docs: Adds common Teleport configure,start and helm charts for non-iam db access guides (#23878)

* Adds common Teleport configure,start and helm charts for db access

* Add helm install and standard configure, start for non-IAM DBs

* Correct teleport version used in helm install

* Correct helm reference

* Change helm install styles

Co-authored-by: Alex Fornuto <alex.fornuto@goteleport.com>

* rm extra space

* elevate and expand multi-service warning

* Add oracle for helm option

* language update

* specify database name for db configure and helm

* spell fix

* lint fix

---------

Co-authored-by: Alex Fornuto <alex.fornuto@goteleport.com>
This commit is contained in:
Steven Martin
2023-04-21 17:53:59 +00:00
committed by GitHub
co-authored by Alex Fornuto
parent 2e9ed857da
commit 989d6ee73c
13 changed files with 344 additions and 579 deletions
@@ -20,10 +20,10 @@ This guide will help you to:
- Connect to your database through Teleport.
<ScopedBlock scope={["oss", "enterprise"]}>
![Teleport Database Access Redis Self-Hosted](../../../img/database-access/guides/cassandra_selfhosted.png)
![Teleport Database Access Cassandra Self-Hosted](../../../img/database-access/guides/cassandra_selfhosted.png)
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
![Teleport Database Access Redis Cloud](../../../img/database-access/guides/cassandra_cloud.png)
![Teleport Database Access Cassandra Cloud](../../../img/database-access/guides/cassandra_cloud.png)
</ScopedBlock>
## Prerequisites
@@ -38,55 +38,26 @@ This guide will help you to:
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="Linux Server">
(!docs/pages/includes/install-linux.mdx!)
<ScopedBlock scope={["oss", "enterprise"]}>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="cassandra" dbProtocol="cassandra" databaseAddress="cassandra.example.com:9042" !)
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Proxy Service:
</TabItem>
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=example-cassandra \
--protocol=cassandra \
--uri=cassandra.example.com:9042 \
--labels=env=dev
```
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
<Admonition type="note">
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="cassandra" dbProtocol="cassandra" databaseAddress="cassandra.example.com:9042" !)
</TabItem>
</Tabs>
The `--auth-server` flag must point to the Teleport cluster's Proxy Service
endpoint because the Database Service always connects back to the cluster over a
reverse tunnel.
</Admonition>
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Cloud tenant:
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name=example-cassandra \
--protocol=cassandra \
--uri=cassandra.example.com:9042 \
--labels=env=dev
```
</ScopedBlock>
<Admonition type="tip">
You can start the Database Service using a configuration file instead of CLI flags.
See the [YAML reference](../reference/configuration.mdx) for details.
</Admonition>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 2/5. Create a Teleport user
@@ -39,52 +39,26 @@ This guide will help you to:
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="Linux Server">
(!docs/pages/includes/install-linux.mdx!)
<Tabs>
<TabItem label="Self-Hosted" scope={["enterprise","oss"]}>
Start the Teleport Database Service, pointing the `--auth-server` flag to the address of your Teleport Proxy Service:
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=roach \
--protocol=cockroachdb \
--uri=roach.example.com:26257 \
--labels=env=dev
```
<Admonition type="note">
The `--auth-server` flag must point to the Teleport cluster's Proxy Service endpoint
because the Database Service always connects back to the cluster over a reverse
tunnel.
</Admonition>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="roach" "dbProtocol="cockroachdb" databaseAddress="roach.example.com:26257" !)
</TabItem>
<TabItem label="Teleport Cloud" scope={["cloud"]}>
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
Start the Teleport Database Service, pointing the `--auth-server` flag at the address of your Teleport Cloud tenant, e.g., `mytenant.teleport.sh`.
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name=roach \
--protocol=cockroachdb \
--uri=roach.example.com:26257 \
--labels=env=dev
```
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="roach" dbProtocol="cockroachdb" databaseAddress="roach.example.com:26257" !)
</TabItem>
</Tabs>
<Admonition type="tip">
You can start the Database Service using a configuration file instead of CLI flags.
See [YAML reference](../reference/configuration.mdx).
</Admonition>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 2/4. Create a Teleport user
+11 -102
View File
@@ -34,118 +34,27 @@ This guide will help you to configure secured access to an Elasticsearch databas
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service. Make sure you've selected your installation type (OSS, Enterprise, Cloud):
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="Linux Server">
(!docs/pages/includes/install-linux.mdx!)
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Proxy Service:
<Tabs>
<TabItem label="Standalone Binary">
<ScopedBlock scope={["oss", "enterprise"]}>
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=myelastic \
--protocol=elasticsearch \
--uri=elasticsearch.example.com:9200 \
--labels=env=dev
```
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytennant.teleport.sh:443 \
--name=myelastic \
--protocol=elasticsearch \
--uri=elasticsearch.example.com:9200 \
--labels=env=dev
```
</ScopedBlock>
<Admonition type="note">
The `--auth-server` flag must point to the Teleport cluster's Proxy Service
endpoint because the Database Service always connects back to the cluster over a
reverse tunnel.
</Admonition>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="myelastic" dbProtocol="elastic" databaseAddress="elasticsearch.example.com:9200" !)
</TabItem>
<TabItem label="Config File">
Configure `teleport.yaml` using the example below:
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
<ScopedBlock scope={["cloud"]}>
```yaml
version: v3
teleport:
auth_token: <insert token here>
proxy_server: mytenant.teleport.sh:443
# disable services that are on by default
ssh_service: { enabled: no }
proxy_service: { enabled: no }
auth_service: { enabled: no }
# db service config
db_service:
enabled: "yes"
resources:
- labels:
"*": "*"
databases:
- name: myelastic
protocol: elasticsearch
uri: elasticsearch.example.com:9200
static_labels:
env: dev
```
</ScopedBlock>
<ScopedBlock scope={["oss", "enterprise"]}>
```yaml
version: v3
teleport:
auth_token: <insert token here>
proxy_server: teleport.example.com
# disable services that are on by default
ssh_service: { enabled: no }
proxy_service: { enabled: no }
auth_service: { enabled: no }
# db service config
db_service:
enabled: "yes"
resources:
- labels:
"*": "*"
databases:
- name: myelastic
protocol: elasticsearch
uri: elasticsearch.example.com:9200
static_labels:
env: dev
```
</ScopedBlock>
Adjust for your environment, then start or restart Teleport. See the [YAML reference](../reference/configuration.mdx) for details.
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="myelastic" dbProtocol="elastic" databaseAddress="elasticsearch.example.com:9200" !)
</TabItem>
</Tabs>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 2/5. Create a Teleport user
(!docs/pages/includes/database-access/create-user.mdx!)
@@ -38,50 +38,26 @@ In this guide you will:
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="Linux Server">
(!docs/pages/includes/install-linux.mdx!)
<ScopedBlock scope={["oss", "enterprise"]}>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="example-mongo" dbProtocol="mongodb" databaseAddress="mongo.example.com:27017" !)
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Proxy Service:
</TabItem>
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=example-mongo \
--protocol=mongodb \
--uri=mongo.example.com:27017 \
--labels=env=dev
```
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
<Admonition type="note">
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="example-mongo" dbProtocol="mongodb" databaseAddress="mongo.example.com:27017" !)
</TabItem>
</Tabs>
The `--auth-server` flag must point to the Teleport cluster's Proxy Service
endpoint because the Database Service always connects back to the cluster over a
reverse tunnel.
</Admonition>
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Cloud tenant:
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name=example-mongo \
--protocol=mongodb \
--uri=mongo.example.com:27017 \
--labels=env=dev
```
</ScopedBlock>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
You can specify either a single connection address or a MongoDB
[connection string](https://docs.mongodb.com/manual/reference/connection-string/)
@@ -99,11 +75,6 @@ connection string setting:
$ --uri="mongodb://mongo1.example.com:27017,mongo2.example.com:27017/?replicaSet=rs0&readPreference=secondary"
```
<Admonition type="tip">
You can start the Database Service using a configuration file instead of CLI flags.
See the [YAML reference](../reference/configuration.mdx) for details.
</Admonition>
### Create a Teleport user
(!docs/pages/includes/database-access/create-user.mdx!)
@@ -25,14 +25,10 @@ This guide will help you to:
Service.
- (!docs/pages/includes/tctl.mdx!)
## Step 1/4. Set up the Teleport Database Service
## Step 1/4. Create the Teleport Database Token
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
(!docs/pages/includes/install-linux.mdx!)
## Step 2/4. Create a certificate/key pair
(!docs/pages/includes/database-access/tctl-auth-sign.mdx!)
@@ -137,101 +133,29 @@ in the MariaDB documentation for more details.
(!docs/pages/includes/database-access/create-user.mdx!)
### Start the Database Service
### Configure and Start the Database Service
You can configure Teleport to start the Database Service and access MySQL or
MariaDB by running the `teleport` daemon either with CLI flags or a
configuration file.
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="Using CLI flags">
<TabItem label="Linux Server">
On the host where you will run the Teleport Database Service, run the following
command:
(!docs/pages/includes/install-linux.mdx!)
<ScopedBlock scope={["oss", "enterprise"]}>
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=test \
--protocol=mysql \
--uri=mysql.example.com:3306 \
--labels=env=dev
```
Note that the `--auth-server` flag must point to the Teleport cluster's Proxy
Service endpoint because Database Service always connects back to the cluster
over a reverse tunnel.
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name=test \
--protocol=mysql \
--uri=mysql.example.com:3306 \
--labels=env=dev
```
Note that the `--auth-server` flag must point to your Teleport Cloud tenant
address.
</ScopedBlock>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="example-mysql" dbProtocol="mysql" databaseAddress="mysql.example.com:3306" !)
</TabItem>
<TabItem label="Using a config file">
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
On the host where you will run the Teleport Database Service, create a
configuration file at `/etc/teleport.yaml`:
<ScopedBlock scope={["oss", "enterprise"]}>
```code
$ teleport db configure create \
-o file \
--token=/tmp/token \
--proxy=teleport.example.com:3080 \
--name=test \
--protocol=mysql \
--uri=mysql.example.com:3306 \
--labels=env=dev
```
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
```code
$ teleport db configure create \
-o file \
--token=/tmp/token \
--proxy=mytenant.teleport.sh:443 \
--name=test \
--protocol=mysql \
--uri=mysql.example.com:3306 \
--labels=env=dev
```
</ScopedBlock>
<Admonition
type="tip"
title="Tip"
>
A single Teleport process can run multiple services, for example
multiple Database Access instances as well as other services such the
SSH Service or Application Service.
</Admonition>
(!docs/pages/includes/start-teleport.mdx service="the Teleport Database Service"!)
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="example-mysql" dbProtocol="mysql" databaseAddress="mysql.example.com:3306" !)
</TabItem>
</Tabs>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 4/4. Connect
Once the Database Service has joined the cluster, log in to see the available
@@ -242,9 +166,9 @@ databases:
```code
$ tsh login --proxy=teleport.example.com --user=testuser
$ tsh db ls
# Name Description Labels
# ------- ------------- --------
# example Example MySQL env=dev
# Name Description Labels
# ------------- ------------- --------
# example-mysql Example MySQL env=dev
```
</ScopedBlock>
@@ -253,9 +177,9 @@ $ tsh db ls
```code
$ tsh login --proxy=mytenant.teleport.sh --user=testuser
$ tsh db ls
# Name Description Labels
# ------- ------------- --------
# example Example MySQL env=dev
# Name Description Labels
# ------------- ------------- --------
# example-mysql Example MySQL env=dev
```
</ScopedBlock>
@@ -266,14 +190,14 @@ the [RBAC](../rbac.mdx) guide for more details.
To retrieve credentials for a database and connect to it:
```code
$ tsh db connect example
$ tsh db connect example-mysql
```
You can optionally specify the database name and the user to use by default
when connecting to the database instance:
```code
$ tsh db connect --db-user=root --db-name=mysql example
$ tsh db connect --db-user=root --db-name=mysql example-mysql
```
<Admonition type="note" title="Note">
@@ -285,7 +209,7 @@ To log out of the database and remove credentials:
```code
# Remove credentials for a particular database instance.
$ tsh db logout example
$ tsh db logout example-mysql
# Remove credentials for all database instances.
$ tsh db logout
```
@@ -27,53 +27,30 @@ This guide will help you to:
- The `sqlcl` [Oracle client](https://www.oracle.com/pl/database/sqldeveloper/technologies/sqlcl/) installed and added to your system's `PATH` environment variable or any GUI client that supports JDBC
Oracle thin client.
## Step 1/6. Create a Teleport user
(!docs/pages/includes/database-access/create-user.mdx!)
## Step 2/6. Create a Database Service configuration
## Step 1/5. Create a Teleport token and user
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
(!docs/pages/includes/database-access/create-user.mdx!)
(!docs/pages/includes/install-linux.mdx!)
Create the Database Service configuration:
```code
$ teleport db configure create \
-o file \
--token=/tmp/token \
--proxy=<Var name="teleport.example.com"/> \
--name=example-oracle \
--protocol=oracle \
--uri=oracle.example.com:2484 \
--labels=env=dev
```
## Step 3/6. Start the Database Service
(!docs/pages/includes/start-teleport.mdx service="the Database Service"!)
## Step 4/6. Create a certificate/key pair and Teleport Oracle Wallet
## Step 2/5. Create a certificate/key pair and Teleport Oracle Wallet
(!docs/pages/includes/database-access/tctl-auth-sign.mdx!)
Follow the instructions below to generate TLS credentials for your database.
```code
# Export Teleport's certificate authority and a generate certificate/key pair
# Export Teleport's certificate authority and a generated certificate/key pair
# for host db.example.com with a 1-year validity period.
$ tctl auth sign --format=oracle --host=db.example.com --out=server --ttl=2190h
```
(!docs/pages/includes/database-access/ttl-note.mdx!)
If `tctl` finds the Orapki tool in your local environment, the `tctl auth sign --format=oracle --hostdb.example.com --out=server --ttl=2190h` command will produce an Oracle Wallet and
If `tctl` finds the Orapki tool in your local environment, the `tctl auth sign --format=oracle --host=db.example.com --out=server --ttl=2190h` command will produce an Oracle Wallet and
instructions how to configure the Oracle TCPS listener with Teleport Oracle Wallet. Otherwise the `tctl auth sign --format=oracle` command will produce a `p12` certificate and instructions on how to create an Oracle Wallet on your Oracle Database instance.
## Step 5/6. Configure Oracle Database
## Step 3/5. Configure Oracle Database
In order to enable the Teleport Oracle integration you will need to configure the TCPS Oracle listener and use the Teleport Oracle Wallet created in the previous step.
@@ -109,21 +86,51 @@ Additionally, your Oracle Database user accounts must be configured to require a
CREATE USER alice IDENTIFIED EXTERNALLY AS 'CN=alice';
GRANT CREATE SESSION TO alice;
```
## Step 4/5. Configure and Start the Database Service
Install and configure Teleport where you will run the Teleport Database Service:
## Step 6/6. Connect
<Tabs>
<TabItem label="Linux Server">
(!docs/pages/includes/install-linux.mdx!)
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="oracle.example.com:2484" dbName="oracle" !)
</TabItem>
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="oracle" dbProtocol="oracle" databaseAddress="oracle.example.com:2484" dbName="oracle" !)
</TabItem>
</Tabs>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 5/5. Connect
Once the Database Service has joined the cluster, log in to see the available
databases:
<ScopedBlock scope={["oss", "enterprise"]}>
```code
$ tsh login --proxy=<Var name="teleport.example.com"/> --user=testuser
$ tsh login --proxy=teleport.example.com --user=testuser
$ tsh db ls
# Name Description Allowed Users Labels Connect
# ------ ----------- ------------- ------- -------
# oracle [*] env=dev
# Name Description Allowed Users Labels Connect
# ------ -------------- ------------- ------- -------
# oracle Oracle Example [*] env=dev
```
To connect to the Oracle `XE` Oracle SID/SERVICE_NAME:
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
```code
$ tsh login --proxy=mytenant.teleport.sh --user=testuser
$ tsh db ls
# Name Description Allowed Users Labels Connect
# ------ -------------- ------------- ------- -------
# oracle Oracle Example [*] env=dev
```
</ScopedBlock>
```code
$ tsh db connect --db-user=alice --db-name=XE oracle
@@ -26,14 +26,10 @@ This guide will help you to:
Service.
- (!docs/pages/includes/tctl.mdx!)
## Step 1/5. Set up the Teleport Database Service
## Step 1/5. Create a Teleport token and user
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
(!docs/pages/includes/install-linux.mdx!)
### Create a Teleport user
(!docs/pages/includes/database-access/create-user.mdx!)
@@ -86,100 +82,29 @@ certificate-based Teleport login will fail.
See [The pg_hba.conf File](https://www.postgresql.org/docs/current/auth-pg-hba-conf.html)
in the PostgreSQL documentation for more details.
## Step 4/5. Start the Database Service
## Step 4/5. Configure and Start the Database Service
On the host where you will run the Teleport Database Service, start Teleport
with the appropriate configuration.
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="With CLI flags">
<TabItem label="Linux Server">
You can start the Teleport Database Service without configuration file using a
CLI command:
(!docs/pages/includes/install-linux.mdx!)
<ScopedBlock scope={["oss", "enterprise"]}>
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=test \
--protocol=postgres \
--uri=postgres.example.com:5432 \
--labels=env=dev
```
Note that the `--auth-server` flag must point to the Teleport cluster's Proxy
Service endpoint because the Database Service always connects back to the
cluster over a reverse tunnel.
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name=test \
--protocol=postgres \
--uri=postgres.example.com:5432 \
--labels=env=dev
```
Note that the `--auth-server` flag must point to your Teleport Cloud tenant
address.
</ScopedBlock>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="example-postgres" dbProtocol="postgres" databaseAddress="postgres.example.com:5432" !)
</TabItem>
<TabItem label="Using a config file">
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
Generate a configuration file at `/etc/teleport.yaml` for the Database Service:
<ScopedBlock scope={["oss", "enterprise"]}>
```code
$ teleport db configure create \
-o file \
--token=/tmp/token \
--proxy=teleport.example.com:3080 \
--name=test \
--protocol=postgres \
--uri=postgres.example.com:5432 \
--labels=env=dev
```
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
```code
$ teleport db configure create \
-o file \
--token=/tmp/token \
--proxy=mytenant.teleport.sh:443 \
--name=test \
--protocol=postgres \
--uri=postgres.example.com:5432 \
--labels=env=dev
```
</ScopedBlock>
<Admonition
type="tip"
title="Tip"
>
A single Teleport process can run multiple different services, for example
multiple Database Service agents as well as the SSH Service or Application
Service.
</Admonition>
(!docs/pages/includes/start-teleport.mdx service="the Teleport Database Service"!)
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="example-postgres" dbProtocol="postgres" databaseAddress="postgres.example.com:5432" !)
</TabItem>
</Tabs>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 5/5. Connect
Once the Database Service has joined the cluster, log in to see the available
@@ -190,9 +115,9 @@ databases:
```code
$ tsh login --proxy=teleport.example.com --user=testuser
$ tsh db ls
# Name Description Labels
# ------- ------------------ --------
# example Example PostgreSQL env=dev
# Name Description Labels
# ---------------- ------------------ --------
# example-postgres Example PostgreSQL env=dev
```
</ScopedBlock>
@@ -201,9 +126,9 @@ $ tsh db ls
```code
$ tsh login --proxy=mytenant.teleport.sh --user=testuser
$ tsh db ls
# Name Description Labels
# ------- ------------------ --------
# example Example PostgreSQL env=dev
# Name Description Labels
# ---------------- ------------------ --------
# example-postgres Example PostgreSQL env=dev
```
</ScopedBlock>
@@ -214,21 +139,21 @@ Note that you will only be able to see databases your role has access to. See
To retrieve credentials for a database and connect to it:
```code
$ tsh db connect example
$ tsh db connect example-postgres
```
You can optionally specify the database name and the user to use by default
when connecting to the database instance:
```code
$ tsh db connect --db-user=postgres --db-name=postgres example
$ tsh db connect --db-user=postgres --db-name=postgres example-postgres
```
To log out of the database and remove credentials:
```code
# Remove credentials for a particular database instance.
$ tsh db logout example
$ tsh db logout example-postgres
# Remove credentials for all database instances.
$ tsh db logout
```
@@ -46,55 +46,26 @@ This guide will help you to:
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="Linux Server">
(!docs/pages/includes/install-linux.mdx!)
<ScopedBlock scope={["oss", "enterprise"]}>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="example-redis" dbProtocol="redis" databaseAddress="rediss://redis.example.com:6379?mode=cluster" !)
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Proxy Service:
</TabItem>
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=example-redis \
--protocol=redis \
--uri=rediss://redis.example.com:6379?mode=cluster \
--labels=env=dev
```
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
<Admonition type="note">
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="example-redis" dbProtocol="redis" databaseAddress="rediss://redis.example.com:6379?mode=cluster" !)
</TabItem>
</Tabs>
The `--auth-server` flag must point to the Teleport cluster's Proxy Service
endpoint because the Database Service always connects back to the cluster over a
reverse tunnel.
</Admonition>
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Cloud tenant:
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name=example-redis \
--protocol=redis \
--uri=rediss://redis.example.com:6379?mode=cluster \
--labels=env=dev
```
</ScopedBlock>
<Admonition type="tip">
You can start the Database Service using a configuration file instead of CLI flags.
See the [YAML reference](../reference/configuration.mdx) for details.
</Admonition>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 2/6. Create a Teleport user
+13 -42
View File
@@ -51,55 +51,26 @@ This guide will help you to:
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="Linux Server">
(!docs/pages/includes/install-linux.mdx!)
<ScopedBlock scope={["oss", "enterprise"]}>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="example-redis" dbProtocol="redis" databaseAddress="rediss://redis.example.com:6379" !)
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Proxy Service:
</TabItem>
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=example-redis \
--protocol=redis \
--uri=rediss://redis.example.com:6379 \
--labels=env=dev
```
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
<Admonition type="note">
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="example-redis" dbProtocol="redis" databaseAddress="rediss://redis.example.com:6379" !)
</TabItem>
</Tabs>
The `--auth-server` flag must point to the Teleport cluster's Proxy Service
endpoint because the Database Service always connects back to the cluster over a
reverse tunnel.
</Admonition>
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Cloud tenant:
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name=example-redis \
--protocol=redis \
--uri=rediss://redis.example.com:6379 \
--labels=env=dev
```
</ScopedBlock>
<Admonition type="tip">
You can start the Database Service using a configuration file instead of CLI flags.
See the [YAML reference](../reference/configuration.mdx) for details.
</Admonition>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 2/5. Create a Teleport user
+13 -42
View File
@@ -44,55 +44,26 @@ This guide will help you to:
(!docs/pages/includes/database-access/token.mdx!)
Install Teleport on the host where you will run the Teleport Database Service:
Install and configure Teleport where you will run the Teleport Database Service:
<Tabs>
<TabItem label="Linux Server">
(!docs/pages/includes/install-linux.mdx!)
<ScopedBlock scope={["oss", "enterprise"]}>
(!docs/pages/includes/database-access/db-configure-start.mdx dbName="example-snowflake" dbProtocol="snowflake" databaseAddress="https://abc12345.snowflakecomputing.com" !)
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Proxy Service:
</TabItem>
<TabItem label="Kubernetes Cluster">
Teleport provides Helm charts for installing the Teleport Database Service in Kubernetes Clusters.
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:3080 \
--name=example-snowflake \
--protocol=snowflake \
--uri=https://abc12345.snowflakecomputing.com \
--labels=env=dev
```
(!docs/pages/kubernetes-access/helm/includes/helm-repo-add.mdx!)
<Admonition type="note">
(!docs/pages/includes/database-access/db-helm-install.mdx dbName="example-snowflake" dbProtocol="snowflake" databaseAddress="https://abc12345.snowflakecomputing.com" !)
</TabItem>
</Tabs>
The `--auth-server` flag must point to the Teleport cluster's Proxy Service
endpoint because the Database Service always connects back to the cluster over a
reverse tunnel.
</Admonition>
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
Start the Teleport Database Service, pointing the `--auth-server` flag to the
address of your Teleport Cloud tenant:
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name=example-snowflake \
--protocol=snowflake \
--uri=https://abc12345.snowflakecomputing.com \
--labels=env=dev
```
</ScopedBlock>
<Admonition type="tip">
You can start the Database Service using a configuration file instead of CLI flags.
See the [YAML reference](../reference/configuration.mdx) for details.
</Admonition>
(!docs/pages/includes/database-access/multiple-instances-tip.mdx !)
## Step 2/5. Create a Teleport user
@@ -0,0 +1,122 @@
{{ dbName="test" }}
<Tabs>
<TabItem label="Using a config file">
On the host where you will run the Teleport Database Service, start Teleport
with the appropriate configuration.
Note that a single Teleport process can run multiple different services, for
example multiple Database Service agents as well as the SSH Service or Application
Service. The step below will overwrite an existing configuration file, so if
you're running multiple services add `--output=stdout` to print the config in
your terminal, and manually adjust `/etc/teleport.yaml`.
Generate a configuration file at `/etc/teleport.yaml` for the Database Service:
<ScopedBlock scope={["oss", "enterprise"]}>
```code
$ teleport db configure create \
-o file \
--token=/tmp/token \
--proxy=teleport.example.com:443 \
--name={{ dbName }} \
--protocol={{ dbProtocol }} \
--uri={{ databaseAddress }} \
--labels=env=dev
```
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
```code
$ teleport db configure create \
-o file \
--token=/tmp/token \
--proxy=mytenant.teleport.sh:443 \
--name={{ dbName }} \
--protocol={{ dbProtocol }} \
--uri={{ databaseAddress }} \
--labels=env=dev
```
</ScopedBlock>
Configure the Database Service to start automatically when the host boots up by
creating a systemd service for it. The instructions depend on how you installed
the Database Service.
<Tabs>
<TabItem label="Package Manager">
On the host where you will run {{ service }}, start Teleport:
```code
$ sudo systemctl enable teleport
$ sudo systemctl start teleport
```
</TabItem>
<TabItem label="TAR Archive">
On the host where you will run {{ service }}, create a systemd service
configuration for Teleport, enable the Teleport service, and start Teleport:
```code
$ sudo teleport install systemd -o /etc/systemd/system/teleport.service
$ sudo systemctl enable teleport
$ sudo systemctl start teleport
```
</TabItem>
</Tabs>
</TabItem>
<TabItem label="With CLI flags">
You can start the Teleport Database Service without configuration file using a
CLI command:
<ScopedBlock scope={["oss", "enterprise"]}>
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=teleport.example.com:443 \
--name={{ dbName }} \
--protocol={{ dbProtocol }} \
--uri={{ databaseAddress }} \
--labels=env=dev
```
Note that the `--auth-server` flag must point to the Teleport cluster's Proxy
Service endpoint because the Database Service always connects back to the
cluster over a reverse tunnel.
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
```code
$ teleport db start \
--token=/tmp/token \
--auth-server=mytenant.teleport.sh:443 \
--name={{ dbName }} \
--protocol={{ dbProtocol }} \
--uri={{ databaseAddress }} \
--labels=env=dev
```
Note that the `--auth-server` flag must point to your Teleport Cloud tenant
address.
</ScopedBlock>
</TabItem>
</Tabs>
<Admonition type="note">
The `--auth-server` flag must point to the Teleport cluster's Proxy Service
endpoint because the Database Service always connects back to the cluster over a
reverse tunnel.
</Admonition>
@@ -0,0 +1,41 @@
{{ dbName="test" }}
<ScopedBlock scope={["oss", "enterprise"]}>
Install the Teleport Kube Agent into your Kubernetes Cluster
with the Teleport Database Service configuration.
```code
$ JOIN_TOKEN=$(cat /tmp/token)
$ helm install teleport-kube-agent teleport/teleport-kube-agent \
--create-namespace \
--namespace teleport-agent \
--set roles=db \
--set proxyAddr=teleport.example.com:443 \
--set authToken=${JOIN_TOKEN?} \
--set "databases[0].name={{ dbName }}" \
--set "databases[0].uri={{ databaseAddress }}" \
--set "databases[0].protocol={{ dbProtocol }}" \
--set "labels.env=dev" \
--version (=teleport.version=)
```
</ScopedBlock>
<ScopedBlock scope={["cloud"]}>
Install the Teleport Kube Agent into your Kubernetes Cluster
with the Teleport Database Service configuration.
```code
$ JOIN_TOKEN=$(cat /tmp/token)
$ helm install teleport-kube-agent teleport/teleport-kube-agent \
--create-namespace \
--namespace teleport-agent \
--set roles=db \
--set proxyAddr=mytenant.teleport.sh:443 \
--set authToken=${JOIN_TOKEN?} \
--set "databases[0].name={{ dbName }}" \
--set "databases[0].uri={{ databaseAddress }}" \
--set "databases[0].protocol={{ dbProtocol }}" \
--set "labels.env=dev" \
--version (=cloud.version=)
```
</ScopedBlock>
@@ -0,0 +1,8 @@
<Admonition
type="tip"
title="Tip"
>
A single Teleport process can run multiple services, for example
multiple Database Service instances as well as other services such the
SSH Service or Application Service.
</Admonition>