diff --git a/CHANGELOG.md b/CHANGELOG.md index 4fe8e35b731..d95577f7ca0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -714,7 +714,7 @@ to log into their AWS console using `tsh apps login` and use `tsh aws` commands to interact with AWS APIs. See more info in the -[documentation](docs/pages/application-access/guides/aws-console.mdx). +[documentation](docs/pages/application-access/cloud-apis/aws-console.mdx). #### Application and Database Dynamic Registration @@ -849,7 +849,7 @@ View the Cloud SQL MySQL [guide](docs/pages/database-access/guides/mysql-cloudsq Added support for [AWS Console](https://aws.amazon.com/console) to Teleport Application Access. [#7590](https://github.com/gravitational/teleport/pull/7590) -Teleport Application Access can now automatically sign users into the AWS Management Console using [Identity federation](https://aws.amazon.com/identity/federation). View AWS Management Console [guide](docs/pages/application-access/guides/aws-console.mdx) for more details. +Teleport Application Access can now automatically sign users into the AWS Management Console using [Identity federation](https://aws.amazon.com/identity/federation). View AWS Management Console [guide](docs/pages/application-access/cloud-apis/aws-console.mdx) for more details. #### Restricted Sessions diff --git a/docs/pages/application-access/cloud-apis/aws-console.mdx b/docs/pages/application-access/cloud-apis/aws-console.mdx index 808e15e0324..57c2f8f6f07 100644 --- a/docs/pages/application-access/cloud-apis/aws-console.mdx +++ b/docs/pages/application-access/cloud-apis/aws-console.mdx @@ -20,7 +20,7 @@ This guide will explain how to: - A running Teleport cluster, either self hosted or in Teleport Cloud. - A host running the `teleport` daemon with Application Access enabled. Follow the [Getting Started](../getting-started.mdx) or - [Connecting Apps](./connecting-apps.mdx) guides to get it running. + [Connecting Apps](../guides/connecting-apps.mdx) guides to get it running. - IAM permissions in the AWS account you want to connect. - AWS EC2 or other instance where you can assign a IAM Security Role for the Teleport Agent. - `aws` command line interface (CLI) tool in PATH. [Installing or updating the latest version of the AWS CLI diff --git a/docs/pages/application-access/cloud-apis/google-cloud.mdx b/docs/pages/application-access/cloud-apis/google-cloud.mdx index f70f4886342..74c9340c21f 100644 --- a/docs/pages/application-access/cloud-apis/google-cloud.mdx +++ b/docs/pages/application-access/cloud-apis/google-cloud.mdx @@ -119,7 +119,8 @@ permissions to impersonate target service accounts. If you are enabling access to an existing service account, you can skip to the [next -section](#enable-the-application-service-to-impersonate-your-service-account). +section](#enable-teleport-google-cloud-cli-to-impersonate-target-service-accounts +). @@ -680,7 +681,6 @@ command. our documentation on [Role Access Requests](../../access-controls/access-requests/role-requests.mdx) and [Access Request plugins](../../access-controls/access-request-plugins/index.mdx). - - You can proxy any `gcloud` or `gsutil` command via Teleport. For a full reference of commands, view the Google Cloud documentation for [`gcloud`](https://cloud.google.com/sdk/gcloud/reference) and diff --git a/docs/pages/application-access/controls.mdx b/docs/pages/application-access/controls.mdx index 8956fd2b4f7..997caa8d5bc 100644 --- a/docs/pages/application-access/controls.mdx +++ b/docs/pages/application-access/controls.mdx @@ -126,7 +126,7 @@ This command uses the `--set-azure-identities` flag to add Azure identities to a user. The value of this flag is a comma-separated list of Azure identity URIs. See our [Azure -CLI](./guides/azure.mdx#step-34-enable-your-user-to-access-azure-clis) guide +CLI](./cloud-apis/azure.mdx#step-34-enable-your-user-to-access-azure-clis) guide for more information on enabling access to Azure managed identities. ## Next steps diff --git a/docs/pages/application-access/guides/dynamodb.mdx b/docs/pages/application-access/guides/dynamodb.mdx index 7dc2f9fbdcc..522ed95ce99 100644 --- a/docs/pages/application-access/guides/dynamodb.mdx +++ b/docs/pages/application-access/guides/dynamodb.mdx @@ -327,5 +327,5 @@ $ tsh apps logout aws-dynamodb ``` ## Next steps -- More information on [AWS Management and API with Teleport Application Access](../../application-access/guides/aws-console.mdx). +- More information on [AWS Management and API with Teleport Application Access](../../application-access/cloud-apis/aws-console.mdx). - Learn more about [AWS service endpoints](https://docs.aws.amazon.com/general/latest/gr/rande.html). diff --git a/docs/pages/application-access/reference.mdx b/docs/pages/application-access/reference.mdx index 9dc46f7a9d0..545ed3ece16 100644 --- a/docs/pages/application-access/reference.mdx +++ b/docs/pages/application-access/reference.mdx @@ -207,5 +207,5 @@ To run this command, one of the user's roles must include the `spec.allow.azure_identities` field with one of the identities used by the Application Service. To learn how to set up secure access to Azure via Teleport, read [Protect the Azure CLI with Teleport Application -Access](guides/azure.mdx). +Access](cloud-apis/azure.mdx). diff --git a/docs/pages/choose-an-edition/teleport-cloud/getting-started.mdx b/docs/pages/choose-an-edition/teleport-cloud/getting-started.mdx index 629eaec83fb..a1437807ec3 100644 --- a/docs/pages/choose-an-edition/teleport-cloud/getting-started.mdx +++ b/docs/pages/choose-an-edition/teleport-cloud/getting-started.mdx @@ -182,12 +182,12 @@ $ tsh ssh root@ - Now that you have registered your first server with Teleport, read about how you can register resources in your infrastructure, including: - - [Additional SSH servers](../../server-access/introduction.mdx) - - [Cloud provider tools and internal web applications](../../application-access/introduction.mdx) - - [Databases](../../database-access/introduction.mdx) - - [Kubernetes clusters](../../kubernetes-access/introduction.mdx) - - [Service accounts](../../machine-id/introduction.mdx) - - [Windows desktops](../../desktop-access.mdx) + - [Additional SSH servers](../../server-access/introduction.mdx) + - [Cloud provider tools and internal web applications](../../application-access/introduction.mdx) + - [Databases](../../database-access/introduction.mdx) + - [Kubernetes clusters](../../kubernetes-access/introduction.mdx) + - [Service accounts](../../machine-id/introduction.mdx) + - [Windows desktops](../../desktop-access/introduction.mdx) - Aside from `tsh` and the Web UI, you can also connect to Teleport with our desktop application, [Teleport diff --git a/docs/pages/database-access/getting-started.mdx b/docs/pages/database-access/getting-started.mdx index 345e40cead9..abe9ec19132 100644 --- a/docs/pages/database-access/getting-started.mdx +++ b/docs/pages/database-access/getting-started.mdx @@ -146,7 +146,7 @@ $ teleport db start \ title="AWS Credentials" > The node that connects to the database should have AWS credentials configured - with the policy from [step 1](#step-13-set-up-aurora). + with the policy from [step 1](#step-14-set-up-aurora). ## Step 3/4. Create a user and role diff --git a/docs/pages/database-access/guides/azure-postgres-mysql.mdx b/docs/pages/database-access/guides/azure-postgres-mysql.mdx index ef7a190707f..5c02d756564 100644 --- a/docs/pages/database-access/guides/azure-postgres-mysql.mdx +++ b/docs/pages/database-access/guides/azure-postgres-mysql.mdx @@ -49,6 +49,7 @@ Create the Database Service configuration. - Specify the region for your database(s) in `--azure-postgres-discovery`. + - Replace the `--proxy` value with your Teleport proxy address or Teleport cloud URI (e.g. `mytenant.teleport.sh:443`): diff --git a/docs/pages/database-access/guides/azure-sql-server-ad.mdx b/docs/pages/database-access/guides/azure-sql-server-ad.mdx index 8397bfffa1a..215d8c802b4 100644 --- a/docs/pages/database-access/guides/azure-sql-server-ad.mdx +++ b/docs/pages/database-access/guides/azure-sql-server-ad.mdx @@ -295,7 +295,7 @@ to add it. When connecting to your database, and you see the error `mssql: login error: Login failed for user ''`, it means your managed identity login is not present on the SQL database. You’ll need to create their users as -described in [Step 6](#step-69-enable-managed-identities-login-on-sql-server). +described in [Step 6](#step-58-enable-managed-identities-login-on-sql-server). Remember: you must create the users on all databases you want to connect. ### Timeout connecting to the database diff --git a/docs/pages/database-access/guides/mongodb-atlas.mdx b/docs/pages/database-access/guides/mongodb-atlas.mdx index 15c40d079f3..e2d4e46f4a8 100644 --- a/docs/pages/database-access/guides/mongodb-atlas.mdx +++ b/docs/pages/database-access/guides/mongodb-atlas.mdx @@ -146,7 +146,7 @@ See the full [YAML reference](../reference/configuration.mdx) for details. See below for details on how to configure the Teleport Database Service. -#### Connection endpoint +### Connection endpoint You will need to provide your Atlas cluster's connection endpoint for the `db_service.databases[*].uri` configuration option or `--uri` CLI flag. You can find this via the Connect dialog on the Database Deployments overview page: @@ -163,7 +163,7 @@ Use only the scheme and hostname parts of the connection string in the URI: $ --uri=mongodb+srv://cluster0.abcde.mongodb.net ``` -#### Atlas CA certificate +### Atlas CA certificate MongoDB Atlas uses certificates signed by Let's Encrypt. diff --git a/docs/pages/deploy-a-cluster/helm-deployments/digitalocean.mdx b/docs/pages/deploy-a-cluster/helm-deployments/digitalocean.mdx index 53822764604..923353714b7 100644 --- a/docs/pages/deploy-a-cluster/helm-deployments/digitalocean.mdx +++ b/docs/pages/deploy-a-cluster/helm-deployments/digitalocean.mdx @@ -260,7 +260,7 @@ guide](../../reference/helm-reference/teleport-cluster.mdx). Read our guides to additional ways you can protect a Kubernetes cluster with Teleport: -- [Connect Multiple Kubernetes Clusters](../../kubernetes-access/guides/multiple-clusters.mdx) +- [Connect Multiple Kubernetes Clusters](../../kubernetes-access/register-clusters/register-via-deployment.mdx) - [Set up Machine ID with Kubernetes](../../machine-id/guides/kubernetes.mdx) -- [Federated Access using Trusted Clusters](../../kubernetes-access/guides/federation.mdx) +- [Federated Access using Trusted Clusters](../../kubernetes-access/manage-access/federation.mdx) - [Single-Sign On and Kubernetes Access Control](../../kubernetes-access/controls.mdx) diff --git a/docs/pages/deploy-a-cluster/helm-deployments/kubernetes-cluster.mdx b/docs/pages/deploy-a-cluster/helm-deployments/kubernetes-cluster.mdx index e972801f147..9d5a5ccddd1 100644 --- a/docs/pages/deploy-a-cluster/helm-deployments/kubernetes-cluster.mdx +++ b/docs/pages/deploy-a-cluster/helm-deployments/kubernetes-cluster.mdx @@ -406,7 +406,7 @@ guide](../../reference/helm-reference/teleport-cluster.mdx). Read our guides to additional ways you can protect Kubernetes clusters with Teleport: -- [Connect Multiple Kubernetes Clusters](../../kubernetes-access/guides/multiple-clusters.mdx) +- [Connect Multiple Kubernetes Clusters](../../kubernetes-access/register-clusters/register-via-deployment.mdx) - [Set up Machine ID with Kubernetes](../../machine-id/guides/kubernetes.mdx) -- [Federated Access using Trusted Clusters](../../kubernetes-access/guides/federation.mdx) +- [Federated Access using Trusted Clusters](../../kubernetes-access/manage-access/federation.mdx) - [Single-Sign On and Kubernetes Access Control](../../kubernetes-access/controls.mdx) diff --git a/docs/pages/deploy-a-cluster/helm-deployments/migration-kubernetes-1-25-psp.mdx b/docs/pages/deploy-a-cluster/helm-deployments/migration-kubernetes-1-25-psp.mdx index df731276c5e..0d9a29f102d 100644 --- a/docs/pages/deploy-a-cluster/helm-deployments/migration-kubernetes-1-25-psp.mdx +++ b/docs/pages/deploy-a-cluster/helm-deployments/migration-kubernetes-1-25-psp.mdx @@ -20,6 +20,7 @@ Their removal has two main consequences: To prepare for the 1.25 upgrade: - Make sure you are running at least Kubernetes 1.23 (run `kubectl version`) + - Label the namespace you are deploying the chart in with the PSA enforcement level: ```code diff --git a/docs/pages/desktop-access/active-directory.mdx b/docs/pages/desktop-access/active-directory.mdx index 856292aa206..62067827038 100644 --- a/docs/pages/desktop-access/active-directory.mdx +++ b/docs/pages/desktop-access/active-directory.mdx @@ -32,9 +32,8 @@ access to Windows desktops. ## Prerequisites - -- One or more hosts to run the Teleport Auth and Proxy services on. - +(!docs/pages/includes/edition-prereqs-tabs.mdx!) + - A server or virtual machine running a Windows Server operating system. In this guide, we'll install Active Directory on this server in order to support passwordless logins with Teleport to the Windows desktops @@ -48,13 +47,7 @@ access to Windows desktops. encrypted LDAP connection). Typically this means installing [AD CS](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/). -## Step 1/2. Install Teleport - -### Set up the Teleport Auth and Proxy Services - -(!docs/pages/includes/database-access/start-auth-proxy.mdx!) - -## Step 2/2. Run the discovery wizard +## Step 1/2. Run the discovery wizard In your web browser, access the teleport Web UI at `teleport.example.com` @@ -122,6 +115,8 @@ windows_desktop_service: Click **Next**. +## Step 2/2. Start Teleport + Once you've saved `/etc/teleport.yaml`, start Teleport: diff --git a/docs/pages/includes/access-control-guides.mdx b/docs/pages/includes/access-control-guides.mdx index c39600adfd2..f74341cfb54 100644 --- a/docs/pages/includes/access-control-guides.mdx +++ b/docs/pages/includes/access-control-guides.mdx @@ -1,4 +1,4 @@ -- [Dual Authorization](../access-control../access-controls/guides/dual-authz.mdx): Protect access to critical resources with dual authorization. +- [Dual Authorization](../access-controls/guides/dual-authz.mdx): Protect access to critical resources with dual authorization. - [Role Templates](../access-controls/guides/role-templates.mdx): Set up Dynamic Access Policies with Role Templates. - [Impersonating Teleport Users](../access-controls/guides/impersonation.mdx): Create certificates for CI/CD with impersonation. - [Passwordless](../access-controls/guides/passwordless.mdx): Use passwordless authentication. diff --git a/docs/pages/installation.mdx b/docs/pages/installation.mdx index caf7dc97060..fcff6fbf7bd 100644 --- a/docs/pages/installation.mdx +++ b/docs/pages/installation.mdx @@ -158,7 +158,7 @@ If you choose to use Homebrew, you must verify that the versions of `tsh` and `tctl` you run on your local machine are compatible with the versions you run on your infrastructure. Homebrew usually ships the latest release of Teleport, which may be incompatible with older versions. See our -[compatibility policy](../management/operations/upgrading.mdx) for details. +[compatibility policy](management/operations/upgrading.mdx) for details. To verify versions, log in to your cluster and compare the output of `tctl status` against `tsh version` and `tctl version`. diff --git a/docs/pages/kubernetes-access/controls.mdx b/docs/pages/kubernetes-access/controls.mdx index 9d7c31f4055..fe5b2d392c9 100644 --- a/docs/pages/kubernetes-access/controls.mdx +++ b/docs/pages/kubernetes-access/controls.mdx @@ -26,8 +26,8 @@ following fields in the `spec.allow` section: - [`kubernetes_labels`](#kubernetes_labels) - [`kubernetes_resources`](#kubernetes_resources) -- [`kubernetes_groups`](#kubernetes_groups) -- [`kubernetes_users`](#kubernetes_users) +- [`kubernetes_groups`](#kubernetes_groups-and-kubernetes_users) +- [`kubernetes_users`](#kubernetes_groups-and-kubernetes_users) Here is an example of a Teleport role that restricts access to Kubernetes clusters: diff --git a/docs/pages/kubernetes-access/getting-started.mdx b/docs/pages/kubernetes-access/getting-started.mdx index 467fbb24dc8..cf0048515f2 100644 --- a/docs/pages/kubernetes-access/getting-started.mdx +++ b/docs/pages/kubernetes-access/getting-started.mdx @@ -14,7 +14,7 @@ Kubernetes and registers the cluster automatically. You can also run the Teleport Kubernetes Service on a Linux host in a separate network from your Kubernetes cluster. Learn how in [Kubernetes Access from a -Standalone Teleport Cluster](./guides/standalone-teleport.mdx). +Standalone Teleport Cluster](./register-clusters/static-kubeconfig.mdx). diff --git a/docs/pages/kubernetes-access/introduction.mdx b/docs/pages/kubernetes-access/introduction.mdx index 32602f2bb6d..6efca7f1c33 100644 --- a/docs/pages/kubernetes-access/introduction.mdx +++ b/docs/pages/kubernetes-access/introduction.mdx @@ -38,7 +38,7 @@ commands, and view your `kubectl` activity in Teleport's audit log: The fastest way to register a Kubernetes cluster with Teleport is to deploy a Teleport Kubernetes Service instance on the cluster you want to register. We'll show you how to do this in our [Getting Started -Guide](../getting-started.mdx). +Guide](getting-started.mdx). ## Automatically register Kubernetes clusters diff --git a/docs/pages/kubernetes-access/manage-access/rbac.mdx b/docs/pages/kubernetes-access/manage-access/rbac.mdx index 4908fcedf5e..5434d783dbc 100644 --- a/docs/pages/kubernetes-access/manage-access/rbac.mdx +++ b/docs/pages/kubernetes-access/manage-access/rbac.mdx @@ -447,8 +447,8 @@ RBAC configurations. Now that you know how to configure Teleport's RBAC system to control access to Kubernetes clusters, learn how to set up [Resource Access -Requests](../../access-controls/access-requests/resource-access-requests.mdx) +Requests](../../access-controls/access-requests/resource-requests.mdx) for just-in-time access and [Access Request -plugins](../../access-controls/access-request-plugins.mdx) so you can manage +plugins](../../access-controls/access-request-plugins/index.mdx) so you can manage access with your communication workflow of choice. diff --git a/docs/pages/kubernetes-access/register-clusters.mdx b/docs/pages/kubernetes-access/register-clusters.mdx index aa6fdbc925f..90da2a57912 100644 --- a/docs/pages/kubernetes-access/register-clusters.mdx +++ b/docs/pages/kubernetes-access/register-clusters.mdx @@ -8,12 +8,13 @@ In some cases, you will want to register a Kubernetes cluster with Teleport manually, rather than letting Teleport [discover the cluster automatically](./discovery.mdx). There are a few ways to do this: -- [Deploy the Teleport Kubernetes Service](./guides/multiple-clusters.mdx) on - your cluster of choice. +- [Deploy the Teleport Kubernetes + Service](./register-clusters/register-via-deployment.mdx) on your cluster of + choice. - Deploy the Teleport Kubernetes Service outside your Kubernetes cluster (e.g., directly on a virtual machine) and [give it access to a kubeconfig](./register-clusters/static-kubeconfig.mdx). - Deploy the Teleport Kubernetes Service outside of Kubernetes and [use dynamic - configuration resources](./register-clusters/dynamic-registration.mdx) to register your - clusters. + configuration resources](./register-clusters/dynamic-registration.mdx) to + register your clusters. diff --git a/docs/pages/kubernetes-access/register-clusters/dynamic-registration.mdx b/docs/pages/kubernetes-access/register-clusters/dynamic-registration.mdx index 878b23bdd0d..391abe1b304 100644 --- a/docs/pages/kubernetes-access/register-clusters/dynamic-registration.mdx +++ b/docs/pages/kubernetes-access/register-clusters/dynamic-registration.mdx @@ -500,5 +500,5 @@ clusters via Teleport, check out the following guides: the `teleport-kube-agent` Helm chart to register a Kubernetes cluster with Teleport. - [Kubernetes Access from a Standalone Teleport - Cluster](./standalone-teleport.mdx): How to use the Teleport Kubernetes + Cluster](./static-kubeconfig.mdx): How to use the Teleport Kubernetes Service's configuration file to register a Kubernetes cluster with Teleport. diff --git a/docs/pages/machine-id/introduction.mdx b/docs/pages/machine-id/introduction.mdx index 8b57daa3eb1..ee9e5e99933 100644 --- a/docs/pages/machine-id/introduction.mdx +++ b/docs/pages/machine-id/introduction.mdx @@ -15,7 +15,7 @@ Machine ID supports the following Teleport features: - [Database Access](./guides/databases.mdx) - [Kubernetes Access](./guides/kubernetes.mdx) (*in Teleport v10.1*) - [Application Access](./guides/applications.mdx) (*in Teleport v10.1*) - - Note: [AWS Console](../application-access/guides/aws-console.mdx) and API access is currently unsupported. + - Note: [AWS Console](../application-access/cloud-apis/aws-console.mdx) and API access is currently unsupported. - [Teleport API Access](../api/introduction.mdx) These features are supported in Teleport Enterprise and Teleport Cloud. @@ -25,7 +25,7 @@ The following features are **not** yet supported by Machine ID: - [User Impersonation](../access-controls/guides/impersonation.mdx): Machine ID uses Role Impersonation which cannot be combined with User Impersonation - Multifactor authentication like [WebAuthn](../access-controls/guides/webauthn.mdx) and [Passwordless](../access-controls/guides/passwordless.mdx) - - [AWS Console Access](../application-access/guides/aws-console.mdx) + - [AWS Console Access](../application-access/cloud-apis/aws-console.mdx) { /* diff --git a/docs/pages/reference/cli.mdx b/docs/pages/reference/cli.mdx index adec5932358..e95a09406c0 100644 --- a/docs/pages/reference/cli.mdx +++ b/docs/pages/reference/cli.mdx @@ -645,7 +645,7 @@ To run the local proxy server, one of the user's roles must include the `spec.allow.azure_identities` field with one of the identities used by the Application Service. To learn how to set up secure access to Azure via Teleport, read [Protect the Azure CLI with Teleport Application -Access](../application-access/guides/azure.mdx). +Access](../application-access/cloud-apis/azure.mdx). #### Arguments diff --git a/docs/pages/reference/helm-reference/teleport-kube-agent.mdx b/docs/pages/reference/helm-reference/teleport-kube-agent.mdx index e6376de516b..d17b7b83141 100644 --- a/docs/pages/reference/helm-reference/teleport-kube-agent.mdx +++ b/docs/pages/reference/helm-reference/teleport-kube-agent.mdx @@ -22,7 +22,7 @@ The `teleport-kube-agent` chart can run any or all of three Teleport services: | Teleport service | Name for `roles` and `tctl tokens add` | Purpose | |--------------------------------------------------------------|----------------------------------------|----------------------------------------------------------------------------------------| -| [`kubernetes_service`](../../kubernetes-access/guides.mdx) | `kube` | Uses Teleport to handle authentication
with and proxy access to a Kubernetes cluster | +| [`kubernetes_service`](../../kubernetes-access/introduction.mdx) | `kube` | Uses Teleport to handle authentication
with and proxy access to a Kubernetes cluster | | [`application_service`](../../application-access/guides.mdx) | `app` | Uses Teleport to handle authentication
with and proxy access to web-based applications | | [`database_service`](../../database-access/guides.mdx) | `db` | Uses Teleport to handle authentication
with and proxy access to databases | @@ -472,7 +472,7 @@ You can specify multiple database filters by adding additional list elements. - For Azure database auto-discovery to work, your Database Service pods will need to have appropriate IAM permissions as per the [database documentation](../../database-access/guides/azure-postgres-mysql.mdx#step-35-configure-iam-permissions-for-teleport). + For Azure database auto-discovery to work, your Database Service pods will need to have appropriate IAM permissions as per the [database documentation](../../database-access/guides/azure-postgres-mysql.mdx#step-46-configure-iam-permissions-for-teleport). After configuring a service principal with appropriate IAM permissions, you must pass credentials to the pods. The easiest way is to use an Azure client secret. diff --git a/docs/pages/try-out-teleport/local-kubernetes.mdx b/docs/pages/try-out-teleport/local-kubernetes.mdx index 9a1117ffcdc..e6dc1d7e74a 100644 --- a/docs/pages/try-out-teleport/local-kubernetes.mdx +++ b/docs/pages/try-out-teleport/local-kubernetes.mdx @@ -421,4 +421,4 @@ production. - Integrate Teleport with your SSO provider: [Single Sign-On and Kubernetes RBAC](../kubernetes-access/controls.mdx) - Have a Kubernetes cluster but don't want to run Teleport there? - [Kubernetes Access from Standalone Teleport](../kubernetes-access/guides/standalone-teleport.mdx) + [Kubernetes Access from Standalone Teleport](../kubernetes-access/register-clusters/static-kubeconfig.mdx)