mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Restructure docs menu pages (#47797)
Docusaurus [sidebar generation](https://docusaurus.io/docs/next/sidebar/autogenerated) expects category index pages to have one of three file path conventions: - `section/index.mdx` - `section/README.mdx` - `section/section.mdx` This change standardizes category index paths on the third convention so Docusaurus sidebar generation succeeds. We can then add checks to the current docs site to prevent additional menu pages from violating this convention. This change also adds redirects to the new category index pages, and updates internal links to pages that were moved. Note that this change does not move all relevant menu pages. We still need to reorganize the `reference/terraform-provider` section. Since this section is automatically generated, we need another approach to restructuring it.
This commit is contained in:
+15
-15
@@ -386,7 +386,7 @@ applications in Kubernetes clusters. When connected to a Kubernetes cluster (or
|
||||
deployed as a Helm chart), the Teleport Discovery Service will automatically find
|
||||
and enroll web applications with your Teleport cluster.
|
||||
|
||||
See documentation [here](docs/pages/enroll-resources/auto-discovery/kubernetes-applications.mdx).
|
||||
See documentation [here](docs/pages/enroll-resources/auto-discovery/kubernetes-applications/kubernetes-applications.mdx).
|
||||
|
||||
#### Extended Kubernetes per-resource RBAC
|
||||
|
||||
@@ -1909,7 +1909,7 @@ is more than one major version behind them. You can use the `--skip-version-chec
|
||||
bypass the version check.
|
||||
|
||||
Take a look at component compatibility guarantees in the
|
||||
[documentation](docs/pages/upgrading.mdx).
|
||||
[documentation](docs/pages/upgrading/upgrading.mdx).
|
||||
|
||||
#### HTTP_PROXY for reverse tunnels
|
||||
|
||||
@@ -2898,7 +2898,7 @@ if err = clt.CreateAccessRequest(ctx, accessRequest); err != nil {
|
||||
|
||||
### Upgrade Notes
|
||||
|
||||
Please follow our [standard upgrade procedure](docs/pages/admin-guides/management/admin.mdx) to upgrade your cluster.
|
||||
Please follow our [standard upgrade procedure](docs/pages/admin-guides/management/admin/admin.mdx) to upgrade your cluster.
|
||||
|
||||
Note, for clusters using GitHub SSO and Trusted Clusters, when upgrading SSO users will lose connectivity to leaf clusters. Local users will not be affected.
|
||||
|
||||
@@ -3149,7 +3149,7 @@ Other updates:
|
||||
|
||||
* We now provide local user management via `https://[cluster-url]/web/users`, providing the ability to edit, reset and delete local users.
|
||||
* Teleport Node & App Install scripts. This is currently an Enterprise-only feature that provides customers with an 'auto-magic' installer script. Enterprise customers can enable this feature by modifying the 'token' resource. See note above.
|
||||
* We've added a Waiting Room for customers using Access Workflows. [Docs](docs/pages/admin-guides/access-controls/access-request-plugins.mdx)
|
||||
* We've added a Waiting Room for customers using Access Workflows. [Docs](docs/pages/admin-guides/access-controls/access-request-plugins/access-request-plugins.mdx)
|
||||
|
||||
##### Signed RPM and Releases
|
||||
|
||||
@@ -3183,7 +3183,7 @@ We've added an [API Guide](docs/pages/admin-guides/api/api.mdx) to simply develo
|
||||
|
||||
#### Upgrade Notes
|
||||
|
||||
Please follow our [standard upgrade procedure](./docs/pages/upgrading.mdx).
|
||||
Please follow our [standard upgrade procedure](docs/pages/upgrading/upgrading.mdx).
|
||||
|
||||
* Optional: Consider updating `https_key_file` & `https_cert_file` to our new `https_keypairs:` format.
|
||||
* Optional: Consider migrating Kubernetes access from `proxy_service` to `kubernetes_service` after the upgrade.
|
||||
@@ -3327,7 +3327,7 @@ auth_service:
|
||||
#### Upgrade Notes
|
||||
|
||||
Please follow our [standard upgrade
|
||||
procedure](docs/pages/upgrading.mdx).
|
||||
procedure](docs/pages/upgrading/upgrading.mdx).
|
||||
|
||||
## 4.3.9
|
||||
|
||||
@@ -3412,7 +3412,7 @@ Teleport's Web UI now exposes Teleport’s Audit log, letting auditors and admin
|
||||
|
||||
##### Teleport Plugins
|
||||
|
||||
Teleport 4.3 introduces four new plugins that work out of the box with [Approval Workflow](docs/pages/admin-guides/access-controls/access-request-plugins.mdx). These plugins allow you to automatically support role escalation with commonly used third party services. The built-in plugins are listed below.
|
||||
Teleport 4.3 introduces four new plugins that work out of the box with [Approval Workflow](docs/pages/admin-guides/access-controls/access-request-plugins/access-request-plugins.mdx). These plugins allow you to automatically support role escalation with commonly used third party services. The built-in plugins are listed below.
|
||||
|
||||
* [PagerDuty](docs/pages/admin-guides/access-controls/access-request-plugins/ssh-approval-pagerduty.mdx)
|
||||
* [Jira](docs/pages/admin-guides/access-controls/access-request-plugins/ssh-approval-jira.mdx)
|
||||
@@ -3448,7 +3448,7 @@ Teleport 4.3 introduces four new plugins that work out of the box with [Approval
|
||||
#### Upgrade Notes
|
||||
|
||||
Always follow the [recommended upgrade
|
||||
procedure](./docs/pages/upgrading.mdx) to upgrade to this version.
|
||||
procedure](docs/pages/upgrading/upgrading.mdx) to upgrade to this version.
|
||||
|
||||
##### New Signing Algorithm
|
||||
|
||||
@@ -3489,7 +3489,7 @@ permissions](./docs/pages/enroll-resources/kubernetes-access/controls.mdx).
|
||||
The [etcd backend](docs/pages/reference/backends.mdx#etcd) now correctly uses
|
||||
the “prefix” config value when storing data. Upgrading from 4.2 to 4.3 will
|
||||
migrate the data as needed at startup. Make sure you follow our Teleport
|
||||
[upgrade guidance](docs/pages/upgrading.mdx).
|
||||
[upgrade guidance](docs/pages/upgrading/upgrading.mdx).
|
||||
|
||||
**Note: If you use an etcd backend with a non-default prefix and need to downgrade from 4.3 to 4.2, you should [backup Teleport data and restore it](docs/pages/admin-guides/management/operations/backup-restore.mdx) into the downgraded cluster.**
|
||||
|
||||
@@ -3612,7 +3612,7 @@ This is a minor Teleport release with a focus on new features and bug fixes.
|
||||
### Improvements
|
||||
|
||||
* Alpha: Enhanced Session Recording lets you know what's really happening during a Teleport Session. [#2948](https://github.com/gravitational/teleport/issues/2948)
|
||||
* Alpha: Workflows API lets admins escalate RBAC roles in response to user requests. [Read the docs](docs/pages/admin-guides/access-controls/access-requests.mdx). [#3006](https://github.com/gravitational/teleport/issues/3006)
|
||||
* Alpha: Workflows API lets admins escalate RBAC roles in response to user requests. [Read the docs](docs/pages/admin-guides/access-controls/access-requests/access-requests.mdx). [#3006](https://github.com/gravitational/teleport/issues/3006)
|
||||
* Beta: Teleport provides HA Support using Firestore and Google Cloud Storage using Google Cloud Platform. [Read the docs](docs/pages/admin-guides/deploy-a-cluster/deployments/gcp.mdx). [#2821](https://github.com/gravitational/teleport/pull/2821)
|
||||
* Remote tctl execution is now possible. [Read the docs](./docs/pages/reference/cli/tctl.mdx). [#1525](https://github.com/gravitational/teleport/issues/1525) [#2991](https://github.com/gravitational/teleport/issues/2991)
|
||||
|
||||
@@ -3868,7 +3868,7 @@ The lists of improvements and bug fixes above mention only the significant chang
|
||||
|
||||
### Upgrading
|
||||
|
||||
Teleport 4.0 is backwards compatible with Teleport 3.2 and later. [Follow the recommended upgrade procedure to upgrade to this version.](docs/pages/upgrading.mdx)
|
||||
Teleport 4.0 is backwards compatible with Teleport 3.2 and later. [Follow the recommended upgrade procedure to upgrade to this version.](docs/pages/upgrading/upgrading.mdx)
|
||||
|
||||
Note that due to substantial changes between Teleport 3.2 and 4.0, we recommend creating a backup of the backend datastore (DynamoDB, etcd, or dir) before upgrading a cluster to Teleport 4.0 to allow downgrades.
|
||||
|
||||
@@ -4136,7 +4136,7 @@ on Github for more.
|
||||
#### Upgrading to 3.0
|
||||
|
||||
Follow the [recommended upgrade
|
||||
procedure](docs/pages/upgrading.mdx) to upgrade to this
|
||||
procedure](docs/pages/upgrading/upgrading.mdx) to upgrade to this
|
||||
version.
|
||||
|
||||
**WARNING:** if you are using Teleport with the etcd back-end, make sure your
|
||||
@@ -4242,7 +4242,7 @@ As always, this release contains several bug fixes. The full list can be seen [h
|
||||
#### Upgrading
|
||||
|
||||
Follow the [recommended upgrade
|
||||
procedure](docs/pages/upgrading.mdx) to upgrade to this
|
||||
procedure](docs/pages/upgrading/upgrading.mdx) to upgrade to this
|
||||
version.
|
||||
|
||||
## 2.6.9
|
||||
@@ -4372,7 +4372,7 @@ You can see the full list of 2.6.0 changes [here](https://github.com/gravitation
|
||||
#### Upgrading
|
||||
|
||||
Follow the [recommended upgrade
|
||||
procedure](docs/pages/upgrading.mdx) to upgrade to this
|
||||
procedure](docs/pages/upgrading/upgrading.mdx) to upgrade to this
|
||||
version.
|
||||
|
||||
## 2.5.7
|
||||
@@ -4459,7 +4459,7 @@ release, which includes:
|
||||
|
||||
* The Teleport daemon now implements built-in connection draining which allows
|
||||
zero-downtime upgrades. [See
|
||||
documentation](docs/pages/upgrading.mdx).
|
||||
documentation](docs/pages/upgrading/upgrading.mdx).
|
||||
|
||||
* Dynamic join tokens for new nodes can now be explicitly set via `tctl node add --token`.
|
||||
This allows Teleport admins to use an external mechanism for generating
|
||||
|
||||
+46
-51
@@ -22,7 +22,7 @@
|
||||
},
|
||||
{
|
||||
"title": "Upgrading",
|
||||
"slug": "/upgrading/",
|
||||
"slug": "/upgrading/upgrading/",
|
||||
"entries": [
|
||||
{
|
||||
"title": "Compatibility Overview",
|
||||
@@ -232,7 +232,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/database-access/guides/",
|
||||
"destination": "/enroll-resources/database-access/guides/",
|
||||
"destination": "/enroll-resources/database-access/guides/guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -272,7 +272,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/agents/join-services-to-your-cluster/",
|
||||
"destination": "/enroll-resources/agents/join-services-to-your-cluster/",
|
||||
"destination": "/enroll-resources/agents/join-services-to-your-cluster/join-services-to-your-cluster/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -307,7 +307,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/application-access/cloud-apis/",
|
||||
"destination": "/enroll-resources/application-access/cloud-apis/",
|
||||
"destination": "/enroll-resources/application-access/cloud-apis/cloud-apis/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -342,7 +342,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/application-access/guides/",
|
||||
"destination": "/enroll-resources/application-access/guides/",
|
||||
"destination": "/enroll-resources/application-access/guides/guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -407,7 +407,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/application-access/okta/",
|
||||
"destination": "/enroll-resources/application-access/okta/",
|
||||
"destination": "/enroll-resources/application-access/okta/okta/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -442,7 +442,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/auto-discovery/databases/",
|
||||
"destination": "/enroll-resources/auto-discovery/databases/",
|
||||
"destination": "/enroll-resources/auto-discovery/databases/databases/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -457,7 +457,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/auto-discovery/kubernetes-applications/",
|
||||
"destination": "/enroll-resources/auto-discovery/kubernetes-applications/",
|
||||
"destination": "/enroll-resources/auto-discovery/kubernetes-applications/kubernetes-applications/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -477,7 +477,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/auto-discovery/kubernetes/",
|
||||
"destination": "/enroll-resources/auto-discovery/kubernetes/",
|
||||
"destination": "/enroll-resources/auto-discovery/kubernetes/kubernetes/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -497,7 +497,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/auto-discovery/servers/",
|
||||
"destination": "/enroll-resources/auto-discovery/servers/",
|
||||
"destination": "/enroll-resources/auto-discovery/servers/servers/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -517,7 +517,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/database-access/auto-user-provisioning/",
|
||||
"destination": "/enroll-resources/database-access/auto-user-provisioning/",
|
||||
"destination": "/enroll-resources/database-access/auto-user-provisioning/auto-user-provisioning/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -547,7 +547,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/database-access/enroll-aws-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-aws-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-aws-databases/enroll-aws-databases/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -612,7 +612,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/database-access/enroll-azure-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-azure-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-azure-databases/enroll-azure-databases/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -632,7 +632,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/database-access/enroll-google-cloud-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-google-cloud-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-google-cloud-databases/enroll-google-cloud-databases/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -652,7 +652,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/database-access/enroll-managed-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-managed-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-managed-databases/enroll-managed-databases/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -667,7 +667,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/database-access/enroll-self-hosted-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-self-hosted-databases/",
|
||||
"destination": "/enroll-resources/database-access/enroll-self-hosted-databases/enroll-self-hosted-databases/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -882,7 +882,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/kubernetes-access/register-clusters/",
|
||||
"destination": "/enroll-resources/kubernetes-access/register-clusters/",
|
||||
"destination": "/enroll-resources/kubernetes-access/register-clusters/register-clusters/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -907,7 +907,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/machine-id/access-guides/",
|
||||
"destination": "/enroll-resources/machine-id/access-guides/",
|
||||
"destination": "/enroll-resources/machine-id/access-guides/access-guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -952,7 +952,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/machine-id/deployment/",
|
||||
"destination": "/enroll-resources/machine-id/deployment/",
|
||||
"destination": "/enroll-resources/machine-id/deployment/deployment/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1097,7 +1097,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/server-access/guides/",
|
||||
"destination": "/enroll-resources/server-access/guides/",
|
||||
"destination": "/enroll-resources/server-access/guides/guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1147,7 +1147,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/server-access/openssh/",
|
||||
"destination": "/enroll-resources/server-access/openssh/",
|
||||
"destination": "/enroll-resources/server-access/openssh/openssh/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1252,12 +1252,12 @@
|
||||
},
|
||||
{
|
||||
"source": "/enterprise/sso/",
|
||||
"destination": "/admin-guides/access-controls/sso/",
|
||||
"destination": "/admin-guides/access-controls/sso/sso/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/guides/device-trust/",
|
||||
"destination": "/admin-guides/access-controls/device-trust/",
|
||||
"destination": "/admin-guides/access-controls/device-trust/device-trust/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1272,7 +1272,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/application-access/okta/guide/",
|
||||
"destination": "/enroll-resources/application-access/okta/",
|
||||
"destination": "/enroll-resources/application-access/okta/okta/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1327,7 +1327,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/setup/operations/upgrading/",
|
||||
"destination": "/upgrading/",
|
||||
"destination": "/upgrading/upgrading/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1447,7 +1447,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/access-lists/",
|
||||
"destination": "/admin-guides/access-controls/access-lists/",
|
||||
"destination": "/admin-guides/access-controls/access-lists/access-lists/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1467,7 +1467,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/access-request-plugins/",
|
||||
"destination": "/admin-guides/access-controls/access-request-plugins/",
|
||||
"destination": "/admin-guides/access-controls/access-request-plugins/access-request-plugins/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1527,7 +1527,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/access-requests/",
|
||||
"destination": "/admin-guides/access-controls/access-requests/",
|
||||
"destination": "/admin-guides/access-controls/access-requests/access-requests/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1552,7 +1552,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/compliance-frameworks/",
|
||||
"destination": "/admin-guides/access-controls/compliance-frameworks/",
|
||||
"destination": "/admin-guides/access-controls/compliance-frameworks/compliance-frameworks/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1567,7 +1567,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/device-trust/",
|
||||
"destination": "/admin-guides/access-controls/device-trust/",
|
||||
"destination": "/admin-guides/access-controls/device-trust/device-trust/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1597,7 +1597,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/guides/",
|
||||
"destination": "/admin-guides/access-controls/guides/",
|
||||
"destination": "/admin-guides/access-controls/guides/guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1662,7 +1662,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/idps/",
|
||||
"destination": "/admin-guides/access-controls/idps/",
|
||||
"destination": "/admin-guides/access-controls/idps/idps/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1697,7 +1697,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/login-rules/",
|
||||
"destination": "/admin-guides/access-controls/login-rules/",
|
||||
"destination": "/admin-guides/access-controls/login-rules/login-rules/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1727,7 +1727,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/access-controls/sso/",
|
||||
"destination": "/admin-guides/access-controls/sso/",
|
||||
"destination": "/admin-guides/access-controls/sso/sso/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1927,7 +1927,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/deploy-a-cluster/deployments/",
|
||||
"destination": "/admin-guides/deploy-a-cluster/deployments/",
|
||||
"destination": "/admin-guides/deploy-a-cluster/deployments/deployments/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -1957,7 +1957,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/deploy-a-cluster/helm-deployments/",
|
||||
"destination": "/admin-guides/deploy-a-cluster/helm-deployments/",
|
||||
"destination": "/admin-guides/deploy-a-cluster/helm-deployments/helm-deployments/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2132,7 +2132,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/management/admin/",
|
||||
"destination": "/admin-guides/management/admin/",
|
||||
"destination": "/admin-guides/management/admin/admin/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2177,7 +2177,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/management/diagnostics/",
|
||||
"destination": "/admin-guides/management/diagnostics/",
|
||||
"destination": "/admin-guides/management/diagnostics/diagnostics/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2212,7 +2212,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/management/dynamic-resources/",
|
||||
"destination": "/admin-guides/infrastructure-as-code/",
|
||||
"destination": "/admin-guides/infrastructure-as-code/infrastructure-as-code/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2237,12 +2237,12 @@
|
||||
},
|
||||
{
|
||||
"source": "/management/dynamic-resources/teleport-operator/",
|
||||
"destination": "/admin-guides/infrastructure-as-code/teleport-operator/",
|
||||
"destination": "/admin-guides/infrastructure-as-code/teleport-operator/teleport-operator/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/management/dynamic-resources/terraform-provider/",
|
||||
"destination": "/admin-guides/infrastructure-as-code/terraform-provider/",
|
||||
"destination": "/admin-guides/infrastructure-as-code/terraform-provider/terraform-provider/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2252,7 +2252,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/management/export-audit-events/",
|
||||
"destination": "/admin-guides/management/export-audit-events/",
|
||||
"destination": "/admin-guides/management/export-audit-events/export-audit-events/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2277,7 +2277,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/management/guides/",
|
||||
"destination": "/admin-guides/management/guides/",
|
||||
"destination": "/admin-guides/management/guides/guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2307,7 +2307,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/management/operations/",
|
||||
"destination": "/admin-guides/management/operations/",
|
||||
"destination": "/admin-guides/management/operations/operations/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2347,7 +2347,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/management/security/",
|
||||
"destination": "/admin-guides/management/security/",
|
||||
"destination": "/admin-guides/management/security/security/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2390,11 +2390,6 @@
|
||||
"destination": "/upgrading/upgrading-reference/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/upgrading/upgrading/",
|
||||
"destination": "/upgrading/upgrading-reference/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/choose-an-edition/teleport-enterprise/introduction/",
|
||||
"destination": "/admin-guides/deploy-a-cluster/deploy-a-cluster/",
|
||||
@@ -2407,7 +2402,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/kubernetes-access/helm/guides/",
|
||||
"destination": "/admin-guides/deploy-a-cluster/helm-deployments/",
|
||||
"destination": "/admin-guides/deploy-a-cluster/helm-deployments/helm-deployments/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
|
||||
@@ -28,7 +28,7 @@ that specifies access policies for resources in your Teleport cluster.
|
||||
Assigning a role to a Teleport user applies the policies listed in the role to
|
||||
the user.
|
||||
|
||||
See the [Cluster Access and RBAC](./guides.mdx) section for instructions on
|
||||
See the [Cluster Access and RBAC](guides/guides.mdx) section for instructions on
|
||||
setting up Teleport roles.
|
||||
|
||||
## Integrate with your Single Sign-On provider
|
||||
@@ -42,7 +42,7 @@ automatically assigns roles to the user based on data provided by the IdP. This
|
||||
means that you can implement a fully fledged infrastructure RBAC system based on
|
||||
your existing Single Sign-On solution.
|
||||
|
||||
Read our [Single Sign-On guide](./sso.mdx) to get started.
|
||||
Read our [Single Sign-On guide](sso/sso.mdx) to get started.
|
||||
|
||||
## Enable Access Requests
|
||||
|
||||
@@ -51,13 +51,13 @@ resources in your infrastructure based on the approval of other users. You can
|
||||
set up your RBAC so all privileged access is short lived, and there are no
|
||||
longstanding admin roles for attackers to hijack.
|
||||
|
||||
[Get started with Access Requests](./access-requests.mdx).
|
||||
[Get started with Access Requests](access-requests/access-requests.mdx).
|
||||
|
||||
You can integrate Teleport with your existing communication tool, e.g., Slack,
|
||||
PagerDuty, or Microsoft Teams, so Teleport users can easily create and approve
|
||||
Access Requests.
|
||||
|
||||
[Get started with Access Request plugins](access-request-plugins.mdx).
|
||||
[Get started with Access Request plugins](access-request-plugins/access-request-plugins.mdx).
|
||||
|
||||
## Achieve compliance
|
||||
|
||||
|
||||
+2
-2
@@ -9,6 +9,6 @@ managed within Teleport. With Access Lists, administrators and access list
|
||||
owners can regularly audit and control membership to specific roles and
|
||||
traits, which then tie easily back into Teleport's existing RBAC system.
|
||||
|
||||
[Getting Started with Access Lists](./access-lists/guide.mdx)
|
||||
[Getting Started with Access Lists](guide.mdx)
|
||||
|
||||
[Access List Reference](../../reference/access-controls/access-lists.mdx)
|
||||
[Access List Reference](../../../reference/access-controls/access-lists.mdx)
|
||||
+1
-1
@@ -56,4 +56,4 @@ workflows by reading our setup guides:
|
||||
|
||||
To read more about the architecture of an Access Request plugin, and start
|
||||
writing your own, read our [Access Request plugin development
|
||||
guide](../api/access-plugin.mdx).
|
||||
guide](../../api/access-plugin.mdx).
|
||||
+5
-5
@@ -16,7 +16,7 @@ be configured with limited cluster access so they are not high value targets.
|
||||
Access Requests are designed to provide temporary permissions to users. If you
|
||||
want to grant longstanding permissions to a group of users, with the option to
|
||||
renew these permissions after a recurring interval (such as three months),
|
||||
consider [Access Lists](access-lists.mdx).
|
||||
consider [Access Lists](../access-lists/access-lists.mdx).
|
||||
|
||||
## See how Access Requests work
|
||||
|
||||
@@ -26,12 +26,12 @@ and **Resource Access Requests**.
|
||||
With Role Access Requests, engineers can request temporary credentials with
|
||||
elevated roles in order to perform critical system-wide tasks.
|
||||
|
||||
[Get started with Role Access Requests](./access-requests/role-requests.mdx).
|
||||
[Get started with Role Access Requests](role-requests.mdx).
|
||||
|
||||
With Resource Access Requests, engineers can easily get access to only the
|
||||
individual resources they need, when they need it.
|
||||
|
||||
[Get started with Resource Access Requests](./access-requests/resource-requests.mdx).
|
||||
[Get started with Resource Access Requests](resource-requests.mdx).
|
||||
|
||||
## Configure Access Requests
|
||||
|
||||
@@ -44,7 +44,7 @@ including:
|
||||
- How many users can approve or deny different kinds of requests.
|
||||
|
||||
Read the [Access Request
|
||||
Configuration](access-requests/access-request-configuration.mdx) guide for an
|
||||
Configuration](access-request-configuration.mdx) guide for an
|
||||
overview of the configuration options available for Access Requests.
|
||||
|
||||
## Teleport Community Edition users
|
||||
@@ -56,6 +56,6 @@ including Resource Access Requests managing Access Requests via the Web UI are
|
||||
available in Teleport Enterprise.
|
||||
|
||||
For information on how to use Just-in-time Access Requests with Teleport Community
|
||||
Edition, see [Teleport Community Access Requests](./access-requests/oss-role-requests.mdx).
|
||||
Edition, see [Teleport Community Access Requests](oss-role-requests.mdx).
|
||||
|
||||
|
||||
@@ -153,7 +153,7 @@ $ tctl request approve \
|
||||
|
||||
## Next Steps
|
||||
|
||||
- Learn more about [Access Requests](../access-requests.mdx)
|
||||
- Learn more about [Access Requests](access-requests.mdx)
|
||||
- See what additional features are available for
|
||||
[role requests](./role-requests.mdx) in Teleport Enterprise
|
||||
- Request access to [specific resources](./resource-requests.mdx) with Teleport Enterprise
|
||||
@@ -120,7 +120,7 @@ However, it prevents you from access any resources belonging to another namespac
|
||||
</Details>
|
||||
|
||||
Advanced filters and queries are supported. See our
|
||||
[filtering reference](../../../reference/cli.mdx) for more information.
|
||||
[filtering reference](../../../reference/cli/cli.mdx) for more information.
|
||||
|
||||
Try narrowing your search to a specific resource you want to access.
|
||||
|
||||
@@ -606,4 +606,4 @@ within your organization's existing messaging and project management solutions.
|
||||
|
||||
## Next Steps
|
||||
|
||||
- Learn more about [Access Lists](../access-lists.mdx)
|
||||
- Learn more about [Access Lists](../access-lists/access-lists.mdx)
|
||||
|
||||
@@ -217,5 +217,5 @@ just-in-time Access Request workflow for your organization.
|
||||
|
||||
Access Lists enable you to assign privileges to groups of users for a fixed
|
||||
period of time. Learn more about Access Lists in the
|
||||
[documentation](../access-lists.mdx).
|
||||
[documentation](../access-lists/access-lists.mdx).
|
||||
|
||||
|
||||
+2
-2
@@ -10,5 +10,5 @@ settings within Teleport.
|
||||
|
||||
Follow our guides to see how to use Teleport to achieve compliance:
|
||||
|
||||
- [FedRAMP](./compliance-frameworks/fedramp.mdx)
|
||||
- [SOC 2](./compliance-frameworks/soc2.mdx)
|
||||
- [FedRAMP](fedramp.mdx)
|
||||
- [SOC 2](soc2.mdx)
|
||||
@@ -58,16 +58,16 @@ Each principle has many "Points of Focus" which will apply differently to differ
|
||||
| CC6.1 - Manages Credentials for Infrastructure and Software | New internal and external infrastructure and software are registered, authorized, and documented prior to being granted access credentials and implemented on the network or access point. Credentials are removed and access is disabled when access is no longer required or the infrastructure and software are no longer in use. | [Invite nodes to your cluster with short lived tokens](../../../enroll-resources/agents/join-services-to-your-cluster/join-token.mdx) |
|
||||
| CC6.1 - Uses Encryption to Protect Data | The entity uses encryption to supplement other measures used to protect data at rest, when such protections are deemed appropriate based on assessed risk. | Teleport Audit logs can use DynamoDB encryption at rest. |
|
||||
| CC6.1 - Protects Encryption Keys | Processes are in place to protect encryption keys during generation, storage, use, and destruction. | Teleport acts as a Certificate Authority to issue SSH and x509 user certificates that are signed by the CA and are (by default) short-lived. SSH host certificates are also signed by the CA and rotated automatically |
|
||||
| CC6.2 - Controls Access Credentials to Protected Assets | Information asset access credentials are created based on an authorization from the system's asset owner or authorized custodian. | [Request Approval from the command line](../../../reference/cli/tctl.mdx) <br/><br/> [Build Approval Workflows with Access Requests](../../access-controls/access-requests.mdx) <br/><br/> [Use Plugins to send approvals to tools like Slack or Jira](../../access-controls/access-requests.mdx) |
|
||||
| CC6.2 - Removes Access to Protected Assets When Appropriate | Processes are in place to remove credential access when an individual no longer requires such access. | [Teleport issues temporary credentials based on an employees role and are revoked upon job change, termination or end of a maintenance window](../../access-controls/access-requests.mdx) |
|
||||
| CC6.2 - Controls Access Credentials to Protected Assets | Information asset access credentials are created based on an authorization from the system's asset owner or authorized custodian. | [Request Approval from the command line](../../../reference/cli/tctl.mdx) <br/><br/> [Build Approval Workflows with Access Requests](../access-requests/access-requests.mdx) <br/><br/> [Use Plugins to send approvals to tools like Slack or Jira](../access-requests/access-requests.mdx) |
|
||||
| CC6.2 - Removes Access to Protected Assets When Appropriate | Processes are in place to remove credential access when an individual no longer requires such access. | [Teleport issues temporary credentials based on an employees role and are revoked upon job change, termination or end of a maintenance window](../access-requests/access-requests.mdx) |
|
||||
| CC6.2 - Reviews Appropriateness of Access Credentials | The appropriateness of access credentials is reviewed on a periodic basis for unnecessary and inappropriate individuals with credentials. | Teleport maintains a live list of all nodes within a cluster. This node list can be queried by users (who see a subset they have access to) and administrators any time. |
|
||||
| CC6.3 - Creates or Modifies Access to Protected Information Assets | Processes are in place to create or modify access to protected information assets based on authorization from the asset’s owner. | [Build Approval Workflows with Access Requests](../../access-controls/access-requests.mdx) to get authorization from asset owners. |
|
||||
| CC6.3 - Creates or Modifies Access to Protected Information Assets | Processes are in place to create or modify access to protected information assets based on authorization from the asset’s owner. | [Build Approval Workflows with Access Requests](../access-requests/access-requests.mdx) to get authorization from asset owners. |
|
||||
| CC6.3 - Removes Access to Protected Information Assets | Processes are in place to remove access to protected information assets when an individual no longer requires access. | Teleport uses temporary credentials and can be integrated with your version control system or even your HR system to [revoke access with the Access requests API](../../api/api.mdx) |
|
||||
| CC6.3 - Uses Role-Based Access Controls | Role-based access control is utilized to support segregation of incompatible functions. | [Role based access control ("RBAC") allows Teleport administrators to grant granular access permissions to users.](../access-controls.mdx) |
|
||||
| CC6.3 - Reviews Access Roles and Rules | The appropriateness of access roles and access rules is reviewed on a periodic basis for unnecessary and inappropriate individuals with access and access rules are modified as appropriate. | Teleport maintains a live list of all nodes within a cluster. This node list can be queried by users (who see a subset they have access to) and administrators any time. |
|
||||
| CC6.6 - Restricts Access | The types of activities that can occur through a communication channel (for example, FTP site, router port) are restricted. | Teleport makes it easy to restrict access to common ports like 21, 22 and instead have users [tunnel to the server](../../../faq.mdx) using Teleport. [Teleport uses the following default ports.](../../../reference/networking.mdx) |
|
||||
| CC6.6 - Protects Identification and Authentication Credentials | Identification and authentication credentials are protected during transmission outside system boundaries. | [Yes, Teleport protects credentials outside your network allowing for Zero Trust network architecture](https://goteleport.com/blog/applying-principles-of-zero-trust-to-ssh/) |
|
||||
| CC6.6 - Requires Additional Authentication or Credentials | Additional authentication information or credentials are required when accessing the system from outside its boundaries. | [Yes, Teleport can manage MFA with TOTP, WebAuthn or U2F Standards or connect to your Identity Provider using SAML, OAUTH or OIDC](../../access-controls/sso.mdx) |
|
||||
| CC6.6 - Requires Additional Authentication or Credentials | Additional authentication information or credentials are required when accessing the system from outside its boundaries. | [Yes, Teleport can manage MFA with TOTP, WebAuthn or U2F Standards or connect to your Identity Provider using SAML, OAUTH or OIDC](../sso/sso.mdx) |
|
||||
| CC6.6 - Implements Boundary Protection Systems | Boundary protection systems (for example, firewalls, demilitarized zones, and intrusion detection systems) are implemented to protect external access points from attempts and unauthorized access and are monitored to detect such attempts. | [Trusted clusters](../../management/admin/trustedclusters.mdx) |
|
||||
| CC6.7 - Uses Encryption Technologies or Secure Communication Channels to Protect Data | Encryption technologies or secured communication channels are used to protect transmission of data and other communications beyond connectivity access points. | [Teleport has strong encryption including a FedRAMP compliant FIPS mode](./fedramp.mdx#start-teleport-in-fips-mode) |
|
||||
| CC7.2 - Implements Detection Policies, Procedures, and Tools | Processes are in place to detect changes to software and configuration parameters that may be indicative of unauthorized or malicious software. | [Teleport creates detailed SSH Audit Logs with Metadata](../../../reference/monitoring/audit.mdx) <br/><br/> [Use BPF Session Recording to catch malicious program execution](../../../enroll-resources/server-access/guides/bpf-session-recording.mdx) |
|
||||
|
||||
+4
-4
@@ -82,7 +82,7 @@ enforcement and Cluster-wide enforcement.
|
||||
|
||||
## Guides
|
||||
|
||||
- [Getting Started with Device Trust](./device-trust/guide.mdx)
|
||||
- [Device Management](./device-trust/device-management.mdx)
|
||||
- [Enforcing Device Trust](./device-trust/enforcing-device-trust.mdx)
|
||||
- [Jamf Pro Integration](./device-trust/jamf-integration.mdx)
|
||||
- [Getting Started with Device Trust](guide.mdx)
|
||||
- [Device Management](device-management.mdx)
|
||||
- [Enforcing Device Trust](enforcing-device-trust.mdx)
|
||||
- [Jamf Pro Integration](jamf-integration.mdx)
|
||||
@@ -14,7 +14,7 @@ Teleport if a computer is removed from Jamf Pro.
|
||||
Syncing devices from Jamf Pro is an **inventory management** step, equivalent to
|
||||
automatically running the corresponding `tctl devices add` commands.
|
||||
|
||||
See the [Device Trust guide](../device-trust.mdx) for fundamental Device Trust concepts
|
||||
See the [Device Trust guide](device-trust.mdx) for fundamental Device Trust concepts
|
||||
and behavior.
|
||||
|
||||
<Details title="This integration is hosted on Teleport Cloud" open={false}>
|
||||
|
||||
@@ -14,7 +14,7 @@ In this guide, we will set up Teleport's Just-in-Time Access Requests to require
|
||||
the approval of two team members for a privileged role `dbadmin`.
|
||||
|
||||
The steps below describe how to use Teleport with Mattermost. You can also
|
||||
[integrate with many other providers](../access-requests.mdx).
|
||||
[integrate with many other providers](../access-requests/access-requests.mdx).
|
||||
|
||||
<Notice type="warning">
|
||||
|
||||
|
||||
@@ -22,7 +22,7 @@ A lock can target the following objects or attributes:
|
||||
- a Teleport agent by the agent's server UUID (effectively unregistering it from the
|
||||
cluster)
|
||||
- a Windows desktop by the desktop's name
|
||||
- an [Access Request](../access-requests.mdx) by UUID
|
||||
- an [Access Request](../access-requests/access-requests.mdx) by UUID
|
||||
|
||||
## Prerequisites
|
||||
|
||||
|
||||
@@ -1,13 +0,0 @@
|
||||
---
|
||||
title: Configure Teleport as an identity provider
|
||||
description: How to set up Teleport's identity provider functionality
|
||||
---
|
||||
|
||||
Users can authenticate to both internal and external applications
|
||||
through the use of a built in identity provider in Teleport.
|
||||
|
||||
- [SAML Guide](./idps/saml-guide.mdx): A guide for setting up an example application to integration with the SAML identity provider.
|
||||
- [SAML Attribute Mapping](./idps/saml-attribute-mapping.mdx): A reference on how attribute mapping works in Teleport and how to
|
||||
use it to assert custom user attribute name and values in a SAML response.
|
||||
- [Use Teleport's SAML Provider to authenticate with Grafana](./idps/saml-grafana.mdx): Configure Grafana to authenticate using Teleport identities.
|
||||
- [SAML Reference](../../reference/access-controls/saml-idp.mdx): A reference for Teleport's SAML identity provider.
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
title: Configure Teleport as an identity provider
|
||||
description: How to set up Teleport's identity provider functionality
|
||||
---
|
||||
|
||||
Users can authenticate to both internal and external applications
|
||||
through the use of a built in identity provider in Teleport.
|
||||
|
||||
- [SAML Guide](saml-guide.mdx): A guide for setting up an example application to integration with the SAML identity provider.
|
||||
- [SAML Attribute Mapping](saml-attribute-mapping.mdx): A reference on how attribute mapping works in Teleport and how to
|
||||
use it to assert custom user attribute name and values in a SAML response.
|
||||
- [Use Teleport's SAML Provider to authenticate with Grafana](saml-grafana.mdx): Configure Grafana to authenticate using Teleport identities.
|
||||
- [SAML Reference](../../../reference/access-controls/saml-idp.mdx): A reference for Teleport's SAML identity provider.
|
||||
@@ -17,7 +17,7 @@ cluster on version `11.3.1` or greater.
|
||||
|
||||
Login Rules only operate on SSO logins, so make sure you have
|
||||
configured an OIDC, SAML, or GitHub connector before you begin.
|
||||
Check the [Single Sign-On](../sso.mdx) docs to learn how to set this up.
|
||||
Check the [Single Sign-On](../sso/sso.mdx) docs to learn how to set this up.
|
||||
|
||||
## Step 1/5. Configure RBAC
|
||||
|
||||
|
||||
+4
-4
@@ -19,7 +19,7 @@ Some use cases for Login Rules are:
|
||||
traits will be included in your user's SSH certificates and JWTs, which can
|
||||
become too large for some third-party applications to handle. Login Rules can
|
||||
filter out unnecessary traits and keep just the ones you need.
|
||||
- When you have multiple [Role Templates](./guides/role-templates.mdx) repeating
|
||||
- When you have multiple [Role Templates](../guides/role-templates.mdx) repeating
|
||||
the same logic to combine and transform external traits, consider using Login
|
||||
Rules to consolidate the logic to one place and simplify your Roles.
|
||||
|
||||
@@ -42,13 +42,13 @@ traits_map:
|
||||
- 'ifelse(external.groups.contains("db-admins"), external.groups.add("db-users"), external.groups)'
|
||||
```
|
||||
|
||||
Check out the [Login Rules guide](./login-rules/guide.mdx) for a quick walkthrough
|
||||
Check out the [Login Rules guide](guide.mdx) for a quick walkthrough
|
||||
that will show you how to write, test, and add the first Login Rule to your
|
||||
cluster. See [example Login Rules](./login-rules/guide.mdx#example-login-rules) to
|
||||
cluster. See [example Login Rules](guide.mdx) to
|
||||
learn how to address common use cases.
|
||||
|
||||
When you're ready to take full advantage of Login Rules in your cluster, see the
|
||||
[Login Rules Reference](../../reference/access-controls/login-rules.mdx) for details on the expression
|
||||
[Login Rules Reference](../../../reference/access-controls/login-rules.mdx) for details on the expression
|
||||
language that powers them.
|
||||
|
||||
## FAQ
|
||||
@@ -17,7 +17,7 @@ Teleport administrators to define policies like:
|
||||
|
||||
In Teleport Enterprise Cloud and Self-Hosted Teleport Enterprise, Teleport can
|
||||
automatically configure an SSO connector for you when as part of [enrolling the
|
||||
hosted Okta integration](../../../enroll-resources/application-access/okta.mdx).
|
||||
hosted Okta integration](../../../enroll-resources/application-access/okta/okta.mdx).
|
||||
|
||||
You can enroll the Okta integration from the Teleport Web UI.
|
||||
|
||||
|
||||
+22
-22
@@ -7,15 +7,15 @@ Teleport users can log in to servers, Kubernetes clusters, databases, web
|
||||
applications, and Windows desktops through their organization's Single Sign-On
|
||||
(SSO) provider.
|
||||
|
||||
- [Azure Active Directory (AD)](./sso/azuread.mdx): Configure Azure Active Directory SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [Active Directory (ADFS)](./sso/adfs.mdx): Configure Windows Active Directory SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [Google Workspace](./sso/google-workspace.mdx): Configure Google Workspace SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [GitHub](./sso/github-sso.mdx): Configure GitHub SSO for SSH,
|
||||
- [Azure Active Directory (AD)](azuread.mdx): Configure Azure Active Directory SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [Active Directory (ADFS)](adfs.mdx): Configure Windows Active Directory SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [Google Workspace](google-workspace.mdx): Configure Google Workspace SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [GitHub](github-sso.mdx): Configure GitHub SSO for SSH,
|
||||
Kubernetes, databases, desktops, and web apps.
|
||||
- [GitLab](./sso/gitlab.mdx): Configure GitLab SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [OneLogin](./sso/one-login.mdx): Configure OneLogin SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [OIDC](./sso/oidc.mdx): Configure OIDC SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [Okta](./sso/okta.mdx): Configure Okta SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [GitLab](gitlab.mdx): Configure GitLab SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [OneLogin](one-login.mdx): Configure OneLogin SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [OIDC](oidc.mdx): Configure OIDC SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
- [Okta](okta.mdx): Configure Okta SSO for SSH, Kubernetes, databases, desktops and web apps.
|
||||
|
||||
## How Teleport uses SSO
|
||||
|
||||
@@ -402,9 +402,9 @@ flow. These provider-specific changes can be enabled by setting the
|
||||
values to match your identity provider:
|
||||
|
||||
- `adfs` (SAML): Required for compatibility with Active Directory (ADFS); refer
|
||||
to the full [ADFS guide](./sso/adfs.mdx#step-23-create-teleport-roles) for details.
|
||||
to the full [ADFS guide](adfs.mdx) for details.
|
||||
- `netiq` (OIDC): Used to enable NetIQ-specific ACR value processing; refer to
|
||||
the [OIDC guide](./sso/oidc.mdx#optional-acr-values) for details.
|
||||
the [OIDC guide](oidc.mdx) for details.
|
||||
- `ping` (SAML and OIDC): Required for compatibility with Ping Identity (including
|
||||
PingOne and PingFederate).
|
||||
- `okta` (OIDC): Required when using Okta as an OIDC provider.
|
||||
@@ -456,7 +456,7 @@ $ tctl get connectors
|
||||
```
|
||||
|
||||
To delete/update connectors, use the usual `tctl rm` and `tctl create` commands
|
||||
as described in the [Resources Reference](../../reference/resources.mdx).
|
||||
as described in the [Resources Reference](../../../reference/resources.mdx).
|
||||
|
||||
If multiple authentication connectors exist, the clients must supply a
|
||||
connector name to `tsh login` via `--auth` argument:
|
||||
@@ -472,10 +472,10 @@ $ tsh --proxy=proxy.example.com login --auth=local --user=admin
|
||||
Refer to the following guides to configure authentication connectors of both
|
||||
SAML and OIDC types:
|
||||
|
||||
- [SSH Authentication with Okta](./sso/okta.mdx)
|
||||
- [SSH Authentication with OneLogin](./sso/one-login.mdx)
|
||||
- [SSH Authentication with ADFS](./sso/adfs.mdx)
|
||||
- [SSH Authentication with OAuth2 / OpenID Connect](./sso/oidc.mdx)
|
||||
- [SSH Authentication with Okta](okta.mdx)
|
||||
- [SSH Authentication with OneLogin](one-login.mdx)
|
||||
- [SSH Authentication with ADFS](adfs.mdx)
|
||||
- [SSH Authentication with OAuth2 / OpenID Connect](oidc.mdx)
|
||||
|
||||
## SSO customization
|
||||
|
||||
@@ -484,11 +484,11 @@ of SSO buttons in the Teleport Web UI.
|
||||
|
||||
| Provider | YAML | Example |
|
||||
| - | - | - |
|
||||
| GitHub | `display: GitHub` |  |
|
||||
| Microsoft | `display: Microsoft` |  |
|
||||
| Google | `display: Google` |  |
|
||||
| BitBucket | `display: Bitbucket` |  |
|
||||
| OpenID | `display: Okta` |  |
|
||||
| GitHub | `display: GitHub` |  |
|
||||
| Microsoft | `display: Microsoft` |  |
|
||||
| Google | `display: Google` |  |
|
||||
| BitBucket | `display: Bitbucket` |  |
|
||||
| OpenID | `display: Okta` |  |
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
@@ -516,7 +516,7 @@ If something is not working, we recommend to:
|
||||
If you get "access denied" or other login errors, the number one place to check is the Audit
|
||||
Log. You can access it in the **Activity** tab of the Teleport Web UI.
|
||||
|
||||

|
||||

|
||||
|
||||
Example of a user being denied because the role `clusteradmin` wasn't set up:
|
||||
|
||||
@@ -561,5 +561,5 @@ The roles we illustrated in this guide use `external` traits,
|
||||
which Teleport replaces with values from the single sign-on provider that the
|
||||
user used to authenticate with Teleport. For full details on how variable
|
||||
expansion works in Teleport roles, see the [Teleport Access Controls
|
||||
Reference](../../reference/access-controls/roles.mdx).
|
||||
Reference](../../../reference/access-controls/roles.mdx).
|
||||
|
||||
@@ -3,12 +3,12 @@ title: How to Build an Access Request Plugin
|
||||
description: Manage Access Requests using custom workflows with the Teleport API
|
||||
---
|
||||
|
||||
With Teleport [Access Requests](../access-controls/access-requests.mdx), you can
|
||||
With Teleport [Access Requests](../access-controls/access-requests/access-requests.mdx), you can
|
||||
assign Teleport users to less privileged roles by default and allow them to
|
||||
temporarily escalate their privileges. Reviewers can grant or deny Access
|
||||
Requests within your organization's existing communication workflows (e.g.,
|
||||
Slack, email, and PagerDuty) using [Access Request
|
||||
plugins](../access-controls/access-request-plugins.mdx).
|
||||
plugins](../access-controls/access-request-plugins/access-request-plugins.mdx).
|
||||
|
||||
You can use Teleport's API client library to build an Access Request plugin that
|
||||
integrates with your organization's unique workflows.
|
||||
|
||||
@@ -11,13 +11,13 @@ cluster. In this section, we will show you how to use Teleport's API.
|
||||
|
||||
Teleport has a public [Go
|
||||
client](https://pkg.go.dev/github.com/gravitational/teleport/api/client) to
|
||||
programatically interact with the API. [tsh and tctl](../../reference/cli.mdx) use
|
||||
programatically interact with the API. [tsh and tctl](../../reference/cli/cli.mdx) use
|
||||
the same API.
|
||||
|
||||
Here is what you can do with the Go Client:
|
||||
|
||||
- Integrate with external tools, e.g., to write an [Access Request
|
||||
plugin](../access-controls/access-request-plugins.mdx). Teleport
|
||||
plugin](../access-controls/access-request-plugins/access-request-plugins.mdx). Teleport
|
||||
maintains Access Request plugins for tools like Slack, Jira, and Mattermost.
|
||||
- Perform CRUD actions on resources, such as roles, authentication connectors,
|
||||
and provisioning tokens.
|
||||
|
||||
@@ -7,7 +7,7 @@ You can use Teleport's API to automatically register resources in your
|
||||
infrastructure with your Teleport cluster.
|
||||
|
||||
Teleport already supports the automatic discovery of [Kubernetes
|
||||
clusters](../../enroll-resources/auto-discovery/kubernetes.mdx) in AWS, Azure, and
|
||||
clusters](../../enroll-resources/auto-discovery/kubernetes/kubernetes.mdx) in AWS, Azure, and
|
||||
Google Cloud, as well as
|
||||
[servers](../../enroll-resources/auto-discovery/servers/ec2-discovery.mdx) on
|
||||
Amazon EC2. To support other resources and cloud providers, you can use the API
|
||||
|
||||
@@ -127,4 +127,4 @@ $ go run main.go
|
||||
- Read about Teleport [API architecture](../../reference/architecture/api-architecture.mdx) for an in-depth overview of the API and API clients.
|
||||
- Read [API authorization](../../reference/architecture/api-architecture.mdx) to learn more about defining custom roles for your API client.
|
||||
- Review the `client` [pkg.go reference documentation](https://pkg.go.dev/github.com/gravitational/teleport/api/client) for more information about working with the Teleport API programmatically.
|
||||
- Familiarize yourself with the [admin manual](../management/admin.mdx) to make the best use of the API.
|
||||
- Familiarize yourself with the [admin manual](../management/admin/admin.mdx) to make the best use of the API.
|
||||
|
||||
@@ -22,7 +22,7 @@ to Teleport Enterprise customers.
|
||||
- Helm >= (=helm.version=)
|
||||
- A running Teleport Enterprise cluster v14.3.6 or later.
|
||||
- For the purposes of this guide, we assume that the Teleport cluster is set up
|
||||
[using the `teleport-cluster` Helm chart](../../deploy-a-cluster/helm-deployments.mdx)
|
||||
[using the `teleport-cluster` Helm chart](../helm-deployments/helm-deployments.mdx)
|
||||
in the same Kubernetes cluster that will be used to deploy Access Graph.
|
||||
- An updated `license.pem` with Teleport Policy enabled.
|
||||
- A PostgreSQL database server v14 or later.
|
||||
|
||||
@@ -1,19 +0,0 @@
|
||||
---
|
||||
title: Reference Deployment Guides
|
||||
description: Teleport Installation and Configuration Reference Deployment Guides.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
These guides show you how to set up a full self-hosted Teleport deployment on
|
||||
the platform of your choice.
|
||||
|
||||
- [AWS High Availability Deployment with Terraform](./deployments/aws-ha-autoscale-cluster-terraform.mdx): Deploy HA Teleport with
|
||||
Terraform on AWS.
|
||||
- [AWS Single-Instance Deployment with Terraform](./deployments/aws-starter-cluster-terraform.mdx): Deploy Teleport on a single instance with
|
||||
Terraform on AWS.
|
||||
- [AWS Multi-Region Proxy
|
||||
Deployment](./deployments/aws-gslb-proxy-peering-ha-deployment.mdx): Deploy HA
|
||||
Teleport with Proxy Service instances in multiple regions for low-latency
|
||||
access.
|
||||
- [GCP](./deployments/gcp.mdx): Deploy HA Teleport on GCP.
|
||||
- [IBM Cloud](./deployments/ibm.mdx): Deploy HA Teleport on IBM cloud.
|
||||
+1
-1
@@ -837,7 +837,7 @@ To add new nodes/EC2 servers that you can "SSH into" you'll need to:
|
||||
- [Run Teleport - we recommend using systemd](../../management/admin/daemon.mdx)
|
||||
- [Set the correct settings in /etc/teleport.yaml](../../../reference/config.mdx)
|
||||
- [Add Nodes to the Teleport
|
||||
cluster](../../../enroll-resources/agents/join-services-to-your-cluster.mdx)
|
||||
cluster](../../../enroll-resources/agents/join-services-to-your-cluster/join-services-to-your-cluster.mdx)
|
||||
|
||||
### Getting the SSH Service join token
|
||||
|
||||
|
||||
+1
-1
@@ -726,7 +726,7 @@ To add new nodes/EC2 servers that you can "SSH into" you'll need to:
|
||||
- [Run Teleport - we recommend using systemd](../../management/admin/daemon.mdx)
|
||||
- [Set the correct settings in /etc/teleport.yaml](../../../reference/config.mdx)
|
||||
- [Add Nodes to the Teleport
|
||||
cluster](../../../enroll-resources/agents/join-services-to-your-cluster.mdx)
|
||||
cluster](../../../enroll-resources/agents/join-services-to-your-cluster/join-services-to-your-cluster.mdx)
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
---
|
||||
title: Reference Deployment Guides
|
||||
description: Teleport Installation and Configuration Reference Deployment Guides.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
These guides show you how to set up a full self-hosted Teleport deployment on
|
||||
the platform of your choice.
|
||||
|
||||
- [AWS High Availability Deployment with Terraform](aws-ha-autoscale-cluster-terraform.mdx): Deploy HA Teleport with
|
||||
Terraform on AWS.
|
||||
- [AWS Single-Instance Deployment with Terraform](aws-starter-cluster-terraform.mdx): Deploy Teleport on a single instance with
|
||||
Terraform on AWS.
|
||||
- [AWS Multi-Region Proxy
|
||||
Deployment](aws-gslb-proxy-peering-ha-deployment.mdx): Deploy HA
|
||||
Teleport with Proxy Service instances in multiple regions for low-latency
|
||||
access.
|
||||
- [GCP](gcp.mdx): Deploy HA Teleport on GCP.
|
||||
- [IBM Cloud](ibm.mdx): Deploy HA Teleport on IBM cloud.
|
||||
+9
-9
@@ -15,24 +15,24 @@ order to protect a Kubernetes cluster with Teleport, and it is possible to
|
||||
enroll a Kubernetes cluster on Teleport Cloud or by running the Teleport
|
||||
Kubernetes Service on a Linux server. For instructions on enrolling a Kubernetes
|
||||
cluster with Teleport, read the [Kubernetes
|
||||
Access](../../enroll-resources/kubernetes-access/introduction.mdx) documentation.
|
||||
Access](../../../enroll-resources/kubernetes-access/introduction.mdx) documentation.
|
||||
|
||||
## Helm deployment guides
|
||||
|
||||
These guides show you how to set up a full self-hosted Teleport deployment using
|
||||
our `teleport-cluster` Helm chart.
|
||||
|
||||
- [Deploy Teleport on Kubernetes](./helm-deployments/kubernetes-cluster.mdx): Run a Teleport cluster in a Kubernetes cluster using
|
||||
- [Deploy Teleport on Kubernetes](kubernetes-cluster.mdx): Run a Teleport cluster in a Kubernetes cluster using
|
||||
the default configuration. This deployment is a great starting point to try a self-hosted
|
||||
Teleport with minimal resources.
|
||||
- [HA AWS Teleport Cluster](./helm-deployments/aws.mdx): Running an HA Teleport cluster in Kubernetes using an AWS EKS Cluster
|
||||
- [HA Azure Teleport Cluster](./helm-deployments/azure.mdx): Running an HA Teleport cluster in Kubernetes using an Azure AKS Cluster
|
||||
- [HA GCP Teleport Cluster](./helm-deployments/gcp.mdx): Running an HA Teleport cluster in Kubernetes using a Google Cloud GKE Cluster
|
||||
- [DigitalOcean Kubernetes Cluster](./helm-deployments/digitalocean.mdx):
|
||||
- [HA AWS Teleport Cluster](aws.mdx): Running an HA Teleport cluster in Kubernetes using an AWS EKS Cluster
|
||||
- [HA Azure Teleport Cluster](azure.mdx): Running an HA Teleport cluster in Kubernetes using an Azure AKS Cluster
|
||||
- [HA GCP Teleport Cluster](gcp.mdx): Running an HA Teleport cluster in Kubernetes using a Google Cloud GKE Cluster
|
||||
- [DigitalOcean Kubernetes Cluster](digitalocean.mdx):
|
||||
Running Teleport on DigitalOcean Kubernetes.
|
||||
- [Custom Teleport config](./helm-deployments/custom.mdx): Running a Teleport cluster in Kubernetes with a custom Teleport config
|
||||
- [Custom Teleport config](custom.mdx): Running a Teleport cluster in Kubernetes with a custom Teleport config
|
||||
|
||||
## Migration Guides
|
||||
|
||||
- [Migrating from v11 to v12](./helm-deployments/migration-v12.mdx)
|
||||
- [Kubernetes 1.25 and PSP removal](./helm-deployments/migration-kubernetes-1-25-psp.mdx)
|
||||
- [Migrating from v11 to v12](migration-v12.mdx)
|
||||
- [Kubernetes 1.25 and PSP removal](migration-kubernetes-1-25-psp.mdx)
|
||||
@@ -372,13 +372,13 @@ cluster.
|
||||
- **Set up Single Sign-On:** In this guide, we showed you how to create a local
|
||||
user, which is appropriate for demo environments. For a production deployment,
|
||||
you should set up Single Sign-On with your provider of choice. See our [Single
|
||||
Sign-On guides](../../access-controls/sso.mdx) for how to do this.
|
||||
Sign-On guides](../../access-controls/sso/sso.mdx) for how to do this.
|
||||
- **Configure your Teleport deployment:** To see all of the options you can set
|
||||
in the values file for the `teleport-cluster` Helm chart, consult our
|
||||
[reference guide](../../../reference/helm-reference/teleport-cluster.mdx).
|
||||
- **Register resources:** You can register all of the Kubernetes clusters in
|
||||
your infrastructure with Teleport. To start, read our [Auto-Discovery
|
||||
guides](../../../enroll-resources/auto-discovery/kubernetes.mdx) to see how to automatically
|
||||
guides](../../../enroll-resources/auto-discovery/kubernetes/kubernetes.mdx) to see how to automatically
|
||||
register every cluster in your cloud. You can also register servers,
|
||||
databases, applications, and Windows desktops.
|
||||
- **Fine-tune your Kubernetes RBAC:** While the user you created in this guide
|
||||
|
||||
@@ -296,7 +296,7 @@ pod or virtual machine in your group.
|
||||
|
||||
If you plan to run Teleport on Kubernetes, the `teleport-cluster` Helm chart
|
||||
deploys the Auth Service and Proxy Service pools for you. To see how to use this
|
||||
Helm chart, read our [Helm Deployments](helm-deployments.mdx) documentation.
|
||||
Helm chart, read our [Helm Deployments](helm-deployments/helm-deployments.mdx) documentation.
|
||||
|
||||
</Notice>
|
||||
|
||||
@@ -353,7 +353,7 @@ Create a configuration file and provide it to each of your Proxy Service
|
||||
instances at `/etc/teleport.yaml`. We will explain the required configuration
|
||||
fields for a high-availability Teleport deployment below. These are the minimum
|
||||
requirements, and when planning your high-availability deployment, you will want
|
||||
to follow a more specific [deployment guide](deployments.mdx) for your
|
||||
to follow a more specific [deployment guide](deployments/deployments.mdx) for your
|
||||
environment.
|
||||
|
||||
#### `proxy_service` and `auth_service`
|
||||
@@ -467,7 +467,7 @@ Create a configuration file and provide it to each of your Auth Service
|
||||
instances at `/etc/teleport.yaml`. We will explain the required configuration
|
||||
fields for a high-availability Teleport deployment below. These are the minimum
|
||||
requirements, and when planning your high-availability deployment, you will want
|
||||
to follow a more specific [deployment guide](deployments.mdx) for your
|
||||
to follow a more specific [deployment guide](deployments/deployments.mdx) for your
|
||||
environment.
|
||||
|
||||
#### `storage`
|
||||
@@ -540,8 +540,8 @@ deployment, read about how to design your own deployment on Kubernetes or a
|
||||
cluster of virtual machines in your cloud of choice:
|
||||
|
||||
- [High-availability Teleport Deployments on Kubernetes with
|
||||
Helm](helm-deployments.mdx)
|
||||
- [Reference Deployments](deployments.mdx) for running Teleport on a cluster of
|
||||
Helm](helm-deployments/helm-deployments.mdx)
|
||||
- [Reference Deployments](deployments/deployments.mdx) for running Teleport on a cluster of
|
||||
virtual machines
|
||||
|
||||
### Ensure high performance
|
||||
@@ -550,7 +550,7 @@ You should also get familiar with how to ensure that your Teleport deployment is
|
||||
performing as expected:
|
||||
|
||||
- [Scaling a Teleport cluster](../management/operations/scaling.mdx)
|
||||
- [Monitoring a Teleport cluster](../management/diagnostics.mdx)
|
||||
- [Monitoring a Teleport cluster](../management/diagnostics/diagnostics.mdx)
|
||||
|
||||
### Deploy Teleport services
|
||||
|
||||
|
||||
+13
-13
@@ -27,7 +27,7 @@ There are two ways to configure a Teleport cluster:
|
||||
This approach makes it possible to incrementally adjust your Teleport
|
||||
configuration without restarting Teleport instances.
|
||||
|
||||

|
||||

|
||||
|
||||
A cluster is composed of different objects (i.e., resources) and there are three
|
||||
common operations that can be performed on them: `get` , `create` , and `remove`
|
||||
@@ -64,13 +64,13 @@ infrastructure-as-code and GitOps approaches.
|
||||
|
||||
You can get started with `tctl`, the Terraform Provider, and the Kubernetes
|
||||
Operator by following:
|
||||
- the ["Managing Users and Roles with IaC" guide](infrastructure-as-code/managing-resources/user-and-role.mdx)
|
||||
- the ["Creating Access Lists with IaC" guide](infrastructure-as-code/managing-resources/access-list.mdx)
|
||||
- the ["Registering Agentless OpenSSH Servers with IaC" guide](infrastructure-as-code/managing-resources/agentless-ssh-servers.mdx)
|
||||
- the ["Managing Users and Roles with IaC" guide](managing-resources/user-and-role.mdx)
|
||||
- the ["Creating Access Lists with IaC" guide](managing-resources/access-list.mdx)
|
||||
- the ["Registering Agentless OpenSSH Servers with IaC" guide](managing-resources/agentless-ssh-servers.mdx)
|
||||
|
||||
For more information on Teleport roles, including the `internal.logins`
|
||||
trait we use in these example roles, see the [Teleport Access
|
||||
Controls Reference](../reference/access-controls/roles.mdx).
|
||||
Controls Reference](../../reference/access-controls/roles.mdx).
|
||||
|
||||
### YAML documents with `tctl`
|
||||
|
||||
@@ -92,7 +92,7 @@ spec:
|
||||
|
||||
Since `tctl` works from the local filesystem, you can write commands that apply
|
||||
all configuration documents in a directory tree. See the [CLI
|
||||
reference](../reference/cli/tctl.mdx) for more information on `tctl`.
|
||||
reference](../../reference/cli/tctl.mdx) for more information on `tctl`.
|
||||
|
||||
### Teleport Terraform provider
|
||||
|
||||
@@ -121,7 +121,7 @@ resource "teleport_role" "developer" {
|
||||
```
|
||||
|
||||
[Get started with the Terraform
|
||||
provider](infrastructure-as-code/terraform-provider.mdx).
|
||||
provider](terraform-provider/terraform-provider.mdx).
|
||||
|
||||
### Teleport Kubernetes Operator
|
||||
|
||||
@@ -142,7 +142,7 @@ spec:
|
||||
'env': 'test'
|
||||
```
|
||||
|
||||
[Get started with the Kubernetes Operator](infrastructure-as-code/teleport-operator.mdx).
|
||||
[Get started with the Kubernetes Operator](teleport-operator/teleport-operator.mdx).
|
||||
|
||||
## Reconciling the configuration file with dynamic resources
|
||||
|
||||
@@ -255,16 +255,16 @@ configuration resources with the `teleport.dev/origin=config-file` label.
|
||||
### Configuration references
|
||||
|
||||
- For a comprehensive reference of Teleport's static configuration options, read
|
||||
the [Configuration Reference](../reference/config.mdx).
|
||||
the [Configuration Reference](../../reference/config.mdx).
|
||||
- To see the dynamic configuration resources available to apply, read the
|
||||
[Configuration Resource Reference](../reference/resources.mdx). There are also
|
||||
[Configuration Resource Reference](../../reference/resources.mdx). There are also
|
||||
dedicated configuration resource references for
|
||||
[applications](../reference/agent-services/application-access.mdx) and
|
||||
[databases](../reference/agent-services/database-access-reference/configuration.mdx).
|
||||
[applications](../../reference/agent-services/application-access.mdx) and
|
||||
[databases](../../reference/agent-services/database-access-reference/configuration.mdx).
|
||||
|
||||
### Other ways to use the Teleport API
|
||||
|
||||
The Teleport Kubernetes Operator, Terraform provider, and `tctl` are all clients
|
||||
of the Teleport Auth Service's gRPC API. To build your own API client to extend
|
||||
Teleport for your organization's needs, read our [API
|
||||
guides](api/api.mdx).
|
||||
guides](../api/api.mdx).
|
||||
+1
-1
@@ -43,7 +43,7 @@ $ export OPERATOR_NAMESPACE="teleport-iac"
|
||||
</TabItem>
|
||||
<TabItem label="Terraform">
|
||||
|
||||
A functional Teleport Terraform provider by following [the Terraform provider guide](../terraform-provider.mdx).
|
||||
A functional Teleport Terraform provider by following [the Terraform provider guide](../terraform-provider/terraform-provider.mdx).
|
||||
|
||||
</TabItem>
|
||||
</Tabs>
|
||||
|
||||
+1
-1
@@ -84,4 +84,4 @@ cluster configuration matches your expectations.
|
||||
Provider to create Teleport users and grant them roles.
|
||||
- Explore the full list of supported [Terraform provider
|
||||
resources](../../../reference/terraform-provider.mdx).
|
||||
- See [the list of supported Teleport Terraform setups](../terraform-provider.mdx):
|
||||
- See [the list of supported Teleport Terraform setups](../terraform-provider/terraform-provider.mdx):
|
||||
|
||||
+2
-2
@@ -39,7 +39,7 @@ This guide is applicable if you self-host Teleport in Kubernetes using the
|
||||
|
||||
</Admonition>
|
||||
|
||||
- Follow the [Teleport operator guides](../teleport-operator.mdx)
|
||||
- Follow the [Teleport operator guides](../teleport-operator/teleport-operator.mdx)
|
||||
to install the Teleport Operator in your Kubernetes cluster.
|
||||
Make sure to follow the Enterprise instructions if you're deploying the
|
||||
operator as part of the `teleport-cluster` chart.
|
||||
@@ -245,7 +245,7 @@ logins:
|
||||
|
||||
## Next Steps
|
||||
|
||||
- Read the [Teleport Operator Guide](../teleport-operator.mdx) to
|
||||
- Read the [Teleport Operator Guide](../teleport-operator/teleport-operator.mdx) to
|
||||
learn more about the Teleport Operator.
|
||||
- Read the [Login Rules reference](../../../reference/access-controls/login-rules.mdx) to learn mode about the
|
||||
Login Rule expression syntax.
|
||||
|
||||
+2
-2
@@ -27,7 +27,7 @@ For simplicity, this guide will configure the Terraform provider to use your
|
||||
current logged-in user's Teleport credentials obtained from `tsh login`.
|
||||
|
||||
<Admonition type="note">
|
||||
The [Terraform provider guide](../terraform-provider.mdx)
|
||||
The [Terraform provider guide](../terraform-provider/terraform-provider.mdx)
|
||||
includes instructions for configuring a dedicated `terraform` user and role,
|
||||
which is a better option when running Terraform in a non-interactive
|
||||
environment.
|
||||
@@ -152,7 +152,7 @@ logins:
|
||||
|
||||
## Next Steps
|
||||
|
||||
- Read the [Terraform Guide](../terraform-provider.mdx) to
|
||||
- Read the [Terraform Guide](../terraform-provider/terraform-provider.mdx) to
|
||||
learn more about configuring the Terraform provider.
|
||||
- Read the [Login Rules reference](../../../reference/access-controls/login-rules.mdx) to learn mode about the
|
||||
Login Rule expression syntax.
|
||||
|
||||
@@ -44,7 +44,7 @@ $ export OPERATOR_NAMESPACE="teleport-iac"
|
||||
</TabItem>
|
||||
<TabItem label="Terraform">
|
||||
|
||||
A functional Teleport Terraform provider by following [the Terraform provider guide](../terraform-provider.mdx).
|
||||
A functional Teleport Terraform provider by following [the Terraform provider guide](../terraform-provider/terraform-provider.mdx).
|
||||
|
||||
</TabItem>
|
||||
</Tabs>
|
||||
@@ -480,13 +480,13 @@ resource "teleport_user" "bob" {
|
||||
- Allow users with the `manager` role to grant access to production servers to
|
||||
some `engineers` via Access Lists. Manager will need to justify and review
|
||||
granted access periodically.
|
||||
See [the AccessList documentation](../../access-controls/access-lists.mdx) for
|
||||
See [the AccessList documentation](../../access-controls/access-lists/access-lists.mdx) for
|
||||
a high-level explanation of the feature,
|
||||
and [the AccessList IaC guide](access-list.mdx) for a step by step IaC
|
||||
AccessList setup.
|
||||
- Allow users with the `engineer` role to request temporary access to
|
||||
production, and have users with the `manager` role validate the requests.
|
||||
See [the Access Requests documentation](../../access-controls/access-requests.mdx)
|
||||
See [the Access Requests documentation](../../access-controls/access-requests/access-requests.mdx)
|
||||
- You can see all supported fields in the references
|
||||
of [the user resource](../../../reference/resources.mdx)
|
||||
and [the role resource](../../../reference/resources.mdx).
|
||||
|
||||
@@ -18,7 +18,7 @@ Currently only the GithubConnector and OIDCConnector `client_secret` field suppo
|
||||
To follow this guide you need:
|
||||
|
||||
- A running Teleport cluster
|
||||
- [A functional Teleport Kubernetes operator setup](../teleport-operator.mdx#setting-up-the-operator)
|
||||
- [A functional Teleport Kubernetes operator setup](teleport-operator.mdx)
|
||||
- Kubernetes rights to edit CRs and Secrets in the operator namespace
|
||||
- `kubectl` installed locally and configured for your Kubernetes cluster
|
||||
- A working GitHub or OIDC connector you want to manage with the operator
|
||||
|
||||
+1
-1
@@ -104,7 +104,7 @@ roles.
|
||||
|
||||
Helm Chart parameters are documented in the [`teleport-cluster` Helm chart reference](../../../reference/helm-reference/teleport-cluster.mdx).
|
||||
|
||||
See the [Helm Deployment guides](../../deploy-a-cluster/helm-deployments.mdx) detailing specific setups like running Teleport on AWS or GCP.
|
||||
See the [Helm Deployment guides](../../deploy-a-cluster/helm-deployments/helm-deployments.mdx) detailing specific setups like running Teleport on AWS or GCP.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
|
||||
+5
-5
@@ -40,10 +40,10 @@ Currently supported Teleport resources are:
|
||||
### Setting up the operator
|
||||
|
||||
If you are self-hosting Teleport using the `teleport-cluster` Helm chart,
|
||||
follow [the guide for Helm-deployed clusters](teleport-operator/teleport-operator-helm.mdx).
|
||||
follow [the guide for Helm-deployed clusters](teleport-operator-helm.mdx).
|
||||
|
||||
If you are hosting Teleport out of Kubernetes (Teleport Cloud, Terraform, ...),
|
||||
follow [the standalone operator guide](teleport-operator/teleport-operator-standalone.mdx).
|
||||
follow [the standalone operator guide](teleport-operator-standalone.mdx).
|
||||
|
||||
### Control reconciliation with annotations
|
||||
|
||||
@@ -81,7 +81,7 @@ Even when you store sensitive values out of CRs, the CRs must still be considere
|
||||
the Kubernetes secrets themselves. Many CRs configure Teleport RBAC. Someone with CR editing permissions can become a
|
||||
Teleport administrator and retrieve the sensitive values from Teleport.
|
||||
|
||||
See [the dedicated guide](./teleport-operator/secret-lookup.mdx) for more details.
|
||||
See [the dedicated guide](secret-lookup.mdx) for more details.
|
||||
|
||||
### Troubleshooting
|
||||
|
||||
@@ -89,5 +89,5 @@ See [the dedicated guide](./teleport-operator/secret-lookup.mdx) for more detail
|
||||
|
||||
## Next steps
|
||||
|
||||
- Follow the ["Managing users and roles with IaC" guide](managing-resources/user-and-role.mdx).
|
||||
- Check out [access controls documentation](../access-controls/access-controls.mdx).
|
||||
- Follow the ["Managing users and roles with IaC" guide](../managing-resources/user-and-role.mdx).
|
||||
- Check out [access controls documentation](../../access-controls/access-controls.mdx).
|
||||
@@ -1,39 +0,0 @@
|
||||
---
|
||||
title: Configuring Teleport with Terraform
|
||||
description: How to manage dynamic resources using the Teleport Terraform provider.
|
||||
videoBanner: YgNHD4SS8dg
|
||||
---
|
||||
|
||||
The Teleport Terraform provider allows Teleport administrators to use Terraform to configure Teleport via
|
||||
dynamic resources.
|
||||
|
||||
## Setup
|
||||
|
||||
For instructions on managing users and roles via Terraform, read
|
||||
the ["Managing users and roles with IaC" guide](managing-resources/user-and-role.mdx).
|
||||
|
||||
The provider must obtain an identity to connect to Teleport. The method to obtain it depends on where the Terraform code
|
||||
is executed. You must pick the correct guide for your setup:
|
||||
|
||||
| Guide | Use-case | How it works |
|
||||
|---------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| [Run the Teleport Terraform provider locally](./terraform-provider/local.mdx) | You are getting started with the Teleport Terraform provider and managing Teleport resources with IaC. | You use local credentials to create a temporary bot, obtain short-lived credentials, and store them in environment variables. |
|
||||
| [Run the Teleport Terraform provider on Terraform Cloud](./terraform-provider/terraform-cloud.mdx) | You're running on HCP Terraform (Terraform Cloud) or self-hosted Terraform Enterprise. | Terraform Cloud Workload Identity issues a proof of identity and the Teleport Terraform provider uses it to authenticate. |
|
||||
| [Run the Teleport Terraform provider in CI or a cloud VM](./terraform-provider/ci-or-cloud.mdx) | You already have a working Terraform module configuring Teleport and want to run it in CI to benefit from review and audit capabilities from your versioning system (e.g. git). | You're using a proof provided by your runtime (CI engine, cloud provider) to prove your identity and join using MachineID. |
|
||||
| [Run the Teleport Terraform provider on Spacelift](./terraform-provider/spacelift.mdx) | You already have a working Terraform module configuring Teleport and want to run it on the Spacelift platform. | You're using a proof provided by Spacelift to prove your identity and join using MachineID. |
|
||||
| [Run the Teleport Terraform provider from a server](./terraform-provider/dedicated-server.mdx) | You have working Terraform code and want to run it on a dedicated server. The server is long-lived, like a bastion or a task runner. | You setup a MachineID daemon (`tbot`) that obtains and refreshes credentials for the Terraform provider. |
|
||||
| [Run the Teleport Terraform provider with long-lived credentials.](./terraform-provider/long-lived-credentials.mdx) | This method is discouraged as less secure than the others. This should be used when none of the other methods work in your case (short-lived CI environments that don't have dedicated Teleport join methods). | You sign one long lived certificate allowing the Terraform provider to connect to Teleport. |
|
||||
|
||||
## Resource guides
|
||||
|
||||
Once you have a functional Teleport Terraform provider, you will want to configure your resources with it.
|
||||
|
||||
You can find the list of supported resources and their fields is
|
||||
available [in the Terraform reference](../../reference/terraform-provider.mdx).
|
||||
|
||||
Some resources have their dedicated Infrastructure-as-Code (IaC) step-by step guides such as:
|
||||
- [Managing Users And Roles With IaC](managing-resources/user-and-role.mdx)
|
||||
- [Creating Access Lists with IaC](managing-resources/access-list.mdx)
|
||||
- [Registering Agentless OpenSSH Servers with IaC](managing-resources/agentless-ssh-servers.mdx)
|
||||
|
||||
Finally, you can [import your existing resources in Terraform](managing-resources/import-existing-resources.mdx).
|
||||
+1
-1
@@ -13,7 +13,7 @@ they hold full Teleport administrative access. You should prefer
|
||||
using [`tbot`](./dedicated-server.mdx), [native MachineID joining](./ci-or-cloud.mdx) in CI or Cloud environments,
|
||||
or [create temporary bots for local use](./local.mdx) when possible.
|
||||
|
||||
See [the list of possible Terraform provider setups](../terraform-provider.mdx#setup) to find which one fits your
|
||||
See [the list of possible Terraform provider setups](terraform-provider.mdx) to find which one fits your
|
||||
use-case.
|
||||
|
||||
</Admonition>
|
||||
|
||||
+39
@@ -0,0 +1,39 @@
|
||||
---
|
||||
title: Configuring Teleport with Terraform
|
||||
description: How to manage dynamic resources using the Teleport Terraform provider.
|
||||
videoBanner: YgNHD4SS8dg
|
||||
---
|
||||
|
||||
The Teleport Terraform provider allows Teleport administrators to use Terraform to configure Teleport via
|
||||
dynamic resources.
|
||||
|
||||
## Setup
|
||||
|
||||
For instructions on managing users and roles via Terraform, read
|
||||
the ["Managing users and roles with IaC" guide](../managing-resources/user-and-role.mdx).
|
||||
|
||||
The provider must obtain an identity to connect to Teleport. The method to obtain it depends on where the Terraform code
|
||||
is executed. You must pick the correct guide for your setup:
|
||||
|
||||
| Guide | Use-case | How it works |
|
||||
|---------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| [Run the Teleport Terraform provider locally](local.mdx) | You are getting started with the Teleport Terraform provider and managing Teleport resources with IaC. | You use local credentials to create a temporary bot, obtain short-lived credentials, and store them in environment variables. |
|
||||
| [Run the Teleport Terraform provider on Terraform Cloud](terraform-cloud.mdx) | You're running on HCP Terraform (Terraform Cloud) or self-hosted Terraform Enterprise. | Terraform Cloud Workload Identity issues a proof of identity and the Teleport Terraform provider uses it to authenticate. |
|
||||
| [Run the Teleport Terraform provider in CI or a cloud VM](ci-or-cloud.mdx) | You already have a working Terraform module configuring Teleport and want to run it in CI to benefit from review and audit capabilities from your versioning system (e.g. git). | You're using a proof provided by your runtime (CI engine, cloud provider) to prove your identity and join using MachineID. |
|
||||
| [Run the Teleport Terraform provider on Spacelift](spacelift.mdx) | You already have a working Terraform module configuring Teleport and want to run it on the Spacelift platform. | You're using a proof provided by Spacelift to prove your identity and join using MachineID. |
|
||||
| [Run the Teleport Terraform provider from a server](dedicated-server.mdx) | You have working Terraform code and want to run it on a dedicated server. The server is long-lived, like a bastion or a task runner. | You setup a MachineID daemon (`tbot`) that obtains and refreshes credentials for the Terraform provider. |
|
||||
| [Run the Teleport Terraform provider with long-lived credentials.](long-lived-credentials.mdx) | This method is discouraged as less secure than the others. This should be used when none of the other methods work in your case (short-lived CI environments that don't have dedicated Teleport join methods). | You sign one long lived certificate allowing the Terraform provider to connect to Teleport. |
|
||||
|
||||
## Resource guides
|
||||
|
||||
Once you have a functional Teleport Terraform provider, you will want to configure your resources with it.
|
||||
|
||||
You can find the list of supported resources and their fields is
|
||||
available [in the Terraform reference](../../../reference/terraform-provider.mdx).
|
||||
|
||||
Some resources have their dedicated Infrastructure-as-Code (IaC) step-by step guides such as:
|
||||
- [Managing Users And Roles With IaC](../managing-resources/user-and-role.mdx)
|
||||
- [Creating Access Lists with IaC](../managing-resources/access-list.mdx)
|
||||
- [Registering Agentless OpenSSH Servers with IaC](../managing-resources/agentless-ssh-servers.mdx)
|
||||
|
||||
Finally, you can [import your existing resources in Terraform](../managing-resources/import-existing-resources.mdx).
|
||||
+2
-2
@@ -5,7 +5,7 @@ description: Explains how to deploy a pool of Teleport Agents so you can apply d
|
||||
---
|
||||
|
||||
*This guide is Part One of the Teleport Terraform starter guide. Read the
|
||||
[overview](../terraform-starter.mdx) for the scope and purpose of the Terraform
|
||||
[overview](terraform-starter.mdx) for the scope and purpose of the Terraform
|
||||
starter guide.*
|
||||
|
||||
This guide shows you how to use Terraform to enroll infrastructure resources
|
||||
@@ -25,7 +25,7 @@ Agents](../../../enroll-resources/agents/introduction.mdx).
|
||||
|
||||
There are several methods you can use to join a Teleport Agent to your cluster,
|
||||
which we discuss in the [Joining Services to your
|
||||
Cluster](../../../enroll-resources/agents/join-services-to-your-cluster.mdx) guide. In this guide, we will use
|
||||
Cluster](../../../enroll-resources/agents/join-services-to-your-cluster/join-services-to-your-cluster.mdx) guide. In this guide, we will use
|
||||
the **join token** method, where the operator stores a secure token on the Auth
|
||||
Service, and an Agent presents the token in order to join a cluster.
|
||||
|
||||
|
||||
@@ -5,7 +5,7 @@ description: Explains how to manage Teleport roles and authentication connectors
|
||||
---
|
||||
|
||||
*This guide is Part Two of the Teleport Terraform starter guide. Read the
|
||||
[overview](../terraform-starter.mdx) for the scope and purpose of the Terraform
|
||||
[overview](terraform-starter.mdx) for the scope and purpose of the Terraform
|
||||
starter guide.*
|
||||
|
||||
In [Part One](enroll-resources.mdx) of this series, we showed you how to use
|
||||
|
||||
+3
-4
@@ -9,8 +9,7 @@ Teleport resources to manage with Terraform in order to accomplish common
|
||||
Teleport setup tasks. You can use the example module as a starting point for
|
||||
managing a complete set of Teleport cluster resources.
|
||||
|
||||
The guides in the Terraform starter module assume that you have [a working Terraform provider setup](
|
||||
./terraform-provider.mdx) on your workstation.
|
||||
The guides in the Terraform starter module assume that you have [a working Terraform provider setup](../terraform-provider/terraform-provider.mdx) on your workstation.
|
||||
|
||||
## Part One: Enroll resources
|
||||
|
||||
@@ -20,7 +19,7 @@ Teleport Agents on virtual machine instances. You can then declare dynamic
|
||||
infrastructure resources with Terraform or change the configuration file
|
||||
provided to each Agent.
|
||||
|
||||
[Read Part One](./terraform-starter/enroll-resources.mdx).
|
||||
[Read Part One](enroll-resources.mdx).
|
||||
|
||||
## Part Two: Configure RBAC
|
||||
|
||||
@@ -32,5 +31,5 @@ roles by default but can request access to more privileged roles. An
|
||||
authentication connector lets users authenticate to Teleport using a Single
|
||||
Sign-On provider.
|
||||
|
||||
[Read Part Two](./terraform-starter/rbac.mdx).
|
||||
[Read Part Two](rbac.mdx).
|
||||
|
||||
@@ -1,30 +0,0 @@
|
||||
---
|
||||
title: Cluster Administration Guides
|
||||
description: Teleport Cluster Administration Guides.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
The guides in this section show you the fundamentals of setting up and running a
|
||||
Teleport cluster. You will learn how to run the `teleport` daemon, manage users
|
||||
and resources, and troubleshoot any issues that arise.
|
||||
|
||||
If you already understand how to set up a Teleport cluster, consult the
|
||||
[Operations](./operations.mdx) section so you can start conducting periodic
|
||||
cluster maintenance tasks.
|
||||
|
||||
## Run Teleport
|
||||
|
||||
- [Teleport Daemon](./admin/daemon.mdx): Set up Teleport as a daemon on Linux with systemd.
|
||||
- [Run Teleport with Self-Signed Certificates](./admin/self-signed-certs.mdx): Set up Teleport in a local
|
||||
environment without configuring TLS certificates.
|
||||
|
||||
## Manage users and resources
|
||||
|
||||
- [Trusted Clusters](./admin/trustedclusters.mdx): Connect multiple Teleport clusters using trusted clusters.
|
||||
- [Labels](./admin/labels.mdx): Manage resource metadata with labels.
|
||||
- [Local Users](./admin/users.mdx): Manage local user accounts.
|
||||
|
||||
## Troubleshoot issues
|
||||
|
||||
- [Troubleshooting](./admin/troubleshooting.mdx): Collect metrics and diagnostic information from Teleport.
|
||||
- [Uninstall Teleport](./admin/uninstall-teleport.mdx): Uninstall Teleport from your system.
|
||||
@@ -0,0 +1,30 @@
|
||||
---
|
||||
title: Cluster Administration Guides
|
||||
description: Teleport Cluster Administration Guides.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
The guides in this section show you the fundamentals of setting up and running a
|
||||
Teleport cluster. You will learn how to run the `teleport` daemon, manage users
|
||||
and resources, and troubleshoot any issues that arise.
|
||||
|
||||
If you already understand how to set up a Teleport cluster, consult the
|
||||
[Operations](../operations/operations.mdx) section so you can start conducting periodic
|
||||
cluster maintenance tasks.
|
||||
|
||||
## Run Teleport
|
||||
|
||||
- [Teleport Daemon](daemon.mdx): Set up Teleport as a daemon on Linux with systemd.
|
||||
- [Run Teleport with Self-Signed Certificates](self-signed-certs.mdx): Set up Teleport in a local
|
||||
environment without configuring TLS certificates.
|
||||
|
||||
## Manage users and resources
|
||||
|
||||
- [Trusted Clusters](trustedclusters.mdx): Connect multiple Teleport clusters using trusted clusters.
|
||||
- [Labels](labels.mdx): Manage resource metadata with labels.
|
||||
- [Local Users](users.mdx): Manage local user accounts.
|
||||
|
||||
## Troubleshoot issues
|
||||
|
||||
- [Troubleshooting](troubleshooting.mdx): Collect metrics and diagnostic information from Teleport.
|
||||
- [Uninstall Teleport](uninstall-teleport.mdx): Uninstall Teleport from your system.
|
||||
@@ -110,7 +110,7 @@ configured with a single sign-on identity provider that authenticates her identi
|
||||
Based on the information from the identity provider, the root cluster assigns Alice the `full-access` role
|
||||
and issues her a certificate. The mapping of single sign-on properties to Teleport roles is configured when
|
||||
you add an authentication connector to the Teleport cluster. To learn more about configuring single sign-on
|
||||
through an external identity provider, see [Configure Single Sign-on](../../access-controls/sso.mdx).
|
||||
through an external identity provider, see [Configure Single Sign-on](../../access-controls/sso/sso.mdx).
|
||||
|
||||
Alice receives the certificate that specifies the roles assigned to her in the root cluster. This metadata
|
||||
about her roles is contained in the certificate extensions and is protected by the signature of the root
|
||||
@@ -167,7 +167,7 @@ To complete the steps in this guide, verify your environment meets the following
|
||||
|
||||
- A Teleport SSH server that is joined to the cluster you plan to use as the **leaf cluster**.
|
||||
For information about how to enroll a resource in your cluster, see
|
||||
[Join Services to your Cluster](../../../enroll-resources/agents/join-services-to-your-cluster.mdx).
|
||||
[Join Services to your Cluster](../../../enroll-resources/agents/join-services-to-your-cluster/join-services-to-your-cluster.mdx).
|
||||
|
||||
(!docs/pages/includes/permission-warning.mdx!)
|
||||
|
||||
|
||||
@@ -120,7 +120,7 @@ For all available `tctl` commands and flags, see our [CLI Reference](../../../re
|
||||
You can also configure Teleport so that users can log in using an SSO provider.
|
||||
For more information, see:
|
||||
|
||||
- [Single Sign-On](../../access-controls/sso.mdx)
|
||||
- [Single Sign-On](../../access-controls/sso/sso.mdx)
|
||||
|
||||
</TabItem>
|
||||
<TabItem label="Teleport Community Edition">
|
||||
|
||||
+1
-1
@@ -98,7 +98,7 @@ to a format that your telemetry backend accepts.
|
||||
## Configure Teleport
|
||||
|
||||
In order to enable tracing for a `teleport` instance, add the following section to that instance's configuration file (`/etc/teleport.yaml`).
|
||||
For a detailed description of these configuration fields, see the [configuration reference](../../reference/config.mdx) page.
|
||||
For a detailed description of these configuration fields, see the [configuration reference](../../../reference/config.mdx) page.
|
||||
|
||||
```yaml
|
||||
tracing_service:
|
||||
+5
-5
@@ -10,7 +10,7 @@ You can use Teleport's Event Handler plugin to export audit events from Teleport
|
||||
so you can store them in a log management platform or custom backend.
|
||||
|
||||
If you are new to exporting audit events with Teleport, read [Forwarding Events
|
||||
with Fluentd](./export-audit-events/fluentd.mdx) to learn the basics of how our
|
||||
with Fluentd](fluentd.mdx) to learn the basics of how our
|
||||
Event Handler plugin works. While this guide focuses on Fluentd, the Event
|
||||
Handler plugin can export audit events to any endpoint that ingests JSON
|
||||
messages via HTTP.
|
||||
@@ -19,14 +19,14 @@ Next, read our guides to setting up the Event Handler plugin to export audit
|
||||
events to your solution of choice:
|
||||
|
||||
- [Monitor Teleport Audit Events with the Elastic
|
||||
Stack](./export-audit-events/elastic-stack.mdx): How to configure the Event
|
||||
Stack](elastic-stack.mdx): How to configure the Event
|
||||
Handler plugin to forward Teleport audit logs to Logstash for ingestion in
|
||||
Elasticsearch so you can explore them in Kibana.
|
||||
- [Monitor Teleport Audit Events with Panther](./export-audit-events/panther.mdx):
|
||||
- [Monitor Teleport Audit Events with Panther](panther.mdx):
|
||||
How to configure the Event Handler plugin to send logs to Panther via Fluentd
|
||||
so you can explore your audit events in Panther.
|
||||
- [Monitor Teleport Audit Events with Splunk](./export-audit-events/splunk.mdx):
|
||||
- [Monitor Teleport Audit Events with Splunk](splunk.mdx):
|
||||
How to configure the Event Handler plugin to send logs to Splunk's Universal
|
||||
Forwarder so you can explore your audit events in Splunk.
|
||||
- [Monitor Teleport Audit Events with Datadog](./export-audit-events/datadog.mdx):
|
||||
- [Monitor Teleport Audit Events with Datadog](datadog.mdx):
|
||||
How to configure the Event Handler plugin to export audit logs to Datadog via Fluentd.
|
||||
@@ -154,7 +154,7 @@ recordings will be stored in your S3 bucket, and they will *not* be stored in
|
||||
the Teleport Cloud infrastructure.
|
||||
|
||||
If you currently use the
|
||||
[Event Handler](export-audit-events.mdx) plugin to export
|
||||
[Event Handler](export-audit-events/export-audit-events.mdx) plugin to export
|
||||
events, it will follow the switch from the old to new backends and new events
|
||||
will continue to be exported. Only events emitted after the transition to
|
||||
External Audit Storage will be visible in the Teleport UI or accessible to
|
||||
|
||||
@@ -28,7 +28,7 @@ fakehost.example.com 127.0.0.1:3022 env=example,hostname=ip-172-31-53-70,aws/Nam
|
||||
|
||||
(!docs/pages/includes/edition-prereqs-tabs.mdx!)
|
||||
- One Teleport agent running on an Amazon EC2 instance. See
|
||||
[our guides](../../../enroll-resources/agents/join-services-to-your-cluster.mdx) for how to set up Teleport agents.
|
||||
[our guides](../../../enroll-resources/agents/join-services-to-your-cluster/join-services-to-your-cluster.mdx) for how to set up Teleport agents.
|
||||
|
||||
## Enable tags in instance metadata
|
||||
|
||||
|
||||
@@ -36,7 +36,7 @@ fakehost.example.com 127.0.0.1:3022 gcp/label/testing=yes,gcp/tag/environment=st
|
||||
|
||||
(!docs/pages/includes/edition-prereqs-tabs.mdx!)
|
||||
- One Teleport agent running on a GCP Compute instance. See
|
||||
[our guides](../../../enroll-resources/agents/join-services-to-your-cluster.mdx) for how to set up Teleport agents.
|
||||
[our guides](../../../enroll-resources/agents/join-services-to-your-cluster/join-services-to-your-cluster.mdx) for how to set up Teleport agents.
|
||||
|
||||
## Configure service account on instances with Teleport nodes
|
||||
|
||||
|
||||
+4
-4
@@ -8,12 +8,12 @@ You can integrate Teleport with third-party tools in order to complete various
|
||||
tasks in your cluster. These guides describe Teleport integrations that are not
|
||||
documented elsewhere:
|
||||
|
||||
- [EC2 tags as Teleport agent labels](./guides/ec2-tags.mdx). How to set up
|
||||
- [EC2 tags as Teleport agent labels](ec2-tags.mdx). How to set up
|
||||
Teleport agent labels based on EC2 tags.
|
||||
- [GCP tags and labels as Teleport agent labels](./guides/gcp-tags.mdx). How
|
||||
- [GCP tags and labels as Teleport agent labels](gcp-tags.mdx). How
|
||||
to set up Teleport agent labels based on GCP tags and labels.
|
||||
- [Using Teleport's Certificate Authority with
|
||||
GitHub](./guides/ssh-key-extensions.mdx). Use Teleport's short-lived
|
||||
GitHub](ssh-key-extensions.mdx). Use Teleport's short-lived
|
||||
certificates with GitHub's Certificate Authority.
|
||||
- [Using Teleport with Datadog](./guides/datadog.mdx). Set up the official
|
||||
- [Using Teleport with Datadog](datadog.mdx). Set up the official
|
||||
Datadog integration to export Teleport metrics and logs.
|
||||
@@ -1,18 +0,0 @@
|
||||
---
|
||||
title: Operations
|
||||
description: Teleport Operations - Scaling and High-Availability.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
The guides in this section show you how to carry out common administration tasks
|
||||
on an already running Teleport cluster.
|
||||
|
||||
For guides on the fundamentals of setting up your cluster, you should consult
|
||||
the [Cluster Administration Guides](./admin.mdx) section.
|
||||
|
||||
- [Scaling](./operations/scaling.mdx): How to configure Teleport for large-scale deployments.
|
||||
- [Backup and Restore](./operations/backup-restore.mdx): Backing up and restoring the cluster.
|
||||
- [CA Rotation](./operations/ca-rotation.mdx): Rotating Teleport certificate authorities.
|
||||
- [TLS Routing Migration](./operations/tls-routing.mdx): Migrating your Teleport cluster to single-port TLS routing mode.
|
||||
- [Proxy Peering Migration](./operations/proxy-peering.mdx): Migrating your Teleport cluster to Proxy Peering mode.
|
||||
- [Database CA Migrations](./operations/db-ca-migrations.mdx): Completing Teleport's Database CA migrations.
|
||||
@@ -190,7 +190,7 @@ to reconfigure them again before transitioning to `standby` from the
|
||||
### `openssh`
|
||||
|
||||
The `openssh` CA issues certificates for [OpenSSH servers registered with
|
||||
Teleport](../../../enroll-resources/server-access/openssh.mdx). Clients verify these certificates
|
||||
Teleport](../../../enroll-resources/server-access/openssh/openssh.mdx). Clients verify these certificates
|
||||
when connecting to Teleport-protected OpenSSH servers.
|
||||
|
||||
If you used the [manual
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
---
|
||||
title: Operations
|
||||
description: Teleport Operations - Scaling and High-Availability.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
The guides in this section show you how to carry out common administration tasks
|
||||
on an already running Teleport cluster.
|
||||
|
||||
For guides on the fundamentals of setting up your cluster, you should consult
|
||||
the [Cluster Administration Guides](../admin/admin.mdx) section.
|
||||
|
||||
- [Scaling](scaling.mdx): How to configure Teleport for large-scale deployments.
|
||||
- [Backup and Restore](backup-restore.mdx): Backing up and restoring the cluster.
|
||||
- [CA Rotation](ca-rotation.mdx): Rotating Teleport certificate authorities.
|
||||
- [TLS Routing Migration](tls-routing.mdx): Migrating your Teleport cluster to single-port TLS routing mode.
|
||||
- [Proxy Peering Migration](proxy-peering.mdx): Migrating your Teleport cluster to Proxy Peering mode.
|
||||
- [Database CA Migrations](db-ca-migrations.mdx): Completing Teleport's Database CA migrations.
|
||||
@@ -42,7 +42,7 @@ $ curl https://mytenant.teleport.sh/webapi/ping | jq '.proxy'
|
||||
|
||||
Download Teleport from the [downloads page](https://goteleport.com/download) or
|
||||
your enterprise portal and follow the standard [upgrade
|
||||
procedure](../../../upgrading.mdx). Make sure to upgrade both root and leaf clusters
|
||||
procedure](../../../upgrading/upgrading.mdx). Make sure to upgrade both root and leaf clusters
|
||||
as well as `tsh` client.
|
||||
|
||||
## Step 2/7. Enable proxy multiplexing
|
||||
|
||||
@@ -280,7 +280,7 @@ Two `user`s can grant elevated privileges to another `user` temporarily without
|
||||
- [Per-session MFA](../../access-controls/guides/per-session-mfa.mdx)
|
||||
- [Dual authorization](../../access-controls/guides/dual-authz.mdx)
|
||||
- [Role templates, allow/deny rules, and traits](../../access-controls/guides/role-templates.mdx)
|
||||
- [Access Requests](../../access-controls/access-requests.mdx)
|
||||
- [Access Requests](../../access-controls/access-requests/access-requests.mdx)
|
||||
|
||||
### Background reading
|
||||
- [Authentication connectors](../../../reference/access-controls/authentication.mdx)
|
||||
|
||||
+3
-3
@@ -15,10 +15,10 @@ You should note that the security practices covered in this section aren't neces
|
||||
examples used in the documentation. Examples in the documentation are primarily intended for demonstration
|
||||
purposes and for development environments.
|
||||
|
||||
- [Restrict Access for Privileged Accounts](./security/restrict-privileges.mdx). Learn about potential
|
||||
- [Restrict Access for Privileged Accounts](restrict-privileges.mdx). Learn about potential
|
||||
risks of allowing privileged access and how to mitigate them.
|
||||
- [Reducing the Blast Radius of Attacks](./security/reduce-blast-radius.mdx).
|
||||
- [Reducing the Blast Radius of Attacks](reduce-blast-radius.mdx).
|
||||
Prevent attackers from accessing your infrastructure even if they manage to
|
||||
obtain passwords or certificates.
|
||||
- [Revoking Access](./security/revoking-access.mdx). Revoke access in the event
|
||||
- [Revoking Access](revoking-access.mdx). Revoke access in the event
|
||||
of a compromise.
|
||||
@@ -43,7 +43,7 @@ migrating from Teleport Enterprise to Teleport Community Edition.
|
||||
- An existing Teleport cluster.
|
||||
- The `tsh` and `tctl` client tools. This guide assumes that you are using
|
||||
`tctl` to manage dynamic resources, but it is also possible to use [Teleport
|
||||
Terraform provider](infrastructure-as-code/terraform-provider.mdx) and
|
||||
Terraform provider](infrastructure-as-code/terraform-provider/terraform-provider.mdx) and
|
||||
[Kubernetes
|
||||
operator](infrastructure-as-code/teleport-operator/teleport-operator-standalone.mdx), in
|
||||
addition to custom scripts that use the [Teleport API](api/api.mdx)
|
||||
@@ -307,7 +307,7 @@ In general, you can migrate a Machine ID Bot using the following steps:
|
||||
1. Restart `tbot`.
|
||||
|
||||
To learn how to restart and configure a Machine ID Bot in your infrastructure,
|
||||
read the [full documentation](../enroll-resources/machine-id/deployment.mdx) on deploying a
|
||||
read the [full documentation](../enroll-resources/machine-id/deployment/deployment.mdx) on deploying a
|
||||
Machine ID Bot.
|
||||
|
||||
### Access Request plugins and the Event Handler
|
||||
@@ -329,8 +329,8 @@ In general, you can migrate Teleport plugins using the following steps:
|
||||
|
||||
For specific plugins running in your infrastructure, read the full documentation
|
||||
on:
|
||||
- [Access Request plugins](access-controls/access-request-plugins.mdx)
|
||||
- The [Teleport Event Handler](management/export-audit-events.mdx)
|
||||
- [Access Request plugins](access-controls/access-request-plugins/access-request-plugins.mdx)
|
||||
- The [Teleport Event Handler](management/export-audit-events/export-audit-events.mdx)
|
||||
|
||||
## Step 4/4. Verify end user access and performance
|
||||
|
||||
|
||||
@@ -94,4 +94,4 @@ Here is what an example audit event looks like:
|
||||
```
|
||||
|
||||
You can export the audit event using the event handler.
|
||||
The setup is described [here](../management/export-audit-events.mdx).
|
||||
The setup is described [here](../management/export-audit-events/export-audit-events.mdx).
|
||||
|
||||
@@ -46,7 +46,7 @@ Teleport's `tsh` CLI tool can scan users' laptops for SSH private keys.
|
||||
It goes through the specified directories, defaulting to `/Users` on macOS, `/home` on Linux, and `C:\Users` on Windows,
|
||||
by peeking into files to identify SSH private keys.
|
||||
|
||||
The `tsh` tool authenticates with the Teleport cluster through the [Device Trust](../../access-controls/device-trust.mdx) feature,
|
||||
The `tsh` tool authenticates with the Teleport cluster through the [Device Trust](../../access-controls/device-trust/device-trust.mdx) feature,
|
||||
which guarantees that only enrolled devices can submit private keys to the cluster. By utilizing the device's Secure
|
||||
Enclave or TPM private key, it confirms that the device is the same one that was enrolled, enabling Teleport to trust
|
||||
and accept the private key reports without requiring further authentication or credentials thus allowing scanning operations
|
||||
@@ -72,7 +72,7 @@ It also never sends the private key path or any other sensitive information.
|
||||
- A running Teleport Enterprise cluster v15.4.16/v16.2.0 or later.
|
||||
- Teleport Policy enabled for your account.
|
||||
- A Linux/macOS server running the Teleport SSH Service.
|
||||
- Devices enrolled in the [Teleport Device Trust feature](../../access-controls/device-trust.mdx).
|
||||
- Devices enrolled in the [Teleport Device Trust feature](../../access-controls/device-trust/device-trust.mdx).
|
||||
- For Jamf Pro integration, devices must be enrolled in Jamf Pro and have the signed `tsh` binary installed.
|
||||
- For self-hosted clusters:
|
||||
- Ensure that an up-to-date `license.pem` is used in the Auth Service configuration.
|
||||
@@ -110,7 +110,7 @@ and local users.
|
||||
|
||||
## Step 2/3. Scan for SSH Private Keys
|
||||
|
||||
On devices enrolled in the Teleport, you can use the `tsh` CLI tool to scan for SSH Private Keys. Check [Device Trust](../../access-controls/device-trust.mdx)
|
||||
On devices enrolled in the Teleport, you can use the `tsh` CLI tool to scan for SSH Private Keys. Check [Device Trust](../../access-controls/device-trust/device-trust.mdx)
|
||||
for details on how to enroll devices in Teleport, specially if you are using Jamf Pro.
|
||||
|
||||
To scan for SSH Private Keys, run the following command from any enrolled device:
|
||||
@@ -186,7 +186,7 @@ Cluster. The keys will be imported and displayed in the Access Graph.
|
||||
### `"device not enrolled"` error
|
||||
|
||||
If you see the `device not enrolled` error when running the `tsh scan keys` command, it means that the device is not enrolled
|
||||
in the Teleport Device Trust feature. Check the [Device Trust](../../access-controls/device-trust.mdx) page for details on how to enroll devices
|
||||
in the Teleport Device Trust feature. Check the [Device Trust](../../access-controls/device-trust/device-trust.mdx) page for details on how to enroll devices
|
||||
in Teleport.
|
||||
|
||||
### `"binary missing signature or entitlements"` error
|
||||
|
||||
@@ -14,7 +14,7 @@ work with Teleport.
|
||||
|
||||
- (!docs/pages/includes/tctl.mdx!)
|
||||
- The Teleport Database Service configured to access a database. See one of our
|
||||
[guides](../enroll-resources/database-access/guides.mdx) for how to set up the Teleport
|
||||
[guides](../enroll-resources/database-access/guides/guides.mdx) for how to set up the Teleport
|
||||
Database Service for your database.
|
||||
|
||||
### Get connection information
|
||||
|
||||
@@ -153,7 +153,7 @@ with that command executed.
|
||||
Teleport Connect supports launching applications in the browser, as well as creating
|
||||
authenticated tunnels for web and TCP applications.
|
||||
|
||||
When it comes to [cloud APIs secured with Application Access](../enroll-resources/application-access/cloud-apis.mdx),
|
||||
When it comes to [cloud APIs secured with Application Access](../enroll-resources/application-access/cloud-apis/cloud-apis.mdx),
|
||||
Teleport Connect supports launching the AWS console in the browser, but other CLI applications can
|
||||
be used only through tsh in [a local terminal tab](#opening-a-local-terminal).
|
||||
|
||||
|
||||
@@ -196,7 +196,7 @@ subject of the certificate—including its username and Teleport roles—to
|
||||
authorize the user.
|
||||
|
||||
Read more about [local users](reference/access-controls/authentication.mdx) and how [SSO
|
||||
authentication works in Teleport](admin-guides/access-controls/sso.mdx).
|
||||
authentication works in Teleport](admin-guides/access-controls/sso/sso.mdx).
|
||||
|
||||
### Authentication connector
|
||||
|
||||
|
||||
@@ -78,7 +78,7 @@ Teleport Agents need to establish trust with the Teleport Auth Service in order
|
||||
to join a cluster. There are several ways to join an Agent to your Teleport
|
||||
cluster, making it possible to automate the join process for your environment.
|
||||
Read about the available join methods in our [Join Services to your
|
||||
Cluster](./join-services-to-your-cluster.mdx) guides.
|
||||
Cluster](join-services-to-your-cluster/join-services-to-your-cluster.mdx) guides.
|
||||
|
||||
When a Teleport process first runs, it checks its configuration file to
|
||||
determine which services are enabled. Each service then connects separately to
|
||||
|
||||
@@ -1,22 +0,0 @@
|
||||
---
|
||||
title: Join Services to your Teleport Cluster
|
||||
description: How to register the Proxy Service, Database Service, and other Teleport services with your cluster.
|
||||
---
|
||||
|
||||
A **Teleport service** manages access to resources in your infrastructure, such
|
||||
as Kubernetes clusters, Windows desktops, internal web applications, and
|
||||
databases. A single **Teleport process** can run multiple Teleport services.
|
||||
|
||||
There are multiple methods you can use to join a Teleport process to your
|
||||
cluster in order to run Teleport services, including an instance of the Proxy
|
||||
Service. Choose the method that best suits your infrastructure:
|
||||
|
||||
|Method|Description|When to use|
|
||||
|------|-----------|-----------|
|
||||
|[EC2 Identity Document](./join-services-to-your-cluster/aws-ec2.mdx)|A Teleport process running on an EC2 instance authenticates to your cluster via a signed EC2 instance identity document.|Your Teleport process will run on EC2 and your Teleport cluster is self hosted.|
|
||||
|[AWS IAM](./join-services-to-your-cluster/aws-iam.mdx)|A Teleport process uses AWS credentials to join the cluster, whether running on EC2 or not.|At least some of your infrastructure runs on AWS.|
|
||||
|[Azure Managed Identity](./join-services-to-your-cluster/azure.mdx)|A Teleport process demonstrates that it runs in your Azure subscription by sending a signed attested data document and access token to the Teleport Auth Service.|Your Teleport process will run on Azure.|
|
||||
|[Kubernetes ServiceAccount](./join-services-to-your-cluster/kubernetes.mdx)|A Teleport process uses a Kubernetes-signed proof to establish a trust relationship with your Teleport cluster.|Your Teleport process will run on Kubernetes.|
|
||||
|[GCP IAM](./join-services-to-your-cluster/gcp.mdx)|A Teleport process uses a GCP-signed token to establish a trust relationship with your Teleport cluster.|Your Teleport process will run on a GCP VM.|
|
||||
|[Join Token](./join-services-to-your-cluster/join-token.mdx)|A Teleport process presents a join token provided when starting the service.|There is no other supported method for your cloud provider.|
|
||||
|
||||
@@ -12,7 +12,7 @@ Azure Virtual Machine. Support for joining a cluster with the Proxy Service
|
||||
behind a layer 7 load balancer or reverse proxy is available in Teleport 13.0+.
|
||||
|
||||
For other methods of joining a Teleport process to a cluster, see [Joining
|
||||
Teleport Services to a Cluster](../join-services-to-your-cluster.mdx).
|
||||
Teleport Services to a Cluster](join-services-to-your-cluster.mdx).
|
||||
|
||||
## Prerequisites
|
||||
|
||||
|
||||
+22
@@ -0,0 +1,22 @@
|
||||
---
|
||||
title: Join Services to your Teleport Cluster
|
||||
description: How to register the Proxy Service, Database Service, and other Teleport services with your cluster.
|
||||
---
|
||||
|
||||
A **Teleport service** manages access to resources in your infrastructure, such
|
||||
as Kubernetes clusters, Windows desktops, internal web applications, and
|
||||
databases. A single **Teleport process** can run multiple Teleport services.
|
||||
|
||||
There are multiple methods you can use to join a Teleport process to your
|
||||
cluster in order to run Teleport services, including an instance of the Proxy
|
||||
Service. Choose the method that best suits your infrastructure:
|
||||
|
||||
|Method|Description|When to use|
|
||||
|------|-----------|-----------|
|
||||
|[EC2 Identity Document](aws-ec2.mdx)|A Teleport process running on an EC2 instance authenticates to your cluster via a signed EC2 instance identity document.|Your Teleport process will run on EC2 and your Teleport cluster is self hosted.|
|
||||
|[AWS IAM](aws-iam.mdx)|A Teleport process uses AWS credentials to join the cluster, whether running on EC2 or not.|At least some of your infrastructure runs on AWS.|
|
||||
|[Azure Managed Identity](azure.mdx)|A Teleport process demonstrates that it runs in your Azure subscription by sending a signed attested data document and access token to the Teleport Auth Service.|Your Teleport process will run on Azure.|
|
||||
|[Kubernetes ServiceAccount](kubernetes.mdx)|A Teleport process uses a Kubernetes-signed proof to establish a trust relationship with your Teleport cluster.|Your Teleport process will run on Kubernetes.|
|
||||
|[GCP IAM](gcp.mdx)|A Teleport process uses a GCP-signed token to establish a trust relationship with your Teleport cluster.|Your Teleport process will run on a GCP VM.|
|
||||
|[Join Token](join-token.mdx)|A Teleport process presents a join token provided when starting the service.|There is no other supported method for your cloud provider.|
|
||||
|
||||
@@ -27,7 +27,7 @@ as the Auth Service.
|
||||
## Prerequisites
|
||||
|
||||
- A running Teleport cluster in Kubernetes. For details on how to set this up,
|
||||
see [Guides for running Teleport using Helm](../../../admin-guides/deploy-a-cluster/helm-deployments.mdx).
|
||||
see [Guides for running Teleport using Helm](../../../admin-guides/deploy-a-cluster/helm-deployments/helm-deployments.mdx).
|
||||
- Editor access to the Kubernetes cluster running the Teleport cluster.
|
||||
You must be able to create Namespaces and Deployments.
|
||||
- A Teleport user with `access` role, or any other role that allows access to
|
||||
@@ -240,5 +240,5 @@ namespace "teleport-agent" deleted
|
||||
|
||||
- The possible values for `teleport-kube-agent` chart are documented
|
||||
[in its reference](../../../reference/helm-reference/teleport-kube-agent.mdx).
|
||||
- See [Application Access Guides](../../application-access/guides.mdx)
|
||||
- See [Database Access Guides](../../database-access/guides.mdx)
|
||||
- See [Application Access Guides](../../application-access/guides/guides.mdx)
|
||||
- See [Database Access Guides](../../database-access/guides/guides.mdx)
|
||||
|
||||
@@ -811,7 +811,7 @@ applications](../guides/dynamic-registration.mdx).
|
||||
This guide shows you how to use the **join token method** to enroll the Teleport
|
||||
Application Service in your cluster. This is one of several available methods,
|
||||
and we recommend reading the [Join Services to your Teleport
|
||||
Cluster](../../agents/join-services-to-your-cluster.mdx) guide to configure the
|
||||
Cluster](../../agents/join-services-to-your-cluster/join-services-to-your-cluster.mdx) guide to configure the
|
||||
most appropriate method for your environment.
|
||||
|
||||
## Further reading
|
||||
|
||||
@@ -222,7 +222,7 @@ teleport-azure-access-agent-0 1/1 Running 0 99s
|
||||
longstanding admin roles for attackers to hijack. View our documentation on
|
||||
[Role Access
|
||||
Requests](../../../admin-guides/access-controls/access-requests/role-requests.mdx) and
|
||||
[Access Request plugins](../../../admin-guides/access-controls/access-request-plugins.mdx).
|
||||
[Access Request plugins](../../../admin-guides/access-controls/access-request-plugins/access-request-plugins.mdx).
|
||||
- Consult the Azure documentation for information about [Azure managed
|
||||
identities](https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview)
|
||||
and how to [manage user-assigned managed
|
||||
|
||||
@@ -224,7 +224,7 @@ Application Service host.
|
||||
longstanding admin roles for attackers to hijack. View our documentation on
|
||||
[Role Access
|
||||
Requests](../../../admin-guides/access-controls/access-requests/role-requests.mdx) and
|
||||
[Access Request plugins](../../../admin-guides/access-controls/access-request-plugins.mdx).
|
||||
[Access Request plugins](../../../admin-guides/access-controls/access-request-plugins/access-request-plugins.mdx).
|
||||
- Consult the Azure documentation for information about [Azure managed
|
||||
identities](https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview)
|
||||
and how to [manage user-assigned managed
|
||||
|
||||
+5
-5
@@ -15,8 +15,8 @@ longstanding admin accounts to target.
|
||||
|
||||
Learn how to protect your cloud provider APIs with Teleport:
|
||||
|
||||
- [AWS (console and CLI applications)](./cloud-apis/aws-console.mdx)
|
||||
- [Azure CLI applications](./cloud-apis/azure.mdx)
|
||||
- [Azure CLI applications (AKS with Workload ID deployment)](./cloud-apis/azure-aks-workload-id.mdx)
|
||||
- [Google Cloud CLI applications](./cloud-apis/google-cloud.mdx)
|
||||
- [GCP Web Console Access with Workforce Identity Federation and Teleport SAML IdP](../../admin-guides/access-controls/idps/saml-gcp-workforce-identity-federation.mdx)
|
||||
- [AWS (console and CLI applications)](aws-console.mdx)
|
||||
- [Azure CLI applications](azure.mdx)
|
||||
- [Azure CLI applications (AKS with Workload ID deployment)](azure-aks-workload-id.mdx)
|
||||
- [Google Cloud CLI applications](google-cloud.mdx)
|
||||
- [GCP Web Console Access with Workforce Identity Federation and Teleport SAML IdP](../../../admin-guides/access-controls/idps/saml-gcp-workforce-identity-federation.mdx)
|
||||
@@ -631,7 +631,7 @@ command.
|
||||
temporarily, with no longstanding admin roles for attackers to hijack. View
|
||||
our documentation on [Role Access
|
||||
Requests](../../../admin-guides/access-controls/access-requests/role-requests.mdx) and [Access
|
||||
Request plugins](../../../admin-guides/access-controls/access-request-plugins.mdx).
|
||||
Request plugins](../../../admin-guides/access-controls/access-request-plugins/access-request-plugins.mdx).
|
||||
- You can proxy any `gcloud` or `gsutil` command via Teleport. For a full
|
||||
reference of commands, view the Google Cloud documentation for
|
||||
[`gcloud`](https://cloud.google.com/sdk/gcloud/reference) and
|
||||
|
||||
@@ -133,12 +133,12 @@ for more information on enabling access to Azure managed identities.
|
||||
## Next steps
|
||||
|
||||
- View access controls [Getting Started](../../admin-guides/access-controls/getting-started.mdx)
|
||||
and other available [guides](../../admin-guides/access-controls/guides.mdx).
|
||||
and other available [guides](../../admin-guides/access-controls/guides/guides.mdx).
|
||||
- For full details on how Teleport populates the `internal` and `external`
|
||||
traits we illustrated in this guide, see the [Teleport Access
|
||||
Controls Reference](../../reference/access-controls/roles.mdx).
|
||||
- View access controls [Getting Started](../../admin-guides/access-controls/getting-started.mdx)
|
||||
and other available [guides](../../admin-guides/access-controls/guides.mdx).
|
||||
and other available [guides](../../admin-guides/access-controls/guides/guides.mdx).
|
||||
- Learn about using [JWT tokens](./jwt/introduction.mdx) to implement access
|
||||
controls in your application.
|
||||
- Integrate with your identity provider:
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
---
|
||||
title: Application Access Guides
|
||||
description: Guides for configuring Teleport application access.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
These guides explain how to use the Teleport Application Service, which allows
|
||||
your teams to connect to applications within private networks with fine-grained
|
||||
RBAC and audit logging.
|
||||
|
||||
Manage access to internal applications:
|
||||
|
||||
- [Web App Access](./guides/connecting-apps.mdx): How to access web apps with Teleport.
|
||||
- [TCP App Access](./guides/tcp.mdx): How to access plain TCP apps with Teleport.
|
||||
- [VNet](./guides/vnet.mdx): How to configure VNet to support applications with custom public addresses.
|
||||
- [API Access](./guides/api-access.mdx): How to access REST APIs with Teleport.
|
||||
- [Dynamic Registration](./guides/dynamic-registration.mdx): Register/unregister apps without restarting Teleport.
|
||||
- [Amazon Athena Access](./guides/amazon-athena.mdx): How to access Amazon Athena with Teleport.
|
||||
- [Amazon DynamoDB Access](./guides/dynamodb.mdx): How to access Amazon DynamoDB as an application.
|
||||
- [Application Access HA](./guides/ha.mdx): How to configure the Teleport Application Service for high availability.
|
||||
@@ -14,7 +14,7 @@ Service needs to proxy an application.
|
||||
Dynamic registration is useful for [managing pools of Application Service
|
||||
instances](../../../admin-guides/infrastructure-as-code/terraform-starter/enroll-resources.mdx). And behind the scenes, the
|
||||
Teleport Discovery Service uses dynamic registration to [register Kubernetes
|
||||
applications](../../auto-discovery/kubernetes-applications.mdx).
|
||||
applications](../../auto-discovery/kubernetes-applications/kubernetes-applications.mdx).
|
||||
|
||||
## Required permissions
|
||||
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
---
|
||||
title: Application Access Guides
|
||||
description: Guides for configuring Teleport application access.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
These guides explain how to use the Teleport Application Service, which allows
|
||||
your teams to connect to applications within private networks with fine-grained
|
||||
RBAC and audit logging.
|
||||
|
||||
Manage access to internal applications:
|
||||
|
||||
- [Web App Access](connecting-apps.mdx): How to access web apps with Teleport.
|
||||
- [TCP App Access](tcp.mdx): How to access plain TCP apps with Teleport.
|
||||
- [VNet](vnet.mdx): How to configure VNet to support applications with custom public addresses.
|
||||
- [API Access](api-access.mdx): How to access REST APIs with Teleport.
|
||||
- [Dynamic Registration](dynamic-registration.mdx): Register/unregister apps without restarting Teleport.
|
||||
- [Amazon Athena Access](amazon-athena.mdx): How to access Amazon Athena with Teleport.
|
||||
- [Amazon DynamoDB Access](dynamodb.mdx): How to access Amazon DynamoDB as an application.
|
||||
- [Application Access HA](ha.mdx): How to configure the Teleport Application Service for high availability.
|
||||
@@ -18,7 +18,7 @@ Examples include:
|
||||

|
||||
|
||||
If you are running applications on Kubernetes, you can [enroll them in your
|
||||
Teleport cluster automatically](../auto-discovery/kubernetes-applications.mdx).
|
||||
Teleport cluster automatically](../auto-discovery/kubernetes-applications/kubernetes-applications.mdx).
|
||||
|
||||
Teleport protects applications through the Teleport Application Service, which
|
||||
is a Teleport agent service. For more information on agent services, read
|
||||
@@ -78,4 +78,4 @@ can access Okta applications through the Teleport Web UI and `tsh`, and
|
||||
administrators can manage access to these applications by defining RBAC policies
|
||||
in Teleport roles.
|
||||
|
||||
Learn more about the [Teleport Okta integration](./okta.mdx).
|
||||
Learn more about the [Teleport Okta integration](okta/okta.mdx).
|
||||
|
||||
+2
-2
@@ -8,5 +8,5 @@ These guides explain how web apps behind the Teleport Application Service can
|
||||
leverage Teleport-signed JWT tokens to implement authentication and
|
||||
authorization.
|
||||
|
||||
- [Introduction](./jwt/introduction.mdx): Introduction to JWT tokens with application access.
|
||||
- [Elasticsearch](./jwt/elasticsearch.mdx): How to use JWT authentication with Elasticsearch.
|
||||
- [Introduction](introduction.mdx): Introduction to JWT tokens with application access.
|
||||
- [Elasticsearch](elasticsearch.mdx): How to use JWT authentication with Elasticsearch.
|
||||
@@ -1,12 +0,0 @@
|
||||
---
|
||||
title: Okta Integration with Application Access
|
||||
description: Guides for using Teleport Okta integration.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
Configure Teleport to import and grant access to Okta applications and user groups.
|
||||
|
||||
- [Configuring Okta integration](./okta/hosted-guide.mdx): A guide for connecting Okta organization to Teleport.
|
||||
- [Setting up a SCIM-only integration](./okta/scim-only.mdx): A guide for setting up a SCIM-only Okta integration in Teleport.
|
||||
- [Resource Synchronization](./okta/sync-scim.mdx): How synchronized resources are represented in Teleport.
|
||||
- [Reference](../../reference/agent-services/okta.mdx): A reference for the Okta integration resources.
|
||||
@@ -0,0 +1,12 @@
|
||||
---
|
||||
title: Okta Integration with Application Access
|
||||
description: Guides for using Teleport Okta integration.
|
||||
layout: tocless-doc
|
||||
---
|
||||
|
||||
Configure Teleport to import and grant access to Okta applications and user groups.
|
||||
|
||||
- [Configuring Okta integration](hosted-guide.mdx): A guide for connecting Okta organization to Teleport.
|
||||
- [Setting up a SCIM-only integration](scim-only.mdx): A guide for setting up a SCIM-only Okta integration in Teleport.
|
||||
- [Resource Synchronization](sync-scim.mdx): How synchronized resources are represented in Teleport.
|
||||
- [Reference](../../../reference/agent-services/okta.mdx): A reference for the Okta integration resources.
|
||||
@@ -291,17 +291,17 @@ Additional Teleport RBAC configuration and possibly IAM configuration may also
|
||||
be required to connect to the discovered databases via Teleport.
|
||||
|
||||
Refer to the appropriate guide in
|
||||
[Enroll AWS Databases](../../database-access/enroll-aws-databases.mdx)
|
||||
[Enroll AWS Databases](../../database-access/enroll-aws-databases/enroll-aws-databases.mdx)
|
||||
for information about database user provisioning and configuration.
|
||||
</Notice>
|
||||
|
||||
## Next
|
||||
- Learn about [Dynamic Registration](../../database-access/guides/dynamic-registration.mdx) by the
|
||||
Teleport Database Service.
|
||||
- Get started by [connecting](../../database-access/guides.mdx) your database.
|
||||
- Get started by [connecting](../../database-access/guides/guides.mdx) your database.
|
||||
- Connect AWS databases in [external AWS accounts](../../database-access/enroll-aws-databases/aws-cross-account.mdx).
|
||||
- Refer to the appropriate guide in
|
||||
[Enroll AWS Databases](../../database-access/enroll-aws-databases.mdx)
|
||||
[Enroll AWS Databases](../../database-access/enroll-aws-databases/enroll-aws-databases.mdx)
|
||||
for information about database user provisioning and configuration.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
+6
-6
@@ -8,8 +8,8 @@ them with your Teleport cluster.
|
||||
|
||||
## Supported clouds
|
||||
|
||||
- [AWS](./databases/aws.mdx): Discovery for AWS databases.
|
||||
- [Azure](../database-access/enroll-azure-databases.mdx): Discovery for Azure databases.
|
||||
- [AWS](aws.mdx): Discovery for AWS databases.
|
||||
- [Azure](../../database-access/enroll-azure-databases/enroll-azure-databases.mdx): Discovery for Azure databases.
|
||||
{/* TODO(gavin): Add an Azure discovery guide and permission reference */}
|
||||
|
||||
## Architecture overview
|
||||
@@ -31,7 +31,7 @@ from database access.
|
||||
The Teleport Discovery Service is responsible for polling APIs for databases
|
||||
that match its configured selectors.
|
||||
When the Discovery Service matches a database, it will
|
||||
[dynamically register the database](../database-access/guides/dynamic-registration.mdx)
|
||||
[dynamically register the database](../../database-access/guides/dynamic-registration.mdx)
|
||||
with your Teleport cluster.
|
||||
The dynamic `db` resources it creates in your Teleport cluster will include
|
||||
information such as:
|
||||
@@ -154,12 +154,12 @@ Here's how it works in detail:
|
||||
|
||||
For more information about Discovery Service configuration, refer to
|
||||
[one of the guides above](#supported-clouds) or the
|
||||
[Discovery Service Config File Reference](../../reference/config.mdx#discovery-service).
|
||||
[Discovery Service Config File Reference](../../../reference/config.mdx).
|
||||
|
||||
## How the Database Service works
|
||||
|
||||
The Teleport Database Service is responsible for monitoring
|
||||
[dynamically registered](../database-access/guides/dynamic-registration.mdx)
|
||||
[dynamically registered](../../database-access/guides/dynamic-registration.mdx)
|
||||
`db` resources in your Teleport cluster and acting as a connection proxy for the
|
||||
databases they represent.
|
||||
|
||||
@@ -171,7 +171,7 @@ database that the `db` resource represents.
|
||||
The Database Service must have network connectivity to the database endpoint and
|
||||
permissions to authenticate to the database.
|
||||
The permissions it needs vary by database type, so refer to Teleport's
|
||||
[database access guides](../database-access/database-access.mdx)
|
||||
[database access guides](../../database-access/database-access.mdx)
|
||||
for detailed permissions information.
|
||||
|
||||
## Database Service configuration
|
||||
+3
-3
@@ -16,10 +16,10 @@ applications, and registers these applications with your cluster. The Teleport
|
||||
Application Service then detects the new application resources and proxies user
|
||||
traffic to them.
|
||||
|
||||
- [Get started](./kubernetes-applications/get-started.mdx): Set up automatic
|
||||
- [Get started](get-started.mdx): Set up automatic
|
||||
application discovery with the `teleport-kube-agent` Helm chart.
|
||||
- [Architecture](../../reference/architecture/kubernetes-applications-architecture.mdx): Learn how
|
||||
- [Architecture](../../../reference/architecture/kubernetes-applications-architecture.mdx): Learn how
|
||||
automatic application discovery works.
|
||||
- [Reference](../../reference/agent-services/kubernetes-application-discovery.mdx): Consult this guide
|
||||
- [Reference](../../../reference/agent-services/kubernetes-application-discovery.mdx): Consult this guide
|
||||
for options and Kubernetes annotations you can use to configure automatic
|
||||
Kubernetes application discovery.
|
||||
+3
-3
@@ -12,9 +12,9 @@ minimal access permissions.
|
||||
|
||||
## Supported clouds
|
||||
|
||||
- [AWS](./kubernetes/aws.mdx): Discovery for AWS EKS clusters.
|
||||
- [Azure](./kubernetes/azure.mdx): Discovery for Azure AKS clusters.
|
||||
- [Google Cloud](./kubernetes/google-cloud.mdx): Discovery for
|
||||
- [AWS](aws.mdx): Discovery for AWS EKS clusters.
|
||||
- [Azure](azure.mdx): Discovery for Azure AKS clusters.
|
||||
- [Google Cloud](google-cloud.mdx): Discovery for
|
||||
Google Kubernetes Engine clusters.
|
||||
|
||||
## How Kubernetes Clusters Discovery works
|
||||
@@ -1,7 +0,0 @@
|
||||
---
|
||||
title: Discovery Service Reference
|
||||
description: Configuration reference for the Teleport Discovery Service.
|
||||
---
|
||||
|
||||
- [AWS IAM](./reference/aws-iam.mdx)
|
||||
- [Kubernetes Applications](../../reference/agent-services/kubernetes-application-discovery.mdx)
|
||||
@@ -0,0 +1,7 @@
|
||||
---
|
||||
title: Discovery Service Reference
|
||||
description: Configuration reference for the Teleport Discovery Service.
|
||||
---
|
||||
|
||||
- [AWS IAM](aws-iam.mdx)
|
||||
- [Kubernetes Applications](../../../reference/agent-services/kubernetes-application-discovery.mdx)
|
||||
+3
-3
@@ -10,6 +10,6 @@ Teleport, start it and join the cluster.
|
||||
|
||||
Learn how to set up auto-discovery for servers in your cloud:
|
||||
|
||||
- [Amazon EC2](./servers/ec2-discovery.mdx)
|
||||
- [Google Compute Engine](./servers/gcp-discovery.mdx)
|
||||
- [Azure Virtual Machines](./servers/azure-discovery.mdx)
|
||||
- [Amazon EC2](ec2-discovery.mdx)
|
||||
- [Google Compute Engine](gcp-discovery.mdx)
|
||||
- [Azure Virtual Machines](azure-discovery.mdx)
|
||||
@@ -1,16 +0,0 @@
|
||||
---
|
||||
title: Database Automatic User Provisioning
|
||||
description: Configure automatic user provisioning for databases.
|
||||
---
|
||||
|
||||
(!docs/pages/includes/database-access/auto-user-provisioning/intro.mdx!)
|
||||
|
||||
Currently, automatic user provisioning is supported for the following databases:
|
||||
- [PostgreSQL databases (self-hosted and Amazon RDS)](./auto-user-provisioning/postgres.mdx)
|
||||
- [MySQL databases (self-hosted and Amazon RDS)](./auto-user-provisioning/mysql.mdx)
|
||||
- [MariaDB databases (self-hosted and Amazon RDS)](./auto-user-provisioning/mariadb.mdx)
|
||||
- [Amazon Redshift databases](./auto-user-provisioning/aws-redshift.mdx)
|
||||
- [MongoDB databases (self-hosted)](./auto-user-provisioning/mongodb.mdx)
|
||||
|
||||
|
||||
|
||||
+16
@@ -0,0 +1,16 @@
|
||||
---
|
||||
title: Database Automatic User Provisioning
|
||||
description: Configure automatic user provisioning for databases.
|
||||
---
|
||||
|
||||
(!docs/pages/includes/database-access/auto-user-provisioning/intro.mdx!)
|
||||
|
||||
Currently, automatic user provisioning is supported for the following databases:
|
||||
- [PostgreSQL databases (self-hosted and Amazon RDS)](postgres.mdx)
|
||||
- [MySQL databases (self-hosted and Amazon RDS)](mysql.mdx)
|
||||
- [MariaDB databases (self-hosted and Amazon RDS)](mariadb.mdx)
|
||||
- [Amazon Redshift databases](aws-redshift.mdx)
|
||||
- [MongoDB databases (self-hosted)](mongodb.mdx)
|
||||
|
||||
|
||||
|
||||
@@ -11,7 +11,7 @@ Some of the things you can do with database access:
|
||||
- Enable users to retrieve short-lived database certificates using a Single Sign-On
|
||||
flow, thus maintaining their organization-wide identity.
|
||||
- Configure role-based access controls for databases and implement custom
|
||||
[Access Request](../../admin-guides/access-controls/access-requests.mdx) workflows.
|
||||
[Access Request](../../admin-guides/access-controls/access-requests/access-requests.mdx) workflows.
|
||||
- Capture database activity in the Teleport audit log.
|
||||
|
||||
Teleport protects databases through the Teleport Database Service, which is a
|
||||
|
||||
@@ -1,31 +0,0 @@
|
||||
---
|
||||
title: Enroll AWS Databases
|
||||
description: "Provides instructions on protecting databases in your AWS-managed infrastructure with Teleport."
|
||||
---
|
||||
|
||||
The guides in this section show you how to protect AWS-managed databases with
|
||||
Teleport.
|
||||
|
||||
You can configure Teleport to discover databases in your AWS account and enroll
|
||||
them with your cluster automatically. Read more about setting up
|
||||
[Database Auto-Discovery](../auto-discovery/databases.mdx).
|
||||
|
||||
It is also possible to protect databases across your AWS accounts. Read the
|
||||
instructions in [AWS Cross-Account Database
|
||||
Access](./enroll-aws-databases/aws-cross-account.mdx).
|
||||
|
||||
Read the following guides for how to protect a specific AWS-managed database
|
||||
with Teleport:
|
||||
|
||||
- [Amazon DocumentDB](./enroll-aws-databases/aws-docdb.mdx)
|
||||
- [Amazon DynamoDB](./enroll-aws-databases/aws-dynamodb.mdx)
|
||||
- [Amazon ElastiCache and MemoryDB for Redis](./enroll-aws-databases/redis-aws.mdx)
|
||||
- [Amazon Keyspaces (Apache Cassandra)](./enroll-aws-databases/aws-cassandra-keyspaces.mdx)
|
||||
- [Amazon OpenSearch](./enroll-aws-databases/aws-opensearch.mdx)
|
||||
- [Amazon RDS Proxy MySQL](./enroll-aws-databases/rds-proxy-mysql.mdx)
|
||||
- [Amazon RDS Proxy for Microsoft SQL Server](./enroll-aws-databases/rds-proxy-sqlserver.mdx)
|
||||
- [Amazon RDS Proxy for PostgreSQL](./enroll-aws-databases/rds-proxy-postgres.mdx)
|
||||
- [Amazon RDS and Aurora](./enroll-aws-databases/rds.mdx)
|
||||
- [Amazon RDS for SQL Server](./enroll-aws-databases/sql-server-ad.mdx)
|
||||
- [Amazon Redshift Serverless](./enroll-aws-databases/redshift-serverless.mdx)
|
||||
- [Amazon Redshift](./enroll-aws-databases/postgres-redshift.mdx)
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user