Add Teleport Connect to Headless docs (#30300)

* Support TELEPORT_HEADLESS_SKIP_CONFIRM env flag in teleport connect.

* Replace reject button with cancel button that persists through approval state. This makes it possible to reject a headless authentication when it skips the initial confirmation step.

* Add headlessSkipConfirm config option.

* Apply changes from CR.

* Add Teleport Connect docs for headless login.

* Address comments.

* Apply suggestions from code review

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>

---------

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
This commit is contained in:
Brian Joerger
2023-08-14 19:40:29 +00:00
committed by GitHub
co-authored by Paul Gottschling
parent 963ee50998
commit c2e7f548ba
4 changed files with 21 additions and 0 deletions
Binary file not shown.

After

Width:  |  Height:  |  Size: 87 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 58 KiB

@@ -35,6 +35,7 @@ For example:
- Machines for Headless WebAuthn activities have [Linux](../../installation.mdx#linux), [macOS](../../installation.mdx#macos) or [Windows](../../installation.mdx#windows-tsh-client-only) `tsh` binary v12.2+ installed.
- Machines used to approve Headless WebAuthn requests have a Web browser with [WebAuthn support](
https://developers.yubico.com/WebAuthn/WebAuthn_Browser_Support/) or `tsh` binary v12.2+ installed.
- Optional: Teleport Connect v13.3.1+ for [seamless Headless WebAuthn approval](#optional-teleport-connect).
## Step 1/3. Configuration
@@ -178,6 +179,25 @@ alice@server01 $
your local terminal.
</Notice>
## Optional: Teleport Connect
Teleport Connect v13.3.1+ can also be used to approve Headless WebAuthn logins.
Teleport Connect will automatically detect the Headless WebAuthn login attempt
and allow you to approve or cancel the request.
<Figure width="700">
![Headless Confirmation](../../../img/headless/confirmation.png)
</Figure>
You will be prompted to tap your MFA key to complete the approval process.
<Figure width="700">
![Headless WebAuthn Approval](../../../img/headless/approval.png)
</Figure>
<Notice type="note">
This also requires a v13.3.1+ Teleport Auth Service.
</Notice>
## Troubleshooting
@@ -212,6 +212,7 @@ Below is the list of the supported config properties.
| `keymap.openClusters` | `Command+E` on macOS<br/>`Ctrl+E` on Windows/Linux | Shortcut to open the cluster selector. |
| `keymap.openProfiles` | `Command+I` on macOS<br/>`Ctrl+I` on Windows/Linux | Shortcut to open the profile selector. |
| `keymap.openSearchBar` | `Command+K` on macOS<br/>`Ctrl+K` on Windows/Linux | Shortcut to open the search bar. |
| `headless.skipConfirm` | false | Skips the confirmation prompt for Headless WebAuthn approval and instead prompts for WebAuthn immediately. |
<Admonition
type="note"