509IssuerOverride not implemented")
}
func (UnimplementedX509OverridesServiceServer) ListX509IssuerOverrides(context.Context, *ListX509IssuerOverridesRequest) (*ListX509IssuerOverridesResponse, error) {
return nil, status.Errorf(codes.Unimplemented, "method ListX509IssuerOverrides not implemented")
}
func (UnimplementedX509OverridesServiceServer) CreateX509IssuerOverride(context.Context, *CreateX509IssuerOverrideRequest) (*X509IssuerOverride, error) {
return nil, status.Errorf(codes.Unimplemented, "method CreateX509IssuerOverride not implemented")
}
func (UnimplementedX509OverridesServiceServer) UpdateX509IssuerOverride(context.Context, *UpdateX509IssuerOverrideRequest) (*X509IssuerOverride, error) {
return nil, status.Errorf(codes.Unimplemented, "method UpdateX509IssuerOverride not implemented")
}
func (UnimplementedX509OverridesServiceServer) UpsertX509IssuerOverride(context.Context, *UpsertX509IssuerOverrideRequest) (*X509IssuerOverride, error) {
return nil, status.Errorf(codes.Unimplemented, "method UpsertX509IssuerOverride not implemented")
}
func (UnimplementedX509OverridesServiceServer) DeleteX509IssuerOverride(context.Context, *DeleteX509IssuerOverrideRequest) (*emptypb.Empty, error) {
return nil, status.Errorf(codes.Unimplemented, "method DeleteX509IssuerOverride not implemented")
}
func (UnimplementedX509OverridesServiceServer) mustEmbedUnimplementedX509OverridesServiceServer() {}
func (UnimplementedX509OverridesServiceServer) testEmbeddedByValue() {}
// UnsafeX509OverridesServiceServer may be embedded to opt out of forward compatibility for this service.
// Use of this interface is not recommended, as added methods to X509OverridesServiceServer will
// result in compilation errors.
type UnsafeX509OverridesServiceServer interface {
mustEmbedUnimplementedX509OverridesServiceServer()
}
func RegisterX509OverridesServiceServer(s grpc.ServiceRegistrar, srv X509OverridesServiceServer) {
// If the following call pancis, it indicates UnimplementedX509OverridesServiceServer was
// embedded by pointer and is nil. This will cause panics if an
// unimplemented method is ever invoked, so we test this at initialization
// time to prevent it from happening at runtime later due to I/O.
if t, ok := srv.(interface{ testEmbeddedByValue() }); ok {
t.testEmbeddedByValue()
}
s.RegisterService(&X509OverridesService_ServiceDesc, srv)
}
func _X509OverridesService_GetX509IssuerOverride_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
in := new(GetX509IssuerOverrideRequest)
if err := dec(in); err != nil {
return nil, err
}
if interceptor == nil {
return srv.(X509OverridesServiceServer).GetX509IssuerOverride(ctx, in)
}
info := &grpc.UnaryServerInfo{
Server: srv,
FullMethod: X509OverridesService_GetX509IssuerOverride_FullMethodName,
}
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
return srv.(X509OverridesServiceServer).GetX509IssuerOverride(ctx, req.(*GetX509IssuerOverrideRequest))
}
return interceptor(ctx, in, info, handler)
}
func _X509OverridesService_ListX509IssuerOverrides_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
in := new(ListX509IssuerOverridesRequest)
if err := dec(in); err != nil {
return nil, err
}
if interceptor == nil {
return srv.(X509OverridesServiceServer).ListX509IssuerOverrides(ctx, in)
}
info := &grpc.UnaryServerInfo{
Server: srv,
FullMethod: X509OverridesService_ListX509IssuerOverrides_FullMethodName,
}
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
return srv.(X509OverridesServiceServer).ListX509IssuerOverrides(ctx, req.(*ListX509IssuerOverridesRequest))
}
return interceptor(ctx, in, info, handler)
}
func _X509OverridesService_CreateX509IssuerOverride_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
in := new(CreateX509IssuerOverrideRequest)
if err := dec(in); err != nil {
return nil, err
}
if interceptor == nil {
return srv.(X509OverridesServiceServer).CreateX509IssuerOverride(ctx, in)
}
info := &grpc.UnaryServerInfo{
Server: srv,
FullMethod: X509OverridesService_CreateX509IssuerOverride_FullMethodName,
}
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
return srv.(X509OverridesServiceServer).CreateX509IssuerOverride(ctx, req.(*CreateX509IssuerOverrideRequest))
}
return interceptor(ctx, in, info, handler)
}
func _X509OverridesService_UpdateX509IssuerOverride_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
in := new(UpdateX509IssuerOverrideRequest)
if err := dec(in); err != nil {
return nil, err
}
if interceptor == nil {
return srv.(X509OverridesServiceServer).UpdateX509IssuerOverride(ctx, in)
}
info := &grpc.UnaryServerInfo{
Server: srv,
FullMethod: X509OverridesService_UpdateX509IssuerOverride_FullMethodName,
}
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
return srv.(X509OverridesServiceServer).UpdateX509IssuerOverride(ctx, req.(*UpdateX509IssuerOverrideRequest))
}
return interceptor(ctx, in, info, handler)
}
func _X509OverridesService_UpsertX509IssuerOverride_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
in := new(UpsertX509IssuerOverrideRequest)
if err := dec(in); err != nil {
return nil, err
}
if interceptor == nil {
return srv.(X509OverridesServiceServer).UpsertX509IssuerOverride(ctx, in)
}
info := &grpc.UnaryServerInfo{
Server: srv,
FullMethod: X509OverridesService_UpsertX509IssuerOverride_FullMethodName,
}
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
return srv.(X509OverridesServiceServer).UpsertX509IssuerOverride(ctx, req.(*UpsertX509IssuerOverrideRequest))
}
return interceptor(ctx, in, info, handler)
}
func _X509OverridesService_DeleteX509IssuerOverride_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
in := new(DeleteX509IssuerOverrideRequest)
if err := dec(in); err != nil {
return nil, err
}
if interceptor == nil {
return srv.(X509OverridesServiceServer).DeleteX509IssuerOverride(ctx, in)
}
info := &grpc.UnaryServerInfo{
Server: srv,
FullMethod: X509OverridesService_DeleteX509IssuerOverride_FullMethodName,
}
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
return srv.(X509OverridesServiceServer).DeleteX509IssuerOverride(ctx, req.(*DeleteX509IssuerOverrideRequest))
}
return interceptor(ctx, in, info, handler)
}
// X509OverridesService_ServiceDesc is the grpc.ServiceDesc for X509OverridesService service.
// It's only intended for direct use with grpc.RegisterService,
// and not to be introspected or modified (even as a copy)
var X509OverridesService_ServiceDesc = grpc.ServiceDesc{
ServiceName: "teleport.workloadidentity.v1.X509OverridesService",
HandlerType: (*X509OverridesServiceServer)(nil),
Methods: []grpc.MethodDesc{
{
MethodName: "GetX509IssuerOverride",
Handler: _X509OverridesService_GetX509IssuerOverride_Handler,
},
{
MethodName: "ListX509IssuerOverrides",
Handler: _X509OverridesService_ListX509IssuerOverrides_Handler,
},
{
MethodName: "CreateX509IssuerOverride",
Handler: _X509OverridesService_CreateX509IssuerOverride_Handler,
},
{
MethodName: "UpdateX509IssuerOverride",
Handler: _X509OverridesService_UpdateX509IssuerOverride_Handler,
},
{
MethodName: "UpsertX509IssuerOverride",
Handler: _X509OverridesService_UpsertX509IssuerOverride_Handler,
},
{
MethodName: "DeleteX509IssuerOverride",
Handler: _X509OverridesService_DeleteX509IssuerOverride_Handler,
},
},
Streams: []grpc.StreamDesc{},
Metadata: "teleport/workloadidentity/v1/x509_overrides_service.proto",
}
@@ -4778,6 +4778,8 @@ message OneOf {
events.HealthCheckConfigCreate HealthCheckConfigCreate = 205;
events.HealthCheckConfigUpdate HealthCheckConfigUpdate = 206;
events.HealthCheckConfigDelete HealthCheckConfigDelete = 207;
WorkloadIdentityX509IssuerOverrideCreate WorkloadIdentityX509IssuerOverrideCreate = 208;
WorkloadIdentityX509IssuerOverrideDelete WorkloadIdentityX509IssuerOverrideDelete = 209;
}
}
@@ -8231,3 +8233,55 @@ message HealthCheckConfigDelete {
(gogoproto.jsontag) = ""
];
}
message WorkloadIdentityX509IssuerOverrideCreate {
Metadata Metadata = 1 [
(gogoproto.nullable) = false,
(gogoproto.embed) = true,
(gogoproto.jsontag) = ""
];
UserMetadata User = 2 [
(gogoproto.nullable) = false,
(gogoproto.embed) = true,
(gogoproto.jsontag) = ""
];
ConnectionMetadata Connection = 3 [
(gogoproto.nullable) = false,
(gogoproto.embed) = true,
(gogoproto.jsontag) = ""
];
ResourceMetadata Resource = 4 [
(gogoproto.nullable) = false,
(gogoproto.embed) = true,
(gogoproto.jsontag) = ""
];
}
message WorkloadIdentityX509IssuerOverrideDelete {
Metadata Metadata = 1 [
(gogoproto.nullable) = false,
(gogoproto.embed) = true,
(gogoproto.jsontag) = ""
];
UserMetadata User = 2 [
(gogoproto.nullable) = false,
(gogoproto.embed) = true,
(gogoproto.jsontag) = ""
];
ConnectionMetadata Connection = 3 [
(gogoproto.nullable) = false,
(gogoproto.embed) = true,
(gogoproto.jsontag) = ""
];
ResourceMetadata Resource = 4 [
(gogoproto.nullable) = false,
(gogoproto.embed) = true,
(gogoproto.jsontag) = ""
];
}
@@ -0,0 +1,39 @@
// Copyright 2025 Gravitational, Inc.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
syntax = "proto3";
package teleport.workloadidentity.v1;
import "teleport/header/v1/metadata.proto";
option go_package = "github.com/gravitational/teleport/api/gen/proto/go/teleport/workloadidentity/v1;workloadidentityv1";
// A configuration resource to override the issuers of SPIFFE X509-SVID
// credentials. This message serves as both the type used in the v1 service and
// as the canonical v1 storage format (in protojson).
message X509IssuerOverride {
// Fixed string, "workload_identity_x509_issuer_override".
string kind = 1;
// Fixed string, "".
string sub_kind = 2;
// Fixed string, "v1".
string version = 3;
teleport.header.v1.Metadata metadata = 4;
X509IssuerOverrideSpec spec = 5;
}
// The spec for X509IssuerOverride.
message X509IssuerOverrideSpec {}
@@ -0,0 +1,90 @@
// Copyright 2025 Gravitational, Inc.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
syntax = "proto3";
package teleport.workloadidentity.v1;
import "google/protobuf/empty.proto";
import "teleport/workloadidentity/v1/x509_overrides.proto";
option go_package = "github.com/gravitational/teleport/api/gen/proto/go/teleport/workloadidentity/v1;workloadidentityv1";
// This service contains RPCs for the configuration resources related to X.509
// issuer overrides, and for operations that require the auth's help or
// involvement in generating overrides.
service X509OverridesService {
// Get a workload_identity_x509_issuer_override by name.
rpc GetX509IssuerOverride(GetX509IssuerOverrideRequest) returns (X509IssuerOverride) {
option idempotency_level = NO_SIDE_EFFECTS;
}
// List a page of workload_identity_x509_issuer_override items.
rpc ListX509IssuerOverrides(ListX509IssuerOverridesRequest) returns (ListX509IssuerOverridesResponse) {
option idempotency_level = NO_SIDE_EFFECTS;
}
// Create a new workload_identity_x509_issuer_override. An ALREADY_EXISTS
// error will be returned if an item with the same name already exists in the
// cluster state storage.
rpc CreateX509IssuerOverride(CreateX509IssuerOverrideRequest) returns (X509IssuerOverride);
// Update a workload_identity_x509_issuer_override; an item with the same name
// must exist and the revision of the new item must match the revision of the
// existing item. A FAILED_PRECONDITION error will be returned otherwise.
rpc UpdateX509IssuerOverride(UpdateX509IssuerOverrideRequest) returns (X509IssuerOverride);
// Create a new workload_identity_x509_issuer_override or overwrite an
// existing one with the same name.
rpc UpsertX509IssuerOverride(UpsertX509IssuerOverrideRequest) returns (X509IssuerOverride) {
option idempotency_level = IDEMPOTENT;
}
// Delete an existing workload_identity_x509_issuer_override that has a given
// name. A NOT_FOUND error is returned if the item didn't exist.
rpc DeleteX509IssuerOverride(DeleteX509IssuerOverrideRequest) returns (google.protobuf.Empty);
}
// Request message for GetX509IssuerOverride.
message GetX509IssuerOverrideRequest {
string name = 1;
}
// Response message for GetX509IssuerOverride.
message ListX509IssuerOverridesRequest {
int32 page_size = 1;
string page_token = 2;
}
// Request message for ListX509IssuerOverrides.
message ListX509IssuerOverridesResponse {
repeated X509IssuerOverride x509_issuer_overrides = 1;
string next_page_token = 2;
}
// Request message for CreateX509IssuerOverride.
message CreateX509IssuerOverrideRequest {
X509IssuerOverride x509_issuer_override = 1;
}
// Request message for UpdateX509IssuerOverride.
message UpdateX509IssuerOverrideRequest {
X509IssuerOverride x509_issuer_override = 1;
}
// Request message for UpsertX509IssuerOverride.
message UpsertX509IssuerOverrideRequest {
X509IssuerOverride x509_issuer_override = 1;
}
// Request message for DeleteX509IssuerOverride.
message DeleteX509IssuerOverrideRequest {
string name = 1;
}
+4
View File
@@ -611,6 +611,10 @@ const (
// resource.
KindWorkloadIdentityX509Revocation = "workload_identity_x509_revocation"
// KindWorkloadIdentityX509IssuerOverride is the kind of
// teleport.workloadidentity.v1.X509IssuerOverride.
KindWorkloadIdentityX509IssuerOverride = "workload_identity_x509_issuer_override"
// KindGitServer represents a Git server that can proxy git commands.
KindGitServer = "git_server"
// SubKindGitHub specifies the GitHub subkind of a Git server.
+10
View File
@@ -2514,3 +2514,13 @@ func (m *HealthCheckConfigUpdate) TrimToMaxSize(int) AuditEvent {
func (m *HealthCheckConfigDelete) TrimToMaxSize(int) AuditEvent {
return m
}
// TrimToMaxSize implements [AuditEvent].
func (m *WorkloadIdentityX509IssuerOverrideCreate) TrimToMaxSize(int) AuditEvent {
return m
}
// TrimToMaxSize implements [AuditEvent].
func (m *WorkloadIdentityX509IssuerOverrideDelete) TrimToMaxSize(int) AuditEvent {
return m
}
+2164 -1361
View File
File diff suppressed because it is too large Load Diff
+8
View File
@@ -855,6 +855,14 @@ func ToOneOf(in AuditEvent) (*OneOf, error) {
out.Event = &OneOf_HealthCheckConfigDelete{
HealthCheckConfigDelete: e,
}
case *WorkloadIdentityX509IssuerOverrideCreate:
out.Event = &OneOf_WorkloadIdentityX509IssuerOverrideCreate{
WorkloadIdentityX509IssuerOverrideCreate: e,
}
case *WorkloadIdentityX509IssuerOverrideDelete:
out.Event = &OneOf_WorkloadIdentityX509IssuerOverrideDelete{
WorkloadIdentityX509IssuerOverrideDelete: e,
}
default:
slog.ErrorContext(context.Background(), "Attempted to convert dynamic event of unknown type into protobuf event.", "event_type", in.GetType())
unknown := &Unknown{}
+8
View File
@@ -411,6 +411,12 @@ func NewServer(cfg *InitConfig, opts ...ServerOption) (*Server, error) {
return nil, trace.Wrap(err, "creating WorkloadIdentityX509Revocation service")
}
}
if cfg.WorkloadIdentityX509Overrides == nil {
cfg.WorkloadIdentityX509Overrides, err = local.NewWorkloadIdentityX509OverridesService(cfg.Backend)
if err != nil {
return nil, trace.Wrap(err, "creating WorkloadIdentityX509Overrides service")
}
}
if cfg.StableUNIXUsers == nil {
cfg.StableUNIXUsers = &local.StableUNIXUsersService{
Backend: cfg.Backend,
@@ -518,6 +524,7 @@ func NewServer(cfg *InitConfig, opts ...ServerOption) (*Server, error) {
WorkloadIdentities: cfg.WorkloadIdentity,
StableUNIXUsersInternal: cfg.StableUNIXUsers,
WorkloadIdentityX509Revocations: cfg.WorkloadIdentityX509Revocations,
WorkloadIdentityX509Overrides: cfg.WorkloadIdentityX509Overrides,
}
as := Server{
@@ -750,6 +757,7 @@ type Services struct {
services.WorkloadIdentities
services.StableUNIXUsersInternal
services.WorkloadIdentityX509Revocations
services.WorkloadIdentityX509Overrides
}
// GetWebSession returns existing web session described by req.
+14
View File
@@ -5334,6 +5334,20 @@ func NewGRPCServer(cfg GRPCServerConfig) (*GRPCServer, error) {
workloadidentityv1pb.RegisterWorkloadIdentityRevocationServiceServer(server, workloadIdentityRevocationService)
go workloadIdentityRevocationService.RunCRLSigner(cfg.AuthServer.CloseContext())
if cfg.PluginRegistry == nil || !cfg.PluginRegistry.IsRegistered("auth.enterprise") {
srv, err := workloadidentityv1.NewX509OverridesService(workloadidentityv1.X509OverridesServiceConfig{
Authorizer: cfg.Authorizer,
Storage: cfg.AuthServer.Services,
Emitter: cfg.Emitter,
ClusterName: clusterName.GetClusterName(),
})
if err != nil {
return nil, trace.Wrap(err, "creating workload identity X509 overrides service")
}
workloadidentityv1pb.RegisterX509OverridesServiceServer(server, srv)
}
dbObjectImportRuleService, err := dbobjectimportrulev1.NewDatabaseObjectImportRuleService(dbobjectimportrulev1.DatabaseObjectImportRuleServiceConfig{
Authorizer: cfg.Authorizer,
Backend: cfg.AuthServer.Services,
+4
View File
@@ -328,6 +328,10 @@ type InitConfig struct {
// WorkloadIdentityX509Revocations.
WorkloadIdentityX509Revocations services.WorkloadIdentityX509Revocations
// WorkloadIdentityX509Overrides handles the storage for workload
// identity-related X.509 certificate overrides.
WorkloadIdentityX509Overrides services.WorkloadIdentityX509Overrides
// StaticHostUsers is a service that manages host users that should be
// created on SSH nodes.
StaticHostUsers services.StaticHostUser
@@ -0,0 +1,176 @@
// Teleport
// Copyright (C) 2025 Gravitational, Inc.
//
// This program is free software: you can redistribute it and/or modify
// it under the terms of the GNU Affero General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU Affero General Public License for more details.
//
// You should have received a copy of the GNU Affero General Public License
// along with this program. If not, see <http://www.gnu.org/licenses/>.
package workloadidentityv1
import (
"context"
"github.com/gravitational/trace"
"google.golang.org/protobuf/types/known/emptypb"
workloadidentityv1pb "github.com/gravitational/teleport/api/gen/proto/go/teleport/workloadidentity/v1"
apitypes "github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/authz"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/services"
)
type X509OverridesServiceConfig struct {
Authorizer authz.Authorizer
Storage services.WorkloadIdentityX509Overrides
Emitter apievents.Emitter
ClusterName string
}
// NewX509OverridesService returns an implementation of
// [workloadidentityv1pb.X509OverridesServiceServer] that only allows reading
// and deleting override resources, suitable for checking and cleaning things up
// after downgrading from a licensed version of Teleport. A matching
// fully-featured implementation can be found in
// e/lib/auth/machineid/workloadidentityv1 .
func NewX509OverridesService(cfg X509OverridesServiceConfig) (*X509OverridesService, error) {
if cfg.Authorizer == nil {
return nil, trace.BadParameter("authorizer is required")
}
if cfg.Storage == nil {
return nil, trace.BadParameter("storage is required")
}
if cfg.Emitter == nil {
return nil, trace.BadParameter("emitter is required")
}
if cfg.ClusterName == "" {
return nil, trace.BadParameter("cluster name is required")
}
return &X509OverridesService{
authorizer: cfg.Authorizer,
storage: cfg.Storage,
emitter: cfg.Emitter,
clusterName: cfg.ClusterName,
}, nil
}
// X509OverridesService implements the non-enterprise version of
// [workloadidentityv1pb.X509OverridesServiceServer], only allowing reading,
// listing and deleting any stored state.
type X509OverridesService struct {
workloadidentityv1pb.UnsafeX509OverridesServiceServer
authorizer authz.Authorizer
storage services.WorkloadIdentityX509Overrides
emitter apievents.Emitter
clusterName string
}
var _ workloadidentityv1pb.X509OverridesServiceServer = (*X509OverridesService)(nil)
func (s *X509OverridesService) authorizeAccessToKind(ctx context.Context, kind string, verb string, additionalVerbs ...string) error {
authzCtx, err := s.authorizer.Authorize(ctx)
if err != nil {
return trace.Wrap(err)
}
return authzCtx.CheckAccessToKind(kind, verb, additionalVerbs...)
}
func (s *X509OverridesService) authorizeAccessToKindAdminReusedMFA(ctx context.Context, kind string, verb string, additionalVerbs ...string) error {
authzCtx, err := s.authorizer.Authorize(ctx)
if err != nil {
return trace.Wrap(err)
}
if err := authzCtx.CheckAccessToKind(kind, verb, additionalVerbs...); err != nil {
return trace.Wrap(err)
}
if err := authzCtx.AuthorizeAdminActionAllowReusedMFA(); err != nil {
return trace.Wrap(err)
}
return nil
}
func (s *X509OverridesService) requireEnterprise() error {
return trace.AccessDenied("SPIFFE X.509 issuer overrides are only available with an enterprise license")
}
// GetX509IssuerOverride implements [workloadidentityv1pb.X509OverridesServiceServer].
func (s *X509OverridesService) GetX509IssuerOverride(ctx context.Context, req *workloadidentityv1pb.GetX509IssuerOverrideRequest) (*workloadidentityv1pb.X509IssuerOverride, error) {
if err := s.authorizeAccessToKind(ctx, apitypes.KindWorkloadIdentityX509IssuerOverride, apitypes.VerbRead); err != nil {
return nil, trace.Wrap(err)
}
return s.storage.GetX509IssuerOverride(ctx, req.GetName())
}
// ListX509IssuerOverrides implements [workloadidentityv1pb.X509OverridesServiceServer].
func (s *X509OverridesService) ListX509IssuerOverrides(ctx context.Context, req *workloadidentityv1pb.ListX509IssuerOverridesRequest) (*workloadidentityv1pb.ListX509IssuerOverridesResponse, error) {
if err := s.authorizeAccessToKind(ctx, apitypes.KindWorkloadIdentityX509IssuerOverride, apitypes.VerbList, apitypes.VerbRead); err != nil {
return nil, trace.Wrap(err)
}
overrides, nextPageToken, err := s.storage.ListX509IssuerOverrides(ctx, int(req.GetPageSize()), req.GetPageToken())
if err != nil {
return nil, trace.Wrap(err)
}
return &workloadidentityv1pb.ListX509IssuerOverridesResponse{
X509IssuerOverrides: overrides,
NextPageToken: nextPageToken,
}, nil
}
// CreateX509IssuerOverride implements [workloadidentityv1pb.X509OverridesServiceServer].
func (s *X509OverridesService) CreateX509IssuerOverride(ctx context.Context, req *workloadidentityv1pb.CreateX509IssuerOverrideRequest) (*workloadidentityv1pb.X509IssuerOverride, error) {
return nil, s.requireEnterprise()
}
// UpdateX509IssuerOverride implements [workloadidentityv1pb.X509OverridesServiceServer].
func (s *X509OverridesService) UpdateX509IssuerOverride(ctx context.Context, req *workloadidentityv1pb.UpdateX509IssuerOverrideRequest) (*workloadidentityv1pb.X509IssuerOverride, error) {
return nil, s.requireEnterprise()
}
// UpsertX509IssuerOverride implements [workloadidentityv1pb.X509OverridesServiceServer].
func (s *X509OverridesService) UpsertX509IssuerOverride(ctx context.Context, req *workloadidentityv1pb.UpsertX509IssuerOverrideRequest) (*workloadidentityv1pb.X509IssuerOverride, error) {
return nil, s.requireEnterprise()
}
// DeleteX509IssuerOverride implements [workloadidentityv1pb.X509OverridesServiceServer].
func (s *X509OverridesService) DeleteX509IssuerOverride(ctx context.Context, req *workloadidentityv1pb.DeleteX509IssuerOverrideRequest) (*emptypb.Empty, error) {
if err := s.authorizeAccessToKindAdminReusedMFA(ctx, apitypes.KindWorkloadIdentityX509IssuerOverride, apitypes.VerbDelete); err != nil {
return nil, trace.Wrap(err)
}
if err := s.storage.DeleteX509IssuerOverride(ctx, req.GetName()); err != nil {
return nil, trace.Wrap(err)
}
s.emitter.EmitAuditEvent(ctx, &apievents.WorkloadIdentityX509IssuerOverrideDelete{
Metadata: apievents.Metadata{
Type: events.WorkloadIdentityX509IssuerOverrideDeleteEvent,
Code: events.WorkloadIdentityX509IssuerOverrideDeleteCode,
},
UserMetadata: authz.ClientUserMetadata(ctx),
ConnectionMetadata: authz.ConnectionMetadata(ctx),
ResourceMetadata: apievents.ResourceMetadata{
Name: req.GetName(),
},
})
return &emptypb.Empty{}, nil
}
+6
View File
@@ -868,6 +868,12 @@ const (
// WorkloadIdentityX509RevocationDeleteEvent is emitted when a
// WorkloadIdentityX509Revocation resource is deleted.
WorkloadIdentityX509RevocationDeleteEvent = "workload_identity_x509_revocation.delete"
// WorkloadIdentityX509IssuerOverrideCreateEvent is emitted when a
// workload_identity_x509_issuer_override is written.
WorkloadIdentityX509IssuerOverrideCreateEvent = "workload_identity_x509_issuer_override.create"
// WorkloadIdentityX509IssuerOverrideDeleteEvent is emitted when a
// workload_identity_x509_issuer_override is deleted.
WorkloadIdentityX509IssuerOverrideDeleteEvent = "workload_identity_x509_issuer_override.delete"
// GitCommandEvent is emitted when a Git command is executed.
GitCommandEvent = "git.command"
+6
View File
@@ -696,6 +696,12 @@ const (
// WorkloadIdentityX509RevocationDeleteCode is the
// WorkloadIdentityX509Revocation delete event code.
WorkloadIdentityX509RevocationDeleteCode = "WID006I"
// WorkloadIdentityX509IssuerOverrideCreateCode is the code for the
// workload_identity_x509_issuer_override.create event.
WorkloadIdentityX509IssuerOverrideCreateCode = "WID007I"
// WorkloadIdentityX509IssuerOverrideDeleteCode is the code for the
// workload_identity_x509_issuer_override.delete event.
WorkloadIdentityX509IssuerOverrideDeleteCode = "WID008I"
// HealthCheckConfigCreateCode is the health check config create event code.
HealthCheckConfigCreateCode = "THCC001I"
+5
View File
@@ -508,6 +508,11 @@ func FromEventFields(fields EventFields) (events.AuditEvent, error) {
case HealthCheckConfigDeleteEvent:
e = &events.HealthCheckConfigDelete{}
case WorkloadIdentityX509IssuerOverrideCreateEvent:
e = &events.WorkloadIdentityX509IssuerOverrideCreate{}
case WorkloadIdentityX509IssuerOverrideDeleteEvent:
e = &events.WorkloadIdentityX509IssuerOverrideDelete{}
default:
slog.ErrorContext(context.Background(), "Attempted to convert dynamic event of unknown type into protobuf event.", "event_type", eventType)
unknown := &events.Unknown{}
+127 -127
View File
@@ -159,105 +159,107 @@ var eventsMap = map[string]apievents.AuditEvent{
AccessRequestDeleteEvent: &apievents.AccessRequestDelete{},
CertificateCreateEvent: &apievents.CertificateCreate{},
RenewableCertificateGenerationMismatchEvent: &apievents.RenewableCertificateGenerationMismatch{},
SFTPEvent: &apievents.SFTP{},
UpgradeWindowStartUpdateEvent: &apievents.UpgradeWindowStartUpdate{},
SessionRecordingAccessEvent: &apievents.SessionRecordingAccess{},
SSMRunEvent: &apievents.SSMRun{},
KubernetesClusterCreateEvent: &apievents.KubernetesClusterCreate{},
KubernetesClusterUpdateEvent: &apievents.KubernetesClusterUpdate{},
KubernetesClusterDeleteEvent: &apievents.KubernetesClusterDelete{},
DesktopSharedDirectoryStartEvent: &apievents.DesktopSharedDirectoryStart{},
DesktopSharedDirectoryReadEvent: &apievents.DesktopSharedDirectoryRead{},
DesktopSharedDirectoryWriteEvent: &apievents.DesktopSharedDirectoryWrite{},
BotJoinEvent: &apievents.BotJoin{},
InstanceJoinEvent: &apievents.InstanceJoin{},
BotCreateEvent: &apievents.BotCreate{},
BotUpdateEvent: &apievents.BotUpdate{},
BotDeleteEvent: &apievents.BotDelete{},
LoginRuleCreateEvent: &apievents.LoginRuleCreate{},
LoginRuleDeleteEvent: &apievents.LoginRuleDelete{},
SAMLIdPAuthAttemptEvent: &apievents.SAMLIdPAuthAttempt{},
SAMLIdPServiceProviderCreateEvent: &apievents.SAMLIdPServiceProviderCreate{},
SAMLIdPServiceProviderUpdateEvent: &apievents.SAMLIdPServiceProviderUpdate{},
SAMLIdPServiceProviderDeleteEvent: &apievents.SAMLIdPServiceProviderDelete{},
SAMLIdPServiceProviderDeleteAllEvent: &apievents.SAMLIdPServiceProviderDeleteAll{},
OktaGroupsUpdateEvent: &apievents.OktaResourcesUpdate{},
OktaApplicationsUpdateEvent: &apievents.OktaResourcesUpdate{},
OktaSyncFailureEvent: &apievents.OktaSyncFailure{},
OktaAssignmentProcessEvent: &apievents.OktaAssignmentResult{},
OktaAssignmentCleanupEvent: &apievents.OktaAssignmentResult{},
OktaUserSyncEvent: &apievents.OktaUserSync{},
OktaAccessListSyncEvent: &apievents.OktaAccessListSync{},
AccessGraphAccessPathChangedEvent: &apievents.AccessPathChanged{},
AccessListCreateEvent: &apievents.AccessListCreate{},
AccessListUpdateEvent: &apievents.AccessListUpdate{},
AccessListDeleteEvent: &apievents.AccessListDelete{},
AccessListReviewEvent: &apievents.AccessListReview{},
AccessListMemberCreateEvent: &apievents.AccessListMemberCreate{},
AccessListMemberUpdateEvent: &apievents.AccessListMemberUpdate{},
AccessListMemberDeleteEvent: &apievents.AccessListMemberDelete{},
AccessListMemberDeleteAllForAccessListEvent: &apievents.AccessListMemberDeleteAllForAccessList{},
UserLoginAccessListInvalidEvent: &apievents.UserLoginAccessListInvalid{},
SecReportsAuditQueryRunEvent: &apievents.AuditQueryRun{},
SecReportsReportRunEvent: &apievents.SecurityReportRun{},
ExternalAuditStorageEnableEvent: &apievents.ExternalAuditStorageEnable{},
ExternalAuditStorageDisableEvent: &apievents.ExternalAuditStorageDisable{},
CreateMFAAuthChallengeEvent: &apievents.CreateMFAAuthChallenge{},
ValidateMFAAuthResponseEvent: &apievents.ValidateMFAAuthResponse{},
SPIFFESVIDIssuedEvent: &apievents.SPIFFESVIDIssued{},
AuthPreferenceUpdateEvent: &apievents.AuthPreferenceUpdate{},
ClusterNetworkingConfigUpdateEvent: &apievents.ClusterNetworkingConfigUpdate{},
SessionRecordingConfigUpdateEvent: &apievents.SessionRecordingConfigUpdate{},
AccessGraphSettingsUpdateEvent: &apievents.AccessGraphSettingsUpdate{},
DatabaseSessionSpannerRPCEvent: &apievents.SpannerRPC{},
UnknownEvent: &apievents.Unknown{},
DatabaseSessionCassandraBatchEvent: &apievents.CassandraBatch{},
DatabaseSessionCassandraRegisterEvent: &apievents.CassandraRegister{},
DatabaseSessionCassandraPrepareEvent: &apievents.CassandraPrepare{},
DatabaseSessionCassandraExecuteEvent: &apievents.CassandraExecute{},
DiscoveryConfigCreateEvent: &apievents.DiscoveryConfigCreate{},
DiscoveryConfigUpdateEvent: &apievents.DiscoveryConfigUpdate{},
DiscoveryConfigDeleteEvent: &apievents.DiscoveryConfigDelete{},
DiscoveryConfigDeleteAllEvent: &apievents.DiscoveryConfigDeleteAll{},
IntegrationCreateEvent: &apievents.IntegrationCreate{},
IntegrationUpdateEvent: &apievents.IntegrationUpdate{},
IntegrationDeleteEvent: &apievents.IntegrationDelete{},
SPIFFEFederationCreateEvent: &apievents.SPIFFEFederationCreate{},
SPIFFEFederationDeleteEvent: &apievents.SPIFFEFederationDelete{},
PluginCreateEvent: &apievents.PluginCreate{},
PluginUpdateEvent: &apievents.PluginUpdate{},
PluginDeleteEvent: &apievents.PluginDelete{},
StaticHostUserCreateEvent: &apievents.StaticHostUserCreate{},
StaticHostUserUpdateEvent: &apievents.StaticHostUserUpdate{},
StaticHostUserDeleteEvent: &apievents.StaticHostUserDelete{},
CrownJewelCreateEvent: &apievents.CrownJewelCreate{},
CrownJewelUpdateEvent: &apievents.CrownJewelUpdate{},
CrownJewelDeleteEvent: &apievents.CrownJewelDelete{},
UserTaskCreateEvent: &apievents.UserTaskCreate{},
UserTaskUpdateEvent: &apievents.UserTaskUpdate{},
UserTaskDeleteEvent: &apievents.UserTaskDelete{},
SFTPSummaryEvent: &apievents.SFTPSummary{},
AutoUpdateConfigCreateEvent: &apievents.AutoUpdateConfigCreate{},
AutoUpdateConfigUpdateEvent: &apievents.AutoUpdateConfigUpdate{},
AutoUpdateConfigDeleteEvent: &apievents.AutoUpdateConfigDelete{},
AutoUpdateVersionCreateEvent: &apievents.AutoUpdateVersionCreate{},
AutoUpdateVersionUpdateEvent: &apievents.AutoUpdateVersionUpdate{},
AutoUpdateVersionDeleteEvent: &apievents.AutoUpdateVersionDelete{},
ContactCreateEvent: &apievents.ContactCreate{},
ContactDeleteEvent: &apievents.ContactDelete{},
WorkloadIdentityCreateEvent: &apievents.WorkloadIdentityCreate{},
WorkloadIdentityUpdateEvent: &apievents.WorkloadIdentityUpdate{},
WorkloadIdentityDeleteEvent: &apievents.WorkloadIdentityDelete{},
AccessRequestExpireEvent: &apievents.AccessRequestExpire{},
StableUNIXUserCreateEvent: &apievents.StableUNIXUserCreate{},
WorkloadIdentityX509RevocationCreateEvent: &apievents.WorkloadIdentityX509RevocationCreate{},
WorkloadIdentityX509RevocationDeleteEvent: &apievents.WorkloadIdentityX509RevocationDelete{},
WorkloadIdentityX509RevocationUpdateEvent: &apievents.WorkloadIdentityX509RevocationUpdate{},
AWSICResourceSyncSuccessEvent: &apievents.AWSICResourceSync{},
AWSICResourceSyncFailureEvent: &apievents.AWSICResourceSync{},
HealthCheckConfigCreateEvent: &apievents.HealthCheckConfigCreate{},
HealthCheckConfigUpdateEvent: &apievents.HealthCheckConfigUpdate{},
HealthCheckConfigDeleteEvent: &apievents.HealthCheckConfigDelete{},
SFTPEvent: &apievents.SFTP{},
UpgradeWindowStartUpdateEvent: &apievents.UpgradeWindowStartUpdate{},
SessionRecordingAccessEvent: &apievents.SessionRecordingAccess{},
SSMRunEvent: &apievents.SSMRun{},
KubernetesClusterCreateEvent: &apievents.KubernetesClusterCreate{},
KubernetesClusterUpdateEvent: &apievents.KubernetesClusterUpdate{},
KubernetesClusterDeleteEvent: &apievents.KubernetesClusterDelete{},
DesktopSharedDirectoryStartEvent: &apievents.DesktopSharedDirectoryStart{},
DesktopSharedDirectoryReadEvent: &apievents.DesktopSharedDirectoryRead{},
DesktopSharedDirectoryWriteEvent: &apievents.DesktopSharedDirectoryWrite{},
BotJoinEvent: &apievents.BotJoin{},
InstanceJoinEvent: &apievents.InstanceJoin{},
BotCreateEvent: &apievents.BotCreate{},
BotUpdateEvent: &apievents.BotUpdate{},
BotDeleteEvent: &apievents.BotDelete{},
LoginRuleCreateEvent: &apievents.LoginRuleCreate{},
LoginRuleDeleteEvent: &apievents.LoginRuleDelete{},
SAMLIdPAuthAttemptEvent: &apievents.SAMLIdPAuthAttempt{},
SAMLIdPServiceProviderCreateEvent: &apievents.SAMLIdPServiceProviderCreate{},
SAMLIdPServiceProviderUpdateEvent: &apievents.SAMLIdPServiceProviderUpdate{},
SAMLIdPServiceProviderDeleteEvent: &apievents.SAMLIdPServiceProviderDelete{},
SAMLIdPServiceProviderDeleteAllEvent: &apievents.SAMLIdPServiceProviderDeleteAll{},
OktaGroupsUpdateEvent: &apievents.OktaResourcesUpdate{},
OktaApplicationsUpdateEvent: &apievents.OktaResourcesUpdate{},
OktaSyncFailureEvent: &apievents.OktaSyncFailure{},
OktaAssignmentProcessEvent: &apievents.OktaAssignmentResult{},
OktaAssignmentCleanupEvent: &apievents.OktaAssignmentResult{},
OktaUserSyncEvent: &apievents.OktaUserSync{},
OktaAccessListSyncEvent: &apievents.OktaAccessListSync{},
AccessGraphAccessPathChangedEvent: &apievents.AccessPathChanged{},
AccessListCreateEvent: &apievents.AccessListCreate{},
AccessListUpdateEvent: &apievents.AccessListUpdate{},
AccessListDeleteEvent: &apievents.AccessListDelete{},
AccessListReviewEvent: &apievents.AccessListReview{},
AccessListMemberCreateEvent: &apievents.AccessListMemberCreate{},
AccessListMemberUpdateEvent: &apievents.AccessListMemberUpdate{},
AccessListMemberDeleteEvent: &apievents.AccessListMemberDelete{},
AccessListMemberDeleteAllForAccessListEvent: &apievents.AccessListMemberDeleteAllForAccessList{},
UserLoginAccessListInvalidEvent: &apievents.UserLoginAccessListInvalid{},
SecReportsAuditQueryRunEvent: &apievents.AuditQueryRun{},
SecReportsReportRunEvent: &apievents.SecurityReportRun{},
ExternalAuditStorageEnableEvent: &apievents.ExternalAuditStorageEnable{},
ExternalAuditStorageDisableEvent: &apievents.ExternalAuditStorageDisable{},
CreateMFAAuthChallengeEvent: &apievents.CreateMFAAuthChallenge{},
ValidateMFAAuthResponseEvent: &apievents.ValidateMFAAuthResponse{},
SPIFFESVIDIssuedEvent: &apievents.SPIFFESVIDIssued{},
AuthPreferenceUpdateEvent: &apievents.AuthPreferenceUpdate{},
ClusterNetworkingConfigUpdateEvent: &apievents.ClusterNetworkingConfigUpdate{},
SessionRecordingConfigUpdateEvent: &apievents.SessionRecordingConfigUpdate{},
AccessGraphSettingsUpdateEvent: &apievents.AccessGraphSettingsUpdate{},
DatabaseSessionSpannerRPCEvent: &apievents.SpannerRPC{},
UnknownEvent: &apievents.Unknown{},
DatabaseSessionCassandraBatchEvent: &apievents.CassandraBatch{},
DatabaseSessionCassandraRegisterEvent: &apievents.CassandraRegister{},
DatabaseSessionCassandraPrepareEvent: &apievents.CassandraPrepare{},
DatabaseSessionCassandraExecuteEvent: &apievents.CassandraExecute{},
DiscoveryConfigCreateEvent: &apievents.DiscoveryConfigCreate{},
DiscoveryConfigUpdateEvent: &apievents.DiscoveryConfigUpdate{},
DiscoveryConfigDeleteEvent: &apievents.DiscoveryConfigDelete{},
DiscoveryConfigDeleteAllEvent: &apievents.DiscoveryConfigDeleteAll{},
IntegrationCreateEvent: &apievents.IntegrationCreate{},
IntegrationUpdateEvent: &apievents.IntegrationUpdate{},
IntegrationDeleteEvent: &apievents.IntegrationDelete{},
SPIFFEFederationCreateEvent: &apievents.SPIFFEFederationCreate{},
SPIFFEFederationDeleteEvent: &apievents.SPIFFEFederationDelete{},
PluginCreateEvent: &apievents.PluginCreate{},
PluginUpdateEvent: &apievents.PluginUpdate{},
PluginDeleteEvent: &apievents.PluginDelete{},
StaticHostUserCreateEvent: &apievents.StaticHostUserCreate{},
StaticHostUserUpdateEvent: &apievents.StaticHostUserUpdate{},
StaticHostUserDeleteEvent: &apievents.StaticHostUserDelete{},
CrownJewelCreateEvent: &apievents.CrownJewelCreate{},
CrownJewelUpdateEvent: &apievents.CrownJewelUpdate{},
CrownJewelDeleteEvent: &apievents.CrownJewelDelete{},
UserTaskCreateEvent: &apievents.UserTaskCreate{},
UserTaskUpdateEvent: &apievents.UserTaskUpdate{},
UserTaskDeleteEvent: &apievents.UserTaskDelete{},
SFTPSummaryEvent: &apievents.SFTPSummary{},
AutoUpdateConfigCreateEvent: &apievents.AutoUpdateConfigCreate{},
AutoUpdateConfigUpdateEvent: &apievents.AutoUpdateConfigUpdate{},
AutoUpdateConfigDeleteEvent: &apievents.AutoUpdateConfigDelete{},
AutoUpdateVersionCreateEvent: &apievents.AutoUpdateVersionCreate{},
AutoUpdateVersionUpdateEvent: &apievents.AutoUpdateVersionUpdate{},
AutoUpdateVersionDeleteEvent: &apievents.AutoUpdateVersionDelete{},
ContactCreateEvent: &apievents.ContactCreate{},
ContactDeleteEvent: &apievents.ContactDelete{},
WorkloadIdentityCreateEvent: &apievents.WorkloadIdentityCreate{},
WorkloadIdentityUpdateEvent: &apievents.WorkloadIdentityUpdate{},
WorkloadIdentityDeleteEvent: &apievents.WorkloadIdentityDelete{},
AccessRequestExpireEvent: &apievents.AccessRequestExpire{},
StableUNIXUserCreateEvent: &apievents.StableUNIXUserCreate{},
WorkloadIdentityX509RevocationCreateEvent: &apievents.WorkloadIdentityX509RevocationCreate{},
WorkloadIdentityX509RevocationDeleteEvent: &apievents.WorkloadIdentityX509RevocationDelete{},
WorkloadIdentityX509RevocationUpdateEvent: &apievents.WorkloadIdentityX509RevocationUpdate{},
WorkloadIdentityX509IssuerOverrideCreateEvent: &apievents.WorkloadIdentityX509IssuerOverrideCreate{},
WorkloadIdentityX509IssuerOverrideDeleteEvent: &apievents.WorkloadIdentityX509IssuerOverrideDelete{},
AWSICResourceSyncSuccessEvent: &apievents.AWSICResourceSync{},
AWSICResourceSyncFailureEvent: &apievents.AWSICResourceSync{},
HealthCheckConfigCreateEvent: &apievents.HealthCheckConfigCreate{},
HealthCheckConfigUpdateEvent: &apievents.HealthCheckConfigUpdate{},
HealthCheckConfigDeleteEvent: &apievents.HealthCheckConfigDelete{},
}
// TestJSON tests JSON marshal events
@@ -277,7 +279,7 @@ func TestJSON(t *testing.T) {
Type: SessionStartEvent,
ID: "36cee9e9-9a80-4c32-9163-3d9241cdac7a",
Code: SessionStartCode,
Time: time.Date(2020, 03, 30, 15, 58, 54, 561*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o3, 30, 15, 58, 54, 561*int(time.Millisecond), time.UTC),
ClusterName: "testcluster",
},
ServerMetadata: apievents.ServerMetadata{
@@ -313,7 +315,7 @@ func TestJSON(t *testing.T) {
Type: ResizeEvent,
ID: "c34e512f-e6cb-44f1-ab94-4cea09002d29",
Code: TerminalResizeCode,
Time: time.Date(2020, 03, 30, 15, 58, 54, 564*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o3, 30, 15, 58, 54, 564*int(time.Millisecond), time.UTC),
ClusterName: "testcluster",
},
ServerMetadata: apievents.ServerMetadata{
@@ -339,7 +341,7 @@ func TestJSON(t *testing.T) {
Type: SessionEndEvent,
ID: "da455e0f-c27d-459f-a218-4e83b3db9426",
Code: SessionEndCode,
Time: time.Date(2020, 03, 30, 15, 58, 58, 999*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o3, 30, 15, 58, 58, 999*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
ServerMetadata: apievents.ServerMetadata{
@@ -355,8 +357,8 @@ func TestJSON(t *testing.T) {
EnhancedRecording: true,
Interactive: true,
Participants: []string{"alice@example.com"},
StartTime: time.Date(2020, 03, 30, 15, 58, 54, 561*int(time.Millisecond), time.UTC),
EndTime: time.Date(2020, 03, 30, 15, 58, 58, 999*int(time.Millisecond), time.UTC),
StartTime: time.Date(2020, 0o3, 30, 15, 58, 54, 561*int(time.Millisecond), time.UTC),
EndTime: time.Date(2020, 0o3, 30, 15, 58, 58, 999*int(time.Millisecond), time.UTC),
},
},
{
@@ -366,7 +368,7 @@ func TestJSON(t *testing.T) {
Metadata: apievents.Metadata{
Index: 11,
Type: SessionPrintEvent,
Time: time.Date(2020, 03, 30, 15, 58, 56, 959*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o3, 30, 15, 58, 56, 959*int(time.Millisecond), time.UTC),
ClusterName: "test",
},
ChunkIndex: 9,
@@ -383,7 +385,7 @@ func TestJSON(t *testing.T) {
Index: 4,
ID: "4f725f11-e87a-452f-96ec-ef93e9e6a260",
Type: SessionCommandEvent,
Time: time.Date(2020, 03, 30, 15, 58, 54, 650*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o3, 30, 15, 58, 54, 650*int(time.Millisecond), time.UTC),
Code: SessionCommandCode,
ClusterName: "test",
},
@@ -418,7 +420,7 @@ func TestJSON(t *testing.T) {
Index: 0,
ID: "729498e0-c28b-438f-baa7-663a74418449",
Type: SessionNetworkEvent,
Time: time.Date(2020, 04, 07, 18, 45, 16, 602*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o4, 0o7, 18, 45, 16, 602*int(time.Millisecond), time.UTC),
Code: SessionNetworkCode,
ClusterName: "example",
},
@@ -455,7 +457,7 @@ func TestJSON(t *testing.T) {
Index: 175,
ID: "ab8467af-6d85-46ce-bb5c-bdfba8acad3f",
Type: SessionDiskEvent,
Time: time.Date(2020, 04, 07, 19, 56, 38, 545*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o4, 0o7, 19, 56, 38, 545*int(time.Millisecond), time.UTC),
Code: SessionDiskCode,
ClusterName: "example2",
},
@@ -488,7 +490,7 @@ func TestJSON(t *testing.T) {
Metadata: apievents.Metadata{
ID: "019432f1-3021-4860-af41-d9bd1668c3ea",
Type: UserLoginEvent,
Time: time.Date(2020, 04, 07, 18, 45, 07, 0*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o4, 0o7, 18, 45, 0o7, 0*int(time.Millisecond), time.UTC),
Code: UserSSOLoginCode,
ClusterName: "testcluster",
},
@@ -530,7 +532,7 @@ func TestJSON(t *testing.T) {
Index: 2147483646,
ID: "cb404873-cd7c-4036-854b-42e0f5fd5f2c",
Type: SessionDataEvent,
Time: time.Date(2020, 04, 07, 19, 56, 39, 0*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o4, 0o7, 19, 56, 39, 0*int(time.Millisecond), time.UTC),
Code: SessionDataCode,
ClusterName: "test",
},
@@ -560,7 +562,7 @@ func TestJSON(t *testing.T) {
Index: 39,
ID: "d7c7489f-6559-42ad-9963-8543e518a058",
Type: SessionLeaveEvent,
Time: time.Date(2020, 04, 07, 19, 56, 38, 556*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o4, 0o7, 19, 56, 38, 556*int(time.Millisecond), time.UTC),
Code: SessionLeaveCode,
ClusterName: "example",
},
@@ -604,7 +606,7 @@ func TestJSON(t *testing.T) {
Metadata: apievents.Metadata{
ID: "7efc5025-a712-47de-8086-7d935c110188",
Type: PortForwardEvent,
Time: time.Date(2020, 4, 15, 18, 06, 56, 397*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 4, 15, 18, 0o6, 56, 397*int(time.Millisecond), time.UTC),
Code: PortForwardCode,
ClusterName: "test",
},
@@ -704,7 +706,7 @@ func TestJSON(t *testing.T) {
Type: SessionJoinEvent,
ID: "cd03665f-3ce1-4c22-809d-4be9512c36e2",
Code: SessionJoinCode,
Time: time.Date(2020, 04, 23, 18, 22, 35, 350*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o4, 23, 18, 22, 35, 350*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
ServerMetadata: apievents.ServerMetadata{
@@ -733,7 +735,7 @@ func TestJSON(t *testing.T) {
ID: "cd06365f-3cef-4b21-809a-4af9502c11a1",
Type: WindowsDesktopSessionStartEvent,
Code: DesktopSessionStartCode,
Time: time.Date(2020, 04, 23, 18, 22, 35, 350*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o4, 23, 18, 22, 35, 350*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -771,7 +773,7 @@ func TestJSON(t *testing.T) {
ID: "cd06365f-3cef-4b21-809a-4af9502c11a1",
Type: WindowsDesktopSessionEndEvent,
Code: DesktopSessionEndCode,
Time: time.Date(2020, 04, 23, 18, 22, 35, 350*int(time.Millisecond), time.UTC),
Time: time.Date(2020, 0o4, 23, 18, 22, 35, 350*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -790,8 +792,8 @@ func TestJSON(t *testing.T) {
WindowsUser: "Administrator",
DesktopLabels: map[string]string{"env": "production"},
Participants: []string{"foo"},
StartTime: time.Date(2020, 04, 23, 18, 22, 35, 350*int(time.Millisecond), time.UTC),
EndTime: time.Date(2020, 04, 23, 18, 26, 35, 350*int(time.Millisecond), time.UTC),
StartTime: time.Date(2020, 0o4, 23, 18, 22, 35, 350*int(time.Millisecond), time.UTC),
EndTime: time.Date(2020, 0o4, 23, 18, 26, 35, 350*int(time.Millisecond), time.UTC),
},
},
{
@@ -803,7 +805,7 @@ func TestJSON(t *testing.T) {
ID: "test-id",
Type: DatabaseSessionMySQLStatementPrepareEvent,
Code: MySQLStatementPrepareCode,
Time: time.Date(2022, 02, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
Time: time.Date(2022, 0o2, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -831,7 +833,7 @@ func TestJSON(t *testing.T) {
ID: "test-id",
Type: DatabaseSessionMySQLStatementExecuteEvent,
Code: MySQLStatementExecuteCode,
Time: time.Date(2022, 02, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
Time: time.Date(2022, 0o2, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -859,7 +861,7 @@ func TestJSON(t *testing.T) {
ID: "test-id",
Type: DatabaseSessionMySQLStatementSendLongDataEvent,
Code: MySQLStatementSendLongDataCode,
Time: time.Date(2022, 02, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
Time: time.Date(2022, 0o2, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -889,7 +891,7 @@ func TestJSON(t *testing.T) {
ID: "test-id",
Type: DatabaseSessionMySQLStatementCloseEvent,
Code: MySQLStatementCloseCode,
Time: time.Date(2022, 02, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
Time: time.Date(2022, 0o2, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -917,7 +919,7 @@ func TestJSON(t *testing.T) {
ID: "test-id",
Type: DatabaseSessionMySQLStatementResetEvent,
Code: MySQLStatementResetCode,
Time: time.Date(2022, 02, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
Time: time.Date(2022, 0o2, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -945,7 +947,7 @@ func TestJSON(t *testing.T) {
ID: "test-id",
Type: DatabaseSessionMySQLStatementFetchEvent,
Code: MySQLStatementFetchCode,
Time: time.Date(2022, 02, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
Time: time.Date(2022, 0o2, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -974,7 +976,7 @@ func TestJSON(t *testing.T) {
ID: "test-id",
Type: DatabaseSessionMySQLStatementBulkExecuteEvent,
Code: MySQLStatementBulkExecuteCode,
Time: time.Date(2022, 02, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
Time: time.Date(2022, 0o2, 22, 22, 22, 22, 222*int(time.Millisecond), time.UTC),
ClusterName: "test-cluster",
},
UserMetadata: apievents.UserMetadata{
@@ -1127,9 +1129,7 @@ func setProtoFields(msg proto.Message) {
const metadataString = "some metadata"
var (
eventString = strings.Repeat("umai", 170)
)
var eventString = strings.Repeat("umai", 170)
func getDefaultValue(m protoreflect.Message, fd protoreflect.FieldDescriptor) protoreflect.Value {
strVal := metadataString
@@ -0,0 +1,89 @@
// Teleport
// Copyright (C) 2025 Gravitational, Inc.
//
// This program is free software: you can redistribute it and/or modify
// it under the terms of the GNU Affero General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU Affero General Public License for more details.
//
// You should have received a copy of the GNU Affero General Public License
// along with this program. If not, see <http://www.gnu.org/licenses/>.
package local
import (
"context"
"github.com/gravitational/trace"
workloadidentityv1pb "github.com/gravitational/teleport/api/gen/proto/go/teleport/workloadidentity/v1"
apitypes "github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/services/local/generic"
)
const workloadIdentityX509IssuerOverridePrefix = "workload_identity_x509_issuer_override"
func NewWorkloadIdentityX509OverridesService(b backend.Backend) (*WorkloadIdentityX509OverridesService, error) {
// issuer overrides can be a bit bulky in terms of size, so we deviate from
// the default of 1000
const pageLimit = 100
issuer, err := generic.NewServiceWrapper(generic.ServiceConfig[*workloadidentityv1pb.X509IssuerOverride]{
Backend: b,
PageLimit: pageLimit,
ResourceKind: apitypes.KindWorkloadIdentityX509IssuerOverride,
BackendPrefix: backend.NewKey(workloadIdentityX509IssuerOverridePrefix),
MarshalFunc: services.MarshalProtoResource[*workloadidentityv1pb.X509IssuerOverride],
UnmarshalFunc: services.UnmarshalProtoResource[*workloadidentityv1pb.X509IssuerOverride],
})
if err != nil {
return nil, trace.Wrap(err)
}
return &WorkloadIdentityX509OverridesService{
issuer: issuer,
}, nil
}
type WorkloadIdentityX509OverridesService struct {
issuer *generic.ServiceWrapper[*workloadidentityv1pb.X509IssuerOverride]
}
var _ services.WorkloadIdentityX509Overrides = (*WorkloadIdentityX509OverridesService)(nil)
// GetX509IssuerOverride implements [services.WorkloadIdentityX509Overrides].
func (s *WorkloadIdentityX509OverridesService) GetX509IssuerOverride(ctx context.Context, name string) (*workloadidentityv1pb.X509IssuerOverride, error) {
return s.issuer.GetResource(ctx, name)
}
// ListX509IssuerOverrides implements [services.WorkloadIdentityX509Overrides].
func (s *WorkloadIdentityX509OverridesService) ListX509IssuerOverrides(ctx context.Context, pageSize int, pageToken string) (_ []*workloadidentityv1pb.X509IssuerOverride, nextPageToken string, _ error) {
return s.issuer.ListResources(ctx, pageSize, pageToken)
}
// CreateX509IssuerOverride implements [services.WorkloadIdentityX509Overrides].
func (s *WorkloadIdentityX509OverridesService) CreateX509IssuerOverride(ctx context.Context, resource *workloadidentityv1pb.X509IssuerOverride) (*workloadidentityv1pb.X509IssuerOverride, error) {
return s.issuer.CreateResource(ctx, resource)
}
// UpdateX509IssuerOverride implements [services.WorkloadIdentityX509Overrides].
func (s *WorkloadIdentityX509OverridesService) UpdateX509IssuerOverride(ctx context.Context, resource *workloadidentityv1pb.X509IssuerOverride) (*workloadidentityv1pb.X509IssuerOverride, error) {
return s.issuer.ConditionalUpdateResource(ctx, resource)
}
// UpsertX509IssuerOverride implements [services.WorkloadIdentityX509Overrides].
func (s *WorkloadIdentityX509OverridesService) UpsertX509IssuerOverride(ctx context.Context, resource *workloadidentityv1pb.X509IssuerOverride) (*workloadidentityv1pb.X509IssuerOverride, error) {
return s.issuer.UpsertResource(ctx, resource)
}
// DeleteX509IssuerOverride implements [services.WorkloadIdentityX509Overrides].
func (s *WorkloadIdentityX509OverridesService) DeleteX509IssuerOverride(ctx context.Context, name string) error {
return s.issuer.DeleteResource(ctx, name)
}
+2
View File
@@ -277,6 +277,8 @@ func ParseShortcut(in string) (string, error) {
return types.KindGitServer, nil
case types.KindWorkloadIdentityX509Revocation, types.KindWorkloadIdentityX509Revocation + "s":
return types.KindWorkloadIdentityX509Revocation, nil
case types.KindWorkloadIdentityX509IssuerOverride, types.KindWorkloadIdentityX509IssuerOverride + "s":
return types.KindWorkloadIdentityX509IssuerOverride, nil
}
return "", trace.BadParameter("unsupported resource: %q - resources should be expressed as 'type/name', for example 'connector/github'", in)
}
@@ -0,0 +1,48 @@
// Teleport
// Copyright (C) 2025 Gravitational, Inc.
//
// This program is free software: you can redistribute it and/or modify
// it under the terms of the GNU Affero General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU Affero General Public License for more details.
//
// You should have received a copy of the GNU Affero General Public License
// along with this program. If not, see <http://www.gnu.org/licenses/>.
package services
import (
"context"
workloadidentityv1pb "github.com/gravitational/teleport/api/gen/proto/go/teleport/workloadidentity/v1"
)
type WorkloadIdentityX509Overrides interface {
// GetX509IssuerOverride gets a single override by name. If no override with
// such a name exists, a [*trace.NotFoundError] is returned.
GetX509IssuerOverride(ctx context.Context, name string) (*workloadidentityv1pb.X509IssuerOverride, error)
// ListX509IssuerOverrides returns a page of overrides with a given size;
// iteration starts at the beginning of the list with an empty page token,
// then can be continued in following calls by using the returned next page
// token until it's empty.
ListX509IssuerOverrides(ctx context.Context, pageSize int, pageToken string) (_ []*workloadidentityv1pb.X509IssuerOverride, nextPageToken string, _ error)
// CreateX509IssuerOverride creates a new override. A
// [*trace.AlreadyExistsError] will be returned if an override with the same
// name already exists.
CreateX509IssuerOverride(ctx context.Context, resource *workloadidentityv1pb.X509IssuerOverride) (*workloadidentityv1pb.X509IssuerOverride, error)
// UpdateX509IssuerOverride updates an override; an override with the same
// name and revision as the one passed in must already exist, or a
// [*trace.CompareFailedError] will be returned.
UpdateX509IssuerOverride(ctx context.Context, resource *workloadidentityv1pb.X509IssuerOverride) (*workloadidentityv1pb.X509IssuerOverride, error)
// UpsertX509IssuerOverride creates or updates an override unconditionally.
UpsertX509IssuerOverride(ctx context.Context, resource *workloadidentityv1pb.X509IssuerOverride) (*workloadidentityv1pb.X509IssuerOverride, error)
// DeleteX509IssuerOverride deletes an existing override by name. If no
// override with such a name exists, a [*trace.NotFoundError] is returned.
DeleteX509IssuerOverride(ctx context.Context, name string) error
}
+18
View File
@@ -68,6 +68,24 @@ type ResourceCollection interface {
resources() []types.Resource
}
// namedResourceCollection is an implementation of [ResourceCollection] that
// displays resources in a table as a list of names and nothing else.
type namedResourceCollection []types.Resource
// resources implements [ResourceCollection].
func (c namedResourceCollection) resources() []types.Resource {
return c
}
// writeText implements [ResourceCollection].
func (c namedResourceCollection) writeText(w io.Writer, verbose bool) error {
t := asciitable.MakeTable([]string{"Name"})
for _, override := range c {
t.AddRow([]string{override.GetName()})
}
return trace.Wrap(t.WriteTo(w))
}
type roleCollection struct {
roles []types.Role
}
+183 -70
View File
@@ -134,78 +134,80 @@ Same as above, but using JSON output:
// Initialize allows ResourceCommand to plug itself into the CLI parser
func (rc *ResourceCommand) Initialize(app *kingpin.Application, _ *tctlcfg.GlobalCLIFlags, config *servicecfg.Config) {
rc.CreateHandlers = map[ResourceKind]ResourceCreateHandler{
types.KindUser: rc.createUser,
types.KindRole: rc.createRole,
types.KindTrustedCluster: rc.createTrustedCluster,
types.KindGithubConnector: rc.createGithubConnector,
types.KindCertAuthority: rc.createCertAuthority,
types.KindClusterAuthPreference: rc.createAuthPreference,
types.KindClusterNetworkingConfig: rc.createClusterNetworkingConfig,
types.KindClusterMaintenanceConfig: rc.createClusterMaintenanceConfig,
types.KindSessionRecordingConfig: rc.createSessionRecordingConfig,
types.KindExternalAuditStorage: rc.createExternalAuditStorage,
types.KindUIConfig: rc.createUIConfig,
types.KindLock: rc.createLock,
types.KindNetworkRestrictions: rc.createNetworkRestrictions,
types.KindApp: rc.createApp,
types.KindAppServer: rc.createAppServer,
types.KindDatabase: rc.createDatabase,
types.KindKubernetesCluster: rc.createKubeCluster,
types.KindToken: rc.createToken,
types.KindInstaller: rc.createInstaller,
types.KindNode: rc.createNode,
types.KindOIDCConnector: rc.createOIDCConnector,
types.KindSAMLConnector: rc.createSAMLConnector,
types.KindLoginRule: rc.createLoginRule,
types.KindSAMLIdPServiceProvider: rc.createSAMLIdPServiceProvider,
types.KindDevice: rc.createDevice,
types.KindOktaImportRule: rc.createOktaImportRule,
types.KindIntegration: rc.createIntegration,
types.KindWindowsDesktop: rc.createWindowsDesktop,
types.KindDynamicWindowsDesktop: rc.createDynamicWindowsDesktop,
types.KindAccessList: rc.createAccessList,
types.KindDiscoveryConfig: rc.createDiscoveryConfig,
types.KindAuditQuery: rc.createAuditQuery,
types.KindSecurityReport: rc.createSecurityReport,
types.KindServerInfo: rc.createServerInfo,
types.KindBot: rc.createBot,
types.KindDatabaseObjectImportRule: rc.createDatabaseObjectImportRule,
types.KindDatabaseObject: rc.createDatabaseObject,
types.KindAccessMonitoringRule: rc.createAccessMonitoringRule,
types.KindCrownJewel: rc.createCrownJewel,
types.KindVnetConfig: rc.createVnetConfig,
types.KindAccessGraphSettings: rc.upsertAccessGraphSettings,
types.KindPlugin: rc.createPlugin,
types.KindSPIFFEFederation: rc.createSPIFFEFederation,
types.KindWorkloadIdentity: rc.createWorkloadIdentity,
types.KindStaticHostUser: rc.createStaticHostUser,
types.KindUserTask: rc.createUserTask,
types.KindAutoUpdateConfig: rc.createAutoUpdateConfig,
types.KindAutoUpdateVersion: rc.createAutoUpdateVersion,
types.KindGitServer: rc.createGitServer,
types.KindAutoUpdateAgentRollout: rc.createAutoUpdateAgentRollout,
types.KindUser: rc.createUser,
types.KindRole: rc.createRole,
types.KindTrustedCluster: rc.createTrustedCluster,
types.KindGithubConnector: rc.createGithubConnector,
types.KindCertAuthority: rc.createCertAuthority,
types.KindClusterAuthPreference: rc.createAuthPreference,
types.KindClusterNetworkingConfig: rc.createClusterNetworkingConfig,
types.KindClusterMaintenanceConfig: rc.createClusterMaintenanceConfig,
types.KindSessionRecordingConfig: rc.createSessionRecordingConfig,
types.KindExternalAuditStorage: rc.createExternalAuditStorage,
types.KindUIConfig: rc.createUIConfig,
types.KindLock: rc.createLock,
types.KindNetworkRestrictions: rc.createNetworkRestrictions,
types.KindApp: rc.createApp,
types.KindAppServer: rc.createAppServer,
types.KindDatabase: rc.createDatabase,
types.KindKubernetesCluster: rc.createKubeCluster,
types.KindToken: rc.createToken,
types.KindInstaller: rc.createInstaller,
types.KindNode: rc.createNode,
types.KindOIDCConnector: rc.createOIDCConnector,
types.KindSAMLConnector: rc.createSAMLConnector,
types.KindLoginRule: rc.createLoginRule,
types.KindSAMLIdPServiceProvider: rc.createSAMLIdPServiceProvider,
types.KindDevice: rc.createDevice,
types.KindOktaImportRule: rc.createOktaImportRule,
types.KindIntegration: rc.createIntegration,
types.KindWindowsDesktop: rc.createWindowsDesktop,
types.KindDynamicWindowsDesktop: rc.createDynamicWindowsDesktop,
types.KindAccessList: rc.createAccessList,
types.KindDiscoveryConfig: rc.createDiscoveryConfig,
types.KindAuditQuery: rc.createAuditQuery,
types.KindSecurityReport: rc.createSecurityReport,
types.KindServerInfo: rc.createServerInfo,
types.KindBot: rc.createBot,
types.KindDatabaseObjectImportRule: rc.createDatabaseObjectImportRule,
types.KindDatabaseObject: rc.createDatabaseObject,
types.KindAccessMonitoringRule: rc.createAccessMonitoringRule,
types.KindCrownJewel: rc.createCrownJewel,
types.KindVnetConfig: rc.createVnetConfig,
types.KindAccessGraphSettings: rc.upsertAccessGraphSettings,
types.KindPlugin: rc.createPlugin,
types.KindSPIFFEFederation: rc.createSPIFFEFederation,
types.KindWorkloadIdentity: rc.createWorkloadIdentity,
types.KindStaticHostUser: rc.createStaticHostUser,
types.KindUserTask: rc.createUserTask,
types.KindAutoUpdateConfig: rc.createAutoUpdateConfig,
types.KindAutoUpdateVersion: rc.createAutoUpdateVersion,
types.KindGitServer: rc.createGitServer,
types.KindAutoUpdateAgentRollout: rc.createAutoUpdateAgentRollout,
types.KindWorkloadIdentityX509IssuerOverride: rc.createWorkloadIdentityX509IssuerOverride,
}
rc.UpdateHandlers = map[ResourceKind]ResourceCreateHandler{
types.KindUser: rc.updateUser,
types.KindGithubConnector: rc.updateGithubConnector,
types.KindOIDCConnector: rc.updateOIDCConnector,
types.KindSAMLConnector: rc.updateSAMLConnector,
types.KindRole: rc.updateRole,
types.KindClusterNetworkingConfig: rc.updateClusterNetworkingConfig,
types.KindClusterAuthPreference: rc.updateAuthPreference,
types.KindSessionRecordingConfig: rc.updateSessionRecordingConfig,
types.KindAccessMonitoringRule: rc.updateAccessMonitoringRule,
types.KindCrownJewel: rc.updateCrownJewel,
types.KindVnetConfig: rc.updateVnetConfig,
types.KindAccessGraphSettings: rc.updateAccessGraphSettings,
types.KindPlugin: rc.updatePlugin,
types.KindStaticHostUser: rc.updateStaticHostUser,
types.KindUserTask: rc.updateUserTask,
types.KindAutoUpdateConfig: rc.updateAutoUpdateConfig,
types.KindAutoUpdateVersion: rc.updateAutoUpdateVersion,
types.KindDynamicWindowsDesktop: rc.updateDynamicWindowsDesktop,
types.KindGitServer: rc.updateGitServer,
types.KindAutoUpdateAgentRollout: rc.updateAutoUpdateAgentRollout,
types.KindUser: rc.updateUser,
types.KindGithubConnector: rc.updateGithubConnector,
types.KindOIDCConnector: rc.updateOIDCConnector,
types.KindSAMLConnector: rc.updateSAMLConnector,
types.KindRole: rc.updateRole,
types.KindClusterNetworkingConfig: rc.updateClusterNetworkingConfig,
types.KindClusterAuthPreference: rc.updateAuthPreference,
types.KindSessionRecordingConfig: rc.updateSessionRecordingConfig,
types.KindAccessMonitoringRule: rc.updateAccessMonitoringRule,
types.KindCrownJewel: rc.updateCrownJewel,
types.KindVnetConfig: rc.updateVnetConfig,
types.KindAccessGraphSettings: rc.updateAccessGraphSettings,
types.KindPlugin: rc.updatePlugin,
types.KindStaticHostUser: rc.updateStaticHostUser,
types.KindUserTask: rc.updateUserTask,
types.KindAutoUpdateConfig: rc.updateAutoUpdateConfig,
types.KindAutoUpdateVersion: rc.updateAutoUpdateVersion,
types.KindDynamicWindowsDesktop: rc.updateDynamicWindowsDesktop,
types.KindGitServer: rc.updateGitServer,
types.KindAutoUpdateAgentRollout: rc.updateAutoUpdateAgentRollout,
types.KindWorkloadIdentityX509IssuerOverride: rc.updateWorkloadIdentityX509IssuerOverride,
}
rc.config = config
@@ -1162,6 +1164,65 @@ func (rc *ResourceCommand) createWorkloadIdentity(ctx context.Context, client *a
return nil
}
func (rc *ResourceCommand) createWorkloadIdentityX509IssuerOverride(ctx context.Context, client *authclient.Client, raw services.UnknownResource) error {
r, err := services.UnmarshalProtoResource[*workloadidentityv1pb.X509IssuerOverride](raw.Raw, services.DisallowUnknown())
if err != nil {
return trace.Wrap(err)
}
c := client.WorkloadIdentityX509OverridesClient()
if rc.IsForced() {
if _, err := c.UpsertX509IssuerOverride(
ctx,
&workloadidentityv1pb.UpsertX509IssuerOverrideRequest{
X509IssuerOverride: r,
},
); err != nil {
return trace.Wrap(err)
}
} else {
if _, err := c.CreateX509IssuerOverride(
ctx,
&workloadidentityv1pb.CreateX509IssuerOverrideRequest{
X509IssuerOverride: r,
},
); err != nil {
return trace.Wrap(err)
}
}
fmt.Fprintf(
rc.stdout,
types.KindWorkloadIdentityX509IssuerOverride+" %q has been created\n",
r.GetMetadata().GetName(),
)
return nil
}
func (rc *ResourceCommand) updateWorkloadIdentityX509IssuerOverride(ctx context.Context, client *authclient.Client, raw services.UnknownResource) error {
r, err := services.UnmarshalProtoResource[*workloadidentityv1pb.X509IssuerOverride](raw.Raw, services.DisallowUnknown())
if err != nil {
return trace.Wrap(err)
}
c := client.WorkloadIdentityX509OverridesClient()
if _, err = c.UpdateX509IssuerOverride(
ctx,
&workloadidentityv1pb.UpdateX509IssuerOverrideRequest{
X509IssuerOverride: r,
},
); err != nil {
return trace.Wrap(err)
}
fmt.Fprintf(
rc.stdout,
types.KindWorkloadIdentityX509IssuerOverride+" %q has been updated\n",
r.GetMetadata().GetName(),
)
return nil
}
func (rc *ResourceCommand) updateCrownJewel(ctx context.Context, client *authclient.Client, resource services.UnknownResource) error {
in, err := services.UnmarshalCrownJewel(resource.Raw, services.DisallowUnknown())
if err != nil {
@@ -2077,6 +2138,21 @@ func (rc *ResourceCommand) Delete(ctx context.Context, client *authclient.Client
return trace.Wrap(err)
}
fmt.Printf("Workload identity X509 revocation %q has been deleted\n", rc.ref.Name)
case types.KindWorkloadIdentityX509IssuerOverride:
c := client.WorkloadIdentityX509OverridesClient()
if _, err := c.DeleteX509IssuerOverride(
ctx,
&workloadidentityv1pb.DeleteX509IssuerOverrideRequest{
Name: rc.ref.Name,
},
); err != nil {
return trace.Wrap(err)
}
fmt.Fprintf(
rc.stdout,
types.KindWorkloadIdentityX509IssuerOverride+" %q has been deleted\n",
rc.ref.Name,
)
case types.KindStaticHostUser:
if err := client.StaticHostUserClient().DeleteStaticHostUser(ctx, rc.ref.Name); err != nil {
return trace.Wrap(err)
@@ -3422,6 +3498,43 @@ func (rc *ResourceCommand) getCollection(ctx context.Context, client *authclient
}
// TODO(greedy52) consider making dedicated git server collection.
return &serverCollection{servers: servers}, nil
case types.KindWorkloadIdentityX509IssuerOverride:
c := client.WorkloadIdentityX509OverridesClient()
if rc.ref.Name != "" {
r, err := c.GetX509IssuerOverride(
ctx,
&workloadidentityv1pb.GetX509IssuerOverrideRequest{
Name: rc.ref.Name,
},
)
if err != nil {
return nil, trace.Wrap(err)
}
return namedResourceCollection{types.ProtoResource153ToLegacy(r)}, nil
}
var collection namedResourceCollection
var pageToken string
for {
resp, err := c.ListX509IssuerOverrides(
ctx,
&workloadidentityv1pb.ListX509IssuerOverridesRequest{
PageToken: pageToken,
},
)
if err != nil {
return nil, trace.Wrap(err)
}
collection = slices.Grow(collection, len(resp.GetX509IssuerOverrides()))
for _, r := range resp.GetX509IssuerOverrides() {
collection = append(collection, types.ProtoResource153ToLegacy(r))
}
pageToken = resp.GetNextPageToken()
if pageToken == "" {
break
}
}
return collection, nil
}
return nil, trace.BadParameter("getting %q is not supported", rc.ref.String())
}
@@ -98,6 +98,8 @@ const EventIconMap: Record<EventCode, any> = {
[eventCodes.WORKLOAD_IDENTITY_CREATE]: Icons.Info,
[eventCodes.WORKLOAD_IDENTITY_UPDATE]: Icons.Info,
[eventCodes.WORKLOAD_IDENTITY_DELETE]: Icons.Info,
[eventCodes.WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_CREATE]: Icons.Info,
[eventCodes.WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_DELETE]: Icons.Info,
[eventCodes.RESET_PASSWORD_TOKEN_CREATED]: Icons.Info,
[eventCodes.USER_PASSWORD_CHANGED]: Icons.Info,
[eventCodes.ACCESS_REQUEST_CREATED]: Icons.Info,
@@ -3917,6 +3917,32 @@ export const events = [
uid: '0efbb33d-fa50-44e0-8dec-4ac89c0dd4ab',
user: 'gavin',
},
{
'addr.remote': '203.0.113.71:59517',
cluster_name: 'clustername',
code: 'WID007I',
ei: 0,
event: 'workload_identity_x509_issuer_override.create',
expires: '0001-01-01T00:00:00Z',
name: 'default',
time: '2025-03-28T08:42:14.526Z',
uid: 'd99124ab-34f8-490e-b839-ca881e7cc6ba',
user: 'alice',
user_kind: 1,
},
{
'addr.remote': '203.0.113.77:64794',
cluster_name: 'clustername',
code: 'WID008I',
ei: 0,
event: 'workload_identity_x509_issuer_override.delete',
expires: '0001-01-01T00:00:00Z',
name: 'default',
time: '2025-03-26T01:14:36.881Z',
uid: 'e52def2f-4109-4cc9-91a8-150c6792f89f',
user: 'bob',
user_kind: 1,
},
].map(makeEvent);
// Do not add new events to this array, add it to `events` list.
@@ -1481,6 +1481,20 @@ export const formatters: Formatters = {
return `User [${user}] deleted a Workload Identity [${name}]`;
},
},
[eventCodes.WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_CREATE]: {
type: 'workload_identity_x509_issuer_override.create',
desc: 'Workload Identity X.509 Issuer Override Created',
format: ({ user, name }) => {
return `User [${user}] created a Workload Identity X.509 Issuer Override [${name}]`;
},
},
[eventCodes.WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_DELETE]: {
type: 'workload_identity_x509_issuer_override.delete',
desc: 'Workload Identity X.509 Issuer Override Deleted',
format: ({ user, name }) => {
return `User [${user}] deleted a Workload Identity X.509 Issuer Override [${name}]`;
},
},
[eventCodes.LOGIN_RULE_CREATE]: {
type: 'login_rule.create',
desc: 'Login Rule Created',
@@ -238,6 +238,8 @@ export const eventCodes = {
WORKLOAD_IDENTITY_CREATE: `WID001I`,
WORKLOAD_IDENTITY_UPDATE: `WID002I`,
WORKLOAD_IDENTITY_DELETE: `WID003I`,
WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_CREATE: `WID007I`,
WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_DELETE: `WID008I`,
LOGIN_RULE_CREATE: 'TLR00I',
LOGIN_RULE_DELETE: 'TLR01I',
SAML_IDP_AUTH_ATTEMPT: 'TSI000I',
@@ -1355,6 +1357,14 @@ export type RawEvents = {
typeof eventCodes.WORKLOAD_IDENTITY_DELETE,
HasName
>;
[eventCodes.WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_CREATE]: RawEvent<
typeof eventCodes.WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_CREATE,
HasName
>;
[eventCodes.WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_DELETE]: RawEvent<
typeof eventCodes.WORKLOAD_IDENTITY_X509_ISSUER_OVERRIDE_DELETE,
HasName
>;
[eventCodes.LOGIN_RULE_CREATE]: RawEvent<
typeof eventCodes.LOGIN_RULE_CREATE,
HasName