Update Access Graph Docs (#41307)

* Update TAG docs

* Update images

* Update docs

* Update images
Add EC2 instances to supported AWS types

* Linter fixes

* Update docs/pages/access-controls/access-graph.mdx

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* Update TAG version

---------

Co-authored-by: Roman Tkachenko <roman@goteleport.com>
This commit is contained in:
Jakub Nyckowski
2024-05-13 20:07:35 +00:00
committed by GitHub
co-authored by Roman Tkachenko
parent 575b79a871
commit 98d6e2765d
33 changed files with 99 additions and 100 deletions
+1 -1
View File
@@ -1893,7 +1893,7 @@
"nodeIP": "ip-172-31-35-170"
},
"access_graph": {
"version": "1.13.0"
"version": "1.20.1"
},
"ansible": {
"min_version": "2.9.6"
Binary file not shown.

Before

Width:  |  Height:  |  Size: 18 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 11 KiB

After

Width:  |  Height:  |  Size: 14 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 54 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 28 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 11 KiB

After

Width:  |  Height:  |  Size: 8.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 52 KiB

After

Width:  |  Height:  |  Size: 73 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 24 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 81 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 14 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 13 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 73 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 373 KiB

After

Width:  |  Height:  |  Size: 622 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 28 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 14 KiB

After

Width:  |  Height:  |  Size: 18 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 7.2 KiB

After

Width:  |  Height:  |  Size: 17 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 10 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 75 KiB

After

Width:  |  Height:  |  Size: 61 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.6 MiB

After

Width:  |  Height:  |  Size: 743 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 MiB

After

Width:  |  Height:  |  Size: 507 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 41 KiB

After

Width:  |  Height:  |  Size: 7.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 70 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 9.8 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 10 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 6.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 8.1 KiB

+93 -95
View File
@@ -23,126 +23,56 @@ under the Permission Management section.
## Graph nodes
Teleport Access Graph divides your infrastructure into eight main components:
Teleport Access Graph divides your infrastructure into six main components:
1. Users
1. Identities
![User Node](../../img/access-graph/user-node.png)
![Identity Node](../../img/access-graph/identity-node.png)
Users are the people who access your infrastructure. They can be employees,
contractors, or bots.
Identities are the actors that can access your infrastructure. They can be employees,
contractors, machines or bots.
The number on the right hand side shows "standing privileges".
Standing privileges is the number of resources that an identity can access without
creating an access request.
2. User Groups
![User Group Node](../../img/access-graph/user-group-node.png)
![Identity Group Node](../../img/access-graph/identity-group-node.png)
User Groups are collections of users. They can be used to organize users
based on their role or team.
Identity Groups are collections of identities. They can be used to organize users
based on their role or team, and they can be nested.
3. Temporary user groups
![Temporary User Group Node](../../img/access-graph/temporary-user-group-node.png)
Temporary User Groups are created when a user is granted temporary access to a
resource. They are automatically deleted when the user's access expires.
4. Actions
3. Actions
![Action Node](../../img/access-graph/allow-action-node.png)
Actions are the things that users can or cannot do. Actions are related to
Actions are the things that identities can or cannot do. Actions are related to
resources. For example, a user can SSH into a node.
5. Deny Actions
4. Deny Actions
![Deny Action Node](../../img/access-graph/deny-action-node.png)
Deny Actions are the things that users cannot do. Deny Actions are related to
Deny Actions are the things that identities cannot do. Deny Actions are related to
resources. For example, a user cannot SSH into a node.
6. Temporary Actions
![Temporary Action Node](../../img/access-graph/temporary-action-node.png)
Temporary Actions are created when a user is granted temporary access to a
resource. They are automatically deleted when the user's access expires.
7. Resource Groups
5. Resource Groups
![Resource Group Node](../../img/access-graph/resource-group-node.png)
Resource Groups are collections of resources. They can be used to organize
resources based on their role or team.
8. Resources
The number on the right hand side shows the number of resources that a resource group contains.
6. Resources
![Resource Node](../../img/access-graph/resource-node.png)
Resources are the things that users can or cannot access. They can be
servers, databases, or Kubernetes clusters.
## Searching
To search for a graph node, either click the search button in the sidebar on the left,
or press the `s` key.
![Search](../../img/access-graph/search.png)
You can then search through all node types. If you select a result using your keyboard
arrow keys, you can press either `Tab` to add the node to the graph, or `Enter` to replace
the graph with just the individual node.
## Changing what is visible
By default, Teleport Access Graph shows all types of nodes and paths. You can see what
node types are visible by looking at the sidebar on the left.
![Sidebar](../../img/access-graph/sidebar.png)
### Showing/removing individual graph nodes
To show or remove an individual graph node, open up the node type in the sidebar and
click on the node you want to show or remove.
![Show/Remove Node](../../img/access-graph/search-item-click.png)
Clicking on the node name will toggle the visibility of that node.
![Select only one node](../../img/access-graph/search-item-checkbox-click.png)
Clicking on the checkbox will select only that node.
### Adding/removing graph node types
To add a graph node type that isn't in the view, select it from the list of available
node types.
![Add node type](../../img/access-graph/add-node-type.png)
To remove the graph node type, expand the node type in the sidebar and click on the
remove button.
![Remove node type](../../img/access-graph/remove-node-type.png)
### Expanding/collapsing graph nodes
If a graph node has connections to other nodes, it can be expanded to show those
connections. To expand a node, hover over the edge of the node. If there are
connections in that direction, the edge will turn blue. Clicking on the edge
will expand the node.
![Expand node](../../img/access-graph/expand-node.png)
You can keep expanding graph nodes until you reach the end of the path.
![Expand one level](../../img/access-graph/expand-one-level.png)
![Expand two levels](../../img/access-graph/expand-two-levels.png)
To collapse a graph node, click on the edge that was used to expand it.
![Collapse node](../../img/access-graph/collapse-node.png)
## Graph paths
Teleport Access Graph shows the relationships between users, roles, and
@@ -161,14 +91,14 @@ Paths can be divided into two categories:
![Allow Path](../../img/access-graph/allow-path.png)
Allow paths connect users to resources. They show what a user can access
Allow paths connect identities to resources. They show what an identity can access
and what actions they can perform.
2. Deny paths
![Deny Path](../../img/access-graph/deny-path.png)
Deny paths connect users to resources. They show what a user cannot access
Deny paths connect identities to resources. They show what a identity cannot access
and what actions they cannot perform. Deny paths take precedence over allow
paths.
@@ -184,13 +114,80 @@ Teleport Access Graph can help you to answer questions like:
![Show Access Path](../../img/access-graph/show-access-path.gif)
## Navigation
## How Teleport resources are represented
![Navigation](../../img/access-graph/sidebar.png)
Teleport Access Graph imports all Teleport resources and keeps them up to date, so every time you make a change
The left hand side menu contains the main navigation options:
- Graph view
- Search
- SQL editor
- Integrations
## Graph View
Graph view is the main view that shows the connections between identities and resources.
By default, an aggregated view of access paths grouped by identity is showed.
## Search
To search for a graph node use the search bar at the top of the page or the search icon on the right hand side.
![Search](../../img/access-graph/search.png)
You can then search through all node types and all imported entities.
## SQL Editor
Access Graph allows creating SQL like queries to explore the graph.
![SQL Editor](../../img/access-graph/sql-editor.png)
The query language allows to create different views of the graph, ex:
Show only allowed paths
```sql
SELECT * FROM access_path WHERE kind = 'ALLOWED';
```
Show only denied paths
```sql
SELECT * FROM access_path WHERE kind = 'DENIED';
```
Show all access paths for a user
```sql
SELECT * FROM access_path WHERE identity = 'bob';
```
Show all access paths for a user AND resource
```sql
SELECT * FROM access_path WHERE identity = 'bob' AND resource = 'postgres';
```
More actionable examples is available under ? icon.
## Integrations
![Integrations](../../img/access-graph/integrations.png)
Integrations page shows integrations that can be enabled or are already enabled in Access Graph.
<Admonition title="Note" type="tip">
Resources imported into Teleport through Teleport enabled integrations are automatically imported into
Access graph without any additional configuration.
</Admonition>
## How resources and identities are represented
Access Graph imports all resources and identities from Teleport and keeps them up to date, so every time you make a change
to your Teleport resources, the Access Graph will reflect those changes.
### Users
### Identities
Users are created from Teleport Users.
Local users are imported as soon as they are created.
@@ -222,6 +219,7 @@ Actions take precedence over Allow Actions.
Temporary Actions are created when a user is granted temporary access to a
resource. They are automatically deleted when the user's access expires.
The temporary actions can be identified by having `Temporary: true` property.
#### Resource Groups
@@ -45,6 +45,7 @@ AWS account:
- User Groups
- IAM Roles
- IAM Policies
- EC2 Instances
- EKS Clusters
- RDS Databases
- S3 Buckets
@@ -22,10 +22,10 @@ to Teleport Enterprise customers.
- Kubernetes >= v1.21
- Helm >= (=helm.version=)
- A running Teleport Enterprise cluster v14.3.4 or later.
- A running Teleport Enterprise cluster v14.3.6 or later.
- For the purposes of this guide, we assume that the Teleport cluster is set up
[using the `teleport-cluster` Helm chart](../../deploy-a-cluster/helm-deployments.mdx)
in the same Kubernetes cluster that will be used to deploy Teleport Access Graph .
in the same Kubernetes cluster that will be used to deploy Teleport Access Graph.
- An updated `license.pem` with Teleport Policy enabled.
- A PostgreSQL database server v14 or later.
- Access Graph needs a dedicated [database](https://www.postgresql.org/docs/current/sql-createdatabase.html) to store its data.
@@ -34,7 +34,7 @@ to Teleport Enterprise customers.
- Amazon RDS for PostgreSQL is supported.
- A TLS certificate for the Access Graph service
- The TLS certificate must be issued for "server authentication" key usage,
and must contain a X.509 v3 `subjectAltName` extension with the Kubernetes service name for TAG
and must contain an X.509 v3 `subjectAltName` extension with the Kubernetes service name for TAG
(<span style="white-space: nowrap;">`teleport-access-graph.teleport-access-graph.svc.cluster.local`</span> by default).
@@ -18,7 +18,7 @@ to Teleport Enterprise customers.
## Prerequisites
- A running Teleport Enterprise cluster v14.3.4 or later.
- A running Teleport Enterprise cluster v14.3.6 or later.
- An updated `license.pem` with Teleport Policy enabled.
- Docker version v(=docker.version=) or later.
- A PostgreSQL database server v14 or later.