docs: update db docs (#64930)

* docs: db update

* docs: remove invalid file

* Update name of Opensearch in resource examples
This commit is contained in:
Steven Martin
2026-03-25 09:39:48 +00:00
committed by GitHub
parent 2078c88da9
commit 49c783ace8
27 changed files with 44 additions and 44 deletions
@@ -29,7 +29,7 @@ spec:
# 'elasticache' - Amazon ElastiCache Redis and Valkey databases.
# 'elasticache-serverless' - Amazon ElastiCache Serverless Redis or Valkey databases.
# 'memorydb' - Amazon MemoryDB databases.
# 'opensearch' - Amazon OpenSearch Redis databases.
# 'opensearch' - Amazon OpenSearch databases.
# 'docdb' - Amazon DocumentDB databases.
- types: ["ec2"]
# AWS regions to search for resources from
@@ -116,7 +116,7 @@ role to assume this role:
Finally, click **Create Role**.
### Configure Cluster Fine-grained access control IAM Role mapping in Amazon OpenSearch Managed Custer
### Configure Cluster Fine-grained access control IAM Role mapping in Amazon OpenSearch Managed Cluster
Teleport Amazon OpenSearch service integration leverages the OpenSearch Fine-grained
access control
@@ -293,7 +293,7 @@ Provide Active Directory parameters:
(!docs/pages/includes/start-teleport.mdx service="the Teleport Database Service"!)
## Step 7/9. Create a Teleport users
## Step 7/9. Create a Teleport user
(!docs/pages/includes/database-access/create-user.mdx!)
@@ -11,11 +11,6 @@ tags:
(!docs/pages/includes/database-access/db-introduction.mdx dbType="Amazon Redshift Serverless" dbConfigure="with IAM authentication"!)
This guide will help you to:
- Set up Teleport to access your Amazon Redshift Serverless workgroups.
- Connect to your databases through Teleport.
## How it works
(!docs/pages/includes/database-access/how-it-works/iam.mdx db="Redshift Serverless" cloud="AWS"!)
@@ -359,7 +359,7 @@ Save this file and apply it to your Teleport cluster:
```code
$ tctl create -f azure-database-role.yaml
role 'azure-database-role.yaml' has been created
role 'azure-database-access' has been created
```
(!docs/pages/includes/create-role-using-web.mdx!)
@@ -258,7 +258,7 @@ to add it.
When connecting to your database, and you see the error `mssql: login error: Login
failed for user '<token-identified principal>'`, it means your managed identity
login is not present on the SQL database. You’ll need to create their users as
described in [Step 6](#step-58-enable-managed-identities-login-on-sql-server).
described in [Step 5](#step-58-enable-managed-identities-login-on-sql-server).
Remember: you must create the users on all databases you want to connect.
### Timeout connecting to the database
@@ -63,7 +63,7 @@ cloudsql.users.get
The pre-defined "Cloud SQL Viewer" role has this permission, but also has other
permissions that are not needed. Define and bind a custom role to the service
account to follow the principal of least privilege.
account to follow the principle of least privilege.
<Admonition type="note">
Support for legacy one-time password authentication will be deprecated.
@@ -95,10 +95,10 @@ with Cloud SQL MySQL instances.
### (Optional) SSL mode "require trusted client certificates"
When using Cloud SQL MySQL with "require trusted client certificates" enabled,
Teleport connects to the database's Cloud SQL Proxy port 3307 instead of the
default 3306 as the default Cloud SQL MySQL listener does not trust generated
Teleport connects to the database's Cloud SQL Proxy port `3307` instead of the
default `3306` as the default Cloud SQL MySQL listener does not trust generated
ephemeral certificates. For this reason, you should make sure to allow port
3307 when using "require trusted client certificates".
`3307` when using "require trusted client certificates".
<Admonition type="note">
The "require trusted client certificates" SSL mode only forces the client
@@ -124,7 +124,7 @@ Teleport Database Service:
Proxy Service or cloud-hosted Teleport Enterprise site
- <Var name="project-id"/> The GCP project ID. You can normally see it in the
organization view at the top of the GCP dashboard.
- <Var name="instance-id"/> The name of your Cloud SQL instance.
- <Var name="instance-id"/> The name of your Cloud Spanner instance.
```code
$ sudo teleport db configure create \
@@ -217,7 +217,7 @@ necessary credentials to authenticate to MongoDB:
Your role won’t require any permission, so you can leave it empty on the
**Add Permissions** step. Then, choose a name for it and create it. In this
guide, we will the name `teleport-access`.
guide, we will use the name `teleport-access`.
### Create a MongoDB User
@@ -12,7 +12,12 @@ tags:
## How it works
(!docs/pages/includes/database-access/how-it-works/mtls.mdx db="Oracle"!)
The Teleport Database Service authenticates to your Oracle Exadata
database using mutual TLS. Oracle Exadata trusts the Teleport certificate authority
for database clients, and presents a certificate signed by either the Teleport
database CA or a custom CA. When a user initiates a database session, the
Teleport Database Service presents a certificate signed by Teleport. The
authenticated connection then proxies client traffic from the user.
<Tabs>
<TabItem scope={["enterprise"]} label="Teleport Enterprise (Self-Hosted)">
@@ -143,7 +143,7 @@ Log into your Teleport cluster and see available databases:
</TabItem>
<TabItem label="Teleport Cloud">
```code
$ tsh login --proxy=mytennant.teleport.sh --user=alice
$ tsh login --proxy=mytenant.teleport.sh --user=alice
$ tsh db ls
Name Description Allowed Users Labels Connect
--------------------------- ----------- ------------- ------- ------------------------
@@ -161,7 +161,7 @@ Install and configure Teleport where you will run the Teleport Database Service:
(!docs/pages/includes/install-linux.mdx!)
(!docs/pages/includes/database-access/self-hosted-config-start.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="oracle.example.com:2484" dbName="oracle" !)
(!docs/pages/includes/database-access/self-hosted-config-start.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="db.example.com:2484" dbName="oracle" !)
</TabItem>
<TabItem label="Kubernetes Cluster">
@@ -169,7 +169,7 @@ Install and configure Teleport where you will run the Teleport Database Service:
(!docs/pages/includes/kubernetes-access/helm/helm-repo-add.mdx!)
(!docs/pages/includes/database-access/self-hosted-db-helm-install.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="oracle.example.com:2484" !)
(!docs/pages/includes/database-access/self-hosted-db-helm-install.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="db.example.com:2484" !)
</TabItem>
</Tabs>
@@ -216,7 +216,7 @@ db_service:
databases:
- name: "oracle"
protocol: "oracle"
uri: "oracle.example.com:2484"
uri: "db.example.com:2484"
oracle:
audit_user: "teleport"
```
@@ -98,13 +98,13 @@ cells:
required: true
tls:
clientCACertSecret:
name: teleport-cluster-config
name: example-cluster-config
key: server.cas
certSecret:
name: teleport-cluster-config
name: example-cluster-config
key: server.crt
keySecret:
name: teleport-cluster-config
name: example-cluster-config
key: server.key
```
@@ -28,7 +28,7 @@ db_service:
"*": "*"
```
You can use a wildcard selector to register all dynamic app resources in the cluster
You can use a wildcard selector to register all dynamic database resources in the cluster
on the Database Service or provide a specific set of labels for a subset:
```yaml
@@ -240,7 +240,6 @@ spec:
values:
- 'staging'
- 'dev'
- 'prod'
mappings:
# Apply project label
- add_labels:
@@ -318,7 +317,8 @@ metadata:
# ...
spec:
# ...
admin_user: "teleport-admin"
admin_user:
name: "teleport-admin"
```
</TabItem>
@@ -119,7 +119,7 @@ $ teleport db configure create \
| `--redshift-discovery` | List of AWS regions in which the agent will discover Redshift instances. |
| `--redshift-serverless-discovery` | List of AWS regions in which the agent will discover Redshift Serverless instances. |
| `--elasticache-discovery` | List of AWS regions in which the agent will discover ElastiCache Redis and Valkey clusters. |
| `elasticache-serverless-discovery` | List of AWS regions in which the agent will discover ElastiCache Serverless Valkey or Redis caches. |
| `--elasticache-serverless-discovery` | List of AWS regions in which the agent will discover ElastiCache Serverless Valkey or Redis caches. |
| `--aws-tags` | (Only for AWS discoveries) Comma-separated list of AWS resource tags to match, for example env=dev,dept=it |
| `--memorydb-discovery` | List of AWS regions in which the agent will discover MemoryDB clusters. |
| `--azure-mysql-discovery` | List of Azure regions in which the agent will discover MySQL servers. |
@@ -87,7 +87,7 @@ proxy_service:
# Address advertised to PostgreSQL clients.
postgres_public_addr: "mytenant.teleport.sh:443"
# Address advertised to Mongo clients. If not set, public_addr is used.
mongo_public_addr: "mongo.teleport.example.com:443
mongo_public_addr: "mongo.teleport.example.com:443"
```
</TabItem>
@@ -20,7 +20,7 @@ of the following values:
| - | - |
| `cloud` | database resources created by auto-discovery. |
| `config` | database resources manually defined in the `database_service.databases` section of `teleport.yaml`. |
| `dynamic` | database resources created through [dynamic registration](../../../enroll-resources/database-access/guides/dynamic-registration.mdx) like `tcl create` command. |
| `dynamic` | database resources created through [dynamic registration](../../../enroll-resources/database-access/guides/dynamic-registration.mdx) like `tctl create` command. |
## Auto-discovery
@@ -34,7 +34,7 @@ The command used to generate a new certificate is `tctl auth sign`. For example,
to create a certificate for PostgreSQL, the command looks like this:
```code
# Export Teleport's certificate authority and a generate certificate/key pair
# Export Teleport's certificate authority and a generated certificate/key pair
# for host db.example.com with a 3-month validity period.
$ tctl auth sign --format=db --host=db.example.com --out=server --ttl=2190h
@@ -55,7 +55,7 @@ db_service:
# on the Database Service.
#
# NOTE: for most deployments, it is recommended to use the Discovery Service
# to register AWS databases instead of Database Service–based discovery.
# to register Azure databases instead of Database Service–based discovery.
azure:
# Database types. Valid options are:
# 'mysql' - discovers and registers Azure MySQL databases.
@@ -1,5 +1,5 @@
The Teleport Database Service needs permissions to automatically download
your Cloud SQL instance's root CA certificate and to general an ephemeral
your Cloud SQL instance's root CA certificate and to generate an ephemeral
client certificate.
If you intend to download the CA certificate manually and your Cloud SQL
@@ -56,4 +56,4 @@ If any of the Database Service instances listed here **should not** proxy the
database, (for example, a Database Service instance in a different VPC or AWS
region without connectivity), locate and update their configurations so they
only receive or discover databases they can reach. In most cases, you can
achieve this by refining your tag filters, such as adding the a `vpc-id` label.
achieve this by refining your tag filters, such as adding the `vpc-id` label.
@@ -3,6 +3,6 @@
title="Tip"
>
A single Teleport process can run multiple services, for example
multiple Database Service instances as well as other services such the
SSH Service or Application Service.
multiple Database Service instances as well as other services such as
the SSH Service or Application Service.
</Admonition>
@@ -53,8 +53,8 @@ ORA-28860: Fatal SSL error
To identify the root cause, follow the debugging steps in the sections below. The output of the following `openssl` command can help diagnose many common TLS issues. Capture the output and use it as you follow the debugging steps.
```
> openssl s_client -connect oracle.example.com:2484 -showcerts
```code
$ openssl s_client -connect db.example.com:2484 -showcerts
```
#### Wrong server certificate
@@ -76,7 +76,7 @@ Compare the `issuer` in the server certificate with the `issuer` of the Teleport
# openssl s_client output:
...
Server certificate
subject=CN=oracle.example.com
subject=CN=db.example.com
issuer=O=teleport.example.com, CN=teleport.example.com, serialNumber=200129862304303044762346177566738813560
...
```
@@ -92,7 +92,7 @@ The "User Certificates" section of the output should contain the server's certif
```
User Certificates:
Subject: CN=oracle.example.com
Subject: CN=db.example.com
Issuer: SERIALNUMBER=200129862304303044762346177566738813560,CN=teleport.example.com,O=teleport.example.com
Serial Number: ...
```
@@ -191,4 +191,4 @@ SQL> SELECT username, authentication_type, external_name
USERNAME AUTHENTICATION_TYPE EXTERNAL_NAME
_____________ ______________________ ________________
ALICE EXTERNAL cn=alice
```
```
@@ -29,7 +29,7 @@ the database, follow these instructions on your workstation:
roles: ["Db"]
```
1. Export Teleport's certificate authority and a generate certificate/key pair.
1. Export Teleport's certificate authority and generate a certificate/key pair.
This example generates a certificate with a 90-day validity period.
`db.example.com` is the hostname where the Teleport Database Service can
reach the {{ dbname }} server.
@@ -1,5 +1,5 @@
<Admonition type="note" title="TTL">
We recommend using a shorter TTL, but keep mind that you'll need to update the
We recommend using a shorter TTL, but keep in mind that you'll need to update the
database server certificate before it expires to not lose the ability to
connect. Pick the TTL value that best fits your use-case.
</Admonition>
@@ -46,7 +46,7 @@ spec:
# 'elasticache' - Amazon ElastiCache Redis and Valkey databases.
# 'elasticache-serverless' - Amazon ElastiCache Serverless Redis or Valkey databases.
# 'memorydb' - Amazon MemoryDB databases.
# 'opensearch' - Amazon OpenSearch Redis databases.
# 'opensearch' - Amazon OpenSearch databases.
# 'docdb' - Amazon DocumentDB databases.
- types: ["ec2"]
# AWS regions to search for resources from