mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Remove remaining API aliases (#7137)
This commit is contained in:
+12
-10
@@ -27,10 +27,6 @@ const (
|
||||
// Namespace is default namespace
|
||||
Namespace = "default"
|
||||
|
||||
// ServerKeepAliveTTL is a period between server keep-alives,
|
||||
// when servers announce only presence without sending full data
|
||||
ServerKeepAliveTTL = 60 * time.Second
|
||||
|
||||
// DefaultDialTimeout is a default TCP dial timeout we set for our
|
||||
// connection attempts
|
||||
DefaultDialTimeout = 30 * time.Second
|
||||
@@ -46,12 +42,6 @@ const (
|
||||
// CertDuration is a default certificate duration.
|
||||
CertDuration = 12 * time.Hour
|
||||
|
||||
// KeepAliveInterval is interval at which Teleport will send keep-alive
|
||||
// messages to the client. The default interval of 5 minutes (300 seconds) is
|
||||
// set to help keep connections alive when using AWS NLBs (which have a default
|
||||
// timeout of 350 seconds)
|
||||
KeepAliveInterval = 5 * time.Minute
|
||||
|
||||
// ServerAnnounceTTL is a period between heartbeats
|
||||
// Median sleep time between node pings is this value / 2 + random
|
||||
// deviation added to this time to avoid lots of simultaneous
|
||||
@@ -59,6 +49,18 @@ const (
|
||||
ServerAnnounceTTL = 600 * time.Second
|
||||
)
|
||||
|
||||
var (
|
||||
// ServerKeepAliveTTL is a period between server keep-alives,
|
||||
// when servers announce only presence without sending full data
|
||||
ServerKeepAliveTTL = 60 * time.Second
|
||||
|
||||
// KeepAliveInterval is interval at which Teleport will send keep-alive
|
||||
// messages to the client. The default interval of 5 minutes (300 seconds) is
|
||||
// set to help keep connections alive when using AWS NLBs (which have a default
|
||||
// timeout of 350 seconds)
|
||||
KeepAliveInterval = 5 * time.Minute
|
||||
)
|
||||
|
||||
// EnhancedEvents returns the default list of enhanced events.
|
||||
func EnhancedEvents() []string {
|
||||
return []string{
|
||||
|
||||
+1
-1
Submodule e updated: f74f54d23c...db6441154a
@@ -22,6 +22,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib"
|
||||
@@ -268,7 +269,7 @@ func waitForAuditEventTypeWithBackoff(t *testing.T, cli *auth.Server, startTime
|
||||
t.Fatalf("failed to create linear backoff: %v", err)
|
||||
}
|
||||
for {
|
||||
events, _, err := cli.SearchEvents(startTime, time.Now().Add(time.Hour), defaults.Namespace, []string{eventType}, 100, "")
|
||||
events, _, err := cli.SearchEvents(startTime, time.Now().Add(time.Hour), apidefaults.Namespace, []string{eventType}, 100, "")
|
||||
if err != nil {
|
||||
t.Fatalf("failed to call SearchEvents: %v", err)
|
||||
}
|
||||
@@ -573,7 +574,7 @@ func (p *databasePack) waitForLeaf(t *testing.T) {
|
||||
for {
|
||||
select {
|
||||
case <-time.Tick(500 * time.Millisecond):
|
||||
servers, err := accessPoint.GetDatabaseServers(context.Background(), defaults.Namespace)
|
||||
servers, err := accessPoint.GetDatabaseServers(context.Background(), apidefaults.Namespace)
|
||||
if err != nil {
|
||||
logrus.WithError(err).Debugf("Leaf cluster access point is unavailable.")
|
||||
continue
|
||||
|
||||
@@ -40,6 +40,7 @@ import (
|
||||
"golang.org/x/crypto/ssh/agent"
|
||||
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/auth/native"
|
||||
@@ -70,9 +71,9 @@ const (
|
||||
// SetTestTimeouts affects global timeouts inside Teleport, making connections
|
||||
// work faster but consuming more CPU (useful for integration testing)
|
||||
func SetTestTimeouts(t time.Duration) {
|
||||
defaults.KeepAliveInterval = t
|
||||
apidefaults.KeepAliveInterval = t
|
||||
defaults.ResyncInterval = t
|
||||
defaults.ServerKeepAliveTTL = t
|
||||
apidefaults.ServerKeepAliveTTL = t
|
||||
defaults.SessionRefreshPeriod = t
|
||||
defaults.HeartbeatCheckPeriod = t
|
||||
defaults.CachePollPeriod = t
|
||||
|
||||
@@ -43,8 +43,10 @@ import (
|
||||
"golang.org/x/crypto/ssh"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/profile"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/api/utils/keypaths"
|
||||
"github.com/gravitational/teleport/lib"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
@@ -305,7 +307,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
|
||||
for {
|
||||
select {
|
||||
case <-tickCh:
|
||||
nodesInSite, err := site.GetNodes(ctx, defaults.Namespace)
|
||||
nodesInSite, err := site.GetNodes(ctx, apidefaults.Namespace)
|
||||
if err != nil && !trace.IsNotFound(err) {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -321,7 +323,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// should have no sessions:
|
||||
sessions, err := site.GetSessions(defaults.Namespace)
|
||||
sessions, err := site.GetSessions(apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Empty(t, sessions)
|
||||
|
||||
@@ -351,7 +353,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
|
||||
for {
|
||||
select {
|
||||
case <-tickCh:
|
||||
sessions, err = site.GetSessions(defaults.Namespace)
|
||||
sessions, err = site.GetSessions(apidefaults.Namespace)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
@@ -370,7 +372,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
|
||||
// wait for the user to join this session:
|
||||
for len(session.Parties) == 0 {
|
||||
time.Sleep(time.Millisecond * 5)
|
||||
session, err = site.GetSession(defaults.Namespace, sessions[0].ID)
|
||||
session, err = site.GetSession(apidefaults.Namespace, sessions[0].ID)
|
||||
require.NoError(t, err)
|
||||
}
|
||||
// make sure it's us who joined! :)
|
||||
@@ -409,7 +411,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
|
||||
// everything because the session is closing)
|
||||
var sessionStream []byte
|
||||
for i := 0; i < 6; i++ {
|
||||
sessionStream, err = site.GetSessionChunk(defaults.Namespace, session.ID, 0, events.MaxChunkBytes)
|
||||
sessionStream, err = site.GetSessionChunk(apidefaults.Namespace, session.ID, 0, events.MaxChunkBytes)
|
||||
require.NoError(t, err)
|
||||
if strings.Contains(string(sessionStream), "exit") {
|
||||
break
|
||||
@@ -441,7 +443,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) {
|
||||
select {
|
||||
case <-tickCh:
|
||||
// Get all session events from the backend.
|
||||
sessionEvents, err := site.GetSessionEvents(defaults.Namespace, session.ID, 0, false)
|
||||
sessionEvents, err := site.GetSessionEvents(apidefaults.Namespace, session.ID, 0, false)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
@@ -763,7 +765,7 @@ func testUUIDBasedProxy(t *testing.T, suite *integrationTestSuite) {
|
||||
for {
|
||||
select {
|
||||
case <-tickCh:
|
||||
nodesInSite, err := site.GetNodes(ctx, defaults.Namespace)
|
||||
nodesInSite, err := site.GetNodes(ctx, apidefaults.Namespace)
|
||||
if err != nil && !trace.IsNotFound(err) {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -914,7 +916,7 @@ func verifySessionJoin(t *testing.T, username string, teleport *TeleInstance) {
|
||||
var sessionID string
|
||||
for {
|
||||
time.Sleep(time.Millisecond)
|
||||
sessions, _ := site.GetSessions(defaults.Namespace)
|
||||
sessions, _ := site.GetSessions(apidefaults.Namespace)
|
||||
if len(sessions) == 0 {
|
||||
continue
|
||||
}
|
||||
@@ -925,7 +927,7 @@ func verifySessionJoin(t *testing.T, username string, teleport *TeleInstance) {
|
||||
require.NoError(t, err)
|
||||
cl.Stdout = personB
|
||||
for i := 0; i < 10; i++ {
|
||||
err = cl.Join(context.TODO(), defaults.Namespace, session.ID(sessionID), personB)
|
||||
err = cl.Join(context.TODO(), apidefaults.Namespace, session.ID(sessionID), personB)
|
||||
if err == nil {
|
||||
break
|
||||
}
|
||||
@@ -1126,7 +1128,7 @@ func testDisconnectScenarios(t *testing.T, suite *integrationTestSuite) {
|
||||
|
||||
var ss []session.Session
|
||||
for i := 0; i < 6; i++ {
|
||||
ss, err = site.GetSessions(defaults.Namespace)
|
||||
ss, err = site.GetSessions(apidefaults.Namespace)
|
||||
if err == nil && len(ss) > 0 {
|
||||
break
|
||||
}
|
||||
@@ -1511,7 +1513,7 @@ func twoClustersTunnel(t *testing.T, suite *integrationTestSuite, now time.Time,
|
||||
for {
|
||||
select {
|
||||
case <-tickCh:
|
||||
eventsInSite, _, err := site.SearchEvents(now, now.Add(1*time.Hour), defaults.Namespace, eventTypes, 0, "")
|
||||
eventsInSite, _, err := site.SearchEvents(now, now.Add(1*time.Hour), apidefaults.Namespace, eventTypes, 0, "")
|
||||
if err != nil {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -1761,7 +1763,7 @@ func testMapRoles(t *testing.T, suite *integrationTestSuite) {
|
||||
// correct nodes that identity aware GetNodes is done in TestList.
|
||||
var nodes []types.Server
|
||||
for i := 0; i < 10; i++ {
|
||||
nodes, err = aux.Process.GetAuthServer().GetNodes(ctx, defaults.Namespace)
|
||||
nodes, err = aux.Process.GetAuthServer().GetNodes(ctx, apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
if len(nodes) != 2 {
|
||||
time.Sleep(100 * time.Millisecond)
|
||||
@@ -2798,7 +2800,7 @@ func waitForNodeCount(ctx context.Context, t *TeleInstance, clusterName string,
|
||||
if err != nil {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
nodes, err := accessPoint.GetNodes(ctx, defaults.Namespace)
|
||||
nodes, err := accessPoint.GetNodes(ctx, apidefaults.Namespace)
|
||||
if err != nil {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -3158,7 +3160,7 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) {
|
||||
require.NotNil(t, site)
|
||||
|
||||
// should have no sessions in it to start with
|
||||
sessions, _ := site.GetSessions(defaults.Namespace)
|
||||
sessions, _ := site.GetSessions(apidefaults.Namespace)
|
||||
require.Len(t, sessions, 0)
|
||||
|
||||
// create interactive session (this goroutine is this user's terminal time)
|
||||
@@ -3182,7 +3184,7 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) {
|
||||
// wait until there's a session in there:
|
||||
for i := 0; len(sessions) == 0; i++ {
|
||||
time.Sleep(time.Millisecond * 20)
|
||||
sessions, _ = site.GetSessions(defaults.Namespace)
|
||||
sessions, _ = site.GetSessions(apidefaults.Namespace)
|
||||
if i > 100 {
|
||||
t.Fatalf("Waited %v, but no sessions found", 100*20*time.Millisecond)
|
||||
return
|
||||
@@ -3193,7 +3195,7 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) {
|
||||
// wait for the user to join this session
|
||||
for len(session.Parties) == 0 {
|
||||
time.Sleep(time.Millisecond * 5)
|
||||
session, err = site.GetSession(defaults.Namespace, sessions[0].ID)
|
||||
session, err = site.GetSession(apidefaults.Namespace, sessions[0].ID)
|
||||
require.NoError(t, err)
|
||||
}
|
||||
// make sure it's us who joined! :)
|
||||
@@ -3210,13 +3212,13 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) {
|
||||
}
|
||||
|
||||
// audit log should have the fact that the session occurred recorded in it
|
||||
sessions, err = site.GetSessions(defaults.Namespace)
|
||||
sessions, err = site.GetSessions(apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Len(t, sessions, 1)
|
||||
|
||||
// however, attempts to read the actual sessions should fail because it was
|
||||
// not actually recorded
|
||||
_, err = site.GetSessionChunk(defaults.Namespace, session.ID, 0, events.MaxChunkBytes)
|
||||
_, err = site.GetSessionChunk(apidefaults.Namespace, session.ID, 0, events.MaxChunkBytes)
|
||||
require.Error(t, err)
|
||||
}
|
||||
|
||||
@@ -4166,7 +4168,7 @@ func testWindowChange(t *testing.T, suite *integrationTestSuite) {
|
||||
var sessionID string
|
||||
for {
|
||||
time.Sleep(time.Millisecond)
|
||||
sessions, _ := site.GetSessions(defaults.Namespace)
|
||||
sessions, _ := site.GetSessions(apidefaults.Namespace)
|
||||
if len(sessions) == 0 {
|
||||
continue
|
||||
}
|
||||
@@ -4195,7 +4197,7 @@ func testWindowChange(t *testing.T, suite *integrationTestSuite) {
|
||||
}
|
||||
|
||||
for i := 0; i < 10; i++ {
|
||||
err = cl.Join(context.TODO(), defaults.Namespace, session.ID(sessionID), personB)
|
||||
err = cl.Join(context.TODO(), apidefaults.Namespace, session.ID(sessionID), personB)
|
||||
if err == nil {
|
||||
break
|
||||
}
|
||||
@@ -4308,7 +4310,7 @@ func testList(t *testing.T, suite *integrationTestSuite) {
|
||||
for {
|
||||
select {
|
||||
case <-tickCh:
|
||||
nodesInCluster, err := clt.GetNodes(ctx, defaults.Namespace)
|
||||
nodesInCluster, err := clt.GetNodes(ctx, apidefaults.Namespace)
|
||||
if err != nil && !trace.IsNotFound(err) {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -4383,7 +4385,7 @@ func testList(t *testing.T, suite *integrationTestSuite) {
|
||||
nodes, err := userClt.ListNodes(context.Background())
|
||||
require.NoError(t, err)
|
||||
for _, node := range nodes {
|
||||
ok := utils.SliceContainsStr(tt.outNodes, node.GetHostname())
|
||||
ok := apiutils.SliceContainsStr(tt.outNodes, node.GetHostname())
|
||||
if !ok {
|
||||
t.Fatalf("Got nodes: %v, want: %v.", nodes, tt.outNodes)
|
||||
}
|
||||
@@ -5393,7 +5395,7 @@ func TestTraitsPropagation(t *testing.T) {
|
||||
role.SetName("test")
|
||||
role.SetLogins(services.Allow, []string{me.Username})
|
||||
// Users created by CreateEx have "testing: integration" trait.
|
||||
role.SetNodeLabels(services.Allow, map[string]utils.Strings{"env": []string{"{{external.testing}}"}})
|
||||
role.SetNodeLabels(services.Allow, map[string]apiutils.Strings{"env": []string{"{{external.testing}}"}})
|
||||
|
||||
rc.AddUserWithRole(me.Username, role)
|
||||
lc.AddUserWithRole(me.Username, role)
|
||||
|
||||
@@ -34,11 +34,11 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/profile"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib"
|
||||
"github.com/gravitational/teleport/lib/auth/testauthority"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
kubeproxy "github.com/gravitational/teleport/lib/kube/proxy"
|
||||
kubeutils "github.com/gravitational/teleport/lib/kube/utils"
|
||||
@@ -294,7 +294,7 @@ loop:
|
||||
}
|
||||
|
||||
// read back the entire session and verify that it matches the stated output
|
||||
capturedStream, err := teleport.Process.GetAuthServer().GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
|
||||
capturedStream, err := teleport.Process.GetAuthServer().GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
|
||||
require.NoError(t, err)
|
||||
|
||||
require.Equal(t, sessionStream, string(capturedStream))
|
||||
@@ -668,7 +668,7 @@ loop:
|
||||
}
|
||||
|
||||
// read back the entire session and verify that it matches the stated output
|
||||
capturedStream, err := main.Process.GetAuthServer().GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
|
||||
capturedStream, err := main.Process.GetAuthServer().GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
|
||||
require.NoError(t, err)
|
||||
|
||||
require.Equal(t, sessionStream, string(capturedStream))
|
||||
@@ -926,7 +926,7 @@ loop:
|
||||
}
|
||||
|
||||
// read back the entire session and verify that it matches the stated output
|
||||
capturedStream, err := main.Process.GetAuthServer().GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
|
||||
capturedStream, err := main.Process.GetAuthServer().GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, events.MaxChunkBytes)
|
||||
require.NoError(t, err)
|
||||
|
||||
require.Equal(t, sessionStream, string(capturedStream))
|
||||
|
||||
@@ -24,10 +24,10 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/bpf"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/pam"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/srv/regular"
|
||||
@@ -212,7 +212,7 @@ func newSrvCtx(t *testing.T) *SrvCtx {
|
||||
"",
|
||||
utils.NetAddr{},
|
||||
regular.SetUUID(s.nodeID),
|
||||
regular.SetNamespace(defaults.Namespace),
|
||||
regular.SetNamespace(apidefaults.Namespace),
|
||||
regular.SetEmitter(s.nodeClient),
|
||||
regular.SetShell("/bin/sh"),
|
||||
regular.SetSessionServer(s.nodeClient),
|
||||
|
||||
@@ -30,6 +30,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -66,10 +67,10 @@ type APIConfig struct {
|
||||
// CheckAndSetDefaults checks and sets default values
|
||||
func (a *APIConfig) CheckAndSetDefaults() error {
|
||||
if a.KeepAlivePeriod == 0 {
|
||||
a.KeepAlivePeriod = defaults.ServerKeepAliveTTL
|
||||
a.KeepAlivePeriod = apidefaults.ServerKeepAliveTTL
|
||||
}
|
||||
if a.KeepAliveCount == 0 {
|
||||
a.KeepAliveCount = defaults.KeepAliveCountMax
|
||||
a.KeepAliveCount = apidefaults.KeepAliveCountMax
|
||||
}
|
||||
return nil
|
||||
}
|
||||
@@ -1813,7 +1814,7 @@ func (s *APIServer) searchEvents(auth ClientI, w http.ResponseWriter, r *http.Re
|
||||
}
|
||||
|
||||
eventTypes := query[events.EventType]
|
||||
eventsList, _, err := auth.SearchEvents(from, to, defaults.Namespace, eventTypes, limit, "")
|
||||
eventsList, _, err := auth.SearchEvents(from, to, apidefaults.Namespace, eventTypes, limit, "")
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
|
||||
+10
-10
@@ -24,8 +24,8 @@ import (
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
|
||||
"github.com/google/go-cmp/cmp"
|
||||
@@ -50,13 +50,13 @@ func TestUpsertServer(t *testing.T) {
|
||||
{
|
||||
desc: "node",
|
||||
reqServer: &types.ServerV2{
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
|
||||
Version: types.V2,
|
||||
Kind: types.KindNode,
|
||||
},
|
||||
role: types.RoleNode,
|
||||
wantServer: &types.ServerV2{
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
|
||||
Version: types.V2,
|
||||
Kind: types.KindNode,
|
||||
},
|
||||
@@ -65,13 +65,13 @@ func TestUpsertServer(t *testing.T) {
|
||||
{
|
||||
desc: "proxy",
|
||||
reqServer: &types.ServerV2{
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
|
||||
Version: types.V2,
|
||||
Kind: types.KindProxy,
|
||||
},
|
||||
role: types.RoleProxy,
|
||||
wantServer: &types.ServerV2{
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
|
||||
Version: types.V2,
|
||||
Kind: types.KindProxy,
|
||||
},
|
||||
@@ -80,13 +80,13 @@ func TestUpsertServer(t *testing.T) {
|
||||
{
|
||||
desc: "auth",
|
||||
reqServer: &types.ServerV2{
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
|
||||
Version: types.V2,
|
||||
Kind: types.KindAuthServer,
|
||||
},
|
||||
role: types.RoleAuth,
|
||||
wantServer: &types.ServerV2{
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
|
||||
Version: types.V2,
|
||||
Kind: types.KindAuthServer,
|
||||
},
|
||||
@@ -95,7 +95,7 @@ func TestUpsertServer(t *testing.T) {
|
||||
{
|
||||
desc: "unknown",
|
||||
reqServer: &types.ServerV2{
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "test-server", Namespace: apidefaults.Namespace},
|
||||
Version: types.V2,
|
||||
Kind: types.KindNode,
|
||||
},
|
||||
@@ -118,7 +118,7 @@ func TestUpsertServer(t *testing.T) {
|
||||
req := httptest.NewRequest(http.MethodPost, "http://localhost", bytes.NewReader(body))
|
||||
req.RemoteAddr = remoteAddr
|
||||
|
||||
_, err = new(APIServer).upsertServer(s, tt.role, req, httprouter.Params{httprouter.Param{Key: "namespace", Value: defaults.Namespace}})
|
||||
_, err = new(APIServer).upsertServer(s, tt.role, req, httprouter.Params{httprouter.Param{Key: "namespace", Value: apidefaults.Namespace}})
|
||||
tt.assertErr(t, err)
|
||||
if err != nil {
|
||||
return
|
||||
@@ -131,7 +131,7 @@ func TestUpsertServer(t *testing.T) {
|
||||
allServers = append(allServers, servers...)
|
||||
}
|
||||
addServers(s.GetAuthServers())
|
||||
addServers(s.GetNodes(ctx, defaults.Namespace))
|
||||
addServers(s.GetNodes(ctx, apidefaults.Namespace))
|
||||
addServers(s.GetProxies())
|
||||
require.Empty(t, cmp.Diff(allServers, []types.Server{tt.wantServer}, cmpopts.IgnoreFields(types.Metadata{}, "ID")))
|
||||
})
|
||||
|
||||
+13
-12
@@ -40,6 +40,7 @@ import (
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/api/types/wrappers"
|
||||
@@ -317,7 +318,7 @@ func (a *Server) runPeriodicOperations() {
|
||||
ticker := time.NewTicker(period)
|
||||
// Create a ticker with jitter
|
||||
heartbeatCheckTicker := interval.New(interval.Config{
|
||||
Duration: defaults.ServerKeepAliveTTL * 2,
|
||||
Duration: apidefaults.ServerKeepAliveTTL * 2,
|
||||
Jitter: utils.NewSeventhJitter(),
|
||||
})
|
||||
missedKeepAliveCount := 0
|
||||
@@ -337,7 +338,7 @@ func (a *Server) runPeriodicOperations() {
|
||||
}
|
||||
}
|
||||
case <-heartbeatCheckTicker.Next():
|
||||
nodes, err := a.GetNodes(ctx, defaults.Namespace)
|
||||
nodes, err := a.GetNodes(ctx, apidefaults.Namespace)
|
||||
if err != nil {
|
||||
log.Errorf("Failed to load nodes for heartbeat metric calculation: %v", err)
|
||||
}
|
||||
@@ -876,7 +877,7 @@ func (a *Server) WithUserLock(username string, authenticateFn func() error) erro
|
||||
status := user.GetStatus()
|
||||
if status.IsLocked && status.LockExpires.After(a.clock.Now().UTC()) {
|
||||
return trace.AccessDenied("%v exceeds %v failed login attempts, locked until %v",
|
||||
user.GetName(), defaults.MaxLoginAttempts, utils.HumanTimeFormat(status.LockExpires))
|
||||
user.GetName(), defaults.MaxLoginAttempts, apiutils.HumanTimeFormat(status.LockExpires))
|
||||
}
|
||||
fnErr := authenticateFn()
|
||||
if fnErr == nil {
|
||||
@@ -910,7 +911,7 @@ func (a *Server) WithUserLock(username string, authenticateFn func() error) erro
|
||||
}
|
||||
lockUntil := a.clock.Now().UTC().Add(defaults.AccountLockInterval)
|
||||
message := fmt.Sprintf("%v exceeds %v failed login attempts, locked until %v",
|
||||
username, defaults.MaxLoginAttempts, utils.HumanTimeFormat(status.LockExpires))
|
||||
username, defaults.MaxLoginAttempts, apiutils.HumanTimeFormat(status.LockExpires))
|
||||
log.Debug(message)
|
||||
user.SetLocked(lockUntil, "user has exceeded maximum failed login attempts")
|
||||
err = a.Identity.UpsertUser(user)
|
||||
@@ -1043,7 +1044,7 @@ func (a *Server) ExtendWebSession(req WebSessionReq, identity tlsca.Identity) (t
|
||||
}
|
||||
|
||||
roles = append(roles, newRoles...)
|
||||
roles = utils.Deduplicate(roles)
|
||||
roles = apiutils.Deduplicate(roles)
|
||||
|
||||
// Let session expire with the shortest expiry time.
|
||||
if expiresAt.After(requestExpiry) {
|
||||
@@ -1068,7 +1069,7 @@ func (a *Server) ExtendWebSession(req WebSessionReq, identity tlsca.Identity) (t
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
|
||||
sessionTTL := roleSet.AdjustSessionTTL(defaults.CertDuration)
|
||||
sessionTTL := roleSet.AdjustSessionTTL(apidefaults.CertDuration)
|
||||
|
||||
// Set default roles and expiration.
|
||||
expiresAt = prevSession.GetLoginTime().UTC().Add(sessionTTL)
|
||||
@@ -1317,7 +1318,7 @@ func (a *Server) GenerateServerKeys(req GenerateServerKeysRequest) (*PackedKeys,
|
||||
// If the request contains 0.0.0.0, this implies an advertise IP was not
|
||||
// specified on the node. Try and guess what the address by replacing 0.0.0.0
|
||||
// with the RemoteAddr as known to the Auth Server.
|
||||
if utils.SliceContainsStr(req.AdditionalPrincipals, defaults.AnyAddress) {
|
||||
if apiutils.SliceContainsStr(req.AdditionalPrincipals, defaults.AnyAddress) {
|
||||
remoteHost, err := utils.Host(req.RemoteAddr)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
@@ -1672,7 +1673,7 @@ func (a *Server) NewWebSession(req types.NewWebSessionRequest) (types.WebSession
|
||||
}
|
||||
sessionTTL := req.SessionTTL
|
||||
if sessionTTL == 0 {
|
||||
sessionTTL = checker.AdjustSessionTTL(defaults.CertDuration)
|
||||
sessionTTL = checker.AdjustSessionTTL(apidefaults.CertDuration)
|
||||
}
|
||||
certs, err := a.generateUserCert(certRequest{
|
||||
user: user,
|
||||
@@ -1726,7 +1727,7 @@ func (a *Server) GetWebSessionInfo(ctx context.Context, user, sessionID string)
|
||||
|
||||
func (a *Server) DeleteNamespace(namespace string) error {
|
||||
ctx := context.TODO()
|
||||
if namespace == defaults.Namespace {
|
||||
if namespace == apidefaults.Namespace {
|
||||
return trace.AccessDenied("can't delete default namespace")
|
||||
}
|
||||
nodes, err := a.Presence.GetNodes(ctx, namespace)
|
||||
@@ -2168,7 +2169,7 @@ func (a *Server) isMFARequired(ctx context.Context, checker services.AccessCheck
|
||||
return nil, trace.BadParameter("empty Login field")
|
||||
}
|
||||
// Find the target node and check whether MFA is required.
|
||||
nodes, err := a.GetNodes(ctx, defaults.Namespace)
|
||||
nodes, err := a.GetNodes(ctx, apidefaults.Namespace)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
@@ -2229,14 +2230,14 @@ func (a *Server) isMFARequired(ctx context.Context, checker services.AccessCheck
|
||||
if cluster == nil {
|
||||
return nil, trace.Wrap(notFoundErr)
|
||||
}
|
||||
noMFAAccessErr = checker.CheckAccessToKubernetes(defaults.Namespace, cluster, services.AccessMFAParams{AlwaysRequired: false, Verified: false})
|
||||
noMFAAccessErr = checker.CheckAccessToKubernetes(apidefaults.Namespace, cluster, services.AccessMFAParams{AlwaysRequired: false, Verified: false})
|
||||
|
||||
case *proto.IsMFARequiredRequest_Database:
|
||||
notFoundErr = trace.NotFound("database service %q not found", t.Database.ServiceName)
|
||||
if t.Database.ServiceName == "" {
|
||||
return nil, trace.BadParameter("missing ServiceName field in a database-only UserCertsRequest")
|
||||
}
|
||||
dbs, err := a.GetDatabaseServers(ctx, defaults.Namespace)
|
||||
dbs, err := a.GetDatabaseServers(ctx, apidefaults.Namespace)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
|
||||
@@ -35,6 +35,7 @@ import (
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/api/utils/sshutils"
|
||||
"github.com/gravitational/teleport/lib/auth/testauthority"
|
||||
authority "github.com/gravitational/teleport/lib/auth/testauthority"
|
||||
@@ -577,7 +578,7 @@ func (s *AuthSuite) TestTokensCRUD(c *C) {
|
||||
hostCert, err := sshutils.ParseCertificate(keys.Cert)
|
||||
c.Assert(err, IsNil)
|
||||
comment := Commentf("can't find example.com in %v", hostCert.ValidPrincipals)
|
||||
c.Assert(utils.SliceContainsStr(hostCert.ValidPrincipals, "example.com"), Equals, true, comment)
|
||||
c.Assert(apiutils.SliceContainsStr(hostCert.ValidPrincipals, "example.com"), Equals, true, comment)
|
||||
|
||||
_, err = s.a.RegisterUsingToken(RegisterUsingTokenRequest{
|
||||
Token: multiUseToken,
|
||||
|
||||
+210
-208
File diff suppressed because it is too large
Load Diff
+4
-9
@@ -35,6 +35,7 @@ import (
|
||||
"github.com/gravitational/teleport/api/client"
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/auth/u2f"
|
||||
@@ -58,12 +59,6 @@ const (
|
||||
MissingNamespaceError = "missing required parameter: namespace"
|
||||
)
|
||||
|
||||
// ContextDialer type alias for backwards compatibility
|
||||
type ContextDialer = client.ContextDialer
|
||||
|
||||
// ContextDialerFunc type alias for backwards compatibility
|
||||
type ContextDialerFunc = client.ContextDialerFunc
|
||||
|
||||
// Client is the Auth API client. It works by connecting to auth servers
|
||||
// via gRPC and HTTP.
|
||||
//
|
||||
@@ -133,7 +128,7 @@ func NewHTTPClient(cfg client.Config, tls *tls.Config, params ...roundtrip.Clien
|
||||
return nil, trace.BadParameter("no addresses to dial")
|
||||
}
|
||||
contextDialer := client.NewDirectDialer(cfg.KeepAlivePeriod, cfg.DialTimeout)
|
||||
dialer = ContextDialerFunc(func(ctx context.Context, network, _ string) (conn net.Conn, err error) {
|
||||
dialer = client.ContextDialerFunc(func(ctx context.Context, network, _ string) (conn net.Conn, err error) {
|
||||
for _, addr := range cfg.Addrs {
|
||||
conn, err = contextDialer.DialContext(ctx, network, addr)
|
||||
if err == nil {
|
||||
@@ -158,7 +153,7 @@ func NewHTTPClient(cfg client.Config, tls *tls.Config, params ...roundtrip.Clien
|
||||
// custom DialContext overrides this DNS name to the real address.
|
||||
// In addition this dialer tries multiple addresses if provided
|
||||
DialContext: dialer.DialContext,
|
||||
ResponseHeaderTimeout: defaults.DefaultDialTimeout,
|
||||
ResponseHeaderTimeout: apidefaults.DefaultDialTimeout,
|
||||
TLSClientConfig: tls,
|
||||
|
||||
// Increase the size of the connection pool. This substantially improves the
|
||||
@@ -222,7 +217,7 @@ type ClientConfig struct {
|
||||
// Addrs is a list of addresses to dial
|
||||
Addrs []utils.NetAddr
|
||||
// Dialer is a custom dialer that is used instead of Addrs when provided
|
||||
Dialer ContextDialer
|
||||
Dialer client.ContextDialer
|
||||
// DialTimeout defines how long to attempt dialing before timing out
|
||||
DialTimeout time.Duration
|
||||
// KeepAlivePeriod defines period between keep alives
|
||||
|
||||
+2
-2
@@ -22,8 +22,8 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/modules"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/tlsca"
|
||||
@@ -130,7 +130,7 @@ func (s *Server) SignDatabaseCSR(ctx context.Context, req *proto.DatabaseCSRRequ
|
||||
}
|
||||
|
||||
// Get the correct cert TTL based on roles.
|
||||
ttl := roles.AdjustSessionTTL(defaults.CertDuration)
|
||||
ttl := roles.AdjustSessionTTL(apidefaults.CertDuration)
|
||||
|
||||
// Generate the TLS certificate.
|
||||
userCA, err := s.Trust.GetCertAuthority(types.CertAuthID{
|
||||
|
||||
+3
-2
@@ -26,6 +26,7 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -364,7 +365,7 @@ func (a *Server) calculateGithubUser(connector types.GithubConnector, claims *ty
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
roleTTL := roles.AdjustSessionTTL(defaults.MaxCertDuration)
|
||||
roleTTL := roles.AdjustSessionTTL(apidefaults.MaxCertDuration)
|
||||
p.sessionTTL = utils.MinTTL(roleTTL, request.CertTTL)
|
||||
|
||||
return &p, nil
|
||||
@@ -383,7 +384,7 @@ func (a *Server) createGithubUser(p *createUserParams) (types.User, error) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: p.username,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Expires: &expires,
|
||||
},
|
||||
Spec: types.UserSpecV2{
|
||||
|
||||
+3
-3
@@ -28,11 +28,11 @@ import (
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/client"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
authority "github.com/gravitational/teleport/lib/auth/testauthority"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/memory"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/limiter"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
@@ -82,13 +82,13 @@ func CreateUploaderDir(dir string) error {
|
||||
// DELETE IN(5.1.0)
|
||||
// this folder is no longer used past 5.0 upgrade
|
||||
err := os.MkdirAll(filepath.Join(dir, teleport.LogsDir, teleport.ComponentUpload,
|
||||
events.SessionLogsDir, defaults.Namespace), teleport.SharedDirMode)
|
||||
events.SessionLogsDir, apidefaults.Namespace), teleport.SharedDirMode)
|
||||
if err != nil {
|
||||
return trace.ConvertSystemError(err)
|
||||
}
|
||||
|
||||
err = os.MkdirAll(filepath.Join(dir, teleport.LogsDir, teleport.ComponentUpload,
|
||||
events.StreamingLogsDir, defaults.Namespace), teleport.SharedDirMode)
|
||||
events.StreamingLogsDir, apidefaults.Namespace), teleport.SharedDirMode)
|
||||
if err != nil {
|
||||
return trace.ConvertSystemError(err)
|
||||
}
|
||||
|
||||
+7
-6
@@ -29,6 +29,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
apisshutils "github.com/gravitational/teleport/api/utils/sshutils"
|
||||
@@ -308,11 +309,11 @@ func Init(cfg InitConfig, opts ...ServerOption) (*Server, error) {
|
||||
log.Infof("Updating cluster configuration: %v.", cfg.StaticTokens)
|
||||
|
||||
// always create the default namespace
|
||||
err = asrv.UpsertNamespace(types.NewNamespace(defaults.Namespace))
|
||||
err = asrv.UpsertNamespace(types.NewNamespace(apidefaults.Namespace))
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
log.Infof("Created namespace: %q.", defaults.Namespace)
|
||||
log.Infof("Created namespace: %q.", apidefaults.Namespace)
|
||||
|
||||
// always create a default admin role
|
||||
defaultRole := services.NewAdminRole()
|
||||
@@ -354,7 +355,7 @@ func Init(cfg InitConfig, opts ...ServerOption) (*Server, error) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: cfg.ClusterName.GetClusterName(),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.CertAuthoritySpecV2{
|
||||
ClusterName: cfg.ClusterName.GetClusterName(),
|
||||
@@ -414,7 +415,7 @@ func Init(cfg InitConfig, opts ...ServerOption) (*Server, error) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: cfg.ClusterName.GetClusterName(),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.CertAuthoritySpecV2{
|
||||
ClusterName: cfg.ClusterName.GetClusterName(),
|
||||
@@ -1015,7 +1016,7 @@ func (i *Identity) SSHClientConfig() *ssh.ClientConfig {
|
||||
ssh.PublicKeys(i.KeySigner),
|
||||
},
|
||||
HostKeyCallback: i.hostKeyCallback,
|
||||
Timeout: defaults.DefaultDialTimeout,
|
||||
Timeout: apidefaults.DefaultDialTimeout,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1287,7 +1288,7 @@ func migrateRoleOptions(ctx context.Context, asrv *Server) error {
|
||||
options := role.GetOptions()
|
||||
if options.BPF == nil {
|
||||
log.Debugf("Migrating role %v. Added default enhanced events.", role.GetName())
|
||||
options.BPF = defaults.EnhancedEvents()
|
||||
options.BPF = apidefaults.EnhancedEvents()
|
||||
} else {
|
||||
continue
|
||||
}
|
||||
|
||||
+2
-2
@@ -20,8 +20,8 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/modules"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/tlsca"
|
||||
@@ -128,7 +128,7 @@ func (s *Server) ProcessKubeCSR(req KubeCSR) (*KubeCSRResponse, error) {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
// Get the correct cert TTL based on roles.
|
||||
ttl := roles.AdjustSessionTTL(defaults.CertDuration)
|
||||
ttl := roles.AdjustSessionTTL(apidefaults.CertDuration)
|
||||
|
||||
userCA, err := s.Trust.GetCertAuthority(types.CertAuthID{
|
||||
Type: types.UserCA,
|
||||
|
||||
@@ -26,12 +26,12 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/limiter"
|
||||
"github.com/gravitational/teleport/lib/multiplexer"
|
||||
"github.com/gravitational/teleport/lib/tlsca"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
"github.com/gravitational/trace/trail"
|
||||
@@ -144,7 +144,7 @@ func NewTLSServer(cfg TLSServerConfig) (*TLSServer, error) {
|
||||
cfg: cfg,
|
||||
httpServer: &http.Server{
|
||||
Handler: limiter,
|
||||
ReadHeaderTimeout: defaults.DefaultDialTimeout,
|
||||
ReadHeaderTimeout: apidefaults.DefaultDialTimeout,
|
||||
},
|
||||
log: logrus.WithFields(logrus.Fields{
|
||||
trace.Component: cfg.Component,
|
||||
|
||||
@@ -31,6 +31,7 @@ import (
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/api/types/wrappers"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/sshutils"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
@@ -207,7 +208,7 @@ func (k *Keygen) GenerateHostCertWithoutValidation(c services.HostCertParams) ([
|
||||
return nil, trace.BadParameter("no principals provided: %v, %v, %v",
|
||||
c.HostID, c.NodeName, c.Principals)
|
||||
}
|
||||
principals = utils.Deduplicate(principals)
|
||||
principals = apiutils.Deduplicate(principals)
|
||||
|
||||
// create certificate
|
||||
validBefore := uint64(ssh.CertTimeInfinity)
|
||||
@@ -370,5 +371,5 @@ func BuildPrincipals(hostID string, nodeName string, clusterName string, roles t
|
||||
)
|
||||
|
||||
// deduplicate (in-case hostID and nodeName are the same) and return
|
||||
return utils.Deduplicate(principals)
|
||||
return apiutils.Deduplicate(principals)
|
||||
}
|
||||
|
||||
+5
-3
@@ -26,8 +26,10 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
@@ -124,7 +126,7 @@ func oidcConfig(conn types.OIDCConnector) oidc.ClientConfig {
|
||||
Secret: conn.GetClientSecret(),
|
||||
},
|
||||
// open id notifies provider that we are using OIDC scopes
|
||||
Scope: utils.Deduplicate(append([]string{"openid", "email"}, conn.GetScope()...)),
|
||||
Scope: apiutils.Deduplicate(append([]string{"openid", "email"}, conn.GetScope()...)),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -452,7 +454,7 @@ func (a *Server) calculateOIDCUser(connector types.OIDCConnector, claims jose.Cl
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
roleTTL := roles.AdjustSessionTTL(defaults.MaxCertDuration)
|
||||
roleTTL := roles.AdjustSessionTTL(apidefaults.MaxCertDuration)
|
||||
p.sessionTTL = utils.MinTTL(roleTTL, request.CertTTL)
|
||||
|
||||
return &p, nil
|
||||
@@ -467,7 +469,7 @@ func (a *Server) createOIDCUser(p *createUserParams) (types.User, error) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: p.username,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Expires: &expires,
|
||||
},
|
||||
Spec: types.UserSpecV2{
|
||||
|
||||
+3
-2
@@ -28,6 +28,7 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -166,7 +167,7 @@ func (a *Server) calculateSAMLUser(connector types.SAMLConnector, assertionInfo
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
roleTTL := roles.AdjustSessionTTL(defaults.MaxCertDuration)
|
||||
roleTTL := roles.AdjustSessionTTL(apidefaults.MaxCertDuration)
|
||||
p.sessionTTL = utils.MinTTL(roleTTL, request.CertTTL)
|
||||
|
||||
return &p, nil
|
||||
@@ -182,7 +183,7 @@ func (a *Server) createSAMLUser(p *createUserParams) (types.User, error) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: p.username,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Expires: &expires,
|
||||
},
|
||||
Spec: types.UserSpecV2{
|
||||
|
||||
+54
-52
@@ -41,8 +41,10 @@ import (
|
||||
"github.com/gravitational/teleport/api/client"
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/api/utils/sshutils"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
@@ -110,7 +112,7 @@ func (s *TLSSuite) TestRemoteBuiltinRole(c *check.C) {
|
||||
|
||||
// certificate authority is not recognized, because
|
||||
// the trust has not been established yet
|
||||
_, err = remoteProxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = remoteProxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
fixtures.ExpectConnectionProblem(c, err)
|
||||
|
||||
// after trust is established, things are good
|
||||
@@ -122,7 +124,7 @@ func (s *TLSSuite) TestRemoteBuiltinRole(c *check.C) {
|
||||
TestBuiltin(types.RoleProxy), s.server.Addr(), certPool)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
_, err = remoteProxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = remoteProxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// remote auth server will get rejected even with established trust
|
||||
@@ -160,7 +162,7 @@ func (s *TLSSuite) TestAcceptedUsage(c *check.C) {
|
||||
|
||||
// certificate authority is not recognized, because
|
||||
// the trust has not been established yet
|
||||
_, err = client.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = client.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// restricted clients can use restricted servers if restrictions
|
||||
@@ -170,7 +172,7 @@ func (s *TLSSuite) TestAcceptedUsage(c *check.C) {
|
||||
client, err = tlsServer.NewClient(identity)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
_, err = client.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = client.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// restricted clients can will be rejected if usage does not match
|
||||
@@ -179,7 +181,7 @@ func (s *TLSSuite) TestAcceptedUsage(c *check.C) {
|
||||
client, err = tlsServer.NewClient(identity)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
_, err = client.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = client.GetNodes(ctx, apidefaults.Namespace)
|
||||
fixtures.ExpectAccessDenied(c, err)
|
||||
|
||||
// restricted clients can will be rejected, for now if there is any mismatch,
|
||||
@@ -189,7 +191,7 @@ func (s *TLSSuite) TestAcceptedUsage(c *check.C) {
|
||||
client, err = tlsServer.NewClient(identity)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
_, err = client.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = client.GetNodes(ctx, apidefaults.Namespace)
|
||||
fixtures.ExpectAccessDenied(c, err)
|
||||
}
|
||||
|
||||
@@ -288,11 +290,11 @@ func (s *TLSSuite) TestRemoteRotation(c *check.C) {
|
||||
TestBuiltin(types.RoleProxy), s.server.Addr(), certPool)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
_, err = newRemoteProxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = newRemoteProxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// old proxy client is still trusted
|
||||
_, err = s.server.CloneClient(remoteProxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(remoteProxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
}
|
||||
|
||||
@@ -344,7 +346,7 @@ func (s *TLSSuite) TestAutoRotation(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// client works before rotation is initiated
|
||||
_, err = proxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = proxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// starts rotation
|
||||
@@ -371,7 +373,7 @@ func (s *TLSSuite) TestAutoRotation(c *check.C) {
|
||||
c.Assert(ca.GetRotation().Phase, check.Equals, types.RotationPhaseUpdateClients)
|
||||
|
||||
// old clients should work
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// new clients work as well
|
||||
@@ -391,14 +393,14 @@ func (s *TLSSuite) TestAutoRotation(c *check.C) {
|
||||
c.Assert(ca.GetRotation().Phase, check.Equals, types.RotationPhaseUpdateServers)
|
||||
|
||||
// old clients should work
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// new clients work as well
|
||||
newProxy, err := s.server.NewClient(TestBuiltin(types.RoleProxy))
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
_, err = newProxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = newProxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// complete rotation - advance rotation by clock
|
||||
@@ -418,11 +420,11 @@ func (s *TLSSuite) TestAutoRotation(c *check.C) {
|
||||
// connection instead of re-using the one from pool
|
||||
// this is not going to be a problem in real teleport
|
||||
// as it reloads the full server after reload
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.ErrorMatches, ".*bad certificate.*")
|
||||
|
||||
// new clients work
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
}
|
||||
|
||||
@@ -438,7 +440,7 @@ func (s *TLSSuite) TestAutoFallback(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// client works before rotation is initiated
|
||||
_, err = proxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = proxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// starts rotation
|
||||
@@ -494,7 +496,7 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// client works before rotation is initiated
|
||||
_, err = proxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = proxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// can't jump to mid-phase
|
||||
@@ -519,7 +521,7 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// old clients should work
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// clients reconnect
|
||||
@@ -532,14 +534,14 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// old clients should work
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// new clients work as well
|
||||
newProxy, err := s.server.NewClient(TestBuiltin(types.RoleProxy))
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
_, err = newProxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = newProxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// can't jump to standy
|
||||
@@ -561,11 +563,11 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// old clients should work
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// new clients work as well
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// complete rotation
|
||||
@@ -582,11 +584,11 @@ func (s *TLSSuite) TestManualRotation(c *check.C) {
|
||||
// connection instead of re-using the one from pool
|
||||
// this is not going to be a problem in real teleport
|
||||
// as it reloads the full server after reload
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.ErrorMatches, ".*bad certificate.*")
|
||||
|
||||
// new clients work
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
}
|
||||
|
||||
@@ -600,7 +602,7 @@ func (s *TLSSuite) TestRollback(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// client works before rotation is initiated
|
||||
_, err = proxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = proxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// starts rotation
|
||||
@@ -628,7 +630,7 @@ func (s *TLSSuite) TestRollback(c *check.C) {
|
||||
newProxy, err := s.server.NewClient(TestBuiltin(types.RoleProxy))
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
_, err = newProxy.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = newProxy.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// advance rotation:
|
||||
@@ -651,7 +653,7 @@ func (s *TLSSuite) TestRollback(c *check.C) {
|
||||
|
||||
// new clients work, server still accepts the creds
|
||||
// because new clients should re-register and receive new certs
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// can't jump to other phases
|
||||
@@ -673,11 +675,11 @@ func (s *TLSSuite) TestRollback(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// clients with new creds will no longer work
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(newProxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.ErrorMatches, ".*bad certificate.*")
|
||||
|
||||
// clients with old creds will still work
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, defaults.Namespace)
|
||||
_, err = s.server.CloneClient(proxy).GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
}
|
||||
|
||||
@@ -876,7 +878,7 @@ func (s *TLSSuite) TestNopUser(c *check.C) {
|
||||
_, err = client.GetUsers(false)
|
||||
fixtures.ExpectAccessDenied(c, err)
|
||||
|
||||
_, err = client.GetNodes(ctx, defaults.Namespace)
|
||||
_, err = client.GetNodes(ctx, apidefaults.Namespace)
|
||||
fixtures.ExpectAccessDenied(c, err)
|
||||
|
||||
// Endpoints that allow current user access should return access denied to
|
||||
@@ -1090,12 +1092,12 @@ func (s *TLSSuite) TestValidateUploadSessionRecording(c *check.C) {
|
||||
Created: date,
|
||||
LastActive: date,
|
||||
Login: "bob",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
}
|
||||
c.Assert(clt.CreateSession(sess), check.IsNil)
|
||||
|
||||
err = clt.UploadSessionRecording(events.SessionRecording{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: sess.ID,
|
||||
Recording: recording,
|
||||
})
|
||||
@@ -1181,7 +1183,7 @@ func (s *TLSSuite) TestValidatePostSessionSlice(c *check.C) {
|
||||
Created: date,
|
||||
LastActive: date,
|
||||
Login: "bob",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
}
|
||||
c.Assert(clt.CreateSession(sess), check.IsNil)
|
||||
|
||||
@@ -1194,7 +1196,7 @@ func (s *TLSSuite) TestValidatePostSessionSlice(c *check.C) {
|
||||
}
|
||||
|
||||
err = clt.PostSessionSlice(events.SessionSlice{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: string(sess.ID),
|
||||
Chunks: []*events.SessionChunk{
|
||||
{
|
||||
@@ -1216,7 +1218,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
clt, err := s.server.NewClient(TestAdmin())
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
out, err := clt.GetSessions(defaults.Namespace)
|
||||
out, err := clt.GetSessions(apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.DeepEquals, []session.Session{})
|
||||
|
||||
@@ -1227,11 +1229,11 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
Created: date,
|
||||
LastActive: date,
|
||||
Login: "bob",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
}
|
||||
c.Assert(clt.CreateSession(sess), check.IsNil)
|
||||
|
||||
out, err = clt.GetSessions(defaults.Namespace)
|
||||
out, err = clt.GetSessions(apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
c.Assert(out, check.DeepEquals, []session.Session{sess})
|
||||
@@ -1247,10 +1249,10 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
|
||||
// emit two events: "one" and "two" for this session, and event "three"
|
||||
// for some other session
|
||||
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", defaults.Namespace), 0755)
|
||||
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", apidefaults.Namespace), 0755)
|
||||
c.Assert(err, check.IsNil)
|
||||
forwarder, err := events.NewForwarder(events.ForwarderConfig{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: sess.ID,
|
||||
ServerID: teleport.ComponentUpload,
|
||||
DataDir: uploadDir,
|
||||
@@ -1260,7 +1262,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
err = forwarder.PostSessionSlice(events.SessionSlice{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: string(sess.ID),
|
||||
Chunks: []*events.SessionChunk{
|
||||
{
|
||||
@@ -1283,7 +1285,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
|
||||
anotherSessionID := session.NewID()
|
||||
forwarder, err = events.NewForwarder(events.ForwarderConfig{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: sess.ID,
|
||||
ServerID: teleport.ComponentUpload,
|
||||
DataDir: uploadDir,
|
||||
@@ -1292,7 +1294,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
})
|
||||
c.Assert(err, check.IsNil)
|
||||
err = clt.PostSessionSlice(events.SessionSlice{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: string(anotherSessionID),
|
||||
Chunks: []*events.SessionChunk{
|
||||
{
|
||||
@@ -1318,7 +1320,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
uploader, err := events.NewUploader(events.UploaderConfig{
|
||||
ServerID: "upload",
|
||||
DataDir: uploadDir,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Context: context.TODO(),
|
||||
ScanPeriod: 100 * time.Millisecond,
|
||||
AuditLog: clt,
|
||||
@@ -1338,7 +1340,7 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
}
|
||||
|
||||
// ask for strictly session events:
|
||||
e, err := clt.GetSessionEvents(defaults.Namespace, sess.ID, 0, true)
|
||||
e, err := clt.GetSessionEvents(apidefaults.Namespace, sess.ID, 0, true)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(len(e), check.Equals, 2)
|
||||
c.Assert(e[0].GetString("val"), check.Equals, "one")
|
||||
@@ -1347,14 +1349,14 @@ func (s *TLSSuite) TestSharedSessions(c *check.C) {
|
||||
// try searching for events with no filter (empty query) - should get all 3 events:
|
||||
to := time.Now().In(time.UTC).Add(time.Hour)
|
||||
from := to.Add(-time.Hour * 2)
|
||||
history, _, err := clt.SearchEvents(from, to, defaults.Namespace, nil, 0, "")
|
||||
history, _, err := clt.SearchEvents(from, to, apidefaults.Namespace, nil, 0, "")
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(history, check.NotNil)
|
||||
// Extra event is the upload event
|
||||
c.Assert(len(history), check.Equals, 5)
|
||||
|
||||
// try searching for only "session.end" events (real query)
|
||||
history, _, err = clt.SearchEvents(from, to, defaults.Namespace, []string{events.SessionEndEvent}, 0, "")
|
||||
history, _, err = clt.SearchEvents(from, to, apidefaults.Namespace, []string{events.SessionEndEvent}, 0, "")
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(history, check.NotNil)
|
||||
c.Assert(len(history), check.Equals, 2)
|
||||
@@ -1713,7 +1715,7 @@ func (s *TLSSuite) TestAccessRequest(c *check.C) {
|
||||
identity, err := tlsca.FromSubject(cert.Subject, cert.NotAfter)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
return utils.SliceContainsStr(identity.Groups, role)
|
||||
return apiutils.SliceContainsStr(identity.Groups, role)
|
||||
}
|
||||
|
||||
// certLogins extracts the logins from an ssh certificate
|
||||
@@ -2144,7 +2146,7 @@ func TestGenerateCerts(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
parsedCert, diff := parseCert(userCerts.SSH)
|
||||
require.Less(t, int64(defaults.MaxCertDuration), int64(diff))
|
||||
require.Less(t, int64(apidefaults.MaxCertDuration), int64(diff))
|
||||
|
||||
// user should have agent forwarding (default setting)
|
||||
require.Contains(t, parsedCert.Extensions, teleport.CertExtensionPermitAgentForwarding)
|
||||
@@ -2218,7 +2220,7 @@ func TestGenerateCerts(t *testing.T) {
|
||||
})
|
||||
require.Error(t, err)
|
||||
|
||||
userRole2.SetClusterLabels(types.Allow, types.Labels{"env": utils.Strings{"prod"}})
|
||||
userRole2.SetClusterLabels(types.Allow, types.Labels{"env": apiutils.Strings{"prod"}})
|
||||
err = srv.Auth().UpsertRole(ctx, userRole2)
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -2361,7 +2363,7 @@ func (s *TLSSuite) TestCertificateFormat(c *check.C) {
|
||||
},
|
||||
},
|
||||
CompatibilityMode: tt.inClientCertificateFormat,
|
||||
TTL: defaults.CertDuration,
|
||||
TTL: apidefaults.CertDuration,
|
||||
PublicKey: pub,
|
||||
})
|
||||
c.Assert(err, check.IsNil)
|
||||
@@ -2842,7 +2844,7 @@ func (s *TLSSuite) TestEventsNodePresence(c *check.C) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "node1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
Addr: "localhost:3022",
|
||||
@@ -3113,7 +3115,7 @@ func (s *TLSSuite) TestEventsClusterConfig(c *check.C) {
|
||||
Kind: types.KindToken,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Name: token.GetName(),
|
||||
},
|
||||
})
|
||||
@@ -3142,7 +3144,7 @@ func (s *TLSSuite) TestEventsClusterConfig(c *check.C) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: types.MetaNameClusterName,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{
|
||||
"key": "val",
|
||||
},
|
||||
|
||||
@@ -28,9 +28,9 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/tlsca"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
@@ -267,7 +267,7 @@ func (cfg *Config) Validate() error {
|
||||
cfg.BufferSize = backend.DefaultBufferSize
|
||||
}
|
||||
if cfg.DialTimeout == 0 {
|
||||
cfg.DialTimeout = defaults.DefaultDialTimeout
|
||||
cfg.DialTimeout = apidefaults.DefaultDialTimeout
|
||||
}
|
||||
if cfg.PasswordFile != "" {
|
||||
out, err := ioutil.ReadFile(cfg.PasswordFile)
|
||||
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
@@ -301,7 +302,7 @@ func buildKeyLabel(key []byte, sensitivePrefixes []string) string {
|
||||
return string(bytes.Join(parts, []byte{Separator}))
|
||||
}
|
||||
|
||||
if utils.SliceContainsStr(sensitivePrefixes, string(parts[1])) {
|
||||
if apiutils.SliceContainsStr(sensitivePrefixes, string(parts[1])) {
|
||||
hiddenBefore := int(math.Floor(0.75 * float64(len(parts[2]))))
|
||||
asterisks := bytes.Repeat([]byte("*"), hiddenBefore)
|
||||
parts[2] = append(asterisks, parts[2][hiddenBefore:]...)
|
||||
|
||||
+2
-2
@@ -35,7 +35,7 @@ import (
|
||||
"github.com/aquasecurity/tracee/libbpfgo"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/prometheus/client_golang/prometheus"
|
||||
"github.com/prometheus/client_golang/prometheus/testutil"
|
||||
@@ -88,7 +88,7 @@ func (s *Suite) TestWatch(c *check.C) {
|
||||
// Create a monitoring session for init. The events we execute should not
|
||||
// have PID 1, so nothing should be captured in the Audit Log.
|
||||
cgroupID, err := service.OpenSession(&SessionContext{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: uuid.New(),
|
||||
ServerID: uuid.New(),
|
||||
Login: "foo",
|
||||
|
||||
Vendored
+5
-4
@@ -22,6 +22,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -172,7 +173,7 @@ func ForNode(cfg Config) Config {
|
||||
// Node only needs to "know" about default
|
||||
// namespace events to avoid matching too much
|
||||
// data about other namespaces or node events
|
||||
{Kind: types.KindNamespace, Name: defaults.Namespace},
|
||||
{Kind: types.KindNamespace, Name: apidefaults.Namespace},
|
||||
}
|
||||
cfg.QueueSize = defaults.NodeQueueSize
|
||||
return cfg
|
||||
@@ -190,7 +191,7 @@ func ForKubernetes(cfg Config) Config {
|
||||
{Kind: types.KindSessionRecordingConfig},
|
||||
{Kind: types.KindUser},
|
||||
{Kind: types.KindRole},
|
||||
{Kind: types.KindNamespace, Name: defaults.Namespace},
|
||||
{Kind: types.KindNamespace, Name: apidefaults.Namespace},
|
||||
{Kind: types.KindKubeService},
|
||||
}
|
||||
cfg.QueueSize = defaults.KubernetesQueueSize
|
||||
@@ -212,7 +213,7 @@ func ForApps(cfg Config) Config {
|
||||
{Kind: types.KindProxy},
|
||||
// Applications only need to "know" about default namespace events to avoid
|
||||
// matching too much data about other namespaces or events.
|
||||
{Kind: types.KindNamespace, Name: defaults.Namespace},
|
||||
{Kind: types.KindNamespace, Name: apidefaults.Namespace},
|
||||
}
|
||||
cfg.QueueSize = defaults.AppsQueueSize
|
||||
return cfg
|
||||
@@ -232,7 +233,7 @@ func ForDatabases(cfg Config) Config {
|
||||
{Kind: types.KindProxy},
|
||||
// Databases only need to "know" about default namespace events to
|
||||
// avoid matching too much data about other namespaces or events.
|
||||
{Kind: types.KindNamespace, Name: defaults.Namespace},
|
||||
{Kind: types.KindNamespace, Name: apidefaults.Namespace},
|
||||
}
|
||||
cfg.QueueSize = defaults.DatabasesQueueSize
|
||||
return cfg
|
||||
|
||||
Vendored
+25
-23
@@ -24,7 +24,9 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/lite"
|
||||
"github.com/gravitational/teleport/lib/backend/memory"
|
||||
@@ -413,7 +415,7 @@ func waitForEvent(c *check.C, eventsC <-chan Event, expectedEvent string, skipEv
|
||||
// wait for watcher to restart
|
||||
select {
|
||||
case event := <-eventsC:
|
||||
if utils.SliceContainsStr(skipEvents, event.Type) {
|
||||
if apiutils.SliceContainsStr(skipEvents, event.Type) {
|
||||
continue
|
||||
}
|
||||
c.Assert(event.Type, check.Equals, expectedEvent)
|
||||
@@ -1259,11 +1261,11 @@ func (s *CacheSuite) TestNodes(c *check.C) {
|
||||
p := s.newPackForProxy(c)
|
||||
defer p.Close()
|
||||
|
||||
server := suite.NewServer(types.KindNode, "srv1", "127.0.0.1:2022", defaults.Namespace)
|
||||
server := suite.NewServer(types.KindNode, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
|
||||
_, err := p.presenceS.UpsertNode(ctx, server)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
out, err := p.presenceS.GetNodes(ctx, defaults.Namespace)
|
||||
out, err := p.presenceS.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
srv := out[0]
|
||||
@@ -1275,7 +1277,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
|
||||
c.Fatalf("timeout waiting for event")
|
||||
}
|
||||
|
||||
out, err = p.cache.GetNodes(ctx, defaults.Namespace)
|
||||
out, err = p.cache.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
|
||||
@@ -1289,7 +1291,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
|
||||
lease, err := p.presenceS.UpsertNode(ctx, srv)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
out, err = p.presenceS.GetNodes(ctx, defaults.Namespace)
|
||||
out, err = p.presenceS.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
srv = out[0]
|
||||
@@ -1301,7 +1303,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
|
||||
c.Fatalf("timeout waiting for event")
|
||||
}
|
||||
|
||||
out, err = p.cache.GetNodes(ctx, defaults.Namespace)
|
||||
out, err = p.cache.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
|
||||
@@ -1321,7 +1323,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
|
||||
c.Fatalf("timeout waiting for event")
|
||||
}
|
||||
|
||||
out, err = p.cache.GetNodes(ctx, defaults.Namespace)
|
||||
out, err = p.cache.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
|
||||
@@ -1329,7 +1331,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
|
||||
srv.SetExpiry(lease.Expires)
|
||||
fixtures.DeepCompare(c, srv, out[0])
|
||||
|
||||
err = p.presenceS.DeleteAllNodes(ctx, defaults.Namespace)
|
||||
err = p.presenceS.DeleteAllNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
select {
|
||||
@@ -1338,7 +1340,7 @@ func (s *CacheSuite) TestNodes(c *check.C) {
|
||||
c.Fatalf("timeout waiting for event")
|
||||
}
|
||||
|
||||
out, err = p.cache.GetNodes(ctx, defaults.Namespace)
|
||||
out, err = p.cache.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 0)
|
||||
}
|
||||
@@ -1348,7 +1350,7 @@ func (s *CacheSuite) TestProxies(c *check.C) {
|
||||
p := s.newPackForProxy(c)
|
||||
defer p.Close()
|
||||
|
||||
server := suite.NewServer(types.KindProxy, "srv1", "127.0.0.1:2022", defaults.Namespace)
|
||||
server := suite.NewServer(types.KindProxy, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
|
||||
err := p.presenceS.UpsertProxy(server)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
@@ -1415,7 +1417,7 @@ func (s *CacheSuite) TestAuthServers(c *check.C) {
|
||||
p := s.newPackForProxy(c)
|
||||
defer p.Close()
|
||||
|
||||
server := suite.NewServer(types.KindAuthServer, "srv1", "127.0.0.1:2022", defaults.Namespace)
|
||||
server := suite.NewServer(types.KindAuthServer, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
|
||||
err := p.presenceS.UpsertAuthServer(server)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
@@ -1561,7 +1563,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// Check that the application is now in the backend.
|
||||
out, err := p.presenceS.GetAppServers(context.Background(), defaults.Namespace)
|
||||
out, err := p.presenceS.GetAppServers(context.Background(), apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
srv := out[0]
|
||||
@@ -1575,7 +1577,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
|
||||
}
|
||||
|
||||
// Make sure the cache has a single application in it.
|
||||
out, err = p.cache.GetAppServers(context.Background(), defaults.Namespace)
|
||||
out, err = p.cache.GetAppServers(context.Background(), apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
|
||||
@@ -1593,7 +1595,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
|
||||
|
||||
// Check that the application is in the backend and only one exists (so an
|
||||
// update occurred).
|
||||
out, err = p.presenceS.GetAppServers(context.Background(), defaults.Namespace)
|
||||
out, err = p.presenceS.GetAppServers(context.Background(), apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
srv = out[0]
|
||||
@@ -1607,7 +1609,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
|
||||
}
|
||||
|
||||
// Make sure the cache has a single application in it.
|
||||
out, err = p.cache.GetAppServers(context.Background(), defaults.Namespace)
|
||||
out, err = p.cache.GetAppServers(context.Background(), apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 1)
|
||||
|
||||
@@ -1617,7 +1619,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
|
||||
fixtures.DeepCompare(c, srv, out[0])
|
||||
|
||||
// Remove all applications from the backend.
|
||||
err = p.presenceS.DeleteAllAppServers(context.Background(), defaults.Namespace)
|
||||
err = p.presenceS.DeleteAllAppServers(context.Background(), apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// Check that information has been replicated to the cache.
|
||||
@@ -1629,7 +1631,7 @@ func (s *CacheSuite) TestAppServers(c *check.C) {
|
||||
}
|
||||
|
||||
// Check that the cache is now empty.
|
||||
out, err = p.cache.GetAppServers(context.Background(), defaults.Namespace)
|
||||
out, err = p.cache.GetAppServers(context.Background(), apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(out, check.HasLen, 0)
|
||||
}
|
||||
@@ -1655,7 +1657,7 @@ func TestDatabaseServers(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// Check that the database server is now in the backend.
|
||||
out, err := p.presenceS.GetDatabaseServers(context.Background(), defaults.Namespace)
|
||||
out, err := p.presenceS.GetDatabaseServers(context.Background(), apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Empty(t, cmp.Diff([]types.DatabaseServer{server}, out,
|
||||
cmpopts.IgnoreFields(types.Metadata{}, "ID")))
|
||||
@@ -1669,7 +1671,7 @@ func TestDatabaseServers(t *testing.T) {
|
||||
}
|
||||
|
||||
// Make sure the cache has a single database server in it.
|
||||
out, err = p.cache.GetDatabaseServers(context.Background(), defaults.Namespace)
|
||||
out, err = p.cache.GetDatabaseServers(context.Background(), apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Empty(t, cmp.Diff([]types.DatabaseServer{server}, out,
|
||||
cmpopts.IgnoreFields(types.Metadata{}, "ID")))
|
||||
@@ -1681,7 +1683,7 @@ func TestDatabaseServers(t *testing.T) {
|
||||
|
||||
// Check that the server is in the backend and only one exists (so an
|
||||
// update occurred).
|
||||
out, err = p.presenceS.GetDatabaseServers(context.Background(), defaults.Namespace)
|
||||
out, err = p.presenceS.GetDatabaseServers(context.Background(), apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Empty(t, cmp.Diff([]types.DatabaseServer{server}, out,
|
||||
cmpopts.IgnoreFields(types.Metadata{}, "ID")))
|
||||
@@ -1695,13 +1697,13 @@ func TestDatabaseServers(t *testing.T) {
|
||||
}
|
||||
|
||||
// Make sure the cache has a single database server in it.
|
||||
out, err = p.cache.GetDatabaseServers(context.Background(), defaults.Namespace)
|
||||
out, err = p.cache.GetDatabaseServers(context.Background(), apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Empty(t, cmp.Diff([]types.DatabaseServer{server}, out,
|
||||
cmpopts.IgnoreFields(types.Metadata{}, "ID")))
|
||||
|
||||
// Remove all database servers from the backend.
|
||||
err = p.presenceS.DeleteAllDatabaseServers(context.Background(), defaults.Namespace)
|
||||
err = p.presenceS.DeleteAllDatabaseServers(context.Background(), apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
|
||||
// Check that information has been replicated to the cache.
|
||||
@@ -1713,7 +1715,7 @@ func TestDatabaseServers(t *testing.T) {
|
||||
}
|
||||
|
||||
// Check that the cache is now empty.
|
||||
out, err = p.cache.GetDatabaseServers(context.Background(), defaults.Namespace)
|
||||
out, err = p.cache.GetDatabaseServers(context.Background(), apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, 0, len(out))
|
||||
}
|
||||
|
||||
Vendored
+7
-7
@@ -20,8 +20,8 @@ import (
|
||||
"context"
|
||||
"strings"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
)
|
||||
@@ -624,7 +624,7 @@ type node struct {
|
||||
|
||||
// erase erases all data in the collection
|
||||
func (c *node) erase(ctx context.Context) error {
|
||||
if err := c.presenceCache.DeleteAllNodes(ctx, defaults.Namespace); err != nil {
|
||||
if err := c.presenceCache.DeleteAllNodes(ctx, apidefaults.Namespace); err != nil {
|
||||
if !trace.IsNotFound(err) {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -633,7 +633,7 @@ func (c *node) erase(ctx context.Context) error {
|
||||
}
|
||||
|
||||
func (c *node) fetch(ctx context.Context) (apply func(ctx context.Context) error, err error) {
|
||||
resources, err := c.Presence.GetNodes(ctx, defaults.Namespace)
|
||||
resources, err := c.Presence.GetNodes(ctx, apidefaults.Namespace)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
@@ -1307,7 +1307,7 @@ type databaseServer struct {
|
||||
}
|
||||
|
||||
func (s *databaseServer) erase(ctx context.Context) error {
|
||||
err := s.presenceCache.DeleteAllDatabaseServers(ctx, defaults.Namespace)
|
||||
err := s.presenceCache.DeleteAllDatabaseServers(ctx, apidefaults.Namespace)
|
||||
if err != nil && !trace.IsNotFound(err) {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -1315,7 +1315,7 @@ func (s *databaseServer) erase(ctx context.Context) error {
|
||||
}
|
||||
|
||||
func (s *databaseServer) fetch(ctx context.Context) (apply func(ctx context.Context) error, err error) {
|
||||
resources, err := s.Presence.GetDatabaseServers(ctx, defaults.Namespace)
|
||||
resources, err := s.Presence.GetDatabaseServers(ctx, apidefaults.Namespace)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
@@ -1374,7 +1374,7 @@ type appServer struct {
|
||||
|
||||
// erase erases all data in the collection
|
||||
func (a *appServer) erase(ctx context.Context) error {
|
||||
if err := a.presenceCache.DeleteAllAppServers(ctx, defaults.Namespace); err != nil {
|
||||
if err := a.presenceCache.DeleteAllAppServers(ctx, apidefaults.Namespace); err != nil {
|
||||
if !trace.IsNotFound(err) {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -1383,7 +1383,7 @@ func (a *appServer) erase(ctx context.Context) error {
|
||||
}
|
||||
|
||||
func (a *appServer) fetch(ctx context.Context) (apply func(ctx context.Context) error, err error) {
|
||||
resources, err := a.Presence.GetAppServers(ctx, defaults.Namespace)
|
||||
resources, err := a.Presence.GetAppServers(ctx, apidefaults.Namespace)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
|
||||
+2
-1
@@ -49,6 +49,7 @@ import (
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
"github.com/gravitational/teleport/api/client/webclient"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/profile"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/api/types/wrappers"
|
||||
@@ -1032,7 +1033,7 @@ func NewClient(c *Config) (tc *TeleportClient, err error) {
|
||||
log.Infof("no host login given. defaulting to %s", c.HostLogin)
|
||||
}
|
||||
if c.KeyTTL == 0 {
|
||||
c.KeyTTL = defaults.CertDuration
|
||||
c.KeyTTL = apidefaults.CertDuration
|
||||
}
|
||||
c.Namespace = types.ProcessNamespace(c.Namespace)
|
||||
|
||||
|
||||
@@ -35,9 +35,9 @@ import (
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/client"
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/sshutils"
|
||||
"github.com/gravitational/teleport/lib/sshutils/scp"
|
||||
@@ -102,7 +102,7 @@ func (proxy *ProxyClient) GetSites() ([]types.Site, error) {
|
||||
}()
|
||||
select {
|
||||
case <-done:
|
||||
case <-time.After(defaults.DefaultDialTimeout):
|
||||
case <-time.After(apidefaults.DefaultDialTimeout):
|
||||
return nil, trace.ConnectionProblem(nil, "timeout")
|
||||
}
|
||||
log.Debugf("Found clusters: %v", stdout.String())
|
||||
@@ -682,7 +682,7 @@ func (proxy *ProxyClient) ConnectToRootCluster(ctx context.Context, quiet bool)
|
||||
// if 'quiet' is set to true, no errors will be printed to stdout, otherwise
|
||||
// any connection errors are visible to a user.
|
||||
func (proxy *ProxyClient) ConnectToCluster(ctx context.Context, clusterName string, quiet bool) (auth.ClientI, error) {
|
||||
dialer := auth.ContextDialerFunc(func(ctx context.Context, network, _ string) (net.Conn, error) {
|
||||
dialer := client.ContextDialerFunc(func(ctx context.Context, network, _ string) (net.Conn, error) {
|
||||
return proxy.dialAuthServer(ctx, clusterName)
|
||||
})
|
||||
|
||||
@@ -997,7 +997,7 @@ func (proxy *ProxyClient) ConnectToNode(ctx context.Context, nodeAddress NodeAdd
|
||||
nc := &NodeClient{
|
||||
Client: client,
|
||||
Proxy: proxy,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
TC: proxy.teleportClient,
|
||||
}
|
||||
|
||||
@@ -1069,7 +1069,7 @@ func (proxy *ProxyClient) PortForwardToNode(ctx context.Context, nodeAddress Nod
|
||||
nc := &NodeClient{
|
||||
Client: client,
|
||||
Proxy: proxy,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
TC: proxy.teleportClient,
|
||||
}
|
||||
|
||||
|
||||
@@ -37,6 +37,7 @@ import (
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/lite"
|
||||
@@ -1042,7 +1043,7 @@ func parseKnownHosts(bytes []byte, allowedLogins []string) (types.CertAuthority,
|
||||
|
||||
// transform old allowed logins into roles
|
||||
role := services.RoleForCertAuthority(ca)
|
||||
role.SetLogins(services.Allow, utils.CopyStrings(allowedLogins))
|
||||
role.SetLogins(services.Allow, apiutils.CopyStrings(allowedLogins))
|
||||
ca.AddRole(role.GetName())
|
||||
|
||||
return ca, role, nil
|
||||
@@ -1203,7 +1204,7 @@ func Configure(clf *CommandLineFlags, cfg *service.Config) error {
|
||||
|
||||
// If this process is trying to join a cluster as an application service,
|
||||
// make sure application name and URI are provided.
|
||||
if utils.SliceContainsStr(splitRoles(clf.Roles), defaults.RoleApp) &&
|
||||
if apiutils.SliceContainsStr(splitRoles(clf.Roles), defaults.RoleApp) &&
|
||||
(clf.AppName == "" || clf.AppURI == "") {
|
||||
return trace.BadParameter("application name (--app-name) and URI (--app-uri) flags are both required to join application proxy to the cluster")
|
||||
}
|
||||
|
||||
@@ -29,7 +29,9 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/lite"
|
||||
@@ -42,10 +44,9 @@ import (
|
||||
|
||||
"github.com/google/go-cmp/cmp"
|
||||
"github.com/google/go-cmp/cmp/cmpopts"
|
||||
"github.com/gravitational/trace"
|
||||
"github.com/stretchr/testify/require"
|
||||
"golang.org/x/crypto/ssh"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
)
|
||||
|
||||
type testConfigFiles struct {
|
||||
@@ -273,7 +274,7 @@ func TestConfigReading(t *testing.T) {
|
||||
ListenAddress: "tcp://kube",
|
||||
},
|
||||
KubeClusterName: "kube-cluster",
|
||||
PublicAddr: utils.Strings([]string{"kube-host:1234"}),
|
||||
PublicAddr: apiutils.Strings([]string{"kube-host:1234"}),
|
||||
},
|
||||
Apps: Apps{
|
||||
Service: Service{
|
||||
@@ -490,7 +491,7 @@ func TestApplyConfig(t *testing.T) {
|
||||
conf, err := ReadConfig(bytes.NewBufferString(fmt.Sprintf(SmallConfigString, tokenPath)))
|
||||
require.NoError(t, err)
|
||||
require.NotNil(t, conf)
|
||||
require.Equal(t, utils.Strings{"web3:443"}, conf.Proxy.PublicAddr)
|
||||
require.Equal(t, apiutils.Strings{"web3:443"}, conf.Proxy.PublicAddr)
|
||||
|
||||
cfg := service.MakeDefaultConfig()
|
||||
err = ApplyFileConfig(conf, cfg)
|
||||
@@ -529,7 +530,7 @@ func TestApplyConfig(t *testing.T) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "cluster-auth-preference",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{types.OriginLabel: types.OriginConfigFile},
|
||||
},
|
||||
Spec: types.AuthPreferenceSpecV2{
|
||||
@@ -809,7 +810,7 @@ func checkStaticConfig(t *testing.T, conf *FileConfig) {
|
||||
{Name: "hostname", Command: []string{"/bin/hostname"}, Period: 10 * time.Millisecond},
|
||||
{Name: "date", Command: []string{"/bin/date"}, Period: 20 * time.Millisecond},
|
||||
},
|
||||
PublicAddr: utils.Strings{"luna3:22"},
|
||||
PublicAddr: apiutils.Strings{"luna3:22"},
|
||||
}, cmp.AllowUnexported(Service{})))
|
||||
|
||||
require.True(t, conf.Auth.Configured())
|
||||
@@ -843,7 +844,7 @@ func checkStaticConfig(t *testing.T, conf *FileConfig) {
|
||||
"proxy,node:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
|
||||
"auth:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
|
||||
},
|
||||
PublicAddr: utils.Strings{
|
||||
PublicAddr: apiutils.Strings{
|
||||
"auth.default.svc.cluster.local:3080",
|
||||
},
|
||||
ClientIdleTimeout: types.Duration(17 * time.Second),
|
||||
@@ -940,7 +941,7 @@ func makeConfigFixture() string {
|
||||
ListenAddress: "tcp://kube",
|
||||
},
|
||||
KubeClusterName: "kube-cluster",
|
||||
PublicAddr: utils.Strings([]string{"kube-host:1234"}),
|
||||
PublicAddr: apiutils.Strings([]string{"kube-host:1234"}),
|
||||
}
|
||||
|
||||
// Application service.
|
||||
@@ -1143,7 +1144,7 @@ func TestProxyKube(t *testing.T) {
|
||||
cfg: Proxy{Kube: KubeProxy{
|
||||
Service: Service{EnabledFlag: "yes", ListenAddress: "0.0.0.0:8080"},
|
||||
KubeconfigFile: "/tmp/kubeconfig",
|
||||
PublicAddr: utils.Strings([]string{"kube.example.com:443"}),
|
||||
PublicAddr: apiutils.Strings([]string{"kube.example.com:443"}),
|
||||
}},
|
||||
want: service.KubeProxyConfig{
|
||||
Enabled: true,
|
||||
@@ -1180,7 +1181,7 @@ func TestProxyKube(t *testing.T) {
|
||||
Kube: KubeProxy{
|
||||
Service: Service{EnabledFlag: "no", ListenAddress: "0.0.0.0:8080"},
|
||||
KubeconfigFile: "/tmp/kubeconfig",
|
||||
PublicAddr: utils.Strings([]string{"kube.example.com:443"}),
|
||||
PublicAddr: apiutils.Strings([]string{"kube.example.com:443"}),
|
||||
},
|
||||
},
|
||||
want: service.KubeProxyConfig{
|
||||
|
||||
+21
-20
@@ -34,6 +34,7 @@ import (
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/api/utils/tlsutils"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/bpf"
|
||||
@@ -175,7 +176,7 @@ func MakeSampleFileConfig(flags SampleFlags) (fc *FileConfig, err error) {
|
||||
p.ACME.Email = flags.ACMEEmail
|
||||
// ACME uses TLS-ALPN-01 challenge that requires port 443
|
||||
// https://letsencrypt.org/docs/challenge-types/#tls-alpn-01
|
||||
p.PublicAddr = utils.Strings{net.JoinHostPort(flags.ClusterName, fmt.Sprintf("%d", teleport.StandardHTTPSPort))}
|
||||
p.PublicAddr = apiutils.Strings{net.JoinHostPort(flags.ClusterName, fmt.Sprintf("%d", teleport.StandardHTTPSPort))}
|
||||
p.WebAddr = fmt.Sprintf(":%d", teleport.StandardHTTPSPort)
|
||||
}
|
||||
|
||||
@@ -210,21 +211,21 @@ func (conf *FileConfig) CheckAndSetDefaults() error {
|
||||
sc.SetDefaults()
|
||||
|
||||
for _, c := range conf.Ciphers {
|
||||
if !utils.SliceContainsStr(sc.Ciphers, c) {
|
||||
if !apiutils.SliceContainsStr(sc.Ciphers, c) {
|
||||
return trace.BadParameter("cipher algorithm %q is not supported; supported algorithms: %q", c, sc.Ciphers)
|
||||
}
|
||||
}
|
||||
for _, k := range conf.KEXAlgorithms {
|
||||
if !utils.SliceContainsStr(sc.KeyExchanges, k) {
|
||||
if !apiutils.SliceContainsStr(sc.KeyExchanges, k) {
|
||||
return trace.BadParameter("KEX algorithm %q is not supported; supported algorithms: %q", k, sc.KeyExchanges)
|
||||
}
|
||||
}
|
||||
for _, m := range conf.MACAlgorithms {
|
||||
if !utils.SliceContainsStr(sc.MACs, m) {
|
||||
if !apiutils.SliceContainsStr(sc.MACs, m) {
|
||||
return trace.BadParameter("MAC algorithm %q is not supported; supported algorithms: %q", m, sc.MACs)
|
||||
}
|
||||
}
|
||||
if conf.CASignatureAlgorithm != nil && !utils.SliceContainsStr(validCASigAlgos, *conf.CASignatureAlgorithm) {
|
||||
if conf.CASignatureAlgorithm != nil && !apiutils.SliceContainsStr(validCASigAlgos, *conf.CASignatureAlgorithm) {
|
||||
return trace.BadParameter("CA signature algorithm %q is not supported; supported algorithms: %q", *conf.CASignatureAlgorithm, validCASigAlgos)
|
||||
}
|
||||
|
||||
@@ -318,7 +319,7 @@ func (c *CachePolicy) Enabled() bool {
|
||||
if c.EnabledFlag == "" {
|
||||
return true
|
||||
}
|
||||
enabled, _ := utils.ParseBool(c.EnabledFlag)
|
||||
enabled, _ := apiutils.ParseBool(c.EnabledFlag)
|
||||
return enabled
|
||||
}
|
||||
|
||||
@@ -366,7 +367,7 @@ func (s *Service) Enabled() bool {
|
||||
if !s.Configured() {
|
||||
return s.defaultEnabled
|
||||
}
|
||||
v, err := utils.ParseBool(s.EnabledFlag)
|
||||
v, err := apiutils.ParseBool(s.EnabledFlag)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
@@ -441,7 +442,7 @@ type Auth struct {
|
||||
|
||||
// PublicAddr sets SSH host principals and TLS DNS names to auth
|
||||
// server certificates
|
||||
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
|
||||
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
|
||||
|
||||
// ClientIdleTimeout sets global cluster default setting for client idle timeouts
|
||||
ClientIdleTimeout types.Duration `yaml:"client_idle_timeout,omitempty"`
|
||||
@@ -613,7 +614,7 @@ type SSH struct {
|
||||
PermitUserEnvironment bool `yaml:"permit_user_env,omitempty"`
|
||||
PAM *PAM `yaml:"pam,omitempty"`
|
||||
// PublicAddr sets SSH host principals for SSH service
|
||||
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
|
||||
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
|
||||
|
||||
// BPF is used to configure BPF-based auditing for this node.
|
||||
BPF *BPF `yaml:"enhanced_recording,omitempty"`
|
||||
@@ -649,7 +650,7 @@ func (p *PAM) Parse() *pam.Config {
|
||||
if serviceName == "" {
|
||||
serviceName = defaults.ServiceName
|
||||
}
|
||||
enabled, _ := utils.ParseBool(p.Enabled)
|
||||
enabled, _ := apiutils.ParseBool(p.Enabled)
|
||||
return &pam.Config{
|
||||
Enabled: enabled,
|
||||
ServiceName: serviceName,
|
||||
@@ -678,7 +679,7 @@ type BPF struct {
|
||||
|
||||
// Parse will parse the enhanced session recording configuration.
|
||||
func (b *BPF) Parse() *bpf.Config {
|
||||
enabled, _ := utils.ParseBool(b.Enabled)
|
||||
enabled, _ := apiutils.ParseBool(b.Enabled)
|
||||
return &bpf.Config{
|
||||
Enabled: enabled,
|
||||
CommandBufferSize: b.CommandBufferSize,
|
||||
@@ -817,22 +818,22 @@ type Proxy struct {
|
||||
// local Kubernetes cluster.
|
||||
KubeAddr string `yaml:"kube_listen_addr,omitempty"`
|
||||
// KubePublicAddr is a public address of the kubernetes endpoint.
|
||||
KubePublicAddr utils.Strings `yaml:"kube_public_addr,omitempty"`
|
||||
KubePublicAddr apiutils.Strings `yaml:"kube_public_addr,omitempty"`
|
||||
|
||||
// PublicAddr sets the hostport the proxy advertises for the HTTP endpoint.
|
||||
// The hosts in PublicAddr are included in the list of host principals
|
||||
// on the SSH certificate.
|
||||
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
|
||||
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
|
||||
|
||||
// SSHPublicAddr sets the hostport the proxy advertises for the SSH endpoint.
|
||||
// The hosts in PublicAddr are included in the list of host principals
|
||||
// on the SSH certificate.
|
||||
SSHPublicAddr utils.Strings `yaml:"ssh_public_addr,omitempty"`
|
||||
SSHPublicAddr apiutils.Strings `yaml:"ssh_public_addr,omitempty"`
|
||||
|
||||
// TunnelPublicAddr sets the hostport the proxy advertises for the tunnel
|
||||
// endpoint. The hosts in PublicAddr are included in the list of host
|
||||
// principals on the SSH certificate.
|
||||
TunnelPublicAddr utils.Strings `yaml:"tunnel_public_addr,omitempty"`
|
||||
TunnelPublicAddr apiutils.Strings `yaml:"tunnel_public_addr,omitempty"`
|
||||
|
||||
// KeyPairs is a list of x509 key pairs the proxy will load.
|
||||
KeyPairs []KeyPair `yaml:"https_keypairs"`
|
||||
@@ -844,10 +845,10 @@ type Proxy struct {
|
||||
MySQLAddr string `yaml:"mysql_listen_addr,omitempty"`
|
||||
// MySQLPublicAddr is the hostport the proxy advertises for MySQL
|
||||
// client connections.
|
||||
MySQLPublicAddr utils.Strings `yaml:"mysql_public_addr,omitempty"`
|
||||
MySQLPublicAddr apiutils.Strings `yaml:"mysql_public_addr,omitempty"`
|
||||
// PostgresPublicAddr is the hostport the proxy advertises for Postgres
|
||||
// client connections.
|
||||
PostgresPublicAddr utils.Strings `yaml:"postgres_public_addr,omitempty"`
|
||||
PostgresPublicAddr apiutils.Strings `yaml:"postgres_public_addr,omitempty"`
|
||||
}
|
||||
|
||||
// ACME configures ACME protocol - automatic X.509 certificates
|
||||
@@ -869,7 +870,7 @@ func (a ACME) Parse() (*service.ACME, error) {
|
||||
}
|
||||
|
||||
var err error
|
||||
out.Enabled, err = utils.ParseBool(a.EnabledFlag)
|
||||
out.Enabled, err = apiutils.ParseBool(a.EnabledFlag)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
@@ -898,7 +899,7 @@ type KubeProxy struct {
|
||||
// Service is a generic service configuration section
|
||||
Service `yaml:",inline"`
|
||||
// PublicAddr is a publicly advertised address of the kubernetes proxy
|
||||
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
|
||||
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
|
||||
// KubeconfigFile is an optional path to kubeconfig file,
|
||||
// if specified, teleport will use API server address and
|
||||
// trusted certificate authority information from it
|
||||
@@ -913,7 +914,7 @@ type Kube struct {
|
||||
// Service is a generic service configuration section
|
||||
Service `yaml:",inline"`
|
||||
// PublicAddr is a publicly advertised address of the kubernetes service
|
||||
PublicAddr utils.Strings `yaml:"public_addr,omitempty"`
|
||||
PublicAddr apiutils.Strings `yaml:"public_addr,omitempty"`
|
||||
// KubeconfigFile is an optional path to kubeconfig file,
|
||||
// if specified, teleport will use API server address and
|
||||
// trusted certificate authority information from it
|
||||
|
||||
@@ -91,10 +91,6 @@ const (
|
||||
// to a cluster
|
||||
InviteTokenTTL = 15 * time.Minute
|
||||
|
||||
// DefaultDialTimeout is a default TCP dial timeout we set for our
|
||||
// connection attempts
|
||||
DefaultDialTimeout = defaults.DefaultDialTimeout
|
||||
|
||||
// HTTPMaxIdleConns is the max idle connections across all hosts.
|
||||
HTTPMaxIdleConns = 2000
|
||||
|
||||
@@ -218,9 +214,6 @@ const (
|
||||
// is locked after MaxLoginAttempts
|
||||
AccountLockInterval = 20 * time.Minute
|
||||
|
||||
// Namespace is default namespace
|
||||
Namespace = defaults.Namespace
|
||||
|
||||
// AttemptTTL is TTL for login attempt
|
||||
AttemptTTL = time.Minute * 30
|
||||
|
||||
@@ -282,16 +275,6 @@ var (
|
||||
// ResyncInterval is how often tunnels are resynced.
|
||||
ResyncInterval = 5 * time.Second
|
||||
|
||||
// ServerAnnounceTTL is a period between heartbeats
|
||||
// Median sleep time between node pings is this value / 2 + random
|
||||
// deviation added to this time to avoid lots of simultaneous
|
||||
// heartbeats coming to auth server
|
||||
ServerAnnounceTTL = defaults.ServerAnnounceTTL
|
||||
|
||||
// ServerKeepAliveTTL is a period between server keep alives,
|
||||
// when servers announce only presence withough sending full data
|
||||
ServerKeepAliveTTL = defaults.ServerKeepAliveTTL
|
||||
|
||||
// AuthServersRefreshPeriod is a period for clients to refresh their
|
||||
// their stored list of auth servers
|
||||
AuthServersRefreshPeriod = 30 * time.Second
|
||||
@@ -343,17 +326,6 @@ var (
|
||||
// period used in services
|
||||
HighResReportingPeriod = 10 * time.Second
|
||||
|
||||
// KeepAliveInterval is interval at which Teleport will send keep-alive
|
||||
// messages to the client. The default interval of 5 minutes (300 seconds) is
|
||||
// set to help keep connections alive when using AWS NLBs (which have a default
|
||||
// timeout of 350 seconds)
|
||||
KeepAliveInterval = defaults.KeepAliveInterval
|
||||
|
||||
// KeepAliveCountMax is the number of keep-alive messages that can be sent
|
||||
// without receiving a response from the client before the client is
|
||||
// disconnected. The max count mirrors ClientAliveCountMax of sshd.
|
||||
KeepAliveCountMax = defaults.KeepAliveCountMax
|
||||
|
||||
// DiskAlertThreshold is the disk space alerting threshold.
|
||||
DiskAlertThreshold = 90
|
||||
|
||||
@@ -431,19 +403,18 @@ const (
|
||||
const (
|
||||
// MinCertDuration specifies minimum duration of validity of issued certificate
|
||||
MinCertDuration = time.Minute
|
||||
// MaxCertDuration limits maximum duration of validity of issued certificate
|
||||
MaxCertDuration = defaults.MaxCertDuration
|
||||
// CertDuration is a default certificate duration.
|
||||
CertDuration = defaults.CertDuration
|
||||
|
||||
// RotationGracePeriod is a default rotation period for graceful
|
||||
// certificate rotations, by default to set to maximum allowed user
|
||||
// cert duration
|
||||
RotationGracePeriod = MaxCertDuration
|
||||
RotationGracePeriod = defaults.MaxCertDuration
|
||||
|
||||
// PendingAccessDuration defines the expiry of a pending access request.
|
||||
PendingAccessDuration = time.Hour
|
||||
|
||||
// MaxAccessDuration defines the maximum time for which an access request
|
||||
// can be active.
|
||||
MaxAccessDuration = MaxCertDuration
|
||||
MaxAccessDuration = defaults.MaxCertDuration
|
||||
)
|
||||
|
||||
// list of roles teleport service can run as:
|
||||
@@ -492,9 +463,6 @@ const (
|
||||
ArgsCacheSize = 1024
|
||||
)
|
||||
|
||||
// EnhancedEvents returns the default list of enhanced events.
|
||||
var EnhancedEvents = defaults.EnhancedEvents
|
||||
|
||||
var (
|
||||
// ConfigFilePath is default path to teleport config file
|
||||
ConfigFilePath = "/etc/teleport.yaml"
|
||||
|
||||
@@ -32,6 +32,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/session"
|
||||
@@ -241,7 +242,7 @@ func NewAuditLog(cfg AuditLogConfig) (*AuditLog, error) {
|
||||
}
|
||||
ctx, cancel := context.WithCancel(cfg.Context)
|
||||
al := &AuditLog{
|
||||
playbackDir: filepath.Join(cfg.DataDir, PlaybackDir, SessionLogsDir, defaults.Namespace),
|
||||
playbackDir: filepath.Join(cfg.DataDir, PlaybackDir, SessionLogsDir, apidefaults.Namespace),
|
||||
AuditLogConfig: cfg,
|
||||
log: log.WithFields(log.Fields{
|
||||
trace.Component: teleport.ComponentAuditLog,
|
||||
@@ -258,7 +259,7 @@ func NewAuditLog(cfg AuditLogConfig) (*AuditLog, error) {
|
||||
return nil, trace.ConvertSystemError(err)
|
||||
}
|
||||
// create a directory for session logs:
|
||||
sessionDir := filepath.Join(cfg.DataDir, cfg.ServerID, SessionLogsDir, defaults.Namespace)
|
||||
sessionDir := filepath.Join(cfg.DataDir, cfg.ServerID, SessionLogsDir, apidefaults.Namespace)
|
||||
if err := os.MkdirAll(sessionDir, *cfg.DirMask); err != nil {
|
||||
return nil, trace.ConvertSystemError(err)
|
||||
}
|
||||
@@ -325,7 +326,7 @@ func (l *SessionRecording) CheckAndSetDefaults() error {
|
||||
return trace.BadParameter("missing parameter session ID")
|
||||
}
|
||||
if l.Namespace == "" {
|
||||
l.Namespace = defaults.Namespace
|
||||
l.Namespace = apidefaults.Namespace
|
||||
}
|
||||
return nil
|
||||
}
|
||||
@@ -1176,7 +1177,7 @@ func (l *LegacyHandler) IsUnpacked(ctx context.Context, sessionID session.ID) (b
|
||||
if err != nil {
|
||||
return false, trace.Wrap(err)
|
||||
}
|
||||
_, err = readSessionIndex(l.cfg.Dir, authServers, defaults.Namespace, sessionID)
|
||||
_, err = readSessionIndex(l.cfg.Dir, authServers, apidefaults.Namespace, sessionID)
|
||||
if err == nil {
|
||||
return true, nil
|
||||
}
|
||||
|
||||
+23
-24
@@ -26,14 +26,13 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/jonboulle/clockwork"
|
||||
"gopkg.in/check.v1"
|
||||
|
||||
"github.com/jonboulle/clockwork"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types/events"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/fixtures"
|
||||
"github.com/gravitational/teleport/lib/session"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
@@ -126,11 +125,11 @@ func (a *AuditTestSuite) TestSessionsOnOneAuthServer(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
uploadDir := c.MkDir()
|
||||
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", defaults.Namespace), 0755)
|
||||
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", apidefaults.Namespace), 0755)
|
||||
c.Assert(err, check.IsNil)
|
||||
sessionID := string(session.NewID())
|
||||
forwarder, err := NewForwarder(ForwarderConfig{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: session.ID(sessionID),
|
||||
ServerID: teleport.ComponentUpload,
|
||||
DataDir: uploadDir,
|
||||
@@ -143,7 +142,7 @@ func (a *AuditTestSuite) TestSessionsOnOneAuthServer(c *check.C) {
|
||||
// start the session and emit data stream to it
|
||||
firstMessage := []byte("hello")
|
||||
err = forwarder.PostSessionSlice(SessionSlice{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: sessionID,
|
||||
Chunks: []*SessionChunk{
|
||||
// start the session
|
||||
@@ -180,7 +179,7 @@ func (a *AuditTestSuite) TestSessionsOnOneAuthServer(c *check.C) {
|
||||
// does not matter which audit server is accessed the results should be the same
|
||||
for _, a := range []*AuditLog{alog, alog2} {
|
||||
// read the session bytes
|
||||
history, err := a.GetSessionEvents(defaults.Namespace, session.ID(sessionID), 0, true)
|
||||
history, err := a.GetSessionEvents(apidefaults.Namespace, session.ID(sessionID), 0, true)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(history, check.HasLen, 3)
|
||||
|
||||
@@ -189,12 +188,12 @@ func (a *AuditTestSuite) TestSessionsOnOneAuthServer(c *check.C) {
|
||||
c.Assert(history[1][SessionEventTimestamp], check.Equals, float64(0))
|
||||
|
||||
// fetch all bytes
|
||||
buff, err := a.GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, 5000)
|
||||
buff, err := a.GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, 5000)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(string(buff), check.Equals, string(firstMessage))
|
||||
|
||||
// with offset
|
||||
buff, err = a.GetSessionChunk(defaults.Namespace, session.ID(sessionID), 2, 5000)
|
||||
buff, err = a.GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 2, 5000)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(string(buff), check.Equals, string(firstMessage[2:]))
|
||||
}
|
||||
@@ -207,7 +206,7 @@ func upload(c *check.C, uploadDir string, clock clockwork.Clock, auditLog IAudit
|
||||
ServerID: "upload",
|
||||
DataDir: uploadDir,
|
||||
Clock: clock,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Context: context.TODO(),
|
||||
ScanPeriod: 100 * time.Millisecond,
|
||||
AuditLog: auditLog,
|
||||
@@ -247,10 +246,10 @@ func (a *AuditTestSuite) TestSessionRecordingOff(c *check.C) {
|
||||
sessionID := string(session.NewID())
|
||||
|
||||
uploadDir := c.MkDir()
|
||||
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", defaults.Namespace), 0755)
|
||||
err = os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", apidefaults.Namespace), 0755)
|
||||
c.Assert(err, check.IsNil)
|
||||
forwarder, err := NewForwarder(ForwarderConfig{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: session.ID(sessionID),
|
||||
ServerID: teleport.ComponentUpload,
|
||||
DataDir: uploadDir,
|
||||
@@ -263,7 +262,7 @@ func (a *AuditTestSuite) TestSessionRecordingOff(c *check.C) {
|
||||
// start the session and emit data stream to it
|
||||
firstMessage := []byte("hello")
|
||||
err = forwarder.PostSessionSlice(SessionSlice{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: sessionID,
|
||||
Chunks: []*SessionChunk{
|
||||
// start the session
|
||||
@@ -298,7 +297,7 @@ func (a *AuditTestSuite) TestSessionRecordingOff(c *check.C) {
|
||||
upload(c, uploadDir, fakeClock, alog)
|
||||
|
||||
// get all events from the audit log, should have two session event and one upload event
|
||||
found, _, err := alog.SearchEvents(now.Add(-time.Hour), now.Add(time.Hour), defaults.Namespace, nil, 0, "")
|
||||
found, _, err := alog.SearchEvents(now.Add(-time.Hour), now.Add(time.Hour), apidefaults.Namespace, nil, 0, "")
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(found, check.HasLen, 3)
|
||||
eventA, okA := found[0].(*apievents.SessionStart)
|
||||
@@ -309,12 +308,12 @@ func (a *AuditTestSuite) TestSessionRecordingOff(c *check.C) {
|
||||
c.Assert(eventB.Login, check.Equals, username)
|
||||
|
||||
// inspect the session log for "200", should have two events
|
||||
history, err := alog.GetSessionEvents(defaults.Namespace, session.ID(sessionID), 0, true)
|
||||
history, err := alog.GetSessionEvents(apidefaults.Namespace, session.ID(sessionID), 0, true)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(history, check.HasLen, 2)
|
||||
|
||||
// try getting the session stream, should get an error
|
||||
_, err = alog.GetSessionChunk(defaults.Namespace, session.ID(sessionID), 0, 5000)
|
||||
_, err = alog.GetSessionChunk(apidefaults.Namespace, session.ID(sessionID), 0, 5000)
|
||||
c.Assert(err, check.NotNil)
|
||||
}
|
||||
|
||||
@@ -383,7 +382,7 @@ func (a *AuditTestSuite) TestLogRotation(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(string(bytes), check.Equals, string(contents))
|
||||
|
||||
found, _, err := alog.SearchEvents(now.Add(-time.Hour), now.Add(time.Hour), defaults.Namespace, nil, 0, "")
|
||||
found, _, err := alog.SearchEvents(now.Add(-time.Hour), now.Add(time.Hour), apidefaults.Namespace, nil, 0, "")
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(found, check.HasLen, 1)
|
||||
}
|
||||
@@ -443,7 +442,7 @@ func (a *AuditTestSuite) TestLegacyHandler(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(authServers, check.HasLen, 1)
|
||||
|
||||
targetDir := filepath.Join(a.dataDir, authServers[0], SessionLogsDir, defaults.Namespace)
|
||||
targetDir := filepath.Join(a.dataDir, authServers[0], SessionLogsDir, apidefaults.Namespace)
|
||||
|
||||
_, err = tarball.Seek(0, 0)
|
||||
c.Assert(err, check.IsNil)
|
||||
@@ -491,12 +490,12 @@ func (a *AuditTestSuite) TestExternalLog(c *check.C) {
|
||||
// server case
|
||||
func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock, alog IAuditLog) (session.ID, func() error) {
|
||||
uploadDir := c.MkDir()
|
||||
err := os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", defaults.Namespace), 0755)
|
||||
err := os.MkdirAll(filepath.Join(uploadDir, "upload", "sessions", apidefaults.Namespace), 0755)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
sessionID := session.NewID()
|
||||
forwarder, err := NewForwarder(ForwarderConfig{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: sessionID,
|
||||
ServerID: "upload",
|
||||
DataDir: uploadDir,
|
||||
@@ -508,7 +507,7 @@ func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock,
|
||||
// start the session and emit data stream to it and wrap it up
|
||||
firstMessage := []byte("hello")
|
||||
err = forwarder.PostSessionSlice(SessionSlice{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: string(sessionID),
|
||||
Chunks: []*SessionChunk{
|
||||
// start the seession
|
||||
@@ -543,7 +542,7 @@ func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock,
|
||||
upload(c, uploadDir, fakeClock, alog)
|
||||
|
||||
compare := func() error {
|
||||
history, err := alog.GetSessionEvents(defaults.Namespace, sessionID, 0, true)
|
||||
history, err := alog.GetSessionEvents(apidefaults.Namespace, sessionID, 0, true)
|
||||
if err != nil {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -560,7 +559,7 @@ func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock,
|
||||
}
|
||||
|
||||
// fetch all bytes
|
||||
buff, err := alog.GetSessionChunk(defaults.Namespace, sessionID, 0, 5000)
|
||||
buff, err := alog.GetSessionChunk(apidefaults.Namespace, sessionID, 0, 5000)
|
||||
if err != nil {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -569,7 +568,7 @@ func (a *AuditTestSuite) forwardAndUpload(c *check.C, fakeClock clockwork.Clock,
|
||||
}
|
||||
|
||||
// with offset
|
||||
buff, err = alog.GetSessionChunk(defaults.Namespace, sessionID, 2, 5000)
|
||||
buff, err = alog.GetSessionChunk(apidefaults.Namespace, sessionID, 2, 5000)
|
||||
if err != nil {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
|
||||
@@ -21,6 +21,7 @@ import (
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/session"
|
||||
@@ -124,7 +125,7 @@ func (cfg *AuditWriterConfig) CheckAndSetDefaults() error {
|
||||
return trace.BadParameter("audit writer config: missing parameter ClusterName")
|
||||
}
|
||||
if cfg.Namespace == "" {
|
||||
cfg.Namespace = defaults.Namespace
|
||||
cfg.Namespace = apidefaults.Namespace
|
||||
}
|
||||
if cfg.Clock == nil {
|
||||
cfg.Clock = clockwork.NewRealClock()
|
||||
|
||||
@@ -23,8 +23,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/session"
|
||||
"github.com/gravitational/trace"
|
||||
|
||||
@@ -321,7 +321,7 @@ func newAuditWriterTest(t *testing.T, newStreamer newStreamerFn) *auditWriterTes
|
||||
sid := session.NewID()
|
||||
writer, err := NewAuditWriter(AuditWriterConfig{
|
||||
SessionID: sid,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
RecordOutput: true,
|
||||
Streamer: streamer,
|
||||
Context: ctx,
|
||||
|
||||
@@ -21,8 +21,10 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types/events"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
@@ -181,7 +183,7 @@ func (u *UploadCompleter) ensureSessionEndEvent(ctx context.Context, uploadData
|
||||
var interactive bool
|
||||
|
||||
// Get session events to find fields for constructed session end
|
||||
sessionEvents, err := u.cfg.AuditLog.GetSessionEvents(defaults.Namespace, uploadData.SessionID, 0, false)
|
||||
sessionEvents, err := u.cfg.AuditLog.GetSessionEvents(apidefaults.Namespace, uploadData.SessionID, 0, false)
|
||||
if err != nil {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
@@ -263,5 +265,5 @@ func getParticipants(sessionEvents []EventFields) []string {
|
||||
|
||||
}
|
||||
}
|
||||
return utils.Deduplicate(participants)
|
||||
return apiutils.Deduplicate(participants)
|
||||
}
|
||||
|
||||
@@ -27,10 +27,10 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/dynamo"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/session"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
@@ -458,7 +458,7 @@ func (l *Log) EmitAuditEvent(ctx context.Context, in apievents.AuditEvent) error
|
||||
SessionID: sessionID,
|
||||
EventIndex: in.GetIndex(),
|
||||
EventType: in.GetType(),
|
||||
EventNamespace: defaults.Namespace,
|
||||
EventNamespace: apidefaults.Namespace,
|
||||
CreatedAt: in.GetTime().Unix(),
|
||||
Fields: string(data),
|
||||
CreatedAtDate: in.GetTime().Format(iso8601DateFormat),
|
||||
@@ -505,7 +505,7 @@ func (l *Log) EmitAuditEventLegacy(ev events.Event, fields events.EventFields) e
|
||||
SessionID: sessionID,
|
||||
EventIndex: int64(eventIndex),
|
||||
EventType: fields.GetString(events.EventType),
|
||||
EventNamespace: defaults.Namespace,
|
||||
EventNamespace: apidefaults.Namespace,
|
||||
CreatedAt: created.Unix(),
|
||||
Fields: string(data),
|
||||
CreatedAtDate: created.Format(iso8601DateFormat),
|
||||
@@ -555,7 +555,7 @@ func (l *Log) PostSessionSlice(slice events.SessionSlice) error {
|
||||
|
||||
event := event{
|
||||
SessionID: slice.SessionID,
|
||||
EventNamespace: defaults.Namespace,
|
||||
EventNamespace: apidefaults.Namespace,
|
||||
EventType: chunk.EventType,
|
||||
EventIndex: chunk.EventIndex,
|
||||
CreatedAt: timeAt.Unix(),
|
||||
@@ -862,7 +862,7 @@ func (l *Log) SearchSessionEvents(fromUTC time.Time, toUTC time.Time, limit int,
|
||||
events.SessionStartEvent,
|
||||
events.SessionEndEvent,
|
||||
}
|
||||
return l.SearchEvents(fromUTC, toUTC, defaults.Namespace, query, limit, startKey)
|
||||
return l.SearchEvents(fromUTC, toUTC, apidefaults.Namespace, query, limit, startKey)
|
||||
}
|
||||
|
||||
// WaitForDelivery waits for resources to be released and outstanding requests to
|
||||
|
||||
@@ -31,9 +31,9 @@ import (
|
||||
"github.com/aws/aws-sdk-go/service/dynamodb"
|
||||
"github.com/aws/aws-sdk-go/service/dynamodb/dynamodbattribute"
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/backend/memory"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/events/test"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
@@ -118,7 +118,7 @@ func (s *DynamoeventsSuite) TestSessionEventsCRUD(c *check.C) {
|
||||
for i := 0; i < dynamoDBLargeQueryRetries; i++ {
|
||||
time.Sleep(s.EventsSuite.QueryDelay)
|
||||
|
||||
history, _, err = s.Log.SearchEvents(s.Clock.Now().Add(-1*time.Hour), s.Clock.Now().Add(time.Hour), defaults.Namespace, nil, 0, "")
|
||||
history, _, err = s.Log.SearchEvents(s.Clock.Now().Add(-1*time.Hour), s.Clock.Now().Add(time.Hour), apidefaults.Namespace, nil, 0, "")
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
if len(history) == eventCount {
|
||||
@@ -189,7 +189,7 @@ func (s *DynamoeventsSuite) TestEventMigration(c *check.C) {
|
||||
|
||||
for time.Since(waitStart) < attemptWaitFor {
|
||||
err = utils.RetryStaticFor(time.Minute*5, time.Second*5, func() error {
|
||||
eventArr, _, err = s.log.searchEventsRaw(start, end, defaults.Namespace, []string{"test.event"}, 1000, "")
|
||||
eventArr, _, err = s.log.searchEventsRaw(start, end, apidefaults.Namespace, []string{"test.event"}, 1000, "")
|
||||
return err
|
||||
})
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
@@ -21,9 +21,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types/events"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
|
||||
"github.com/jonboulle/clockwork"
|
||||
"github.com/stretchr/testify/require"
|
||||
@@ -45,7 +44,7 @@ func TestFileLogPagination(t *testing.T) {
|
||||
Type: SessionJoinEvent,
|
||||
Time: clock.Now().UTC(),
|
||||
},
|
||||
UserMetadata: apievents.UserMetadata{
|
||||
UserMetadata: events.UserMetadata{
|
||||
User: "bob",
|
||||
},
|
||||
})
|
||||
@@ -57,7 +56,7 @@ func TestFileLogPagination(t *testing.T) {
|
||||
Type: SessionJoinEvent,
|
||||
Time: clock.Now().Add(time.Minute).UTC(),
|
||||
},
|
||||
UserMetadata: apievents.UserMetadata{
|
||||
UserMetadata: events.UserMetadata{
|
||||
User: "alice",
|
||||
},
|
||||
})
|
||||
@@ -69,7 +68,7 @@ func TestFileLogPagination(t *testing.T) {
|
||||
Type: SessionJoinEvent,
|
||||
Time: clock.Now().Add(time.Minute * 2).UTC(),
|
||||
},
|
||||
UserMetadata: apievents.UserMetadata{
|
||||
UserMetadata: events.UserMetadata{
|
||||
User: "dave",
|
||||
},
|
||||
})
|
||||
@@ -77,12 +76,12 @@ func TestFileLogPagination(t *testing.T) {
|
||||
|
||||
from := clock.Now().Add(-time.Hour).UTC()
|
||||
to := clock.Now().Add(time.Hour).UTC()
|
||||
eventArr, checkpoint, err := log.SearchEvents(from, to, defaults.Namespace, nil, 2, "")
|
||||
eventArr, checkpoint, err := log.SearchEvents(from, to, apidefaults.Namespace, nil, 2, "")
|
||||
require.Nil(t, err)
|
||||
require.Len(t, eventArr, 2)
|
||||
require.NotEqual(t, checkpoint, "")
|
||||
|
||||
eventArr, checkpoint, err = log.SearchEvents(from, to, defaults.Namespace, nil, 2, checkpoint)
|
||||
eventArr, checkpoint, err = log.SearchEvents(from, to, apidefaults.Namespace, nil, 2, checkpoint)
|
||||
require.Nil(t, err)
|
||||
require.Len(t, eventArr, 1)
|
||||
require.Equal(t, checkpoint, "")
|
||||
|
||||
@@ -27,6 +27,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
@@ -532,7 +533,7 @@ func (u *Uploader) upload(up *upload) error {
|
||||
// before the files are closed to avoid async writes
|
||||
// the timeout is a defensive measure to avoid blocking
|
||||
// indefinitely in case of unforeseen error (e.g. write taking too long)
|
||||
wctx, wcancel := context.WithTimeout(ctx, defaults.DefaultDialTimeout)
|
||||
wctx, wcancel := context.WithTimeout(ctx, apidefaults.DefaultDialTimeout)
|
||||
defer wcancel()
|
||||
|
||||
<-wctx.Done()
|
||||
|
||||
@@ -30,6 +30,7 @@ import (
|
||||
"github.com/prometheus/client_golang/prometheus"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
firestorebk "github.com/gravitational/teleport/lib/backend/firestore"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
@@ -324,7 +325,7 @@ func (l *Log) EmitAuditEvent(ctx context.Context, in apievents.AuditEvent) error
|
||||
SessionID: sessionID,
|
||||
EventIndex: in.GetIndex(),
|
||||
EventType: in.GetType(),
|
||||
EventNamespace: defaults.Namespace,
|
||||
EventNamespace: apidefaults.Namespace,
|
||||
CreatedAt: in.GetTime().Unix(),
|
||||
Fields: string(data),
|
||||
}
|
||||
@@ -363,7 +364,7 @@ func (l *Log) EmitAuditEventLegacy(ev events.Event, fields events.EventFields) e
|
||||
SessionID: sessionID,
|
||||
EventIndex: int64(eventIndex),
|
||||
EventType: fields.GetString(events.EventType),
|
||||
EventNamespace: defaults.Namespace,
|
||||
EventNamespace: apidefaults.Namespace,
|
||||
CreatedAt: created.Unix(),
|
||||
Fields: string(data),
|
||||
}
|
||||
@@ -395,7 +396,7 @@ func (l *Log) PostSessionSlice(slice events.SessionSlice) error {
|
||||
}
|
||||
event := event{
|
||||
SessionID: slice.SessionID,
|
||||
EventNamespace: defaults.Namespace,
|
||||
EventNamespace: apidefaults.Namespace,
|
||||
EventType: chunk.EventType,
|
||||
EventIndex: chunk.EventIndex,
|
||||
CreatedAt: time.Unix(0, chunk.Time).In(time.UTC).Unix(),
|
||||
@@ -486,7 +487,7 @@ func (l *Log) SearchEvents(fromUTC, toUTC time.Time, namespace string, eventType
|
||||
|
||||
start := time.Now()
|
||||
docSnaps, err := modifyquery(l.svc.Collection(l.CollectionName).
|
||||
Where(eventNamespaceDocProperty, "==", defaults.Namespace).
|
||||
Where(eventNamespaceDocProperty, "==", apidefaults.Namespace).
|
||||
Where(createdAtDocProperty, ">=", fromUTC.Unix()).
|
||||
Where(createdAtDocProperty, "<=", toUTC.Unix()).
|
||||
OrderBy(createdAtDocProperty, firestore.Asc)).
|
||||
@@ -553,7 +554,7 @@ func (l *Log) SearchSessionEvents(fromUTC time.Time, toUTC time.Time, limit int,
|
||||
events.SessionStartEvent,
|
||||
events.SessionEndEvent,
|
||||
}
|
||||
return l.SearchEvents(fromUTC, toUTC, defaults.Namespace, query, limit, startKey)
|
||||
return l.SearchEvents(fromUTC, toUTC, apidefaults.Namespace, query, limit, startKey)
|
||||
}
|
||||
|
||||
// WaitForDelivery waits for resources to be released and outstanding requests to
|
||||
|
||||
@@ -22,6 +22,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/session"
|
||||
@@ -100,7 +101,7 @@ func (cfg *ForwardRecorderConfig) CheckAndSetDefaults() error {
|
||||
return trace.BadParameter("missing parameter DataDir")
|
||||
}
|
||||
if cfg.Namespace == "" {
|
||||
cfg.Namespace = defaults.Namespace
|
||||
cfg.Namespace = apidefaults.Namespace
|
||||
}
|
||||
if cfg.ForwardTo == nil {
|
||||
cfg.ForwardTo = &DiscardAuditLog{}
|
||||
|
||||
@@ -26,8 +26,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/fixtures"
|
||||
"github.com/gravitational/teleport/lib/session"
|
||||
@@ -104,7 +104,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
|
||||
var checkpoint string
|
||||
|
||||
err = utils.RetryStaticFor(time.Minute*5, time.Second*5, func() error {
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 100, checkpoint)
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 100, checkpoint)
|
||||
return err
|
||||
})
|
||||
c.Assert(err, check.IsNil)
|
||||
@@ -112,7 +112,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
|
||||
c.Assert(checkpoint, check.Equals, "")
|
||||
|
||||
for _, name := range names {
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 1, checkpoint)
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 1, checkpoint)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(arr, check.HasLen, 1)
|
||||
event, ok := arr[0].(*apievents.UserLogin)
|
||||
@@ -120,7 +120,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
|
||||
c.Assert(name, check.Equals, event.User)
|
||||
}
|
||||
if checkpoint != "" {
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 1, checkpoint)
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 1, checkpoint)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(arr, check.HasLen, 0)
|
||||
}
|
||||
@@ -129,7 +129,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
|
||||
for _, i := range []int{0, 2} {
|
||||
nameA := names[i]
|
||||
nameB := names[i+1]
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 2, checkpoint)
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 2, checkpoint)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(arr, check.HasLen, 2)
|
||||
eventA, okA := arr[0].(*apievents.UserLogin)
|
||||
@@ -140,7 +140,7 @@ func (s *EventsSuite) EventPagination(c *check.C) {
|
||||
c.Assert(nameB, check.Equals, eventB.User)
|
||||
}
|
||||
if checkpoint != "" {
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, defaults.Namespace, nil, 1, checkpoint)
|
||||
arr, checkpoint, err = s.Log.SearchEvents(baseTime, toTime, apidefaults.Namespace, nil, 1, checkpoint)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(arr, check.HasLen, 0)
|
||||
}
|
||||
@@ -166,7 +166,7 @@ func (s *EventsSuite) SessionEventsCRUD(c *check.C) {
|
||||
var history []apievents.AuditEvent
|
||||
|
||||
err = utils.RetryStaticFor(time.Minute*5, time.Second*5, func() error {
|
||||
history, _, err = s.Log.SearchEvents(s.Clock.Now().Add(-1*time.Hour), s.Clock.Now().Add(time.Hour), defaults.Namespace, nil, 100, "")
|
||||
history, _, err = s.Log.SearchEvents(s.Clock.Now().Add(-1*time.Hour), s.Clock.Now().Add(time.Hour), apidefaults.Namespace, nil, 100, "")
|
||||
return err
|
||||
})
|
||||
c.Assert(err, check.IsNil)
|
||||
@@ -175,7 +175,7 @@ func (s *EventsSuite) SessionEventsCRUD(c *check.C) {
|
||||
// start the session and emit data stream to it and wrap it up
|
||||
sessionID := session.NewID()
|
||||
err = s.Log.PostSessionSlice(events.SessionSlice{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
SessionID: string(sessionID),
|
||||
Chunks: []*events.SessionChunk{
|
||||
// start the seession
|
||||
@@ -198,7 +198,7 @@ func (s *EventsSuite) SessionEventsCRUD(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
// read the session event
|
||||
historyEvents, err := s.Log.GetSessionEvents(defaults.Namespace, sessionID, 0, false)
|
||||
historyEvents, err := s.Log.GetSessionEvents(apidefaults.Namespace, sessionID, 0, false)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(historyEvents, check.HasLen, 2)
|
||||
c.Assert(historyEvents[0].GetString(events.EventType), check.Equals, events.SessionStartEvent)
|
||||
|
||||
@@ -32,8 +32,10 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
@@ -159,7 +161,7 @@ func (f *ForwarderConfig) CheckAndSetDefaults() error {
|
||||
return trace.BadParameter("missing parameter ServerID")
|
||||
}
|
||||
if f.Namespace == "" {
|
||||
f.Namespace = defaults.Namespace
|
||||
f.Namespace = apidefaults.Namespace
|
||||
}
|
||||
if f.Context == nil {
|
||||
f.Context = context.TODO()
|
||||
@@ -493,7 +495,7 @@ func (f *Forwarder) setupContext(ctx auth.Context, req *http.Request, isRemoteUs
|
||||
// any user to access common API methods, e.g. discovery methods
|
||||
// required for initial client usage, without it, restricted user's
|
||||
// kubectl clients will not work
|
||||
if !utils.SliceContainsStr(kubeGroups, teleport.KubeSystemAuthenticated) {
|
||||
if !apiutils.SliceContainsStr(kubeGroups, teleport.KubeSystemAuthenticated) {
|
||||
kubeGroups = append(kubeGroups, teleport.KubeSystemAuthenticated)
|
||||
}
|
||||
|
||||
@@ -661,7 +663,7 @@ func (f *Forwarder) newStreamer(ctx *authContext) (events.Streamer, error) {
|
||||
f.log.Debugf("Using async streamer for session.")
|
||||
dir := filepath.Join(
|
||||
f.cfg.DataDir, teleport.LogsDir, teleport.ComponentUpload,
|
||||
events.StreamingLogsDir, defaults.Namespace,
|
||||
events.StreamingLogsDir, apidefaults.Namespace,
|
||||
)
|
||||
fileStreamer, err := filesessions.NewStreamer(dir)
|
||||
if err != nil {
|
||||
@@ -1138,7 +1140,7 @@ func setupImpersonationHeaders(log log.FieldLogger, ctx authContext, headers htt
|
||||
}
|
||||
}
|
||||
|
||||
impersonateGroups = utils.Deduplicate(impersonateGroups)
|
||||
impersonateGroups = apiutils.Deduplicate(impersonateGroups)
|
||||
|
||||
// By default, if no kubernetes_users is set (which will be a majority),
|
||||
// user will impersonate themselves, which is the backwards-compatible behavior.
|
||||
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
"sync"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -118,7 +119,7 @@ func NewTLSServer(cfg TLSServerConfig) (*TLSServer, error) {
|
||||
TLSServerConfig: cfg,
|
||||
Server: &http.Server{
|
||||
Handler: limiter,
|
||||
ReadHeaderTimeout: defaults.DefaultDialTimeout * 2,
|
||||
ReadHeaderTimeout: apidefaults.DefaultDialTimeout * 2,
|
||||
},
|
||||
}
|
||||
server.TLS.GetConfigForClient = server.GetConfigForClient
|
||||
@@ -137,9 +138,9 @@ func NewTLSServer(cfg TLSServerConfig) (*TLSServer, error) {
|
||||
Component: cfg.Component,
|
||||
Announcer: cfg.AuthClient,
|
||||
GetServerInfo: server.GetServerInfo,
|
||||
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/10),
|
||||
ServerTTL: defaults.ServerAnnounceTTL,
|
||||
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/10),
|
||||
ServerTTL: apidefaults.ServerAnnounceTTL,
|
||||
CheckPeriod: defaults.HeartbeatCheckPeriod,
|
||||
Clock: cfg.Clock,
|
||||
OnHeartbeat: cfg.OnHeartbeat,
|
||||
@@ -282,6 +283,6 @@ func (t *TLSServer) GetServerInfo() (types.Resource, error) {
|
||||
KubernetesClusters: t.fwd.kubeClusters(),
|
||||
},
|
||||
}
|
||||
srv.SetExpiry(t.Clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
|
||||
srv.SetExpiry(t.Clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
|
||||
return srv, nil
|
||||
}
|
||||
|
||||
@@ -22,7 +22,7 @@ import (
|
||||
"sort"
|
||||
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/trace"
|
||||
|
||||
"k8s.io/client-go/kubernetes"
|
||||
@@ -180,7 +180,7 @@ func CheckOrSetKubeCluster(ctx context.Context, p KubeServicesPresence, kubeClus
|
||||
return "", trace.Wrap(err)
|
||||
}
|
||||
if kubeClusterName != "" {
|
||||
if !utils.SliceContainsStr(kubeClusterNames, kubeClusterName) {
|
||||
if !apiutils.SliceContainsStr(kubeClusterNames, kubeClusterName) {
|
||||
return "", trace.BadParameter("kubernetes cluster %q is not registered in this teleport cluster; you can list registered kubernetes clusters using 'tsh kube ls'", kubeClusterName)
|
||||
}
|
||||
return kubeClusterName, nil
|
||||
@@ -191,7 +191,7 @@ func CheckOrSetKubeCluster(ctx context.Context, p KubeServicesPresence, kubeClus
|
||||
if len(kubeClusterNames) == 0 {
|
||||
return "", trace.NotFound("no kubernetes clusters registered")
|
||||
}
|
||||
if utils.SliceContainsStr(kubeClusterNames, teleportClusterName) {
|
||||
if apiutils.SliceContainsStr(kubeClusterNames, teleportClusterName) {
|
||||
return teleportClusterName, nil
|
||||
}
|
||||
return kubeClusterNames[0], nil
|
||||
|
||||
@@ -29,10 +29,10 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apisshutils "github.com/gravitational/teleport/api/utils/sshutils"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/reversetunnel/track"
|
||||
"github.com/gravitational/teleport/lib/sshutils"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
@@ -255,7 +255,7 @@ func (a *Agent) connect() (conn *ssh.Client, err error) {
|
||||
for _, authMethod := range a.authMethods {
|
||||
// Create a dialer (that respects HTTP proxies) and connect to remote host.
|
||||
dialer := proxy.DialerFromEnvironment(a.Addr.Addr)
|
||||
pconn, err := dialer.DialTimeout(a.Addr.AddrNetwork, a.Addr.Addr, defaults.DefaultDialTimeout)
|
||||
pconn, err := dialer.DialTimeout(a.Addr.AddrNetwork, a.Addr.Addr, apidefaults.DefaultDialTimeout)
|
||||
if err != nil {
|
||||
a.log.Debugf("Dial to %v failed: %v.", a.Addr.Addr, err)
|
||||
continue
|
||||
@@ -267,7 +267,7 @@ func (a *Agent) connect() (conn *ssh.Client, err error) {
|
||||
User: a.Username,
|
||||
Auth: []ssh.AuthMethod{authMethod},
|
||||
HostKeyCallback: a.checkHostSignature,
|
||||
Timeout: defaults.DefaultDialTimeout,
|
||||
Timeout: apidefaults.DefaultDialTimeout,
|
||||
})
|
||||
if err != nil {
|
||||
a.log.Debugf("Failed to create client to %v: %v.", a.Addr.Addr, err)
|
||||
|
||||
@@ -25,10 +25,10 @@ import (
|
||||
"golang.org/x/crypto/ssh"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/api/utils/sshutils"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/srv/forward"
|
||||
"github.com/gravitational/teleport/lib/utils/proxy"
|
||||
@@ -154,7 +154,7 @@ func (s *localSite) DialAuthServer() (conn net.Conn, err error) {
|
||||
|
||||
// try and dial to one of them, as soon as we are successful, return the net.Conn
|
||||
for _, authServer := range authServers {
|
||||
conn, err = net.DialTimeout("tcp", authServer.GetAddr(), defaults.DefaultDialTimeout)
|
||||
conn, err = net.DialTimeout("tcp", authServer.GetAddr(), apidefaults.DefaultDialTimeout)
|
||||
if err == nil {
|
||||
return conn, nil
|
||||
}
|
||||
@@ -316,7 +316,7 @@ func (s *localSite) getConn(params DialParams) (conn net.Conn, useTunnel bool, e
|
||||
|
||||
// If no tunnel connection was found, dial to the target host.
|
||||
dialer := proxy.DialerFromEnvironment(params.To.String())
|
||||
conn, directErr := dialer.DialTimeout(params.To.Network(), params.To.String(), defaults.DefaultDialTimeout)
|
||||
conn, directErr := dialer.DialTimeout(params.To.Network(), params.To.String(), apidefaults.DefaultDialTimeout)
|
||||
if directErr != nil {
|
||||
s.log.WithError(directErr).WithField("address", params.To.String()).Debug("Error occurred while dialing directly.")
|
||||
aggregateErr := trace.NewAggregate(tunnelErr, directErr)
|
||||
|
||||
@@ -114,7 +114,7 @@ func (s *remoteSite) getRemoteClient() (auth.ClientI, bool, error) {
|
||||
// authority to verify)
|
||||
tlsConfig.ServerName = auth.EncodeClusterName(s.srv.ClusterName)
|
||||
clt, err := auth.NewClient(client.Config{
|
||||
Dialer: auth.ContextDialerFunc(s.authServerContextDialer),
|
||||
Dialer: client.ContextDialerFunc(s.authServerContextDialer),
|
||||
Credentials: []client.Credentials{
|
||||
client.LoadTLS(tlsConfig),
|
||||
},
|
||||
|
||||
@@ -27,10 +27,10 @@ import (
|
||||
"golang.org/x/crypto/ssh"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/api/utils/sshutils"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
"github.com/gravitational/teleport/lib/utils/proxy"
|
||||
|
||||
@@ -134,7 +134,7 @@ func (p *transport) start() {
|
||||
if req == nil {
|
||||
return
|
||||
}
|
||||
case <-time.After(defaults.DefaultDialTimeout):
|
||||
case <-time.After(apidefaults.DefaultDialTimeout):
|
||||
p.log.Warnf("Transport request failed: timed out waiting for request.")
|
||||
return
|
||||
}
|
||||
|
||||
+2
-1
@@ -21,6 +21,7 @@ import (
|
||||
"net"
|
||||
"strings"
|
||||
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/reversetunnel"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
"github.com/gravitational/teleport/lib/web/app"
|
||||
@@ -53,7 +54,7 @@ func (h *hostPolicyChecker) checkHost(ctx context.Context, host string) error {
|
||||
host, strings.Join(h.dnsNames, ","))
|
||||
}
|
||||
|
||||
if utils.SliceContainsStr(h.dnsNames, host) {
|
||||
if apiutils.SliceContainsStr(h.dnsNames, host) {
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
+2
-1
@@ -33,6 +33,7 @@ import (
|
||||
"k8s.io/apimachinery/pkg/util/validation"
|
||||
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/lite"
|
||||
@@ -627,7 +628,7 @@ func (d *Database) Check() error {
|
||||
if errs := validation.IsDNS1035Label(d.Name); len(errs) > 0 {
|
||||
return trace.BadParameter("invalid database %q name: %v", d.Name, errs)
|
||||
}
|
||||
if !utils.SliceContainsStr(defaults.DatabaseProtocols, d.Protocol) {
|
||||
if !apiutils.SliceContainsStr(defaults.DatabaseProtocols, d.Protocol) {
|
||||
return trace.BadParameter("unsupported database %q protocol %q, supported are: %v",
|
||||
d.Name, d.Protocol, defaults.DatabaseProtocols)
|
||||
}
|
||||
|
||||
@@ -21,10 +21,10 @@ import (
|
||||
"net/http"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/cache"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
kubeproxy "github.com/gravitational/teleport/lib/kube/proxy"
|
||||
"github.com/gravitational/teleport/lib/labels"
|
||||
@@ -208,7 +208,7 @@ func (process *TeleportProcess) initKubernetesService(log *logrus.Entry, conn *C
|
||||
|
||||
kubeServer, err := kubeproxy.NewTLSServer(kubeproxy.TLSServerConfig{
|
||||
ForwarderConfig: kubeproxy.ForwarderConfig{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Keygen: cfg.Keygen,
|
||||
ClusterName: teleportClusterName,
|
||||
Authz: authorizer,
|
||||
|
||||
+14
-13
@@ -50,6 +50,7 @@ import (
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
"github.com/gravitational/teleport/api/client/webclient"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
@@ -1353,7 +1354,7 @@ func (process *TeleportProcess) initAuthService() error {
|
||||
Kind: types.KindAuthServer,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Name: process.Config.HostUUID,
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
@@ -1371,13 +1372,13 @@ func (process *TeleportProcess) initAuthService() error {
|
||||
} else {
|
||||
srv.Spec.Rotation = state.Spec.Rotation
|
||||
}
|
||||
srv.SetExpiry(process.Clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
|
||||
srv.SetExpiry(process.Clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
|
||||
return &srv, nil
|
||||
},
|
||||
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/10),
|
||||
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/10),
|
||||
CheckPeriod: defaults.HeartbeatCheckPeriod,
|
||||
ServerTTL: defaults.ServerAnnounceTTL,
|
||||
ServerTTL: apidefaults.ServerAnnounceTTL,
|
||||
OnHeartbeat: func(err error) {
|
||||
if err != nil {
|
||||
process.BroadcastEvent(Event{Name: TeleportDegradedEvent, Payload: teleport.ComponentAuth})
|
||||
@@ -1915,11 +1916,11 @@ func (process *TeleportProcess) initUploaderService(accessPoint auth.AccessPoint
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
// prepare dirs for uploader
|
||||
streamingDir := []string{process.Config.DataDir, teleport.LogsDir, teleport.ComponentUpload, events.StreamingLogsDir, defaults.Namespace}
|
||||
streamingDir := []string{process.Config.DataDir, teleport.LogsDir, teleport.ComponentUpload, events.StreamingLogsDir, apidefaults.Namespace}
|
||||
paths := [][]string{
|
||||
// DELETE IN (5.1.0)
|
||||
// this directory will no longer be used after migration to 5.1.0
|
||||
{process.Config.DataDir, teleport.LogsDir, teleport.ComponentUpload, events.SessionLogsDir, defaults.Namespace},
|
||||
{process.Config.DataDir, teleport.LogsDir, teleport.ComponentUpload, events.SessionLogsDir, apidefaults.Namespace},
|
||||
// This directory will remain to be used after migration to 5.1.0
|
||||
streamingDir,
|
||||
}
|
||||
@@ -1949,7 +1950,7 @@ func (process *TeleportProcess) initUploaderService(accessPoint auth.AccessPoint
|
||||
// see below
|
||||
uploader, err := events.NewUploader(events.UploaderConfig{
|
||||
DataDir: filepath.Join(process.Config.DataDir, teleport.LogsDir),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
ServerID: teleport.ComponentUpload,
|
||||
AuditLog: auditLog,
|
||||
EventsC: process.Config.UploadEventsC,
|
||||
@@ -2080,7 +2081,7 @@ func (process *TeleportProcess) initDiagnosticService() error {
|
||||
|
||||
server := &http.Server{
|
||||
Handler: mux,
|
||||
ReadHeaderTimeout: defaults.DefaultDialTimeout,
|
||||
ReadHeaderTimeout: apidefaults.DefaultDialTimeout,
|
||||
ErrorLog: utils.NewStdlogger(log.Error, teleport.ComponentDiagnostic),
|
||||
}
|
||||
|
||||
@@ -2653,7 +2654,7 @@ func (process *TeleportProcess) initProxyEndpoint(conn *Connector) error {
|
||||
}
|
||||
webServer = &http.Server{
|
||||
Handler: proxyLimiter,
|
||||
ReadHeaderTimeout: defaults.DefaultDialTimeout,
|
||||
ReadHeaderTimeout: apidefaults.DefaultDialTimeout,
|
||||
ErrorLog: utils.NewStdlogger(log.Error, teleport.ComponentProxy),
|
||||
}
|
||||
process.RegisterCriticalFunc("proxy.web", func() error {
|
||||
@@ -2685,7 +2686,7 @@ func (process *TeleportProcess) initProxyEndpoint(conn *Connector) error {
|
||||
regular.SetCiphers(cfg.Ciphers),
|
||||
regular.SetKEXAlgorithms(cfg.KEXAlgorithms),
|
||||
regular.SetMACAlgorithms(cfg.MACAlgorithms),
|
||||
regular.SetNamespace(defaults.Namespace),
|
||||
regular.SetNamespace(apidefaults.Namespace),
|
||||
regular.SetRotationGetter(process.getRotation),
|
||||
regular.SetFIPS(cfg.FIPS),
|
||||
regular.SetOnHeartbeat(func(err error) {
|
||||
@@ -2758,7 +2759,7 @@ func (process *TeleportProcess) initProxyEndpoint(conn *Connector) error {
|
||||
}
|
||||
kubeServer, err = kubeproxy.NewTLSServer(kubeproxy.TLSServerConfig{
|
||||
ForwarderConfig: kubeproxy.ForwarderConfig{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Keygen: cfg.Keygen,
|
||||
ClusterName: clusterName,
|
||||
ReverseTunnelSrv: tsrv,
|
||||
@@ -3068,7 +3069,7 @@ func (process *TeleportProcess) initApps() {
|
||||
Kind: types.KindAppServer,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Name: process.Config.HostUUID,
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
|
||||
@@ -23,6 +23,7 @@ import (
|
||||
"github.com/google/go-cmp/cmp"
|
||||
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
"github.com/gravitational/teleport/lib/utils/parse"
|
||||
|
||||
@@ -256,7 +257,7 @@ func ApplyAccessReview(req types.AccessRequest, rev types.AccessReview, author t
|
||||
}
|
||||
|
||||
// role lists must be deduplicated and sorted
|
||||
rev.Roles = utils.Deduplicate(rev.Roles)
|
||||
rev.Roles = apiutils.Deduplicate(rev.Roles)
|
||||
sort.Strings(rev.Roles)
|
||||
|
||||
// basic compatibility/sanity checks
|
||||
@@ -931,7 +932,7 @@ func (m *RequestValidator) Validate(req types.AccessRequest) error {
|
||||
// if no suggested reviewers were provided by the user then
|
||||
// use the defaults suggested by the user's static roles.
|
||||
if len(req.GetSuggestedReviewers()) == 0 {
|
||||
req.SetSuggestedReviewers(utils.Deduplicate(m.SuggestedReviewers))
|
||||
req.SetSuggestedReviewers(apiutils.Deduplicate(m.SuggestedReviewers))
|
||||
}
|
||||
}
|
||||
return nil
|
||||
@@ -949,7 +950,7 @@ func (m *RequestValidator) GetRequestableRoles() ([]string, error) {
|
||||
|
||||
var expanded []string
|
||||
for _, role := range allRoles {
|
||||
if n := role.GetName(); !utils.SliceContainsStr(m.user.GetRoles(), n) && m.CanRequestRole(n) {
|
||||
if n := role.GetName(); !apiutils.SliceContainsStr(m.user.GetRoles(), n) && m.CanRequestRole(n) {
|
||||
// user does not currently hold this role, and is allowed to request it.
|
||||
expanded = append(expanded, n)
|
||||
}
|
||||
@@ -1119,7 +1120,7 @@ func (m *RequestValidator) SystemAnnotations() map[string][]string {
|
||||
for k, va := range m.Annotations.Allow {
|
||||
var filtered []string
|
||||
for _, v := range va {
|
||||
if !utils.SliceContainsStr(m.Annotations.Deny[k], v) {
|
||||
if !apiutils.SliceContainsStr(m.Annotations.Deny[k], v) {
|
||||
filtered = append(filtered, v)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -19,8 +19,8 @@ package services
|
||||
import (
|
||||
"github.com/gravitational/trace"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
)
|
||||
|
||||
@@ -32,7 +32,7 @@ func DefaultClusterConfig() types.ClusterConfig {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: types.MetaNameClusterConfig,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.ClusterConfigSpecV3{},
|
||||
}
|
||||
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
"context"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth/u2f"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -306,7 +307,7 @@ func (r *GithubAuthRequest) Check() error {
|
||||
if err != nil {
|
||||
return trace.BadParameter("bad PublicKey: %v", err)
|
||||
}
|
||||
if (r.CertTTL > defaults.MaxCertDuration) || (r.CertTTL < defaults.MinCertDuration) {
|
||||
if (r.CertTTL > apidefaults.MaxCertDuration) || (r.CertTTL < defaults.MinCertDuration) {
|
||||
return trace.BadParameter("wrong CertTTL")
|
||||
}
|
||||
}
|
||||
@@ -374,7 +375,7 @@ func (i *OIDCAuthRequest) Check() error {
|
||||
if err != nil {
|
||||
return trace.BadParameter("PublicKey: bad key: %v", err)
|
||||
}
|
||||
if (i.CertTTL > defaults.MaxCertDuration) || (i.CertTTL < defaults.MinCertDuration) {
|
||||
if (i.CertTTL > apidefaults.MaxCertDuration) || (i.CertTTL < defaults.MinCertDuration) {
|
||||
return trace.BadParameter("CertTTL: wrong certificate TTL")
|
||||
}
|
||||
}
|
||||
@@ -439,7 +440,7 @@ func (i *SAMLAuthRequest) Check() error {
|
||||
if err != nil {
|
||||
return trace.BadParameter("PublicKey: bad key: %v", err)
|
||||
}
|
||||
if (i.CertTTL > defaults.MaxCertDuration) || (i.CertTTL < defaults.MinCertDuration) {
|
||||
if (i.CertTTL > apidefaults.MaxCertDuration) || (i.CertTTL < defaults.MinCertDuration) {
|
||||
return trace.BadParameter("CertTTL: wrong certificate TTL")
|
||||
}
|
||||
}
|
||||
|
||||
@@ -20,8 +20,8 @@ import (
|
||||
"fmt"
|
||||
"testing"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
"github.com/stretchr/testify/require"
|
||||
@@ -31,18 +31,18 @@ func TestCheckImpersonate(t *testing.T) {
|
||||
noLabelsRole := &types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "no-labels",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
}
|
||||
wildcardRole := &types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "wildcard",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
@@ -56,7 +56,7 @@ func TestCheckImpersonate(t *testing.T) {
|
||||
wildcardDenyRole := &types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "wildcard-deny-user",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Deny: types.RoleConditions{
|
||||
@@ -78,7 +78,7 @@ func TestCheckImpersonate(t *testing.T) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: name,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: props.labels,
|
||||
},
|
||||
Spec: types.UserSpecV2{
|
||||
@@ -156,7 +156,7 @@ func TestCheckImpersonate(t *testing.T) {
|
||||
&types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "limited",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
@@ -199,7 +199,7 @@ func TestCheckImpersonate(t *testing.T) {
|
||||
&types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "team-impersonator",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
@@ -222,7 +222,7 @@ func TestCheckImpersonate(t *testing.T) {
|
||||
&types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "dev",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{
|
||||
"team": "dev",
|
||||
},
|
||||
@@ -242,7 +242,7 @@ func TestCheckImpersonate(t *testing.T) {
|
||||
&types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "dev",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{
|
||||
"team": "dev",
|
||||
},
|
||||
|
||||
@@ -23,6 +23,7 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
@@ -91,7 +92,7 @@ func (s *DynamicAccessService) SetAccessRequestState(ctx context.Context, params
|
||||
req.SetResolveAnnotations(params.Annotations)
|
||||
if len(params.Roles) > 0 {
|
||||
for _, role := range params.Roles {
|
||||
if !utils.SliceContainsStr(req.GetRoles(), role) {
|
||||
if !apiutils.SliceContainsStr(req.GetRoles(), role) {
|
||||
return nil, trace.BadParameter("role %q not in original request, overrides must be a subset of original role list", role)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
"bytes"
|
||||
"context"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -281,7 +282,7 @@ func (p *certAuthorityParser) parse(event backend.Event) (types.Resource, error)
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: name,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
}, nil
|
||||
case types.OpPut:
|
||||
@@ -696,7 +697,7 @@ func (p *userParser) parse(event backend.Event) (types.Resource, error) {
|
||||
|
||||
func newNodeParser() *nodeParser {
|
||||
return &nodeParser{
|
||||
baseParser: newBaseParser(backend.Key(nodesPrefix, defaults.Namespace)),
|
||||
baseParser: newBaseParser(backend.Key(nodesPrefix, apidefaults.Namespace)),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -759,7 +760,7 @@ func (p *tunnelConnectionParser) parse(event backend.Event) (types.Resource, err
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: name,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
}, nil
|
||||
case types.OpPut:
|
||||
@@ -806,7 +807,7 @@ func (p *reverseTunnelParser) parse(event backend.Event) (types.Resource, error)
|
||||
|
||||
func newAppServerParser() *appServerParser {
|
||||
return &appServerParser{
|
||||
baseParser: newBaseParser(backend.Key(appsPrefix, serversPrefix, defaults.Namespace)),
|
||||
baseParser: newBaseParser(backend.Key(appsPrefix, serversPrefix, apidefaults.Namespace)),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -907,7 +908,7 @@ func (p *kubeServiceParser) parse(event backend.Event) (types.Resource, error) {
|
||||
|
||||
func newDatabaseServerParser() *databaseServerParser {
|
||||
return &databaseServerParser{
|
||||
baseParser: newBaseParser(backend.Key(dbServersPrefix, defaults.Namespace)),
|
||||
baseParser: newBaseParser(backend.Key(dbServersPrefix, apidefaults.Namespace)),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -927,7 +928,7 @@ func (p *databaseServerParser) parse(event backend.Event) (types.Resource, error
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: name,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Description: hostID, // Pass host ID via description field for the cache.
|
||||
},
|
||||
}, nil
|
||||
@@ -1007,7 +1008,7 @@ func resourceHeader(event backend.Event, kind, version string, offset int) (type
|
||||
Version: version,
|
||||
Metadata: types.Metadata{
|
||||
Name: string(name),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
}, nil
|
||||
}
|
||||
@@ -1023,7 +1024,7 @@ func resourceHeaderWithTemplate(event backend.Event, hdr types.ResourceHeader, o
|
||||
Version: hdr.Version,
|
||||
Metadata: types.Metadata{
|
||||
Name: string(name),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
}, nil
|
||||
}
|
||||
|
||||
@@ -23,11 +23,11 @@ import (
|
||||
"os"
|
||||
"testing"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/lite"
|
||||
"github.com/gravitational/teleport/lib/backend/memory"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -108,7 +108,7 @@ func insertNodes(ctx context.Context, t assert.TestingT, svc services.Presence,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: name,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: labels,
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
@@ -126,7 +126,7 @@ func benchmarkGetNodes(ctx context.Context, b *testing.B, svc services.Presence,
|
||||
var nodes []types.Server
|
||||
var err error
|
||||
for i := 0; i < b.N; i++ {
|
||||
nodes, err = svc.GetNodes(ctx, defaults.Namespace, opts...)
|
||||
nodes, err = svc.GetNodes(ctx, apidefaults.Namespace, opts...)
|
||||
assert.NoError(b, err)
|
||||
}
|
||||
// do *something* with the loop result. probably unnecessary since the loop
|
||||
|
||||
@@ -26,6 +26,7 @@ import (
|
||||
"github.com/stretchr/testify/require"
|
||||
"gopkg.in/check.v1"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/lite"
|
||||
@@ -127,7 +128,7 @@ func TestDatabaseServersCRUD(t *testing.T) {
|
||||
})
|
||||
|
||||
// Initially expect not to be returned any servers.
|
||||
out, err := presence.GetDatabaseServers(ctx, defaults.Namespace)
|
||||
out, err := presence.GetDatabaseServers(ctx, apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, 0, len(out))
|
||||
|
||||
@@ -158,7 +159,7 @@ func TestDatabaseServersCRUD(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// Now expect no servers to be returned.
|
||||
out, err = presence.GetDatabaseServers(ctx, defaults.Namespace)
|
||||
out, err = presence.GetDatabaseServers(ctx, apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, 0, len(out))
|
||||
|
||||
@@ -185,7 +186,7 @@ func TestDatabaseServersCRUD(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// Now expect no servers to be returned.
|
||||
out, err = presence.GetDatabaseServers(ctx, defaults.Namespace)
|
||||
out, err = presence.GetDatabaseServers(ctx, apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, 0, len(out))
|
||||
}
|
||||
|
||||
@@ -27,11 +27,11 @@ import (
|
||||
|
||||
"golang.org/x/crypto/bcrypt"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth/u2f"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/lite"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/services/suite"
|
||||
|
||||
@@ -184,7 +184,7 @@ func (r *ResourceSuite) TestGithubConnectorResource(c *check.C) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "github",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.GithubConnectorSpecV3{
|
||||
ClientID: "aaa",
|
||||
@@ -250,7 +250,7 @@ func newUserTestCase(c *check.C, name string, roles []string, withSecrets bool,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: name,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Expires: &expires,
|
||||
},
|
||||
Spec: types.UserSpecV2{
|
||||
|
||||
+12
-12
@@ -20,8 +20,8 @@ import (
|
||||
"github.com/gravitational/teleport"
|
||||
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
|
||||
"github.com/pborman/uuid"
|
||||
)
|
||||
@@ -34,19 +34,19 @@ func NewPresetEditorRole() types.Role {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: teleport.PresetEditorRoleName,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Description: "Edit cluster configuration",
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ForwardAgent: types.NewBool(true),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
types.NewRule(types.KindUser, RW()),
|
||||
types.NewRule(types.KindRole, RW()),
|
||||
@@ -73,19 +73,19 @@ func NewPresetAccessRole() types.Role {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: teleport.PresetAccessRoleName,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Description: "Access cluster resources",
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ForwardAgent: types.NewBool(true),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
@@ -113,16 +113,16 @@ func NewPresetAuditorRole() types.Role {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: teleport.PresetAuditorRoleName,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Description: "Review cluster events and replay sessions",
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
types.NewRule(types.KindSession, RO()),
|
||||
types.NewRule(types.KindEvent, RO()),
|
||||
|
||||
+35
-34
@@ -28,9 +28,10 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/api/types/wrappers"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/modules"
|
||||
"github.com/gravitational/teleport/lib/tlsca"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
@@ -115,18 +116,18 @@ func NewAdminRole() types.Role {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: teleport.AdminRoleName,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ForwardAgent: types.NewBool(true),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
@@ -151,7 +152,7 @@ func NewImplicitRole() types.Role {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: constants.DefaultImplicitRole,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -162,7 +163,7 @@ func NewImplicitRole() types.Role {
|
||||
PortForwarding: types.NewBoolOption(false),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: types.CopyRulesSlice(DefaultImplicitRules),
|
||||
},
|
||||
},
|
||||
@@ -176,18 +177,18 @@ func RoleForUser(u types.User) types.Role {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: RoleNameForUser(u.GetName()),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ForwardAgent: types.NewBool(true),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
@@ -216,19 +217,19 @@ func NewDowngradedOSSAdminRole() types.Role {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: teleport.AdminRoleName,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{teleport.OSSMigratedV6: types.True},
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ForwardAgent: types.NewBool(true),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
@@ -255,18 +256,18 @@ func NewOSSGithubRole(logins []string, kubeUsers []string, kubeGroups []string)
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "github-" + uuid.New(),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ForwardAgent: types.NewBool(true),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
@@ -292,14 +293,14 @@ func RoleForCertAuthority(ca types.CertAuthority) types.Role {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: RoleNameForCertAuthority(ca.GetClusterName()),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
NodeLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
@@ -422,7 +423,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
|
||||
}
|
||||
}
|
||||
|
||||
r.SetLogins(condition, utils.Deduplicate(outLogins))
|
||||
r.SetLogins(condition, apiutils.Deduplicate(outLogins))
|
||||
|
||||
// apply templates to kubernetes groups
|
||||
inKubeGroups := r.GetKubeGroups(condition)
|
||||
@@ -437,7 +438,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
|
||||
}
|
||||
outKubeGroups = append(outKubeGroups, variableValues...)
|
||||
}
|
||||
r.SetKubeGroups(condition, utils.Deduplicate(outKubeGroups))
|
||||
r.SetKubeGroups(condition, apiutils.Deduplicate(outKubeGroups))
|
||||
|
||||
// apply templates to kubernetes users
|
||||
inKubeUsers := r.GetKubeUsers(condition)
|
||||
@@ -452,7 +453,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
|
||||
}
|
||||
outKubeUsers = append(outKubeUsers, variableValues...)
|
||||
}
|
||||
r.SetKubeUsers(condition, utils.Deduplicate(outKubeUsers))
|
||||
r.SetKubeUsers(condition, apiutils.Deduplicate(outKubeUsers))
|
||||
|
||||
// apply templates to database names
|
||||
inDbNames := r.GetDatabaseNames(condition)
|
||||
@@ -467,7 +468,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
|
||||
}
|
||||
outDbNames = append(outDbNames, variableValues...)
|
||||
}
|
||||
r.SetDatabaseNames(condition, utils.Deduplicate(outDbNames))
|
||||
r.SetDatabaseNames(condition, apiutils.Deduplicate(outDbNames))
|
||||
|
||||
// apply templates to database users
|
||||
inDbUsers := r.GetDatabaseUsers(condition)
|
||||
@@ -482,7 +483,7 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
|
||||
}
|
||||
outDbUsers = append(outDbUsers, variableValues...)
|
||||
}
|
||||
r.SetDatabaseUsers(condition, utils.Deduplicate(outDbUsers))
|
||||
r.SetDatabaseUsers(condition, apiutils.Deduplicate(outDbUsers))
|
||||
|
||||
// apply templates to node labels
|
||||
inLabels := r.GetNodeLabels(condition)
|
||||
@@ -537,8 +538,8 @@ func ApplyTraits(r types.Role, traits map[string][]string) types.Role {
|
||||
}
|
||||
outCond.Roles = append(outCond.Roles, variableValues...)
|
||||
}
|
||||
outCond.Users = utils.Deduplicate(outCond.Users)
|
||||
outCond.Roles = utils.Deduplicate(outCond.Roles)
|
||||
outCond.Users = apiutils.Deduplicate(outCond.Users)
|
||||
outCond.Roles = apiutils.Deduplicate(outCond.Roles)
|
||||
outCond.Where = inCond.Where
|
||||
r.SetImpersonateConditions(condition, outCond)
|
||||
}
|
||||
@@ -580,7 +581,7 @@ func applyLabelsTraits(inLabels types.Labels, traits map[string][]string) types.
|
||||
}
|
||||
values = append(values, valVars...)
|
||||
}
|
||||
outLabels[keyVars[0]] = utils.Deduplicate(values)
|
||||
outLabels[keyVars[0]] = apiutils.Deduplicate(values)
|
||||
}
|
||||
return outLabels
|
||||
}
|
||||
@@ -623,7 +624,7 @@ func ApplyValueTraits(val string, traits map[string][]string) ([]string, error)
|
||||
func ruleScore(r *types.Rule) int {
|
||||
score := 0
|
||||
// wildcard rules are less specific
|
||||
if utils.SliceContainsStr(r.Resources, types.Wildcard) {
|
||||
if apiutils.SliceContainsStr(r.Resources, types.Wildcard) {
|
||||
score -= 4
|
||||
} else if len(r.Resources) == 1 {
|
||||
// rules that match specific resource are more specific than
|
||||
@@ -631,7 +632,7 @@ func ruleScore(r *types.Rule) int {
|
||||
score += 2
|
||||
}
|
||||
// rules that have wildcard verbs are less specific
|
||||
if utils.SliceContainsStr(r.Verbs, types.Wildcard) {
|
||||
if apiutils.SliceContainsStr(r.Verbs, types.Wildcard) {
|
||||
score -= 2
|
||||
}
|
||||
// rules that supply 'where' or 'actions' are more specific
|
||||
@@ -1092,7 +1093,7 @@ func MatchLabels(selector types.Labels, target map[string]string) (bool, string,
|
||||
return false, fmt.Sprintf("no key match: '%v'", key), nil
|
||||
}
|
||||
|
||||
if !utils.SliceContainsStr(selectorValues, types.Wildcard) {
|
||||
if !apiutils.SliceContainsStr(selectorValues, types.Wildcard) {
|
||||
result, err := utils.SliceMatchesRegex(targetVal, selectorValues)
|
||||
if err != nil {
|
||||
return false, "", trace.Wrap(err)
|
||||
@@ -1319,7 +1320,7 @@ func (set RoleSet) GetLoginsForTTL(ttl time.Duration) (logins []string, matchedT
|
||||
logins = append(logins, role.GetLogins(Allow)...)
|
||||
}
|
||||
}
|
||||
return utils.Deduplicate(logins), matchedTTL
|
||||
return apiutils.Deduplicate(logins), matchedTTL
|
||||
}
|
||||
|
||||
// CheckAccessToRemoteCluster checks if a role has access to remote cluster. Deny rules are
|
||||
|
||||
+109
-108
@@ -27,13 +27,14 @@ import (
|
||||
"github.com/google/go-cmp/cmp"
|
||||
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
"github.com/gravitational/teleport/api/defaults"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/api/types/wrappers"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/api/utils/sshutils"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/fixtures"
|
||||
"github.com/gravitational/teleport/lib/tlsca"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
"github.com/pborman/uuid"
|
||||
"github.com/stretchr/testify/require"
|
||||
@@ -76,7 +77,7 @@ func TestConnAndSessLimits(t *testing.T) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: fmt.Sprintf("role-%d", i),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -170,24 +171,24 @@ func TestRoleParse(t *testing.T) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "defrole",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
NodeLabels: types.Labels{},
|
||||
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
DatabaseLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -237,7 +238,7 @@ func TestRoleParse(t *testing.T) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{"a-b": "c"},
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
@@ -247,7 +248,7 @@ func TestRoleParse(t *testing.T) {
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ClientIdleTimeout: types.NewDuration(17 * time.Minute),
|
||||
DisconnectExpiredCert: types.NewBool(true),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
NodeLabels: types.Labels{"a": []string{"b"}, "c-d": []string{"e"}},
|
||||
@@ -269,7 +270,7 @@ func TestRoleParse(t *testing.T) {
|
||||
},
|
||||
},
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Logins: []string{"c"},
|
||||
},
|
||||
},
|
||||
@@ -319,7 +320,7 @@ func TestRoleParse(t *testing.T) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -329,7 +330,7 @@ func TestRoleParse(t *testing.T) {
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ClientIdleTimeout: types.NewDuration(0),
|
||||
DisconnectExpiredCert: types.NewBool(false),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
NodeLabels: types.Labels{"a": []string{"b"}},
|
||||
@@ -349,7 +350,7 @@ func TestRoleParse(t *testing.T) {
|
||||
},
|
||||
},
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Logins: []string{"c"},
|
||||
},
|
||||
},
|
||||
@@ -388,7 +389,7 @@ func TestRoleParse(t *testing.T) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -398,7 +399,7 @@ func TestRoleParse(t *testing.T) {
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
ClientIdleTimeout: types.NewDuration(0),
|
||||
DisconnectExpiredCert: types.NewBool(false),
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
NodeLabels: types.Labels{
|
||||
@@ -424,7 +425,7 @@ func TestRoleParse(t *testing.T) {
|
||||
Namespaces: []string{"default"},
|
||||
},
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Logins: []string{"c"},
|
||||
},
|
||||
},
|
||||
@@ -524,7 +525,7 @@ func TestValidateRole(t *testing.T) {
|
||||
err := ValidateRole(&types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: tc.spec,
|
||||
})
|
||||
@@ -569,7 +570,7 @@ func TestCheckAccessToServer(t *testing.T) {
|
||||
serverWorker := &types.ServerV2{
|
||||
Metadata: types.Metadata{
|
||||
Name: "b",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{"role": "worker", "status": "follower"},
|
||||
},
|
||||
}
|
||||
@@ -592,7 +593,7 @@ func TestCheckAccessToServer(t *testing.T) {
|
||||
r := types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -627,7 +628,7 @@ func TestCheckAccessToServer(t *testing.T) {
|
||||
roles: []types.RoleV3{
|
||||
newRole(func(r *types.RoleV3) {
|
||||
r.Spec.Allow.Logins = []string{"admin"}
|
||||
r.Spec.Allow.Namespaces = []string{defaults.Namespace}
|
||||
r.Spec.Allow.Namespaces = []string{apidefaults.Namespace}
|
||||
}),
|
||||
},
|
||||
checks: []check{
|
||||
@@ -876,7 +877,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -902,7 +903,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -911,7 +912,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"admin"},
|
||||
ClusterLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -928,14 +929,14 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.Duration(20 * time.Hour),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -952,7 +953,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -960,21 +961,21 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
ClusterLabels: types.Labels{"role": []string{"worker"}},
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name2",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.Duration(20 * time.Hour),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -991,7 +992,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -1000,7 +1001,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"admin"},
|
||||
ClusterLabels: types.Labels{"role": []string{}},
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -1017,7 +1018,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -1026,14 +1027,14 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"admin"},
|
||||
ClusterLabels: types.Labels{"role": []string{"worker"}},
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name2",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -1059,7 +1060,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
@@ -1068,7 +1069,7 @@ func TestCheckAccessToRemoteCluster(t *testing.T) {
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"admin"},
|
||||
ClusterLabels: types.Labels{"role": []string{"^db(.*)$"}, "status": []string{"follow*"}},
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -1137,11 +1138,11 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
types.NewRule(types.KindSSHSession, []string{types.VerbRead}),
|
||||
},
|
||||
@@ -1150,8 +1151,8 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
},
|
||||
checks: []check{
|
||||
{rule: types.KindSSHSession, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: true},
|
||||
{rule: types.KindSSHSession, verb: types.VerbList, namespace: defaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindSSHSession, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: true},
|
||||
{rule: types.KindSSHSession, verb: types.VerbList, namespace: apidefaults.Namespace, hasAccess: false},
|
||||
},
|
||||
},
|
||||
{
|
||||
@@ -1160,7 +1161,7 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
@@ -1174,11 +1175,11 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name2",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
types.NewRule(types.KindSSHSession, []string{types.VerbCreate, types.VerbRead}),
|
||||
},
|
||||
@@ -1187,10 +1188,10 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
},
|
||||
checks: []check{
|
||||
{rule: types.KindSSHSession, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: true},
|
||||
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: defaults.Namespace, hasAccess: true},
|
||||
{rule: types.KindSSHSession, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: true},
|
||||
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: apidefaults.Namespace, hasAccess: true},
|
||||
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: "system", hasAccess: false},
|
||||
{rule: types.KindRole, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindRole, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: false},
|
||||
},
|
||||
},
|
||||
{
|
||||
@@ -1199,17 +1200,17 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
types.NewRule(types.KindSSHSession, []string{types.VerbCreate}),
|
||||
},
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
types.NewRule(types.KindSSHSession, []string{types.VerbCreate}),
|
||||
},
|
||||
@@ -1218,7 +1219,7 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
},
|
||||
checks: []check{
|
||||
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: defaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindSSHSession, verb: types.VerbCreate, namespace: apidefaults.Namespace, hasAccess: false},
|
||||
},
|
||||
},
|
||||
{
|
||||
@@ -1227,11 +1228,11 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
{
|
||||
Resources: []string{types.KindSession},
|
||||
@@ -1247,8 +1248,8 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
},
|
||||
checks: []check{
|
||||
{rule: types.KindSession, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindSession, verb: types.VerbList, namespace: defaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindSession, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindSession, verb: types.VerbList, namespace: apidefaults.Namespace, hasAccess: false},
|
||||
{
|
||||
context: testContext{
|
||||
buffer: &bytes.Buffer{},
|
||||
@@ -1267,7 +1268,7 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
rule: types.KindSession,
|
||||
verb: types.VerbRead,
|
||||
namespace: defaults.Namespace,
|
||||
namespace: apidefaults.Namespace,
|
||||
hasAccess: true,
|
||||
},
|
||||
{
|
||||
@@ -1285,7 +1286,7 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
rule: types.KindSession,
|
||||
verb: types.VerbRead,
|
||||
namespace: defaults.Namespace,
|
||||
namespace: apidefaults.Namespace,
|
||||
hasAccess: false,
|
||||
},
|
||||
},
|
||||
@@ -1296,11 +1297,11 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
{
|
||||
Resources: []string{types.KindRole},
|
||||
@@ -1316,8 +1317,8 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
},
|
||||
checks: []check{
|
||||
{rule: types.KindRole, verb: types.VerbRead, namespace: defaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindRole, verb: types.VerbList, namespace: defaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindRole, verb: types.VerbRead, namespace: apidefaults.Namespace, hasAccess: false},
|
||||
{rule: types.KindRole, verb: types.VerbList, namespace: apidefaults.Namespace, hasAccess: false},
|
||||
{
|
||||
context: testContext{
|
||||
buffer: &bytes.Buffer{},
|
||||
@@ -1331,7 +1332,7 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
rule: types.KindRole,
|
||||
verb: types.VerbRead,
|
||||
namespace: defaults.Namespace,
|
||||
namespace: apidefaults.Namespace,
|
||||
hasAccess: true,
|
||||
},
|
||||
},
|
||||
@@ -1342,11 +1343,11 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
{
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
{
|
||||
Resources: []string{types.Wildcard},
|
||||
@@ -1379,7 +1380,7 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
},
|
||||
rule: types.KindRole,
|
||||
verb: types.VerbRead,
|
||||
namespace: defaults.Namespace,
|
||||
namespace: apidefaults.Namespace,
|
||||
hasAccess: true,
|
||||
matchBuffer: "more specific rule",
|
||||
},
|
||||
@@ -1864,7 +1865,7 @@ func TestApplyTraits(t *testing.T) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "name1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
@@ -2080,7 +2081,7 @@ func TestBoolOptions(t *testing.T) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "role-name",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: tt.inOptions,
|
||||
@@ -2114,10 +2115,10 @@ func TestCheckAccessToDatabase(t *testing.T) {
|
||||
},
|
||||
}
|
||||
roleDevProd := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "dev-prod", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "dev-prod", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseLabels: types.Labels{"env": []string{"prod"}},
|
||||
DatabaseNames: []string{"test"},
|
||||
DatabaseUsers: []string{"dev"},
|
||||
@@ -2125,13 +2126,13 @@ func TestCheckAccessToDatabase(t *testing.T) {
|
||||
},
|
||||
}
|
||||
roleDevProdWithMFA := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "dev-prod", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "dev-prod", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
RequireSessionMFA: true,
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseLabels: types.Labels{"env": []string{"prod"}},
|
||||
DatabaseNames: []string{"test"},
|
||||
DatabaseUsers: []string{"dev"},
|
||||
@@ -2141,15 +2142,15 @@ func TestCheckAccessToDatabase(t *testing.T) {
|
||||
// Database labels are not set in allow/deny rules on purpose to test
|
||||
// that they're set during check and set defaults below.
|
||||
roleDeny := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "deny", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "deny", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseNames: []string{types.Wildcard},
|
||||
DatabaseUsers: []string{types.Wildcard},
|
||||
},
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseNames: []string{"postgres"},
|
||||
DatabaseUsers: []string{"postgres"},
|
||||
},
|
||||
@@ -2270,10 +2271,10 @@ func TestCheckAccessToDatabaseUser(t *testing.T) {
|
||||
},
|
||||
}
|
||||
roleDevProd := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "dev-prod", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "dev-prod", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseLabels: types.Labels{"env": []string{"prod"}},
|
||||
DatabaseUsers: []string{"dev"},
|
||||
},
|
||||
@@ -2326,36 +2327,36 @@ func TestCheckAccessToDatabaseUser(t *testing.T) {
|
||||
|
||||
func TestCheckDatabaseNamesAndUsers(t *testing.T) {
|
||||
roleEmpty := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "roleA", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "roleA", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{MaxSessionTTL: types.Duration(time.Hour)},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
}
|
||||
roleA := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "roleA", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "roleA", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{MaxSessionTTL: types.Duration(2 * time.Hour)},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseNames: []string{"postgres", "main"},
|
||||
DatabaseUsers: []string{"postgres", "alice"},
|
||||
},
|
||||
},
|
||||
}
|
||||
roleB := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "roleB", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "roleB", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{MaxSessionTTL: types.Duration(time.Hour)},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseNames: []string{"metrics"},
|
||||
DatabaseUsers: []string{"bob"},
|
||||
},
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseNames: []string{"postgres"},
|
||||
DatabaseUsers: []string{"postgres"},
|
||||
},
|
||||
@@ -2434,32 +2435,32 @@ func TestCheckAccessToDatabaseService(t *testing.T) {
|
||||
map[string]string{"env": "prod"},
|
||||
types.DatabaseServerSpecV3{})
|
||||
roleAdmin := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "admin", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "admin", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
},
|
||||
},
|
||||
}
|
||||
roleDev := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "dev", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "dev", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseLabels: types.Labels{"env": []string{"stage"}},
|
||||
},
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
DatabaseLabels: types.Labels{"arch": []string{"amd64"}},
|
||||
},
|
||||
},
|
||||
}
|
||||
roleIntern := &types.RoleV3{
|
||||
Metadata: types.Metadata{Name: "intern", Namespace: defaults.Namespace},
|
||||
Metadata: types.Metadata{Name: "intern", Namespace: apidefaults.Namespace},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
}
|
||||
@@ -2541,7 +2542,7 @@ func TestCheckAccessToKubernetes(t *testing.T) {
|
||||
wildcardRole := &types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "wildcard-labels",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
@@ -2553,14 +2554,14 @@ func TestCheckAccessToKubernetes(t *testing.T) {
|
||||
matchingLabelsRole := &types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "matching-labels",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
KubernetesLabels: types.Labels{
|
||||
"foo": utils.Strings{"bar"},
|
||||
"baz": utils.Strings{"qux"},
|
||||
"foo": apiutils.Strings{"bar"},
|
||||
"baz": apiutils.Strings{"qux"},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -2568,17 +2569,17 @@ func TestCheckAccessToKubernetes(t *testing.T) {
|
||||
matchingLabelsRoleWithMFA := &types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "matching-labels",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
RequireSessionMFA: true,
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
KubernetesLabels: types.Labels{
|
||||
"foo": utils.Strings{"bar"},
|
||||
"baz": utils.Strings{"qux"},
|
||||
"foo": apiutils.Strings{"bar"},
|
||||
"baz": apiutils.Strings{"qux"},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -2586,25 +2587,25 @@ func TestCheckAccessToKubernetes(t *testing.T) {
|
||||
noLabelsRole := &types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "no-labels",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
}
|
||||
mismatchingLabelsRole := &types.RoleV3{
|
||||
Metadata: types.Metadata{
|
||||
Name: "mismatching-labels",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
KubernetesLabels: types.Labels{
|
||||
"qux": utils.Strings{"baz"},
|
||||
"bar": utils.Strings{"foo"},
|
||||
"qux": apiutils.Strings{"baz"},
|
||||
"bar": apiutils.Strings{"foo"},
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -2699,7 +2700,7 @@ func TestCheckAccessToKubernetes(t *testing.T) {
|
||||
for _, r := range tc.roles {
|
||||
set = append(set, r)
|
||||
}
|
||||
err := set.CheckAccessToKubernetes(defaults.Namespace, tc.cluster, tc.mfaParams)
|
||||
err := set.CheckAccessToKubernetes(apidefaults.Namespace, tc.cluster, tc.mfaParams)
|
||||
if tc.hasAccess {
|
||||
require.NoError(t, err)
|
||||
} else {
|
||||
@@ -2742,7 +2743,7 @@ func BenchmarkCheckAccessToServer(b *testing.B) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: hostname,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
Addr: "127.0.0.1:3022",
|
||||
@@ -2761,7 +2762,7 @@ func BenchmarkCheckAccessToServer(b *testing.B) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: strconv.Itoa(i),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Allow: types.RoleConditions{
|
||||
|
||||
@@ -21,7 +21,9 @@ import (
|
||||
"fmt"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
@@ -246,12 +248,12 @@ func UnmarshalServer(bytes []byte, kind string, opts ...MarshalOption) (types.Se
|
||||
s.SetExpiry(cfg.Expires)
|
||||
}
|
||||
if s.Metadata.Expires != nil {
|
||||
utils.UTC(s.Metadata.Expires)
|
||||
apiutils.UTC(s.Metadata.Expires)
|
||||
}
|
||||
// Force the timestamps to UTC for consistency.
|
||||
// See https://github.com/gogo/protobuf/issues/519 for details on issues this causes for proto.Clone
|
||||
utils.UTC(&s.Spec.Rotation.Started)
|
||||
utils.UTC(&s.Spec.Rotation.LastRotated)
|
||||
apiutils.UTC(&s.Spec.Rotation.Started)
|
||||
apiutils.UTC(&s.Spec.Rotation.LastRotated)
|
||||
return &s, nil
|
||||
}
|
||||
return nil, trace.BadParameter("server resource version %q is not supported", h.Version)
|
||||
@@ -314,5 +316,5 @@ func MarshalServers(s []types.Server) ([]byte, error) {
|
||||
// NodeHasMissedKeepAlives checks if node has missed its keep alive
|
||||
func NodeHasMissedKeepAlives(s types.Server) bool {
|
||||
serverExpiry := s.Expiry()
|
||||
return serverExpiry.Before(time.Now().Add(defaults.ServerAnnounceTTL - (defaults.ServerKeepAliveTTL * 2)))
|
||||
return serverExpiry.Before(time.Now().Add(apidefaults.ServerAnnounceTTL - (apidefaults.ServerKeepAliveTTL * 2)))
|
||||
}
|
||||
|
||||
@@ -21,6 +21,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/fixtures"
|
||||
@@ -42,7 +43,7 @@ func (s *ServerSuite) TestServersCompare(c *check.C) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "node1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{"a": "b"},
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
@@ -166,7 +167,7 @@ func TestUnmarshalServerKubernetes(t *testing.T) {
|
||||
Kind: types.KindKubeService,
|
||||
Metadata: types.Metadata{
|
||||
Name: "foo",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -187,7 +188,7 @@ func TestUnmarshalServerKubernetes(t *testing.T) {
|
||||
Kind: types.KindKubeService,
|
||||
Metadata: types.Metadata{
|
||||
Name: "foo",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
KubernetesClusters: []*types.KubernetesCluster{
|
||||
|
||||
@@ -21,8 +21,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/fixtures"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
@@ -115,7 +115,7 @@ func TestServerDeepCopy(t *testing.T) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "a",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Labels: map[string]string{"label": "value"},
|
||||
Expires: &expires,
|
||||
},
|
||||
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
"encoding/json"
|
||||
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
@@ -43,8 +44,8 @@ func UnmarshalWebSession(bytes []byte, opts ...MarshalOption) (types.WebSession,
|
||||
if err := utils.FastUnmarshal(bytes, &ws); err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
utils.UTC(&ws.Spec.BearerTokenExpires)
|
||||
utils.UTC(&ws.Spec.Expires)
|
||||
apiutils.UTC(&ws.Spec.BearerTokenExpires)
|
||||
apiutils.UTC(&ws.Spec.Expires)
|
||||
|
||||
if err := ws.CheckAndSetDefaults(); err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
@@ -138,7 +139,7 @@ func UnmarshalWebToken(bytes []byte, opts ...MarshalOption) (types.WebToken, err
|
||||
if !config.Expires.IsZero() {
|
||||
token.Metadata.SetExpiry(config.Expires)
|
||||
}
|
||||
utils.UTC(token.Metadata.Expires)
|
||||
apiutils.UTC(token.Metadata.Expires)
|
||||
return &token, nil
|
||||
}
|
||||
return nil, trace.BadParameter("web token resource version %v is not supported", hdr.Version)
|
||||
|
||||
@@ -19,8 +19,8 @@ package services
|
||||
import (
|
||||
"github.com/gravitational/trace"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
)
|
||||
|
||||
@@ -32,7 +32,7 @@ func DefaultStaticTokens() types.StaticTokens {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: types.MetaNameStaticTokens,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.StaticTokensSpecV2{
|
||||
StaticTokens: []types.ProvisionTokenV1{},
|
||||
|
||||
+27
-26
@@ -32,6 +32,7 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth/u2f"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -110,7 +111,7 @@ func NewTestCAWithConfig(config TestCAConfig) *types.CertAuthorityV2 {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: config.ClusterName,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.CertAuthoritySpecV2{
|
||||
Type: config.Type,
|
||||
@@ -173,7 +174,7 @@ func newUser(name string, roles []string) types.User {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: name,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.UserSpecV2{
|
||||
Roles: roles,
|
||||
@@ -230,7 +231,7 @@ func (s *ServicesTestSuite) UsersExpiry(c *check.C) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "foo",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Expires: &expiresAt,
|
||||
},
|
||||
Spec: types.UserSpecV2{},
|
||||
@@ -343,11 +344,11 @@ func NewServer(kind, name, addr, namespace string) *types.ServerV2 {
|
||||
func (s *ServicesTestSuite) ServerCRUD(c *check.C) {
|
||||
ctx := context.Background()
|
||||
// SSH service.
|
||||
out, err := s.PresenceS.GetNodes(ctx, defaults.Namespace)
|
||||
out, err := s.PresenceS.GetNodes(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(len(out), check.Equals, 0)
|
||||
|
||||
srv := NewServer(types.KindNode, "srv1", "127.0.0.1:2022", defaults.Namespace)
|
||||
srv := NewServer(types.KindNode, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
|
||||
_, err = s.PresenceS.UpsertNode(ctx, srv)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
@@ -374,7 +375,7 @@ func (s *ServicesTestSuite) ServerCRUD(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(len(out), check.Equals, 0)
|
||||
|
||||
proxy := NewServer(types.KindProxy, "proxy1", "127.0.0.1:2023", defaults.Namespace)
|
||||
proxy := NewServer(types.KindProxy, "proxy1", "127.0.0.1:2023", apidefaults.Namespace)
|
||||
c.Assert(s.PresenceS.UpsertProxy(proxy), check.IsNil)
|
||||
|
||||
out, err = s.PresenceS.GetProxies()
|
||||
@@ -395,7 +396,7 @@ func (s *ServicesTestSuite) ServerCRUD(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(len(out), check.Equals, 0)
|
||||
|
||||
auth := NewServer(types.KindAuthServer, "auth1", "127.0.0.1:2025", defaults.Namespace)
|
||||
auth := NewServer(types.KindAuthServer, "auth1", "127.0.0.1:2025", apidefaults.Namespace)
|
||||
c.Assert(s.PresenceS.UpsertAuthServer(auth), check.IsNil)
|
||||
|
||||
out, err = s.PresenceS.GetAuthServers()
|
||||
@@ -409,9 +410,9 @@ func (s *ServicesTestSuite) ServerCRUD(c *check.C) {
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(len(out), check.Equals, 0)
|
||||
|
||||
kube1 := NewServer(types.KindKubeService, "kube1", "10.0.0.1:3026", defaults.Namespace)
|
||||
kube1 := NewServer(types.KindKubeService, "kube1", "10.0.0.1:3026", apidefaults.Namespace)
|
||||
c.Assert(s.PresenceS.UpsertKubeService(ctx, kube1), check.IsNil)
|
||||
kube2 := NewServer(types.KindKubeService, "kube2", "10.0.0.2:3026", defaults.Namespace)
|
||||
kube2 := NewServer(types.KindKubeService, "kube2", "10.0.0.2:3026", apidefaults.Namespace)
|
||||
c.Assert(s.PresenceS.UpsertKubeService(ctx, kube2), check.IsNil)
|
||||
|
||||
out, err = s.PresenceS.GetKubeServices(ctx)
|
||||
@@ -440,7 +441,7 @@ func NewAppServer(name string, internalAddr string, publicAddr string) *types.Se
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: uuid.New(),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
Apps: []*types.App{
|
||||
@@ -462,7 +463,7 @@ func (s *ServicesTestSuite) AppServerCRUD(c *check.C) {
|
||||
server := NewAppServer("foo", "http://127.0.0.1:8080", "foo.example.com")
|
||||
|
||||
// Expect not to be returned any applications and trace.NotFound.
|
||||
out, err := s.PresenceS.GetAppServers(ctx, defaults.Namespace)
|
||||
out, err := s.PresenceS.GetAppServers(ctx, apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(len(out), check.Equals, 0)
|
||||
|
||||
@@ -493,7 +494,7 @@ func newReverseTunnel(clusterName string, dialAddrs []string) *types.ReverseTunn
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: clusterName,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.ReverseTunnelSpecV2{
|
||||
ClusterName: clusterName,
|
||||
@@ -676,14 +677,14 @@ func (s *ServicesTestSuite) RolesCRUD(c *check.C) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "role1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.RoleSpecV3{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.Duration(time.Hour),
|
||||
PortForwarding: types.NewBoolOption(true),
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
BPF: defaults.EnhancedEvents(),
|
||||
BPF: apidefaults.EnhancedEvents(),
|
||||
},
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"root", "bob"},
|
||||
@@ -691,13 +692,13 @@ func (s *ServicesTestSuite) RolesCRUD(c *check.C) {
|
||||
AppLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
KubernetesLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
DatabaseLabels: types.Labels{types.Wildcard: []string{types.Wildcard}},
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
Rules: []types.Rule{
|
||||
types.NewRule(types.KindRole, services.RO()),
|
||||
},
|
||||
},
|
||||
Deny: types.RoleConditions{
|
||||
Namespaces: []string{defaults.Namespace},
|
||||
Namespaces: []string{apidefaults.Namespace},
|
||||
},
|
||||
},
|
||||
}
|
||||
@@ -733,8 +734,8 @@ func (s *ServicesTestSuite) NamespacesCRUD(c *check.C) {
|
||||
Kind: types.KindNamespace,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: defaults.Namespace,
|
||||
Namespace: defaults.Namespace,
|
||||
Name: apidefaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
}
|
||||
err = s.PresenceS.UpsertNamespace(ns)
|
||||
@@ -828,7 +829,7 @@ func (s *ServicesTestSuite) SAMLCRUD(c *check.C) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "saml1",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.SAMLConnectorSpecV2{
|
||||
Issuer: "http://example.com",
|
||||
@@ -953,7 +954,7 @@ func (s *ServicesTestSuite) GithubConnectorCRUD(c *check.C) {
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Name: "github",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.GithubConnectorSpecV3{
|
||||
ClientID: "aaa",
|
||||
@@ -1523,7 +1524,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "testnamespace",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
}
|
||||
err := s.PresenceS.UpsertNamespace(ns)
|
||||
@@ -1620,7 +1621,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
|
||||
Kind: types.KindNode,
|
||||
},
|
||||
crud: func(context.Context) types.Resource {
|
||||
srv := NewServer(types.KindNode, "srv1", "127.0.0.1:2022", defaults.Namespace)
|
||||
srv := NewServer(types.KindNode, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
|
||||
|
||||
_, err := s.PresenceS.UpsertNode(ctx, srv)
|
||||
c.Assert(err, check.IsNil)
|
||||
@@ -1640,7 +1641,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
|
||||
Kind: types.KindProxy,
|
||||
},
|
||||
crud: func(context.Context) types.Resource {
|
||||
srv := NewServer(types.KindProxy, "srv1", "127.0.0.1:2022", defaults.Namespace)
|
||||
srv := NewServer(types.KindProxy, "srv1", "127.0.0.1:2022", apidefaults.Namespace)
|
||||
|
||||
err := s.PresenceS.UpsertProxy(srv)
|
||||
c.Assert(err, check.IsNil)
|
||||
@@ -1734,7 +1735,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "shmest",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
}
|
||||
err := s.PresenceS.UpsertNamespace(ns)
|
||||
@@ -1884,7 +1885,7 @@ func (s *ServicesTestSuite) ProxyWatcher(c *check.C) {
|
||||
c.Fatalf("Timeout waiting for ProxyWatcher reset")
|
||||
}
|
||||
|
||||
proxy := NewServer(types.KindProxy, "proxy1", "127.0.0.1:2023", defaults.Namespace)
|
||||
proxy := NewServer(types.KindProxy, "proxy1", "127.0.0.1:2023", apidefaults.Namespace)
|
||||
c.Assert(s.PresenceS.UpsertProxy(proxy), check.IsNil)
|
||||
|
||||
// the first event is always the current list of proxies
|
||||
@@ -1901,7 +1902,7 @@ func (s *ServicesTestSuite) ProxyWatcher(c *check.C) {
|
||||
}
|
||||
|
||||
// add a second proxy
|
||||
proxy2 := NewServer(types.KindProxy, "proxy2", "127.0.0.1:2023", defaults.Namespace)
|
||||
proxy2 := NewServer(types.KindProxy, "proxy2", "127.0.0.1:2023", apidefaults.Namespace)
|
||||
c.Assert(s.PresenceS.UpsertProxy(proxy2), check.IsNil)
|
||||
|
||||
// watcher should detect the proxy list change
|
||||
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
"fmt"
|
||||
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
"github.com/gravitational/teleport/lib/utils/parse"
|
||||
|
||||
@@ -34,7 +35,7 @@ func TraitsToRoles(ms types.TraitMappingSet, traits map[string][]string) (warnin
|
||||
warnings = traitsToRoles(ms, traits, func(role string, expanded bool) {
|
||||
roles = append(roles, role)
|
||||
})
|
||||
return warnings, utils.Deduplicate(roles)
|
||||
return warnings, apiutils.Deduplicate(roles)
|
||||
}
|
||||
|
||||
// TraitsToRoleMatchers maps the supplied traits to a list of role matchers. Prefer calling
|
||||
|
||||
@@ -20,7 +20,7 @@ import (
|
||||
"testing"
|
||||
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
@@ -136,6 +136,6 @@ func TestTraitsToRoleMatchers(t *testing.T) {
|
||||
|
||||
// verify that the resulting matches, once deduplicated, are equivalent
|
||||
// to the expected matches.
|
||||
require.ElementsMatch(t, utils.Deduplicate(matches), tt.matches, tt.desc)
|
||||
require.ElementsMatch(t, apiutils.Deduplicate(matches), tt.matches, tt.desc)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -20,13 +20,14 @@ import (
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
|
||||
"github.com/coreos/go-oidc/jose"
|
||||
saml2 "github.com/russellhaering/gosaml2"
|
||||
samltypes "github.com/russellhaering/gosaml2/types"
|
||||
"gopkg.in/check.v1"
|
||||
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
)
|
||||
|
||||
type UserSuite struct {
|
||||
@@ -54,7 +55,7 @@ func (s *UserSuite) TestTraits(c *check.C) {
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Name: "foo",
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
},
|
||||
Spec: types.UserSpecV2{
|
||||
Traits: map[string][]string{
|
||||
|
||||
+18
-17
@@ -22,6 +22,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/lib/backend"
|
||||
"github.com/gravitational/teleport/lib/backend/lite"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -93,14 +94,14 @@ func (s *sessionSuite) TestID(t *testing.T) {
|
||||
}
|
||||
|
||||
func (s *sessionSuite) TestSessionsCRUD(t *testing.T) {
|
||||
out, err := s.srv.GetSessions(defaults.Namespace)
|
||||
out, err := s.srv.GetSessions(apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Empty(t, out)
|
||||
|
||||
// Create session.
|
||||
sess := Session{
|
||||
ID: NewID(),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
TerminalParams: TerminalParams{W: 100, H: 100},
|
||||
Login: "bob",
|
||||
LastActive: s.clock.Now().UTC(),
|
||||
@@ -109,35 +110,35 @@ func (s *sessionSuite) TestSessionsCRUD(t *testing.T) {
|
||||
require.NoError(t, s.srv.CreateSession(sess))
|
||||
|
||||
// Make sure only one session exists.
|
||||
out, err = s.srv.GetSessions(defaults.Namespace)
|
||||
out, err = s.srv.GetSessions(apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, out, []Session{sess})
|
||||
|
||||
// Make sure the session is the one created above.
|
||||
s2, err := s.srv.GetSession(defaults.Namespace, sess.ID)
|
||||
s2, err := s.srv.GetSession(apidefaults.Namespace, sess.ID)
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, s2, &sess)
|
||||
|
||||
// Update session terminal parameter
|
||||
err = s.srv.UpdateSession(UpdateRequest{
|
||||
ID: sess.ID,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
TerminalParams: &TerminalParams{W: 101, H: 101},
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
// Verify update was applied.
|
||||
sess.TerminalParams = TerminalParams{W: 101, H: 101}
|
||||
s2, err = s.srv.GetSession(defaults.Namespace, sess.ID)
|
||||
s2, err = s.srv.GetSession(apidefaults.Namespace, sess.ID)
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, s2, &sess)
|
||||
|
||||
// Remove the session.
|
||||
err = s.srv.DeleteSession(defaults.Namespace, sess.ID)
|
||||
err = s.srv.DeleteSession(apidefaults.Namespace, sess.ID)
|
||||
require.NoError(t, err)
|
||||
|
||||
// Make sure session no longer exists.
|
||||
_, err = s.srv.GetSession(defaults.Namespace, sess.ID)
|
||||
_, err = s.srv.GetSession(apidefaults.Namespace, sess.ID)
|
||||
require.Error(t, err)
|
||||
}
|
||||
|
||||
@@ -146,7 +147,7 @@ func (s *sessionSuite) TestSessionsCRUD(t *testing.T) {
|
||||
func (s *sessionSuite) TestSessionsInactivity(t *testing.T) {
|
||||
sess := Session{
|
||||
ID: NewID(),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
TerminalParams: TerminalParams{W: 100, H: 100},
|
||||
Login: "bob",
|
||||
LastActive: s.clock.Now().UTC(),
|
||||
@@ -158,7 +159,7 @@ func (s *sessionSuite) TestSessionsInactivity(t *testing.T) {
|
||||
s.clock.Advance(defaults.ActiveSessionTTL + time.Second)
|
||||
|
||||
// should not be in active sessions:
|
||||
s2, err := s.srv.GetSession(defaults.Namespace, sess.ID)
|
||||
s2, err := s.srv.GetSession(apidefaults.Namespace, sess.ID)
|
||||
require.IsType(t, trace.NotFound(""), err)
|
||||
require.Nil(t, s2)
|
||||
}
|
||||
@@ -167,7 +168,7 @@ func (s *sessionSuite) TestPartiesCRUD(t *testing.T) {
|
||||
// create session:
|
||||
sess := Session{
|
||||
ID: NewID(),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
TerminalParams: TerminalParams{W: 100, H: 100},
|
||||
Login: "vincent",
|
||||
LastActive: s.clock.Now().UTC(),
|
||||
@@ -194,27 +195,27 @@ func (s *sessionSuite) TestPartiesCRUD(t *testing.T) {
|
||||
}
|
||||
err = s.srv.UpdateSession(UpdateRequest{
|
||||
ID: sess.ID,
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Parties: &parties,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
// verify they're in the session:
|
||||
copy, err := s.srv.GetSession(defaults.Namespace, sess.ID)
|
||||
copy, err := s.srv.GetSession(apidefaults.Namespace, sess.ID)
|
||||
require.NoError(t, err)
|
||||
require.Len(t, copy.Parties, 2)
|
||||
|
||||
// empty update (list of parties must not change)
|
||||
err = s.srv.UpdateSession(UpdateRequest{ID: sess.ID, Namespace: defaults.Namespace})
|
||||
err = s.srv.UpdateSession(UpdateRequest{ID: sess.ID, Namespace: apidefaults.Namespace})
|
||||
require.NoError(t, err)
|
||||
copy, _ = s.srv.GetSession(defaults.Namespace, sess.ID)
|
||||
copy, _ = s.srv.GetSession(apidefaults.Namespace, sess.ID)
|
||||
require.Len(t, copy.Parties, 2)
|
||||
|
||||
// remove the 2nd party:
|
||||
deleted := copy.RemoveParty(parties[1].ID)
|
||||
require.True(t, deleted)
|
||||
err = s.srv.UpdateSession(UpdateRequest{ID: copy.ID, Parties: ©.Parties, Namespace: defaults.Namespace})
|
||||
err = s.srv.UpdateSession(UpdateRequest{ID: copy.ID, Parties: ©.Parties, Namespace: apidefaults.Namespace})
|
||||
require.NoError(t, err)
|
||||
copy, _ = s.srv.GetSession(defaults.Namespace, sess.ID)
|
||||
copy, _ = s.srv.GetSession(apidefaults.Namespace, sess.ID)
|
||||
require.Len(t, copy.Parties, 1)
|
||||
|
||||
// we still have the 1st party in:
|
||||
|
||||
@@ -29,6 +29,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -204,10 +205,10 @@ func New(ctx context.Context, c *Config) (*Server, error) {
|
||||
Component: teleport.ComponentApp,
|
||||
Announcer: c.AccessPoint,
|
||||
GetServerInfo: s.GetServerInfo,
|
||||
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/2),
|
||||
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/2),
|
||||
CheckPeriod: defaults.HeartbeatCheckPeriod,
|
||||
ServerTTL: defaults.ServerAnnounceTTL,
|
||||
ServerTTL: apidefaults.ServerAnnounceTTL,
|
||||
OnHeartbeat: c.OnHeartbeat,
|
||||
})
|
||||
if err != nil {
|
||||
@@ -245,7 +246,7 @@ func (s *Server) GetServerInfo() (types.Resource, error) {
|
||||
s.server.SetApps(apps)
|
||||
|
||||
// Update the TTL.
|
||||
s.server.SetExpiry(s.c.Clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
|
||||
s.server.SetExpiry(s.c.Clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
|
||||
|
||||
// Update rotation state.
|
||||
rotation, err := s.c.GetRotation(types.RoleApp)
|
||||
@@ -383,7 +384,7 @@ func (s *Server) authorize(ctx context.Context, r *http.Request) (*tlsca.Identit
|
||||
Verified: identity.MFAVerified != "",
|
||||
AlwaysRequired: ap.GetRequireSessionMFA(),
|
||||
}
|
||||
err = authContext.Checker.CheckAccessToApp(defaults.Namespace, app, mfaParams)
|
||||
err = authContext.Checker.CheckAccessToApp(apidefaults.Namespace, app, mfaParams)
|
||||
if err != nil {
|
||||
return nil, nil, utils.OpaqueAccessDenied(err)
|
||||
}
|
||||
@@ -448,7 +449,7 @@ func (s *Server) newHTTPServer() *http.Server {
|
||||
|
||||
return &http.Server{
|
||||
Handler: authMiddleware,
|
||||
ReadHeaderTimeout: defaults.DefaultDialTimeout,
|
||||
ReadHeaderTimeout: apidefaults.DefaultDialTimeout,
|
||||
ErrorLog: utils.NewStdlogger(s.log.Error, teleport.ComponentApp),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -38,9 +38,10 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
"github.com/gravitational/teleport/api/defaults"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
@@ -195,7 +196,7 @@ func (s *Suite) SetUpTest(c *check.C) {
|
||||
// Make sure the upload directory is created.
|
||||
err = os.MkdirAll(filepath.Join(
|
||||
s.dataDir, teleport.LogsDir, teleport.ComponentUpload,
|
||||
events.StreamingLogsDir, defaults.Namespace,
|
||||
events.StreamingLogsDir, apidefaults.Namespace,
|
||||
), 0755)
|
||||
c.Assert(err, check.IsNil)
|
||||
|
||||
@@ -230,7 +231,7 @@ func (s *Suite) TearDownTest(c *check.C) {
|
||||
|
||||
s.testhttp.Close()
|
||||
|
||||
err = s.tlsServer.Auth().DeleteAllAppServers(context.Background(), defaults.Namespace)
|
||||
err = s.tlsServer.Auth().DeleteAllAppServers(context.Background(), apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
}
|
||||
|
||||
@@ -238,7 +239,7 @@ func (s *Suite) TearDownTest(c *check.C) {
|
||||
// has been created.
|
||||
func (s *Suite) TestStart(c *check.C) {
|
||||
// Fetch the services.App that the service heartbeat.
|
||||
servers, err := s.authServer.AuthServer.GetAppServers(context.Background(), defaults.Namespace)
|
||||
servers, err := s.authServer.AuthServer.GetAppServers(context.Background(), apidefaults.Namespace)
|
||||
c.Assert(err, check.IsNil)
|
||||
c.Assert(servers, check.HasLen, 1)
|
||||
server := servers[0]
|
||||
@@ -260,7 +261,7 @@ func (s *Suite) TestStart(c *check.C) {
|
||||
|
||||
// Check the expiry time is correct.
|
||||
c.Assert(s.clock.Now().Before(server.Expiry()), check.Equals, true)
|
||||
c.Assert(s.clock.Now().Add(2*defaults.ServerAnnounceTTL).After(server.Expiry()), check.Equals, true)
|
||||
c.Assert(s.clock.Now().Add(2*apidefaults.ServerAnnounceTTL).After(server.Expiry()), check.Equals, true)
|
||||
}
|
||||
|
||||
// TestWaitStop makes sure the server will block and unlock.
|
||||
|
||||
@@ -23,6 +23,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -130,7 +131,7 @@ func (s *Server) newStreamWriter(identity *tlsca.Identity) (events.StreamWriter,
|
||||
Streamer: streamer,
|
||||
Clock: s.c.Clock,
|
||||
SessionID: session_pkg.ID(chunkID),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
ServerID: s.c.Server.GetName(),
|
||||
RecordOutput: recConfig.GetMode() != types.RecordOff,
|
||||
Component: teleport.ComponentApp,
|
||||
@@ -149,7 +150,7 @@ func (s *Server) newStreamWriter(identity *tlsca.Identity) (events.StreamWriter,
|
||||
},
|
||||
ServerMetadata: apievents.ServerMetadata{
|
||||
ServerID: s.c.Server.GetName(),
|
||||
ServerNamespace: defaults.Namespace,
|
||||
ServerNamespace: apidefaults.Namespace,
|
||||
},
|
||||
SessionMetadata: apievents.SessionMetadata{
|
||||
SessionID: identity.RouteToApp.SessionID,
|
||||
@@ -181,7 +182,7 @@ func (s *Server) newStreamer(ctx context.Context, sessionID string, recConfig ty
|
||||
s.log.Debugf("Using async streamer for session %v.", sessionID)
|
||||
uploadDir := filepath.Join(
|
||||
s.c.DataDir, teleport.LogsDir, teleport.ComponentUpload,
|
||||
events.StreamingLogsDir, defaults.Namespace,
|
||||
events.StreamingLogsDir, apidefaults.Namespace,
|
||||
)
|
||||
fileStreamer, err := filesessions.NewStreamer(uploadDir)
|
||||
if err != nil {
|
||||
|
||||
@@ -28,6 +28,7 @@ import (
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/api/types/wrappers"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
@@ -287,7 +288,7 @@ func (t *transport) rewriteRedirect(resp *http.Response) error {
|
||||
|
||||
// If the redirect location is one of the hosts specified in the list of
|
||||
// redirects, rewrite the header.
|
||||
if utils.SliceContainsStr(t.c.rewrite.Redirect, host(u.Host)) {
|
||||
if apiutils.SliceContainsStr(t.c.rewrite.Redirect, host(u.Host)) {
|
||||
u.Scheme = "https"
|
||||
u.Host = net.JoinHostPort(t.c.publicAddr, t.c.publicPort)
|
||||
}
|
||||
|
||||
@@ -19,8 +19,8 @@ package common
|
||||
import (
|
||||
"context"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
libevents "github.com/gravitational/teleport/lib/events"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
@@ -80,7 +80,7 @@ func (a *audit) OnSessionStart(ctx context.Context, session *Session, sessionErr
|
||||
},
|
||||
ServerMetadata: events.ServerMetadata{
|
||||
ServerID: session.Server.GetHostID(),
|
||||
ServerNamespace: defaults.Namespace,
|
||||
ServerNamespace: apidefaults.Namespace,
|
||||
},
|
||||
UserMetadata: events.UserMetadata{
|
||||
User: session.Identity.Username,
|
||||
|
||||
@@ -29,11 +29,11 @@ import (
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/auth/native"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/multiplexer"
|
||||
"github.com/gravitational/teleport/lib/reversetunnel"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
@@ -418,7 +418,7 @@ func (s *ProxyServer) pickDatabaseServer(ctx context.Context, identity tlsca.Ide
|
||||
if err != nil {
|
||||
return nil, nil, trace.Wrap(err)
|
||||
}
|
||||
servers, err := accessPoint.GetDatabaseServers(ctx, defaults.Namespace)
|
||||
servers, err := accessPoint.GetDatabaseServers(ctx, apidefaults.Namespace)
|
||||
if err != nil {
|
||||
return nil, nil, trace.Wrap(err)
|
||||
}
|
||||
|
||||
@@ -23,6 +23,7 @@ import (
|
||||
"sync"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
@@ -256,10 +257,10 @@ func (s *Server) initHeartbeat(ctx context.Context, server types.DatabaseServer)
|
||||
Mode: srv.HeartbeatModeDB,
|
||||
Announcer: s.cfg.AccessPoint,
|
||||
GetServerInfo: s.getServerInfoFunc(server),
|
||||
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/10),
|
||||
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/10),
|
||||
CheckPeriod: defaults.HeartbeatCheckPeriod,
|
||||
ServerTTL: defaults.ServerAnnounceTTL,
|
||||
ServerTTL: apidefaults.ServerAnnounceTTL,
|
||||
OnHeartbeat: s.cfg.OnHeartbeat,
|
||||
})
|
||||
if err != nil {
|
||||
@@ -291,7 +292,7 @@ func (s *Server) getServerInfoFunc(server types.DatabaseServer) func() (types.Re
|
||||
}
|
||||
}
|
||||
// Update TTL.
|
||||
server.SetExpiry(s.cfg.Clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
|
||||
server.SetExpiry(s.cfg.Clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
|
||||
return server, nil
|
||||
}
|
||||
}
|
||||
|
||||
@@ -21,8 +21,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
@@ -62,7 +62,7 @@ func TestDatabaseServerStart(t *testing.T) {
|
||||
}
|
||||
|
||||
// Make sure servers were announced and their labels updated.
|
||||
servers, err := testCtx.authClient.GetDatabaseServers(ctx, defaults.Namespace)
|
||||
servers, err := testCtx.authClient.GetDatabaseServers(ctx, apidefaults.Namespace)
|
||||
require.NoError(t, err)
|
||||
for _, server := range servers {
|
||||
require.Equal(t, map[string]string{"echo": "test"}, server.GetAllLabels())
|
||||
|
||||
@@ -22,8 +22,8 @@ import (
|
||||
"path/filepath"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
libevents "github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/events/filesessions"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
@@ -58,7 +58,7 @@ func (s *Server) newStreamWriter(sessionCtx *common.Session) (libevents.StreamWr
|
||||
Streamer: streamer,
|
||||
Clock: s.cfg.Clock,
|
||||
SessionID: session.ID(sessionCtx.ID),
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
ServerID: sessionCtx.Server.GetHostID(),
|
||||
RecordOutput: recConfig.GetMode() != types.RecordOff,
|
||||
Component: teleport.ComponentDatabase,
|
||||
@@ -78,7 +78,7 @@ func (s *Server) newStreamer(ctx context.Context, sessionID string, recConfig ty
|
||||
s.log.Debugf("Using async streamer for session %v.", sessionID)
|
||||
uploadDir := filepath.Join(
|
||||
s.cfg.DataDir, teleport.LogsDir, teleport.ComponentUpload,
|
||||
libevents.StreamingLogsDir, defaults.Namespace)
|
||||
libevents.StreamingLogsDir, apidefaults.Namespace)
|
||||
// Make sure the upload dir exists, otherwise file streamer will fail.
|
||||
_, err := utils.StatDir(uploadDir)
|
||||
if err != nil && !trace.IsNotFound(err) {
|
||||
|
||||
+2
-2
@@ -32,9 +32,9 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/utils"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
log "github.com/sirupsen/logrus"
|
||||
@@ -529,7 +529,7 @@ func parseSecureCopy(path string) (string, string, bool, error) {
|
||||
// Look for the -t flag, it indicates that an upload occurred. The other
|
||||
// flags do no matter for now.
|
||||
action := events.SCPActionDownload
|
||||
if utils.SliceContainsStr(parts, "-t") {
|
||||
if apiutils.SliceContainsStr(parts, "-t") {
|
||||
action = events.SCPActionUpload
|
||||
}
|
||||
|
||||
|
||||
@@ -27,12 +27,12 @@ import (
|
||||
"golang.org/x/crypto/ssh/agent"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
apisshutils "github.com/gravitational/teleport/api/utils/sshutils"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/bpf"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/events"
|
||||
"github.com/gravitational/teleport/lib/pam"
|
||||
"github.com/gravitational/teleport/lib/session"
|
||||
@@ -340,7 +340,7 @@ func (s *Server) HostUUID() string {
|
||||
|
||||
// GetNamespace returns the namespace the forwarding server resides in.
|
||||
func (s *Server) GetNamespace() string {
|
||||
return defaults.Namespace
|
||||
return apidefaults.Namespace
|
||||
}
|
||||
|
||||
// AdvertiseAddr is the address of the remote host this forwarding server is
|
||||
@@ -555,7 +555,7 @@ func (s *Server) newRemoteClient(systemLogin string) (*ssh.Client, error) {
|
||||
authMethod,
|
||||
},
|
||||
HostKeyCallback: s.authHandlers.HostKeyAuth,
|
||||
Timeout: defaults.DefaultDialTimeout,
|
||||
Timeout: apidefaults.DefaultDialTimeout,
|
||||
}
|
||||
|
||||
// Ciphers, KEX, and MACs preferences are honored by both the in-memory
|
||||
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
"github.com/jonboulle/clockwork"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
|
||||
@@ -45,7 +46,7 @@ func TestHeartbeatKeepAlive(t *testing.T) {
|
||||
Kind: types.KindNode,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Name: "1",
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
@@ -63,7 +64,7 @@ func TestHeartbeatKeepAlive(t *testing.T) {
|
||||
Kind: types.KindAppServer,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Name: "1",
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
@@ -81,7 +82,7 @@ func TestHeartbeatKeepAlive(t *testing.T) {
|
||||
Kind: types.KindDatabaseServer,
|
||||
Version: types.V3,
|
||||
Metadata: types.Metadata{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Name: "1",
|
||||
},
|
||||
Spec: types.DatabaseServerSpecV3{
|
||||
@@ -113,7 +114,7 @@ func TestHeartbeatKeepAlive(t *testing.T) {
|
||||
ServerTTL: 600 * time.Second,
|
||||
Clock: clock,
|
||||
GetServerInfo: func() (types.Resource, error) {
|
||||
server.SetExpiry(clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
|
||||
server.SetExpiry(clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
|
||||
return server, nil
|
||||
},
|
||||
})
|
||||
@@ -222,7 +223,7 @@ func TestHeartbeatAnnounce(t *testing.T) {
|
||||
Kind: tt.kind,
|
||||
Version: types.V2,
|
||||
Metadata: types.Metadata{
|
||||
Namespace: defaults.Namespace,
|
||||
Namespace: apidefaults.Namespace,
|
||||
Name: "1",
|
||||
},
|
||||
Spec: types.ServerSpecV2{
|
||||
@@ -230,7 +231,7 @@ func TestHeartbeatAnnounce(t *testing.T) {
|
||||
Hostname: "2",
|
||||
},
|
||||
}
|
||||
srv.SetExpiry(clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
|
||||
srv.SetExpiry(clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
|
||||
return srv, nil
|
||||
},
|
||||
})
|
||||
|
||||
@@ -29,7 +29,9 @@ import (
|
||||
"golang.org/x/crypto/ssh"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/reversetunnel"
|
||||
"github.com/gravitational/teleport/lib/srv"
|
||||
@@ -94,7 +96,7 @@ func parseProxySubsysRequest(request string) (proxySubsysRequest, error) {
|
||||
return proxySubsysRequest{}, trace.BadParameter(paramMessage)
|
||||
}
|
||||
requestBody := strings.TrimPrefix(request, prefix)
|
||||
namespace := defaults.Namespace
|
||||
namespace := apidefaults.Namespace
|
||||
var err error
|
||||
parts := strings.Split(requestBody, "@")
|
||||
switch {
|
||||
@@ -162,7 +164,7 @@ func (p *proxySubsysRequest) String() string {
|
||||
// SetDefaults sets default values.
|
||||
func (p *proxySubsysRequest) SetDefaults() {
|
||||
if p.namespace == "" {
|
||||
p.namespace = defaults.Namespace
|
||||
p.namespace = apidefaults.Namespace
|
||||
}
|
||||
}
|
||||
|
||||
@@ -366,7 +368,7 @@ func (t *proxySubsys) proxyToHost(
|
||||
t.log.Errorf("Failed to parse address %q: %v.", servers[i].GetAddr(), err)
|
||||
continue
|
||||
}
|
||||
if t.host == ip || t.host == servers[i].GetHostname() || utils.SliceContainsStr(ips, ip) {
|
||||
if t.host == ip || t.host == servers[i].GetHostname() || apiutils.SliceContainsStr(ips, ip) {
|
||||
if !specifiedPort || t.port == port {
|
||||
server = servers[i]
|
||||
matches++
|
||||
|
||||
@@ -17,7 +17,7 @@ limitations under the License.
|
||||
package regular
|
||||
|
||||
import (
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/lib/srv"
|
||||
|
||||
"gopkg.in/check.v1"
|
||||
@@ -74,7 +74,7 @@ func (s *ProxyTestSuite) TestParseProxyRequest(c *check.C) {
|
||||
// test cases without a defined namespace are testing for
|
||||
// the presence of the default namespace; namespace should
|
||||
// never actually be empty.
|
||||
t.namespace = defaults.Namespace
|
||||
t.namespace = apidefaults.Namespace
|
||||
}
|
||||
cmt := check.Commentf("Test case %d: %+v", i, t)
|
||||
req, err := parseProxySubsysRequest(t.req)
|
||||
|
||||
@@ -34,6 +34,7 @@ import (
|
||||
"golang.org/x/crypto/ssh"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
@@ -626,9 +627,9 @@ func New(addr utils.NetAddr,
|
||||
Component: component,
|
||||
Announcer: s.authService,
|
||||
GetServerInfo: s.getServerInfo,
|
||||
KeepAlivePeriod: defaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: defaults.ServerAnnounceTTL/2 + utils.RandomDuration(defaults.ServerAnnounceTTL/10),
|
||||
ServerTTL: defaults.ServerAnnounceTTL,
|
||||
KeepAlivePeriod: apidefaults.ServerKeepAliveTTL,
|
||||
AnnouncePeriod: apidefaults.ServerAnnounceTTL/2 + utils.RandomDuration(apidefaults.ServerAnnounceTTL/10),
|
||||
ServerTTL: apidefaults.ServerAnnounceTTL,
|
||||
CheckPeriod: defaults.HeartbeatCheckPeriod,
|
||||
Clock: s.clock,
|
||||
OnHeartbeat: s.onHeartbeat,
|
||||
@@ -770,7 +771,7 @@ func (s *Server) getServerInfo() (types.Resource, error) {
|
||||
server.SetRotation(*rotation)
|
||||
}
|
||||
}
|
||||
server.SetExpiry(s.clock.Now().UTC().Add(defaults.ServerAnnounceTTL))
|
||||
server.SetExpiry(s.clock.Now().UTC().Add(apidefaults.ServerAnnounceTTL))
|
||||
server.SetPublicAddr(s.proxyPublicAddr.String())
|
||||
return server, nil
|
||||
}
|
||||
|
||||
@@ -39,10 +39,10 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
"github.com/gravitational/teleport/lib/bpf"
|
||||
"github.com/gravitational/teleport/lib/defaults"
|
||||
"github.com/gravitational/teleport/lib/limiter"
|
||||
"github.com/gravitational/teleport/lib/pam"
|
||||
"github.com/gravitational/teleport/lib/reversetunnel"
|
||||
@@ -146,7 +146,7 @@ func newCustomFixture(t *testing.T, mutateCfg func(*auth.TestServerConfig), sshO
|
||||
nodeDir := t.TempDir()
|
||||
serverOptions := []ServerOption{
|
||||
SetUUID(nodeID),
|
||||
SetNamespace(defaults.Namespace),
|
||||
SetNamespace(apidefaults.Namespace),
|
||||
SetEmitter(nodeClient),
|
||||
SetShell("/bin/sh"),
|
||||
SetSessionServer(nodeClient),
|
||||
@@ -810,7 +810,7 @@ func TestProxyReverseTunnel(t *testing.T) {
|
||||
SetProxyMode(reverseTunnelServer),
|
||||
SetSessionServer(proxyClient),
|
||||
SetEmitter(nodeClient),
|
||||
SetNamespace(defaults.Namespace),
|
||||
SetNamespace(apidefaults.Namespace),
|
||||
SetPAMConfig(&pam.Config{Enabled: false}),
|
||||
SetBPF(&bpf.NOP{}),
|
||||
SetClock(f.clock),
|
||||
@@ -887,7 +887,7 @@ func TestProxyReverseTunnel(t *testing.T) {
|
||||
},
|
||||
),
|
||||
SetSessionServer(nodeClient),
|
||||
SetNamespace(defaults.Namespace),
|
||||
SetNamespace(apidefaults.Namespace),
|
||||
SetPAMConfig(&pam.Config{Enabled: false}),
|
||||
SetBPF(&bpf.NOP{}),
|
||||
SetEmitter(nodeClient),
|
||||
@@ -988,7 +988,7 @@ func TestProxyRoundRobin(t *testing.T) {
|
||||
SetProxyMode(reverseTunnelServer),
|
||||
SetSessionServer(proxyClient),
|
||||
SetEmitter(nodeClient),
|
||||
SetNamespace(defaults.Namespace),
|
||||
SetNamespace(apidefaults.Namespace),
|
||||
SetPAMConfig(&pam.Config{Enabled: false}),
|
||||
SetBPF(&bpf.NOP{}),
|
||||
SetClock(f.clock),
|
||||
@@ -1105,7 +1105,7 @@ func TestProxyDirectAccess(t *testing.T) {
|
||||
SetProxyMode(reverseTunnelServer),
|
||||
SetSessionServer(proxyClient),
|
||||
SetEmitter(nodeClient),
|
||||
SetNamespace(defaults.Namespace),
|
||||
SetNamespace(apidefaults.Namespace),
|
||||
SetPAMConfig(&pam.Config{Enabled: false}),
|
||||
SetBPF(&bpf.NOP{}),
|
||||
SetClock(f.clock),
|
||||
@@ -1234,7 +1234,7 @@ func TestLimiter(t *testing.T) {
|
||||
SetShell("/bin/sh"),
|
||||
SetSessionServer(nodeClient),
|
||||
SetEmitter(nodeClient),
|
||||
SetNamespace(defaults.Namespace),
|
||||
SetNamespace(apidefaults.Namespace),
|
||||
SetPAMConfig(&pam.Config{Enabled: false}),
|
||||
SetBPF(&bpf.NOP{}),
|
||||
SetClock(f.clock),
|
||||
|
||||
@@ -1,50 +0,0 @@
|
||||
/*
|
||||
Copyright 2021 Gravitational, Inc.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package utils
|
||||
|
||||
import (
|
||||
"github.com/gravitational/teleport/api/utils"
|
||||
)
|
||||
|
||||
// The following util functions have been moved to /api/utils, and are now
|
||||
// imported here for backwards compatibility.
|
||||
|
||||
// slices.go
|
||||
var (
|
||||
CopyByteSlice = utils.CopyByteSlice
|
||||
CopyByteSlices = utils.CopyByteSlices
|
||||
StringSlicesEqual = utils.StringSlicesEqual
|
||||
SliceContainsStr = utils.SliceContainsStr
|
||||
Deduplicate = utils.Deduplicate
|
||||
)
|
||||
|
||||
// strings.go
|
||||
type Strings = utils.Strings
|
||||
|
||||
var CopyStrings = utils.CopyStrings
|
||||
|
||||
// time.go
|
||||
var (
|
||||
UTC = utils.UTC
|
||||
HumanTimeFormatString = utils.HumanTimeFormatString
|
||||
HumanTimeFormat = utils.HumanTimeFormat
|
||||
)
|
||||
|
||||
// utils.go
|
||||
var (
|
||||
ParseBool = utils.ParseBool
|
||||
)
|
||||
+4
-2
@@ -34,7 +34,9 @@ import (
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/modules"
|
||||
|
||||
"github.com/gravitational/trace"
|
||||
"github.com/pborman/uuid"
|
||||
log "github.com/sirupsen/logrus"
|
||||
@@ -174,7 +176,7 @@ func AsBool(v string) bool {
|
||||
if v == "" {
|
||||
return false
|
||||
}
|
||||
out, _ := ParseBool(v)
|
||||
out, _ := apiutils.ParseBool(v)
|
||||
return out
|
||||
}
|
||||
|
||||
@@ -529,7 +531,7 @@ func CheckCertificateFormatFlag(s string) (string, error) {
|
||||
}
|
||||
|
||||
// AddrsFromStrings returns strings list converted to address list
|
||||
func AddrsFromStrings(s Strings, defaultPort int) ([]NetAddr, error) {
|
||||
func AddrsFromStrings(s apiutils.Strings, defaultPort int) ([]NetAddr, error) {
|
||||
addrs := make([]NetAddr, len(s))
|
||||
for i, val := range s {
|
||||
addr, err := ParseHostPortAddr(val, defaultPort)
|
||||
|
||||
@@ -27,6 +27,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gravitational/teleport"
|
||||
apiutils "github.com/gravitational/teleport/api/utils"
|
||||
"github.com/gravitational/teleport/lib/fixtures"
|
||||
|
||||
"github.com/stretchr/testify/require"
|
||||
@@ -130,14 +131,14 @@ func (s *UtilsSuite) TestRandomDuration(c *check.C) {
|
||||
|
||||
func (s *UtilsSuite) TestMiscFunctions(c *check.C) {
|
||||
// SliceContainsStr
|
||||
c.Assert(SliceContainsStr([]string{"two", "one"}, "one"), check.Equals, true)
|
||||
c.Assert(SliceContainsStr([]string{"two", "one"}, "five"), check.Equals, false)
|
||||
c.Assert(SliceContainsStr([]string(nil), "one"), check.Equals, false)
|
||||
c.Assert(apiutils.SliceContainsStr([]string{"two", "one"}, "one"), check.Equals, true)
|
||||
c.Assert(apiutils.SliceContainsStr([]string{"two", "one"}, "five"), check.Equals, false)
|
||||
c.Assert(apiutils.SliceContainsStr([]string(nil), "one"), check.Equals, false)
|
||||
|
||||
// Deduplicate
|
||||
c.Assert(Deduplicate([]string{}), check.DeepEquals, []string{})
|
||||
c.Assert(Deduplicate([]string{"a", "b"}), check.DeepEquals, []string{"a", "b"})
|
||||
c.Assert(Deduplicate([]string{"a", "b", "b", "a", "c"}), check.DeepEquals, []string{"a", "b", "c"})
|
||||
c.Assert(apiutils.Deduplicate([]string{}), check.DeepEquals, []string{})
|
||||
c.Assert(apiutils.Deduplicate([]string{"a", "b"}), check.DeepEquals, []string{"a", "b"})
|
||||
c.Assert(apiutils.Deduplicate([]string{"a", "b", "b", "a", "c"}), check.DeepEquals, []string{"a", "b", "c"})
|
||||
|
||||
// RemoveFromSlice
|
||||
c.Assert(RemoveFromSlice([]string{}, "a"), check.DeepEquals, []string{})
|
||||
|
||||
@@ -39,6 +39,7 @@ import (
|
||||
"github.com/gravitational/teleport/api/client/proto"
|
||||
"github.com/gravitational/teleport/api/client/webclient"
|
||||
"github.com/gravitational/teleport/api/constants"
|
||||
apidefaults "github.com/gravitational/teleport/api/defaults"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
apievents "github.com/gravitational/teleport/api/types/events"
|
||||
"github.com/gravitational/teleport/lib/auth"
|
||||
@@ -1968,7 +1969,7 @@ func (h *Handler) clusterSearchEvents(w http.ResponseWriter, r *http.Request, p
|
||||
eventTypes = strings.Split(include, ";")
|
||||
}
|
||||
|
||||
rawEvents, _, err := clt.SearchEvents(from, to, defaults.Namespace, eventTypes, limit, "")
|
||||
rawEvents, _, err := clt.SearchEvents(from, to, apidefaults.Namespace, eventTypes, limit, "")
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user