Remove remaining API aliases (#7137)

This commit is contained in:
Brian Joerger
2021-06-08 12:08:55 -07:00
committed by GitHub
parent 9410346b8d
commit 4d36870ff0
118 changed files with 985 additions and 998 deletions
+12 -10
View File
@@ -27,10 +27,6 @@ const (
// Namespace is default namespace
Namespace = "default"
// ServerKeepAliveTTL is a period between server keep-alives,
// when servers announce only presence without sending full data
ServerKeepAliveTTL = 60 * time.Second
// DefaultDialTimeout is a default TCP dial timeout we set for our
// connection attempts
DefaultDialTimeout = 30 * time.Second
@@ -46,12 +42,6 @@ const (
// CertDuration is a default certificate duration.
CertDuration = 12 * time.Hour
// KeepAliveInterval is interval at which Teleport will send keep-alive
// messages to the client. The default interval of 5 minutes (300 seconds) is
// set to help keep connections alive when using AWS NLBs (which have a default
// timeout of 350 seconds)
KeepAliveInterval = 5 * time.Minute
// ServerAnnounceTTL is a period between heartbeats
// Median sleep time between node pings is this value / 2 + random
// deviation added to this time to avoid lots of simultaneous
@@ -59,6 +49,18 @@ const (
ServerAnnounceTTL = 600 * time.Second
)
var (
// ServerKeepAliveTTL is a period between server keep-alives,
// when servers announce only presence without sending full data
ServerKeepAliveTTL = 60 * time.Second
// KeepAliveInterval is interval at which Teleport will send keep-alive
// messages to the client. The default interval of 5 minutes (300 seconds) is
// set to help keep connections alive when using AWS NLBs (which have a default
// timeout of 350 seconds)
KeepAliveInterval = 5 * time.Minute
)
// EnhancedEvents returns the default list of enhanced events.
func EnhancedEvents() []string {
return []string{
+1 -1
Submodule e updated: f74f54d23c...db6441154a
+3 -2
View File
@@ -22,6 +22,7 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib"
@@ -268,7 +269,7 @@ func waitForAuditEventTypeWithBackoff(t *testing.T, cli *auth.Server, startTime
t.Fatalf("failed to create linear backoff: %v", err)
}
for {
events, _, err := cli.SearchEvents(startTime, time.Now().Add(time.Hour), defaults.Namespace, []string{eventType}, 100, "")
events, _, err := cli.SearchEvents(startTime, time.Now().Add(time.Hour), apidefaults.Namespace, []string{eventType}, 100, "")
if err != nil {
t.Fatalf("failed to call SearchEvents: %v", err)
}
@@ -573,7 +574,7 @@ func (p *databasePack) waitForLeaf(t *testing.T) {
for {
select {
case <-time.Tick(500 * time.Millisecond):
servers, err := accessPoint.GetDatabaseServers(context.Background(), defaults.Namespace)
servers, err := accessPoint.GetDatabaseServers(context.Background(), apidefaults.Namespace)
if err != nil {
logrus.WithError(err).Debugf("Leaf cluster access point is unavailable.")
continue
+3 -2
View File
@@ -40,6 +40,7 @@ import (
"golang.org/x/crypto/ssh/agent"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/auth/native"
@@ -70,9 +71,9 @@ const (
// SetTestTimeouts affects global timeouts inside Teleport, making connections
// work faster but consuming more CPU (useful for integration testing)
func SetTestTimeouts(t time.Duration) {
defaults.KeepAliveInterval = t
apidefaults.KeepAliveInterval = t
defaults.ResyncInterval = t
defaults.ServerKeepAliveTTL = t
apidefaults.ServerKeepAliveTTL = t
defaults.SessionRefreshPeriod = t
defaults.HeartbeatCheckPeriod = t
defaults.CachePollPeriod = t
+25 -23
View File
@@ -43,8 +43,10 @@ import (
"golang.org/x/crypto/ssh"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/profile"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/api/utils/keypaths"
"github.com/gravitational/teleport/lib"
"github.com/gravitational/teleport/lib/auth"
@@ -305,7 +307,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
for {
select {
case <-tickCh:
nodesInSite, err := site.GetNodes(ctx, defaults.Namespace)
nodesInSite, err := site.GetNodes(ctx, apidefaults.Namespace)
if err != nil && !trace.IsNotFound(err) {
return trace.Wrap(err)
}
@@ -321,7 +323,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
require.NoError(t, err)
// should have no sessions:
sessions, err := site.GetSessions(defaults.Namespace)
sessions, err := site.GetSessions(apidefaults.Namespace)
require.NoError(t, err)
require.Empty(t, sessions)
@@ -351,7 +353,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
for {
select {
case <-tickCh:
sessions, err = site.GetSessions(defaults.Namespace)
sessions, err = site.GetSessions(apidefaults.Namespace)
if err != nil {
return nil, trace.Wrap(err)
}
@@ -370,7 +372,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
// wait for the user to join this session:
for len(session.Parties) == 0 {
time.Sleep(time.Millisecond * 5)
session, err = site.GetSession(defaults.Namespace, sessions[0].ID)
session, err = site.GetSession(apidefaults.Namespace, sessions[0].ID)
require.NoError(t, err)
}
// make sure it's us who joined! :)
@@ -409,7 +411,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
// everything because the session is closing)
var sessionStream []byte
for i := 0; i < 6; i++ {
sessionStream, err = site.GetSessionChunk(defaults.Namespace, session.ID, 0, events.MaxChunkBytes)
sessionStream, err = site.GetSessionChunk(apidefaults.Namespace, session.ID, 0, events.MaxChunkBytes)
require.NoError(t, err)
if strings.Contains(string(sessionStream), "exit") {
break
@@ -441,7 +443,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
select {
case <-tickCh:
// Get all session events from the backend.
sessionEvents, err := site.GetSessionEvents(defaults.Namespace, session.ID, 0, false)
sessionEvents, err := site.GetSessionEvents(apidefaults.Namespace, session.ID, 0, false)
if err != nil {
return nil, trace.Wrap(err)
}
@@ -763,7 +765,7 @@ func testUUIDBasedProxy(t *testing.T, suite *integrationTestSuite) {
for {
select {
case <-tickCh:
nodesInSite, err := site.GetNodes(ctx, defaults.Namespace)
nodesInSite, err := site.GetNodes(ctx, apidefaults.Namespace)
if err != nil && !trace.IsNotFound(err) {
return trace.Wrap(err)
}
@@ -914,7 +916,7 @@ func verifySessionJoin(t *testing.T, username string, teleport *TeleInstance) {
var sessionID string
for {
time.Sleep(time.Millisecond)
sessions, _ := site.GetSessions(defaults.Namespace)
sessions, _ := site.GetSessions(apidefaults.Namespace)
if len(sessions) == 0 {
continue
}
@@ -925,7 +927,7 @@ func verifySessionJoin(t *testing.T, username string, teleport *TeleInstance) {
require.NoError(t, err)
cl.Stdout = personB
for i := 0; i < 10; i++ {
err = cl.Join(context.TODO(), defaults.Namespace, session.ID(sessionID), personB)
err = cl.Join(context.TODO(), apidefaults.Namespace, session.ID(sessionID), personB)
if err == nil {
break
}
@@ -1126,7 +1128,7 @@ func testDisconnectScenarios(t *testing.T, suite *integrationTestSuite) {
var ss []session.Session
for i := 0; i < 6; i++ {
ss, err = site.GetSessions(defaults.Namespace)
ss, err = site.GetSessions(apidefaults.Namespace)
if err == nil && len(ss) > 0 {
break
}
@@ -1511,7 +1513,7 @@ func twoClustersTunnel(t *testing.T, suite *integrationTestSuite, now time.Time,
for {
select {
case <-tickCh:
eventsInSite, _, err := site.SearchEvents(now, now.Add(1*time.Hour), defaults.Namespace, eventTypes, 0, "")
eventsInSite, _, err := site.SearchEvents(now, now.Add(1*time.Hour), apidefaults.Namespace, eventTypes, 0, "")
if err != nil {
return trace.Wrap(err)
}
@@ -1761,7 +1763,7 @@ func testMapRoles(t *testing.T, suite *integrationTestSuite) {
// correct nodes that identity aware GetNodes is done in TestList.
var nodes []types.Server
for i := 0; i < 10; i++ {
nodes, err = aux.Process.GetAuthServer().GetNodes(ctx, defaults.Namespace)
nodes, err = aux.Process.GetAuthServer().GetNodes(ctx, apidefaults.Namespace)
require.NoError(t, err)
if len(nodes) != 2 {
time.Sleep(100 * time.Millisecond)
@@ -2798,7 +2800,7 @@ func waitForNodeCount(ctx context.Context, t *TeleInstance, clusterName string,
if err != nil {
return trace.Wrap(err)
}
nodes, err := accessPoint.GetNodes(ctx, defaults.Namespace)
nodes, err := accessPoint.GetNodes(ctx, apidefaults.Namespace)
if err != nil {
return trace.Wrap(err)
}
@@ -3158,7 +3160,7 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) {
require.NotNil(t, site)
// should have no sessions in it to start with
sessions, _ := site.GetSessions(defaults.Namespace)
sessions, _ := site.GetSessions(apidefaults.Namespace)
require.Len(t, sessions, 0)
// create interactive session (this goroutine is this user's terminal time)
@@ -3182,7 +3184,7 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) {
// wait until there's a session in there:
for i := 0; len(sessions) == 0; i++ {
time.Sleep(time.Millisecond * 20)
sessions, _ = site.GetSessions(defaults.Namespace)
sessions, _ = site.GetSessions(apidefaults.Namespace)
if i > 100 {
t.Fatalf("Waited %v, but no sessions found", 100*20*time.Millisecond)
return
@@ -3193,7 +3195,7 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) {
// wait for the user to join this session
for len(session.Parties) == 0 {
time.Sleep(time.Millisecond * 5)
session, err = site.GetSession(defaults.Namespace, sessions[0].ID)
session, err = site.GetSession(apidefaults.Namespace, sessions[0].ID)
require.NoError(t, err)
}
// make sure it's us who joined! :)
@@ -3210,13 +3212,13 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) {
}
// audit log should have the fact that the session occurred recorded in it
sessions, err = site.GetSessions(defaults.Namespace)
sessions, err = site.GetSessions(apidefaults.Namespace)
require.NoError(t, err)
require.Len(t, sessions, 1)
// however, attempts to read the actual sessions should fail because it was
// not actually recorded
_, err = site.GetSessionChunk(defaults.Namespace, session.ID, 0, events.MaxChunkBytes)
_, err = site.GetSessionChunk(apidefaults.Namespace, session.ID, 0, events.MaxChunkBytes)
require.Error(t, err)
}
@@ -4166,7 +4168,7 @@ func testWindowChange(t *testing.T, suite *integrationTestSuite) {
var sessionID string
for {
time.Sleep(time.Millisecond)
sessions, _ := site.GetSessions(defaults.Namespace)
sessions, _ := site.GetSessions(apidefaults.Namespace)
if len(sessions) == 0 {
continue
}
@@ -4195,7 +4197,7 @@ func testWindowChange(t *testing.T, suite *integrationTestSuite) {
}
for i := 0; i < 10; i++ {
err = cl.Join(context.TODO(), defaults.Namespace, session.ID(sessionID), personB)
err = cl.Join(context.TODO(), apidefaults.Namespace, session.ID(sessionID), personB)
if err == nil {
break
}
@@ -4308,7 +4310,7 @@ func testList(t *testing.T, suite *integrationTestSuite) {
for {
select {
case <-tickCh:
nodesInCluster, err := clt.GetNodes(ctx, defaults.Namespace)
nodesInCluster, err := clt.GetNodes(ctx, apidefaults.Namespace)
if err != nil && !trace.IsNotFound(err) {
return trace.Wrap(err)
}
@@ -4383,7 +4385,7 @@ func testList(t *testing.T, suite *integrationTestSuite) {
nodes, err := userClt.ListNodes(context.Background())
require.NoError(t, err)
for _, node := range nodes {
ok := utils.SliceContainsStr(tt.outNodes, node.GetHostname())
ok := apiutils.SliceContainsStr(tt.outNodes, node.GetHostname())
if !ok {
t.Fatalf("Got nodes: %v, want: %v.", nodes, tt.outNodes)
}
@@ -5393,7 +5395,7 @@ func TestTraitsPropagation(t *testing.T) {
role.SetName("test")
role.SetLogins(services.Allow, []string{me.Username})
// Users created by CreateEx have "testing: integration" trait.
role.SetNodeLabels(services.Allow, map[string]utils.Strings{"env": []string{"{{external.testing}}"}})
role.SetNodeLabels(services.Allow, map[string]apiutils.Strings{"env": []string{"{{external.testing}}"}})
rc.AddUserWithRole(me.Username, role)
lc.AddUserWithRole(me.Username, role)
+4 -4
View File
@@ -34,11 +34,11 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/profile"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib"
"github.com/gravitational/teleport/lib/auth/testauthority"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
kubeproxy "github.com/gravitational/teleport/lib/kube/proxy"
kubeutils "github.com/gravitational/teleport/lib/kube/utils"
@@ -294,7 +294,7 @@ loop:
}
// read back the entire session and verify that it matches the stated output
capturedStream, err := teleport.Process.GetAuthServer().GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
capturedStream, err := teleport.Process.GetAuthServer().GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
require.NoError(t, err)
require.Equal(t, sessionStream, string(capturedStream))
@@ -668,7 +668,7 @@ loop:
}
// read back the entire session and verify that it matches the stated output
capturedStream, err := main.Process.GetAuthServer().GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
capturedStream, err := main.Process.GetAuthServer().GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
require.NoError(t, err)
require.Equal(t, sessionStream, string(capturedStream))
@@ -926,7 +926,7 @@ loop:
}
// read back the entire session and verify that it matches the stated output
capturedStream, err := main.Process.GetAuthServer().GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
capturedStream, err := main.Process.GetAuthServer().GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
require.NoError(t, err)
require.Equal(t, sessionStream, string(capturedStream))
+2 -2
View File
@@ -24,10 +24,10 @@ import (
"time"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/bpf"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/pam"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/srv/regular"
@@ -212,7 +212,7 @@ func newSrvCtx(t *testing.T) *SrvCtx {
"",
utils.NetAddr{},
regular.SetUUID(s.nodeID),
regular.SetNamespace(defaults.Namespace),
regular.SetNamespace(apidefaults.Namespace),
regular.SetEmitter(s.nodeClient),
regular.SetShell("/bin/sh"),
regular.SetSessionServer(s.nodeClient),
+4 -3
View File
@@ -30,6 +30,7 @@ import (
"time"
"github.com/gravitational/teleport/api/client/proto"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
@@ -66,10 +67,10 @@ type APIConfig struct {
// CheckAndSetDefaults checks and sets default values
func (a *APIConfig) CheckAndSetDefaults() error {
if a.KeepAlivePeriod == 0 {
a.KeepAlivePeriod = defaults.ServerKeepAliveTTL
a.KeepAlivePeriod = apidefaults.ServerKeepAliveTTL
}
if a.KeepAliveCount == 0 {
a.KeepAliveCount = defaults.KeepAliveCountMax
a.KeepAliveCount = apidefaults.KeepAliveCountMax
}
return nil
}
@@ -1813,7 +1814,7 @@ func (s *APIServer) searchEvents(auth ClientI, w http.ResponseWriter, r *http.Re
}
eventTypes := query[events.EventType]
eventsList, _, err := auth.SearchEvents(from, to, defaults.Namespace, eventTypes, limit, "")
eventsList, _, err := auth.SearchEvents(from, to, apidefaults.Namespace, eventTypes, limit, "")
if err != nil {
return nil, trace.Wrap(err)
}
+10 -10
View File
@@ -24,8 +24,8 @@ import (
"net/http/httptest"
"testing"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/services"
"github.com/google/go-cmp/cmp"
@@ -50,13 +50,13 @@ func TestUpsertServer(t *testing.T) {
{
desc: "node",
reqServer: &types.ServerV2{
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
Version: types.V2,
Kind: types.KindNode,
},
role: types.RoleNode,
wantServer: &types.ServerV2{
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
Version: types.V2,
Kind: types.KindNode,
},
@@ -65,13 +65,13 @@ func TestUpsertServer(t *testing.T) {
{
desc: "proxy",
reqServer: &types.ServerV2{
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
Version: types.V2,
Kind: types.KindProxy,
},
role: types.RoleProxy,
wantServer: &types.ServerV2{
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
Version: types.V2,
Kind: types.KindProxy,
},
@@ -80,13 +80,13 @@ func TestUpsertServer(t *testing.T) {
{
desc: "auth",
reqServer: &types.ServerV2{
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
Version: types.V2,
Kind: types.KindAuthServer,
},
role: types.RoleAuth,
wantServer: &types.ServerV2{
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
Version: types.V2,
Kind: types.KindAuthServer,
},
@@ -95,7 +95,7 @@ func TestUpsertServer(t *testing.T) {
{
desc: "unknown",
reqServer: &types.ServerV2{
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
Version: types.V2,
Kind: types.KindNode,
},
@@ -118,7 +118,7 @@ func TestUpsertServer(t *testing.T) {
req := httptest.NewRequest(http.MethodPost, "http://localhost", bytes.NewReader(body))
req.RemoteAddr = remoteAddr
_, err = new(APIServer).upsertServer(s, tt.role, req, httprouter.Params{httprouter.Param{Key: "namespace", Value: defaults.Namespace}})
_, err = new(APIServer).upsertServer(s, tt.role, req, httprouter.Params{httprouter.Param{Key: "namespace", Value: apidefaults.Namespace}})
tt.assertErr(t, err)
if err != nil {
return
@@ -131,7 +131,7 @@ func TestUpsertServer(t *testing.T) {
allServers = append(allServers, servers...)
}
addServers(s.GetAuthServers())
addServers(s.GetNodes(ctx, defaults.Namespace))
addServers(s.GetNodes(ctx, apidefaults.Namespace))
addServers(s.GetProxies())
require.Empty(t, cmp.Diff(allServers, []types.Server{tt.wantServer}, cmpopts.IgnoreFields(types.Metadata{}, "ID")))
})
+13 -12
View File
@@ -40,6 +40,7 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/client/proto"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/api/types/wrappers"
@@ -317,7 +318,7 @@ func (a *Server) runPeriodicOperations() {
ticker := time.NewTicker(period)
// Create a ticker with jitter
heartbeatCheckTicker := interval.New(interval.Config{
Duration: defaults.ServerKeepAliveTTL * 2,
Duration: apidefaults.ServerKeepAliveTTL * 2,
Jitter: utils.NewSeventhJitter(),
})
missedKeepAliveCount := 0
@@ -337,7 +338,7 @@ func (a *Server) runPeriodicOperations() {
}
}
case <-heartbeatCheckTicker.Next():
nodes, err := a.GetNodes(ctx, defaults.Namespace)
nodes, err := a.GetNodes(ctx, apidefaults.Namespace)
if err != nil {
log.Errorf("Failed to load nodes for heartbeat metric calculation: %v", err)
}
@@ -876,7 +877,7 @@ func (a *Server) WithUserLock(username string, authenticateFn func() error) erro
status := user.GetStatus()
if status.IsLocked && status.LockExpires.After(a.clock.Now().UTC()) {
return trace.AccessDenied("%v exceeds %v failed login attempts, locked until %v",
user.GetName(), defaults.MaxLoginAttempts, utils.HumanTimeFormat(status.LockExpires))
user.GetName(), defaults.MaxLoginAttempts, apiutils.HumanTimeFormat(status.LockExpires))
}
fnErr := authenticateFn()
if fnErr == nil {
@@ -910,7 +911,7 @@ func (a *Server) WithUserLock(username string, authenticateFn func() error) erro
}
lockUntil := a.clock.Now().UTC().Add(defaults.AccountLockInterval)
message := fmt.Sprintf("%v exceeds %v failed login attempts, locked until %v",
username, defaults.MaxLoginAttempts, utils.HumanTimeFormat(status.LockExpires))
username, defaults.MaxLoginAttempts, apiutils.HumanTimeFormat(status.LockExpires))
log.Debug(message)
user.SetLocked(lockUntil, "user has exceeded maximum failed login attempts")
err = a.Identity.UpsertUser(user)
@@ -1043,7 +1044,7 @@ func (a *Server) ExtendWebSession(req WebSessionReq, identity tlsca.Identity) (t
}
roles = append(roles, newRoles...)
roles = utils.Deduplicate(roles)
roles = apiutils.Deduplicate(roles)
// Let session expire with the shortest expiry time.
if expiresAt.After(requestExpiry) {
@@ -1068,7 +1069,7 @@ func (a *Server) ExtendWebSession(req WebSessionReq, identity tlsca.Identity) (t
return nil, trace.Wrap(err)
}
sessionTTL := roleSet.AdjustSessionTTL(defaults.CertDuration)
sessionTTL := roleSet.AdjustSessionTTL(apidefaults.CertDuration)
// Set default roles and expiration.
expiresAt = prevSession.GetLoginTime().UTC().Add(sessionTTL)
@@ -1317,7 +1318,7 @@ func (a *Server) GenerateServerKeys(req GenerateServerKeysRequest) (*PackedKeys,
// If the request contains 0.0.0.0, this implies an advertise IP was not
// specified on the node. Try and guess what the address by replacing 0.0.0.0
// with the RemoteAddr as known to the Auth Server.
if utils.SliceContainsStr(req.AdditionalPrincipals, defaults.AnyAddress) {
if apiutils.SliceContainsStr(req.AdditionalPrincipals, defaults.AnyAddress) {
remoteHost, err := utils.Host(req.RemoteAddr)
if err != nil {
return nil, trace.Wrap(err)
@@ -1672,7 +1673,7 @@ func (a *Server) NewWebSession(req types.NewWebSessionRequest) (types.WebSession
}
sessionTTL := req.SessionTTL
if sessionTTL == 0 {
sessionTTL = checker.AdjustSessionTTL(defaults.CertDuration)
sessionTTL = checker.AdjustSessionTTL(apidefaults.CertDuration)
}
certs, err := a.generateUserCert(certRequest{
user: user,
@@ -1726,7 +1727,7 @@ func (a *Server) GetWebSessionInfo(ctx context.Context, user, sessionID string)
func (a *Server) DeleteNamespace(namespace string) error {
ctx := context.TODO()
if namespace == defaults.Namespace {
if namespace == apidefaults.Namespace {
return trace.AccessDenied("can't delete default namespace")
}
nodes, err := a.Presence.GetNodes(ctx, namespace)
@@ -2168,7 +2169,7 @@ func (a *Server) isMFARequired(ctx context.Context, checker services.AccessCheck
return nil, trace.BadParameter("empty Login field")
}
// Find the target node and check whether MFA is required.
nodes, err := a.GetNodes(ctx, defaults.Namespace)
nodes, err := a.GetNodes(ctx, apidefaults.Namespace)
if err != nil {
return nil, trace.Wrap(err)
}
@@ -2229,14 +2230,14 @@ func (a *Server) isMFARequired(ctx context.Context, checker services.AccessCheck
if cluster == nil {
return nil, trace.Wrap(notFoundErr)
}
noMFAAccessErr = checker.CheckAccessToKubernetes(defaults.Namespace, cluster, services.AccessMFAParams{AlwaysRequired: false, Verified: false})
noMFAAccessErr = checker.CheckAccessToKubernetes(apidefaults.Namespace, cluster, services.AccessMFAParams{AlwaysRequired: false, Verified: false})
case *proto.IsMFARequiredRequest_Database:
notFoundErr = trace.NotFound("database service %q not found", t.Database.ServiceName)
if t.Database.ServiceName == "" {
return nil, trace.BadParameter("missing ServiceName field in a database-only UserCertsRequest")
}
dbs, err := a.GetDatabaseServers(ctx, defaults.Namespace)
dbs, err := a.GetDatabaseServers(ctx, apidefaults.Namespace)
if err != nil {
return nil, trace.Wrap(err)
}
+2 -1
View File
@@ -35,6 +35,7 @@ import (
"github.com/gravitational/teleport/api/constants"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/api/utils/sshutils"
"github.com/gravitational/teleport/lib/auth/testauthority"
authority "github.com/gravitational/teleport/lib/auth/testauthority"
@@ -577,7 +578,7 @@ func (s *AuthSuite) TestTokensCRUD(c *C) {
hostCert, err := sshutils.ParseCertificate(keys.Cert)
c.Assert(err, IsNil)
comment := Commentf("can't find example.com in %v", hostCert.ValidPrincipals)
c.Assert(utils.SliceContainsStr(hostCert.ValidPrincipals, "example.com"), Equals, true, comment)
c.Assert(apiutils.SliceContainsStr(hostCert.ValidPrincipals, "example.com"), Equals, true, comment)
_, err = s.a.RegisterUsingToken(RegisterUsingTokenRequest{
Token: multiUseToken,
File diff suppressed because it is too large Load Diff
+4 -9
View File
@@ -35,6 +35,7 @@ import (
"github.com/gravitational/teleport/api/client"
"github.com/gravitational/teleport/api/client/proto"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/auth/u2f"
@@ -58,12 +59,6 @@ const (
MissingNamespaceError = "missing required parameter: namespace"
)
// ContextDialer type alias for backwards compatibility
type ContextDialer = client.ContextDialer
// ContextDialerFunc type alias for backwards compatibility
type ContextDialerFunc = client.ContextDialerFunc
// Client is the Auth API client. It works by connecting to auth servers
// via gRPC and HTTP.
//
@@ -133,7 +128,7 @@ func NewHTTPClient(cfg client.Config, tls *tls.Config, params ...roundtrip.Clien
return nil, trace.BadParameter("no addresses to dial")
}
contextDialer := client.NewDirectDialer(cfg.KeepAlivePeriod, cfg.DialTimeout)
dialer = ContextDialerFunc(func(ctx context.Context, network, _ string) (conn net.Conn, err error) {
dialer = client.ContextDialerFunc(func(ctx context.Context, network, _ string) (conn net.Conn, err error) {
for _, addr := range cfg.Addrs {
conn, err = contextDialer.DialContext(ctx, network, addr)
if err == nil {
@@ -158,7 +153,7 @@ func NewHTTPClient(cfg client.Config, tls *tls.Config, params ...roundtrip.Clien
// custom DialContext overrides this DNS name to the real address.
// In addition this dialer tries multiple addresses if provided
DialContext: dialer.DialContext,
ResponseHeaderTimeout: defaults.DefaultDialTimeout,
ResponseHeaderTimeout: apidefaults.DefaultDialTimeout,
TLSClientConfig: tls,
// Increase the size of the connection pool. This substantially improves the
@@ -222,7 +217,7 @@ type ClientConfig struct {
// Addrs is a list of addresses to dial
Addrs []utils.NetAddr
// Dialer is a custom dialer that is used instead of Addrs when provided
Dialer ContextDialer
Dialer client.ContextDialer
// DialTimeout defines how long to attempt dialing before timing out
DialTimeout time.Duration
// KeepAlivePeriod defines period between keep alives
+2 -2
View File
@@ -22,8 +22,8 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/client/proto"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/modules"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/tlsca"
@@ -130,7 +130,7 @@ func (s *Server) SignDatabaseCSR(ctx context.Context, req *proto.DatabaseCSRRequ
}
// Get the correct cert TTL based on roles.
ttl := roles.AdjustSessionTTL(defaults.CertDuration)
ttl := roles.AdjustSessionTTL(apidefaults.CertDuration)
// Generate the TLS certificate.
userCA, err := s.Trust.GetCertAuthority(types.CertAuthID{
+3 -2
View File
@@ -26,6 +26,7 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
@@ -364,7 +365,7 @@ func (a *Server) calculateGithubUser(connector types.GithubConnector, claims *ty
if err != nil {
return nil, trace.Wrap(err)
}
roleTTL := roles.AdjustSessionTTL(defaults.MaxCertDuration)
roleTTL := roles.AdjustSessionTTL(apidefaults.MaxCertDuration)
p.sessionTTL = utils.MinTTL(roleTTL, request.CertTTL)
return &p, nil
@@ -383,7 +384,7 @@ func (a *Server) createGithubUser(p *createUserParams) (types.User, error) {
Version: types.V2,
Metadata: types.Metadata{
Name: p.username,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Expires: &expires,
},
Spec: types.UserSpecV2{
+3 -3
View File
@@ -28,11 +28,11 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/client"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
authority "github.com/gravitational/teleport/lib/auth/testauthority"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/memory"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/limiter"
"github.com/gravitational/teleport/lib/services"
@@ -82,13 +82,13 @@ func CreateUploaderDir(dir string) error {
// DELETE IN(5.1.0)
// this folder is no longer used past 5.0 upgrade
err := os.MkdirAll(filepath.Join(dir, teleport.LogsDir, teleport.ComponentUpload,
events.SessionLogsDir, defaults.Namespace), teleport.SharedDirMode)
events.SessionLogsDir, apidefaults.Namespace), teleport.SharedDirMode)
if err != nil {
return trace.ConvertSystemError(err)
}
err = os.MkdirAll(filepath.Join(dir, teleport.LogsDir, teleport.ComponentUpload,
events.StreamingLogsDir, defaults.Namespace), teleport.SharedDirMode)
events.StreamingLogsDir, apidefaults.Namespace), teleport.SharedDirMode)
if err != nil {
return trace.ConvertSystemError(err)
}
+7 -6
View File
@@ -29,6 +29,7 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
apisshutils "github.com/gravitational/teleport/api/utils/sshutils"
@@ -308,11 +309,11 @@ func Init(cfg InitConfig, opts ...ServerOption) (*Server, error) {
log.Infof("Updating cluster configuration: %v.", cfg.StaticTokens)
// always create the default namespace
err = asrv.UpsertNamespace(types.NewNamespace(defaults.Namespace))
err = asrv.UpsertNamespace(types.NewNamespace(apidefaults.Namespace))
if err != nil {
return nil, trace.Wrap(err)
}
log.Infof("Created namespace: %q.", defaults.Namespace)
log.Infof("Created namespace: %q.", apidefaults.Namespace)
// always create a default admin role
defaultRole := services.NewAdminRole()
@@ -354,7 +355,7 @@ func Init(cfg InitConfig, opts ...ServerOption) (*Server, error) {
Version: types.V2,
Metadata: types.Metadata{
Name: cfg.ClusterName.GetClusterName(),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.CertAuthoritySpecV2{
ClusterName: cfg.ClusterName.GetClusterName(),
@@ -414,7 +415,7 @@ func Init(cfg InitConfig, opts ...ServerOption) (*Server, error) {
Version: types.V2,
Metadata: types.Metadata{
Name: cfg.ClusterName.GetClusterName(),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.CertAuthoritySpecV2{
ClusterName: cfg.ClusterName.GetClusterName(),
@@ -1015,7 +1016,7 @@ func (i *Identity) SSHClientConfig() *ssh.ClientConfig {
ssh.PublicKeys(i.KeySigner),
},
HostKeyCallback: i.hostKeyCallback,
Timeout: defaults.DefaultDialTimeout,
Timeout: apidefaults.DefaultDialTimeout,
}
}
@@ -1287,7 +1288,7 @@ func migrateRoleOptions(ctx context.Context, asrv *Server) error {
options := role.GetOptions()
if options.BPF == nil {
log.Debugf("Migrating role %v. Added default enhanced events.", role.GetName())
options.BPF = defaults.EnhancedEvents()
options.BPF = apidefaults.EnhancedEvents()
} else {
continue
}
+2 -2
View File
@@ -20,8 +20,8 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/modules"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/tlsca"
@@ -128,7 +128,7 @@ func (s *Server) ProcessKubeCSR(req KubeCSR) (*KubeCSRResponse, error) {
return nil, trace.Wrap(err)
}
// Get the correct cert TTL based on roles.
ttl := roles.AdjustSessionTTL(defaults.CertDuration)
ttl := roles.AdjustSessionTTL(apidefaults.CertDuration)
userCA, err := s.Trust.GetCertAuthority(types.CertAuthID{
Type: types.UserCA,
+3 -3
View File
@@ -26,12 +26,12 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/limiter"
"github.com/gravitational/teleport/lib/multiplexer"
"github.com/gravitational/teleport/lib/tlsca"
"github.com/gravitational/teleport/lib/utils"
"github.com/gravitational/trace"
"github.com/gravitational/trace/trail"
@@ -144,7 +144,7 @@ func NewTLSServer(cfg TLSServerConfig) (*TLSServer, error) {
cfg: cfg,
httpServer: &http.Server{
Handler: limiter,
ReadHeaderTimeout: defaults.DefaultDialTimeout,
ReadHeaderTimeout: apidefaults.DefaultDialTimeout,
},
log: logrus.WithFields(logrus.Fields{
trace.Component: cfg.Component,
+3 -2
View File
@@ -31,6 +31,7 @@ import (
"github.com/gravitational/teleport/api/constants"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/api/types/wrappers"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/sshutils"
"github.com/gravitational/teleport/lib/utils"
@@ -207,7 +208,7 @@ func (k *Keygen) GenerateHostCertWithoutValidation(c services.HostCertParams) ([
return nil, trace.BadParameter("no principals provided: %v, %v, %v",
c.HostID, c.NodeName, c.Principals)
}
principals = utils.Deduplicate(principals)
principals = apiutils.Deduplicate(principals)
// create certificate
validBefore := uint64(ssh.CertTimeInfinity)
@@ -370,5 +371,5 @@ func BuildPrincipals(hostID string, nodeName string, clusterName string, roles t
)
// deduplicate (in-case hostID and nodeName are the same) and return
return utils.Deduplicate(principals)
return apiutils.Deduplicate(principals)
}
+5 -3
View File
@@ -26,8 +26,10 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/services"
@@ -124,7 +126,7 @@ func oidcConfig(conn types.OIDCConnector) oidc.ClientConfig {
Secret: conn.GetClientSecret(),
},
// open id notifies provider that we are using OIDC scopes
Scope: utils.Deduplicate(append([]string{"openid", "email"}, conn.GetScope()...)),
Scope: apiutils.Deduplicate(append([]string{"openid", "email"}, conn.GetScope()...)),
}
}
@@ -452,7 +454,7 @@ func (a *Server) calculateOIDCUser(connector types.OIDCConnector, claims jose.Cl
if err != nil {
return nil, trace.Wrap(err)
}
roleTTL := roles.AdjustSessionTTL(defaults.MaxCertDuration)
roleTTL := roles.AdjustSessionTTL(apidefaults.MaxCertDuration)
p.sessionTTL = utils.MinTTL(roleTTL, request.CertTTL)
return &p, nil
@@ -467,7 +469,7 @@ func (a *Server) createOIDCUser(p *createUserParams) (types.User, error) {
Version: types.V2,
Metadata: types.Metadata{
Name: p.username,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Expires: &expires,
},
Spec: types.UserSpecV2{
+3 -2
View File
@@ -28,6 +28,7 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
@@ -166,7 +167,7 @@ func (a *Server) calculateSAMLUser(connector types.SAMLConnector, assertionInfo
if err != nil {
return nil, trace.Wrap(err)
}
roleTTL := roles.AdjustSessionTTL(defaults.MaxCertDuration)
roleTTL := roles.AdjustSessionTTL(apidefaults.MaxCertDuration)
p.sessionTTL = utils.MinTTL(roleTTL, request.CertTTL)
return &p, nil
@@ -182,7 +183,7 @@ func (a *Server) createSAMLUser(p *createUserParams) (types.User, error) {
Version: types.V2,
Metadata: types.Metadata{
Name: p.username,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Expires: &expires,
},
Spec: types.UserSpecV2{
+54 -52
View File
@@ -41,8 +41,10 @@ import (
"github.com/gravitational/teleport/api/client"
"github.com/gravitational/teleport/api/client/proto"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/api/utils/sshutils"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
@@ -110,7 +112,7 @@ func (s *TLSSuite) TestRemoteBuiltinRole(c *check.C) {
// certificate authority is not recognized, because
// the trust has not been established yet
_, err = remoteProxy.GetNodes(ctx, defaults.Namespace)
_, err = remoteProxy.GetNodes(ctx, apidefaults.Namespace)
fixtures.ExpectConnectionProblem(c, err)
// after trust is established, things are good
@@ -122,7 +124,7 @@ func (s *TLSSuite) TestRemoteBuiltinRole(c *check.C) {
TestBuiltin(types.RoleProxy), s.server.Addr(), certPool)
c.Assert(err, check.IsNil)
_, err = remoteProxy.GetNodes(ctx, defaults.Namespace)
_, err = remoteProxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// remote auth server will get rejected even with established trust
@@ -160,7 +162,7 @@ func (s *TLSSuite) TestAcceptedUsage(c *check.C) {
// certificate authority is not recognized, because
// the trust has not been established yet
_, err = client.GetNodes(ctx, defaults.Namespace)
_, err = client.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// restricted clients can use restricted servers if restrictions
@@ -170,7 +172,7 @@ func (s *TLSSuite) TestAcceptedUsage(c *check.C) {
client, err = tlsServer.NewClient(identity)
c.Assert(err, check.IsNil)
_, err = client.GetNodes(ctx, defaults.Namespace)
_, err = client.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// restricted clients can will be rejected if usage does not match
@@ -179,7 +181,7 @@ func (s *TLSSuite) TestAcceptedUsage(c *check.C) {
client, err = tlsServer.NewClient(identity)
c.Assert(err, check.IsNil)
_, err = client.GetNodes(ctx, defaults.Namespace)
_, err = client.GetNodes(ctx, apidefaults.Namespace)
fixtures.ExpectAccessDenied(c, err)
// restricted clients can will be rejected, for now if there is any mismatch,
@@ -189,7 +191,7 @@ func (s *TLSSuite) TestAcceptedUsage(c *check.C) {
client, err = tlsServer.NewClient(identity)
c.Assert(err, check.IsNil)
_, err = client.GetNodes(ctx, defaults.Namespace)
_, err = client.GetNodes(ctx, apidefaults.Namespace)
fixtures.ExpectAccessDenied(c, err)
}
@@ -288,11 +290,11 @@ func (s *TLSSuite) TestRemoteRotation(c *check.C) {
TestBuiltin(types.RoleProxy), s.server.Addr(), certPool)
c.Assert(err, check.IsNil)
_, err = newRemoteProxy.GetNodes(ctx, defaults.Namespace)
_, err = newRemoteProxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// old proxy client is still trusted
_, err = s.server.CloneClient(remoteProxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(remoteProxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
}
@@ -344,7 +346,7 @@ func (s *TLSSuite) TestAutoRotation(c *check.C) {
c.Assert(err, check.IsNil)
// client works before rotation is initiated
_, err = proxy.GetNodes(ctx, defaults.Namespace)
_, err = proxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// starts rotation
@@ -371,7 +373,7 @@ func (s *TLSSuite) TestAutoRotation(c *check.C) {
c.Assert(ca.GetRotation().Phase, check.Equals, types.RotationPhaseUpdateClients)
// old clients should work
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// new clients work as well
@@ -391,14 +393,14 @@ func (s *TLSSuite) TestAutoRotation(c *check.C) {
c.Assert(ca.GetRotation().Phase, check.Equals, types.RotationPhaseUpdateServers)
// old clients should work
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// new clients work as well
newProxy, err := s.server.NewClient(TestBuiltin(types.RoleProxy))
c.Assert(err, check.IsNil)
_, err = newProxy.GetNodes(ctx, defaults.Namespace)
_, err = newProxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// complete rotation - advance rotation by clock
@@ -418,11 +420,11 @@ func (s *TLSSuite) TestAutoRotation(c *check.C) {
// connection instead of re-using the one from pool
// this is not going to be a problem in real teleport
// as it reloads the full server after reload
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.ErrorMatches, ".*bad certificate.*")
// new clients work
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
}
@@ -438,7 +440,7 @@ func (s *TLSSuite) TestAutoFallback(c *check.C) {
c.Assert(err, check.IsNil)
// client works before rotation is initiated
_, err = proxy.GetNodes(ctx, defaults.Namespace)
_, err = proxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// starts rotation
@@ -494,7 +496,7 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
c.Assert(err, check.IsNil)
// client works before rotation is initiated
_, err = proxy.GetNodes(ctx, defaults.Namespace)
_, err = proxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// can't jump to mid-phase
@@ -519,7 +521,7 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
c.Assert(err, check.IsNil)
// old clients should work
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// clients reconnect
@@ -532,14 +534,14 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
c.Assert(err, check.IsNil)
// old clients should work
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// new clients work as well
newProxy, err := s.server.NewClient(TestBuiltin(types.RoleProxy))
c.Assert(err, check.IsNil)
_, err = newProxy.GetNodes(ctx, defaults.Namespace)
_, err = newProxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// can't jump to standy
@@ -561,11 +563,11 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
c.Assert(err, check.IsNil)
// old clients should work
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// new clients work as well
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// complete rotation
@@ -582,11 +584,11 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
// connection instead of re-using the one from pool
// this is not going to be a problem in real teleport
// as it reloads the full server after reload
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.ErrorMatches, ".*bad certificate.*")
// new clients work
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
}
@@ -600,7 +602,7 @@ func (s *TLSSuite) TestRollback(c *check.C) {
c.Assert(err, check.IsNil)
// client works before rotation is initiated
_, err = proxy.GetNodes(ctx, defaults.Namespace)
_, err = proxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// starts rotation
@@ -628,7 +630,7 @@ func (s *TLSSuite) TestRollback(c *check.C) {
newProxy, err := s.server.NewClient(TestBuiltin(types.RoleProxy))
c.Assert(err, check.IsNil)
_, err = newProxy.GetNodes(ctx, defaults.Namespace)
_, err = newProxy.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// advance rotation:
@@ -651,7 +653,7 @@ func (s *TLSSuite) TestRollback(c *check.C) {
// new clients work, server still accepts the creds
// because new clients should re-register and receive new certs
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
// can't jump to other phases
@@ -673,11 +675,11 @@ func (s *TLSSuite) TestRollback(c *check.C) {
c.Assert(err, check.IsNil)
// clients with new creds will no longer work
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.ErrorMatches, ".*bad certificate.*")
// clients with old creds will still work
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
}
@@ -876,7 +878,7 @@ func (s *TLSSuite) TestNopUser(c *check.C) {
_, err = client.GetUsers(false)
fixtures.ExpectAccessDenied(c, err)
_, err = client.GetNodes(ctx, defaults.Namespace)
_, err = client.GetNodes(ctx, apidefaults.Namespace)
fixtures.ExpectAccessDenied(c, err)
// Endpoints that allow current user access should return access denied to
@@ -1090,12 +1092,12 @@ func (s *TLSSuite) TestValidateUploadSessionRecording(c *check.C) {
Created: date,
LastActive: date,
Login: "bob",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
}
c.Assert(clt.CreateSession(sess), check.IsNil)
err = clt.UploadSessionRecording(events.SessionRecording{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: sess.ID,
Recording: recording,
})
@@ -1181,7 +1183,7 @@ func (s *TLSSuite) TestValidatePostSessionSlice(c *check.C) {
Created: date,
LastActive: date,
Login: "bob",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
}
c.Assert(clt.CreateSession(sess), check.IsNil)
@@ -1194,7 +1196,7 @@ func (s *TLSSuite) TestValidatePostSessionSlice(c *check.C) {
}
err = clt.PostSessionSlice(events.SessionSlice{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: string(sess.ID),
Chunks: []*events.SessionChunk{
{
@@ -1216,7 +1218,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
clt, err := s.server.NewClient(TestAdmin())
c.Assert(err, check.IsNil)
out, err := clt.GetSessions(defaults.Namespace)
out, err := clt.GetSessions(apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.DeepEquals, []session.Session{})
@@ -1227,11 +1229,11 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
Created: date,
LastActive: date,
Login: "bob",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
}
c.Assert(clt.CreateSession(sess), check.IsNil)
out, err = clt.GetSessions(defaults.Namespace)
out, err = clt.GetSessions(apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.DeepEquals, []session.Session{sess})
@@ -1247,10 +1249,10 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
// emit two events: "one" and "two" for this session, and event "three"
// for some other session
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", defaults.Namespace), 0755)
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", apidefaults.Namespace), 0755)
c.Assert(err, check.IsNil)
forwarder, err := events.NewForwarder(events.ForwarderConfig{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: sess.ID,
ServerID: teleport.ComponentUpload,
DataDir: uploadDir,
@@ -1260,7 +1262,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
c.Assert(err, check.IsNil)
err = forwarder.PostSessionSlice(events.SessionSlice{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: string(sess.ID),
Chunks: []*events.SessionChunk{
{
@@ -1283,7 +1285,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
anotherSessionID := session.NewID()
forwarder, err = events.NewForwarder(events.ForwarderConfig{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: sess.ID,
ServerID: teleport.ComponentUpload,
DataDir: uploadDir,
@@ -1292,7 +1294,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
})
c.Assert(err, check.IsNil)
err = clt.PostSessionSlice(events.SessionSlice{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: string(anotherSessionID),
Chunks: []*events.SessionChunk{
{
@@ -1318,7 +1320,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
uploader, err := events.NewUploader(events.UploaderConfig{
ServerID: "upload",
DataDir: uploadDir,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Context: context.TODO(),
ScanPeriod: 100 * time.Millisecond,
AuditLog: clt,
@@ -1338,7 +1340,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
}
// ask for strictly session events:
e, err := clt.GetSessionEvents(defaults.Namespace, sess.ID, 0, true)
e, err := clt.GetSessionEvents(apidefaults.Namespace, sess.ID, 0, true)
c.Assert(err, check.IsNil)
c.Assert(len(e), check.Equals, 2)
c.Assert(e[0].GetString("val"), check.Equals, "one")
@@ -1347,14 +1349,14 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
// try searching for events with no filter (empty query) - should get all 3 events:
to := time.Now().In(time.UTC).Add(time.Hour)
from := to.Add(-time.Hour * 2)
history, _, err := clt.SearchEvents(from, to, defaults.Namespace, nil, 0, "")
history, _, err := clt.SearchEvents(from, to, apidefaults.Namespace, nil, 0, "")
c.Assert(err, check.IsNil)
c.Assert(history, check.NotNil)
// Extra event is the upload event
c.Assert(len(history), check.Equals, 5)
// try searching for only "session.end" events (real query)
history, _, err = clt.SearchEvents(from, to, defaults.Namespace, []string{events.SessionEndEvent}, 0, "")
history, _, err = clt.SearchEvents(from, to, apidefaults.Namespace, []string{events.SessionEndEvent}, 0, "")
c.Assert(err, check.IsNil)
c.Assert(history, check.NotNil)
c.Assert(len(history), check.Equals, 2)
@@ -1713,7 +1715,7 @@ func (s *TLSSuite) TestAccessRequest(c *check.C) {
identity, err := tlsca.FromSubject(cert.Subject, cert.NotAfter)
c.Assert(err, check.IsNil)
return utils.SliceContainsStr(identity.Groups, role)
return apiutils.SliceContainsStr(identity.Groups, role)
}
// certLogins extracts the logins from an ssh certificate
@@ -2144,7 +2146,7 @@ func TestGenerateCerts(t *testing.T) {
require.NoError(t, err)
parsedCert, diff := parseCert(userCerts.SSH)
require.Less(t, int64(defaults.MaxCertDuration), int64(diff))
require.Less(t, int64(apidefaults.MaxCertDuration), int64(diff))
// user should have agent forwarding (default setting)
require.Contains(t, parsedCert.Extensions, teleport.CertExtensionPermitAgentForwarding)
@@ -2218,7 +2220,7 @@ func TestGenerateCerts(t *testing.T) {
})
require.Error(t, err)
userRole2.SetClusterLabels(types.Allow, types.Labels{"env": utils.Strings{"prod"}})
userRole2.SetClusterLabels(types.Allow, types.Labels{"env": apiutils.Strings{"prod"}})
err = srv.Auth().UpsertRole(ctx, userRole2)
require.NoError(t, err)
@@ -2361,7 +2363,7 @@ func (s *TLSSuite) TestCertificateFormat(c *check.C) {
},
},
CompatibilityMode: tt.inClientCertificateFormat,
TTL: defaults.CertDuration,
TTL: apidefaults.CertDuration,
PublicKey: pub,
})
c.Assert(err, check.IsNil)
@@ -2842,7 +2844,7 @@ func (s *TLSSuite) TestEventsNodePresence(c *check.C) {
Version: types.V2,
Metadata: types.Metadata{
Name: "node1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.ServerSpecV2{
Addr: "localhost:3022",
@@ -3113,7 +3115,7 @@ func (s *TLSSuite) TestEventsClusterConfig(c *check.C) {
Kind: types.KindToken,
Version: types.V2,
Metadata: types.Metadata{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Name: token.GetName(),
},
})
@@ -3142,7 +3144,7 @@ func (s *TLSSuite) TestEventsClusterConfig(c *check.C) {
Version: types.V2,
Metadata: types.Metadata{
Name: types.MetaNameClusterName,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{
"key": "val",
},
+2 -2
View File
@@ -28,9 +28,9 @@ import (
"strings"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/tlsca"
"github.com/gravitational/teleport/lib/utils"
@@ -267,7 +267,7 @@ func (cfg *Config) Validate() error {
cfg.BufferSize = backend.DefaultBufferSize
}
if cfg.DialTimeout == 0 {
cfg.DialTimeout = defaults.DefaultDialTimeout
cfg.DialTimeout = apidefaults.DefaultDialTimeout
}
if cfg.PasswordFile != "" {
out, err := ioutil.ReadFile(cfg.PasswordFile)
+2 -1
View File
@@ -24,6 +24,7 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/utils"
"github.com/gravitational/trace"
@@ -301,7 +302,7 @@ func buildKeyLabel(key []byte, sensitivePrefixes []string) string {
return string(bytes.Join(parts, []byte{Separator}))
}
if utils.SliceContainsStr(sensitivePrefixes, string(parts[1])) {
if apiutils.SliceContainsStr(sensitivePrefixes, string(parts[1])) {
hiddenBefore := int(math.Floor(0.75 * float64(len(parts[2]))))
asterisks := bytes.Repeat([]byte("*"), hiddenBefore)
parts[2] = append(asterisks, parts[2][hiddenBefore:]...)
+2 -2
View File
@@ -35,7 +35,7 @@ import (
"github.com/aquasecurity/tracee/libbpfgo"
"github.com/gravitational/teleport/api/constants"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/prometheus/client_golang/prometheus"
"github.com/prometheus/client_golang/prometheus/testutil"
@@ -88,7 +88,7 @@ func (s *Suite) TestWatch(c *check.C) {
// Create a monitoring session for init. The events we execute should not
// have PID 1, so nothing should be captured in the Audit Log.
cgroupID, err := service.OpenSession(&SessionContext{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: uuid.New(),
ServerID: uuid.New(),
Login: "foo",
+5 -4
View File
@@ -22,6 +22,7 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/defaults"
@@ -172,7 +173,7 @@ func ForNode(cfg Config) Config {
// Node only needs to "know" about default
// namespace events to avoid matching too much
// data about other namespaces or node events
{Kind: types.KindNamespace, Name: defaults.Namespace},
{Kind: types.KindNamespace, Name: apidefaults.Namespace},
}
cfg.QueueSize = defaults.NodeQueueSize
return cfg
@@ -190,7 +191,7 @@ func ForKubernetes(cfg Config) Config {
{Kind: types.KindSessionRecordingConfig},
{Kind: types.KindUser},
{Kind: types.KindRole},
{Kind: types.KindNamespace, Name: defaults.Namespace},
{Kind: types.KindNamespace, Name: apidefaults.Namespace},
{Kind: types.KindKubeService},
}
cfg.QueueSize = defaults.KubernetesQueueSize
@@ -212,7 +213,7 @@ func ForApps(cfg Config) Config {
{Kind: types.KindProxy},
// Applications only need to "know" about default namespace events to avoid
// matching too much data about other namespaces or events.
{Kind: types.KindNamespace, Name: defaults.Namespace},
{Kind: types.KindNamespace, Name: apidefaults.Namespace},
}
cfg.QueueSize = defaults.AppsQueueSize
return cfg
@@ -232,7 +233,7 @@ func ForDatabases(cfg Config) Config {
{Kind: types.KindProxy},
// Databases only need to "know" about default namespace events to
// avoid matching too much data about other namespaces or events.
{Kind: types.KindNamespace, Name: defaults.Namespace},
{Kind: types.KindNamespace, Name: apidefaults.Namespace},
}
cfg.QueueSize = defaults.DatabasesQueueSize
return cfg
+25 -23
View File
@@ -24,7 +24,9 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/lite"
"github.com/gravitational/teleport/lib/backend/memory"
@@ -413,7 +415,7 @@ func waitForEvent(c *check.C, eventsC <-chan Event, expectedEvent string, skipEv
// wait for watcher to restart
select {
case event := <-eventsC:
if utils.SliceContainsStr(skipEvents, event.Type) {
if apiutils.SliceContainsStr(skipEvents, event.Type) {
continue
}
c.Assert(event.Type, check.Equals, expectedEvent)
@@ -1259,11 +1261,11 @@ func (s *CacheSuite) TestNodes(c *check.C) {
p := s.newPackForProxy(c)
defer p.Close()
server := suite.NewServer(types.KindNode, "srv1", "127.0.0.1:2022", defaults.Namespace)
server := suite.NewServer(types.KindNode, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
_, err := p.presenceS.UpsertNode(ctx, server)
c.Assert(err, check.IsNil)
out, err := p.presenceS.GetNodes(ctx, defaults.Namespace)
out, err := p.presenceS.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
srv := out[0]
@@ -1275,7 +1277,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
c.Fatalf("timeout waiting for event")
}
out, err = p.cache.GetNodes(ctx, defaults.Namespace)
out, err = p.cache.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
@@ -1289,7 +1291,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
lease, err := p.presenceS.UpsertNode(ctx, srv)
c.Assert(err, check.IsNil)
out, err = p.presenceS.GetNodes(ctx, defaults.Namespace)
out, err = p.presenceS.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
srv = out[0]
@@ -1301,7 +1303,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
c.Fatalf("timeout waiting for event")
}
out, err = p.cache.GetNodes(ctx, defaults.Namespace)
out, err = p.cache.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
@@ -1321,7 +1323,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
c.Fatalf("timeout waiting for event")
}
out, err = p.cache.GetNodes(ctx, defaults.Namespace)
out, err = p.cache.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
@@ -1329,7 +1331,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
srv.SetExpiry(lease.Expires)
fixtures.DeepCompare(c, srv, out[0])
err = p.presenceS.DeleteAllNodes(ctx, defaults.Namespace)
err = p.presenceS.DeleteAllNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
select {
@@ -1338,7 +1340,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
c.Fatalf("timeout waiting for event")
}
out, err = p.cache.GetNodes(ctx, defaults.Namespace)
out, err = p.cache.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 0)
}
@@ -1348,7 +1350,7 @@ func (s *CacheSuite) TestProxies(c *check.C) {
p := s.newPackForProxy(c)
defer p.Close()
server := suite.NewServer(types.KindProxy, "srv1", "127.0.0.1:2022", defaults.Namespace)
server := suite.NewServer(types.KindProxy, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
err := p.presenceS.UpsertProxy(server)
c.Assert(err, check.IsNil)
@@ -1415,7 +1417,7 @@ func (s *CacheSuite) TestAuthServers(c *check.C) {
p := s.newPackForProxy(c)
defer p.Close()
server := suite.NewServer(types.KindAuthServer, "srv1", "127.0.0.1:2022", defaults.Namespace)
server := suite.NewServer(types.KindAuthServer, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
err := p.presenceS.UpsertAuthServer(server)
c.Assert(err, check.IsNil)
@@ -1561,7 +1563,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
c.Assert(err, check.IsNil)
// Check that the application is now in the backend.
out, err := p.presenceS.GetAppServers(context.Background(), defaults.Namespace)
out, err := p.presenceS.GetAppServers(context.Background(), apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
srv := out[0]
@@ -1575,7 +1577,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
}
// Make sure the cache has a single application in it.
out, err = p.cache.GetAppServers(context.Background(), defaults.Namespace)
out, err = p.cache.GetAppServers(context.Background(), apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
@@ -1593,7 +1595,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
// Check that the application is in the backend and only one exists (so an
// update occurred).
out, err = p.presenceS.GetAppServers(context.Background(), defaults.Namespace)
out, err = p.presenceS.GetAppServers(context.Background(), apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
srv = out[0]
@@ -1607,7 +1609,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
}
// Make sure the cache has a single application in it.
out, err = p.cache.GetAppServers(context.Background(), defaults.Namespace)
out, err = p.cache.GetAppServers(context.Background(), apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 1)
@@ -1617,7 +1619,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
fixtures.DeepCompare(c, srv, out[0])
// Remove all applications from the backend.
err = p.presenceS.DeleteAllAppServers(context.Background(), defaults.Namespace)
err = p.presenceS.DeleteAllAppServers(context.Background(), apidefaults.Namespace)
c.Assert(err, check.IsNil)
// Check that information has been replicated to the cache.
@@ -1629,7 +1631,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
}
// Check that the cache is now empty.
out, err = p.cache.GetAppServers(context.Background(), defaults.Namespace)
out, err = p.cache.GetAppServers(context.Background(), apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(out, check.HasLen, 0)
}
@@ -1655,7 +1657,7 @@ func TestDatabaseServers(t *testing.T) {
require.NoError(t, err)
// Check that the database server is now in the backend.
out, err := p.presenceS.GetDatabaseServers(context.Background(), defaults.Namespace)
out, err := p.presenceS.GetDatabaseServers(context.Background(), apidefaults.Namespace)
require.NoError(t, err)
require.Empty(t, cmp.Diff([]types.DatabaseServer{server}, out,
cmpopts.IgnoreFields(types.Metadata{}, "ID")))
@@ -1669,7 +1671,7 @@ func TestDatabaseServers(t *testing.T) {
}
// Make sure the cache has a single database server in it.
out, err = p.cache.GetDatabaseServers(context.Background(), defaults.Namespace)
out, err = p.cache.GetDatabaseServers(context.Background(), apidefaults.Namespace)
require.NoError(t, err)
require.Empty(t, cmp.Diff([]types.DatabaseServer{server}, out,
cmpopts.IgnoreFields(types.Metadata{}, "ID")))
@@ -1681,7 +1683,7 @@ func TestDatabaseServers(t *testing.T) {
// Check that the server is in the backend and only one exists (so an
// update occurred).
out, err = p.presenceS.GetDatabaseServers(context.Background(), defaults.Namespace)
out, err = p.presenceS.GetDatabaseServers(context.Background(), apidefaults.Namespace)
require.NoError(t, err)
require.Empty(t, cmp.Diff([]types.DatabaseServer{server}, out,
cmpopts.IgnoreFields(types.Metadata{}, "ID")))
@@ -1695,13 +1697,13 @@ func TestDatabaseServers(t *testing.T) {
}
// Make sure the cache has a single database server in it.
out, err = p.cache.GetDatabaseServers(context.Background(), defaults.Namespace)
out, err = p.cache.GetDatabaseServers(context.Background(), apidefaults.Namespace)
require.NoError(t, err)
require.Empty(t, cmp.Diff([]types.DatabaseServer{server}, out,
cmpopts.IgnoreFields(types.Metadata{}, "ID")))
// Remove all database servers from the backend.
err = p.presenceS.DeleteAllDatabaseServers(context.Background(), defaults.Namespace)
err = p.presenceS.DeleteAllDatabaseServers(context.Background(), apidefaults.Namespace)
require.NoError(t, err)
// Check that information has been replicated to the cache.
@@ -1713,7 +1715,7 @@ func TestDatabaseServers(t *testing.T) {
}
// Check that the cache is now empty.
out, err = p.cache.GetDatabaseServers(context.Background(), defaults.Namespace)
out, err = p.cache.GetDatabaseServers(context.Background(), apidefaults.Namespace)
require.NoError(t, err)
require.Equal(t, 0, len(out))
}
+7 -7
View File
@@ -20,8 +20,8 @@ import (
"context"
"strings"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/trace"
)
@@ -624,7 +624,7 @@ type node struct {
// erase erases all data in the collection
func (c *node) erase(ctx context.Context) error {
if err := c.presenceCache.DeleteAllNodes(ctx, defaults.Namespace); err != nil {
if err := c.presenceCache.DeleteAllNodes(ctx, apidefaults.Namespace); err != nil {
if !trace.IsNotFound(err) {
return trace.Wrap(err)
}
@@ -633,7 +633,7 @@ func (c *node) erase(ctx context.Context) error {
}
func (c *node) fetch(ctx context.Context) (apply func(ctx context.Context) error, err error) {
resources, err := c.Presence.GetNodes(ctx, defaults.Namespace)
resources, err := c.Presence.GetNodes(ctx, apidefaults.Namespace)
if err != nil {
return nil, trace.Wrap(err)
}
@@ -1307,7 +1307,7 @@ type databaseServer struct {
}
func (s *databaseServer) erase(ctx context.Context) error {
err := s.presenceCache.DeleteAllDatabaseServers(ctx, defaults.Namespace)
err := s.presenceCache.DeleteAllDatabaseServers(ctx, apidefaults.Namespace)
if err != nil && !trace.IsNotFound(err) {
return trace.Wrap(err)
}
@@ -1315,7 +1315,7 @@ func (s *databaseServer) erase(ctx context.Context) error {
}
func (s *databaseServer) fetch(ctx context.Context) (apply func(ctx context.Context) error, err error) {
resources, err := s.Presence.GetDatabaseServers(ctx, defaults.Namespace)
resources, err := s.Presence.GetDatabaseServers(ctx, apidefaults.Namespace)
if err != nil {
return nil, trace.Wrap(err)
}
@@ -1374,7 +1374,7 @@ type appServer struct {
// erase erases all data in the collection
func (a *appServer) erase(ctx context.Context) error {
if err := a.presenceCache.DeleteAllAppServers(ctx, defaults.Namespace); err != nil {
if err := a.presenceCache.DeleteAllAppServers(ctx, apidefaults.Namespace); err != nil {
if !trace.IsNotFound(err) {
return trace.Wrap(err)
}
@@ -1383,7 +1383,7 @@ func (a *appServer) erase(ctx context.Context) error {
}
func (a *appServer) fetch(ctx context.Context) (apply func(ctx context.Context) error, err error) {
resources, err := a.Presence.GetAppServers(ctx, defaults.Namespace)
resources, err := a.Presence.GetAppServers(ctx, apidefaults.Namespace)
if err != nil {
return nil, trace.Wrap(err)
}
+2 -1
View File
@@ -49,6 +49,7 @@ import (
"github.com/gravitational/teleport/api/client/proto"
"github.com/gravitational/teleport/api/client/webclient"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/profile"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/api/types/wrappers"
@@ -1032,7 +1033,7 @@ func NewClient(c *Config) (tc *TeleportClient, err error) {
log.Infof("no host login given. defaulting to %s", c.HostLogin)
}
if c.KeyTTL == 0 {
c.KeyTTL = defaults.CertDuration
c.KeyTTL = apidefaults.CertDuration
}
c.Namespace = types.ProcessNamespace(c.Namespace)
+5 -5
View File
@@ -35,9 +35,9 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/client"
"github.com/gravitational/teleport/api/client/proto"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/sshutils"
"github.com/gravitational/teleport/lib/sshutils/scp"
@@ -102,7 +102,7 @@ func (proxy *ProxyClient) GetSites() ([]types.Site, error) {
}()
select {
case <-done:
case <-time.After(defaults.DefaultDialTimeout):
case <-time.After(apidefaults.DefaultDialTimeout):
return nil, trace.ConnectionProblem(nil, "timeout")
}
log.Debugf("Found clusters: %v", stdout.String())
@@ -682,7 +682,7 @@ func (proxy *ProxyClient) ConnectToRootCluster(ctx context.Context, quiet bool)
// if 'quiet' is set to true, no errors will be printed to stdout, otherwise
// any connection errors are visible to a user.
func (proxy *ProxyClient) ConnectToCluster(ctx context.Context, clusterName string, quiet bool) (auth.ClientI, error) {
dialer := auth.ContextDialerFunc(func(ctx context.Context, network, _ string) (net.Conn, error) {
dialer := client.ContextDialerFunc(func(ctx context.Context, network, _ string) (net.Conn, error) {
return proxy.dialAuthServer(ctx, clusterName)
})
@@ -997,7 +997,7 @@ func (proxy *ProxyClient) ConnectToNode(ctx context.Context, nodeAddress NodeAdd
nc := &NodeClient{
Client: client,
Proxy: proxy,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
TC: proxy.teleportClient,
}
@@ -1069,7 +1069,7 @@ func (proxy *ProxyClient) PortForwardToNode(ctx context.Context, nodeAddress Nod
nc := &NodeClient{
Client: client,
Proxy: proxy,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
TC: proxy.teleportClient,
}
+3 -2
View File
@@ -37,6 +37,7 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/lite"
@@ -1042,7 +1043,7 @@ func parseKnownHosts(bytes []byte, allowedLogins []string) (types.CertAuthority,
// transform old allowed logins into roles
role := services.RoleForCertAuthority(ca)
role.SetLogins(services.Allow, utils.CopyStrings(allowedLogins))
role.SetLogins(services.Allow, apiutils.CopyStrings(allowedLogins))
ca.AddRole(role.GetName())
return ca, role, nil
@@ -1203,7 +1204,7 @@ func Configure(clf *CommandLineFlags, cfg *service.Config) error {
// If this process is trying to join a cluster as an application service,
// make sure application name and URI are provided.
if utils.SliceContainsStr(splitRoles(clf.Roles), defaults.RoleApp) &&
if apiutils.SliceContainsStr(splitRoles(clf.Roles), defaults.RoleApp) &&
(clf.AppName == "" || clf.AppURI == "") {
return trace.BadParameter("application name (--app-name) and URI (--app-uri) flags are both required to join application proxy to the cluster")
}
+11 -10
View File
@@ -29,7 +29,9 @@ import (
"time"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/lite"
@@ -42,10 +44,9 @@ import (
"github.com/google/go-cmp/cmp"
"github.com/google/go-cmp/cmp/cmpopts"
"github.com/gravitational/trace"
"github.com/stretchr/testify/require"
"golang.org/x/crypto/ssh"
"github.com/gravitational/trace"
)
type testConfigFiles struct {
@@ -273,7 +274,7 @@ func TestConfigReading(t *testing.T) {
ListenAddress: "tcp://kube",
},
KubeClusterName: "kube-cluster",
PublicAddr: utils.Strings([]string{"kube-host:1234"}),
PublicAddr: apiutils.Strings([]string{"kube-host:1234"}),
},
Apps: Apps{
Service: Service{
@@ -490,7 +491,7 @@ func TestApplyConfig(t *testing.T) {
conf, err := ReadConfig(bytes.NewBufferString(fmt.Sprintf(SmallConfigString, tokenPath)))
require.NoError(t, err)
require.NotNil(t, conf)
require.Equal(t, utils.Strings{"web3:443"}, conf.Proxy.PublicAddr)
require.Equal(t, apiutils.Strings{"web3:443"}, conf.Proxy.PublicAddr)
cfg := service.MakeDefaultConfig()
err = ApplyFileConfig(conf, cfg)
@@ -529,7 +530,7 @@ func TestApplyConfig(t *testing.T) {
Version: types.V2,
Metadata: types.Metadata{
Name: "cluster-auth-preference",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{types.OriginLabel: types.OriginConfigFile},
},
Spec: types.AuthPreferenceSpecV2{
@@ -809,7 +810,7 @@ func checkStaticConfig(t *testing.T, conf *FileConfig) {
{Name: "hostname", Command: []string{"/bin/hostname"}, Period: 10 * time.Millisecond},
{Name: "date", Command: []string{"/bin/date"}, Period: 20 * time.Millisecond},
},
PublicAddr: utils.Strings{"luna3:22"},
PublicAddr: apiutils.Strings{"luna3:22"},
}, cmp.AllowUnexported(Service{})))
require.True(t, conf.Auth.Configured())
@@ -843,7 +844,7 @@ func checkStaticConfig(t *testing.T, conf *FileConfig) {
"proxy,node:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
"auth:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
},
PublicAddr: utils.Strings{
PublicAddr: apiutils.Strings{
"auth.default.svc.cluster.local:3080",
},
ClientIdleTimeout: types.Duration(17 * time.Second),
@@ -940,7 +941,7 @@ func makeConfigFixture() string {
ListenAddress: "tcp://kube",
},
KubeClusterName: "kube-cluster",
PublicAddr: utils.Strings([]string{"kube-host:1234"}),
PublicAddr: apiutils.Strings([]string{"kube-host:1234"}),
}
// Application service.
@@ -1143,7 +1144,7 @@ func TestProxyKube(t *testing.T) {
cfg: Proxy{Kube: KubeProxy{
Service: Service{EnabledFlag: "yes", ListenAddress: "0.0.0.0:8080"},
KubeconfigFile: "/tmp/kubeconfig",
PublicAddr: utils.Strings([]string{"kube.example.com:443"}),
PublicAddr: apiutils.Strings([]string{"kube.example.com:443"}),
}},
want: service.KubeProxyConfig{
Enabled: true,
@@ -1180,7 +1181,7 @@ func TestProxyKube(t *testing.T) {
Kube: KubeProxy{
Service: Service{EnabledFlag: "no", ListenAddress: "0.0.0.0:8080"},
KubeconfigFile: "/tmp/kubeconfig",
PublicAddr: utils.Strings([]string{"kube.example.com:443"}),
PublicAddr: apiutils.Strings([]string{"kube.example.com:443"}),
},
},
want: service.KubeProxyConfig{
+21 -20
View File
@@ -34,6 +34,7 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/api/utils/tlsutils"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/bpf"
@@ -175,7 +176,7 @@ func MakeSampleFileConfig(flags SampleFlags) (fc *FileConfig, err error) {
p.ACME.Email = flags.ACMEEmail
// ACME uses TLS-ALPN-01 challenge that requires port 443
// https://letsencrypt.org/docs/challenge-types/#tls-alpn-01
p.PublicAddr = utils.Strings{net.JoinHostPort(flags.ClusterName, fmt.Sprintf("%d", teleport.StandardHTTPSPort))}
p.PublicAddr = apiutils.Strings{net.JoinHostPort(flags.ClusterName, fmt.Sprintf("%d", teleport.StandardHTTPSPort))}
p.WebAddr = fmt.Sprintf(":%d", teleport.StandardHTTPSPort)
}
@@ -210,21 +211,21 @@ func (conf *FileConfig) CheckAndSetDefaults() error {
sc.SetDefaults()
for _, c := range conf.Ciphers {
if !utils.SliceContainsStr(sc.Ciphers, c) {
if !apiutils.SliceContainsStr(sc.Ciphers, c) {
return trace.BadParameter("cipher algorithm %q is not supported; supported algorithms: %q", c, sc.Ciphers)
}
}
for _, k := range conf.KEXAlgorithms {
if !utils.SliceContainsStr(sc.KeyExchanges, k) {
if !apiutils.SliceContainsStr(sc.KeyExchanges, k) {
return trace.BadParameter("KEX algorithm %q is not supported; supported algorithms: %q", k, sc.KeyExchanges)
}
}
for _, m := range conf.MACAlgorithms {
if !utils.SliceContainsStr(sc.MACs, m) {
if !apiutils.SliceContainsStr(sc.MACs, m) {
return trace.BadParameter("MAC algorithm %q is not supported; supported algorithms: %q", m, sc.MACs)
}
}
if conf.CASignatureAlgorithm != nil && !utils.SliceContainsStr(validCASigAlgos, *conf.CASignatureAlgorithm) {
if conf.CASignatureAlgorithm != nil && !apiutils.SliceContainsStr(validCASigAlgos, *conf.CASignatureAlgorithm) {
return trace.BadParameter("CA signature algorithm %q is not supported; supported algorithms: %q", *conf.CASignatureAlgorithm, validCASigAlgos)
}
@@ -318,7 +319,7 @@ func (c *CachePolicy) Enabled() bool {
if c.EnabledFlag == "" {
return true
}
enabled, _ := utils.ParseBool(c.EnabledFlag)
enabled, _ := apiutils.ParseBool(c.EnabledFlag)
return enabled
}
@@ -366,7 +367,7 @@ func (s *Service) Enabled() bool {
if !s.Configured() {
return s.defaultEnabled
}
v, err := utils.ParseBool(s.EnabledFlag)
v, err := apiutils.ParseBool(s.EnabledFlag)
if err != nil {
return false
}
@@ -441,7 +442,7 @@ type Auth struct {
// PublicAddr sets SSH host principals and TLS DNS names to auth
// server certificates
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
// ClientIdleTimeout sets global cluster default setting for client idle timeouts
ClientIdleTimeout types.Duration `yaml:"client_idle_timeout,omitempty"`
@@ -613,7 +614,7 @@ type SSH struct {
PermitUserEnvironment bool `yaml:"permit_user_env,omitempty"`
PAM *PAM `yaml:"pam,omitempty"`
// PublicAddr sets SSH host principals for SSH service
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
// BPF is used to configure BPF-based auditing for this node.
BPF *BPF `yaml:"enhanced_recording,omitempty"`
@@ -649,7 +650,7 @@ func (p *PAM) Parse() *pam.Config {
if serviceName == "" {
serviceName = defaults.ServiceName
}
enabled, _ := utils.ParseBool(p.Enabled)
enabled, _ := apiutils.ParseBool(p.Enabled)
return &pam.Config{
Enabled: enabled,
ServiceName: serviceName,
@@ -678,7 +679,7 @@ type BPF struct {
// Parse will parse the enhanced session recording configuration.
func (b *BPF) Parse() *bpf.Config {
enabled, _ := utils.ParseBool(b.Enabled)
enabled, _ := apiutils.ParseBool(b.Enabled)
return &bpf.Config{
Enabled: enabled,
CommandBufferSize: b.CommandBufferSize,
@@ -817,22 +818,22 @@ type Proxy struct {
// local Kubernetes cluster.
KubeAddr string `yaml:"kube_listen_addr,omitempty"`
// KubePublicAddr is a public address of the kubernetes endpoint.
KubePublicAddr utils.Strings `yaml:"kube_public_addr,omitempty"`
KubePublicAddr apiutils.Strings `yaml:"kube_public_addr,omitempty"`
// PublicAddr sets the hostport the proxy advertises for the HTTP endpoint.
// The hosts in PublicAddr are included in the list of host principals
// on the SSH certificate.
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
// SSHPublicAddr sets the hostport the proxy advertises for the SSH endpoint.
// The hosts in PublicAddr are included in the list of host principals
// on the SSH certificate.
SSHPublicAddr utils.Strings `yaml:"ssh_public_addr,omitempty"`
SSHPublicAddr apiutils.Strings `yaml:"ssh_public_addr,omitempty"`
// TunnelPublicAddr sets the hostport the proxy advertises for the tunnel
// endpoint. The hosts in PublicAddr are included in the list of host
// principals on the SSH certificate.
TunnelPublicAddr utils.Strings `yaml:"tunnel_public_addr,omitempty"`
TunnelPublicAddr apiutils.Strings `yaml:"tunnel_public_addr,omitempty"`
// KeyPairs is a list of x509 key pairs the proxy will load.
KeyPairs []KeyPair `yaml:"https_keypairs"`
@@ -844,10 +845,10 @@ type Proxy struct {
MySQLAddr string `yaml:"mysql_listen_addr,omitempty"`
// MySQLPublicAddr is the hostport the proxy advertises for MySQL
// client connections.
MySQLPublicAddr utils.Strings `yaml:"mysql_public_addr,omitempty"`
MySQLPublicAddr apiutils.Strings `yaml:"mysql_public_addr,omitempty"`
// PostgresPublicAddr is the hostport the proxy advertises for Postgres
// client connections.
PostgresPublicAddr utils.Strings `yaml:"postgres_public_addr,omitempty"`
PostgresPublicAddr apiutils.Strings `yaml:"postgres_public_addr,omitempty"`
}
// ACME configures ACME protocol - automatic X.509 certificates
@@ -869,7 +870,7 @@ func (a ACME) Parse() (*service.ACME, error) {
}
var err error
out.Enabled, err = utils.ParseBool(a.EnabledFlag)
out.Enabled, err = apiutils.ParseBool(a.EnabledFlag)
if err != nil {
return nil, trace.Wrap(err)
}
@@ -898,7 +899,7 @@ type KubeProxy struct {
// Service is a generic service configuration section
Service `yaml:",inline"`
// PublicAddr is a publicly advertised address of the kubernetes proxy
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
// KubeconfigFile is an optional path to kubeconfig file,
// if specified, teleport will use API server address and
// trusted certificate authority information from it
@@ -913,7 +914,7 @@ type Kube struct {
// Service is a generic service configuration section
Service `yaml:",inline"`
// PublicAddr is a publicly advertised address of the kubernetes service
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
// KubeconfigFile is an optional path to kubeconfig file,
// if specified, teleport will use API server address and
// trusted certificate authority information from it
+5 -37
View File
@@ -91,10 +91,6 @@ const (
// to a cluster
InviteTokenTTL = 15 * time.Minute
// DefaultDialTimeout is a default TCP dial timeout we set for our
// connection attempts
DefaultDialTimeout = defaults.DefaultDialTimeout
// HTTPMaxIdleConns is the max idle connections across all hosts.
HTTPMaxIdleConns = 2000
@@ -218,9 +214,6 @@ const (
// is locked after MaxLoginAttempts
AccountLockInterval = 20 * time.Minute
// Namespace is default namespace
Namespace = defaults.Namespace
// AttemptTTL is TTL for login attempt
AttemptTTL = time.Minute * 30
@@ -282,16 +275,6 @@ var (
// ResyncInterval is how often tunnels are resynced.
ResyncInterval = 5 * time.Second
// ServerAnnounceTTL is a period between heartbeats
// Median sleep time between node pings is this value / 2 + random
// deviation added to this time to avoid lots of simultaneous
// heartbeats coming to auth server
ServerAnnounceTTL = defaults.ServerAnnounceTTL
// ServerKeepAliveTTL is a period between server keep alives,
// when servers announce only presence withough sending full data
ServerKeepAliveTTL = defaults.ServerKeepAliveTTL
// AuthServersRefreshPeriod is a period for clients to refresh their
// their stored list of auth servers
AuthServersRefreshPeriod = 30 * time.Second
@@ -343,17 +326,6 @@ var (
// period used in services
HighResReportingPeriod = 10 * time.Second
// KeepAliveInterval is interval at which Teleport will send keep-alive
// messages to the client. The default interval of 5 minutes (300 seconds) is
// set to help keep connections alive when using AWS NLBs (which have a default
// timeout of 350 seconds)
KeepAliveInterval = defaults.KeepAliveInterval
// KeepAliveCountMax is the number of keep-alive messages that can be sent
// without receiving a response from the client before the client is
// disconnected. The max count mirrors ClientAliveCountMax of sshd.
KeepAliveCountMax = defaults.KeepAliveCountMax
// DiskAlertThreshold is the disk space alerting threshold.
DiskAlertThreshold = 90
@@ -431,19 +403,18 @@ const (
const (
// MinCertDuration specifies minimum duration of validity of issued certificate
MinCertDuration = time.Minute
// MaxCertDuration limits maximum duration of validity of issued certificate
MaxCertDuration = defaults.MaxCertDuration
// CertDuration is a default certificate duration.
CertDuration = defaults.CertDuration
// RotationGracePeriod is a default rotation period for graceful
// certificate rotations, by default to set to maximum allowed user
// cert duration
RotationGracePeriod = MaxCertDuration
RotationGracePeriod = defaults.MaxCertDuration
// PendingAccessDuration defines the expiry of a pending access request.
PendingAccessDuration = time.Hour
// MaxAccessDuration defines the maximum time for which an access request
// can be active.
MaxAccessDuration = MaxCertDuration
MaxAccessDuration = defaults.MaxCertDuration
)
// list of roles teleport service can run as:
@@ -492,9 +463,6 @@ const (
ArgsCacheSize = 1024
)
// EnhancedEvents returns the default list of enhanced events.
var EnhancedEvents = defaults.EnhancedEvents
var (
// ConfigFilePath is default path to teleport config file
ConfigFilePath = "/etc/teleport.yaml"
+5 -4
View File
@@ -32,6 +32,7 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/session"
@@ -241,7 +242,7 @@ func NewAuditLog(cfg AuditLogConfig) (*AuditLog, error) {
}
ctx, cancel := context.WithCancel(cfg.Context)
al := &AuditLog{
playbackDir: filepath.Join(cfg.DataDir, PlaybackDir, SessionLogsDir, defaults.Namespace),
playbackDir: filepath.Join(cfg.DataDir, PlaybackDir, SessionLogsDir, apidefaults.Namespace),
AuditLogConfig: cfg,
log: log.WithFields(log.Fields{
trace.Component: teleport.ComponentAuditLog,
@@ -258,7 +259,7 @@ func NewAuditLog(cfg AuditLogConfig) (*AuditLog, error) {
return nil, trace.ConvertSystemError(err)
}
// create a directory for session logs:
sessionDir := filepath.Join(cfg.DataDir, cfg.ServerID, SessionLogsDir, defaults.Namespace)
sessionDir := filepath.Join(cfg.DataDir, cfg.ServerID, SessionLogsDir, apidefaults.Namespace)
if err := os.MkdirAll(sessionDir, *cfg.DirMask); err != nil {
return nil, trace.ConvertSystemError(err)
}
@@ -325,7 +326,7 @@ func (l *SessionRecording) CheckAndSetDefaults() error {
return trace.BadParameter("missing parameter session ID")
}
if l.Namespace == "" {
l.Namespace = defaults.Namespace
l.Namespace = apidefaults.Namespace
}
return nil
}
@@ -1176,7 +1177,7 @@ func (l *LegacyHandler) IsUnpacked(ctx context.Context, sessionID session.ID) (b
if err != nil {
return false, trace.Wrap(err)
}
_, err = readSessionIndex(l.cfg.Dir, authServers, defaults.Namespace, sessionID)
_, err = readSessionIndex(l.cfg.Dir, authServers, apidefaults.Namespace, sessionID)
if err == nil {
return true, nil
}
+23 -24
View File
@@ -26,14 +26,13 @@ import (
"testing"
"time"
"github.com/jonboulle/clockwork"
"gopkg.in/check.v1"
"github.com/jonboulle/clockwork"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types/events"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/fixtures"
"github.com/gravitational/teleport/lib/session"
"github.com/gravitational/teleport/lib/utils"
@@ -126,11 +125,11 @@ func (a *AuditTestSuite) TestSessionsOnOneAuthServer(c *check.C) {
c.Assert(err, check.IsNil)
uploadDir := c.MkDir()
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", defaults.Namespace), 0755)
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", apidefaults.Namespace), 0755)
c.Assert(err, check.IsNil)
sessionID := string(session.NewID())
forwarder, err := NewForwarder(ForwarderConfig{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: session.ID(sessionID),
ServerID: teleport.ComponentUpload,
DataDir: uploadDir,
@@ -143,7 +142,7 @@ func (a *AuditTestSuite) TestSessionsOnOneAuthServer(c *check.C) {
// start the session and emit data stream to it
firstMessage := []byte("hello")
err = forwarder.PostSessionSlice(SessionSlice{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: sessionID,
Chunks: []*SessionChunk{
// start the session
@@ -180,7 +179,7 @@ func (a *AuditTestSuite) TestSessionsOnOneAuthServer(c *check.C) {
// does not matter which audit server is accessed the results should be the same
for _, a := range []*AuditLog{alog, alog2} {
// read the session bytes
history, err := a.GetSessionEvents(defaults.Namespace, session.ID(sessionID), 0, true)
history, err := a.GetSessionEvents(apidefaults.Namespace, session.ID(sessionID), 0, true)
c.Assert(err, check.IsNil)
c.Assert(history, check.HasLen, 3)
@@ -189,12 +188,12 @@ func (a *AuditTestSuite) TestSessionsOnOneAuthServer(c *check.C) {
c.Assert(history[1][SessionEventTimestamp], check.Equals, float64(0))
// fetch all bytes
buff, err := a.GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, 5000)
buff, err := a.GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, 5000)
c.Assert(err, check.IsNil)
c.Assert(string(buff), check.Equals, string(firstMessage))
// with offset
buff, err = a.GetSessionChunk(defaults.Namespace, session.ID(sessionID), 2, 5000)
buff, err = a.GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 2, 5000)
c.Assert(err, check.IsNil)
c.Assert(string(buff), check.Equals, string(firstMessage[2:]))
}
@@ -207,7 +206,7 @@ func upload(c *check.C, uploadDir string, clock clockwork.Clock, auditLog IAudit
ServerID: "upload",
DataDir: uploadDir,
Clock: clock,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Context: context.TODO(),
ScanPeriod: 100 * time.Millisecond,
AuditLog: auditLog,
@@ -247,10 +246,10 @@ func (a *AuditTestSuite) TestSessionRecordingOff(c *check.C) {
sessionID := string(session.NewID())
uploadDir := c.MkDir()
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", defaults.Namespace), 0755)
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", apidefaults.Namespace), 0755)
c.Assert(err, check.IsNil)
forwarder, err := NewForwarder(ForwarderConfig{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: session.ID(sessionID),
ServerID: teleport.ComponentUpload,
DataDir: uploadDir,
@@ -263,7 +262,7 @@ func (a *AuditTestSuite) TestSessionRecordingOff(c *check.C) {
// start the session and emit data stream to it
firstMessage := []byte("hello")
err = forwarder.PostSessionSlice(SessionSlice{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: sessionID,
Chunks: []*SessionChunk{
// start the session
@@ -298,7 +297,7 @@ func (a *AuditTestSuite) TestSessionRecordingOff(c *check.C) {
upload(c, uploadDir, fakeClock, alog)
// get all events from the audit log, should have two session event and one upload event
found, _, err := alog.SearchEvents(now.Add(-time.Hour), now.Add(time.Hour), defaults.Namespace, nil, 0, "")
found, _, err := alog.SearchEvents(now.Add(-time.Hour), now.Add(time.Hour), apidefaults.Namespace, nil, 0, "")
c.Assert(err, check.IsNil)
c.Assert(found, check.HasLen, 3)
eventA, okA := found[0].(*apievents.SessionStart)
@@ -309,12 +308,12 @@ func (a *AuditTestSuite) TestSessionRecordingOff(c *check.C) {
c.Assert(eventB.Login, check.Equals, username)
// inspect the session log for "200", should have two events
history, err := alog.GetSessionEvents(defaults.Namespace, session.ID(sessionID), 0, true)
history, err := alog.GetSessionEvents(apidefaults.Namespace, session.ID(sessionID), 0, true)
c.Assert(err, check.IsNil)
c.Assert(history, check.HasLen, 2)
// try getting the session stream, should get an error
_, err = alog.GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, 5000)
_, err = alog.GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, 5000)
c.Assert(err, check.NotNil)
}
@@ -383,7 +382,7 @@ func (a *AuditTestSuite) TestLogRotation(c *check.C) {
c.Assert(err, check.IsNil)
c.Assert(string(bytes), check.Equals, string(contents))
found, _, err := alog.SearchEvents(now.Add(-time.Hour), now.Add(time.Hour), defaults.Namespace, nil, 0, "")
found, _, err := alog.SearchEvents(now.Add(-time.Hour), now.Add(time.Hour), apidefaults.Namespace, nil, 0, "")
c.Assert(err, check.IsNil)
c.Assert(found, check.HasLen, 1)
}
@@ -443,7 +442,7 @@ func (a *AuditTestSuite) TestLegacyHandler(c *check.C) {
c.Assert(err, check.IsNil)
c.Assert(authServers, check.HasLen, 1)
targetDir := filepath.Join(a.dataDir, authServers[0], SessionLogsDir, defaults.Namespace)
targetDir := filepath.Join(a.dataDir, authServers[0], SessionLogsDir, apidefaults.Namespace)
_, err = tarball.Seek(0, 0)
c.Assert(err, check.IsNil)
@@ -491,12 +490,12 @@ func (a *AuditTestSuite) TestExternalLog(c *check.C) {
// server case
func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock, alog IAuditLog) (session.ID, func() error) {
uploadDir := c.MkDir()
err := os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", defaults.Namespace), 0755)
err := os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", apidefaults.Namespace), 0755)
c.Assert(err, check.IsNil)
sessionID := session.NewID()
forwarder, err := NewForwarder(ForwarderConfig{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: sessionID,
ServerID: "upload",
DataDir: uploadDir,
@@ -508,7 +507,7 @@ func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock,
// start the session and emit data stream to it and wrap it up
firstMessage := []byte("hello")
err = forwarder.PostSessionSlice(SessionSlice{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: string(sessionID),
Chunks: []*SessionChunk{
// start the seession
@@ -543,7 +542,7 @@ func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock,
upload(c, uploadDir, fakeClock, alog)
compare := func() error {
history, err := alog.GetSessionEvents(defaults.Namespace, sessionID, 0, true)
history, err := alog.GetSessionEvents(apidefaults.Namespace, sessionID, 0, true)
if err != nil {
return trace.Wrap(err)
}
@@ -560,7 +559,7 @@ func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock,
}
// fetch all bytes
buff, err := alog.GetSessionChunk(defaults.Namespace, sessionID, 0, 5000)
buff, err := alog.GetSessionChunk(apidefaults.Namespace, sessionID, 0, 5000)
if err != nil {
return trace.Wrap(err)
}
@@ -569,7 +568,7 @@ func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock,
}
// with offset
buff, err = alog.GetSessionChunk(defaults.Namespace, sessionID, 2, 5000)
buff, err = alog.GetSessionChunk(apidefaults.Namespace, sessionID, 2, 5000)
if err != nil {
return trace.Wrap(err)
}
+2 -1
View File
@@ -21,6 +21,7 @@ import (
"sync"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/session"
@@ -124,7 +125,7 @@ func (cfg *AuditWriterConfig) CheckAndSetDefaults() error {
return trace.BadParameter("audit writer config: missing parameter ClusterName")
}
if cfg.Namespace == "" {
cfg.Namespace = defaults.Namespace
cfg.Namespace = apidefaults.Namespace
}
if cfg.Clock == nil {
cfg.Clock = clockwork.NewRealClock()
+2 -2
View File
@@ -23,8 +23,8 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/session"
"github.com/gravitational/trace"
@@ -321,7 +321,7 @@ func newAuditWriterTest(t *testing.T, newStreamer newStreamerFn) *auditWriterTes
sid := session.NewID()
writer, err := NewAuditWriter(AuditWriterConfig{
SessionID: sid,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
RecordOutput: true,
Streamer: streamer,
Context: ctx,
+4 -2
View File
@@ -21,8 +21,10 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types/events"
apievents "github.com/gravitational/teleport/api/types/events"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/utils"
@@ -181,7 +183,7 @@ func (u *UploadCompleter) ensureSessionEndEvent(ctx context.Context, uploadData
var interactive bool
// Get session events to find fields for constructed session end
sessionEvents, err := u.cfg.AuditLog.GetSessionEvents(defaults.Namespace, uploadData.SessionID, 0, false)
sessionEvents, err := u.cfg.AuditLog.GetSessionEvents(apidefaults.Namespace, uploadData.SessionID, 0, false)
if err != nil {
return trace.Wrap(err)
}
@@ -263,5 +265,5 @@ func getParticipants(sessionEvents []EventFields) []string {
}
}
return utils.Deduplicate(participants)
return apiutils.Deduplicate(participants)
}
+5 -5
View File
@@ -27,10 +27,10 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/dynamo"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/session"
"github.com/gravitational/teleport/lib/utils"
@@ -458,7 +458,7 @@ func (l *Log) EmitAuditEvent(ctx context.Context, in apievents.AuditEvent) error
SessionID: sessionID,
EventIndex: in.GetIndex(),
EventType: in.GetType(),
EventNamespace: defaults.Namespace,
EventNamespace: apidefaults.Namespace,
CreatedAt: in.GetTime().Unix(),
Fields: string(data),
CreatedAtDate: in.GetTime().Format(iso8601DateFormat),
@@ -505,7 +505,7 @@ func (l *Log) EmitAuditEventLegacy(ev events.Event, fields events.EventFields) e
SessionID: sessionID,
EventIndex: int64(eventIndex),
EventType: fields.GetString(events.EventType),
EventNamespace: defaults.Namespace,
EventNamespace: apidefaults.Namespace,
CreatedAt: created.Unix(),
Fields: string(data),
CreatedAtDate: created.Format(iso8601DateFormat),
@@ -555,7 +555,7 @@ func (l *Log) PostSessionSlice(slice events.SessionSlice) error {
event := event{
SessionID: slice.SessionID,
EventNamespace: defaults.Namespace,
EventNamespace: apidefaults.Namespace,
EventType: chunk.EventType,
EventIndex: chunk.EventIndex,
CreatedAt: timeAt.Unix(),
@@ -862,7 +862,7 @@ func (l *Log) SearchSessionEvents(fromUTC time.Time, toUTC time.Time, limit int,
events.SessionStartEvent,
events.SessionEndEvent,
}
return l.SearchEvents(fromUTC, toUTC, defaults.Namespace, query, limit, startKey)
return l.SearchEvents(fromUTC, toUTC, apidefaults.Namespace, query, limit, startKey)
}
// WaitForDelivery waits for resources to be released and outstanding requests to
+3 -3
View File
@@ -31,9 +31,9 @@ import (
"github.com/aws/aws-sdk-go/service/dynamodb"
"github.com/aws/aws-sdk-go/service/dynamodb/dynamodbattribute"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/backend/memory"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/events/test"
"github.com/gravitational/teleport/lib/utils"
@@ -118,7 +118,7 @@ func (s *DynamoeventsSuite) TestSessionEventsCRUD(c *check.C) {
for i := 0; i < dynamoDBLargeQueryRetries; i++ {
time.Sleep(s.EventsSuite.QueryDelay)
history, _, err = s.Log.SearchEvents(s.Clock.Now().Add(-1*time.Hour), s.Clock.Now().Add(time.Hour), defaults.Namespace, nil, 0, "")
history, _, err = s.Log.SearchEvents(s.Clock.Now().Add(-1*time.Hour), s.Clock.Now().Add(time.Hour), apidefaults.Namespace, nil, 0, "")
c.Assert(err, check.IsNil)
if len(history) == eventCount {
@@ -189,7 +189,7 @@ func (s *DynamoeventsSuite) TestEventMigration(c *check.C) {
for time.Since(waitStart) < attemptWaitFor {
err = utils.RetryStaticFor(time.Minute*5, time.Second*5, func() error {
eventArr, _, err = s.log.searchEventsRaw(start, end, defaults.Namespace, []string{"test.event"}, 1000, "")
eventArr, _, err = s.log.searchEventsRaw(start, end, apidefaults.Namespace, []string{"test.event"}, 1000, "")
return err
})
c.Assert(err, check.IsNil)
+6 -7
View File
@@ -21,9 +21,8 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types/events"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
"github.com/jonboulle/clockwork"
"github.com/stretchr/testify/require"
@@ -45,7 +44,7 @@ func TestFileLogPagination(t *testing.T) {
Type: SessionJoinEvent,
Time: clock.Now().UTC(),
},
UserMetadata: apievents.UserMetadata{
UserMetadata: events.UserMetadata{
User: "bob",
},
})
@@ -57,7 +56,7 @@ func TestFileLogPagination(t *testing.T) {
Type: SessionJoinEvent,
Time: clock.Now().Add(time.Minute).UTC(),
},
UserMetadata: apievents.UserMetadata{
UserMetadata: events.UserMetadata{
User: "alice",
},
})
@@ -69,7 +68,7 @@ func TestFileLogPagination(t *testing.T) {
Type: SessionJoinEvent,
Time: clock.Now().Add(time.Minute * 2).UTC(),
},
UserMetadata: apievents.UserMetadata{
UserMetadata: events.UserMetadata{
User: "dave",
},
})
@@ -77,12 +76,12 @@ func TestFileLogPagination(t *testing.T) {
from := clock.Now().Add(-time.Hour).UTC()
to := clock.Now().Add(time.Hour).UTC()
eventArr, checkpoint, err := log.SearchEvents(from, to, defaults.Namespace, nil, 2, "")
eventArr, checkpoint, err := log.SearchEvents(from, to, apidefaults.Namespace, nil, 2, "")
require.Nil(t, err)
require.Len(t, eventArr, 2)
require.NotEqual(t, checkpoint, "")
eventArr, checkpoint, err = log.SearchEvents(from, to, defaults.Namespace, nil, 2, checkpoint)
eventArr, checkpoint, err = log.SearchEvents(from, to, apidefaults.Namespace, nil, 2, checkpoint)
require.Nil(t, err)
require.Len(t, eventArr, 1)
require.Equal(t, checkpoint, "")
+2 -1
View File
@@ -27,6 +27,7 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
@@ -532,7 +533,7 @@ func (u *Uploader) upload(up *upload) error {
// before the files are closed to avoid async writes
// the timeout is a defensive measure to avoid blocking
// indefinitely in case of unforeseen error (e.g. write taking too long)
wctx, wcancel := context.WithTimeout(ctx, defaults.DefaultDialTimeout)
wctx, wcancel := context.WithTimeout(ctx, apidefaults.DefaultDialTimeout)
defer wcancel()
<-wctx.Done()
@@ -30,6 +30,7 @@ import (
"github.com/prometheus/client_golang/prometheus"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
firestorebk "github.com/gravitational/teleport/lib/backend/firestore"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
@@ -324,7 +325,7 @@ func (l *Log) EmitAuditEvent(ctx context.Context, in apievents.AuditEvent) error
SessionID: sessionID,
EventIndex: in.GetIndex(),
EventType: in.GetType(),
EventNamespace: defaults.Namespace,
EventNamespace: apidefaults.Namespace,
CreatedAt: in.GetTime().Unix(),
Fields: string(data),
}
@@ -363,7 +364,7 @@ func (l *Log) EmitAuditEventLegacy(ev events.Event, fields events.EventFields) e
SessionID: sessionID,
EventIndex: int64(eventIndex),
EventType: fields.GetString(events.EventType),
EventNamespace: defaults.Namespace,
EventNamespace: apidefaults.Namespace,
CreatedAt: created.Unix(),
Fields: string(data),
}
@@ -395,7 +396,7 @@ func (l *Log) PostSessionSlice(slice events.SessionSlice) error {
}
event := event{
SessionID: slice.SessionID,
EventNamespace: defaults.Namespace,
EventNamespace: apidefaults.Namespace,
EventType: chunk.EventType,
EventIndex: chunk.EventIndex,
CreatedAt: time.Unix(0, chunk.Time).In(time.UTC).Unix(),
@@ -486,7 +487,7 @@ func (l *Log) SearchEvents(fromUTC, toUTC time.Time, namespace string, eventType
start := time.Now()
docSnaps, err := modifyquery(l.svc.Collection(l.CollectionName).
Where(eventNamespaceDocProperty, "==", defaults.Namespace).
Where(eventNamespaceDocProperty, "==", apidefaults.Namespace).
Where(createdAtDocProperty, ">=", fromUTC.Unix()).
Where(createdAtDocProperty, "<=", toUTC.Unix()).
OrderBy(createdAtDocProperty, firestore.Asc)).
@@ -553,7 +554,7 @@ func (l *Log) SearchSessionEvents(fromUTC time.Time, toUTC time.Time, limit int,
events.SessionStartEvent,
events.SessionEndEvent,
}
return l.SearchEvents(fromUTC, toUTC, defaults.Namespace, query, limit, startKey)
return l.SearchEvents(fromUTC, toUTC, apidefaults.Namespace, query, limit, startKey)
}
// WaitForDelivery waits for resources to be released and outstanding requests to
+2 -1
View File
@@ -22,6 +22,7 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/session"
@@ -100,7 +101,7 @@ func (cfg *ForwardRecorderConfig) CheckAndSetDefaults() error {
return trace.BadParameter("missing parameter DataDir")
}
if cfg.Namespace == "" {
cfg.Namespace = defaults.Namespace
cfg.Namespace = apidefaults.Namespace
}
if cfg.ForwardTo == nil {
cfg.ForwardTo = &DiscardAuditLog{}
+9 -9
View File
@@ -26,8 +26,8 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/fixtures"
"github.com/gravitational/teleport/lib/session"
@@ -104,7 +104,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
var checkpoint string
err = utils.RetryStaticFor(time.Minute*5, time.Second*5, func() error {
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 100, checkpoint)
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 100, checkpoint)
return err
})
c.Assert(err, check.IsNil)
@@ -112,7 +112,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
c.Assert(checkpoint, check.Equals, "")
for _, name := range names {
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 1, checkpoint)
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 1, checkpoint)
c.Assert(err, check.IsNil)
c.Assert(arr, check.HasLen, 1)
event, ok := arr[0].(*apievents.UserLogin)
@@ -120,7 +120,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
c.Assert(name, check.Equals, event.User)
}
if checkpoint != "" {
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 1, checkpoint)
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 1, checkpoint)
c.Assert(err, check.IsNil)
c.Assert(arr, check.HasLen, 0)
}
@@ -129,7 +129,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
for _, i := range []int{0, 2} {
nameA := names[i]
nameB := names[i+1]
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 2, checkpoint)
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 2, checkpoint)
c.Assert(err, check.IsNil)
c.Assert(arr, check.HasLen, 2)
eventA, okA := arr[0].(*apievents.UserLogin)
@@ -140,7 +140,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
c.Assert(nameB, check.Equals, eventB.User)
}
if checkpoint != "" {
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 1, checkpoint)
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 1, checkpoint)
c.Assert(err, check.IsNil)
c.Assert(arr, check.HasLen, 0)
}
@@ -166,7 +166,7 @@ func (s *EventsSuite) SessionEventsCRUD(c *check.C) {
var history []apievents.AuditEvent
err = utils.RetryStaticFor(time.Minute*5, time.Second*5, func() error {
history, _, err = s.Log.SearchEvents(s.Clock.Now().Add(-1*time.Hour), s.Clock.Now().Add(time.Hour), defaults.Namespace, nil, 100, "")
history, _, err = s.Log.SearchEvents(s.Clock.Now().Add(-1*time.Hour), s.Clock.Now().Add(time.Hour), apidefaults.Namespace, nil, 100, "")
return err
})
c.Assert(err, check.IsNil)
@@ -175,7 +175,7 @@ func (s *EventsSuite) SessionEventsCRUD(c *check.C) {
// start the session and emit data stream to it and wrap it up
sessionID := session.NewID()
err = s.Log.PostSessionSlice(events.SessionSlice{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
SessionID: string(sessionID),
Chunks: []*events.SessionChunk{
// start the seession
@@ -198,7 +198,7 @@ func (s *EventsSuite) SessionEventsCRUD(c *check.C) {
c.Assert(err, check.IsNil)
// read the session event
historyEvents, err := s.Log.GetSessionEvents(defaults.Namespace, sessionID, 0, false)
historyEvents, err := s.Log.GetSessionEvents(apidefaults.Namespace, sessionID, 0, false)
c.Assert(err, check.IsNil)
c.Assert(historyEvents, check.HasLen, 2)
c.Assert(historyEvents[0].GetString(events.EventType), check.Equals, events.SessionStartEvent)
+6 -4
View File
@@ -32,8 +32,10 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
@@ -159,7 +161,7 @@ func (f *ForwarderConfig) CheckAndSetDefaults() error {
return trace.BadParameter("missing parameter ServerID")
}
if f.Namespace == "" {
f.Namespace = defaults.Namespace
f.Namespace = apidefaults.Namespace
}
if f.Context == nil {
f.Context = context.TODO()
@@ -493,7 +495,7 @@ func (f *Forwarder) setupContext(ctx auth.Context, req *http.Request, isRemoteUs
// any user to access common API methods, e.g. discovery methods
// required for initial client usage, without it, restricted user's
// kubectl clients will not work
if !utils.SliceContainsStr(kubeGroups, teleport.KubeSystemAuthenticated) {
if !apiutils.SliceContainsStr(kubeGroups, teleport.KubeSystemAuthenticated) {
kubeGroups = append(kubeGroups, teleport.KubeSystemAuthenticated)
}
@@ -661,7 +663,7 @@ func (f *Forwarder) newStreamer(ctx *authContext) (events.Streamer, error) {
f.log.Debugf("Using async streamer for session.")
dir := filepath.Join(
f.cfg.DataDir, teleport.LogsDir, teleport.ComponentUpload,
events.StreamingLogsDir, defaults.Namespace,
events.StreamingLogsDir, apidefaults.Namespace,
)
fileStreamer, err := filesessions.NewStreamer(dir)
if err != nil {
@@ -1138,7 +1140,7 @@ func setupImpersonationHeaders(log log.FieldLogger, ctx authContext, headers htt
}
}
impersonateGroups = utils.Deduplicate(impersonateGroups)
impersonateGroups = apiutils.Deduplicate(impersonateGroups)
// By default, if no kubernetes_users is set (which will be a majority),
// user will impersonate themselves, which is the backwards-compatible behavior.
+6 -5
View File
@@ -24,6 +24,7 @@ import (
"sync"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
@@ -118,7 +119,7 @@ func NewTLSServer(cfg TLSServerConfig) (*TLSServer, error) {
TLSServerConfig: cfg,
Server: &http.Server{
Handler: limiter,
ReadHeaderTimeout: defaults.DefaultDialTimeout * 2,
ReadHeaderTimeout: apidefaults.DefaultDialTimeout * 2,
},
}
server.TLS.GetConfigForClient = server.GetConfigForClient
@@ -137,9 +138,9 @@ func NewTLSServer(cfg TLSServerConfig) (*TLSServer, error) {
Component: cfg.Component,
Announcer: cfg.AuthClient,
GetServerInfo: server.GetServerInfo,
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/10),
ServerTTL: defaults.ServerAnnounceTTL,
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/10),
ServerTTL: apidefaults.ServerAnnounceTTL,
CheckPeriod: defaults.HeartbeatCheckPeriod,
Clock: cfg.Clock,
OnHeartbeat: cfg.OnHeartbeat,
@@ -282,6 +283,6 @@ func (t *TLSServer) GetServerInfo() (types.Resource, error) {
KubernetesClusters: t.fwd.kubeClusters(),
},
}
srv.SetExpiry(t.Clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
srv.SetExpiry(t.Clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
return srv, nil
}
+3 -3
View File
@@ -22,7 +22,7 @@ import (
"sort"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/utils"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/trace"
"k8s.io/client-go/kubernetes"
@@ -180,7 +180,7 @@ func CheckOrSetKubeCluster(ctx context.Context, p KubeServicesPresence, kubeClus
return "", trace.Wrap(err)
}
if kubeClusterName != "" {
if !utils.SliceContainsStr(kubeClusterNames, kubeClusterName) {
if !apiutils.SliceContainsStr(kubeClusterNames, kubeClusterName) {
return "", trace.BadParameter("kubernetes cluster %q is not registered in this teleport cluster; you can list registered kubernetes clusters using 'tsh kube ls'", kubeClusterName)
}
return kubeClusterName, nil
@@ -191,7 +191,7 @@ func CheckOrSetKubeCluster(ctx context.Context, p KubeServicesPresence, kubeClus
if len(kubeClusterNames) == 0 {
return "", trace.NotFound("no kubernetes clusters registered")
}
if utils.SliceContainsStr(kubeClusterNames, teleportClusterName) {
if apiutils.SliceContainsStr(kubeClusterNames, teleportClusterName) {
return teleportClusterName, nil
}
return kubeClusterNames[0], nil
+3 -3
View File
@@ -29,10 +29,10 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apisshutils "github.com/gravitational/teleport/api/utils/sshutils"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/reversetunnel/track"
"github.com/gravitational/teleport/lib/sshutils"
"github.com/gravitational/teleport/lib/utils"
@@ -255,7 +255,7 @@ func (a *Agent) connect() (conn *ssh.Client, err error) {
for _, authMethod := range a.authMethods {
// Create a dialer (that respects HTTP proxies) and connect to remote host.
dialer := proxy.DialerFromEnvironment(a.Addr.Addr)
pconn, err := dialer.DialTimeout(a.Addr.AddrNetwork, a.Addr.Addr, defaults.DefaultDialTimeout)
pconn, err := dialer.DialTimeout(a.Addr.AddrNetwork, a.Addr.Addr, apidefaults.DefaultDialTimeout)
if err != nil {
a.log.Debugf("Dial to %v failed: %v.", a.Addr.Addr, err)
continue
@@ -267,7 +267,7 @@ func (a *Agent) connect() (conn *ssh.Client, err error) {
User: a.Username,
Auth: []ssh.AuthMethod{authMethod},
HostKeyCallback: a.checkHostSignature,
Timeout: defaults.DefaultDialTimeout,
Timeout: apidefaults.DefaultDialTimeout,
})
if err != nil {
a.log.Debugf("Failed to create client to %v: %v.", a.Addr.Addr, err)
+3 -3
View File
@@ -25,10 +25,10 @@ import (
"golang.org/x/crypto/ssh"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/api/utils/sshutils"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/srv/forward"
"github.com/gravitational/teleport/lib/utils/proxy"
@@ -154,7 +154,7 @@ func (s *localSite) DialAuthServer() (conn net.Conn, err error) {
// try and dial to one of them, as soon as we are successful, return the net.Conn
for _, authServer := range authServers {
conn, err = net.DialTimeout("tcp", authServer.GetAddr(), defaults.DefaultDialTimeout)
conn, err = net.DialTimeout("tcp", authServer.GetAddr(), apidefaults.DefaultDialTimeout)
if err == nil {
return conn, nil
}
@@ -316,7 +316,7 @@ func (s *localSite) getConn(params DialParams) (conn net.Conn, useTunnel bool, e
// If no tunnel connection was found, dial to the target host.
dialer := proxy.DialerFromEnvironment(params.To.String())
conn, directErr := dialer.DialTimeout(params.To.Network(), params.To.String(), defaults.DefaultDialTimeout)
conn, directErr := dialer.DialTimeout(params.To.Network(), params.To.String(), apidefaults.DefaultDialTimeout)
if directErr != nil {
s.log.WithError(directErr).WithField("address", params.To.String()).Debug("Error occurred while dialing directly.")
aggregateErr := trace.NewAggregate(tunnelErr, directErr)
+1 -1
View File
@@ -114,7 +114,7 @@ func (s *remoteSite) getRemoteClient() (auth.ClientI, bool, error) {
// authority to verify)
tlsConfig.ServerName = auth.EncodeClusterName(s.srv.ClusterName)
clt, err := auth.NewClient(client.Config{
Dialer: auth.ContextDialerFunc(s.authServerContextDialer),
Dialer: client.ContextDialerFunc(s.authServerContextDialer),
Credentials: []client.Credentials{
client.LoadTLS(tlsConfig),
},
+2 -2
View File
@@ -27,10 +27,10 @@ import (
"golang.org/x/crypto/ssh"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/api/utils/sshutils"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/utils"
"github.com/gravitational/teleport/lib/utils/proxy"
@@ -134,7 +134,7 @@ func (p *transport) start() {
if req == nil {
return
}
case <-time.After(defaults.DefaultDialTimeout):
case <-time.After(apidefaults.DefaultDialTimeout):
p.log.Warnf("Transport request failed: timed out waiting for request.")
return
}
+2 -1
View File
@@ -21,6 +21,7 @@ import (
"net"
"strings"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/reversetunnel"
"github.com/gravitational/teleport/lib/utils"
"github.com/gravitational/teleport/lib/web/app"
@@ -53,7 +54,7 @@ func (h *hostPolicyChecker) checkHost(ctx context.Context, host string) error {
host, strings.Join(h.dnsNames, ","))
}
if utils.SliceContainsStr(h.dnsNames, host) {
if apiutils.SliceContainsStr(h.dnsNames, host) {
return nil
}
+2 -1
View File
@@ -33,6 +33,7 @@ import (
"k8s.io/apimachinery/pkg/util/validation"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/lite"
@@ -627,7 +628,7 @@ func (d *Database) Check() error {
if errs := validation.IsDNS1035Label(d.Name); len(errs) > 0 {
return trace.BadParameter("invalid database %q name: %v", d.Name, errs)
}
if !utils.SliceContainsStr(defaults.DatabaseProtocols, d.Protocol) {
if !apiutils.SliceContainsStr(defaults.DatabaseProtocols, d.Protocol) {
return trace.BadParameter("unsupported database %q protocol %q, supported are: %v",
d.Name, d.Protocol, defaults.DatabaseProtocols)
}
+2 -2
View File
@@ -21,10 +21,10 @@ import (
"net/http"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/cache"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
kubeproxy "github.com/gravitational/teleport/lib/kube/proxy"
"github.com/gravitational/teleport/lib/labels"
@@ -208,7 +208,7 @@ func (process *TeleportProcess) initKubernetesService(log *logrus.Entry, conn *C
kubeServer, err := kubeproxy.NewTLSServer(kubeproxy.TLSServerConfig{
ForwarderConfig: kubeproxy.ForwarderConfig{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Keygen: cfg.Keygen,
ClusterName: teleportClusterName,
Authz: authorizer,
+14 -13
View File
@@ -50,6 +50,7 @@ import (
"github.com/gravitational/teleport/api/client/proto"
"github.com/gravitational/teleport/api/client/webclient"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/auth"
@@ -1353,7 +1354,7 @@ func (process *TeleportProcess) initAuthService() error {
Kind: types.KindAuthServer,
Version: types.V2,
Metadata: types.Metadata{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Name: process.Config.HostUUID,
},
Spec: types.ServerSpecV2{
@@ -1371,13 +1372,13 @@ func (process *TeleportProcess) initAuthService() error {
} else {
srv.Spec.Rotation = state.Spec.Rotation
}
srv.SetExpiry(process.Clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
srv.SetExpiry(process.Clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
return &srv, nil
},
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/10),
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/10),
CheckPeriod: defaults.HeartbeatCheckPeriod,
ServerTTL: defaults.ServerAnnounceTTL,
ServerTTL: apidefaults.ServerAnnounceTTL,
OnHeartbeat: func(err error) {
if err != nil {
process.BroadcastEvent(Event{Name: TeleportDegradedEvent, Payload: teleport.ComponentAuth})
@@ -1915,11 +1916,11 @@ func (process *TeleportProcess) initUploaderService(accessPoint auth.AccessPoint
return trace.Wrap(err)
}
// prepare dirs for uploader
streamingDir := []string{process.Config.DataDir, teleport.LogsDir, teleport.ComponentUpload, events.StreamingLogsDir, defaults.Namespace}
streamingDir := []string{process.Config.DataDir, teleport.LogsDir, teleport.ComponentUpload, events.StreamingLogsDir, apidefaults.Namespace}
paths := [][]string{
// DELETE IN (5.1.0)
// this directory will no longer be used after migration to 5.1.0
{process.Config.DataDir, teleport.LogsDir, teleport.ComponentUpload, events.SessionLogsDir, defaults.Namespace},
{process.Config.DataDir, teleport.LogsDir, teleport.ComponentUpload, events.SessionLogsDir, apidefaults.Namespace},
// This directory will remain to be used after migration to 5.1.0
streamingDir,
}
@@ -1949,7 +1950,7 @@ func (process *TeleportProcess) initUploaderService(accessPoint auth.AccessPoint
// see below
uploader, err := events.NewUploader(events.UploaderConfig{
DataDir: filepath.Join(process.Config.DataDir, teleport.LogsDir),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
ServerID: teleport.ComponentUpload,
AuditLog: auditLog,
EventsC: process.Config.UploadEventsC,
@@ -2080,7 +2081,7 @@ func (process *TeleportProcess) initDiagnosticService() error {
server := &http.Server{
Handler: mux,
ReadHeaderTimeout: defaults.DefaultDialTimeout,
ReadHeaderTimeout: apidefaults.DefaultDialTimeout,
ErrorLog: utils.NewStdlogger(log.Error, teleport.ComponentDiagnostic),
}
@@ -2653,7 +2654,7 @@ func (process *TeleportProcess) initProxyEndpoint(conn *Connector) error {
}
webServer = &http.Server{
Handler: proxyLimiter,
ReadHeaderTimeout: defaults.DefaultDialTimeout,
ReadHeaderTimeout: apidefaults.DefaultDialTimeout,
ErrorLog: utils.NewStdlogger(log.Error, teleport.ComponentProxy),
}
process.RegisterCriticalFunc("proxy.web", func() error {
@@ -2685,7 +2686,7 @@ func (process *TeleportProcess) initProxyEndpoint(conn *Connector) error {
regular.SetCiphers(cfg.Ciphers),
regular.SetKEXAlgorithms(cfg.KEXAlgorithms),
regular.SetMACAlgorithms(cfg.MACAlgorithms),
regular.SetNamespace(defaults.Namespace),
regular.SetNamespace(apidefaults.Namespace),
regular.SetRotationGetter(process.getRotation),
regular.SetFIPS(cfg.FIPS),
regular.SetOnHeartbeat(func(err error) {
@@ -2758,7 +2759,7 @@ func (process *TeleportProcess) initProxyEndpoint(conn *Connector) error {
}
kubeServer, err = kubeproxy.NewTLSServer(kubeproxy.TLSServerConfig{
ForwarderConfig: kubeproxy.ForwarderConfig{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Keygen: cfg.Keygen,
ClusterName: clusterName,
ReverseTunnelSrv: tsrv,
@@ -3068,7 +3069,7 @@ func (process *TeleportProcess) initApps() {
Kind: types.KindAppServer,
Version: types.V2,
Metadata: types.Metadata{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Name: process.Config.HostUUID,
},
Spec: types.ServerSpecV2{
+5 -4
View File
@@ -23,6 +23,7 @@ import (
"github.com/google/go-cmp/cmp"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/utils"
"github.com/gravitational/teleport/lib/utils/parse"
@@ -256,7 +257,7 @@ func ApplyAccessReview(req types.AccessRequest, rev types.AccessReview, author t
}
// role lists must be deduplicated and sorted
rev.Roles = utils.Deduplicate(rev.Roles)
rev.Roles = apiutils.Deduplicate(rev.Roles)
sort.Strings(rev.Roles)
// basic compatibility/sanity checks
@@ -931,7 +932,7 @@ func (m *RequestValidator) Validate(req types.AccessRequest) error {
// if no suggested reviewers were provided by the user then
// use the defaults suggested by the user's static roles.
if len(req.GetSuggestedReviewers()) == 0 {
req.SetSuggestedReviewers(utils.Deduplicate(m.SuggestedReviewers))
req.SetSuggestedReviewers(apiutils.Deduplicate(m.SuggestedReviewers))
}
}
return nil
@@ -949,7 +950,7 @@ func (m *RequestValidator) GetRequestableRoles() ([]string, error) {
var expanded []string
for _, role := range allRoles {
if n := role.GetName(); !utils.SliceContainsStr(m.user.GetRoles(), n) && m.CanRequestRole(n) {
if n := role.GetName(); !apiutils.SliceContainsStr(m.user.GetRoles(), n) && m.CanRequestRole(n) {
// user does not currently hold this role, and is allowed to request it.
expanded = append(expanded, n)
}
@@ -1119,7 +1120,7 @@ func (m *RequestValidator) SystemAnnotations() map[string][]string {
for k, va := range m.Annotations.Allow {
var filtered []string
for _, v := range va {
if !utils.SliceContainsStr(m.Annotations.Deny[k], v) {
if !apiutils.SliceContainsStr(m.Annotations.Deny[k], v) {
filtered = append(filtered, v)
}
}
+2 -2
View File
@@ -19,8 +19,8 @@ package services
import (
"github.com/gravitational/trace"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/utils"
)
@@ -32,7 +32,7 @@ func DefaultClusterConfig() types.ClusterConfig {
Version: types.V3,
Metadata: types.Metadata{
Name: types.MetaNameClusterConfig,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.ClusterConfigSpecV3{},
}
+4 -3
View File
@@ -24,6 +24,7 @@ import (
"context"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth/u2f"
"github.com/gravitational/teleport/lib/defaults"
@@ -306,7 +307,7 @@ func (r *GithubAuthRequest) Check() error {
if err != nil {
return trace.BadParameter("bad PublicKey: %v", err)
}
if (r.CertTTL > defaults.MaxCertDuration) || (r.CertTTL < defaults.MinCertDuration) {
if (r.CertTTL > apidefaults.MaxCertDuration) || (r.CertTTL < defaults.MinCertDuration) {
return trace.BadParameter("wrong CertTTL")
}
}
@@ -374,7 +375,7 @@ func (i *OIDCAuthRequest) Check() error {
if err != nil {
return trace.BadParameter("PublicKey: bad key: %v", err)
}
if (i.CertTTL > defaults.MaxCertDuration) || (i.CertTTL < defaults.MinCertDuration) {
if (i.CertTTL > apidefaults.MaxCertDuration) || (i.CertTTL < defaults.MinCertDuration) {
return trace.BadParameter("CertTTL: wrong certificate TTL")
}
}
@@ -439,7 +440,7 @@ func (i *SAMLAuthRequest) Check() error {
if err != nil {
return trace.BadParameter("PublicKey: bad key: %v", err)
}
if (i.CertTTL > defaults.MaxCertDuration) || (i.CertTTL < defaults.MinCertDuration) {
if (i.CertTTL > apidefaults.MaxCertDuration) || (i.CertTTL < defaults.MinCertDuration) {
return trace.BadParameter("CertTTL: wrong certificate TTL")
}
}
+10 -10
View File
@@ -20,8 +20,8 @@ import (
"fmt"
"testing"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/trace"
"github.com/stretchr/testify/require"
@@ -31,18 +31,18 @@ func TestCheckImpersonate(t *testing.T) {
noLabelsRole := &types.RoleV3{
Metadata: types.Metadata{
Name: "no-labels",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
}
wildcardRole := &types.RoleV3{
Metadata: types.Metadata{
Name: "wildcard",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
@@ -56,7 +56,7 @@ func TestCheckImpersonate(t *testing.T) {
wildcardDenyRole := &types.RoleV3{
Metadata: types.Metadata{
Name: "wildcard-deny-user",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Deny: types.RoleConditions{
@@ -78,7 +78,7 @@ func TestCheckImpersonate(t *testing.T) {
Version: types.V2,
Metadata: types.Metadata{
Name: name,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: props.labels,
},
Spec: types.UserSpecV2{
@@ -156,7 +156,7 @@ func TestCheckImpersonate(t *testing.T) {
&types.RoleV3{
Metadata: types.Metadata{
Name: "limited",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
@@ -199,7 +199,7 @@ func TestCheckImpersonate(t *testing.T) {
&types.RoleV3{
Metadata: types.Metadata{
Name: "team-impersonator",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
@@ -222,7 +222,7 @@ func TestCheckImpersonate(t *testing.T) {
&types.RoleV3{
Metadata: types.Metadata{
Name: "dev",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{
"team": "dev",
},
@@ -242,7 +242,7 @@ func TestCheckImpersonate(t *testing.T) {
&types.RoleV3{
Metadata: types.Metadata{
Name: "dev",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{
"team": "dev",
},
+2 -1
View File
@@ -23,6 +23,7 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/utils"
@@ -91,7 +92,7 @@ func (s *DynamicAccessService) SetAccessRequestState(ctx context.Context, params
req.SetResolveAnnotations(params.Annotations)
if len(params.Roles) > 0 {
for _, role := range params.Roles {
if !utils.SliceContainsStr(req.GetRoles(), role) {
if !apiutils.SliceContainsStr(req.GetRoles(), role) {
return nil, trace.BadParameter("role %q not in original request, overrides must be a subset of original role list", role)
}
}
+9 -8
View File
@@ -20,6 +20,7 @@ import (
"bytes"
"context"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/defaults"
@@ -281,7 +282,7 @@ func (p *certAuthorityParser) parse(event backend.Event) (types.Resource, error)
Version: types.V2,
Metadata: types.Metadata{
Name: name,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
}, nil
case types.OpPut:
@@ -696,7 +697,7 @@ func (p *userParser) parse(event backend.Event) (types.Resource, error) {
func newNodeParser() *nodeParser {
return &nodeParser{
baseParser: newBaseParser(backend.Key(nodesPrefix, defaults.Namespace)),
baseParser: newBaseParser(backend.Key(nodesPrefix, apidefaults.Namespace)),
}
}
@@ -759,7 +760,7 @@ func (p *tunnelConnectionParser) parse(event backend.Event) (types.Resource, err
Version: types.V2,
Metadata: types.Metadata{
Name: name,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
}, nil
case types.OpPut:
@@ -806,7 +807,7 @@ func (p *reverseTunnelParser) parse(event backend.Event) (types.Resource, error)
func newAppServerParser() *appServerParser {
return &appServerParser{
baseParser: newBaseParser(backend.Key(appsPrefix, serversPrefix, defaults.Namespace)),
baseParser: newBaseParser(backend.Key(appsPrefix, serversPrefix, apidefaults.Namespace)),
}
}
@@ -907,7 +908,7 @@ func (p *kubeServiceParser) parse(event backend.Event) (types.Resource, error) {
func newDatabaseServerParser() *databaseServerParser {
return &databaseServerParser{
baseParser: newBaseParser(backend.Key(dbServersPrefix, defaults.Namespace)),
baseParser: newBaseParser(backend.Key(dbServersPrefix, apidefaults.Namespace)),
}
}
@@ -927,7 +928,7 @@ func (p *databaseServerParser) parse(event backend.Event) (types.Resource, error
Version: types.V3,
Metadata: types.Metadata{
Name: name,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Description: hostID, // Pass host ID via description field for the cache.
},
}, nil
@@ -1007,7 +1008,7 @@ func resourceHeader(event backend.Event, kind, version string, offset int) (type
Version: version,
Metadata: types.Metadata{
Name: string(name),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
}, nil
}
@@ -1023,7 +1024,7 @@ func resourceHeaderWithTemplate(event backend.Event, hdr types.ResourceHeader, o
Version: hdr.Version,
Metadata: types.Metadata{
Name: string(name),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
}, nil
}
+3 -3
View File
@@ -23,11 +23,11 @@ import (
"os"
"testing"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/lite"
"github.com/gravitational/teleport/lib/backend/memory"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/services"
"github.com/stretchr/testify/assert"
@@ -108,7 +108,7 @@ func insertNodes(ctx context.Context, t assert.TestingT, svc services.Presence,
Version: types.V2,
Metadata: types.Metadata{
Name: name,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: labels,
},
Spec: types.ServerSpecV2{
@@ -126,7 +126,7 @@ func benchmarkGetNodes(ctx context.Context, b *testing.B, svc services.Presence,
var nodes []types.Server
var err error
for i := 0; i < b.N; i++ {
nodes, err = svc.GetNodes(ctx, defaults.Namespace, opts...)
nodes, err = svc.GetNodes(ctx, apidefaults.Namespace, opts...)
assert.NoError(b, err)
}
// do *something* with the loop result. probably unnecessary since the loop
+4 -3
View File
@@ -26,6 +26,7 @@ import (
"github.com/stretchr/testify/require"
"gopkg.in/check.v1"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/lite"
@@ -127,7 +128,7 @@ func TestDatabaseServersCRUD(t *testing.T) {
})
// Initially expect not to be returned any servers.
out, err := presence.GetDatabaseServers(ctx, defaults.Namespace)
out, err := presence.GetDatabaseServers(ctx, apidefaults.Namespace)
require.NoError(t, err)
require.Equal(t, 0, len(out))
@@ -158,7 +159,7 @@ func TestDatabaseServersCRUD(t *testing.T) {
require.NoError(t, err)
// Now expect no servers to be returned.
out, err = presence.GetDatabaseServers(ctx, defaults.Namespace)
out, err = presence.GetDatabaseServers(ctx, apidefaults.Namespace)
require.NoError(t, err)
require.Equal(t, 0, len(out))
@@ -185,7 +186,7 @@ func TestDatabaseServersCRUD(t *testing.T) {
require.NoError(t, err)
// Now expect no servers to be returned.
out, err = presence.GetDatabaseServers(ctx, defaults.Namespace)
out, err = presence.GetDatabaseServers(ctx, apidefaults.Namespace)
require.NoError(t, err)
require.Equal(t, 0, len(out))
}
+3 -3
View File
@@ -27,11 +27,11 @@ import (
"golang.org/x/crypto/bcrypt"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth/u2f"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/lite"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/services/suite"
@@ -184,7 +184,7 @@ func (r *ResourceSuite) TestGithubConnectorResource(c *check.C) {
Version: types.V3,
Metadata: types.Metadata{
Name: "github",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.GithubConnectorSpecV3{
ClientID: "aaa",
@@ -250,7 +250,7 @@ func newUserTestCase(c *check.C, name string, roles []string, withSecrets bool,
Version: types.V2,
Metadata: types.Metadata{
Name: name,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Expires: &expires,
},
Spec: types.UserSpecV2{
+12 -12
View File
@@ -20,8 +20,8 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/pborman/uuid"
)
@@ -34,19 +34,19 @@ func NewPresetEditorRole() types.Role {
Version: types.V3,
Metadata: types.Metadata{
Name: teleport.PresetEditorRoleName,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Description: "Edit cluster configuration",
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
CertificateFormat: constants.CertificateFormatStandard,
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
PortForwarding: types.NewBoolOption(true),
ForwardAgent: types.NewBool(true),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
types.NewRule(types.KindUser, RW()),
types.NewRule(types.KindRole, RW()),
@@ -73,19 +73,19 @@ func NewPresetAccessRole() types.Role {
Version: types.V3,
Metadata: types.Metadata{
Name: teleport.PresetAccessRoleName,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Description: "Access cluster resources",
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
CertificateFormat: constants.CertificateFormatStandard,
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
PortForwarding: types.NewBoolOption(true),
ForwardAgent: types.NewBool(true),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
@@ -113,16 +113,16 @@ func NewPresetAuditorRole() types.Role {
Version: types.V3,
Metadata: types.Metadata{
Name: teleport.PresetAuditorRoleName,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Description: "Review cluster events and replay sessions",
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
CertificateFormat: constants.CertificateFormatStandard,
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
types.NewRule(types.KindSession, RO()),
types.NewRule(types.KindEvent, RO()),
+35 -34
View File
@@ -28,9 +28,10 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/api/types/wrappers"
"github.com/gravitational/teleport/lib/defaults"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/modules"
"github.com/gravitational/teleport/lib/tlsca"
"github.com/gravitational/teleport/lib/utils"
@@ -115,18 +116,18 @@ func NewAdminRole() types.Role {
Version: types.V3,
Metadata: types.Metadata{
Name: teleport.AdminRoleName,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
CertificateFormat: constants.CertificateFormatStandard,
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
PortForwarding: types.NewBoolOption(true),
ForwardAgent: types.NewBool(true),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
@@ -151,7 +152,7 @@ func NewImplicitRole() types.Role {
Version: types.V3,
Metadata: types.Metadata{
Name: constants.DefaultImplicitRole,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -162,7 +163,7 @@ func NewImplicitRole() types.Role {
PortForwarding: types.NewBoolOption(false),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: types.CopyRulesSlice(DefaultImplicitRules),
},
},
@@ -176,18 +177,18 @@ func RoleForUser(u types.User) types.Role {
Version: types.V3,
Metadata: types.Metadata{
Name: RoleNameForUser(u.GetName()),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
CertificateFormat: constants.CertificateFormatStandard,
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
PortForwarding: types.NewBoolOption(true),
ForwardAgent: types.NewBool(true),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
@@ -216,19 +217,19 @@ func NewDowngradedOSSAdminRole() types.Role {
Version: types.V3,
Metadata: types.Metadata{
Name: teleport.AdminRoleName,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{teleport.OSSMigratedV6: types.True},
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
CertificateFormat: constants.CertificateFormatStandard,
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
PortForwarding: types.NewBoolOption(true),
ForwardAgent: types.NewBool(true),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
@@ -255,18 +256,18 @@ func NewOSSGithubRole(logins []string, kubeUsers []string, kubeGroups []string)
Version: types.V3,
Metadata: types.Metadata{
Name: "github-" + uuid.New(),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
CertificateFormat: constants.CertificateFormatStandard,
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
PortForwarding: types.NewBoolOption(true),
ForwardAgent: types.NewBool(true),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
@@ -292,14 +293,14 @@ func RoleForCertAuthority(ca types.CertAuthority) types.Role {
Version: types.V3,
Metadata: types.Metadata{
Name: RoleNameForCertAuthority(ca.GetClusterName()),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
@@ -422,7 +423,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
}
}
r.SetLogins(condition, utils.Deduplicate(outLogins))
r.SetLogins(condition, apiutils.Deduplicate(outLogins))
// apply templates to kubernetes groups
inKubeGroups := r.GetKubeGroups(condition)
@@ -437,7 +438,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
}
outKubeGroups = append(outKubeGroups, variableValues...)
}
r.SetKubeGroups(condition, utils.Deduplicate(outKubeGroups))
r.SetKubeGroups(condition, apiutils.Deduplicate(outKubeGroups))
// apply templates to kubernetes users
inKubeUsers := r.GetKubeUsers(condition)
@@ -452,7 +453,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
}
outKubeUsers = append(outKubeUsers, variableValues...)
}
r.SetKubeUsers(condition, utils.Deduplicate(outKubeUsers))
r.SetKubeUsers(condition, apiutils.Deduplicate(outKubeUsers))
// apply templates to database names
inDbNames := r.GetDatabaseNames(condition)
@@ -467,7 +468,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
}
outDbNames = append(outDbNames, variableValues...)
}
r.SetDatabaseNames(condition, utils.Deduplicate(outDbNames))
r.SetDatabaseNames(condition, apiutils.Deduplicate(outDbNames))
// apply templates to database users
inDbUsers := r.GetDatabaseUsers(condition)
@@ -482,7 +483,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
}
outDbUsers = append(outDbUsers, variableValues...)
}
r.SetDatabaseUsers(condition, utils.Deduplicate(outDbUsers))
r.SetDatabaseUsers(condition, apiutils.Deduplicate(outDbUsers))
// apply templates to node labels
inLabels := r.GetNodeLabels(condition)
@@ -537,8 +538,8 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
}
outCond.Roles = append(outCond.Roles, variableValues...)
}
outCond.Users = utils.Deduplicate(outCond.Users)
outCond.Roles = utils.Deduplicate(outCond.Roles)
outCond.Users = apiutils.Deduplicate(outCond.Users)
outCond.Roles = apiutils.Deduplicate(outCond.Roles)
outCond.Where = inCond.Where
r.SetImpersonateConditions(condition, outCond)
}
@@ -580,7 +581,7 @@ func applyLabelsTraits(inLabels types.Labels, traits map[string][]string) types.
}
values = append(values, valVars...)
}
outLabels[keyVars[0]] = utils.Deduplicate(values)
outLabels[keyVars[0]] = apiutils.Deduplicate(values)
}
return outLabels
}
@@ -623,7 +624,7 @@ func ApplyValueTraits(val string, traits map[string][]string) ([]string, error)
func ruleScore(r *types.Rule) int {
score := 0
// wildcard rules are less specific
if utils.SliceContainsStr(r.Resources, types.Wildcard) {
if apiutils.SliceContainsStr(r.Resources, types.Wildcard) {
score -= 4
} else if len(r.Resources) == 1 {
// rules that match specific resource are more specific than
@@ -631,7 +632,7 @@ func ruleScore(r *types.Rule) int {
score += 2
}
// rules that have wildcard verbs are less specific
if utils.SliceContainsStr(r.Verbs, types.Wildcard) {
if apiutils.SliceContainsStr(r.Verbs, types.Wildcard) {
score -= 2
}
// rules that supply 'where' or 'actions' are more specific
@@ -1092,7 +1093,7 @@ func MatchLabels(selector types.Labels, target map[string]string) (bool, string,
return false, fmt.Sprintf("no key match: '%v'", key), nil
}
if !utils.SliceContainsStr(selectorValues, types.Wildcard) {
if !apiutils.SliceContainsStr(selectorValues, types.Wildcard) {
result, err := utils.SliceMatchesRegex(targetVal, selectorValues)
if err != nil {
return false, "", trace.Wrap(err)
@@ -1319,7 +1320,7 @@ func (set RoleSet) GetLoginsForTTL(ttl time.Duration) (logins []string, matchedT
logins = append(logins, role.GetLogins(Allow)...)
}
}
return utils.Deduplicate(logins), matchedTTL
return apiutils.Deduplicate(logins), matchedTTL
}
// CheckAccessToRemoteCluster checks if a role has access to remote cluster. Deny rules are
+109 -108
View File
@@ -27,13 +27,14 @@ import (
"github.com/google/go-cmp/cmp"
"github.com/gravitational/teleport/api/constants"
"github.com/gravitational/teleport/api/defaults"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/api/types/wrappers"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/api/utils/sshutils"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/fixtures"
"github.com/gravitational/teleport/lib/tlsca"
"github.com/gravitational/teleport/lib/utils"
"github.com/pborman/uuid"
"github.com/stretchr/testify/require"
@@ -76,7 +77,7 @@ func TestConnAndSessLimits(t *testing.T) {
Version: types.V3,
Metadata: types.Metadata{
Name: fmt.Sprintf("role-%d", i),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -170,24 +171,24 @@ func TestRoleParse(t *testing.T) {
Version: types.V3,
Metadata: types.Metadata{
Name: "defrole",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
CertificateFormat: constants.CertificateFormatStandard,
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
PortForwarding: types.NewBoolOption(true),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
NodeLabels: types.Labels{},
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
DatabaseLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
},
@@ -237,7 +238,7 @@ func TestRoleParse(t *testing.T) {
Version: types.V3,
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{"a-b": "c"},
},
Spec: types.RoleSpecV3{
@@ -247,7 +248,7 @@ func TestRoleParse(t *testing.T) {
PortForwarding: types.NewBoolOption(true),
ClientIdleTimeout: types.NewDuration(17 * time.Minute),
DisconnectExpiredCert: types.NewBool(true),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
NodeLabels: types.Labels{"a": []string{"b"}, "c-d": []string{"e"}},
@@ -269,7 +270,7 @@ func TestRoleParse(t *testing.T) {
},
},
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Logins: []string{"c"},
},
},
@@ -319,7 +320,7 @@ func TestRoleParse(t *testing.T) {
Version: types.V3,
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -329,7 +330,7 @@ func TestRoleParse(t *testing.T) {
PortForwarding: types.NewBoolOption(true),
ClientIdleTimeout: types.NewDuration(0),
DisconnectExpiredCert: types.NewBool(false),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
NodeLabels: types.Labels{"a": []string{"b"}},
@@ -349,7 +350,7 @@ func TestRoleParse(t *testing.T) {
},
},
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Logins: []string{"c"},
},
},
@@ -388,7 +389,7 @@ func TestRoleParse(t *testing.T) {
Version: types.V3,
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -398,7 +399,7 @@ func TestRoleParse(t *testing.T) {
PortForwarding: types.NewBoolOption(true),
ClientIdleTimeout: types.NewDuration(0),
DisconnectExpiredCert: types.NewBool(false),
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
NodeLabels: types.Labels{
@@ -424,7 +425,7 @@ func TestRoleParse(t *testing.T) {
Namespaces: []string{"default"},
},
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Logins: []string{"c"},
},
},
@@ -524,7 +525,7 @@ func TestValidateRole(t *testing.T) {
err := ValidateRole(&types.RoleV3{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: tc.spec,
})
@@ -569,7 +570,7 @@ func TestCheckAccessToServer(t *testing.T) {
serverWorker := &types.ServerV2{
Metadata: types.Metadata{
Name: "b",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{"role": "worker", "status": "follower"},
},
}
@@ -592,7 +593,7 @@ func TestCheckAccessToServer(t *testing.T) {
r := types.RoleV3{
Metadata: types.Metadata{
Name: "name",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -627,7 +628,7 @@ func TestCheckAccessToServer(t *testing.T) {
roles: []types.RoleV3{
newRole(func(r *types.RoleV3) {
r.Spec.Allow.Logins = []string{"admin"}
r.Spec.Allow.Namespaces = []string{defaults.Namespace}
r.Spec.Allow.Namespaces = []string{apidefaults.Namespace}
}),
},
checks: []check{
@@ -876,7 +877,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -902,7 +903,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -911,7 +912,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
Allow: types.RoleConditions{
Logins: []string{"admin"},
ClusterLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
},
@@ -928,14 +929,14 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
MaxSessionTTL: types.Duration(20 * time.Hour),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
},
@@ -952,7 +953,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -960,21 +961,21 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
},
Allow: types.RoleConditions{
ClusterLabels: types.Labels{"role": []string{"worker"}},
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
},
{
Metadata: types.Metadata{
Name: "name2",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
MaxSessionTTL: types.Duration(20 * time.Hour),
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
},
@@ -991,7 +992,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -1000,7 +1001,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
Allow: types.RoleConditions{
Logins: []string{"admin"},
ClusterLabels: types.Labels{"role": []string{}},
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
},
@@ -1017,7 +1018,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -1026,14 +1027,14 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
Allow: types.RoleConditions{
Logins: []string{"admin"},
ClusterLabels: types.Labels{"role": []string{"worker"}},
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
},
{
Metadata: types.Metadata{
Name: "name2",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -1059,7 +1060,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
@@ -1068,7 +1069,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
Allow: types.RoleConditions{
Logins: []string{"admin"},
ClusterLabels: types.Labels{"role": []string{"^db(.*)$"}, "status": []string{"follow*"}},
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
},
@@ -1137,11 +1138,11 @@ func TestCheckRuleAccess(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
types.NewRule(types.KindSSHSession, []string{types.VerbRead}),
},
@@ -1150,8 +1151,8 @@ func TestCheckRuleAccess(t *testing.T) {
},
},
checks: []check{
{rule: types.KindSSHSession, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: true},
{rule: types.KindSSHSession, verb: types.VerbList, namespace: defaults.Namespace, hasAccess: false},
{rule: types.KindSSHSession, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: true},
{rule: types.KindSSHSession, verb: types.VerbList, namespace: apidefaults.Namespace, hasAccess: false},
},
},
{
@@ -1160,7 +1161,7 @@ func TestCheckRuleAccess(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
@@ -1174,11 +1175,11 @@ func TestCheckRuleAccess(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name2",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
types.NewRule(types.KindSSHSession, []string{types.VerbCreate, types.VerbRead}),
},
@@ -1187,10 +1188,10 @@ func TestCheckRuleAccess(t *testing.T) {
},
},
checks: []check{
{rule: types.KindSSHSession, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: true},
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: defaults.Namespace, hasAccess: true},
{rule: types.KindSSHSession, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: true},
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: apidefaults.Namespace, hasAccess: true},
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: "system", hasAccess: false},
{rule: types.KindRole, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: false},
{rule: types.KindRole, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: false},
},
},
{
@@ -1199,17 +1200,17 @@ func TestCheckRuleAccess(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
types.NewRule(types.KindSSHSession, []string{types.VerbCreate}),
},
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
types.NewRule(types.KindSSHSession, []string{types.VerbCreate}),
},
@@ -1218,7 +1219,7 @@ func TestCheckRuleAccess(t *testing.T) {
},
},
checks: []check{
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: defaults.Namespace, hasAccess: false},
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: apidefaults.Namespace, hasAccess: false},
},
},
{
@@ -1227,11 +1228,11 @@ func TestCheckRuleAccess(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
{
Resources: []string{types.KindSession},
@@ -1247,8 +1248,8 @@ func TestCheckRuleAccess(t *testing.T) {
},
},
checks: []check{
{rule: types.KindSession, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: false},
{rule: types.KindSession, verb: types.VerbList, namespace: defaults.Namespace, hasAccess: false},
{rule: types.KindSession, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: false},
{rule: types.KindSession, verb: types.VerbList, namespace: apidefaults.Namespace, hasAccess: false},
{
context: testContext{
buffer: &bytes.Buffer{},
@@ -1267,7 +1268,7 @@ func TestCheckRuleAccess(t *testing.T) {
},
rule: types.KindSession,
verb: types.VerbRead,
namespace: defaults.Namespace,
namespace: apidefaults.Namespace,
hasAccess: true,
},
{
@@ -1285,7 +1286,7 @@ func TestCheckRuleAccess(t *testing.T) {
},
rule: types.KindSession,
verb: types.VerbRead,
namespace: defaults.Namespace,
namespace: apidefaults.Namespace,
hasAccess: false,
},
},
@@ -1296,11 +1297,11 @@ func TestCheckRuleAccess(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
{
Resources: []string{types.KindRole},
@@ -1316,8 +1317,8 @@ func TestCheckRuleAccess(t *testing.T) {
},
},
checks: []check{
{rule: types.KindRole, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: false},
{rule: types.KindRole, verb: types.VerbList, namespace: defaults.Namespace, hasAccess: false},
{rule: types.KindRole, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: false},
{rule: types.KindRole, verb: types.VerbList, namespace: apidefaults.Namespace, hasAccess: false},
{
context: testContext{
buffer: &bytes.Buffer{},
@@ -1331,7 +1332,7 @@ func TestCheckRuleAccess(t *testing.T) {
},
rule: types.KindRole,
verb: types.VerbRead,
namespace: defaults.Namespace,
namespace: apidefaults.Namespace,
hasAccess: true,
},
},
@@ -1342,11 +1343,11 @@ func TestCheckRuleAccess(t *testing.T) {
{
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
{
Resources: []string{types.Wildcard},
@@ -1379,7 +1380,7 @@ func TestCheckRuleAccess(t *testing.T) {
},
rule: types.KindRole,
verb: types.VerbRead,
namespace: defaults.Namespace,
namespace: apidefaults.Namespace,
hasAccess: true,
matchBuffer: "more specific rule",
},
@@ -1864,7 +1865,7 @@ func TestApplyTraits(t *testing.T) {
Version: types.V3,
Metadata: types.Metadata{
Name: "name1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
@@ -2080,7 +2081,7 @@ func TestBoolOptions(t *testing.T) {
Version: types.V3,
Metadata: types.Metadata{
Name: "role-name",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: tt.inOptions,
@@ -2114,10 +2115,10 @@ func TestCheckAccessToDatabase(t *testing.T) {
},
}
roleDevProd := &types.RoleV3{
Metadata: types.Metadata{Name: "dev-prod", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "dev-prod", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseLabels: types.Labels{"env": []string{"prod"}},
DatabaseNames: []string{"test"},
DatabaseUsers: []string{"dev"},
@@ -2125,13 +2126,13 @@ func TestCheckAccessToDatabase(t *testing.T) {
},
}
roleDevProdWithMFA := &types.RoleV3{
Metadata: types.Metadata{Name: "dev-prod", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "dev-prod", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
RequireSessionMFA: true,
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseLabels: types.Labels{"env": []string{"prod"}},
DatabaseNames: []string{"test"},
DatabaseUsers: []string{"dev"},
@@ -2141,15 +2142,15 @@ func TestCheckAccessToDatabase(t *testing.T) {
// Database labels are not set in allow/deny rules on purpose to test
// that they're set during check and set defaults below.
roleDeny := &types.RoleV3{
Metadata: types.Metadata{Name: "deny", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "deny", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseNames: []string{types.Wildcard},
DatabaseUsers: []string{types.Wildcard},
},
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseNames: []string{"postgres"},
DatabaseUsers: []string{"postgres"},
},
@@ -2270,10 +2271,10 @@ func TestCheckAccessToDatabaseUser(t *testing.T) {
},
}
roleDevProd := &types.RoleV3{
Metadata: types.Metadata{Name: "dev-prod", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "dev-prod", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseLabels: types.Labels{"env": []string{"prod"}},
DatabaseUsers: []string{"dev"},
},
@@ -2326,36 +2327,36 @@ func TestCheckAccessToDatabaseUser(t *testing.T) {
func TestCheckDatabaseNamesAndUsers(t *testing.T) {
roleEmpty := &types.RoleV3{
Metadata: types.Metadata{Name: "roleA", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "roleA", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{MaxSessionTTL: types.Duration(time.Hour)},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
}
roleA := &types.RoleV3{
Metadata: types.Metadata{Name: "roleA", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "roleA", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{MaxSessionTTL: types.Duration(2 * time.Hour)},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseNames: []string{"postgres", "main"},
DatabaseUsers: []string{"postgres", "alice"},
},
},
}
roleB := &types.RoleV3{
Metadata: types.Metadata{Name: "roleB", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "roleB", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{MaxSessionTTL: types.Duration(time.Hour)},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseNames: []string{"metrics"},
DatabaseUsers: []string{"bob"},
},
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseNames: []string{"postgres"},
DatabaseUsers: []string{"postgres"},
},
@@ -2434,32 +2435,32 @@ func TestCheckAccessToDatabaseService(t *testing.T) {
map[string]string{"env": "prod"},
types.DatabaseServerSpecV3{})
roleAdmin := &types.RoleV3{
Metadata: types.Metadata{Name: "admin", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "admin", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
},
},
}
roleDev := &types.RoleV3{
Metadata: types.Metadata{Name: "dev", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "dev", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseLabels: types.Labels{"env": []string{"stage"}},
},
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
DatabaseLabels: types.Labels{"arch": []string{"amd64"}},
},
},
}
roleIntern := &types.RoleV3{
Metadata: types.Metadata{Name: "intern", Namespace: defaults.Namespace},
Metadata: types.Metadata{Name: "intern", Namespace: apidefaults.Namespace},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
}
@@ -2541,7 +2542,7 @@ func TestCheckAccessToKubernetes(t *testing.T) {
wildcardRole := &types.RoleV3{
Metadata: types.Metadata{
Name: "wildcard-labels",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
@@ -2553,14 +2554,14 @@ func TestCheckAccessToKubernetes(t *testing.T) {
matchingLabelsRole := &types.RoleV3{
Metadata: types.Metadata{
Name: "matching-labels",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
KubernetesLabels: types.Labels{
"foo": utils.Strings{"bar"},
"baz": utils.Strings{"qux"},
"foo": apiutils.Strings{"bar"},
"baz": apiutils.Strings{"qux"},
},
},
},
@@ -2568,17 +2569,17 @@ func TestCheckAccessToKubernetes(t *testing.T) {
matchingLabelsRoleWithMFA := &types.RoleV3{
Metadata: types.Metadata{
Name: "matching-labels",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
RequireSessionMFA: true,
},
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
KubernetesLabels: types.Labels{
"foo": utils.Strings{"bar"},
"baz": utils.Strings{"qux"},
"foo": apiutils.Strings{"bar"},
"baz": apiutils.Strings{"qux"},
},
},
},
@@ -2586,25 +2587,25 @@ func TestCheckAccessToKubernetes(t *testing.T) {
noLabelsRole := &types.RoleV3{
Metadata: types.Metadata{
Name: "no-labels",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
}
mismatchingLabelsRole := &types.RoleV3{
Metadata: types.Metadata{
Name: "mismatching-labels",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
KubernetesLabels: types.Labels{
"qux": utils.Strings{"baz"},
"bar": utils.Strings{"foo"},
"qux": apiutils.Strings{"baz"},
"bar": apiutils.Strings{"foo"},
},
},
},
@@ -2699,7 +2700,7 @@ func TestCheckAccessToKubernetes(t *testing.T) {
for _, r := range tc.roles {
set = append(set, r)
}
err := set.CheckAccessToKubernetes(defaults.Namespace, tc.cluster, tc.mfaParams)
err := set.CheckAccessToKubernetes(apidefaults.Namespace, tc.cluster, tc.mfaParams)
if tc.hasAccess {
require.NoError(t, err)
} else {
@@ -2742,7 +2743,7 @@ func BenchmarkCheckAccessToServer(b *testing.B) {
Version: types.V2,
Metadata: types.Metadata{
Name: hostname,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.ServerSpecV2{
Addr: "127.0.0.1:3022",
@@ -2761,7 +2762,7 @@ func BenchmarkCheckAccessToServer(b *testing.B) {
Version: types.V3,
Metadata: types.Metadata{
Name: strconv.Itoa(i),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Allow: types.RoleConditions{
+6 -4
View File
@@ -21,7 +21,9 @@ import (
"fmt"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/utils"
@@ -246,12 +248,12 @@ func UnmarshalServer(bytes []byte, kind string, opts ...MarshalOption) (types.Se
s.SetExpiry(cfg.Expires)
}
if s.Metadata.Expires != nil {
utils.UTC(s.Metadata.Expires)
apiutils.UTC(s.Metadata.Expires)
}
// Force the timestamps to UTC for consistency.
// See https://github.com/gogo/protobuf/issues/519 for details on issues this causes for proto.Clone
utils.UTC(&s.Spec.Rotation.Started)
utils.UTC(&s.Spec.Rotation.LastRotated)
apiutils.UTC(&s.Spec.Rotation.Started)
apiutils.UTC(&s.Spec.Rotation.LastRotated)
return &s, nil
}
return nil, trace.BadParameter("server resource version %q is not supported", h.Version)
@@ -314,5 +316,5 @@ func MarshalServers(s []types.Server) ([]byte, error) {
// NodeHasMissedKeepAlives checks if node has missed its keep alive
func NodeHasMissedKeepAlives(s types.Server) bool {
serverExpiry := s.Expiry()
return serverExpiry.Before(time.Now().Add(defaults.ServerAnnounceTTL - (defaults.ServerKeepAliveTTL * 2)))
return serverExpiry.Before(time.Now().Add(apidefaults.ServerAnnounceTTL - (apidefaults.ServerKeepAliveTTL * 2)))
}
+4 -3
View File
@@ -21,6 +21,7 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/fixtures"
@@ -42,7 +43,7 @@ func (s *ServerSuite) TestServersCompare(c *check.C) {
Version: types.V2,
Metadata: types.Metadata{
Name: "node1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{"a": "b"},
},
Spec: types.ServerSpecV2{
@@ -166,7 +167,7 @@ func TestUnmarshalServerKubernetes(t *testing.T) {
Kind: types.KindKubeService,
Metadata: types.Metadata{
Name: "foo",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
},
},
@@ -187,7 +188,7 @@ func TestUnmarshalServerKubernetes(t *testing.T) {
Kind: types.KindKubeService,
Metadata: types.Metadata{
Name: "foo",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.ServerSpecV2{
KubernetesClusters: []*types.KubernetesCluster{
+2 -2
View File
@@ -21,8 +21,8 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/fixtures"
"github.com/gravitational/teleport/lib/utils"
@@ -115,7 +115,7 @@ func TestServerDeepCopy(t *testing.T) {
Version: types.V2,
Metadata: types.Metadata{
Name: "a",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Labels: map[string]string{"label": "value"},
Expires: &expires,
},
+4 -3
View File
@@ -20,6 +20,7 @@ import (
"encoding/json"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/utils"
"github.com/gravitational/trace"
@@ -43,8 +44,8 @@ func UnmarshalWebSession(bytes []byte, opts ...MarshalOption) (types.WebSession,
if err := utils.FastUnmarshal(bytes, &ws); err != nil {
return nil, trace.Wrap(err)
}
utils.UTC(&ws.Spec.BearerTokenExpires)
utils.UTC(&ws.Spec.Expires)
apiutils.UTC(&ws.Spec.BearerTokenExpires)
apiutils.UTC(&ws.Spec.Expires)
if err := ws.CheckAndSetDefaults(); err != nil {
return nil, trace.Wrap(err)
@@ -138,7 +139,7 @@ func UnmarshalWebToken(bytes []byte, opts ...MarshalOption) (types.WebToken, err
if !config.Expires.IsZero() {
token.Metadata.SetExpiry(config.Expires)
}
utils.UTC(token.Metadata.Expires)
apiutils.UTC(token.Metadata.Expires)
return &token, nil
}
return nil, trace.BadParameter("web token resource version %v is not supported", hdr.Version)
+2 -2
View File
@@ -19,8 +19,8 @@ package services
import (
"github.com/gravitational/trace"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/utils"
)
@@ -32,7 +32,7 @@ func DefaultStaticTokens() types.StaticTokens {
Version: types.V2,
Metadata: types.Metadata{
Name: types.MetaNameStaticTokens,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.StaticTokensSpecV2{
StaticTokens: []types.ProvisionTokenV1{},
+27 -26
View File
@@ -32,6 +32,7 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth/u2f"
"github.com/gravitational/teleport/lib/defaults"
@@ -110,7 +111,7 @@ func NewTestCAWithConfig(config TestCAConfig) *types.CertAuthorityV2 {
Version: types.V2,
Metadata: types.Metadata{
Name: config.ClusterName,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.CertAuthoritySpecV2{
Type: config.Type,
@@ -173,7 +174,7 @@ func newUser(name string, roles []string) types.User {
Version: types.V2,
Metadata: types.Metadata{
Name: name,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.UserSpecV2{
Roles: roles,
@@ -230,7 +231,7 @@ func (s *ServicesTestSuite) UsersExpiry(c *check.C) {
Version: types.V2,
Metadata: types.Metadata{
Name: "foo",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Expires: &expiresAt,
},
Spec: types.UserSpecV2{},
@@ -343,11 +344,11 @@ func NewServer(kind, name, addr, namespace string) *types.ServerV2 {
func (s *ServicesTestSuite) ServerCRUD(c *check.C) {
ctx := context.Background()
// SSH service.
out, err := s.PresenceS.GetNodes(ctx, defaults.Namespace)
out, err := s.PresenceS.GetNodes(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(len(out), check.Equals, 0)
srv := NewServer(types.KindNode, "srv1", "127.0.0.1:2022", defaults.Namespace)
srv := NewServer(types.KindNode, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
_, err = s.PresenceS.UpsertNode(ctx, srv)
c.Assert(err, check.IsNil)
@@ -374,7 +375,7 @@ func (s *ServicesTestSuite) ServerCRUD(c *check.C) {
c.Assert(err, check.IsNil)
c.Assert(len(out), check.Equals, 0)
proxy := NewServer(types.KindProxy, "proxy1", "127.0.0.1:2023", defaults.Namespace)
proxy := NewServer(types.KindProxy, "proxy1", "127.0.0.1:2023", apidefaults.Namespace)
c.Assert(s.PresenceS.UpsertProxy(proxy), check.IsNil)
out, err = s.PresenceS.GetProxies()
@@ -395,7 +396,7 @@ func (s *ServicesTestSuite) ServerCRUD(c *check.C) {
c.Assert(err, check.IsNil)
c.Assert(len(out), check.Equals, 0)
auth := NewServer(types.KindAuthServer, "auth1", "127.0.0.1:2025", defaults.Namespace)
auth := NewServer(types.KindAuthServer, "auth1", "127.0.0.1:2025", apidefaults.Namespace)
c.Assert(s.PresenceS.UpsertAuthServer(auth), check.IsNil)
out, err = s.PresenceS.GetAuthServers()
@@ -409,9 +410,9 @@ func (s *ServicesTestSuite) ServerCRUD(c *check.C) {
c.Assert(err, check.IsNil)
c.Assert(len(out), check.Equals, 0)
kube1 := NewServer(types.KindKubeService, "kube1", "10.0.0.1:3026", defaults.Namespace)
kube1 := NewServer(types.KindKubeService, "kube1", "10.0.0.1:3026", apidefaults.Namespace)
c.Assert(s.PresenceS.UpsertKubeService(ctx, kube1), check.IsNil)
kube2 := NewServer(types.KindKubeService, "kube2", "10.0.0.2:3026", defaults.Namespace)
kube2 := NewServer(types.KindKubeService, "kube2", "10.0.0.2:3026", apidefaults.Namespace)
c.Assert(s.PresenceS.UpsertKubeService(ctx, kube2), check.IsNil)
out, err = s.PresenceS.GetKubeServices(ctx)
@@ -440,7 +441,7 @@ func NewAppServer(name string, internalAddr string, publicAddr string) *types.Se
Version: types.V2,
Metadata: types.Metadata{
Name: uuid.New(),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.ServerSpecV2{
Apps: []*types.App{
@@ -462,7 +463,7 @@ func (s *ServicesTestSuite) AppServerCRUD(c *check.C) {
server := NewAppServer("foo", "http://127.0.0.1:8080", "foo.example.com")
// Expect not to be returned any applications and trace.NotFound.
out, err := s.PresenceS.GetAppServers(ctx, defaults.Namespace)
out, err := s.PresenceS.GetAppServers(ctx, apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(len(out), check.Equals, 0)
@@ -493,7 +494,7 @@ func newReverseTunnel(clusterName string, dialAddrs []string) *types.ReverseTunn
Version: types.V2,
Metadata: types.Metadata{
Name: clusterName,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.ReverseTunnelSpecV2{
ClusterName: clusterName,
@@ -676,14 +677,14 @@ func (s *ServicesTestSuite) RolesCRUD(c *check.C) {
Version: types.V3,
Metadata: types.Metadata{
Name: "role1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.RoleSpecV3{
Options: types.RoleOptions{
MaxSessionTTL: types.Duration(time.Hour),
PortForwarding: types.NewBoolOption(true),
CertificateFormat: constants.CertificateFormatStandard,
BPF: defaults.EnhancedEvents(),
BPF: apidefaults.EnhancedEvents(),
},
Allow: types.RoleConditions{
Logins: []string{"root", "bob"},
@@ -691,13 +692,13 @@ func (s *ServicesTestSuite) RolesCRUD(c *check.C) {
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
DatabaseLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
Rules: []types.Rule{
types.NewRule(types.KindRole, services.RO()),
},
},
Deny: types.RoleConditions{
Namespaces: []string{defaults.Namespace},
Namespaces: []string{apidefaults.Namespace},
},
},
}
@@ -733,8 +734,8 @@ func (s *ServicesTestSuite) NamespacesCRUD(c *check.C) {
Kind: types.KindNamespace,
Version: types.V2,
Metadata: types.Metadata{
Name: defaults.Namespace,
Namespace: defaults.Namespace,
Name: apidefaults.Namespace,
Namespace: apidefaults.Namespace,
},
}
err = s.PresenceS.UpsertNamespace(ns)
@@ -828,7 +829,7 @@ func (s *ServicesTestSuite) SAMLCRUD(c *check.C) {
Version: types.V2,
Metadata: types.Metadata{
Name: "saml1",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.SAMLConnectorSpecV2{
Issuer: "http://example.com",
@@ -953,7 +954,7 @@ func (s *ServicesTestSuite) GithubConnectorCRUD(c *check.C) {
Version: types.V3,
Metadata: types.Metadata{
Name: "github",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.GithubConnectorSpecV3{
ClientID: "aaa",
@@ -1523,7 +1524,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
Version: types.V2,
Metadata: types.Metadata{
Name: "testnamespace",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
}
err := s.PresenceS.UpsertNamespace(ns)
@@ -1620,7 +1621,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
Kind: types.KindNode,
},
crud: func(context.Context) types.Resource {
srv := NewServer(types.KindNode, "srv1", "127.0.0.1:2022", defaults.Namespace)
srv := NewServer(types.KindNode, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
_, err := s.PresenceS.UpsertNode(ctx, srv)
c.Assert(err, check.IsNil)
@@ -1640,7 +1641,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
Kind: types.KindProxy,
},
crud: func(context.Context) types.Resource {
srv := NewServer(types.KindProxy, "srv1", "127.0.0.1:2022", defaults.Namespace)
srv := NewServer(types.KindProxy, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
err := s.PresenceS.UpsertProxy(srv)
c.Assert(err, check.IsNil)
@@ -1734,7 +1735,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
Version: types.V2,
Metadata: types.Metadata{
Name: "shmest",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
}
err := s.PresenceS.UpsertNamespace(ns)
@@ -1884,7 +1885,7 @@ func (s *ServicesTestSuite) ProxyWatcher(c *check.C) {
c.Fatalf("Timeout waiting for ProxyWatcher reset")
}
proxy := NewServer(types.KindProxy, "proxy1", "127.0.0.1:2023", defaults.Namespace)
proxy := NewServer(types.KindProxy, "proxy1", "127.0.0.1:2023", apidefaults.Namespace)
c.Assert(s.PresenceS.UpsertProxy(proxy), check.IsNil)
// the first event is always the current list of proxies
@@ -1901,7 +1902,7 @@ func (s *ServicesTestSuite) ProxyWatcher(c *check.C) {
}
// add a second proxy
proxy2 := NewServer(types.KindProxy, "proxy2", "127.0.0.1:2023", defaults.Namespace)
proxy2 := NewServer(types.KindProxy, "proxy2", "127.0.0.1:2023", apidefaults.Namespace)
c.Assert(s.PresenceS.UpsertProxy(proxy2), check.IsNil)
// watcher should detect the proxy list change
+2 -1
View File
@@ -20,6 +20,7 @@ import (
"fmt"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/utils"
"github.com/gravitational/teleport/lib/utils/parse"
@@ -34,7 +35,7 @@ func TraitsToRoles(ms types.TraitMappingSet, traits map[string][]string) (warnin
warnings = traitsToRoles(ms, traits, func(role string, expanded bool) {
roles = append(roles, role)
})
return warnings, utils.Deduplicate(roles)
return warnings, apiutils.Deduplicate(roles)
}
// TraitsToRoleMatchers maps the supplied traits to a list of role matchers. Prefer calling
+2 -2
View File
@@ -20,7 +20,7 @@ import (
"testing"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/utils"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/stretchr/testify/require"
)
@@ -136,6 +136,6 @@ func TestTraitsToRoleMatchers(t *testing.T) {
// verify that the resulting matches, once deduplicated, are equivalent
// to the expected matches.
require.ElementsMatch(t, utils.Deduplicate(matches), tt.matches, tt.desc)
require.ElementsMatch(t, apiutils.Deduplicate(matches), tt.matches, tt.desc)
}
}
+3 -2
View File
@@ -20,13 +20,14 @@ import (
"encoding/json"
"fmt"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/coreos/go-oidc/jose"
saml2 "github.com/russellhaering/gosaml2"
samltypes "github.com/russellhaering/gosaml2/types"
"gopkg.in/check.v1"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
)
type UserSuite struct {
@@ -54,7 +55,7 @@ func (s *UserSuite) TestTraits(c *check.C) {
Version: types.V2,
Metadata: types.Metadata{
Name: "foo",
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
},
Spec: types.UserSpecV2{
Traits: map[string][]string{
+18 -17
View File
@@ -22,6 +22,7 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/lib/backend"
"github.com/gravitational/teleport/lib/backend/lite"
"github.com/gravitational/teleport/lib/defaults"
@@ -93,14 +94,14 @@ func (s *sessionSuite) TestID(t *testing.T) {
}
func (s *sessionSuite) TestSessionsCRUD(t *testing.T) {
out, err := s.srv.GetSessions(defaults.Namespace)
out, err := s.srv.GetSessions(apidefaults.Namespace)
require.NoError(t, err)
require.Empty(t, out)
// Create session.
sess := Session{
ID: NewID(),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
TerminalParams: TerminalParams{W: 100, H: 100},
Login: "bob",
LastActive: s.clock.Now().UTC(),
@@ -109,35 +110,35 @@ func (s *sessionSuite) TestSessionsCRUD(t *testing.T) {
require.NoError(t, s.srv.CreateSession(sess))
// Make sure only one session exists.
out, err = s.srv.GetSessions(defaults.Namespace)
out, err = s.srv.GetSessions(apidefaults.Namespace)
require.NoError(t, err)
require.Equal(t, out, []Session{sess})
// Make sure the session is the one created above.
s2, err := s.srv.GetSession(defaults.Namespace, sess.ID)
s2, err := s.srv.GetSession(apidefaults.Namespace, sess.ID)
require.NoError(t, err)
require.Equal(t, s2, &sess)
// Update session terminal parameter
err = s.srv.UpdateSession(UpdateRequest{
ID: sess.ID,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
TerminalParams: &TerminalParams{W: 101, H: 101},
})
require.NoError(t, err)
// Verify update was applied.
sess.TerminalParams = TerminalParams{W: 101, H: 101}
s2, err = s.srv.GetSession(defaults.Namespace, sess.ID)
s2, err = s.srv.GetSession(apidefaults.Namespace, sess.ID)
require.NoError(t, err)
require.Equal(t, s2, &sess)
// Remove the session.
err = s.srv.DeleteSession(defaults.Namespace, sess.ID)
err = s.srv.DeleteSession(apidefaults.Namespace, sess.ID)
require.NoError(t, err)
// Make sure session no longer exists.
_, err = s.srv.GetSession(defaults.Namespace, sess.ID)
_, err = s.srv.GetSession(apidefaults.Namespace, sess.ID)
require.Error(t, err)
}
@@ -146,7 +147,7 @@ func (s *sessionSuite) TestSessionsCRUD(t *testing.T) {
func (s *sessionSuite) TestSessionsInactivity(t *testing.T) {
sess := Session{
ID: NewID(),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
TerminalParams: TerminalParams{W: 100, H: 100},
Login: "bob",
LastActive: s.clock.Now().UTC(),
@@ -158,7 +159,7 @@ func (s *sessionSuite) TestSessionsInactivity(t *testing.T) {
s.clock.Advance(defaults.ActiveSessionTTL + time.Second)
// should not be in active sessions:
s2, err := s.srv.GetSession(defaults.Namespace, sess.ID)
s2, err := s.srv.GetSession(apidefaults.Namespace, sess.ID)
require.IsType(t, trace.NotFound(""), err)
require.Nil(t, s2)
}
@@ -167,7 +168,7 @@ func (s *sessionSuite) TestPartiesCRUD(t *testing.T) {
// create session:
sess := Session{
ID: NewID(),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
TerminalParams: TerminalParams{W: 100, H: 100},
Login: "vincent",
LastActive: s.clock.Now().UTC(),
@@ -194,27 +195,27 @@ func (s *sessionSuite) TestPartiesCRUD(t *testing.T) {
}
err = s.srv.UpdateSession(UpdateRequest{
ID: sess.ID,
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Parties: &parties,
})
require.NoError(t, err)
// verify they're in the session:
copy, err := s.srv.GetSession(defaults.Namespace, sess.ID)
copy, err := s.srv.GetSession(apidefaults.Namespace, sess.ID)
require.NoError(t, err)
require.Len(t, copy.Parties, 2)
// empty update (list of parties must not change)
err = s.srv.UpdateSession(UpdateRequest{ID: sess.ID, Namespace: defaults.Namespace})
err = s.srv.UpdateSession(UpdateRequest{ID: sess.ID, Namespace: apidefaults.Namespace})
require.NoError(t, err)
copy, _ = s.srv.GetSession(defaults.Namespace, sess.ID)
copy, _ = s.srv.GetSession(apidefaults.Namespace, sess.ID)
require.Len(t, copy.Parties, 2)
// remove the 2nd party:
deleted := copy.RemoveParty(parties[1].ID)
require.True(t, deleted)
err = s.srv.UpdateSession(UpdateRequest{ID: copy.ID, Parties: &copy.Parties, Namespace: defaults.Namespace})
err = s.srv.UpdateSession(UpdateRequest{ID: copy.ID, Parties: &copy.Parties, Namespace: apidefaults.Namespace})
require.NoError(t, err)
copy, _ = s.srv.GetSession(defaults.Namespace, sess.ID)
copy, _ = s.srv.GetSession(apidefaults.Namespace, sess.ID)
require.Len(t, copy.Parties, 1)
// we still have the 1st party in:
+7 -6
View File
@@ -29,6 +29,7 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
@@ -204,10 +205,10 @@ func New(ctx context.Context, c *Config) (*Server, error) {
Component: teleport.ComponentApp,
Announcer: c.AccessPoint,
GetServerInfo: s.GetServerInfo,
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/2),
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/2),
CheckPeriod: defaults.HeartbeatCheckPeriod,
ServerTTL: defaults.ServerAnnounceTTL,
ServerTTL: apidefaults.ServerAnnounceTTL,
OnHeartbeat: c.OnHeartbeat,
})
if err != nil {
@@ -245,7 +246,7 @@ func (s *Server) GetServerInfo() (types.Resource, error) {
s.server.SetApps(apps)
// Update the TTL.
s.server.SetExpiry(s.c.Clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
s.server.SetExpiry(s.c.Clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
// Update rotation state.
rotation, err := s.c.GetRotation(types.RoleApp)
@@ -383,7 +384,7 @@ func (s *Server) authorize(ctx context.Context, r *http.Request) (*tlsca.Identit
Verified: identity.MFAVerified != "",
AlwaysRequired: ap.GetRequireSessionMFA(),
}
err = authContext.Checker.CheckAccessToApp(defaults.Namespace, app, mfaParams)
err = authContext.Checker.CheckAccessToApp(apidefaults.Namespace, app, mfaParams)
if err != nil {
return nil, nil, utils.OpaqueAccessDenied(err)
}
@@ -448,7 +449,7 @@ func (s *Server) newHTTPServer() *http.Server {
return &http.Server{
Handler: authMiddleware,
ReadHeaderTimeout: defaults.DefaultDialTimeout,
ReadHeaderTimeout: apidefaults.DefaultDialTimeout,
ErrorLog: utils.NewStdlogger(s.log.Error, teleport.ComponentApp),
}
}
+6 -5
View File
@@ -38,9 +38,10 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
"github.com/gravitational/teleport/api/defaults"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/utils"
@@ -195,7 +196,7 @@ func (s *Suite) SetUpTest(c *check.C) {
// Make sure the upload directory is created.
err = os.MkdirAll(filepath.Join(
s.dataDir, teleport.LogsDir, teleport.ComponentUpload,
events.StreamingLogsDir, defaults.Namespace,
events.StreamingLogsDir, apidefaults.Namespace,
), 0755)
c.Assert(err, check.IsNil)
@@ -230,7 +231,7 @@ func (s *Suite) TearDownTest(c *check.C) {
s.testhttp.Close()
err = s.tlsServer.Auth().DeleteAllAppServers(context.Background(), defaults.Namespace)
err = s.tlsServer.Auth().DeleteAllAppServers(context.Background(), apidefaults.Namespace)
c.Assert(err, check.IsNil)
}
@@ -238,7 +239,7 @@ func (s *Suite) TearDownTest(c *check.C) {
// has been created.
func (s *Suite) TestStart(c *check.C) {
// Fetch the services.App that the service heartbeat.
servers, err := s.authServer.AuthServer.GetAppServers(context.Background(), defaults.Namespace)
servers, err := s.authServer.AuthServer.GetAppServers(context.Background(), apidefaults.Namespace)
c.Assert(err, check.IsNil)
c.Assert(servers, check.HasLen, 1)
server := servers[0]
@@ -260,7 +261,7 @@ func (s *Suite) TestStart(c *check.C) {
// Check the expiry time is correct.
c.Assert(s.clock.Now().Before(server.Expiry()), check.Equals, true)
c.Assert(s.clock.Now().Add(2*defaults.ServerAnnounceTTL).After(server.Expiry()), check.Equals, true)
c.Assert(s.clock.Now().Add(2*apidefaults.ServerAnnounceTTL).After(server.Expiry()), check.Equals, true)
}
// TestWaitStop makes sure the server will block and unlock.
+4 -3
View File
@@ -23,6 +23,7 @@ import (
"time"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
@@ -130,7 +131,7 @@ func (s *Server) newStreamWriter(identity *tlsca.Identity) (events.StreamWriter,
Streamer: streamer,
Clock: s.c.Clock,
SessionID: session_pkg.ID(chunkID),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
ServerID: s.c.Server.GetName(),
RecordOutput: recConfig.GetMode() != types.RecordOff,
Component: teleport.ComponentApp,
@@ -149,7 +150,7 @@ func (s *Server) newStreamWriter(identity *tlsca.Identity) (events.StreamWriter,
},
ServerMetadata: apievents.ServerMetadata{
ServerID: s.c.Server.GetName(),
ServerNamespace: defaults.Namespace,
ServerNamespace: apidefaults.Namespace,
},
SessionMetadata: apievents.SessionMetadata{
SessionID: identity.RouteToApp.SessionID,
@@ -181,7 +182,7 @@ func (s *Server) newStreamer(ctx context.Context, sessionID string, recConfig ty
s.log.Debugf("Using async streamer for session %v.", sessionID)
uploadDir := filepath.Join(
s.c.DataDir, teleport.LogsDir, teleport.ComponentUpload,
events.StreamingLogsDir, defaults.Namespace,
events.StreamingLogsDir, apidefaults.Namespace,
)
fileStreamer, err := filesessions.NewStreamer(uploadDir)
if err != nil {
+2 -1
View File
@@ -28,6 +28,7 @@ import (
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/api/types/wrappers"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
@@ -287,7 +288,7 @@ func (t *transport) rewriteRedirect(resp *http.Response) error {
// If the redirect location is one of the hosts specified in the list of
// redirects, rewrite the header.
if utils.SliceContainsStr(t.c.rewrite.Redirect, host(u.Host)) {
if apiutils.SliceContainsStr(t.c.rewrite.Redirect, host(u.Host)) {
u.Scheme = "https"
u.Host = net.JoinHostPort(t.c.publicAddr, t.c.publicPort)
}
+2 -2
View File
@@ -19,8 +19,8 @@ package common
import (
"context"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/defaults"
libevents "github.com/gravitational/teleport/lib/events"
"github.com/gravitational/trace"
@@ -80,7 +80,7 @@ func (a *audit) OnSessionStart(ctx context.Context, session *Session, sessionErr
},
ServerMetadata: events.ServerMetadata{
ServerID: session.Server.GetHostID(),
ServerNamespace: defaults.Namespace,
ServerNamespace: apidefaults.Namespace,
},
UserMetadata: events.UserMetadata{
User: session.Identity.Username,
+2 -2
View File
@@ -29,11 +29,11 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/client/proto"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/auth/native"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/multiplexer"
"github.com/gravitational/teleport/lib/reversetunnel"
"github.com/gravitational/teleport/lib/services"
@@ -418,7 +418,7 @@ func (s *ProxyServer) pickDatabaseServer(ctx context.Context, identity tlsca.Ide
if err != nil {
return nil, nil, trace.Wrap(err)
}
servers, err := accessPoint.GetDatabaseServers(ctx, defaults.Namespace)
servers, err := accessPoint.GetDatabaseServers(ctx, apidefaults.Namespace)
if err != nil {
return nil, nil, trace.Wrap(err)
}
+5 -4
View File
@@ -23,6 +23,7 @@ import (
"sync"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/defaults"
@@ -256,10 +257,10 @@ func (s *Server) initHeartbeat(ctx context.Context, server types.DatabaseServer)
Mode: srv.HeartbeatModeDB,
Announcer: s.cfg.AccessPoint,
GetServerInfo: s.getServerInfoFunc(server),
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/10),
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/10),
CheckPeriod: defaults.HeartbeatCheckPeriod,
ServerTTL: defaults.ServerAnnounceTTL,
ServerTTL: apidefaults.ServerAnnounceTTL,
OnHeartbeat: s.cfg.OnHeartbeat,
})
if err != nil {
@@ -291,7 +292,7 @@ func (s *Server) getServerInfoFunc(server types.DatabaseServer) func() (types.Re
}
}
// Update TTL.
server.SetExpiry(s.cfg.Clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
server.SetExpiry(s.cfg.Clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
return server, nil
}
}
+2 -2
View File
@@ -21,8 +21,8 @@ import (
"testing"
"time"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
"github.com/stretchr/testify/require"
)
@@ -62,7 +62,7 @@ func TestDatabaseServerStart(t *testing.T) {
}
// Make sure servers were announced and their labels updated.
servers, err := testCtx.authClient.GetDatabaseServers(ctx, defaults.Namespace)
servers, err := testCtx.authClient.GetDatabaseServers(ctx, apidefaults.Namespace)
require.NoError(t, err)
for _, server := range servers {
require.Equal(t, map[string]string{"echo": "test"}, server.GetAllLabels())
+3 -3
View File
@@ -22,8 +22,8 @@ import (
"path/filepath"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
libevents "github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/events/filesessions"
"github.com/gravitational/teleport/lib/services"
@@ -58,7 +58,7 @@ func (s *Server) newStreamWriter(sessionCtx *common.Session) (libevents.StreamWr
Streamer: streamer,
Clock: s.cfg.Clock,
SessionID: session.ID(sessionCtx.ID),
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
ServerID: sessionCtx.Server.GetHostID(),
RecordOutput: recConfig.GetMode() != types.RecordOff,
Component: teleport.ComponentDatabase,
@@ -78,7 +78,7 @@ func (s *Server) newStreamer(ctx context.Context, sessionID string, recConfig ty
s.log.Debugf("Using async streamer for session %v.", sessionID)
uploadDir := filepath.Join(
s.cfg.DataDir, teleport.LogsDir, teleport.ComponentUpload,
libevents.StreamingLogsDir, defaults.Namespace)
libevents.StreamingLogsDir, apidefaults.Namespace)
// Make sure the upload dir exists, otherwise file streamer will fail.
_, err := utils.StatDir(uploadDir)
if err != nil && !trace.IsNotFound(err) {
+2 -2
View File
@@ -32,9 +32,9 @@ import (
"github.com/gravitational/teleport"
apievents "github.com/gravitational/teleport/api/types/events"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/utils"
"github.com/gravitational/trace"
log "github.com/sirupsen/logrus"
@@ -529,7 +529,7 @@ func parseSecureCopy(path string) (string, string, bool, error) {
// Look for the -t flag, it indicates that an upload occurred. The other
// flags do no matter for now.
action := events.SCPActionDownload
if utils.SliceContainsStr(parts, "-t") {
if apiutils.SliceContainsStr(parts, "-t") {
action = events.SCPActionUpload
}
+3 -3
View File
@@ -27,12 +27,12 @@ import (
"golang.org/x/crypto/ssh/agent"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
apisshutils "github.com/gravitational/teleport/api/utils/sshutils"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/bpf"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/events"
"github.com/gravitational/teleport/lib/pam"
"github.com/gravitational/teleport/lib/session"
@@ -340,7 +340,7 @@ func (s *Server) HostUUID() string {
// GetNamespace returns the namespace the forwarding server resides in.
func (s *Server) GetNamespace() string {
return defaults.Namespace
return apidefaults.Namespace
}
// AdvertiseAddr is the address of the remote host this forwarding server is
@@ -555,7 +555,7 @@ func (s *Server) newRemoteClient(systemLogin string) (*ssh.Client, error) {
authMethod,
},
HostKeyCallback: s.authHandlers.HostKeyAuth,
Timeout: defaults.DefaultDialTimeout,
Timeout: apidefaults.DefaultDialTimeout,
}
// Ciphers, KEX, and MACs preferences are honored by both the in-memory
+7 -6
View File
@@ -24,6 +24,7 @@ import (
"github.com/jonboulle/clockwork"
"github.com/stretchr/testify/require"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/defaults"
@@ -45,7 +46,7 @@ func TestHeartbeatKeepAlive(t *testing.T) {
Kind: types.KindNode,
Version: types.V2,
Metadata: types.Metadata{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Name: "1",
},
Spec: types.ServerSpecV2{
@@ -63,7 +64,7 @@ func TestHeartbeatKeepAlive(t *testing.T) {
Kind: types.KindAppServer,
Version: types.V2,
Metadata: types.Metadata{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Name: "1",
},
Spec: types.ServerSpecV2{
@@ -81,7 +82,7 @@ func TestHeartbeatKeepAlive(t *testing.T) {
Kind: types.KindDatabaseServer,
Version: types.V3,
Metadata: types.Metadata{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Name: "1",
},
Spec: types.DatabaseServerSpecV3{
@@ -113,7 +114,7 @@ func TestHeartbeatKeepAlive(t *testing.T) {
ServerTTL: 600 * time.Second,
Clock: clock,
GetServerInfo: func() (types.Resource, error) {
server.SetExpiry(clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
server.SetExpiry(clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
return server, nil
},
})
@@ -222,7 +223,7 @@ func TestHeartbeatAnnounce(t *testing.T) {
Kind: tt.kind,
Version: types.V2,
Metadata: types.Metadata{
Namespace: defaults.Namespace,
Namespace: apidefaults.Namespace,
Name: "1",
},
Spec: types.ServerSpecV2{
@@ -230,7 +231,7 @@ func TestHeartbeatAnnounce(t *testing.T) {
Hostname: "2",
},
}
srv.SetExpiry(clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
srv.SetExpiry(clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
return srv, nil
},
})
+5 -3
View File
@@ -29,7 +29,9 @@ import (
"golang.org/x/crypto/ssh"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/reversetunnel"
"github.com/gravitational/teleport/lib/srv"
@@ -94,7 +96,7 @@ func parseProxySubsysRequest(request string) (proxySubsysRequest, error) {
return proxySubsysRequest{}, trace.BadParameter(paramMessage)
}
requestBody := strings.TrimPrefix(request, prefix)
namespace := defaults.Namespace
namespace := apidefaults.Namespace
var err error
parts := strings.Split(requestBody, "@")
switch {
@@ -162,7 +164,7 @@ func (p *proxySubsysRequest) String() string {
// SetDefaults sets default values.
func (p *proxySubsysRequest) SetDefaults() {
if p.namespace == "" {
p.namespace = defaults.Namespace
p.namespace = apidefaults.Namespace
}
}
@@ -366,7 +368,7 @@ func (t *proxySubsys) proxyToHost(
t.log.Errorf("Failed to parse address %q: %v.", servers[i].GetAddr(), err)
continue
}
if t.host == ip || t.host == servers[i].GetHostname() || utils.SliceContainsStr(ips, ip) {
if t.host == ip || t.host == servers[i].GetHostname() || apiutils.SliceContainsStr(ips, ip) {
if !specifiedPort || t.port == port {
server = servers[i]
matches++
+2 -2
View File
@@ -17,7 +17,7 @@ limitations under the License.
package regular
import (
"github.com/gravitational/teleport/lib/defaults"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/lib/srv"
"gopkg.in/check.v1"
@@ -74,7 +74,7 @@ func (s *ProxyTestSuite) TestParseProxyRequest(c *check.C) {
// test cases without a defined namespace are testing for
// the presence of the default namespace; namespace should
// never actually be empty.
t.namespace = defaults.Namespace
t.namespace = apidefaults.Namespace
}
cmt := check.Commentf("Test case %d: %+v", i, t)
req, err := parseProxySubsysRequest(t.req)
+5 -4
View File
@@ -34,6 +34,7 @@ import (
"golang.org/x/crypto/ssh"
"github.com/gravitational/teleport"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/auth"
@@ -626,9 +627,9 @@ func New(addr utils.NetAddr,
Component: component,
Announcer: s.authService,
GetServerInfo: s.getServerInfo,
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/10),
ServerTTL: defaults.ServerAnnounceTTL,
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/10),
ServerTTL: apidefaults.ServerAnnounceTTL,
CheckPeriod: defaults.HeartbeatCheckPeriod,
Clock: s.clock,
OnHeartbeat: s.onHeartbeat,
@@ -770,7 +771,7 @@ func (s *Server) getServerInfo() (types.Resource, error) {
server.SetRotation(*rotation)
}
}
server.SetExpiry(s.clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
server.SetExpiry(s.clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
server.SetPublicAddr(s.proxyPublicAddr.String())
return server, nil
}
+7 -7
View File
@@ -39,10 +39,10 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/auth"
"github.com/gravitational/teleport/lib/bpf"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/limiter"
"github.com/gravitational/teleport/lib/pam"
"github.com/gravitational/teleport/lib/reversetunnel"
@@ -146,7 +146,7 @@ func newCustomFixture(t *testing.T, mutateCfg func(*auth.TestServerConfig), sshO
nodeDir := t.TempDir()
serverOptions := []ServerOption{
SetUUID(nodeID),
SetNamespace(defaults.Namespace),
SetNamespace(apidefaults.Namespace),
SetEmitter(nodeClient),
SetShell("/bin/sh"),
SetSessionServer(nodeClient),
@@ -810,7 +810,7 @@ func TestProxyReverseTunnel(t *testing.T) {
SetProxyMode(reverseTunnelServer),
SetSessionServer(proxyClient),
SetEmitter(nodeClient),
SetNamespace(defaults.Namespace),
SetNamespace(apidefaults.Namespace),
SetPAMConfig(&pam.Config{Enabled: false}),
SetBPF(&bpf.NOP{}),
SetClock(f.clock),
@@ -887,7 +887,7 @@ func TestProxyReverseTunnel(t *testing.T) {
},
),
SetSessionServer(nodeClient),
SetNamespace(defaults.Namespace),
SetNamespace(apidefaults.Namespace),
SetPAMConfig(&pam.Config{Enabled: false}),
SetBPF(&bpf.NOP{}),
SetEmitter(nodeClient),
@@ -988,7 +988,7 @@ func TestProxyRoundRobin(t *testing.T) {
SetProxyMode(reverseTunnelServer),
SetSessionServer(proxyClient),
SetEmitter(nodeClient),
SetNamespace(defaults.Namespace),
SetNamespace(apidefaults.Namespace),
SetPAMConfig(&pam.Config{Enabled: false}),
SetBPF(&bpf.NOP{}),
SetClock(f.clock),
@@ -1105,7 +1105,7 @@ func TestProxyDirectAccess(t *testing.T) {
SetProxyMode(reverseTunnelServer),
SetSessionServer(proxyClient),
SetEmitter(nodeClient),
SetNamespace(defaults.Namespace),
SetNamespace(apidefaults.Namespace),
SetPAMConfig(&pam.Config{Enabled: false}),
SetBPF(&bpf.NOP{}),
SetClock(f.clock),
@@ -1234,7 +1234,7 @@ func TestLimiter(t *testing.T) {
SetShell("/bin/sh"),
SetSessionServer(nodeClient),
SetEmitter(nodeClient),
SetNamespace(defaults.Namespace),
SetNamespace(apidefaults.Namespace),
SetPAMConfig(&pam.Config{Enabled: false}),
SetBPF(&bpf.NOP{}),
SetClock(f.clock),
-50
View File
@@ -1,50 +0,0 @@
/*
Copyright 2021 Gravitational, Inc.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package utils
import (
"github.com/gravitational/teleport/api/utils"
)
// The following util functions have been moved to /api/utils, and are now
// imported here for backwards compatibility.
// slices.go
var (
CopyByteSlice = utils.CopyByteSlice
CopyByteSlices = utils.CopyByteSlices
StringSlicesEqual = utils.StringSlicesEqual
SliceContainsStr = utils.SliceContainsStr
Deduplicate = utils.Deduplicate
)
// strings.go
type Strings = utils.Strings
var CopyStrings = utils.CopyStrings
// time.go
var (
UTC = utils.UTC
HumanTimeFormatString = utils.HumanTimeFormatString
HumanTimeFormat = utils.HumanTimeFormat
)
// utils.go
var (
ParseBool = utils.ParseBool
)
+4 -2
View File
@@ -34,7 +34,9 @@ import (
"github.com/gravitational/teleport"
"github.com/gravitational/teleport/api/constants"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/modules"
"github.com/gravitational/trace"
"github.com/pborman/uuid"
log "github.com/sirupsen/logrus"
@@ -174,7 +176,7 @@ func AsBool(v string) bool {
if v == "" {
return false
}
out, _ := ParseBool(v)
out, _ := apiutils.ParseBool(v)
return out
}
@@ -529,7 +531,7 @@ func CheckCertificateFormatFlag(s string) (string, error) {
}
// AddrsFromStrings returns strings list converted to address list
func AddrsFromStrings(s Strings, defaultPort int) ([]NetAddr, error) {
func AddrsFromStrings(s apiutils.Strings, defaultPort int) ([]NetAddr, error) {
addrs := make([]NetAddr, len(s))
for i, val := range s {
addr, err := ParseHostPortAddr(val, defaultPort)
+7 -6
View File
@@ -27,6 +27,7 @@ import (
"time"
"github.com/gravitational/teleport"
apiutils "github.com/gravitational/teleport/api/utils"
"github.com/gravitational/teleport/lib/fixtures"
"github.com/stretchr/testify/require"
@@ -130,14 +131,14 @@ func (s *UtilsSuite) TestRandomDuration(c *check.C) {
func (s *UtilsSuite) TestMiscFunctions(c *check.C) {
// SliceContainsStr
c.Assert(SliceContainsStr([]string{"two", "one"}, "one"), check.Equals, true)
c.Assert(SliceContainsStr([]string{"two", "one"}, "five"), check.Equals, false)
c.Assert(SliceContainsStr([]string(nil), "one"), check.Equals, false)
c.Assert(apiutils.SliceContainsStr([]string{"two", "one"}, "one"), check.Equals, true)
c.Assert(apiutils.SliceContainsStr([]string{"two", "one"}, "five"), check.Equals, false)
c.Assert(apiutils.SliceContainsStr([]string(nil), "one"), check.Equals, false)
// Deduplicate
c.Assert(Deduplicate([]string{}), check.DeepEquals, []string{})
c.Assert(Deduplicate([]string{"a", "b"}), check.DeepEquals, []string{"a", "b"})
c.Assert(Deduplicate([]string{"a", "b", "b", "a", "c"}), check.DeepEquals, []string{"a", "b", "c"})
c.Assert(apiutils.Deduplicate([]string{}), check.DeepEquals, []string{})
c.Assert(apiutils.Deduplicate([]string{"a", "b"}), check.DeepEquals, []string{"a", "b"})
c.Assert(apiutils.Deduplicate([]string{"a", "b", "b", "a", "c"}), check.DeepEquals, []string{"a", "b", "c"})
// RemoveFromSlice
c.Assert(RemoveFromSlice([]string{}, "a"), check.DeepEquals, []string{})
+2 -1
View File
@@ -39,6 +39,7 @@ import (
"github.com/gravitational/teleport/api/client/proto"
"github.com/gravitational/teleport/api/client/webclient"
"github.com/gravitational/teleport/api/constants"
apidefaults "github.com/gravitational/teleport/api/defaults"
"github.com/gravitational/teleport/api/types"
apievents "github.com/gravitational/teleport/api/types/events"
"github.com/gravitational/teleport/lib/auth"
@@ -1968,7 +1969,7 @@ func (h *Handler) clusterSearchEvents(w http.ResponseWriter, r *http.Request, p
eventTypes = strings.Split(include, ";")
}
rawEvents, _, err := clt.SearchEvents(from, to, defaults.Namespace, eventTypes, limit, "")
rawEvents, _, err := clt.SearchEvents(from, to, apidefaults.Namespace, eventTypes, limit, "")
if err != nil {
return nil, trace.Wrap(err)
}

Some files were not shown because too many files have changed in this diff Show More