Updated docker-based example

This commit is contained in:
Ev Kontsevoy
2017-02-23 21:45:13 -08:00
parent 4c5ac2e3c2
commit 4f5ac31e6b
5 changed files with 73 additions and 37 deletions
+7 -2
View File
@@ -1,4 +1,9 @@
PS1='\[\033[33;1m\]container(\h)\[\033[0;33m\] \w\[\033[00m\]: '
PATH=$PATH:/teleport/build
export PS1='\[\033[33;1m\]container(\h)\[\033[0;33m\] \w\[\033[00m\]: '
export PATH=$PATH:/teleport/build
export LS_COLORS="rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=40;31;01:mi=00:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.Z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.jpg=01;35:*.jpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.aac=00;36:*.au=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36:"
alias ls="ls --color=auto"
alias ll="ls -alF"
# quick way to get into teleport repo dir
alias t="cd $HOME/go/src/github.com/gravitational/teleport"
+53 -34
View File
@@ -1,6 +1,6 @@
TELEBOX=teleport:latest
HOMEDIR=$(abspath ..)
CONTAINERHOME=/root/go/src/github.com/gravitational/teleport
CONTAINERHOME=/root/go/src/github.com/gravitational/teleport
THISDIR=`pwd`
NETNAME=telenet
DOCKEROPS=--net $(NETNAME) -w $(CONTAINERHOME) -v $(HOMEDIR):$(CONTAINERHOME)
@@ -9,42 +9,17 @@ DOCKEROPS=--net $(NETNAME) -w $(CONTAINERHOME) -v $(HOMEDIR):$(CONTAINERHOME)
# Default target starts two Teleport clusters
#
.PHONY:run
run:
# create a docker Teleport image and a network
docker build -t $(TELEBOX) .
docker network create --subnet=172.10.0.0/16 $(NETNAME)
mkdir -p data/one data/two/proxy data/two/node data/two/auth
# start the single-node cluster named "one"
docker run --name=one --detach=true \
--hostname one \
--ip 172.10.1.1 \
--publish 3080:3080 -p 3023:3023 \
--volume $(THISDIR)/data/one:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/one.yaml
# start three-node cluster named "two"
docker run --name=two-auth --detach=true \
--hostname two-auth \
--ip 172.10.1.2 \
--volume $(THISDIR)/data/two/auth:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-auth.yaml
docker run --name=two-proxy --detach=true \
--hostname two-proxy \
--ip 172.10.1.3 \
--publish 5080:5080 -p 5023:5023 \
--volume $(THISDIR)/data/two/proxy:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-proxy.yaml
docker run --name=two-node --detach=true \
--hostname two-node \
--ip 172.10.1.4 \
--volume $(THISDIR)/data/two/node:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-node.yaml
run: prepare
$(MAKE) one
$(MAKE) two
# 'make stop' stops all Teleport containers, deletes them
# and their network
#
.PHONY:stop
stop:
-@docker rm -f one two-auth two-proxy two-node
$(MAKE) stop-one
$(MAKE) stop-two
-@docker network rm $(NETNAME)
# `make enter-one` gives you shell inside auth server
@@ -66,12 +41,56 @@ enter-two:
# without Teleport running. Useful if you want to start it manually
# from the inside
.PHONY:shell
shell:
docker build -t $(TELEBOX) .
-docker network create --subnet=172.10.0.0/16 $(NETNAME)
shell: prepare
-docker run --name=one --rm=true -ti \
--hostname one \
--ip 172.10.1.1 \
--volume $(THISDIR)/data/one:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) /bin/bash
-docker network rm $(NETNAME)
# `make one` starts the "One" container with single-node Teleport cluster
.PHONY:one
one:
docker run --name=one --detach=true \
--hostname one \
--ip 172.10.1.1 \
--publish 3080:3080 -p 3023:3023 \
--volume $(THISDIR)/data/one:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/one.yaml
# 'make two' starts the three-node cluster in a container named "two"
.PHONY:two
two:
docker run --name=two-auth --detach=true \
--hostname two-auth \
--ip 172.10.1.2 \
--volume $(THISDIR)/data/two/auth:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-auth.yaml
docker run --name=two-proxy --detach=true \
--hostname two-proxy \
--ip 172.10.1.3 \
--publish 5080:5080 -p 5023:5023 \
--volume $(THISDIR)/data/two/proxy:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-proxy.yaml
docker run --name=two-node --detach=true \
--hostname two-node \
--ip 172.10.1.4 \
--volume $(THISDIR)/data/two/node:/var/lib/teleport \
$(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-node.yaml
# prepare is a sub-target: it creates a container image and a network
.PHONY:prepare
prepare:
docker build -t $(TELEBOX) .
-docker network create --subnet=172.10.0.0/16 $(NETNAME)
mkdir -p data/one data/two/proxy data/two/node data/two/auth
.PHONY:stop-two
stop-two:
docker rm -f two-auth two-proxy two-node
.PHONY:stop-one
stop-one:
docker rm -f one
+4
View File
@@ -10,6 +10,10 @@ auth_service:
cluster_name: one
tokens:
- "node,auth,proxy:xxx"
# to enable trusted clusters, execute `tctl auth export > data/two/two.ca` inside container "two-auth"
# and then uncomment this and restart container "one"
#trusted_clusters:
# - key_file: /root/go/src/github.com/gravitational/teleport/docker/data/two/two.ca
ssh_service:
enabled: yes
+8
View File
@@ -10,6 +10,14 @@ auth_service:
cluster_name: two
tokens:
- "node,auth,proxy:xxx"
listen_addr: 172.10.1.2:3025
# to enable trusted clusters, execute `tctl auth export > data/one/one.ca` inside container "one"
# and then uncomment this and restart container "two-auth"
#trusted_clusters:
# - key_file: /root/go/src/github.com/gravitational/teleport/docker/data/one/one.ca
# allow_logins: root
# tunnel_addr: one
ssh_service:
enabled: yes
+1 -1
View File
@@ -1,6 +1,6 @@
# Dumb SSH node for cluster "two"
teleport:
nodename: two-node
nodename: node-on-second-cluster
auth_servers: ["two-auth"]
auth_token: xxx
log: