mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-21 05:55:42 +08:00
Edit the Feature Matrix docs page (#53724)
* Edit the Feature Matrix docs page Reflect the latest messaging guidance around Teleport products and capabilities. * Edit Feature Matrix formatting - Expand the first column and narrow the final three columns. - Use paragraphs for subsections of Teleport Zero Trust Access * Add br tags before Feature Matrix paragraphs This way, paragraphs that are supposed to divide the Zero Trust Access table into subsections are easier to pick out from the tables they divide. We can use this approach until we introduce a plugin to allow colspans. * Respond to roraback feedback - Fix empty SSO cell - Fix empty "Machines" cells - Fix empty Access Requests cell - Remove "Teleport" from table headers * Include table subsections as shaded rows Edit the Feature Matrix page to: - Shorten table section descriptions - Use a style tag to shade certain rows of the first and final tables * Fix spelling * Fix absolute links in the Feature Matrix * Add missing feature matrix features Add two items to the Identity Governance section
This commit is contained in:
+17
-14
@@ -2,17 +2,8 @@
|
||||
"language": "en",
|
||||
"version": "0.2",
|
||||
"words": [
|
||||
"aabbccddeegg",
|
||||
"aada",
|
||||
"abee",
|
||||
"awsic",
|
||||
"fffc",
|
||||
"fabfc",
|
||||
"microservices",
|
||||
"configmaps",
|
||||
"genrsa",
|
||||
"displayname",
|
||||
"AADUSER",
|
||||
"ABAC",
|
||||
"ABCDEFGHIJKL",
|
||||
"ADFS",
|
||||
"AICPA",
|
||||
@@ -50,7 +41,6 @@
|
||||
"Callouts",
|
||||
"Cgajq",
|
||||
"DBSIZE",
|
||||
"dbus",
|
||||
"DBUS",
|
||||
"DEBU",
|
||||
"DHDR",
|
||||
@@ -110,6 +100,7 @@
|
||||
"IPSANs",
|
||||
"IQMHY",
|
||||
"IRSA",
|
||||
"ITSM",
|
||||
"Ijoi",
|
||||
"Imlzcy",
|
||||
"Infoblox",
|
||||
@@ -218,6 +209,7 @@
|
||||
"SUPATH",
|
||||
"SVID",
|
||||
"SVIDs",
|
||||
"Secretless",
|
||||
"Shockbyte",
|
||||
"Silverfort's",
|
||||
"Slackbot",
|
||||
@@ -256,6 +248,7 @@
|
||||
"Vhka",
|
||||
"Vitess",
|
||||
"Vybm",
|
||||
"WIMSE",
|
||||
"WWFCX",
|
||||
"WXJKZ",
|
||||
"Wdss",
|
||||
@@ -273,7 +266,10 @@
|
||||
"ZRDU",
|
||||
"Zqar",
|
||||
"Zrpsaln",
|
||||
"aabbccddeegg",
|
||||
"aada",
|
||||
"abcdefghijklm",
|
||||
"abee",
|
||||
"accesslist",
|
||||
"acfs",
|
||||
"aclfile",
|
||||
@@ -331,6 +327,7 @@
|
||||
"awscli",
|
||||
"awsconsole",
|
||||
"awsdatabases",
|
||||
"awsic",
|
||||
"awskms",
|
||||
"awsoidc",
|
||||
"awsuser",
|
||||
@@ -403,9 +400,10 @@
|
||||
"compu",
|
||||
"cond",
|
||||
"configmap",
|
||||
"connstring",
|
||||
"configmaps",
|
||||
"connectionupgrade",
|
||||
"connectorname",
|
||||
"connstring",
|
||||
"cprops",
|
||||
"cqlsh",
|
||||
"createkey",
|
||||
@@ -430,6 +428,7 @@
|
||||
"dbgroup",
|
||||
"dbname",
|
||||
"dbreviewer",
|
||||
"dbus",
|
||||
"dbuser",
|
||||
"deanonymize",
|
||||
"deletecollection",
|
||||
@@ -443,6 +442,7 @@
|
||||
"disablerepo",
|
||||
"disablesse",
|
||||
"disenroll",
|
||||
"displayname",
|
||||
"distros",
|
||||
"docdb",
|
||||
"dockerhost",
|
||||
@@ -494,6 +494,7 @@
|
||||
"extfile",
|
||||
"extraargs",
|
||||
"extraenv",
|
||||
"fabfc",
|
||||
"fakehost",
|
||||
"fakekey",
|
||||
"fdpass",
|
||||
@@ -501,6 +502,7 @@
|
||||
"fedmeatadataxml",
|
||||
"fedramp",
|
||||
"fedrampfips",
|
||||
"fffc",
|
||||
"fips",
|
||||
"firstname",
|
||||
"fklvk",
|
||||
@@ -516,6 +518,7 @@
|
||||
"gcpproj",
|
||||
"gecos",
|
||||
"genpkey",
|
||||
"genrsa",
|
||||
"getent",
|
||||
"getstring",
|
||||
"gitref",
|
||||
@@ -652,6 +655,7 @@
|
||||
"metadataaws",
|
||||
"metav",
|
||||
"microk",
|
||||
"microservices",
|
||||
"minikube",
|
||||
"minikube's",
|
||||
"mkstore",
|
||||
@@ -935,8 +939,8 @@
|
||||
"teleportdevprotocol",
|
||||
"teleporters",
|
||||
"teleportgithubconnector",
|
||||
"teleportinfra",
|
||||
"teleporthostname",
|
||||
"teleportinfra",
|
||||
"teleportopensshserverv",
|
||||
"teleportproxy",
|
||||
"teleportrolesv",
|
||||
@@ -1017,7 +1021,6 @@
|
||||
"webproxy",
|
||||
"webui",
|
||||
"westeurope",
|
||||
"WIMSE",
|
||||
"winadj",
|
||||
"windowsaccountname",
|
||||
"windowsdesktop",
|
||||
|
||||
+142
-72
@@ -6,98 +6,168 @@ description: Provides a comparison of features available in Teleport products.
|
||||
The Teleport feature matrix lists capabilities of the Teleport Infrastructure
|
||||
Identity Platform, organized by product.
|
||||
|
||||
{/*Since the feature matrix includes multiple tables, set a fixed cell width to
|
||||
ensure that all tables are aligned.*/}
|
||||
{/*The Feature Matrix table has unique requirements, so include styling in an
|
||||
HTML tag until we can support these requirements some other way.*/}
|
||||
<style dangerouslySetInnerHTML={{__html: `
|
||||
/*
|
||||
Shade certain rows the color of the cell dividers to provide the illusion of
|
||||
column spans until the docs engine supports them in Markdown tables. We need
|
||||
to update this list whenever we change the organization of the tables.
|
||||
*/
|
||||
table:nth-of-type(1) tbody tr:nth-of-type(1),
|
||||
table:nth-of-type(1) tbody tr:nth-of-type(5),
|
||||
table:nth-of-type(1) tbody tr:nth-of-type(7),
|
||||
table:nth-of-type(1) tbody tr:nth-of-type(14),
|
||||
table:nth-of-type(1) tbody tr:nth-of-type(17),
|
||||
table:nth-of-type(1) tbody tr:nth-of-type(25),
|
||||
table:nth-of-type(1) tbody tr:nth-of-type(28),
|
||||
table:nth-of-type(5) tbody tr:nth-of-type(1),
|
||||
table:nth-of-type(5) tbody tr:nth-of-type(9),
|
||||
table:nth-of-type(5) tbody tr:nth-of-type(19)
|
||||
{
|
||||
background: #dddddd;
|
||||
}
|
||||
|
||||
/*
|
||||
Since the feature matrix includes multiple tables, set a fixed cell
|
||||
width to ensure that all tables are aligned.
|
||||
*/
|
||||
table {
|
||||
table-layout: fixed;
|
||||
}
|
||||
|
||||
table td {
|
||||
width: 25%;
|
||||
}`}}
|
||||
th, td {
|
||||
width: 18%;
|
||||
}
|
||||
|
||||
th:first-child, td:first-child {
|
||||
width: 46%;
|
||||
}
|
||||
`
|
||||
}}
|
||||
/>
|
||||
|
||||
The **Teleport Identity Infrastructure Platform** modernizes identity, access,
|
||||
and policy for infrastructure, for both human and non-human identities. Products
|
||||
include:
|
||||
|
||||
- [Teleport Zero Trust Access](#teleport-zero-trust-access)
|
||||
- [Teleport Machine & Workload Identity](#teleport-machine--workload-identity)
|
||||
- [Teleport Identity Governance](#teleport-identity-governance)
|
||||
- [Teleport Identity Security](#teleport-identity-security)
|
||||
|
||||
## Teleport Zero Trust Access
|
||||
|
||||
||[Teleport Enterprise (Cloud)](#teleport-editions)|[Teleport Enterprise (Self-Hosted)](#teleport-editions)|[Teleport Community Edition](#teleport-editions)|
|
||||
|---|:---:|:---:|:---:|
|
||||
|Agentless Integration with [OpenSSH Servers](./enroll-resources/server-access/openssh/openssh-agentless.mdx)|✔|✔|✔|
|
||||
|[Dual Authorization](./admin-guides/access-controls/guides/dual-authz.mdx)|✔|✔|✖|
|
||||
|[Enhanced Session Recording](./enroll-resources/server-access/guides/bpf-session-recording.mdx)|✔|✔|✔|
|
||||
|[FedRAMP Control](./admin-guides/access-controls/compliance-frameworks/fedramp.mdx)|✖|✔|✖|
|
||||
|FIPS-compliant binaries available for FedRAMP High|✖|✔|✖|
|
||||
|IP-Based Restrictions|✔|✔|✖|
|
||||
|[Moderated Sessions](./admin-guides/access-controls/guides/joining-sessions.mdx)|✔|✔|✖|
|
||||
|PCI DSS Features|✔|✔|Limited|
|
||||
|[Protecting Applications](./enroll-resources/application-access/getting-started.mdx)|✔|✔|✔|
|
||||
|[Protecting Databases](./enroll-resources/database-access/getting-started.mdx)|✔|✔|✔|
|
||||
|[Protecting Kubernetes Clusters](./enroll-resources/kubernetes-access/getting-started.mdx)|✔|✔|✔|
|
||||
|[Protecting Linux Servers](./enroll-resources/server-access/getting-started.mdx)|✔|✔|✔|
|
||||
|[Protecting Windows Desktops](./enroll-resources/desktop-access/introduction.mdx)|✔|✔|✔|
|
||||
|[Recording Proxy Mode](./enroll-resources/server-access/guides/recording-proxy-mode.mdx)|✖|✔|✔|
|
||||
|[Role-Based Access Control](./admin-guides/access-controls/guides/role-templates.mdx)|✔|✔|✔|
|
||||
|[Session Recording with Playback](./reference/architecture/session-recording.mdx)|✔|✔|✔|
|
||||
|[Single Sign-On](./admin-guides/access-controls/sso/sso.mdx)|GitHub, Google Workspace, OIDC, SAML, Teleport|GitHub, Google Workspace, OIDC, SAML, Teleport|GitHub|
|
||||
|SOC 2 Features|✔|✔|Limited|
|
||||
|[Structured Audit Logs](./reference/monitoring/audit.mdx)|✔|✔|✔|
|
||||
**Teleport Zero Trust Access** provides engineers with least privileged access
|
||||
to applications, servers, databases, Kubernetes clusters, and other resources
|
||||
across distributed infrastructures.
|
||||
|
||||
## Teleport Identity Governance
|
||||
|
||||
||[Teleport Enterprise (Cloud)](#teleport-editions)|[Teleport Enterprise (Self-Hosted)](#teleport-editions)|[Teleport Community Edition](#teleport-editions)|
|
||||
| | **Enterprise (Cloud)** | **Enterprise (Self-Hosted)** | **Community Edition** |
|
||||
|---|:---:|:---:|:---:|
|
||||
|[Access Lists & Access Reviews](./admin-guides/access-controls/access-lists/access-lists.mdx)|✔|✔|✖|
|
||||
|[Access Monitoring & Response](./admin-guides/access-controls/access-monitoring.mdx)|✔|✔|✖|
|
||||
|[Device Trust](./admin-guides/access-controls/device-trust/guide.mdx)|✔|✔|✖|
|
||||
|[Endpoint Management: Jamf](./admin-guides/access-controls/device-trust/jamf-integration.mdx)|✔|✔|✖|
|
||||
|[Hardware Key Support](./admin-guides/access-controls/guides/hardware-key-support.mdx)|✔|✔|✖|
|
||||
|[Hardware Security Module support](./admin-guides/deploy-a-cluster/hsm.mdx) for encryption at rest|✖|✔|✖|
|
||||
|[JIT Access Requests](./admin-guides/access-controls/guides/dual-authz.mdx)|✔|✔|Limited|
|
||||
|[Session & Identity Locks](./admin-guides/access-controls/guides/locking.mdx)|✔|✔|✖|
|
||||
|**User identity.** Authenticate users without passwords:||||
|
||||
| [Single Sign-On](./admin-guides/access-controls/sso/sso.mdx)| GitHub, Google Workspace, Microsoft Entra ID, Okta, OIDC, SAML, Teleport | GitHub, Google Workspace, Microsoft Entra ID, Okta, OIDC, SAML, Teleport | GitHub |
|
||||
| User & Group Provisioning & Deprovisioning (SCIM & Custom Protocols), including Okta and Entra | Available In Teleport Identity Governance | Available In Teleport Identity Governance | ✖ |
|
||||
| [Hardware Private Key Support](./admin-guides/access-controls/guides/hardware-key-support.mdx) (e.g., via YubiKey) | ✔ (External-connected HSM/KMS coming soon) | ✔ | ✖ |
|
||||
|**Resource identity.** Assign a cryptographic identity to every Teleport Protected Resource:||||
|
||||
| Protecting: [Applications](./enroll-resources/application-access/getting-started.mdx), [Databases](./enroll-resources/database-access/getting-started.mdx), [Kubernetes Clusters](./enroll-resources/kubernetes-access/getting-started.mdx), [Linux Servers](./enroll-resources/server-access/getting-started.mdx), [Windows Servers](./enroll-resources/desktop-access/introduction.mdx), [Windows Desktops](./enroll-resources/desktop-access/introduction.mdx), Cloud Consoles & Resources (AWS, Azure, GCP), [GitHub](./admin-guides/management/guides/github-integration.mdx) | ✔ | ✔ | ✔ (does not include Oracle support) |
|
||||
|**Secure remote access.** Zero-trust, auditable access to your infrastructure:||||
|
||||
| Dynamic, self-updating inventory | ✔ | ✔ | ✔ |
|
||||
| Supports SSH, RDP, Kubernetes, Databases, AWS, Azure, GCP API and CLI, Web applications and services, TCP endpoints for Linux, Windows and MacOS. | ✔ | ✔ | ✔ |
|
||||
| [Machines](./enroll-resources/machine-id/machine-id.mdx) and [workloads](./enroll-resources/workload-identity/introduction.mdx#teleport-workload-identity-vs-machine-id) | Available in Teleport Machine & Workload Identity | Available in Teleport Machine & Workload Identity | Available in Teleport Machine & Workload Identity |
|
||||
| Agentless Integration with [OpenSSH Servers](./enroll-resources/server-access/openssh/openssh-agentless.mdx) | ✔ | ✔ | ✔ |
|
||||
| [IP-Based Restrictions](./admin-guides/access-controls/guides/ip-pinning.mdx) | ✔ | ✔ | ✖ |
|
||||
| [Teleport VNet](./connect-your-client/vnet.mdx) | ✔ | ✔ | ✔ |
|
||||
|**Short-lived privileges.** Ephemeral authorization granted through short-lived certificates:||||
|
||||
| [Role-Based Access Control](./admin-guides/access-controls/guides/role-templates.mdx) | ✔ | ✔ | ✔ |
|
||||
| [Just-in-Time Access Requests & Reviews](./admin-guides/access-controls/access-requests/resource-requests.mdx) | Available in Teleport Identity Governance | Available in Teleport Identity Governance | Only can request roles through CLI |
|
||||
|**Session recording and interactive controls.** Record, replay, join, and moderate interactive sessions:||||
|
||||
| [Session Recording with Playback](./reference/architecture/session-recording.mdx) | ✔ | ✔ | ✔ |
|
||||
| [Enhanced Session Recording](./enroll-resources/server-access/guides/bpf-session-recording.mdx) | ✔ | ✔ | ✔ |
|
||||
| [Recording Proxy Mode](./enroll-resources/server-access/guides/recording-proxy-mode.mdx) | ✖ | ✔ | ✔ |
|
||||
| Live Sessions View | SSH, Kubernetes, Desktops, Databases | SSH, Kubernetes, Desktops, Databases | SSH, Kubernetes, Desktops, Databases |
|
||||
| Protocol-Level Events, for all supported resources | ✔ | ✔ | ✔ |
|
||||
| [Dual Authorization](./admin-guides/access-controls/guides/dual-authz.mdx) | ✔ | ✔ | ✖ |
|
||||
| [Session Sharing & Moderation](./admin-guides/access-controls/guides/joining-sessions.mdx) | ✔ | ✔ | ✖ |
|
||||
|**Identity-based audit events:** ||||
|
||||
| [Structured Audit Logs](./reference/monitoring/audit.mdx) | ✔ | ✔ | ✔ |
|
||||
| [Export to SIEM](./admin-guides/management/export-audit-events/export-audit-events.mdx) | ✔ | ✔ | ✔ |
|
||||
|**Regulatory standards and frameworks:**||||
|
||||
| [FedRAMP Control](./admin-guides/access-controls/compliance-frameworks/fedramp.mdx) | ✖ | ✔ | ✖ |
|
||||
| FIPS-compliant binaries for FedRAMP (Low, Moderate, High) | ✖ | ✔ | ✖ |
|
||||
| DORA, SOX, ISO, NIS2, PCI DSS, SOC 2, HIPAA, NIST | ✔ | ✔ | Limited |
|
||||
|
||||
## Teleport Machine & Workload Identity
|
||||
|
||||
||[Teleport Enterprise (Cloud)](#teleport-editions)|[Teleport Enterprise (Self-Hosted)](#teleport-editions)|[Teleport Community Edition](#teleport-editions)|
|
||||
**Teleport Machine & Workload Identity** is a non-human identity management
|
||||
solution that secures machine-to-machine communication with short-lived
|
||||
certificates, access control, and auditability.
|
||||
|
||||
| | **Enterprise (Cloud)** | **Enterprise (Self-Hosted)** | **Community Edition** |
|
||||
|---|:---:|:---:|:---:|
|
||||
|[Machine Access](./enroll-resources/machine-id/getting-started.mdx)|✔|✔|✔|
|
||||
|[Flexible Workload Identities](./enroll-resources/workload-identity/getting-started.mdx)|✔|✔|✔|
|
||||
| **Service Discovery:** Live inventory of machine and workload identities for CI/CD jobs, microservices, and others | ✔ | ✔ | ✔ |
|
||||
|**Issuance:** Provisions cryptographic identities for [machines](./enroll-resources/machine-id/getting-started.mdx) and [workloads](./enroll-resources/workload-identity/getting-started.mdx), eliminating anonymous computing and the need for static over-privileged users and automating certificate rotation | ✔ | ✔ | ✔ |
|
||||
|**Secretless Authentication:** Eliminates the need for API keys and long-term secrets with short-lived certificates.| ✔ | ✔ | ✔ |
|
||||
|**Ephemeral Authorization:** With granular ABAC/RBAC for workload interactions | ✔ | ✔ | ✔ |
|
||||
|**Auditability:** Audit data, exportable to SIEMs, for compliance reporting & reviews | ✔ | ✔ | ✔ |
|
||||
|**Integration:** Supports open-source policy agents, dev tool APIs, and Cloud IAM. Others include Jenkins, Github actions, Terraform Cloud, AWS Roles anywhere and more. | ✔ | ✔ | ✔ |
|
||||
|**HSM and TPM support** for bootstrapping, joining, and encryption | ✔ | ✔ | ✖ |
|
||||
|**Open Standards** \- JWT, SPIFFE, x509 and others to avoid vendor lock-in | ✔ | ✔ | ✔ |
|
||||
|
||||
## Teleport Identity Governance
|
||||
|
||||
**Teleport Identity Governance** hardens and monitors identities for both human
|
||||
and non-human identities.
|
||||
|
||||
| | **Enterprise (Cloud)** | **Enterprise (Self-Hosted)** | **Community Edition** |
|
||||
|---|:---:|:---:|:---:|
|
||||
| [JIT Access Requests](./admin-guides/access-controls/guides/dual-authz.mdx): Grant only those privileges necessary to complete the task at hand. Remove the need for super-privileged accounts. | ✔ | ✔ | Only can request roles through CLI |
|
||||
| Automatic Access Requests & Approvals: Automate pre-defined workflows based on RBAC, ABAC, or context-based authorization. | ✔ | ✔ | ✖ |
|
||||
| [Access Lists & Access Reviews](./admin-guides/access-controls/access-lists/access-lists.mdx): Review access requests using Slack, PagerDuty, Microsoft Teams, Jira and ServiceNow. Assign managers, automate mandatory reviews, and implement custom review logic using our API and Go SDK. Integrates with AWS Identity Center. | ✔ | ✔ | ✖ |
|
||||
| [Session & Identity Locks](./admin-guides/access-controls/guides/locking.mdx): Lock suspicious or compromised identities and stop all their activity across all protocols and services. | ✔ | ✔ | ✖ |
|
||||
| [Device Trust](./admin-guides/access-controls/device-trust/guide.mdx): Require an up-to-date, registered device for each authentication. Teleport uses TPMs and secure enclaves to give every device a cryptographic identity. Restrict further by resource or MDM-authorization. | ✔ | ✔ | ✖ |
|
||||
| User & Group Provisioning & Deprovisioning (SCIM & Custom Protocols), including Okta and Entra | ✔ | ✔ | ✖ |
|
||||
| [Access Monitoring & Response](./admin-guides/access-controls/access-monitoring.mdx): Detect overly broad privileges and inspect sessions that are not using strong protection, such as multi-factor authentication or device trust. Alert on access violations and purge unused permissions with automated access rules. | ✔ | ✔ | ✖ |
|
||||
| [Okta integration](./enroll-resources/application-access/okta/okta.mdx): Configure Teleport to import and grant access to Okta applications and user groups. | ✔ | ✔ | ✖ |
|
||||
| Microsoft Entra ID directory synchronization and SSO [integration](./admin-guides/access-controls/sso/azuread.mdx) | ✔ | ✔ | ✖ |
|
||||
|
||||
## Teleport Identity Security
|
||||
|
||||
||[Teleport Enterprise (Cloud)](#teleport-editions)|[Teleport Enterprise (Self-Hosted)](#teleport-editions)|[Teleport Community Edition](#teleport-editions)|
|
||||
**Teleport Identity Security** identifies & mitigates risk in access paths.
|
||||
|
||||
| | **Enterprise (Cloud)** | **Enterprise (Self-Hosted)** | **Community Edition** |
|
||||
|---|:---:|:---:|:---:|
|
||||
|[Identity Security](./admin-guides/teleport-policy/teleport-policy.mdx)|✔|✔|✖|
|
||||
|[Crown Jewel Monitoring](./admin-guides/teleport-policy/crown-jewels.mdx)|✔|✔|✖|
|
||||
|[SSH Key Scanning](./admin-guides/teleport-policy/integrations/ssh-keys-scan.mdx)|✔|✔|✖|
|
||||
| Access Graph: Import and analysis of AWS, Azure, Okta, Microsoft Entra, GitLab and AWS IAM roles | ✔ | ✔ | ✖ |
|
||||
| Discover secrets, SSH Key Scanning| ✔ | ✔ | ✖ |
|
||||
| Discover standing privileges | ✔ | ✔ | ✖ |
|
||||
| Analyze shadow access and drift of security posture | ✔ | ✔ | ✖ |
|
||||
| Investigate identity vulnerabilities and potential exposures | ✔ | ✔ | ✖ |
|
||||
| Monitor critical assets with [Crown Jewel](./admin-guides/teleport-policy/crown-jewels.mdx) Alerting | ✔ | ✔ | ✖ |
|
||||
|
||||
## Management and licensing
|
||||
## Platform integrations, management, licensing, and deployment
|
||||
|
||||
||[Teleport Enterprise (Cloud)](#teleport-editions)|[Teleport Enterprise (Self-Hosted)](#teleport-editions)|[Teleport Community Edition](#teleport-editions)|
|
||||
| | **Enterprise (Cloud)** | **Enterprise (Self-Hosted)** | **Community Edition** |
|
||||
|---|:---:|:---:|:---:|
|
||||
|Annual or multi-year contracts, volume discounts|✔|✔|✖|
|
||||
|Anonymized Usage Tracking|✔|✔|Opt-in|
|
||||
|Auth Service and Proxy Service Management|Fully managed|Self-hosted|Self-hosted|
|
||||
|[Backend support](./reference/backends.mdx)|All data is stored in DynamoDB and S3 with server-side encryption.|Any S3-compatible storage for session records, many managed backends for custom audit log storage|Any S3-compatible storage for session records, many managed backends for custom audit log storage.|
|
||||
|Data storage location|Data is stored in Teleport's AWS infrastructure with audit logs/sessions optionally in customer AWS accounts. Proxy Service instances are deployed across the world for low-latency access.|Can store data anywhere in the world, on most managed cloud backends|Can store data anywhere in the world, on most managed cloud backends|
|
||||
|License|Commercial|Commercial|Commercial|
|
||||
|Proxy Service domain name|A subdomain of `teleport.sh`|Custom|Custom|
|
||||
|Support|24x7 support with premium SLAs and account managers|24x7 support with premium SLAs and account managers|Community|
|
||||
|Version support|Deploys last stable release with 2-3 week lag for stability.|All supported releases available to install and download.|All supported releases available to install and download.|
|
||||
| **Integrations:** ||||
|
||||
| Infrastructure as Code (IaC): Terraform, K8s Operator | ✔ | ✔ | ✔ |
|
||||
| Cloud Providers: AWS, Azure, GCP | ✔ | ✔ | ✔ |
|
||||
| Security Information & Event Management (SIEM): Elastic, Splunk, Panther, and anything else that integrates with Fluentd | ✔ | ✔ | ✔ |
|
||||
| ITSM: ServiceNow, JIRA | ✔ | ✔ | ✖ |
|
||||
| Access Request Integration: Slack, Teams, Discord, Mattermost, PagerDuty, Opsgenie, Email | ✔ | ✔ | ✔ |
|
||||
| [Hardware Private Key Support](./admin-guides/access-controls/guides/hardware-key-support.mdx) (e.g., via YubiKey) | ✔ (External-connected HSM/KMS coming soon) | ✔ | ✖ |
|
||||
| [Hardware Security Module support](./admin-guides/deploy-a-cluster/hsm.mdx) for encryption at rest | ✔ (External-connected HSM/KMS coming soon) | ✔ | ✖ |
|
||||
| **Management and licensing:** ||||
|
||||
| Annual or multi-year contracts, volume discounts | ✔ | ✔ | ✖ |
|
||||
| Anonymized Usage Tracking | ✔ | ✔ | Opt-in |
|
||||
| [Backend support](./reference/backends.mdx) | All data is stored in DynamoDB and S3 with server-side encryption. | Any S3-compatible storage for session records, many managed backends for custom audit log storage | Any S3-compatible storage for session records, many managed backends for custom audit log storage. |
|
||||
| Multi-region failover using Cockroach DB | ✔ | ✔ | ✖ |
|
||||
| Data storage location | Data is stored in Teleport's AWS infrastructure with audit logs/sessions optionally in customer AWS accounts. Proxy Service instances are deployed across the world for low-latency access. | Can store data anywhere in the world, on most managed cloud backends | Can store data anywhere in the world, on most managed cloud backends |
|
||||
| License | Commercial | Commercial | Commercial for binaries, with restrictions: Free usage for companies with \<100 employees and \<US$10M annual revenue. Code on GitHub distributed via AGPL-3.0 |
|
||||
| Publicly accessible domain name | A subdomain of teleport.sh | Custom | Custom |
|
||||
| [Support](https://support.goteleport.com/hc/en-us/articles/16562919750419-Priority-Support) | 24x7 (Severity 1) support with premium SLAs and account managers. | 24x7 (Severity 1) support with premium SLAs and account managers | Slack community |
|
||||
| Version support | Deploys last stable release with 2-3 week lag for stability. | All supported releases available to install and download. | All supported releases available to install and download. |
|
||||
| **Deployment options:** ||||
|
||||
| Teleport cloud deployment | ✔ | ✖ | ✖ |
|
||||
| Self-hosted deployment| ✖ | ✔ | ✔ |
|
||||
| Multi-Region High Availability | ✔ (Teleport service) | ✔ (Customer-implemented, via a [supported blueprint](./admin-guides/deploy-a-cluster/multi-region-blueprint.mdx)) | ✖ |
|
||||
| FIPS-compliant binaries available for FedRAMP, including Low, Moderate & High | ✖ | ✔ | ✖ |
|
||||
|
||||
## Teleport editions
|
||||
|
||||
Teleport includes two editions:
|
||||
- **Teleport Community Edition:** An open source offering intended for demos and
|
||||
small teams.
|
||||
- **Teleport Enterprise:** A fully-featured commercial offering.
|
||||
|
||||
Teleport Enterprise offers two deployment
|
||||
options:
|
||||
- **Cloud:** The Teleport team manages the Teleport Auth Service and Teleport
|
||||
Proxy Service on the Teleport Cloud infrastructure.
|
||||
- **Self-Hosted:** Teleport users deploy the Teleport Auth Service and Teleport Proxy
|
||||
Service on their own infrastructure.
|
||||
|
||||
Teleport Enterprise includes add-on products that provide a more complete
|
||||
infrastructure identity solution, which this guide explains in more detail
|
||||
below.
|
||||
|
||||
Reference in New Issue
Block a user