mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Updated docker-based example
This commit is contained in:
+7
-2
@@ -1,4 +1,9 @@
|
||||
PS1='\[\033[33;1m\]container(\h)\[\033[0;33m\] \w\[\033[00m\]: '
|
||||
PATH=$PATH:/teleport/build
|
||||
export PS1='\[\033[33;1m\]container(\h)\[\033[0;33m\] \w\[\033[00m\]: '
|
||||
export PATH=$PATH:/teleport/build
|
||||
export LS_COLORS="rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=40;31;01:mi=00:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.Z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.jpg=01;35:*.jpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.aac=00;36:*.au=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36:"
|
||||
|
||||
alias ls="ls --color=auto"
|
||||
alias ll="ls -alF"
|
||||
|
||||
# quick way to get into teleport repo dir
|
||||
alias t="cd $HOME/go/src/github.com/gravitational/teleport"
|
||||
|
||||
+53
-34
@@ -1,6 +1,6 @@
|
||||
TELEBOX=teleport:latest
|
||||
HOMEDIR=$(abspath ..)
|
||||
CONTAINERHOME=/root/go/src/github.com/gravitational/teleport
|
||||
CONTAINERHOME=/root/go/src/github.com/gravitational/teleport
|
||||
THISDIR=`pwd`
|
||||
NETNAME=telenet
|
||||
DOCKEROPS=--net $(NETNAME) -w $(CONTAINERHOME) -v $(HOMEDIR):$(CONTAINERHOME)
|
||||
@@ -9,42 +9,17 @@ DOCKEROPS=--net $(NETNAME) -w $(CONTAINERHOME) -v $(HOMEDIR):$(CONTAINERHOME)
|
||||
# Default target starts two Teleport clusters
|
||||
#
|
||||
.PHONY:run
|
||||
run:
|
||||
# create a docker Teleport image and a network
|
||||
docker build -t $(TELEBOX) .
|
||||
docker network create --subnet=172.10.0.0/16 $(NETNAME)
|
||||
mkdir -p data/one data/two/proxy data/two/node data/two/auth
|
||||
# start the single-node cluster named "one"
|
||||
docker run --name=one --detach=true \
|
||||
--hostname one \
|
||||
--ip 172.10.1.1 \
|
||||
--publish 3080:3080 -p 3023:3023 \
|
||||
--volume $(THISDIR)/data/one:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/one.yaml
|
||||
# start three-node cluster named "two"
|
||||
docker run --name=two-auth --detach=true \
|
||||
--hostname two-auth \
|
||||
--ip 172.10.1.2 \
|
||||
--volume $(THISDIR)/data/two/auth:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-auth.yaml
|
||||
docker run --name=two-proxy --detach=true \
|
||||
--hostname two-proxy \
|
||||
--ip 172.10.1.3 \
|
||||
--publish 5080:5080 -p 5023:5023 \
|
||||
--volume $(THISDIR)/data/two/proxy:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-proxy.yaml
|
||||
docker run --name=two-node --detach=true \
|
||||
--hostname two-node \
|
||||
--ip 172.10.1.4 \
|
||||
--volume $(THISDIR)/data/two/node:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-node.yaml
|
||||
run: prepare
|
||||
$(MAKE) one
|
||||
$(MAKE) two
|
||||
|
||||
# 'make stop' stops all Teleport containers, deletes them
|
||||
# and their network
|
||||
#
|
||||
.PHONY:stop
|
||||
stop:
|
||||
-@docker rm -f one two-auth two-proxy two-node
|
||||
$(MAKE) stop-one
|
||||
$(MAKE) stop-two
|
||||
-@docker network rm $(NETNAME)
|
||||
|
||||
# `make enter-one` gives you shell inside auth server
|
||||
@@ -66,12 +41,56 @@ enter-two:
|
||||
# without Teleport running. Useful if you want to start it manually
|
||||
# from the inside
|
||||
.PHONY:shell
|
||||
shell:
|
||||
docker build -t $(TELEBOX) .
|
||||
-docker network create --subnet=172.10.0.0/16 $(NETNAME)
|
||||
shell: prepare
|
||||
-docker run --name=one --rm=true -ti \
|
||||
--hostname one \
|
||||
--ip 172.10.1.1 \
|
||||
--volume $(THISDIR)/data/one:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) /bin/bash
|
||||
-docker network rm $(NETNAME)
|
||||
|
||||
# `make one` starts the "One" container with single-node Teleport cluster
|
||||
.PHONY:one
|
||||
one:
|
||||
docker run --name=one --detach=true \
|
||||
--hostname one \
|
||||
--ip 172.10.1.1 \
|
||||
--publish 3080:3080 -p 3023:3023 \
|
||||
--volume $(THISDIR)/data/one:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/one.yaml
|
||||
|
||||
# 'make two' starts the three-node cluster in a container named "two"
|
||||
.PHONY:two
|
||||
two:
|
||||
docker run --name=two-auth --detach=true \
|
||||
--hostname two-auth \
|
||||
--ip 172.10.1.2 \
|
||||
--volume $(THISDIR)/data/two/auth:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-auth.yaml
|
||||
docker run --name=two-proxy --detach=true \
|
||||
--hostname two-proxy \
|
||||
--ip 172.10.1.3 \
|
||||
--publish 5080:5080 -p 5023:5023 \
|
||||
--volume $(THISDIR)/data/two/proxy:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-proxy.yaml
|
||||
docker run --name=two-node --detach=true \
|
||||
--hostname two-node \
|
||||
--ip 172.10.1.4 \
|
||||
--volume $(THISDIR)/data/two/node:/var/lib/teleport \
|
||||
$(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-node.yaml
|
||||
|
||||
|
||||
# prepare is a sub-target: it creates a container image and a network
|
||||
.PHONY:prepare
|
||||
prepare:
|
||||
docker build -t $(TELEBOX) .
|
||||
-docker network create --subnet=172.10.0.0/16 $(NETNAME)
|
||||
mkdir -p data/one data/two/proxy data/two/node data/two/auth
|
||||
|
||||
.PHONY:stop-two
|
||||
stop-two:
|
||||
docker rm -f two-auth two-proxy two-node
|
||||
|
||||
.PHONY:stop-one
|
||||
stop-one:
|
||||
docker rm -f one
|
||||
|
||||
@@ -10,6 +10,10 @@ auth_service:
|
||||
cluster_name: one
|
||||
tokens:
|
||||
- "node,auth,proxy:xxx"
|
||||
# to enable trusted clusters, execute `tctl auth export > data/two/two.ca` inside container "two-auth"
|
||||
# and then uncomment this and restart container "one"
|
||||
#trusted_clusters:
|
||||
# - key_file: /root/go/src/github.com/gravitational/teleport/docker/data/two/two.ca
|
||||
|
||||
ssh_service:
|
||||
enabled: yes
|
||||
|
||||
@@ -10,6 +10,14 @@ auth_service:
|
||||
cluster_name: two
|
||||
tokens:
|
||||
- "node,auth,proxy:xxx"
|
||||
listen_addr: 172.10.1.2:3025
|
||||
|
||||
# to enable trusted clusters, execute `tctl auth export > data/one/one.ca` inside container "one"
|
||||
# and then uncomment this and restart container "two-auth"
|
||||
#trusted_clusters:
|
||||
# - key_file: /root/go/src/github.com/gravitational/teleport/docker/data/one/one.ca
|
||||
# allow_logins: root
|
||||
# tunnel_addr: one
|
||||
|
||||
ssh_service:
|
||||
enabled: yes
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Dumb SSH node for cluster "two"
|
||||
teleport:
|
||||
nodename: two-node
|
||||
nodename: node-on-second-cluster
|
||||
auth_servers: ["two-auth"]
|
||||
auth_token: xxx
|
||||
log:
|
||||
|
||||
Reference in New Issue
Block a user