adding immutable labels to scoped token, inventory, server, joinservice, (#62939)

and decisionprotos
This commit is contained in:
Erik Tate
2026-01-27 21:59:19 +00:00
committed by GitHub
parent 41b8ac7d6f
commit da008f23b3
18 changed files with 2721 additions and 2289 deletions
+49 -34
View File
@@ -24,7 +24,8 @@
package proto
import (
v1 "github.com/gravitational/teleport/api/gen/proto/go/teleport/presence/v1"
v11 "github.com/gravitational/teleport/api/gen/proto/go/teleport/presence/v1"
v1 "github.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1"
types "github.com/gravitational/teleport/api/types"
protoreflect "google.golang.org/protobuf/reflect/protoreflect"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
@@ -531,9 +532,12 @@ type UpstreamInventoryHello struct {
UpdaterInfo *types.UpdaterV2Info `protobuf:"bytes,8,opt,name=UpdaterInfo,proto3" json:"UpdaterInfo,omitempty"`
// The advertized scope of the instance. An instance's scope can not change once assigned, so future
// heartbeats must include a scope value matching the one declared in the hello message.
Scope string `protobuf:"bytes,9,opt,name=scope,proto3" json:"scope,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
Scope string `protobuf:"bytes,9,opt,name=scope,proto3" json:"scope,omitempty"`
// The immutable labels reported by the instance. The hash of these labels is expected to match
// the hash included in the instance's certificate.
ImmutableLabels *v1.ImmutableLabels `protobuf:"bytes,10,opt,name=immutable_labels,json=immutableLabels,proto3" json:"immutable_labels,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *UpstreamInventoryHello) Reset() {
@@ -622,6 +626,13 @@ func (x *UpstreamInventoryHello) GetScope() string {
return ""
}
func (x *UpstreamInventoryHello) GetImmutableLabels() *v1.ImmutableLabels {
if x != nil {
return x.ImmutableLabels
}
return nil
}
// UpstreamInventoryAgentMetadata is the message sent up the inventory control stream containing
// metadata about the instance.
type UpstreamInventoryAgentMetadata struct {
@@ -933,7 +944,7 @@ type InventoryHeartbeat struct {
// KubeServer is a complete kube server spec to be heartbeated.
KubernetesServer *types.KubernetesServerV3 `protobuf:"bytes,4,opt,name=KubernetesServer,proto3" json:"KubernetesServer,omitempty"`
// A relay_server to be heartbeated.
RelayServer *v1.RelayServer `protobuf:"bytes,5,opt,name=relay_server,json=relayServer,proto3" json:"relay_server,omitempty"`
RelayServer *v11.RelayServer `protobuf:"bytes,5,opt,name=relay_server,json=relayServer,proto3" json:"relay_server,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
@@ -996,7 +1007,7 @@ func (x *InventoryHeartbeat) GetKubernetesServer() *types.KubernetesServerV3 {
return nil
}
func (x *InventoryHeartbeat) GetRelayServer() *v1.RelayServer {
func (x *InventoryHeartbeat) GetRelayServer() *v11.RelayServer {
if x != nil {
return x.RelayServer
}
@@ -1470,7 +1481,7 @@ var File_teleport_legacy_client_proto_inventory_proto protoreflect.FileDescripto
const file_teleport_legacy_client_proto_inventory_proto_rawDesc = "" +
"\n" +
",teleport/legacy/client/proto/inventory.proto\x12\x05proto\x1a\x1fgoogle/protobuf/timestamp.proto\x1a!teleport/legacy/types/types.proto\x1a'teleport/presence/v1/relay_server.proto\"\xa1\x03\n" +
",teleport/legacy/client/proto/inventory.proto\x12\x05proto\x1a\x1fgoogle/protobuf/timestamp.proto\x1a!teleport/legacy/types/types.proto\x1a'teleport/presence/v1/relay_server.proto\x1a&teleport/scopes/joining/v1/token.proto\"\xa1\x03\n" +
"\x16UpstreamInventoryOneOf\x125\n" +
"\x05Hello\x18\x01 \x01(\v2\x1d.proto.UpstreamInventoryHelloH\x00R\x05Hello\x129\n" +
"\tHeartbeat\x18\x02 \x01(\v2\x19.proto.InventoryHeartbeatH\x00R\tHeartbeat\x122\n" +
@@ -1488,7 +1499,7 @@ const file_teleport_legacy_client_proto_inventory_proto_rawDesc = "" +
"\x02ID\x18\x01 \x01(\x04R\x02ID\"e\n" +
"\x15UpstreamInventoryPong\x12\x0e\n" +
"\x02ID\x18\x01 \x01(\x04R\x02ID\x12<\n" +
"\vSystemClock\x18\x02 \x01(\v2\x1a.google.protobuf.TimestampR\vSystemClock\"\xcf\x02\n" +
"\vSystemClock\x18\x02 \x01(\v2\x1a.google.protobuf.TimestampR\vSystemClock\"\xa7\x03\n" +
"\x16UpstreamInventoryHello\x12\x18\n" +
"\aVersion\x18\x01 \x01(\tR\aVersion\x12\x1a\n" +
"\bServerID\x18\x02 \x01(\tR\bServerID\x12\x1a\n" +
@@ -1497,7 +1508,9 @@ const file_teleport_legacy_client_proto_inventory_proto_rawDesc = "" +
"\x10ExternalUpgrader\x18\x05 \x01(\tR\x10ExternalUpgrader\x128\n" +
"\x17ExternalUpgraderVersion\x18\x06 \x01(\tR\x17ExternalUpgraderVersion\x126\n" +
"\vUpdaterInfo\x18\b \x01(\v2\x14.types.UpdaterV2InfoR\vUpdaterInfo\x12\x14\n" +
"\x05scope\x18\t \x01(\tR\x05scopeJ\x04\b\a\x10\bR\rUpdaterV2Info\"\xd4\x02\n" +
"\x05scope\x18\t \x01(\tR\x05scope\x12V\n" +
"\x10immutable_labels\x18\n" +
" \x01(\v2+.teleport.scopes.joining.v1.ImmutableLabelsR\x0fimmutableLabelsJ\x04\b\a\x10\bR\rUpdaterV2Info\"\xd4\x02\n" +
"\x1eUpstreamInventoryAgentMetadata\x12\x0e\n" +
"\x02OS\x18\x01 \x01(\tR\x02OS\x12\x1c\n" +
"\tOSVersion\x18\x02 \x01(\tR\tOSVersion\x12*\n" +
@@ -1625,11 +1638,12 @@ var file_teleport_legacy_client_proto_inventory_proto_goTypes = []any{
nil, // 21: proto.InventoryStatusSummary.ServiceCountsEntry
(*timestamppb.Timestamp)(nil), // 22: google.protobuf.Timestamp
(*types.UpdaterV2Info)(nil), // 23: types.UpdaterV2Info
(*types.ServerV2)(nil), // 24: types.ServerV2
(*types.AppServerV3)(nil), // 25: types.AppServerV3
(*types.DatabaseServerV3)(nil), // 26: types.DatabaseServerV3
(*types.KubernetesServerV3)(nil), // 27: types.KubernetesServerV3
(*v1.RelayServer)(nil), // 28: teleport.presence.v1.RelayServer
(*v1.ImmutableLabels)(nil), // 24: teleport.scopes.joining.v1.ImmutableLabels
(*types.ServerV2)(nil), // 25: types.ServerV2
(*types.AppServerV3)(nil), // 26: types.AppServerV3
(*types.DatabaseServerV3)(nil), // 27: types.DatabaseServerV3
(*types.KubernetesServerV3)(nil), // 28: types.KubernetesServerV3
(*v11.RelayServer)(nil), // 29: teleport.presence.v1.RelayServer
}
var file_teleport_legacy_client_proto_inventory_proto_depIdxs = []int32{
6, // 0: proto.UpstreamInventoryOneOf.Hello:type_name -> proto.UpstreamInventoryHello
@@ -1643,26 +1657,27 @@ var file_teleport_legacy_client_proto_inventory_proto_depIdxs = []int32{
10, // 8: proto.DownstreamInventoryOneOf.UpdateLabels:type_name -> proto.DownstreamInventoryUpdateLabels
22, // 9: proto.UpstreamInventoryPong.SystemClock:type_name -> google.protobuf.Timestamp
23, // 10: proto.UpstreamInventoryHello.UpdaterInfo:type_name -> types.UpdaterV2Info
16, // 11: proto.DownstreamInventoryHello.Capabilities:type_name -> proto.DownstreamInventoryHello.SupportedCapabilities
0, // 12: proto.InventoryUpdateLabelsRequest.Kind:type_name -> proto.LabelUpdateKind
17, // 13: proto.InventoryUpdateLabelsRequest.Labels:type_name -> proto.InventoryUpdateLabelsRequest.LabelsEntry
0, // 14: proto.DownstreamInventoryUpdateLabels.Kind:type_name -> proto.LabelUpdateKind
18, // 15: proto.DownstreamInventoryUpdateLabels.Labels:type_name -> proto.DownstreamInventoryUpdateLabels.LabelsEntry
24, // 16: proto.InventoryHeartbeat.SSHServer:type_name -> types.ServerV2
25, // 17: proto.InventoryHeartbeat.AppServer:type_name -> types.AppServerV3
26, // 18: proto.InventoryHeartbeat.DatabaseServer:type_name -> types.DatabaseServerV3
27, // 19: proto.InventoryHeartbeat.KubernetesServer:type_name -> types.KubernetesServerV3
28, // 20: proto.InventoryHeartbeat.relay_server:type_name -> teleport.presence.v1.RelayServer
6, // 21: proto.InventoryStatusSummary.Connected:type_name -> proto.UpstreamInventoryHello
19, // 22: proto.InventoryStatusSummary.VersionCounts:type_name -> proto.InventoryStatusSummary.VersionCountsEntry
20, // 23: proto.InventoryStatusSummary.UpgraderCounts:type_name -> proto.InventoryStatusSummary.UpgraderCountsEntry
21, // 24: proto.InventoryStatusSummary.ServiceCounts:type_name -> proto.InventoryStatusSummary.ServiceCountsEntry
1, // 25: proto.UpstreamInventoryStopHeartbeat.kind:type_name -> proto.StopHeartbeatKind
26, // [26:26] is the sub-list for method output_type
26, // [26:26] is the sub-list for method input_type
26, // [26:26] is the sub-list for extension type_name
26, // [26:26] is the sub-list for extension extendee
0, // [0:26] is the sub-list for field type_name
24, // 11: proto.UpstreamInventoryHello.immutable_labels:type_name -> teleport.scopes.joining.v1.ImmutableLabels
16, // 12: proto.DownstreamInventoryHello.Capabilities:type_name -> proto.DownstreamInventoryHello.SupportedCapabilities
0, // 13: proto.InventoryUpdateLabelsRequest.Kind:type_name -> proto.LabelUpdateKind
17, // 14: proto.InventoryUpdateLabelsRequest.Labels:type_name -> proto.InventoryUpdateLabelsRequest.LabelsEntry
0, // 15: proto.DownstreamInventoryUpdateLabels.Kind:type_name -> proto.LabelUpdateKind
18, // 16: proto.DownstreamInventoryUpdateLabels.Labels:type_name -> proto.DownstreamInventoryUpdateLabels.LabelsEntry
25, // 17: proto.InventoryHeartbeat.SSHServer:type_name -> types.ServerV2
26, // 18: proto.InventoryHeartbeat.AppServer:type_name -> types.AppServerV3
27, // 19: proto.InventoryHeartbeat.DatabaseServer:type_name -> types.DatabaseServerV3
28, // 20: proto.InventoryHeartbeat.KubernetesServer:type_name -> types.KubernetesServerV3
29, // 21: proto.InventoryHeartbeat.relay_server:type_name -> teleport.presence.v1.RelayServer
6, // 22: proto.InventoryStatusSummary.Connected:type_name -> proto.UpstreamInventoryHello
19, // 23: proto.InventoryStatusSummary.VersionCounts:type_name -> proto.InventoryStatusSummary.VersionCountsEntry
20, // 24: proto.InventoryStatusSummary.UpgraderCounts:type_name -> proto.InventoryStatusSummary.UpgraderCountsEntry
21, // 25: proto.InventoryStatusSummary.ServiceCounts:type_name -> proto.InventoryStatusSummary.ServiceCountsEntry
1, // 26: proto.UpstreamInventoryStopHeartbeat.kind:type_name -> proto.StopHeartbeatKind
27, // [27:27] is the sub-list for method output_type
27, // [27:27] is the sub-list for method input_type
27, // [27:27] is the sub-list for extension type_name
27, // [27:27] is the sub-list for extension extendee
0, // [0:27] is the sub-list for field type_name
}
func init() { file_teleport_legacy_client_proto_inventory_proto_init() }
@@ -300,8 +300,10 @@ type SSHIdentity struct {
// When present, AllowedResourceAccessIDs should be treated as authoritative
// (ResourceIDs can be derived by mapping to ResourceAccessID.id).
AllowedResourceAccessIds []*types.ResourceAccessID `protobuf:"bytes,37,rep,name=allowed_resource_access_ids,json=allowedResourceAccessIds,proto3" json:"allowed_resource_access_ids,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
// The hash of the immutable labels assigned to the identity.
ImmutableLabelHash string `protobuf:"bytes,38,opt,name=immutable_label_hash,json=immutableLabelHash,proto3" json:"immutable_label_hash,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *SSHIdentity) Reset() {
@@ -593,6 +595,13 @@ func (x *SSHIdentity) GetAllowedResourceAccessIds() []*types.ResourceAccessID {
return nil
}
func (x *SSHIdentity) GetImmutableLabelHash() string {
if x != nil {
return x.ImmutableLabelHash
}
return ""
}
// CertExtension represents a key/value for a certificate extension. This type must
// be kept up to date with types.CertExtension.
type CertExtension struct {
@@ -678,7 +687,7 @@ const file_teleport_decision_v1alpha1_ssh_identity_proto_rawDesc = "" +
"-teleport/decision/v1alpha1/ssh_identity.proto\x12\x1ateleport.decision.v1alpha1\x1a\x1fgoogle/protobuf/timestamp.proto\x1a-teleport/decision/v1alpha1/tls_identity.proto\x1a%teleport/legacy/types/resources.proto\x1a\x1fteleport/scopes/v1/scopes.proto\x1a\x1dteleport/trait/v1/trait.proto\"X\n" +
"\fSSHAuthority\x12!\n" +
"\fcluster_name\x18\x01 \x01(\tR\vclusterName\x12%\n" +
"\x0eauthority_type\x18\x02 \x01(\tR\rauthorityType\"\xe8\f\n" +
"\x0eauthority_type\x18\x02 \x01(\tR\rauthorityType\"\x9a\r\n" +
"\vSSHIdentity\x12\x1f\n" +
"\vvalid_after\x18\x01 \x01(\x04R\n" +
"validAfter\x12!\n" +
@@ -725,7 +734,8 @@ const file_teleport_decision_v1alpha1_ssh_identity_proto_rawDesc = "" +
"\tscope_pin\x18# \x01(\v2\x17.teleport.scopes.v1.PinR\bscopePin\x12\x1f\n" +
"\vagent_scope\x18$ \x01(\tR\n" +
"agentScope\x12V\n" +
"\x1ballowed_resource_access_ids\x18% \x03(\v2\x17.types.ResourceAccessIDR\x18allowedResourceAccessIds\"\xbf\x01\n" +
"\x1ballowed_resource_access_ids\x18% \x03(\v2\x17.types.ResourceAccessIDR\x18allowedResourceAccessIds\x120\n" +
"\x14immutable_label_hash\x18& \x01(\tR\x12immutableLabelHash\"\xbf\x01\n" +
"\rCertExtension\x12A\n" +
"\x04type\x18\x01 \x01(\x0e2-.teleport.decision.v1alpha1.CertExtensionTypeR\x04type\x12A\n" +
"\x04mode\x18\x02 \x01(\x0e2-.teleport.decision.v1alpha1.CertExtensionModeR\x04mode\x12\x12\n" +
@@ -21,6 +21,7 @@
package joinv1
import (
v1 "github.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1"
protoreflect "google.golang.org/protobuf/reflect/protoreflect"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
timestamppb "google.golang.org/protobuf/types/known/timestamppb"
@@ -2553,9 +2554,11 @@ type HostResult struct {
// Certificates holds issued certificates and cluster CAs.
Certificates *Certificates `protobuf:"bytes,1,opt,name=certificates,proto3" json:"certificates,omitempty"`
// HostId is the unique ID assigned to the host.
HostId string `protobuf:"bytes,2,opt,name=host_id,json=hostId,proto3" json:"host_id,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
HostId string `protobuf:"bytes,2,opt,name=host_id,json=hostId,proto3" json:"host_id,omitempty"`
// The immutable labels assigned to the host by their join token.
ImmutableLabels *v1.ImmutableLabels `protobuf:"bytes,3,opt,name=immutable_labels,json=immutableLabels,proto3" json:"immutable_labels,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *HostResult) Reset() {
@@ -2602,6 +2605,13 @@ func (x *HostResult) GetHostId() string {
return ""
}
func (x *HostResult) GetImmutableLabels() *v1.ImmutableLabels {
if x != nil {
return x.ImmutableLabels
}
return nil
}
// HostResult holds results for bot joining.
type BotResult struct {
state protoimpl.MessageState `protogen:"open.v1"`
@@ -2826,7 +2836,7 @@ var File_teleport_join_v1_joinservice_proto protoreflect.FileDescriptor
const file_teleport_join_v1_joinservice_proto_rawDesc = "" +
"\n" +
"\"teleport/join/v1/joinservice.proto\x12\x10teleport.join.v1\x1a\x1fgoogle/protobuf/timestamp.proto\"\xa0\x03\n" +
"\"teleport/join/v1/joinservice.proto\x12\x10teleport.join.v1\x1a\x1fgoogle/protobuf/timestamp.proto\x1a&teleport/scopes/joining/v1/token.proto\"\xa0\x03\n" +
"\n" +
"ClientInit\x12$\n" +
"\vjoin_method\x18\x01 \x01(\tH\x00R\n" +
@@ -2992,11 +3002,12 @@ const file_teleport_join_v1_joinservice_proto_rawDesc = "" +
"\ftls_ca_certs\x18\x02 \x03(\fR\n" +
"tlsCaCerts\x12\x19\n" +
"\bssh_cert\x18\x03 \x01(\fR\asshCert\x12\x1e\n" +
"\vssh_ca_keys\x18\x04 \x03(\fR\tsshCaKeys\"i\n" +
"\vssh_ca_keys\x18\x04 \x03(\fR\tsshCaKeys\"\xc1\x01\n" +
"\n" +
"HostResult\x12B\n" +
"\fcertificates\x18\x01 \x01(\v2\x1e.teleport.join.v1.CertificatesR\fcertificates\x12\x17\n" +
"\ahost_id\x18\x02 \x01(\tR\x06hostId\"\xc5\x01\n" +
"\ahost_id\x18\x02 \x01(\tR\x06hostId\x12V\n" +
"\x10immutable_labels\x18\x03 \x01(\v2+.teleport.scopes.joining.v1.ImmutableLabelsR\x0fimmutableLabels\"\xc5\x01\n" +
"\tBotResult\x12B\n" +
"\fcertificates\x18\x01 \x01(\v2\x1e.teleport.join.v1.CertificatesR\fcertificates\x12[\n" +
"\x14bound_keypair_result\x18\x02 \x01(\v2$.teleport.join.v1.BoundKeypairResultH\x00R\x12boundKeypairResult\x88\x01\x01B\x17\n" +
@@ -3063,6 +3074,7 @@ var file_teleport_join_v1_joinservice_proto_goTypes = []any{
(*JoinResponse)(nil), // 36: teleport.join.v1.JoinResponse
(*ClientInit_ProxySuppliedParams)(nil), // 37: teleport.join.v1.ClientInit.ProxySuppliedParams
(*timestamppb.Timestamp)(nil), // 38: google.protobuf.Timestamp
(*v1.ImmutableLabels)(nil), // 39: teleport.scopes.joining.v1.ImmutableLabels
}
var file_teleport_join_v1_joinservice_proto_depIdxs = []int32{
37, // 0: teleport.join.v1.ClientInit.proxy_supplied_parameters:type_name -> teleport.join.v1.ClientInit.ProxySuppliedParams
@@ -3106,18 +3118,19 @@ var file_teleport_join_v1_joinservice_proto_depIdxs = []int32{
34, // 38: teleport.join.v1.Result.host_result:type_name -> teleport.join.v1.HostResult
35, // 39: teleport.join.v1.Result.bot_result:type_name -> teleport.join.v1.BotResult
33, // 40: teleport.join.v1.HostResult.certificates:type_name -> teleport.join.v1.Certificates
33, // 41: teleport.join.v1.BotResult.certificates:type_name -> teleport.join.v1.Certificates
13, // 42: teleport.join.v1.BotResult.bound_keypair_result:type_name -> teleport.join.v1.BoundKeypairResult
30, // 43: teleport.join.v1.JoinResponse.init:type_name -> teleport.join.v1.ServerInit
31, // 44: teleport.join.v1.JoinResponse.challenge:type_name -> teleport.join.v1.Challenge
32, // 45: teleport.join.v1.JoinResponse.result:type_name -> teleport.join.v1.Result
29, // 46: teleport.join.v1.JoinService.Join:input_type -> teleport.join.v1.JoinRequest
36, // 47: teleport.join.v1.JoinService.Join:output_type -> teleport.join.v1.JoinResponse
47, // [47:48] is the sub-list for method output_type
46, // [46:47] is the sub-list for method input_type
46, // [46:46] is the sub-list for extension type_name
46, // [46:46] is the sub-list for extension extendee
0, // [0:46] is the sub-list for field type_name
39, // 41: teleport.join.v1.HostResult.immutable_labels:type_name -> teleport.scopes.joining.v1.ImmutableLabels
33, // 42: teleport.join.v1.BotResult.certificates:type_name -> teleport.join.v1.Certificates
13, // 43: teleport.join.v1.BotResult.bound_keypair_result:type_name -> teleport.join.v1.BoundKeypairResult
30, // 44: teleport.join.v1.JoinResponse.init:type_name -> teleport.join.v1.ServerInit
31, // 45: teleport.join.v1.JoinResponse.challenge:type_name -> teleport.join.v1.Challenge
32, // 46: teleport.join.v1.JoinResponse.result:type_name -> teleport.join.v1.Result
29, // 47: teleport.join.v1.JoinService.Join:input_type -> teleport.join.v1.JoinRequest
36, // 48: teleport.join.v1.JoinService.Join:output_type -> teleport.join.v1.JoinResponse
48, // [48:49] is the sub-list for method output_type
47, // [47:48] is the sub-list for method input_type
47, // [47:47] is the sub-list for extension type_name
47, // [47:47] is the sub-list for extension extendee
0, // [0:47] is the sub-list for field type_name
}
func init() { file_teleport_join_v1_joinservice_proto_init() }
@@ -155,9 +155,12 @@ type ScopedTokenSpec struct {
// The usage mode of the token. Can be "single_use" or "unlimited". Single use
// tokens can only be used to provision a single resource. Unlimited tokens
// can be be used to provision any number of resources until it expires.
UsageMode string `protobuf:"bytes,4,opt,name=usage_mode,json=usageMode,proto3" json:"usage_mode,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
UsageMode string `protobuf:"bytes,4,opt,name=usage_mode,json=usageMode,proto3" json:"usage_mode,omitempty"`
// Immutable labels that should be applied to any resulting resources provisioned
// using this token.
ImmutableLabels *ImmutableLabels `protobuf:"bytes,5,opt,name=immutable_labels,json=immutableLabels,proto3" json:"immutable_labels,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *ScopedTokenSpec) Reset() {
@@ -218,6 +221,13 @@ func (x *ScopedTokenSpec) GetUsageMode() string {
return ""
}
func (x *ScopedTokenSpec) GetImmutableLabels() *ImmutableLabels {
if x != nil {
return x.ImmutableLabels
}
return nil
}
// The host certificate parameters that should be cached and leveraged for
// token reuse
type HostCertParams struct {
@@ -502,6 +512,52 @@ func (x *ScopedTokenStatus) GetUsage() *UsageStatus {
return nil
}
// A set of configurations for immutable labels.
type ImmutableLabels struct {
state protoimpl.MessageState `protogen:"open.v1"`
// Labels that should be applied to SSH nodes.
Ssh map[string]string `protobuf:"bytes,1,rep,name=ssh,proto3" json:"ssh,omitempty" protobuf_key:"bytes,1,opt,name=key" protobuf_val:"bytes,2,opt,name=value"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *ImmutableLabels) Reset() {
*x = ImmutableLabels{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[6]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *ImmutableLabels) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*ImmutableLabels) ProtoMessage() {}
func (x *ImmutableLabels) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[6]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use ImmutableLabels.ProtoReflect.Descriptor instead.
func (*ImmutableLabels) Descriptor() ([]byte, []int) {
return file_teleport_scopes_joining_v1_token_proto_rawDescGZIP(), []int{6}
}
func (x *ImmutableLabels) GetSsh() map[string]string {
if x != nil {
return x.Ssh
}
return nil
}
var File_teleport_scopes_joining_v1_token_proto protoreflect.FileDescriptor
const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
@@ -514,14 +570,15 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
"\bmetadata\x18\x04 \x01(\v2\x1c.teleport.header.v1.MetadataR\bmetadata\x12\x14\n" +
"\x05scope\x18\x05 \x01(\tR\x05scope\x12?\n" +
"\x04spec\x18\x06 \x01(\v2+.teleport.scopes.joining.v1.ScopedTokenSpecR\x04spec\x12E\n" +
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\x8e\x01\n" +
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\xe6\x01\n" +
"\x0fScopedTokenSpec\x12%\n" +
"\x0eassigned_scope\x18\x01 \x01(\tR\rassignedScope\x12\x14\n" +
"\x05roles\x18\x02 \x03(\tR\x05roles\x12\x1f\n" +
"\vjoin_method\x18\x03 \x01(\tR\n" +
"joinMethod\x12\x1d\n" +
"\n" +
"usage_mode\x18\x04 \x01(\tR\tusageMode\"\xb6\x01\n" +
"usage_mode\x18\x04 \x01(\tR\tusageMode\x12V\n" +
"\x10immutable_labels\x18\x05 \x01(\v2+.teleport.scopes.joining.v1.ImmutableLabelsR\x0fimmutableLabels\"\xb6\x01\n" +
"\x0eHostCertParams\x12\x17\n" +
"\ahost_id\x18\x01 \x01(\tR\x06hostId\x12\x1b\n" +
"\tnode_name\x18\x02 \x01(\tR\bnodeName\x12\x12\n" +
@@ -539,7 +596,12 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
"\x06status\"j\n" +
"\x11ScopedTokenStatus\x12\x16\n" +
"\x06secret\x18\x01 \x01(\tR\x06secret\x12=\n" +
"\x05usage\x18\x02 \x01(\v2'.teleport.scopes.joining.v1.UsageStatusR\x05usageBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
"\x05usage\x18\x02 \x01(\v2'.teleport.scopes.joining.v1.UsageStatusR\x05usage\"\x91\x01\n" +
"\x0fImmutableLabels\x12F\n" +
"\x03ssh\x18\x01 \x03(\v24.teleport.scopes.joining.v1.ImmutableLabels.SshEntryR\x03ssh\x1a6\n" +
"\bSshEntry\x12\x10\n" +
"\x03key\x18\x01 \x01(\tR\x03key\x12\x14\n" +
"\x05value\x18\x02 \x01(\tR\x05value:\x028\x01BYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
var (
file_teleport_scopes_joining_v1_token_proto_rawDescOnce sync.Once
@@ -553,7 +615,7 @@ func file_teleport_scopes_joining_v1_token_proto_rawDescGZIP() []byte {
return file_teleport_scopes_joining_v1_token_proto_rawDescData
}
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 6)
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 8)
var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
(*ScopedToken)(nil), // 0: teleport.scopes.joining.v1.ScopedToken
(*ScopedTokenSpec)(nil), // 1: teleport.scopes.joining.v1.ScopedTokenSpec
@@ -561,23 +623,27 @@ var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
(*SingleUseStatus)(nil), // 3: teleport.scopes.joining.v1.SingleUseStatus
(*UsageStatus)(nil), // 4: teleport.scopes.joining.v1.UsageStatus
(*ScopedTokenStatus)(nil), // 5: teleport.scopes.joining.v1.ScopedTokenStatus
(*v1.Metadata)(nil), // 6: teleport.header.v1.Metadata
(*timestamppb.Timestamp)(nil), // 7: google.protobuf.Timestamp
(*ImmutableLabels)(nil), // 6: teleport.scopes.joining.v1.ImmutableLabels
nil, // 7: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
(*v1.Metadata)(nil), // 8: teleport.header.v1.Metadata
(*timestamppb.Timestamp)(nil), // 9: google.protobuf.Timestamp
}
var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
6, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
1, // 1: teleport.scopes.joining.v1.ScopedToken.spec:type_name -> teleport.scopes.joining.v1.ScopedTokenSpec
5, // 2: teleport.scopes.joining.v1.ScopedToken.status:type_name -> teleport.scopes.joining.v1.ScopedTokenStatus
7, // 3: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
7, // 4: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
2, // 5: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
3, // 6: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
4, // 7: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
8, // [8:8] is the sub-list for method output_type
8, // [8:8] is the sub-list for method input_type
8, // [8:8] is the sub-list for extension type_name
8, // [8:8] is the sub-list for extension extendee
0, // [0:8] is the sub-list for field type_name
8, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
1, // 1: teleport.scopes.joining.v1.ScopedToken.spec:type_name -> teleport.scopes.joining.v1.ScopedTokenSpec
5, // 2: teleport.scopes.joining.v1.ScopedToken.status:type_name -> teleport.scopes.joining.v1.ScopedTokenStatus
6, // 3: teleport.scopes.joining.v1.ScopedTokenSpec.immutable_labels:type_name -> teleport.scopes.joining.v1.ImmutableLabels
9, // 4: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
9, // 5: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
2, // 6: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
3, // 7: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
4, // 8: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
7, // 9: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
10, // [10:10] is the sub-list for method output_type
10, // [10:10] is the sub-list for method input_type
10, // [10:10] is the sub-list for extension type_name
10, // [10:10] is the sub-list for extension extendee
0, // [0:10] is the sub-list for field type_name
}
func init() { file_teleport_scopes_joining_v1_token_proto_init() }
@@ -594,7 +660,7 @@ func file_teleport_scopes_joining_v1_token_proto_init() {
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
RawDescriptor: unsafe.Slice(unsafe.StringData(file_teleport_scopes_joining_v1_token_proto_rawDesc), len(file_teleport_scopes_joining_v1_token_proto_rawDesc)),
NumEnums: 0,
NumMessages: 6,
NumMessages: 8,
NumExtensions: 0,
NumServices: 0,
},
@@ -176,6 +176,9 @@ message SSHIdentity {
// When present, AllowedResourceAccessIDs should be treated as authoritative
// (ResourceIDs can be derived by mapping to ResourceAccessID.id).
repeated types.ResourceAccessID allowed_resource_access_ids = 37;
// The hash of the immutable labels assigned to the identity.
string immutable_label_hash = 38;
}
// CertExtensionMode specifies the type of extension to use in the cert. This type
@@ -17,6 +17,7 @@ syntax = "proto3";
package teleport.join.v1;
import "google/protobuf/timestamp.proto";
import "teleport/scopes/joining/v1/token.proto";
option go_package = "github.com/gravitational/teleport/api/gen/proto/go/teleport/join/v1;joinv1";
@@ -493,6 +494,8 @@ message HostResult {
Certificates certificates = 1;
// HostId is the unique ID assigned to the host.
string host_id = 2;
// The immutable labels assigned to the host by their join token.
teleport.scopes.joining.v1.ImmutableLabels immutable_labels = 3;
}
// HostResult holds results for bot joining.
@@ -21,6 +21,7 @@ package proto;
import "google/protobuf/timestamp.proto";
import "teleport/legacy/types/types.proto";
import "teleport/presence/v1/relay_server.proto";
import "teleport/scopes/joining/v1/token.proto";
option go_package = "github.com/gravitational/teleport/api/client/proto";
@@ -102,6 +103,9 @@ message UpstreamInventoryHello {
// The advertized scope of the instance. An instance's scope can not change once assigned, so future
// heartbeats must include a scope value matching the one declared in the hello message.
string scope = 9;
// The immutable labels reported by the instance. The hash of these labels is expected to match
// the hash included in the instance's certificate.
teleport.scopes.joining.v1.ImmutableLabels immutable_labels = 10;
}
// UpstreamInventoryAgentMetadata is the message sent up the inventory control stream containing
@@ -952,6 +952,9 @@ message ServerSpecV2 {
// component_features represents features supported by this server
teleport.componentfeatures.v1.ComponentFeatures component_features = 18;
// The immutable labels assigned to the server when joining. The hash of these labels
// is expected to match the hash included in the server's certificate.
map<string, string> immutable_labels = 19;
reserved 8;
reserved 10;
reserved "KubernetesClusters";
@@ -66,6 +66,10 @@ message ScopedTokenSpec {
// tokens can only be used to provision a single resource. Unlimited tokens
// can be be used to provision any number of resources until it expires.
string usage_mode = 4;
// Immutable labels that should be applied to any resulting resources provisioned
// using this token.
ImmutableLabels immutable_labels = 5;
}
// The host certificate parameters that should be cached and leveraged for
@@ -114,3 +118,9 @@ message ScopedTokenStatus {
// The usage status of the scoped token.
UsageStatus usage = 2;
}
// A set of configurations for immutable labels.
message ImmutableLabels {
// Labels that should be applied to SSH nodes.
map<string, string> ssh = 1;
}
+2372 -2210
View File
File diff suppressed because it is too large Load Diff
@@ -33,6 +33,7 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|cloud_metadata|[object](#speccloud_metadata)|CloudMetadata contains info about the cloud instance the server is running on, if any.|
|github|[object](#specgithub)|GitHub contains info about GitHub proxies where each server represents a GitHub organization.|
|hostname|string|Hostname is server hostname|
|immutable_labels|[object](#specimmutable_labels)|The immutable labels assigned to the server when joining. The hash of these labels is expected to match the hash included in the server's certificate.|
|peer_addr|string|PeerAddr is the address a proxy server is reachable at by its peer proxies.|
|proxy_ids|[]string|ProxyIDs is a list of proxy IDs this server is expected to be connected to.|
|public_addrs|[]string|PublicAddrs is a list of public addresses where this server can be reached.|
@@ -66,6 +67,13 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|integration|string|Integration is the integration that is associated with this Server.|
|organization|string|Organization specifies the name of the organization for the GitHub integration.|
### spec.immutable_labels
|Field|Type|Description|
|---|---|---|
|key|string||
|value|string||
### spec.rotation
|Field|Type|Description|
@@ -33,6 +33,7 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|cloud_metadata|[object](#speccloud_metadata)|CloudMetadata contains info about the cloud instance the server is running on, if any.|
|github|[object](#specgithub)|GitHub contains info about GitHub proxies where each server represents a GitHub organization.|
|hostname|string|Hostname is server hostname|
|immutable_labels|[object](#specimmutable_labels)|The immutable labels assigned to the server when joining. The hash of these labels is expected to match the hash included in the server's certificate.|
|peer_addr|string|PeerAddr is the address a proxy server is reachable at by its peer proxies.|
|proxy_ids|[]string|ProxyIDs is a list of proxy IDs this server is expected to be connected to.|
|public_addrs|[]string|PublicAddrs is a list of public addresses where this server can be reached.|
@@ -66,6 +67,13 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|integration|string|Integration is the integration that is associated with this Server.|
|organization|string|Organization specifies the name of the organization for the GitHub integration.|
### spec.immutable_labels
|Field|Type|Description|
|---|---|---|
|key|string||
|value|string||
### spec.rotation
|Field|Type|Description|
@@ -96,6 +96,7 @@ Optional:
- `cloud_metadata` (Attributes) CloudMetadata contains info about the cloud instance the server is running on, if any. (see [below for nested schema](#nested-schema-for-speccloud_metadata))
- `github` (Attributes) GitHub contains info about GitHub proxies where each server represents a GitHub organization. (see [below for nested schema](#nested-schema-for-specgithub))
- `hostname` (String) Hostname is server hostname
- `immutable_labels` (Map of String) The immutable labels assigned to the server when joining. The hash of these labels is expected to match the hash included in the server's certificate.
- `peer_addr` (String) PeerAddr is the address a proxy server is reachable at by its peer proxies.
- `proxy_ids` (List of String) ProxyIDs is a list of proxy IDs this server is expected to be connected to.
- `public_addrs` (List of String) PublicAddrs is a list of public addresses where this server can be reached.
@@ -104,6 +104,17 @@ spec:
hostname:
description: Hostname is server hostname
type: string
immutable_labels:
description: The immutable labels assigned to the server when joining.
The hash of these labels is expected to match the hash included
in the server's certificate.
nullable: true
properties:
key:
type: string
value:
type: string
type: object
peer_addr:
description: PeerAddr is the address a proxy server is reachable at
by its peer proxies.
@@ -103,6 +103,17 @@ spec:
hostname:
description: Hostname is server hostname
type: string
immutable_labels:
description: The immutable labels assigned to the server when joining.
The hash of these labels is expected to match the hash included
in the server's certificate.
nullable: true
properties:
key:
type: string
value:
type: string
type: object
peer_addr:
description: PeerAddr is the address a proxy server is reachable at
by its peer proxies.
@@ -104,6 +104,17 @@ spec:
hostname:
description: Hostname is server hostname
type: string
immutable_labels:
description: The immutable labels assigned to the server when joining.
The hash of these labels is expected to match the hash included
in the server's certificate.
nullable: true
properties:
key:
type: string
value:
type: string
type: object
peer_addr:
description: PeerAddr is the address a proxy server is reachable at
by its peer proxies.
@@ -103,6 +103,17 @@ spec:
hostname:
description: Hostname is server hostname
type: string
immutable_labels:
description: The immutable labels assigned to the server when joining.
The hash of these labels is expected to match the hash included
in the server's certificate.
nullable: true
properties:
key:
type: string
value:
type: string
type: object
peer_addr:
description: PeerAddr is the address a proxy server is reachable at
by its peer proxies.
@@ -728,6 +728,11 @@ func GenSchemaServerV2(ctx context.Context) (github_com_hashicorp_terraform_plug
Optional: true,
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"immutable_labels": {
Description: "The immutable labels assigned to the server when joining. The hash of these labels is expected to match the hash included in the server's certificate.",
Optional: true,
Type: github_com_hashicorp_terraform_plugin_framework_types.MapType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
},
"peer_addr": {
Description: "PeerAddr is the address a proxy server is reachable at by its peer proxies.",
Optional: true,
@@ -10833,6 +10838,33 @@ func CopyServerV2FromTerraform(_ context.Context, tf github_com_hashicorp_terraf
}
}
}
{
a, ok := tf.Attrs["immutable_labels"]
if !ok {
diags.Append(attrReadMissingDiag{"ServerV2.Spec.immutable_labels"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.Map)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ServerV2.Spec.immutable_labels", "github.com/hashicorp/terraform-plugin-framework/types.Map"})
} else {
obj.ImmutableLabels = make(map[string]string, len(v.Elems))
if !v.Null && !v.Unknown {
for k, a := range v.Elems {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ServerV2.Spec.immutable_labels", "github_com_hashicorp_terraform_plugin_framework_types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.ImmutableLabels[k] = t
}
}
}
}
}
}
}
}
}
@@ -11993,6 +12025,56 @@ func CopyServerV2ToTerraform(ctx context.Context, obj *github_com_gravitational_
}
}
}
{
a, ok := tf.AttrTypes["immutable_labels"]
if !ok {
diags.Append(attrWriteMissingDiag{"ServerV2.Spec.immutable_labels"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.MapType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ServerV2.Spec.immutable_labels", "github.com/hashicorp/terraform-plugin-framework/types.MapType"})
} else {
c, ok := tf.Attrs["immutable_labels"].(github_com_hashicorp_terraform_plugin_framework_types.Map)
if !ok {
c = github_com_hashicorp_terraform_plugin_framework_types.Map{
ElemType: o.ElemType,
Elems: make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.ImmutableLabels)),
Null: true,
}
} else {
if c.Elems == nil {
c.Elems = make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.ImmutableLabels))
}
}
if obj.ImmutableLabels != nil {
t := o.ElemType
for k, a := range obj.ImmutableLabels {
v, ok := tf.Attrs["immutable_labels"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"ServerV2.Spec.immutable_labels", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ServerV2.Spec.immutable_labels", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
v.Null = false
}
v.Value = string(a)
v.Unknown = false
c.Elems[k] = v
}
if len(obj.ImmutableLabels) > 0 {
c.Null = false
}
}
c.Unknown = false
tf.Attrs["immutable_labels"] = c
}
}
}
}
v.Unknown = false
tf.Attrs["spec"] = v