mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
docs: update db docs (#64930)
* docs: db update * docs: remove invalid file * Update name of Opensearch in resource examples
This commit is contained in:
+1
-1
@@ -29,7 +29,7 @@ spec:
|
||||
# 'elasticache' - Amazon ElastiCache Redis and Valkey databases.
|
||||
# 'elasticache-serverless' - Amazon ElastiCache Serverless Redis or Valkey databases.
|
||||
# 'memorydb' - Amazon MemoryDB databases.
|
||||
# 'opensearch' - Amazon OpenSearch Redis databases.
|
||||
# 'opensearch' - Amazon OpenSearch databases.
|
||||
# 'docdb' - Amazon DocumentDB databases.
|
||||
- types: ["ec2"]
|
||||
# AWS regions to search for resources from
|
||||
|
||||
@@ -116,7 +116,7 @@ role to assume this role:
|
||||
|
||||
Finally, click **Create Role**.
|
||||
|
||||
### Configure Cluster Fine-grained access control IAM Role mapping in Amazon OpenSearch Managed Custer
|
||||
### Configure Cluster Fine-grained access control IAM Role mapping in Amazon OpenSearch Managed Cluster
|
||||
|
||||
Teleport Amazon OpenSearch service integration leverages the OpenSearch Fine-grained
|
||||
access control
|
||||
|
||||
@@ -293,7 +293,7 @@ Provide Active Directory parameters:
|
||||
|
||||
(!docs/pages/includes/start-teleport.mdx service="the Teleport Database Service"!)
|
||||
|
||||
## Step 7/9. Create a Teleport users
|
||||
## Step 7/9. Create a Teleport user
|
||||
|
||||
(!docs/pages/includes/database-access/create-user.mdx!)
|
||||
|
||||
|
||||
@@ -11,11 +11,6 @@ tags:
|
||||
|
||||
(!docs/pages/includes/database-access/db-introduction.mdx dbType="Amazon Redshift Serverless" dbConfigure="with IAM authentication"!)
|
||||
|
||||
This guide will help you to:
|
||||
|
||||
- Set up Teleport to access your Amazon Redshift Serverless workgroups.
|
||||
- Connect to your databases through Teleport.
|
||||
|
||||
## How it works
|
||||
|
||||
(!docs/pages/includes/database-access/how-it-works/iam.mdx db="Redshift Serverless" cloud="AWS"!)
|
||||
|
||||
+1
-1
@@ -359,7 +359,7 @@ Save this file and apply it to your Teleport cluster:
|
||||
|
||||
```code
|
||||
$ tctl create -f azure-database-role.yaml
|
||||
role 'azure-database-role.yaml' has been created
|
||||
role 'azure-database-access' has been created
|
||||
```
|
||||
|
||||
(!docs/pages/includes/create-role-using-web.mdx!)
|
||||
|
||||
+1
-1
@@ -258,7 +258,7 @@ to add it.
|
||||
When connecting to your database, and you see the error `mssql: login error: Login
|
||||
failed for user '<token-identified principal>'`, it means your managed identity
|
||||
login is not present on the SQL database. You’ll need to create their users as
|
||||
described in [Step 6](#step-58-enable-managed-identities-login-on-sql-server).
|
||||
described in [Step 5](#step-58-enable-managed-identities-login-on-sql-server).
|
||||
Remember: you must create the users on all databases you want to connect.
|
||||
|
||||
### Timeout connecting to the database
|
||||
|
||||
+4
-4
@@ -63,7 +63,7 @@ cloudsql.users.get
|
||||
|
||||
The pre-defined "Cloud SQL Viewer" role has this permission, but also has other
|
||||
permissions that are not needed. Define and bind a custom role to the service
|
||||
account to follow the principal of least privilege.
|
||||
account to follow the principle of least privilege.
|
||||
|
||||
<Admonition type="note">
|
||||
Support for legacy one-time password authentication will be deprecated.
|
||||
@@ -95,10 +95,10 @@ with Cloud SQL MySQL instances.
|
||||
### (Optional) SSL mode "require trusted client certificates"
|
||||
|
||||
When using Cloud SQL MySQL with "require trusted client certificates" enabled,
|
||||
Teleport connects to the database's Cloud SQL Proxy port 3307 instead of the
|
||||
default 3306 as the default Cloud SQL MySQL listener does not trust generated
|
||||
Teleport connects to the database's Cloud SQL Proxy port `3307` instead of the
|
||||
default `3306` as the default Cloud SQL MySQL listener does not trust generated
|
||||
ephemeral certificates. For this reason, you should make sure to allow port
|
||||
3307 when using "require trusted client certificates".
|
||||
`3307` when using "require trusted client certificates".
|
||||
|
||||
<Admonition type="note">
|
||||
The "require trusted client certificates" SSL mode only forces the client
|
||||
|
||||
@@ -124,7 +124,7 @@ Teleport Database Service:
|
||||
Proxy Service or cloud-hosted Teleport Enterprise site
|
||||
- <Var name="project-id"/> The GCP project ID. You can normally see it in the
|
||||
organization view at the top of the GCP dashboard.
|
||||
- <Var name="instance-id"/> The name of your Cloud SQL instance.
|
||||
- <Var name="instance-id"/> The name of your Cloud Spanner instance.
|
||||
|
||||
```code
|
||||
$ sudo teleport db configure create \
|
||||
|
||||
@@ -217,7 +217,7 @@ necessary credentials to authenticate to MongoDB:
|
||||
|
||||
Your role won’t require any permission, so you can leave it empty on the
|
||||
**Add Permissions** step. Then, choose a name for it and create it. In this
|
||||
guide, we will the name `teleport-access`.
|
||||
guide, we will use the name `teleport-access`.
|
||||
|
||||
### Create a MongoDB User
|
||||
|
||||
|
||||
@@ -12,7 +12,12 @@ tags:
|
||||
|
||||
## How it works
|
||||
|
||||
(!docs/pages/includes/database-access/how-it-works/mtls.mdx db="Oracle"!)
|
||||
The Teleport Database Service authenticates to your Oracle Exadata
|
||||
database using mutual TLS. Oracle Exadata trusts the Teleport certificate authority
|
||||
for database clients, and presents a certificate signed by either the Teleport
|
||||
database CA or a custom CA. When a user initiates a database session, the
|
||||
Teleport Database Service presents a certificate signed by Teleport. The
|
||||
authenticated connection then proxies client traffic from the user.
|
||||
|
||||
<Tabs>
|
||||
<TabItem scope={["enterprise"]} label="Teleport Enterprise (Self-Hosted)">
|
||||
|
||||
@@ -143,7 +143,7 @@ Log into your Teleport cluster and see available databases:
|
||||
</TabItem>
|
||||
<TabItem label="Teleport Cloud">
|
||||
```code
|
||||
$ tsh login --proxy=mytennant.teleport.sh --user=alice
|
||||
$ tsh login --proxy=mytenant.teleport.sh --user=alice
|
||||
$ tsh db ls
|
||||
Name Description Allowed Users Labels Connect
|
||||
--------------------------- ----------- ------------- ------- ------------------------
|
||||
|
||||
+3
-3
@@ -161,7 +161,7 @@ Install and configure Teleport where you will run the Teleport Database Service:
|
||||
|
||||
(!docs/pages/includes/install-linux.mdx!)
|
||||
|
||||
(!docs/pages/includes/database-access/self-hosted-config-start.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="oracle.example.com:2484" dbName="oracle" !)
|
||||
(!docs/pages/includes/database-access/self-hosted-config-start.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="db.example.com:2484" dbName="oracle" !)
|
||||
|
||||
</TabItem>
|
||||
<TabItem label="Kubernetes Cluster">
|
||||
@@ -169,7 +169,7 @@ Install and configure Teleport where you will run the Teleport Database Service:
|
||||
|
||||
(!docs/pages/includes/kubernetes-access/helm/helm-repo-add.mdx!)
|
||||
|
||||
(!docs/pages/includes/database-access/self-hosted-db-helm-install.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="oracle.example.com:2484" !)
|
||||
(!docs/pages/includes/database-access/self-hosted-db-helm-install.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="db.example.com:2484" !)
|
||||
|
||||
</TabItem>
|
||||
</Tabs>
|
||||
@@ -216,7 +216,7 @@ db_service:
|
||||
databases:
|
||||
- name: "oracle"
|
||||
protocol: "oracle"
|
||||
uri: "oracle.example.com:2484"
|
||||
uri: "db.example.com:2484"
|
||||
oracle:
|
||||
audit_user: "teleport"
|
||||
```
|
||||
|
||||
@@ -98,13 +98,13 @@ cells:
|
||||
required: true
|
||||
tls:
|
||||
clientCACertSecret:
|
||||
name: teleport-cluster-config
|
||||
name: example-cluster-config
|
||||
key: server.cas
|
||||
certSecret:
|
||||
name: teleport-cluster-config
|
||||
name: example-cluster-config
|
||||
key: server.crt
|
||||
keySecret:
|
||||
name: teleport-cluster-config
|
||||
name: example-cluster-config
|
||||
key: server.key
|
||||
```
|
||||
|
||||
|
||||
@@ -28,7 +28,7 @@ db_service:
|
||||
"*": "*"
|
||||
```
|
||||
|
||||
You can use a wildcard selector to register all dynamic app resources in the cluster
|
||||
You can use a wildcard selector to register all dynamic database resources in the cluster
|
||||
on the Database Service or provide a specific set of labels for a subset:
|
||||
|
||||
```yaml
|
||||
|
||||
@@ -240,7 +240,6 @@ spec:
|
||||
values:
|
||||
- 'staging'
|
||||
- 'dev'
|
||||
- 'prod'
|
||||
mappings:
|
||||
# Apply project label
|
||||
- add_labels:
|
||||
@@ -318,7 +317,8 @@ metadata:
|
||||
# ...
|
||||
spec:
|
||||
# ...
|
||||
admin_user: "teleport-admin"
|
||||
admin_user:
|
||||
name: "teleport-admin"
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
|
||||
@@ -119,7 +119,7 @@ $ teleport db configure create \
|
||||
| `--redshift-discovery` | List of AWS regions in which the agent will discover Redshift instances. |
|
||||
| `--redshift-serverless-discovery` | List of AWS regions in which the agent will discover Redshift Serverless instances. |
|
||||
| `--elasticache-discovery` | List of AWS regions in which the agent will discover ElastiCache Redis and Valkey clusters. |
|
||||
| `elasticache-serverless-discovery` | List of AWS regions in which the agent will discover ElastiCache Serverless Valkey or Redis caches. |
|
||||
| `--elasticache-serverless-discovery` | List of AWS regions in which the agent will discover ElastiCache Serverless Valkey or Redis caches. |
|
||||
| `--aws-tags` | (Only for AWS discoveries) Comma-separated list of AWS resource tags to match, for example env=dev,dept=it |
|
||||
| `--memorydb-discovery` | List of AWS regions in which the agent will discover MemoryDB clusters. |
|
||||
| `--azure-mysql-discovery` | List of Azure regions in which the agent will discover MySQL servers. |
|
||||
|
||||
@@ -87,7 +87,7 @@ proxy_service:
|
||||
# Address advertised to PostgreSQL clients.
|
||||
postgres_public_addr: "mytenant.teleport.sh:443"
|
||||
# Address advertised to Mongo clients. If not set, public_addr is used.
|
||||
mongo_public_addr: "mongo.teleport.example.com:443
|
||||
mongo_public_addr: "mongo.teleport.example.com:443"
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
|
||||
@@ -20,7 +20,7 @@ of the following values:
|
||||
| - | - |
|
||||
| `cloud` | database resources created by auto-discovery. |
|
||||
| `config` | database resources manually defined in the `database_service.databases` section of `teleport.yaml`. |
|
||||
| `dynamic` | database resources created through [dynamic registration](../../../enroll-resources/database-access/guides/dynamic-registration.mdx) like `tcl create` command. |
|
||||
| `dynamic` | database resources created through [dynamic registration](../../../enroll-resources/database-access/guides/dynamic-registration.mdx) like `tctl create` command. |
|
||||
|
||||
## Auto-discovery
|
||||
|
||||
|
||||
@@ -34,7 +34,7 @@ The command used to generate a new certificate is `tctl auth sign`. For example,
|
||||
to create a certificate for PostgreSQL, the command looks like this:
|
||||
|
||||
```code
|
||||
# Export Teleport's certificate authority and a generate certificate/key pair
|
||||
# Export Teleport's certificate authority and a generated certificate/key pair
|
||||
# for host db.example.com with a 3-month validity period.
|
||||
|
||||
$ tctl auth sign --format=db --host=db.example.com --out=server --ttl=2190h
|
||||
|
||||
@@ -55,7 +55,7 @@ db_service:
|
||||
# on the Database Service.
|
||||
#
|
||||
# NOTE: for most deployments, it is recommended to use the Discovery Service
|
||||
# to register AWS databases instead of Database Service–based discovery.
|
||||
# to register Azure databases instead of Database Service–based discovery.
|
||||
azure:
|
||||
# Database types. Valid options are:
|
||||
# 'mysql' - discovers and registers Azure MySQL databases.
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
The Teleport Database Service needs permissions to automatically download
|
||||
your Cloud SQL instance's root CA certificate and to general an ephemeral
|
||||
your Cloud SQL instance's root CA certificate and to generate an ephemeral
|
||||
client certificate.
|
||||
|
||||
If you intend to download the CA certificate manually and your Cloud SQL
|
||||
|
||||
@@ -56,4 +56,4 @@ If any of the Database Service instances listed here **should not** proxy the
|
||||
database, (for example, a Database Service instance in a different VPC or AWS
|
||||
region without connectivity), locate and update their configurations so they
|
||||
only receive or discover databases they can reach. In most cases, you can
|
||||
achieve this by refining your tag filters, such as adding the a `vpc-id` label.
|
||||
achieve this by refining your tag filters, such as adding the `vpc-id` label.
|
||||
|
||||
@@ -3,6 +3,6 @@
|
||||
title="Tip"
|
||||
>
|
||||
A single Teleport process can run multiple services, for example
|
||||
multiple Database Service instances as well as other services such the
|
||||
SSH Service or Application Service.
|
||||
multiple Database Service instances as well as other services such as
|
||||
the SSH Service or Application Service.
|
||||
</Admonition>
|
||||
|
||||
@@ -53,8 +53,8 @@ ORA-28860: Fatal SSL error
|
||||
|
||||
To identify the root cause, follow the debugging steps in the sections below. The output of the following `openssl` command can help diagnose many common TLS issues. Capture the output and use it as you follow the debugging steps.
|
||||
|
||||
```
|
||||
> openssl s_client -connect oracle.example.com:2484 -showcerts
|
||||
```code
|
||||
$ openssl s_client -connect db.example.com:2484 -showcerts
|
||||
```
|
||||
|
||||
#### Wrong server certificate
|
||||
@@ -76,7 +76,7 @@ Compare the `issuer` in the server certificate with the `issuer` of the Teleport
|
||||
# openssl s_client output:
|
||||
...
|
||||
Server certificate
|
||||
subject=CN=oracle.example.com
|
||||
subject=CN=db.example.com
|
||||
issuer=O=teleport.example.com, CN=teleport.example.com, serialNumber=200129862304303044762346177566738813560
|
||||
...
|
||||
```
|
||||
@@ -92,7 +92,7 @@ The "User Certificates" section of the output should contain the server's certif
|
||||
|
||||
```
|
||||
User Certificates:
|
||||
Subject: CN=oracle.example.com
|
||||
Subject: CN=db.example.com
|
||||
Issuer: SERIALNUMBER=200129862304303044762346177566738813560,CN=teleport.example.com,O=teleport.example.com
|
||||
Serial Number: ...
|
||||
```
|
||||
@@ -191,4 +191,4 @@ SQL> SELECT username, authentication_type, external_name
|
||||
USERNAME AUTHENTICATION_TYPE EXTERNAL_NAME
|
||||
_____________ ______________________ ________________
|
||||
ALICE EXTERNAL cn=alice
|
||||
```
|
||||
```
|
||||
|
||||
@@ -29,7 +29,7 @@ the database, follow these instructions on your workstation:
|
||||
roles: ["Db"]
|
||||
```
|
||||
|
||||
1. Export Teleport's certificate authority and a generate certificate/key pair.
|
||||
1. Export Teleport's certificate authority and generate a certificate/key pair.
|
||||
This example generates a certificate with a 90-day validity period.
|
||||
`db.example.com` is the hostname where the Teleport Database Service can
|
||||
reach the {{ dbname }} server.
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
<Admonition type="note" title="TTL">
|
||||
We recommend using a shorter TTL, but keep mind that you'll need to update the
|
||||
We recommend using a shorter TTL, but keep in mind that you'll need to update the
|
||||
database server certificate before it expires to not lose the ability to
|
||||
connect. Pick the TTL value that best fits your use-case.
|
||||
</Admonition>
|
||||
|
||||
@@ -46,7 +46,7 @@ spec:
|
||||
# 'elasticache' - Amazon ElastiCache Redis and Valkey databases.
|
||||
# 'elasticache-serverless' - Amazon ElastiCache Serverless Redis or Valkey databases.
|
||||
# 'memorydb' - Amazon MemoryDB databases.
|
||||
# 'opensearch' - Amazon OpenSearch Redis databases.
|
||||
# 'opensearch' - Amazon OpenSearch databases.
|
||||
# 'docdb' - Amazon DocumentDB databases.
|
||||
- types: ["ec2"]
|
||||
# AWS regions to search for resources from
|
||||
|
||||
Reference in New Issue
Block a user