mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Fix linter issues (#21677)
An issue with `gravitational/docs` caused the docs linter to stop catching issues for a period of time. Now that we have addressed the linter issue, this change addresses warnings/errors flagged by the linter. Co-authored-by: Alex Fornuto <alex.fornuto@goteleport.com>
This commit is contained in:
co-authored by
Alex Fornuto
parent
36831dda6c
commit
a93aaa7e6e
+2
-2
@@ -714,7 +714,7 @@ to log into their AWS console using `tsh apps login` and use `tsh aws` commands
|
||||
to interact with AWS APIs.
|
||||
|
||||
See more info in the
|
||||
[documentation](docs/pages/application-access/guides/aws-console.mdx).
|
||||
[documentation](docs/pages/application-access/cloud-apis/aws-console.mdx).
|
||||
|
||||
#### Application and Database Dynamic Registration
|
||||
|
||||
@@ -849,7 +849,7 @@ View the Cloud SQL MySQL [guide](docs/pages/database-access/guides/mysql-cloudsq
|
||||
|
||||
Added support for [AWS Console](https://aws.amazon.com/console) to Teleport Application Access. [#7590](https://github.com/gravitational/teleport/pull/7590)
|
||||
|
||||
Teleport Application Access can now automatically sign users into the AWS Management Console using [Identity federation](https://aws.amazon.com/identity/federation). View AWS Management Console [guide](docs/pages/application-access/guides/aws-console.mdx) for more details.
|
||||
Teleport Application Access can now automatically sign users into the AWS Management Console using [Identity federation](https://aws.amazon.com/identity/federation). View AWS Management Console [guide](docs/pages/application-access/cloud-apis/aws-console.mdx) for more details.
|
||||
|
||||
#### Restricted Sessions
|
||||
|
||||
|
||||
@@ -20,7 +20,7 @@ This guide will explain how to:
|
||||
- A running Teleport cluster, either self hosted or in Teleport Cloud.
|
||||
- A host running the `teleport` daemon with Application Access enabled. Follow
|
||||
the [Getting Started](../getting-started.mdx) or
|
||||
[Connecting Apps](./connecting-apps.mdx) guides to get it running.
|
||||
[Connecting Apps](../guides/connecting-apps.mdx) guides to get it running.
|
||||
- IAM permissions in the AWS account you want to connect.
|
||||
- AWS EC2 or other instance where you can assign a IAM Security Role for the Teleport Agent.
|
||||
- `aws` command line interface (CLI) tool in PATH. [Installing or updating the latest version of the AWS CLI
|
||||
|
||||
@@ -119,7 +119,8 @@ permissions to impersonate target service accounts.
|
||||
|
||||
If you are enabling access to an existing service account, you can skip to the
|
||||
[next
|
||||
section](#enable-the-application-service-to-impersonate-your-service-account).
|
||||
section](#enable-teleport-google-cloud-cli-to-impersonate-target-service-accounts
|
||||
).
|
||||
|
||||
</Notice>
|
||||
|
||||
@@ -680,7 +681,6 @@ command.
|
||||
our documentation on [Role Access
|
||||
Requests](../../access-controls/access-requests/role-requests.mdx) and [Access
|
||||
Request plugins](../../access-controls/access-request-plugins/index.mdx).
|
||||
|
||||
- You can proxy any `gcloud` or `gsutil` command via Teleport. For a full
|
||||
reference of commands, view the Google Cloud documentation for
|
||||
[`gcloud`](https://cloud.google.com/sdk/gcloud/reference) and
|
||||
|
||||
@@ -126,7 +126,7 @@ This command uses the `--set-azure-identities` flag to add Azure identities to a
|
||||
user. The value of this flag is a comma-separated list of Azure identity URIs.
|
||||
|
||||
See our [Azure
|
||||
CLI](./guides/azure.mdx#step-34-enable-your-user-to-access-azure-clis) guide
|
||||
CLI](./cloud-apis/azure.mdx#step-34-enable-your-user-to-access-azure-clis) guide
|
||||
for more information on enabling access to Azure managed identities.
|
||||
|
||||
## Next steps
|
||||
|
||||
@@ -327,5 +327,5 @@ $ tsh apps logout aws-dynamodb
|
||||
```
|
||||
|
||||
## Next steps
|
||||
- More information on [AWS Management and API with Teleport Application Access](../../application-access/guides/aws-console.mdx).
|
||||
- More information on [AWS Management and API with Teleport Application Access](../../application-access/cloud-apis/aws-console.mdx).
|
||||
- Learn more about [AWS service endpoints](https://docs.aws.amazon.com/general/latest/gr/rande.html).
|
||||
|
||||
@@ -207,5 +207,5 @@ To run this command, one of the user's roles must include the
|
||||
`spec.allow.azure_identities` field with one of the identities used by the
|
||||
Application Service. To learn how to set up secure access to Azure via Teleport,
|
||||
read [Protect the Azure CLI with Teleport Application
|
||||
Access](guides/azure.mdx).
|
||||
Access](cloud-apis/azure.mdx).
|
||||
|
||||
|
||||
@@ -182,12 +182,12 @@ $ tsh ssh root@<Var name="node-name" />
|
||||
- Now that you have registered your first server with Teleport, read about how
|
||||
you can register resources in your infrastructure, including:
|
||||
|
||||
- [Additional SSH servers](../../server-access/introduction.mdx)
|
||||
- [Cloud provider tools and internal web applications](../../application-access/introduction.mdx)
|
||||
- [Databases](../../database-access/introduction.mdx)
|
||||
- [Kubernetes clusters](../../kubernetes-access/introduction.mdx)
|
||||
- [Service accounts](../../machine-id/introduction.mdx)
|
||||
- [Windows desktops](../../desktop-access.mdx)
|
||||
- [Additional SSH servers](../../server-access/introduction.mdx)
|
||||
- [Cloud provider tools and internal web applications](../../application-access/introduction.mdx)
|
||||
- [Databases](../../database-access/introduction.mdx)
|
||||
- [Kubernetes clusters](../../kubernetes-access/introduction.mdx)
|
||||
- [Service accounts](../../machine-id/introduction.mdx)
|
||||
- [Windows desktops](../../desktop-access/introduction.mdx)
|
||||
|
||||
- Aside from `tsh` and the Web UI, you can also connect to Teleport with our
|
||||
desktop application, [Teleport
|
||||
|
||||
@@ -146,7 +146,7 @@ $ teleport db start \
|
||||
title="AWS Credentials"
|
||||
>
|
||||
The node that connects to the database should have AWS credentials configured
|
||||
with the policy from [step 1](#step-13-set-up-aurora).
|
||||
with the policy from [step 1](#step-14-set-up-aurora).
|
||||
</Admonition>
|
||||
|
||||
## Step 3/4. Create a user and role
|
||||
|
||||
@@ -49,6 +49,7 @@ Create the Database Service configuration.
|
||||
<TabItem label="PostgreSQL">
|
||||
|
||||
- Specify the region for your database(s) in `--azure-postgres-discovery`.
|
||||
|
||||
- Replace the `--proxy` value with your Teleport proxy address or Teleport cloud
|
||||
URI (e.g. `mytenant.teleport.sh:443`):
|
||||
|
||||
|
||||
@@ -295,7 +295,7 @@ to add it.
|
||||
When connecting to your database, and you see the error `mssql: login error: Login
|
||||
failed for user '<token-identified principal>'`, it means your managed identity
|
||||
login is not present on the SQL database. You’ll need to create their users as
|
||||
described in [Step 6](#step-69-enable-managed-identities-login-on-sql-server).
|
||||
described in [Step 6](#step-58-enable-managed-identities-login-on-sql-server).
|
||||
Remember: you must create the users on all databases you want to connect.
|
||||
|
||||
### Timeout connecting to the database
|
||||
|
||||
@@ -146,7 +146,7 @@ See the full [YAML reference](../reference/configuration.mdx) for details.
|
||||
|
||||
See below for details on how to configure the Teleport Database Service.
|
||||
|
||||
#### Connection endpoint
|
||||
### Connection endpoint
|
||||
|
||||
You will need to provide your Atlas cluster's connection endpoint for the `db_service.databases[*].uri` configuration option or `--uri` CLI flag. You can find this via the Connect dialog on the Database Deployments overview page:
|
||||
|
||||
@@ -163,7 +163,7 @@ Use only the scheme and hostname parts of the connection string in the URI:
|
||||
$ --uri=mongodb+srv://cluster0.abcde.mongodb.net
|
||||
```
|
||||
|
||||
#### Atlas CA certificate
|
||||
### Atlas CA certificate
|
||||
|
||||
MongoDB Atlas uses certificates signed by Let's Encrypt.
|
||||
|
||||
|
||||
@@ -260,7 +260,7 @@ guide](../../reference/helm-reference/teleport-cluster.mdx).
|
||||
Read our guides to additional ways you can protect a Kubernetes cluster with
|
||||
Teleport:
|
||||
|
||||
- [Connect Multiple Kubernetes Clusters](../../kubernetes-access/guides/multiple-clusters.mdx)
|
||||
- [Connect Multiple Kubernetes Clusters](../../kubernetes-access/register-clusters/register-via-deployment.mdx)
|
||||
- [Set up Machine ID with Kubernetes](../../machine-id/guides/kubernetes.mdx)
|
||||
- [Federated Access using Trusted Clusters](../../kubernetes-access/guides/federation.mdx)
|
||||
- [Federated Access using Trusted Clusters](../../kubernetes-access/manage-access/federation.mdx)
|
||||
- [Single-Sign On and Kubernetes Access Control](../../kubernetes-access/controls.mdx)
|
||||
|
||||
@@ -406,7 +406,7 @@ guide](../../reference/helm-reference/teleport-cluster.mdx).
|
||||
Read our guides to additional ways you can protect Kubernetes clusters with
|
||||
Teleport:
|
||||
|
||||
- [Connect Multiple Kubernetes Clusters](../../kubernetes-access/guides/multiple-clusters.mdx)
|
||||
- [Connect Multiple Kubernetes Clusters](../../kubernetes-access/register-clusters/register-via-deployment.mdx)
|
||||
- [Set up Machine ID with Kubernetes](../../machine-id/guides/kubernetes.mdx)
|
||||
- [Federated Access using Trusted Clusters](../../kubernetes-access/guides/federation.mdx)
|
||||
- [Federated Access using Trusted Clusters](../../kubernetes-access/manage-access/federation.mdx)
|
||||
- [Single-Sign On and Kubernetes Access Control](../../kubernetes-access/controls.mdx)
|
||||
|
||||
@@ -20,6 +20,7 @@ Their removal has two main consequences:
|
||||
To prepare for the 1.25 upgrade:
|
||||
|
||||
- Make sure you are running at least Kubernetes 1.23 (run `kubectl version`)
|
||||
|
||||
- Label the namespace you are deploying the chart in with the PSA enforcement level:
|
||||
|
||||
```code
|
||||
|
||||
@@ -32,9 +32,8 @@ access to Windows desktops.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
<ScopedBlock scope={["oss", "enterprise"]}>
|
||||
- One or more hosts to run the Teleport Auth and Proxy services on.
|
||||
</ScopedBlock>
|
||||
(!docs/pages/includes/edition-prereqs-tabs.mdx!)
|
||||
|
||||
- A server or virtual machine running a Windows Server operating system.
|
||||
In this guide, we'll install Active Directory on this server in order
|
||||
to support passwordless logins with Teleport to the Windows desktops
|
||||
@@ -48,13 +47,7 @@ access to Windows desktops.
|
||||
encrypted LDAP connection). Typically this means installing
|
||||
[AD CS](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/).
|
||||
|
||||
## Step 1/2. Install Teleport
|
||||
|
||||
### Set up the Teleport Auth and Proxy Services
|
||||
|
||||
(!docs/pages/includes/database-access/start-auth-proxy.mdx!)
|
||||
|
||||
## Step 2/2. Run the discovery wizard
|
||||
## Step 1/2. Run the discovery wizard
|
||||
|
||||
In your web browser, access the teleport Web UI at <ScopedBlock scope={["oss", "enterprise"]}>
|
||||
`teleport.example.com`</ScopedBlock><ScopedBlock scope={["cloud"]}>
|
||||
@@ -122,6 +115,8 @@ windows_desktop_service:
|
||||
|
||||
Click **Next**.
|
||||
|
||||
## Step 2/2. Start Teleport
|
||||
|
||||
Once you've saved `/etc/teleport.yaml`, start Teleport:
|
||||
|
||||
<Tabs>
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
- [Dual Authorization](../access-control../access-controls/guides/dual-authz.mdx): Protect access to critical resources with dual authorization.
|
||||
- [Dual Authorization](../access-controls/guides/dual-authz.mdx): Protect access to critical resources with dual authorization.
|
||||
- [Role Templates](../access-controls/guides/role-templates.mdx): Set up Dynamic Access Policies with Role Templates.
|
||||
- [Impersonating Teleport Users](../access-controls/guides/impersonation.mdx): Create certificates for CI/CD with impersonation.
|
||||
- [Passwordless](../access-controls/guides/passwordless.mdx): Use passwordless authentication.
|
||||
|
||||
@@ -158,7 +158,7 @@ If you choose to use Homebrew, you must verify that the versions of `tsh`
|
||||
and `tctl` you run on your local machine are compatible with the versions
|
||||
you run on your infrastructure. Homebrew usually ships the latest release of
|
||||
Teleport, which may be incompatible with older versions. See our
|
||||
[compatibility policy](../management/operations/upgrading.mdx) for details.
|
||||
[compatibility policy](management/operations/upgrading.mdx) for details.
|
||||
|
||||
To verify versions, log in to your cluster and compare the output of `tctl status`
|
||||
against `tsh version` and `tctl version`.
|
||||
|
||||
@@ -26,8 +26,8 @@ following fields in the `spec.allow` section:
|
||||
|
||||
- [`kubernetes_labels`](#kubernetes_labels)
|
||||
- [`kubernetes_resources`](#kubernetes_resources)
|
||||
- [`kubernetes_groups`](#kubernetes_groups)
|
||||
- [`kubernetes_users`](#kubernetes_users)
|
||||
- [`kubernetes_groups`](#kubernetes_groups-and-kubernetes_users)
|
||||
- [`kubernetes_users`](#kubernetes_groups-and-kubernetes_users)
|
||||
|
||||
Here is an example of a Teleport role that restricts access to Kubernetes
|
||||
clusters:
|
||||
|
||||
@@ -14,7 +14,7 @@ Kubernetes and registers the cluster automatically.
|
||||
|
||||
You can also run the Teleport Kubernetes Service on a Linux host in a separate
|
||||
network from your Kubernetes cluster. Learn how in [Kubernetes Access from a
|
||||
Standalone Teleport Cluster](./guides/standalone-teleport.mdx).
|
||||
Standalone Teleport Cluster](./register-clusters/static-kubeconfig.mdx).
|
||||
|
||||
</Notice>
|
||||
|
||||
|
||||
@@ -38,7 +38,7 @@ commands, and view your `kubectl` activity in Teleport's audit log:
|
||||
The fastest way to register a Kubernetes cluster with Teleport is to deploy a
|
||||
Teleport Kubernetes Service instance on the cluster you want to register.
|
||||
We'll show you how to do this in our [Getting Started
|
||||
Guide](../getting-started.mdx).
|
||||
Guide](getting-started.mdx).
|
||||
|
||||
## Automatically register Kubernetes clusters
|
||||
|
||||
|
||||
@@ -447,8 +447,8 @@ RBAC configurations.
|
||||
|
||||
Now that you know how to configure Teleport's RBAC system to control access to
|
||||
Kubernetes clusters, learn how to set up [Resource Access
|
||||
Requests](../../access-controls/access-requests/resource-access-requests.mdx)
|
||||
Requests](../../access-controls/access-requests/resource-requests.mdx)
|
||||
for just-in-time access and [Access Request
|
||||
plugins](../../access-controls/access-request-plugins.mdx) so you can manage
|
||||
plugins](../../access-controls/access-request-plugins/index.mdx) so you can manage
|
||||
access with your communication workflow of choice.
|
||||
|
||||
|
||||
@@ -8,12 +8,13 @@ In some cases, you will want to register a Kubernetes cluster with Teleport
|
||||
manually, rather than letting Teleport [discover the cluster
|
||||
automatically](./discovery.mdx). There are a few ways to do this:
|
||||
|
||||
- [Deploy the Teleport Kubernetes Service](./guides/multiple-clusters.mdx) on
|
||||
your cluster of choice.
|
||||
- [Deploy the Teleport Kubernetes
|
||||
Service](./register-clusters/register-via-deployment.mdx) on your cluster of
|
||||
choice.
|
||||
- Deploy the Teleport Kubernetes Service outside your Kubernetes cluster (e.g.,
|
||||
directly on a virtual machine) and [give it access to a
|
||||
kubeconfig](./register-clusters/static-kubeconfig.mdx).
|
||||
- Deploy the Teleport Kubernetes Service outside of Kubernetes and [use dynamic
|
||||
configuration resources](./register-clusters/dynamic-registration.mdx) to register your
|
||||
clusters.
|
||||
configuration resources](./register-clusters/dynamic-registration.mdx) to
|
||||
register your clusters.
|
||||
|
||||
|
||||
@@ -500,5 +500,5 @@ clusters via Teleport, check out the following guides:
|
||||
the `teleport-kube-agent` Helm chart to register a Kubernetes cluster with
|
||||
Teleport.
|
||||
- [Kubernetes Access from a Standalone Teleport
|
||||
Cluster](./standalone-teleport.mdx): How to use the Teleport Kubernetes
|
||||
Cluster](./static-kubeconfig.mdx): How to use the Teleport Kubernetes
|
||||
Service's configuration file to register a Kubernetes cluster with Teleport.
|
||||
|
||||
@@ -15,7 +15,7 @@ Machine ID supports the following Teleport features:
|
||||
- [Database Access](./guides/databases.mdx)
|
||||
- [Kubernetes Access](./guides/kubernetes.mdx) (*in Teleport v10.1*)
|
||||
- [Application Access](./guides/applications.mdx) (*in Teleport v10.1*)
|
||||
- Note: [AWS Console](../application-access/guides/aws-console.mdx) and API access is currently unsupported.
|
||||
- Note: [AWS Console](../application-access/cloud-apis/aws-console.mdx) and API access is currently unsupported.
|
||||
- [Teleport API Access](../api/introduction.mdx)
|
||||
|
||||
These features are supported in Teleport Enterprise and Teleport Cloud.
|
||||
@@ -25,7 +25,7 @@ The following features are **not** yet supported by Machine ID:
|
||||
- [User Impersonation](../access-controls/guides/impersonation.mdx): Machine
|
||||
ID uses Role Impersonation which cannot be combined with User Impersonation
|
||||
- Multifactor authentication like [WebAuthn](../access-controls/guides/webauthn.mdx) and [Passwordless](../access-controls/guides/passwordless.mdx)
|
||||
- [AWS Console Access](../application-access/guides/aws-console.mdx)
|
||||
- [AWS Console Access](../application-access/cloud-apis/aws-console.mdx)
|
||||
|
||||
{
|
||||
/*
|
||||
|
||||
@@ -645,7 +645,7 @@ To run the local proxy server, one of the user's roles must include the
|
||||
`spec.allow.azure_identities` field with one of the identities used by the
|
||||
Application Service. To learn how to set up secure access to Azure via
|
||||
Teleport, read [Protect the Azure CLI with Teleport Application
|
||||
Access](../application-access/guides/azure.mdx).
|
||||
Access](../application-access/cloud-apis/azure.mdx).
|
||||
|
||||
#### Arguments
|
||||
|
||||
|
||||
@@ -22,7 +22,7 @@ The `teleport-kube-agent` chart can run any or all of three Teleport services:
|
||||
|
||||
| Teleport service | Name for `roles` and `tctl tokens add` | Purpose |
|
||||
|--------------------------------------------------------------|----------------------------------------|----------------------------------------------------------------------------------------|
|
||||
| [`kubernetes_service`](../../kubernetes-access/guides.mdx) | `kube` | Uses Teleport to handle authentication<br/> with and proxy access to a Kubernetes cluster |
|
||||
| [`kubernetes_service`](../../kubernetes-access/introduction.mdx) | `kube` | Uses Teleport to handle authentication<br/> with and proxy access to a Kubernetes cluster |
|
||||
| [`application_service`](../../application-access/guides.mdx) | `app` | Uses Teleport to handle authentication<br/> with and proxy access to web-based applications |
|
||||
| [`database_service`](../../database-access/guides.mdx) | `db` | Uses Teleport to handle authentication<br/> with and proxy access to databases |
|
||||
|
||||
@@ -472,7 +472,7 @@ You can specify multiple database filters by adding additional list elements.
|
||||
</Admonition>
|
||||
|
||||
<Admonition type="note" title="Azure IAM">
|
||||
For Azure database auto-discovery to work, your Database Service pods will need to have appropriate IAM permissions as per the [database documentation](../../database-access/guides/azure-postgres-mysql.mdx#step-35-configure-iam-permissions-for-teleport).
|
||||
For Azure database auto-discovery to work, your Database Service pods will need to have appropriate IAM permissions as per the [database documentation](../../database-access/guides/azure-postgres-mysql.mdx#step-46-configure-iam-permissions-for-teleport).
|
||||
|
||||
After configuring a service principal with appropriate IAM permissions, you must pass credentials to the pods.
|
||||
The easiest way is to use an Azure client secret.
|
||||
|
||||
@@ -421,4 +421,4 @@ production.
|
||||
- Integrate Teleport with your SSO provider:
|
||||
[Single Sign-On and Kubernetes RBAC](../kubernetes-access/controls.mdx)
|
||||
- Have a Kubernetes cluster but don't want to run Teleport there?
|
||||
[Kubernetes Access from Standalone Teleport](../kubernetes-access/guides/standalone-teleport.mdx)
|
||||
[Kubernetes Access from Standalone Teleport](../kubernetes-access/register-clusters/static-kubeconfig.mdx)
|
||||
|
||||
Reference in New Issue
Block a user