mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Detail DAC and TAG integration from the user perspective (#46069)
* Detail DAC and TAG integration from the user perspective * Change wording to make linter happy. * Fix broken links and spacing * Update docs/pages/admin-guides/teleport-policy/database-access-controls.mdx Co-authored-by: STeve (Xin) Huang <xin.huang@goteleport.com> * Update screenshots. Drop redundant instructions and merge the information into an existing suitable page. --------- Co-authored-by: STeve (Xin) Huang <xin.huang@goteleport.com>
This commit is contained in:
co-authored by
STeve Huang
parent
a3f0fdbbda
commit
ba35baa30d
Binary file not shown.
|
After Width: | Height: | Size: 98 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 143 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 107 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 216 KiB |
@@ -71,6 +71,32 @@ can be identified by having `Temporary: true` property.
|
||||
|
||||
Resource Groups are created from Teleport roles.
|
||||
|
||||
### Database Access Controls
|
||||
|
||||
Teleport supports [object-level permissions](../../enroll-resources/database-access/rbac.mdx#executing-database-object-permission-rules) for select database protocols.
|
||||
|
||||
The database objects-level access information is automatically synchronized to Teleport Policy, making it possible to see who has particular levels of access to the different parts of the database.
|
||||
|
||||
When you inspect a particular user's access, the Teleport Access Graph will automatically display the database objects that the user can access.
|
||||
|
||||

|
||||
|
||||
To see more details about a specific database object, simply select it.
|
||||
|
||||
<Figure width="400">
|
||||

|
||||
</Figure>
|
||||
|
||||
In the graph, database objects are connected by multiple edges:
|
||||
|
||||
1. There is exactly one edge connecting the object to its parent database resource. This edge has "contains" label.
|
||||
|
||||

|
||||
|
||||
2. At least one edge shows the permissions associated with the object, such as `INSERT, SELECT, UPDATE`. If multiple roles grant permissions to the same object, additional edges of this type may be present. The permissions are presented as edge labels.
|
||||
|
||||

|
||||
|
||||
#### Resources
|
||||
|
||||
Resources are created from Teleport resources like nodes, databases, and Kubernetes clusters.
|
||||
|
||||
Reference in New Issue
Block a user