Update Access Graph Docs (#41307)
* Update TAG docs * Update images * Update docs * Update images Add EC2 instances to supported AWS types * Linter fixes * Update docs/pages/access-controls/access-graph.mdx Co-authored-by: Roman Tkachenko <roman@goteleport.com> * Update TAG version --------- Co-authored-by: Roman Tkachenko <roman@goteleport.com>
@@ -1893,7 +1893,7 @@
|
||||
"nodeIP": "ip-172-31-35-170"
|
||||
},
|
||||
"access_graph": {
|
||||
"version": "1.13.0"
|
||||
"version": "1.20.1"
|
||||
},
|
||||
"ansible": {
|
||||
"min_version": "2.9.6"
|
||||
|
||||
|
Before Width: | Height: | Size: 18 KiB |
|
Before Width: | Height: | Size: 11 KiB After Width: | Height: | Size: 14 KiB |
|
Before Width: | Height: | Size: 54 KiB After Width: | Height: | Size: 76 KiB |
|
Before Width: | Height: | Size: 28 KiB |
|
Before Width: | Height: | Size: 11 KiB After Width: | Height: | Size: 8.4 KiB |
|
Before Width: | Height: | Size: 52 KiB After Width: | Height: | Size: 73 KiB |
|
Before Width: | Height: | Size: 24 KiB |
|
Before Width: | Height: | Size: 81 KiB |
|
Before Width: | Height: | Size: 114 KiB |
|
After Width: | Height: | Size: 14 KiB |
|
After Width: | Height: | Size: 13 KiB |
|
After Width: | Height: | Size: 73 KiB |
|
Before Width: | Height: | Size: 373 KiB After Width: | Height: | Size: 622 KiB |
|
Before Width: | Height: | Size: 28 KiB |
|
Before Width: | Height: | Size: 14 KiB After Width: | Height: | Size: 18 KiB |
|
Before Width: | Height: | Size: 7.2 KiB After Width: | Height: | Size: 17 KiB |
|
Before Width: | Height: | Size: 10 KiB |
|
Before Width: | Height: | Size: 11 KiB |
|
Before Width: | Height: | Size: 75 KiB After Width: | Height: | Size: 61 KiB |
|
Before Width: | Height: | Size: 3.6 MiB After Width: | Height: | Size: 743 KiB |
|
Before Width: | Height: | Size: 3.0 MiB After Width: | Height: | Size: 507 KiB |
|
Before Width: | Height: | Size: 41 KiB After Width: | Height: | Size: 7.7 KiB |
|
After Width: | Height: | Size: 70 KiB |
|
Before Width: | Height: | Size: 11 KiB |
|
Before Width: | Height: | Size: 9.8 KiB |
|
Before Width: | Height: | Size: 10 KiB |
|
Before Width: | Height: | Size: 6.6 KiB |
|
Before Width: | Height: | Size: 8.1 KiB |
@@ -23,126 +23,56 @@ under the Permission Management section.
|
||||
|
||||
## Graph nodes
|
||||
|
||||
Teleport Access Graph divides your infrastructure into eight main components:
|
||||
Teleport Access Graph divides your infrastructure into six main components:
|
||||
|
||||
1. Users
|
||||
1. Identities
|
||||
|
||||

|
||||

|
||||
|
||||
Users are the people who access your infrastructure. They can be employees,
|
||||
contractors, or bots.
|
||||
Identities are the actors that can access your infrastructure. They can be employees,
|
||||
contractors, machines or bots.
|
||||
|
||||
The number on the right hand side shows "standing privileges".
|
||||
Standing privileges is the number of resources that an identity can access without
|
||||
creating an access request.
|
||||
|
||||
2. User Groups
|
||||
|
||||

|
||||

|
||||
|
||||
User Groups are collections of users. They can be used to organize users
|
||||
based on their role or team.
|
||||
Identity Groups are collections of identities. They can be used to organize users
|
||||
based on their role or team, and they can be nested.
|
||||
|
||||
3. Temporary user groups
|
||||
|
||||

|
||||
|
||||
Temporary User Groups are created when a user is granted temporary access to a
|
||||
resource. They are automatically deleted when the user's access expires.
|
||||
|
||||
4. Actions
|
||||
3. Actions
|
||||
|
||||

|
||||
|
||||
Actions are the things that users can or cannot do. Actions are related to
|
||||
Actions are the things that identities can or cannot do. Actions are related to
|
||||
resources. For example, a user can SSH into a node.
|
||||
|
||||
5. Deny Actions
|
||||
4. Deny Actions
|
||||
|
||||

|
||||
|
||||
Deny Actions are the things that users cannot do. Deny Actions are related to
|
||||
Deny Actions are the things that identities cannot do. Deny Actions are related to
|
||||
resources. For example, a user cannot SSH into a node.
|
||||
|
||||
6. Temporary Actions
|
||||
|
||||

|
||||
|
||||
Temporary Actions are created when a user is granted temporary access to a
|
||||
resource. They are automatically deleted when the user's access expires.
|
||||
|
||||
7. Resource Groups
|
||||
5. Resource Groups
|
||||
|
||||

|
||||
|
||||
Resource Groups are collections of resources. They can be used to organize
|
||||
resources based on their role or team.
|
||||
|
||||
8. Resources
|
||||
The number on the right hand side shows the number of resources that a resource group contains.
|
||||
|
||||
6. Resources
|
||||
|
||||

|
||||
|
||||
Resources are the things that users can or cannot access. They can be
|
||||
servers, databases, or Kubernetes clusters.
|
||||
|
||||
## Searching
|
||||
|
||||
To search for a graph node, either click the search button in the sidebar on the left,
|
||||
or press the `s` key.
|
||||
|
||||

|
||||
|
||||
You can then search through all node types. If you select a result using your keyboard
|
||||
arrow keys, you can press either `Tab` to add the node to the graph, or `Enter` to replace
|
||||
the graph with just the individual node.
|
||||
|
||||
## Changing what is visible
|
||||
|
||||
By default, Teleport Access Graph shows all types of nodes and paths. You can see what
|
||||
node types are visible by looking at the sidebar on the left.
|
||||
|
||||

|
||||
|
||||
### Showing/removing individual graph nodes
|
||||
|
||||
To show or remove an individual graph node, open up the node type in the sidebar and
|
||||
click on the node you want to show or remove.
|
||||
|
||||

|
||||
|
||||
Clicking on the node name will toggle the visibility of that node.
|
||||
|
||||

|
||||
|
||||
Clicking on the checkbox will select only that node.
|
||||
|
||||
### Adding/removing graph node types
|
||||
|
||||
To add a graph node type that isn't in the view, select it from the list of available
|
||||
node types.
|
||||
|
||||

|
||||
|
||||
To remove the graph node type, expand the node type in the sidebar and click on the
|
||||
remove button.
|
||||
|
||||

|
||||
|
||||
### Expanding/collapsing graph nodes
|
||||
|
||||
If a graph node has connections to other nodes, it can be expanded to show those
|
||||
connections. To expand a node, hover over the edge of the node. If there are
|
||||
connections in that direction, the edge will turn blue. Clicking on the edge
|
||||
will expand the node.
|
||||
|
||||

|
||||
|
||||
You can keep expanding graph nodes until you reach the end of the path.
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
To collapse a graph node, click on the edge that was used to expand it.
|
||||
|
||||

|
||||
|
||||
## Graph paths
|
||||
|
||||
Teleport Access Graph shows the relationships between users, roles, and
|
||||
@@ -161,14 +91,14 @@ Paths can be divided into two categories:
|
||||
|
||||

|
||||
|
||||
Allow paths connect users to resources. They show what a user can access
|
||||
Allow paths connect identities to resources. They show what an identity can access
|
||||
and what actions they can perform.
|
||||
|
||||
2. Deny paths
|
||||
|
||||

|
||||
|
||||
Deny paths connect users to resources. They show what a user cannot access
|
||||
Deny paths connect identities to resources. They show what a identity cannot access
|
||||
and what actions they cannot perform. Deny paths take precedence over allow
|
||||
paths.
|
||||
|
||||
@@ -184,13 +114,80 @@ Teleport Access Graph can help you to answer questions like:
|
||||
|
||||

|
||||
|
||||
## Navigation
|
||||
|
||||
## How Teleport resources are represented
|
||||

|
||||
|
||||
Teleport Access Graph imports all Teleport resources and keeps them up to date, so every time you make a change
|
||||
The left hand side menu contains the main navigation options:
|
||||
|
||||
- Graph view
|
||||
- Search
|
||||
- SQL editor
|
||||
- Integrations
|
||||
|
||||
## Graph View
|
||||
|
||||
Graph view is the main view that shows the connections between identities and resources.
|
||||
By default, an aggregated view of access paths grouped by identity is showed.
|
||||
|
||||
## Search
|
||||
|
||||
To search for a graph node use the search bar at the top of the page or the search icon on the right hand side.
|
||||
|
||||

|
||||
|
||||
You can then search through all node types and all imported entities.
|
||||
|
||||
## SQL Editor
|
||||
|
||||
Access Graph allows creating SQL like queries to explore the graph.
|
||||
|
||||

|
||||
|
||||
The query language allows to create different views of the graph, ex:
|
||||
|
||||
Show only allowed paths
|
||||
|
||||
```sql
|
||||
SELECT * FROM access_path WHERE kind = 'ALLOWED';
|
||||
```
|
||||
|
||||
Show only denied paths
|
||||
```sql
|
||||
SELECT * FROM access_path WHERE kind = 'DENIED';
|
||||
```
|
||||
|
||||
Show all access paths for a user
|
||||
|
||||
```sql
|
||||
SELECT * FROM access_path WHERE identity = 'bob';
|
||||
```
|
||||
|
||||
Show all access paths for a user AND resource
|
||||
|
||||
```sql
|
||||
SELECT * FROM access_path WHERE identity = 'bob' AND resource = 'postgres';
|
||||
```
|
||||
|
||||
More actionable examples is available under ? icon.
|
||||
|
||||
## Integrations
|
||||
|
||||

|
||||
|
||||
Integrations page shows integrations that can be enabled or are already enabled in Access Graph.
|
||||
|
||||
<Admonition title="Note" type="tip">
|
||||
Resources imported into Teleport through Teleport enabled integrations are automatically imported into
|
||||
Access graph without any additional configuration.
|
||||
</Admonition>
|
||||
|
||||
## How resources and identities are represented
|
||||
|
||||
Access Graph imports all resources and identities from Teleport and keeps them up to date, so every time you make a change
|
||||
to your Teleport resources, the Access Graph will reflect those changes.
|
||||
|
||||
### Users
|
||||
### Identities
|
||||
|
||||
Users are created from Teleport Users.
|
||||
Local users are imported as soon as they are created.
|
||||
@@ -222,6 +219,7 @@ Actions take precedence over Allow Actions.
|
||||
|
||||
Temporary Actions are created when a user is granted temporary access to a
|
||||
resource. They are automatically deleted when the user's access expires.
|
||||
The temporary actions can be identified by having `Temporary: true` property.
|
||||
|
||||
#### Resource Groups
|
||||
|
||||
|
||||
@@ -45,6 +45,7 @@ AWS account:
|
||||
- User Groups
|
||||
- IAM Roles
|
||||
- IAM Policies
|
||||
- EC2 Instances
|
||||
- EKS Clusters
|
||||
- RDS Databases
|
||||
- S3 Buckets
|
||||
|
||||
@@ -22,10 +22,10 @@ to Teleport Enterprise customers.
|
||||
|
||||
- Kubernetes >= v1.21
|
||||
- Helm >= (=helm.version=)
|
||||
- A running Teleport Enterprise cluster v14.3.4 or later.
|
||||
- A running Teleport Enterprise cluster v14.3.6 or later.
|
||||
- For the purposes of this guide, we assume that the Teleport cluster is set up
|
||||
[using the `teleport-cluster` Helm chart](../../deploy-a-cluster/helm-deployments.mdx)
|
||||
in the same Kubernetes cluster that will be used to deploy Teleport Access Graph .
|
||||
in the same Kubernetes cluster that will be used to deploy Teleport Access Graph.
|
||||
- An updated `license.pem` with Teleport Policy enabled.
|
||||
- A PostgreSQL database server v14 or later.
|
||||
- Access Graph needs a dedicated [database](https://www.postgresql.org/docs/current/sql-createdatabase.html) to store its data.
|
||||
@@ -34,7 +34,7 @@ to Teleport Enterprise customers.
|
||||
- Amazon RDS for PostgreSQL is supported.
|
||||
- A TLS certificate for the Access Graph service
|
||||
- The TLS certificate must be issued for "server authentication" key usage,
|
||||
and must contain a X.509 v3 `subjectAltName` extension with the Kubernetes service name for TAG
|
||||
and must contain an X.509 v3 `subjectAltName` extension with the Kubernetes service name for TAG
|
||||
(<span style="white-space: nowrap;">`teleport-access-graph.teleport-access-graph.svc.cluster.local`</span> by default).
|
||||
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@ to Teleport Enterprise customers.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- A running Teleport Enterprise cluster v14.3.4 or later.
|
||||
- A running Teleport Enterprise cluster v14.3.6 or later.
|
||||
- An updated `license.pem` with Teleport Policy enabled.
|
||||
- Docker version v(=docker.version=) or later.
|
||||
- A PostgreSQL database server v14 or later.
|
||||
|
||||