diff --git a/integration/helpers/helpers.go b/integration/helpers/helpers.go index 1d4a7348058..7087877c80d 100644 --- a/integration/helpers/helpers.go +++ b/integration/helpers/helpers.go @@ -44,7 +44,6 @@ import ( "github.com/gravitational/teleport/lib/auth" "github.com/gravitational/teleport/lib/backend" "github.com/gravitational/teleport/lib/client" - libclient "github.com/gravitational/teleport/lib/client" "github.com/gravitational/teleport/lib/client/identityfile" "github.com/gravitational/teleport/lib/cloud" "github.com/gravitational/teleport/lib/defaults" @@ -202,7 +201,7 @@ func GetLocalIP() (string, error) { } func MustCreateUserIdentityFile(t *testing.T, tc *TeleInstance, username string, ttl time.Duration) string { - key, err := libclient.GenerateRSAKey() + key, err := client.GenerateRSAKey() require.NoError(t, err) key.ClusterName = tc.Secrets.SiteName diff --git a/integration/integration_test.go b/integration/integration_test.go index b98e8ee28fd..9084d9f64b2 100644 --- a/integration/integration_test.go +++ b/integration/integration_test.go @@ -62,7 +62,6 @@ import ( "github.com/gravitational/teleport/api/client/proto" "github.com/gravitational/teleport/api/constants" "github.com/gravitational/teleport/api/defaults" - apidefaults "github.com/gravitational/teleport/api/defaults" tracessh "github.com/gravitational/teleport/api/observability/tracing/ssh" "github.com/gravitational/teleport/api/profile" "github.com/gravitational/teleport/api/types" @@ -526,7 +525,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) { // everything because the session is closing) var sessionStream []byte for i := 0; i < 6; i++ { - sessionStream, err = site.GetSessionChunk(apidefaults.Namespace, session.ID(tracker.GetSessionID()), 0, events.MaxChunkBytes) + sessionStream, err = site.GetSessionChunk(defaults.Namespace, session.ID(tracker.GetSessionID()), 0, events.MaxChunkBytes) require.NoError(t, err) if strings.Contains(string(sessionStream), "exit") { break @@ -558,7 +557,7 @@ func testAuditOn(t *testing.T, suite *integrationTestSuite) { select { case <-tickCh: // Get all session events from the backend. - sessionEvents, err := site.GetSessionEvents(apidefaults.Namespace, session.ID(tracker.GetSessionID()), 0) + sessionEvents, err := site.GetSessionEvents(defaults.Namespace, session.ID(tracker.GetSessionID()), 0) if err != nil { return nil, trace.Wrap(err) } @@ -4456,7 +4455,7 @@ func testAuditOff(t *testing.T, suite *integrationTestSuite) { // however, attempts to read the actual sessions should fail because it was // not actually recorded - _, err = site.GetSessionChunk(apidefaults.Namespace, session.ID(tracker.GetSessionID()), 0, events.MaxChunkBytes) + _, err = site.GetSessionChunk(defaults.Namespace, session.ID(tracker.GetSessionID()), 0, events.MaxChunkBytes) require.Error(t, err) } diff --git a/integrations/operator/controllers/resources/testlib/login_rule_controller_tests.go b/integrations/operator/controllers/resources/testlib/login_rule_controller_tests.go index 8bcc3f8380b..5d327538949 100644 --- a/integrations/operator/controllers/resources/testlib/login_rule_controller_tests.go +++ b/integrations/operator/controllers/resources/testlib/login_rule_controller_tests.go @@ -30,7 +30,6 @@ import ( "github.com/gravitational/teleport/api/types" "github.com/gravitational/teleport/api/types/wrappers" resourcesv1 "github.com/gravitational/teleport/integrations/operator/apis/resources/v1" - v1 "github.com/gravitational/teleport/integrations/operator/apis/resources/v1" ) type loginRuleTestingPrimitives struct { @@ -68,7 +67,7 @@ func (l *loginRuleTestingPrimitives) CreateTeleportResource(ctx context.Context, return trace.Wrap(err) } -func (l *loginRuleTestingPrimitives) GetTeleportResource(ctx context.Context, name string) (*v1.LoginRuleResource, error) { +func (l *loginRuleTestingPrimitives) GetTeleportResource(ctx context.Context, name string) (*resourcesv1.LoginRuleResource, error) { lrClient := l.setup.TeleportClient.LoginRuleClient() loginRule, err := lrClient.GetLoginRule(ctx, &loginrulepb.GetLoginRuleRequest{ Name: name, @@ -85,12 +84,12 @@ func (l *loginRuleTestingPrimitives) DeleteTeleportResource(ctx context.Context, } func (l *loginRuleTestingPrimitives) CreateKubernetesResource(ctx context.Context, name string) error { - rule := v1.TeleportLoginRule{ + rule := resourcesv1.TeleportLoginRule{ ObjectMeta: metav1.ObjectMeta{ Name: name, Namespace: l.setup.Namespace.Name, }, - Spec: v1.TeleportLoginRuleSpec{ + Spec: resourcesv1.TeleportLoginRuleSpec{ Priority: 1, TraitsMap: map[string][]string{ "logins": {"external.logins"}, @@ -102,7 +101,7 @@ func (l *loginRuleTestingPrimitives) CreateKubernetesResource(ctx context.Contex } func (l *loginRuleTestingPrimitives) DeleteKubernetesResource(ctx context.Context, name string) error { - rule := v1.TeleportLoginRule{ + rule := resourcesv1.TeleportLoginRule{ ObjectMeta: metav1.ObjectMeta{ Name: name, Namespace: l.setup.Namespace.Name, @@ -111,8 +110,8 @@ func (l *loginRuleTestingPrimitives) DeleteKubernetesResource(ctx context.Contex return trace.Wrap(l.setup.K8sClient.Delete(ctx, &rule)) } -func (l *loginRuleTestingPrimitives) GetKubernetesResource(ctx context.Context, name string) (*v1.TeleportLoginRule, error) { - rule := &v1.TeleportLoginRule{} +func (l *loginRuleTestingPrimitives) GetKubernetesResource(ctx context.Context, name string) (*resourcesv1.TeleportLoginRule, error) { + rule := &resourcesv1.TeleportLoginRule{} obj := kclient.ObjectKey{ Name: name, Namespace: l.setup.Namespace.Name, @@ -130,7 +129,9 @@ func (l *loginRuleTestingPrimitives) ModifyKubernetesResource(ctx context.Contex return trace.Wrap(l.setup.K8sClient.Update(ctx, rule)) } -func (l *loginRuleTestingPrimitives) CompareTeleportAndKubernetesResource(tResource *v1.LoginRuleResource, kubeResource *v1.TeleportLoginRule) (bool, string) { +func (l *loginRuleTestingPrimitives) CompareTeleportAndKubernetesResource( + tResource *resourcesv1.LoginRuleResource, + kubeResource *resourcesv1.TeleportLoginRule) (bool, string) { diff := cmp.Diff(tResource, kubeResource.ToTeleport(), cmpopts.IgnoreUnexported(loginrulepb.LoginRule{}), cmpopts.IgnoreFields(types.Metadata{}, "ID", "Labels"), @@ -140,15 +141,15 @@ func (l *loginRuleTestingPrimitives) CompareTeleportAndKubernetesResource(tResou func LoginRuleCreationTest(t *testing.T, clt *client.Client) { test := &loginRuleTestingPrimitives{} - ResourceCreationTest[*v1.LoginRuleResource, *v1.TeleportLoginRule](t, test, WithTeleportClient(clt)) + ResourceCreationTest[*resourcesv1.LoginRuleResource, *resourcesv1.TeleportLoginRule](t, test, WithTeleportClient(clt)) } func LoginRuleDeletionDriftTest(t *testing.T, clt *client.Client) { test := &loginRuleTestingPrimitives{} - ResourceDeletionDriftTest[*v1.LoginRuleResource, *resourcesv1.TeleportLoginRule](t, test, WithTeleportClient(clt)) + ResourceDeletionDriftTest[*resourcesv1.LoginRuleResource, *resourcesv1.TeleportLoginRule](t, test, WithTeleportClient(clt)) } func LoginRuleUpdateTest(t *testing.T, clt *client.Client) { test := &loginRuleTestingPrimitives{} - ResourceUpdateTest[*v1.LoginRuleResource, *resourcesv1.TeleportLoginRule](t, test, WithTeleportClient(clt)) + ResourceUpdateTest[*resourcesv1.LoginRuleResource, *resourcesv1.TeleportLoginRule](t, test, WithTeleportClient(clt)) } diff --git a/lib/auth/auth_with_roles_test.go b/lib/auth/auth_with_roles_test.go index cbc051da108..61d09cafb96 100644 --- a/lib/auth/auth_with_roles_test.go +++ b/lib/auth/auth_with_roles_test.go @@ -37,7 +37,6 @@ import ( "github.com/gravitational/teleport/api/client/proto" "github.com/gravitational/teleport/api/constants" "github.com/gravitational/teleport/api/defaults" - apidefaults "github.com/gravitational/teleport/api/defaults" "github.com/gravitational/teleport/api/types" apievents "github.com/gravitational/teleport/api/types/events" "github.com/gravitational/teleport/api/types/installers" @@ -1266,7 +1265,7 @@ func BenchmarkListNodes(b *testing.B) { var resources []types.ResourceWithLabels req := proto.ListResourcesRequest{ ResourceType: types.KindNode, - Namespace: apidefaults.Namespace, + Namespace: defaults.Namespace, Limit: 1_000, } for { diff --git a/lib/client/interfaces.go b/lib/client/interfaces.go index 48ca71d73a3..e355deeb81c 100644 --- a/lib/client/interfaces.go +++ b/lib/client/interfaces.go @@ -37,7 +37,6 @@ import ( apiutils "github.com/gravitational/teleport/api/utils" "github.com/gravitational/teleport/api/utils/keys" "github.com/gravitational/teleport/api/utils/sshutils" - apisshutils "github.com/gravitational/teleport/api/utils/sshutils" "github.com/gravitational/teleport/lib/auth" "github.com/gravitational/teleport/lib/auth/native" "github.com/gravitational/teleport/lib/services" @@ -208,7 +207,7 @@ func (k *Key) authorizedHostKeys(hostnames ...string) ([]ssh.PublicKey, error) { // Mirror the hosts we would find in a known_hosts entry. hosts := []string{k.ProxyHost, ca.ClusterName, "*." + ca.ClusterName} - if len(hostnames) == 0 || apisshutils.HostNameMatch(hostnames, hosts) { + if len(hostnames) == 0 || sshutils.HostNameMatch(hostnames, hosts) { for _, authorizedKey := range ca.AuthorizedKeys { sshPub, _, _, _, err := ssh.ParseAuthorizedKey(authorizedKey) if err != nil { @@ -281,7 +280,7 @@ func (k *Key) ProxyClientSSHConfig(hostname string) (*ssh.ClientConfig, error) { return nil, trace.Wrap(err, "failed to extract username from SSH certificate") } - sshConfig, err := apisshutils.ProxyClientSSHConfig(sshCert, k) + sshConfig, err := sshutils.ProxyClientSSHConfig(sshCert, k) if err != nil { return nil, trace.Wrap(err) } @@ -481,7 +480,7 @@ func (k *Key) AsAuthMethod() (ssh.AuthMethod, error) { if err != nil { return nil, trace.Wrap(err) } - return apisshutils.AsAuthMethod(cert, k) + return sshutils.AsAuthMethod(cert, k) } // SSHSigner returns an ssh.Signer using the SSH certificate in this key. @@ -490,7 +489,7 @@ func (k *Key) SSHSigner() (ssh.Signer, error) { if err != nil { return nil, trace.Wrap(err) } - return apisshutils.SSHSigner(cert, k) + return sshutils.SSHSigner(cert, k) } // SSHCert returns parsed SSH certificate @@ -498,7 +497,7 @@ func (k *Key) SSHCert() (*ssh.Certificate, error) { if k.Cert == nil { return nil, trace.NotFound("SSH cert not available") } - return apisshutils.ParseCertificate(k.Cert) + return sshutils.ParseCertificate(k.Cert) } // ActiveRequests gets the active requests associated with this key. @@ -535,13 +534,13 @@ func (k *Key) CheckCert() error { func (k *Key) checkCert(sshCert *ssh.Certificate) error { // Check that the certificate was for the current public key. If not, the // public/private key pair may have been rotated. - if !apisshutils.KeysEqual(sshCert.Key, k.SSHPublicKey()) { + if !sshutils.KeysEqual(sshCert.Key, k.SSHPublicKey()) { return trace.CompareFailed("public key in profile does not match the public key in SSH certificate") } // A valid principal is always passed in because the principals are not being // checked here, but rather the validity period, signature, and algorithms. - certChecker := apisshutils.CertChecker{ + certChecker := sshutils.CertChecker{ FIPS: isFIPS(), } if len(sshCert.ValidPrincipals) == 0 { diff --git a/lib/web/apiserver_test.go b/lib/web/apiserver_test.go index aaeeb984f71..63718c590e8 100644 --- a/lib/web/apiserver_test.go +++ b/lib/web/apiserver_test.go @@ -61,7 +61,6 @@ import ( "github.com/stretchr/testify/require" commonv1 "go.opentelemetry.io/proto/otlp/common/v1" resourcev1 "go.opentelemetry.io/proto/otlp/resource/v1" - otlp "go.opentelemetry.io/proto/otlp/trace/v1" tracepb "go.opentelemetry.io/proto/otlp/trace/v1" "golang.org/x/crypto/ssh" "golang.org/x/exp/slices" @@ -80,7 +79,6 @@ import ( "github.com/gravitational/teleport" "github.com/gravitational/teleport/api/breaker" authproto "github.com/gravitational/teleport/api/client/proto" - clientproto "github.com/gravitational/teleport/api/client/proto" "github.com/gravitational/teleport/api/client/webclient" "github.com/gravitational/teleport/api/constants" apidefaults "github.com/gravitational/teleport/api/defaults" @@ -7943,8 +7941,8 @@ func startKubeWithoutCleanup(ctx context.Context, t *testing.T, cfg startKubeOpt }, ConnTLSConfig: tlsConfig, Clock: clockwork.NewRealClock(), - ClusterFeatures: func() clientproto.Features { - return clientproto.Features{ + ClusterFeatures: func() authproto.Features { + return authproto.Features{ Kubernetes: true, } }, @@ -8115,7 +8113,7 @@ func TestForwardingTraces(t *testing.T) { cases := []struct { name string req func(t *testing.T) *http.Request - assertion func(t *testing.T, spans []*otlp.ResourceSpans, err error, code int) + assertion func(t *testing.T, spans []*tracepb.ResourceSpans, err error, code int) }{ { name: "no data", @@ -8191,7 +8189,7 @@ func TestForwardingTraces(t *testing.T) { return r }, - assertion: func(t *testing.T, spans []*otlp.ResourceSpans, err error, code int) { + assertion: func(t *testing.T, spans []*tracepb.ResourceSpans, err error, code int) { require.NoError(t, err) require.Equal(t, http.StatusOK, code) require.Len(t, spans, 1) @@ -8201,7 +8199,7 @@ func TestForwardingTraces(t *testing.T) { // compare the spans, but ignore the ids since we know that the rawSpan // has hex encoded ids and protojson.Unmarshal will give us an invalid value - require.Empty(t, cmp.Diff(data.ResourceSpans[0], spans[0], protocmp.Transform(), protocmp.IgnoreFields(&otlp.Span{}, "span_id", "trace_id"))) + require.Empty(t, cmp.Diff(data.ResourceSpans[0], spans[0], protocmp.Transform(), protocmp.IgnoreFields(&tracepb.Span{}, "span_id", "trace_id"))) // compare the ids separately sid1 := spans[0].ScopeSpans[0].Spans[0].SpanId @@ -8261,7 +8259,7 @@ func (m *mockPROXYSigner) SignPROXYHeader(source, destination net.Addr) ([]byte, type mockTraceClient struct { uploadError error uploadReceived chan struct{} - spans []*otlp.ResourceSpans + spans []*tracepb.ResourceSpans } func (m *mockTraceClient) Start(ctx context.Context) error { @@ -8272,7 +8270,7 @@ func (m *mockTraceClient) Stop(ctx context.Context) error { return nil } -func (m *mockTraceClient) UploadTraces(ctx context.Context, protoSpans []*otlp.ResourceSpans) error { +func (m *mockTraceClient) UploadTraces(ctx context.Context, protoSpans []*tracepb.ResourceSpans) error { m.spans = append(m.spans, protoSpans...) m.uploadReceived <- struct{}{} return m.uploadError @@ -8337,12 +8335,12 @@ func TestLogout(t *testing.T) { func TestGetIsDashboard(t *testing.T) { tt := []struct { name string - features clientproto.Features + features authproto.Features expected bool }{ { name: "not cloud nor recovery codes is not dashboard", - features: clientproto.Features{ + features: authproto.Features{ Cloud: false, RecoveryCodes: false, }, @@ -8350,7 +8348,7 @@ func TestGetIsDashboard(t *testing.T) { }, { name: "not cloud, with recovery codes is dashboard", - features: clientproto.Features{ + features: authproto.Features{ Cloud: false, RecoveryCodes: true, }, @@ -8358,7 +8356,7 @@ func TestGetIsDashboard(t *testing.T) { }, { name: "cloud, with recovery codes is not dashboard", - features: clientproto.Features{ + features: authproto.Features{ Cloud: true, RecoveryCodes: true, }, @@ -8366,7 +8364,7 @@ func TestGetIsDashboard(t *testing.T) { }, { name: "cloud, without recovery codes is not dashboard", - features: clientproto.Features{ + features: authproto.Features{ Cloud: true, RecoveryCodes: false, }, diff --git a/tool/tctl/common/tctl.go b/tool/tctl/common/tctl.go index 6a872e4fb1b..7d57c98fb47 100644 --- a/tool/tctl/common/tctl.go +++ b/tool/tctl/common/tctl.go @@ -41,7 +41,6 @@ import ( "github.com/gravitational/teleport/lib/service/servicecfg" "github.com/gravitational/teleport/lib/utils" "github.com/gravitational/teleport/tool/common" - toolcommon "github.com/gravitational/teleport/tool/common" ) const ( @@ -94,7 +93,7 @@ type CLICommand interface { func Run(commands []CLICommand) { err := TryRun(commands, os.Args[1:]) if err != nil { - var exitError *toolcommon.ExitCodeError + var exitError *common.ExitCodeError if errors.As(err, &exitError) { os.Exit(exitError.Code) } @@ -201,7 +200,7 @@ func TryRun(commands []CLICommand, args []string) error { utils.Consolef(os.Stderr, log.WithField(trace.Component, teleport.ComponentClient), teleport.ComponentClient, "Cannot connect to the auth server: %v.\nIs the auth server running on %q?", err, cfg.AuthServerAddresses()[0].Addr) - return trace.NewAggregate(&toolcommon.ExitCodeError{Code: 1}, err) + return trace.NewAggregate(&common.ExitCodeError{Code: 1}, err) } // execute whatever is selected: