diff --git a/docs/config.json b/docs/config.json index 34ee77859b0..208a1485882 100644 --- a/docs/config.json +++ b/docs/config.json @@ -1893,7 +1893,7 @@ "nodeIP": "ip-172-31-35-170" }, "access_graph": { - "version": "1.13.0" + "version": "1.20.1" }, "ansible": { "min_version": "2.9.6" diff --git a/docs/img/access-graph/add-node-type.png b/docs/img/access-graph/add-node-type.png deleted file mode 100644 index ddcba0468ba..00000000000 Binary files a/docs/img/access-graph/add-node-type.png and /dev/null differ diff --git a/docs/img/access-graph/allow-action-node.png b/docs/img/access-graph/allow-action-node.png index 0254ed1e279..e60af86a58f 100644 Binary files a/docs/img/access-graph/allow-action-node.png and b/docs/img/access-graph/allow-action-node.png differ diff --git a/docs/img/access-graph/allow-path.png b/docs/img/access-graph/allow-path.png index c1aa88eed94..d894065a487 100644 Binary files a/docs/img/access-graph/allow-path.png and b/docs/img/access-graph/allow-path.png differ diff --git a/docs/img/access-graph/collapse-node.png b/docs/img/access-graph/collapse-node.png deleted file mode 100644 index 4e9806c03e3..00000000000 Binary files a/docs/img/access-graph/collapse-node.png and /dev/null differ diff --git a/docs/img/access-graph/deny-action-node.png b/docs/img/access-graph/deny-action-node.png index 1edc7c53b48..055b9c8d612 100644 Binary files a/docs/img/access-graph/deny-action-node.png and b/docs/img/access-graph/deny-action-node.png differ diff --git a/docs/img/access-graph/deny-path.png b/docs/img/access-graph/deny-path.png index 46635cbf425..210f86ee3c6 100644 Binary files a/docs/img/access-graph/deny-path.png and b/docs/img/access-graph/deny-path.png differ diff --git a/docs/img/access-graph/expand-node.png b/docs/img/access-graph/expand-node.png deleted file mode 100644 index f133c11d30f..00000000000 Binary files a/docs/img/access-graph/expand-node.png and /dev/null differ diff --git a/docs/img/access-graph/expand-one-level.png b/docs/img/access-graph/expand-one-level.png deleted file mode 100644 index 43e3b69fa5b..00000000000 Binary files a/docs/img/access-graph/expand-one-level.png and /dev/null differ diff --git a/docs/img/access-graph/expand-two-levels.png b/docs/img/access-graph/expand-two-levels.png deleted file mode 100644 index 92c2205dc5e..00000000000 Binary files a/docs/img/access-graph/expand-two-levels.png and /dev/null differ diff --git a/docs/img/access-graph/identity-group-node.png b/docs/img/access-graph/identity-group-node.png new file mode 100644 index 00000000000..468f15cc0e4 Binary files /dev/null and b/docs/img/access-graph/identity-group-node.png differ diff --git a/docs/img/access-graph/identity-node.png b/docs/img/access-graph/identity-node.png new file mode 100644 index 00000000000..4e57afefeed Binary files /dev/null and b/docs/img/access-graph/identity-node.png differ diff --git a/docs/img/access-graph/integrations.png b/docs/img/access-graph/integrations.png new file mode 100644 index 00000000000..0c1222e8178 Binary files /dev/null and b/docs/img/access-graph/integrations.png differ diff --git a/docs/img/access-graph/main-view.png b/docs/img/access-graph/main-view.png index d0994789d2a..e7377c0be1d 100644 Binary files a/docs/img/access-graph/main-view.png and b/docs/img/access-graph/main-view.png differ diff --git a/docs/img/access-graph/remove-node-type.png b/docs/img/access-graph/remove-node-type.png deleted file mode 100644 index 242510b8d59..00000000000 Binary files a/docs/img/access-graph/remove-node-type.png and /dev/null differ diff --git a/docs/img/access-graph/resource-group-node.png b/docs/img/access-graph/resource-group-node.png index 93fc01f7afe..e306ab83fc9 100644 Binary files a/docs/img/access-graph/resource-group-node.png and b/docs/img/access-graph/resource-group-node.png differ diff --git a/docs/img/access-graph/resource-node.png b/docs/img/access-graph/resource-node.png index cc569dd77d2..ceb2bf74acd 100644 Binary files a/docs/img/access-graph/resource-node.png and b/docs/img/access-graph/resource-node.png differ diff --git a/docs/img/access-graph/search-item-checkbox-click.png b/docs/img/access-graph/search-item-checkbox-click.png deleted file mode 100644 index 5428b79909a..00000000000 Binary files a/docs/img/access-graph/search-item-checkbox-click.png and /dev/null differ diff --git a/docs/img/access-graph/search-item-click.png b/docs/img/access-graph/search-item-click.png deleted file mode 100644 index be5ade930ab..00000000000 Binary files a/docs/img/access-graph/search-item-click.png and /dev/null differ diff --git a/docs/img/access-graph/search.png b/docs/img/access-graph/search.png index 5f639889bc6..be454845a04 100644 Binary files a/docs/img/access-graph/search.png and b/docs/img/access-graph/search.png differ diff --git a/docs/img/access-graph/show-access-path-resource.gif b/docs/img/access-graph/show-access-path-resource.gif index 9404a66cb62..e77994988ec 100644 Binary files a/docs/img/access-graph/show-access-path-resource.gif and b/docs/img/access-graph/show-access-path-resource.gif differ diff --git a/docs/img/access-graph/show-access-path.gif b/docs/img/access-graph/show-access-path.gif index 4d21a404954..a98ca9a6c27 100644 Binary files a/docs/img/access-graph/show-access-path.gif and b/docs/img/access-graph/show-access-path.gif differ diff --git a/docs/img/access-graph/sidebar.png b/docs/img/access-graph/sidebar.png index 8af489e10a2..45270be5b56 100644 Binary files a/docs/img/access-graph/sidebar.png and b/docs/img/access-graph/sidebar.png differ diff --git a/docs/img/access-graph/sql-editor.png b/docs/img/access-graph/sql-editor.png new file mode 100644 index 00000000000..cadedcebf08 Binary files /dev/null and b/docs/img/access-graph/sql-editor.png differ diff --git a/docs/img/access-graph/temporary-action-node.png b/docs/img/access-graph/temporary-action-node.png deleted file mode 100644 index e53ac5bed25..00000000000 Binary files a/docs/img/access-graph/temporary-action-node.png and /dev/null differ diff --git a/docs/img/access-graph/temporary-resource-group-node.png b/docs/img/access-graph/temporary-resource-group-node.png deleted file mode 100644 index 73e46c7c78a..00000000000 Binary files a/docs/img/access-graph/temporary-resource-group-node.png and /dev/null differ diff --git a/docs/img/access-graph/temporary-user-group-node.png b/docs/img/access-graph/temporary-user-group-node.png deleted file mode 100644 index 3e9fcb2f06e..00000000000 Binary files a/docs/img/access-graph/temporary-user-group-node.png and /dev/null differ diff --git a/docs/img/access-graph/user-group-node.png b/docs/img/access-graph/user-group-node.png deleted file mode 100644 index 50d80f4d454..00000000000 Binary files a/docs/img/access-graph/user-group-node.png and /dev/null differ diff --git a/docs/img/access-graph/user-node.png b/docs/img/access-graph/user-node.png deleted file mode 100644 index 0686c861fa8..00000000000 Binary files a/docs/img/access-graph/user-node.png and /dev/null differ diff --git a/docs/pages/access-controls/access-graph.mdx b/docs/pages/access-controls/access-graph.mdx index c00bd63b237..f5e17e94a22 100644 --- a/docs/pages/access-controls/access-graph.mdx +++ b/docs/pages/access-controls/access-graph.mdx @@ -23,126 +23,56 @@ under the Permission Management section. ## Graph nodes -Teleport Access Graph divides your infrastructure into eight main components: +Teleport Access Graph divides your infrastructure into six main components: -1. Users +1. Identities -![User Node](../../img/access-graph/user-node.png) +![Identity Node](../../img/access-graph/identity-node.png) -Users are the people who access your infrastructure. They can be employees, -contractors, or bots. +Identities are the actors that can access your infrastructure. They can be employees, +contractors, machines or bots. + +The number on the right hand side shows "standing privileges". +Standing privileges is the number of resources that an identity can access without +creating an access request. 2. User Groups -![User Group Node](../../img/access-graph/user-group-node.png) +![Identity Group Node](../../img/access-graph/identity-group-node.png) -User Groups are collections of users. They can be used to organize users -based on their role or team. +Identity Groups are collections of identities. They can be used to organize users +based on their role or team, and they can be nested. -3. Temporary user groups - -![Temporary User Group Node](../../img/access-graph/temporary-user-group-node.png) - -Temporary User Groups are created when a user is granted temporary access to a -resource. They are automatically deleted when the user's access expires. - -4. Actions +3. Actions ![Action Node](../../img/access-graph/allow-action-node.png) -Actions are the things that users can or cannot do. Actions are related to +Actions are the things that identities can or cannot do. Actions are related to resources. For example, a user can SSH into a node. -5. Deny Actions +4. Deny Actions ![Deny Action Node](../../img/access-graph/deny-action-node.png) -Deny Actions are the things that users cannot do. Deny Actions are related to +Deny Actions are the things that identities cannot do. Deny Actions are related to resources. For example, a user cannot SSH into a node. -6. Temporary Actions - -![Temporary Action Node](../../img/access-graph/temporary-action-node.png) - -Temporary Actions are created when a user is granted temporary access to a -resource. They are automatically deleted when the user's access expires. - -7. Resource Groups +5. Resource Groups ![Resource Group Node](../../img/access-graph/resource-group-node.png) Resource Groups are collections of resources. They can be used to organize resources based on their role or team. -8. Resources +The number on the right hand side shows the number of resources that a resource group contains. + +6. Resources ![Resource Node](../../img/access-graph/resource-node.png) Resources are the things that users can or cannot access. They can be servers, databases, or Kubernetes clusters. -## Searching - -To search for a graph node, either click the search button in the sidebar on the left, -or press the `s` key. - -![Search](../../img/access-graph/search.png) - -You can then search through all node types. If you select a result using your keyboard -arrow keys, you can press either `Tab` to add the node to the graph, or `Enter` to replace -the graph with just the individual node. - -## Changing what is visible - -By default, Teleport Access Graph shows all types of nodes and paths. You can see what -node types are visible by looking at the sidebar on the left. - -![Sidebar](../../img/access-graph/sidebar.png) - -### Showing/removing individual graph nodes - -To show or remove an individual graph node, open up the node type in the sidebar and -click on the node you want to show or remove. - -![Show/Remove Node](../../img/access-graph/search-item-click.png) - -Clicking on the node name will toggle the visibility of that node. - -![Select only one node](../../img/access-graph/search-item-checkbox-click.png) - -Clicking on the checkbox will select only that node. - -### Adding/removing graph node types - -To add a graph node type that isn't in the view, select it from the list of available -node types. - -![Add node type](../../img/access-graph/add-node-type.png) - -To remove the graph node type, expand the node type in the sidebar and click on the -remove button. - -![Remove node type](../../img/access-graph/remove-node-type.png) - -### Expanding/collapsing graph nodes - -If a graph node has connections to other nodes, it can be expanded to show those -connections. To expand a node, hover over the edge of the node. If there are -connections in that direction, the edge will turn blue. Clicking on the edge -will expand the node. - -![Expand node](../../img/access-graph/expand-node.png) - -You can keep expanding graph nodes until you reach the end of the path. - -![Expand one level](../../img/access-graph/expand-one-level.png) - -![Expand two levels](../../img/access-graph/expand-two-levels.png) - -To collapse a graph node, click on the edge that was used to expand it. - -![Collapse node](../../img/access-graph/collapse-node.png) - ## Graph paths Teleport Access Graph shows the relationships between users, roles, and @@ -161,14 +91,14 @@ Paths can be divided into two categories: ![Allow Path](../../img/access-graph/allow-path.png) -Allow paths connect users to resources. They show what a user can access +Allow paths connect identities to resources. They show what an identity can access and what actions they can perform. 2. Deny paths ![Deny Path](../../img/access-graph/deny-path.png) -Deny paths connect users to resources. They show what a user cannot access +Deny paths connect identities to resources. They show what a identity cannot access and what actions they cannot perform. Deny paths take precedence over allow paths. @@ -184,13 +114,80 @@ Teleport Access Graph can help you to answer questions like: ![Show Access Path](../../img/access-graph/show-access-path.gif) +## Navigation -## How Teleport resources are represented +![Navigation](../../img/access-graph/sidebar.png) -Teleport Access Graph imports all Teleport resources and keeps them up to date, so every time you make a change +The left hand side menu contains the main navigation options: + +- Graph view +- Search +- SQL editor +- Integrations + +## Graph View + +Graph view is the main view that shows the connections between identities and resources. +By default, an aggregated view of access paths grouped by identity is showed. + +## Search + +To search for a graph node use the search bar at the top of the page or the search icon on the right hand side. + +![Search](../../img/access-graph/search.png) + +You can then search through all node types and all imported entities. + +## SQL Editor + +Access Graph allows creating SQL like queries to explore the graph. + +![SQL Editor](../../img/access-graph/sql-editor.png) + +The query language allows to create different views of the graph, ex: + +Show only allowed paths + +```sql +SELECT * FROM access_path WHERE kind = 'ALLOWED'; +``` + +Show only denied paths +```sql +SELECT * FROM access_path WHERE kind = 'DENIED'; +``` + +Show all access paths for a user + +```sql +SELECT * FROM access_path WHERE identity = 'bob'; +``` + +Show all access paths for a user AND resource + +```sql +SELECT * FROM access_path WHERE identity = 'bob' AND resource = 'postgres'; +``` + +More actionable examples is available under ? icon. + +## Integrations + +![Integrations](../../img/access-graph/integrations.png) + +Integrations page shows integrations that can be enabled or are already enabled in Access Graph. + + + Resources imported into Teleport through Teleport enabled integrations are automatically imported into + Access graph without any additional configuration. + + +## How resources and identities are represented + +Access Graph imports all resources and identities from Teleport and keeps them up to date, so every time you make a change to your Teleport resources, the Access Graph will reflect those changes. -### Users +### Identities Users are created from Teleport Users. Local users are imported as soon as they are created. @@ -222,6 +219,7 @@ Actions take precedence over Allow Actions. Temporary Actions are created when a user is granted temporary access to a resource. They are automatically deleted when the user's access expires. +The temporary actions can be identified by having `Temporary: true` property. #### Resource Groups diff --git a/docs/pages/access-controls/access-graph/aws-sync.mdx b/docs/pages/access-controls/access-graph/aws-sync.mdx index 60d7a61179d..2d303aa17b1 100644 --- a/docs/pages/access-controls/access-graph/aws-sync.mdx +++ b/docs/pages/access-controls/access-graph/aws-sync.mdx @@ -45,6 +45,7 @@ AWS account: - User Groups - IAM Roles - IAM Policies +- EC2 Instances - EKS Clusters - RDS Databases - S3 Buckets diff --git a/docs/pages/access-controls/access-graph/self-hosted-helm.mdx b/docs/pages/access-controls/access-graph/self-hosted-helm.mdx index 944fbefaccc..2d3654008bf 100644 --- a/docs/pages/access-controls/access-graph/self-hosted-helm.mdx +++ b/docs/pages/access-controls/access-graph/self-hosted-helm.mdx @@ -22,10 +22,10 @@ to Teleport Enterprise customers. - Kubernetes >= v1.21 - Helm >= (=helm.version=) -- A running Teleport Enterprise cluster v14.3.4 or later. +- A running Teleport Enterprise cluster v14.3.6 or later. - For the purposes of this guide, we assume that the Teleport cluster is set up [using the `teleport-cluster` Helm chart](../../deploy-a-cluster/helm-deployments.mdx) - in the same Kubernetes cluster that will be used to deploy Teleport Access Graph . + in the same Kubernetes cluster that will be used to deploy Teleport Access Graph. - An updated `license.pem` with Teleport Policy enabled. - A PostgreSQL database server v14 or later. - Access Graph needs a dedicated [database](https://www.postgresql.org/docs/current/sql-createdatabase.html) to store its data. @@ -34,7 +34,7 @@ to Teleport Enterprise customers. - Amazon RDS for PostgreSQL is supported. - A TLS certificate for the Access Graph service - The TLS certificate must be issued for "server authentication" key usage, - and must contain a X.509 v3 `subjectAltName` extension with the Kubernetes service name for TAG + and must contain an X.509 v3 `subjectAltName` extension with the Kubernetes service name for TAG (`teleport-access-graph.teleport-access-graph.svc.cluster.local` by default). diff --git a/docs/pages/access-controls/access-graph/self-hosted.mdx b/docs/pages/access-controls/access-graph/self-hosted.mdx index c076ee0b1f9..d950401d50b 100644 --- a/docs/pages/access-controls/access-graph/self-hosted.mdx +++ b/docs/pages/access-controls/access-graph/self-hosted.mdx @@ -18,7 +18,7 @@ to Teleport Enterprise customers. ## Prerequisites -- A running Teleport Enterprise cluster v14.3.4 or later. +- A running Teleport Enterprise cluster v14.3.6 or later. - An updated `license.pem` with Teleport Policy enabled. - Docker version v(=docker.version=) or later. - A PostgreSQL database server v14 or later.