From 4f5ac31e6b1a19fb8c19f2e9d75f3724468e05f5 Mon Sep 17 00:00:00 2001 From: Ev Kontsevoy Date: Thu, 23 Feb 2017 21:45:13 -0800 Subject: [PATCH] Updated docker-based example --- docker/.bashrc | 9 ++++- docker/Makefile | 87 +++++++++++++++++++++++++++----------------- docker/one.yaml | 4 ++ docker/two-auth.yaml | 8 ++++ docker/two-node.yaml | 2 +- 5 files changed, 73 insertions(+), 37 deletions(-) diff --git a/docker/.bashrc b/docker/.bashrc index 3f9023a9754..23ddb992333 100644 --- a/docker/.bashrc +++ b/docker/.bashrc @@ -1,4 +1,9 @@ -PS1='\[\033[33;1m\]container(\h)\[\033[0;33m\] \w\[\033[00m\]: ' -PATH=$PATH:/teleport/build +export PS1='\[\033[33;1m\]container(\h)\[\033[0;33m\] \w\[\033[00m\]: ' +export PATH=$PATH:/teleport/build +export LS_COLORS="rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=40;31;01:mi=00:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.Z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.jpg=01;35:*.jpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.aac=00;36:*.au=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36:" + alias ls="ls --color=auto" alias ll="ls -alF" + +# quick way to get into teleport repo dir +alias t="cd $HOME/go/src/github.com/gravitational/teleport" diff --git a/docker/Makefile b/docker/Makefile index 415a43030d4..3f24d72c828 100644 --- a/docker/Makefile +++ b/docker/Makefile @@ -1,6 +1,6 @@ TELEBOX=teleport:latest HOMEDIR=$(abspath ..) -CONTAINERHOME=/root/go/src/github.com/gravitational/teleport +CONTAINERHOME=/root/go/src/github.com/gravitational/teleport THISDIR=`pwd` NETNAME=telenet DOCKEROPS=--net $(NETNAME) -w $(CONTAINERHOME) -v $(HOMEDIR):$(CONTAINERHOME) @@ -9,42 +9,17 @@ DOCKEROPS=--net $(NETNAME) -w $(CONTAINERHOME) -v $(HOMEDIR):$(CONTAINERHOME) # Default target starts two Teleport clusters # .PHONY:run -run: - # create a docker Teleport image and a network - docker build -t $(TELEBOX) . - docker network create --subnet=172.10.0.0/16 $(NETNAME) - mkdir -p data/one data/two/proxy data/two/node data/two/auth - # start the single-node cluster named "one" - docker run --name=one --detach=true \ - --hostname one \ - --ip 172.10.1.1 \ - --publish 3080:3080 -p 3023:3023 \ - --volume $(THISDIR)/data/one:/var/lib/teleport \ - $(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/one.yaml - # start three-node cluster named "two" - docker run --name=two-auth --detach=true \ - --hostname two-auth \ - --ip 172.10.1.2 \ - --volume $(THISDIR)/data/two/auth:/var/lib/teleport \ - $(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-auth.yaml - docker run --name=two-proxy --detach=true \ - --hostname two-proxy \ - --ip 172.10.1.3 \ - --publish 5080:5080 -p 5023:5023 \ - --volume $(THISDIR)/data/two/proxy:/var/lib/teleport \ - $(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-proxy.yaml - docker run --name=two-node --detach=true \ - --hostname two-node \ - --ip 172.10.1.4 \ - --volume $(THISDIR)/data/two/node:/var/lib/teleport \ - $(DOCKEROPS) $(TELEBOX) build/teleport start -c /teleport/docker/two-node.yaml +run: prepare + $(MAKE) one + $(MAKE) two # 'make stop' stops all Teleport containers, deletes them # and their network # .PHONY:stop stop: - -@docker rm -f one two-auth two-proxy two-node + $(MAKE) stop-one + $(MAKE) stop-two -@docker network rm $(NETNAME) # `make enter-one` gives you shell inside auth server @@ -66,12 +41,56 @@ enter-two: # without Teleport running. Useful if you want to start it manually # from the inside .PHONY:shell -shell: - docker build -t $(TELEBOX) . - -docker network create --subnet=172.10.0.0/16 $(NETNAME) +shell: prepare -docker run --name=one --rm=true -ti \ --hostname one \ --ip 172.10.1.1 \ --volume $(THISDIR)/data/one:/var/lib/teleport \ $(DOCKEROPS) $(TELEBOX) /bin/bash -docker network rm $(NETNAME) + +# `make one` starts the "One" container with single-node Teleport cluster +.PHONY:one +one: + docker run --name=one --detach=true \ + --hostname one \ + --ip 172.10.1.1 \ + --publish 3080:3080 -p 3023:3023 \ + --volume $(THISDIR)/data/one:/var/lib/teleport \ + $(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/one.yaml + +# 'make two' starts the three-node cluster in a container named "two" +.PHONY:two +two: + docker run --name=two-auth --detach=true \ + --hostname two-auth \ + --ip 172.10.1.2 \ + --volume $(THISDIR)/data/two/auth:/var/lib/teleport \ + $(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-auth.yaml + docker run --name=two-proxy --detach=true \ + --hostname two-proxy \ + --ip 172.10.1.3 \ + --publish 5080:5080 -p 5023:5023 \ + --volume $(THISDIR)/data/two/proxy:/var/lib/teleport \ + $(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-proxy.yaml + docker run --name=two-node --detach=true \ + --hostname two-node \ + --ip 172.10.1.4 \ + --volume $(THISDIR)/data/two/node:/var/lib/teleport \ + $(DOCKEROPS) $(TELEBOX) build/teleport start -c $(CONTAINERHOME)/docker/two-node.yaml + + +# prepare is a sub-target: it creates a container image and a network +.PHONY:prepare +prepare: + docker build -t $(TELEBOX) . + -docker network create --subnet=172.10.0.0/16 $(NETNAME) + mkdir -p data/one data/two/proxy data/two/node data/two/auth + +.PHONY:stop-two +stop-two: + docker rm -f two-auth two-proxy two-node + +.PHONY:stop-one +stop-one: + docker rm -f one diff --git a/docker/one.yaml b/docker/one.yaml index fd26010daef..3bcd5dc803f 100644 --- a/docker/one.yaml +++ b/docker/one.yaml @@ -10,6 +10,10 @@ auth_service: cluster_name: one tokens: - "node,auth,proxy:xxx" + # to enable trusted clusters, execute `tctl auth export > data/two/two.ca` inside container "two-auth" + # and then uncomment this and restart container "one" + #trusted_clusters: + # - key_file: /root/go/src/github.com/gravitational/teleport/docker/data/two/two.ca ssh_service: enabled: yes diff --git a/docker/two-auth.yaml b/docker/two-auth.yaml index b7edce142f8..d92738241fd 100644 --- a/docker/two-auth.yaml +++ b/docker/two-auth.yaml @@ -10,6 +10,14 @@ auth_service: cluster_name: two tokens: - "node,auth,proxy:xxx" + listen_addr: 172.10.1.2:3025 + + # to enable trusted clusters, execute `tctl auth export > data/one/one.ca` inside container "one" + # and then uncomment this and restart container "two-auth" + #trusted_clusters: + # - key_file: /root/go/src/github.com/gravitational/teleport/docker/data/one/one.ca + # allow_logins: root + # tunnel_addr: one ssh_service: enabled: yes diff --git a/docker/two-node.yaml b/docker/two-node.yaml index 93a6cca0b2a..d0285ef9e58 100644 --- a/docker/two-node.yaml +++ b/docker/two-node.yaml @@ -1,6 +1,6 @@ # Dumb SSH node for cluster "two" teleport: - nodename: two-node + nodename: node-on-second-cluster auth_servers: ["two-auth"] auth_token: xxx log: