Commit Graph
8925 Commits
Author SHA1 Message Date
Isaiah Becker-Mayer 321d3482dd SharedDirectoryMoveRequest and SharedDirectoryMoveResponse (#14959) 2022-08-14 21:15:49 +00:00
Zac Bergquist eff38e2fa5 bot: don't treat docs reviewers as external authors (#15510)
This fixes a corner case where a docs review who submits a PR that
touches code or examples is treated as an external author instead
of an internal employee.
2022-08-13 20:10:31 +00:00
Nic Klaassen 1a91e9cfd3 Fix inverted check for join_params and auth_token mutual exclusion (#15513) 2022-08-13 17:20:03 +00:00
fheinecke 9ff2df0539 Added docs for new RPM repos (#15268)
* Added docs for new RPM repos

* Fixed typos

* Added/fixed supported version links

* Updated docs to use gpg key in new APT repos
2022-08-13 15:25:49 +00:00
Russell Jones 823bbfcc22 Refactor tests under httplib package.
Refactored all tests under "lib/httplib" to use testify instead
of gocheck.
2022-08-12 17:11:13 -07:00
Paul Gottschling 83fef305cd Edit the Mattermost guide (#15041)
Fixes #14577

Update the guide and make it easier to use:

- Give this guide the structure of the Slack guide, adding stepped
  headings and a section on configuring Access Requests, to make this
  guide easier to follow step by step.
- Add the initial Access Request RBAC setup as a partial
- Indicate that this has been tested with Mattermost v7.0.1
- Add clarity tweaks throughout
- Update the instructions for editing the plugin configuration. The
  configuration fields have changed since guide was written.
2022-08-12 21:46:11 +00:00
Paul Gottschling a95231db08 Add redirect from /user-manual (#15419)
An earlier commit erroneously removed the /user-manual redirect, causing
404s for several pages on the goteleport site that still point to this
outdated URL. This change reinstates the redirect.
2022-08-12 20:55:13 +00:00
Tim BuckleyandPaul Gottschling 1c2c5d07b0 Add Machine ID Kubernetes and Apps guides (#14976)
* Add Machine ID Kubernetes guide and partial Apps guide

* Small wording tweaks to the k8s guide

* Rename menu titles to match convention

* Fix inaccurate CA cert recommendation on the API access guide

* Tidy up the Kubernetes guide

* Finish up first pass on Apps guide

* Remove empty admonition

* Address review feedback

* Fix doctest lints

* Apply suggestions from code review

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>

* Address a batch of review comments

* Apply suggestions from code review

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>

* Address further review comments

* Apply suggestions from code review

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-08-12 19:50:09 +00:00
Steven Martin edc29051ec Remove tctl access ls from cli ref (#15455)
Remove tctl access ls
2022-08-12 18:42:26 +00:00
Joel 669d32bbed Improve K8S session join error propagation (#15242) 2022-08-12 17:31:11 +00:00
Joel f2dd75801a Remove legacy session service (#15155) 2022-08-12 16:39:45 +00:00
Forrest Marshall 51411cf5b9 github releases scraper 2022-08-12 08:15:58 -07:00
Zac Bergquist b1d4d608b2 auditlog: fix panic during concurrent streams of the same session (#15361)
The code attempts to wait on an existing download if one is already
in progress rather than starting a concurrent download of the same
session. If this code path runs, we incorrectly defer a call to a
nil function, triggering a panic.

This bug was introduced in #7360.
2022-08-12 14:47:54 +00:00
Andrew LeFevre 0acf527e8f RFD 74: Add SFTP Support (#13216) 2022-08-12 14:12:50 +00:00
Vitor Enes 1afb7d5832 Use the absolute path of the teleport binary in node join script (#15466) 2022-08-12 13:18:06 +00:00
Noah StrideandPaul Gottschling 7c904714e9 Machine ID support for Logins trait (#15117)
* Support user traits in impersonated role certificates

* Add param to tctl bots add for specifying logins

* Update comment on desiredAccessInfoForRoleRequest to be mroe accurate

* Update docs for --logins support with Machine ID

* Rearrange bot tests and name them more in-line with standards

* Add test coverage for Server.createBot

* Test role impersonation preserves user traits

* pass traits directly into desiredAccessInfoForRoleRequests

* Drop underscores from test names

* Remove unnecessary initialization of traits

* Address PR comments

* Update docs/pages/machine-id/getting-started.mdx

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>

* Update docs/pages/machine-id/getting-started.mdx

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>

* Update docs/pages/machine-id/getting-started.mdx

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-08-12 12:06:38 +00:00
Tiago Silva 9b2a781d6e Fix TLS usage across multiple protocols (#15339)
Fix TLS usage across multiple protocols like SPDY used in `kube exec` or WebSockets for moderated sessions that require HTTP/1.1 as the initial protocol while other requests like get/edit/delete rely on HTTP/2 protocol.

The same `*tls.Config` was reused for mixed protocol, causing several issues including a data race while manipulating `*tls.Config.NextProtos` without any lock.

This commit clones the `*tls.Config` per request to prevent mixups between connection protocols.

Fixes #15076
2022-08-12 11:34:35 +00:00
Reed Loden 0d648f2da8 docs: Improve cloud security/compliance documentation (#15408) 2022-08-12 02:34:11 -07:00
Pierre Beaucamp e3031740bd Update docs to use the latest Cloud version number (#15415) 2022-08-12 03:28:16 +00:00
Joel 92883f4a65 Fix race condition to sessions map in K8S proxy (#15238) 2022-08-11 23:11:13 +00:00
Paul GottschlingandZac Bergquist 941f0fc97e Add RBAC instructions for DB tctl auth sign (#14528)
* Add RBAC instructions for DB tctl auth sign

Fixes #13768

Add a `Details` box to the `tctl auth sign` entry in the Database Access
CLI reference explaining how to set up your user's Teleport roles in
order to enable running `tctl auth sign` for database-specific
certificate formats.

* Update docs/pages/database-access/reference/cli.mdx

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2022-08-11 22:02:52 +00:00
Brian Joerger b19836abe7 Update TestForward (#15321) 2022-08-11 16:57:43 +00:00
Brian Joerger 66a428bcf0 Use Debug flag in aws scripts (#15407)
Wrap set -x with DEBUG check to prevent inadvertently logging secrets, such as join tokens held in the /etc/teleport.d/conf.
2022-08-11 16:32:20 +00:00
Paul Gottschling b368c9824b Add forScopes settings to Access Requests pages (#15134)
These are only applicable for Cloud and Enterprise users, so we don't
want to mislead OSS users with the default scopes.
2022-08-11 16:00:26 +00:00
Paul Gottschling 972e6056dc Add instructions for backporting PRs (#14758)
* Add instructions for backporting PRs

Our docs contribution guide already includes instructions for
backporting manually, but doesn't document the two automatic backport
method we support: backporting via GitHub labels and backporting via
`make`.

* Respond to PR feedback

* Respond to PR feedback
2022-08-11 15:08:58 +00:00
Paul Gottschling 15d5699d92 Add an Email Access Request guide (#15133)
Co-authored-by: Steven Martin <steven@gravitational.com>

Closes #8695
Closes #6438
2022-08-11 14:44:26 +00:00
Noah Stride e65b926791 Remove deprecated GenerateUserCerts HTTP endpoint (#15392) 2022-08-11 10:29:52 +00:00
Roman Tkachenko ae1d39905f [auto] Update webassets in teleport/master from webassets/master (#15405) 2022-08-10 23:30:18 +00:00
Paul Gottschling e3b1c2906e Replace Tile components with lists of links (#15266)
This change replaces all `Tile`s in the docs with lists of links. This
achieves two things:

- Helps us move toward a more text-focused look and feel for the docs.
  See gravitational/docs#93.
- Makes it easier to reorganize the docs. Currently, there's no linting
  for internal links in `Tile` hrefs (See gravitational/docs#100).

I used this script to edit each docs page, invoking the script for all
MDX files in docs/pages:

```
gawk '
    BEGIN{inopentag=0; indesc=0; desc=""; title=""; href="";}
    /<\/?TileSet>/{next;}
    /<Tile/ {
        inopentag=1;
    }
    inopentag==1 && /title=/{
        title=gensub(/.*title="([^"]+)".*/, "\\1", "g", $0);
    }
    inopentag==1 && /href=/{
        href=gensub(/.*href="([^"]+)".*/, "\\1", "g", $0);
    }
    inopentag==1 && />/ {
      inopentag=0;
      indesc=1;
      next;
    }
    indesc==1 && !/<\/Tile/{
        gsub(/(\n|\t|\s{2,})/," ",$0);
	desc=desc ($0);
	next;
    }
    /<\/Tile/{
        print "- [" title "](" href "):" desc;
	indesc=0;
	desc="";
	title="";
	href="";
	next;
    }
    inopentag==0 && indesc==0{ print $0 }

' $1 > "$1.tmp";
cat "$1.tmp" > "$1";
rm "$1.tmp";
```

I then cleaned up each file changed by the script and fixed any
incorrect URLs.
2022-08-10 22:27:31 +00:00
Alan Parra 2d66b86033 Add better handling for common libfido2 errors (#15323)
Improve the error message for libfido2 error 60 (UV blocked) and automatically
retry error 63 (UV invalid).

libfido2 error 63 happens with some frequency with Yubikey Bio. The biometric
sensor is a bit finicky, so if the finger is a bit off it tends to happen.

Fixes #13900.

* Simulate libfido2 errors 60 and 63
* Add better handling for common libfido2 errors
2022-08-10 18:53:56 +00:00
Gabriel Corado c9a899bb45 RFD 81: TLS Ping (#15152) 2022-08-10 18:21:42 +00:00
STeve (Xin) Huang 4aeb9ea441 Documentation for AWS DynamoDB guide (#14319) 2022-08-10 16:34:01 +00:00
Logan Davis baa2bb2e12 Update teleport-operator to use amazon ECR for staging registry. (#15275) 2022-08-10 14:50:37 +00:00
Steven Martin 26ebd8e0c6 IP Address cloud faq update (#15362) 2022-08-10 14:28:09 +00:00
Reed Loden d84374f7f8 Update last report date for SOC 2 report (#15365)
Our latest SOC 2 report just came out today, so updating `soc2.last_report` variable.
2022-08-10 14:09:03 +00:00
Rafał Cieślak a4e35a1ed8 Pick correct cert when signing Connect (#15344) 2022-08-10 13:13:57 +00:00
Ryan Clark 29175e57d3 Use a getter/setter for reading the token value from the config (#14080) 2022-08-10 08:50:21 +00:00
Logan Davis 42f399e573 Update teleport-lab to push to amazon ECR (#15283) 2022-08-09 19:10:42 -05:00
rosstimothy c469a34994 Move prometheus collectors from utils to metrics (#15288) 2022-08-09 17:35:19 +00:00
NajiObeid 7833dc63cb Naji/11867 manual resource joining (#13505)
* improve tsh configure messaging

* missing param

* improve cli output

* remove unnecessary change

* address pr comments

* address pr comments
2022-08-09 15:42:17 +00:00
NajiObeid 787395395a Add config setting for proxy peering public addr (#14905)
* peer proxy public addr config

* address pr comments

* address pr comments

* address pr comments
2022-08-09 15:16:22 +00:00
Edward Dowling be1438aecd tsh: tctl: Add basic recordings ls functionality (#12763) 2022-08-09 11:22:14 +00:00
Rafał Cieślak b367148967 Connect docs: Add section about insecure mode (#15115) 2022-08-09 10:10:00 +00:00
Joel 469e12412d Add support for variable playback speed for Desktop Access recordings (#15124) 2022-08-08 21:37:12 +00:00
Łukasz Kozłowski d5a968adfe Add "RDP connection fail" section to desktop access troubleshooting docs (#13059) 2022-08-08 21:03:23 +00:00
Hugo Shaka 299d1c8301 Document teleport-operator (#14965)
* Document teleport-operator
2022-08-08 20:33:07 +00:00
Zac Bergquist d1c6b0618e Fix lint warnings (#15312)
Mostly duplicated imports and redundant types in struct literals.
2022-08-08 20:20:29 +00:00
Zac Bergquist fc05eaf305 desktop access: send full websocket messages to the browser (#15220)
Websockets are a message-based protocol, but our combination of
an io.Writer wrapper and io.Copy means some TDP messages may
get broken up and emitted as separate message events in the browser.

Our UI assumes that each 'message' event is a single TDP message,
so we make sure that each TDP message we send corresponds to a
single WriteMessage call.
2022-08-08 17:55:24 +00:00
Jakub Nyckowski 19d6207919 Docs fixes in BPF module (#15287) 2022-08-08 17:28:18 +00:00
Marco André Dinis 117d7d2d40 Add Suggested Labels to Provision Tokens (#15114)
For Teleport Discover, the user will be able to test connecting to a
resource right after adding it.

The flow should look like this:
- User selects the resource type - in this case Server/Nodes
- WebUI generates a new Token
- WebUI shows the `sudo bash .../<token>/install.sh` to the user
- When the user runs this command, and assuming everything works out,
  the WebUI should be able to receive the Server/Node that was
  generated from that specific Token.

To achieve this, here's a more detailed flow, which this PR implements
- User selects the resource type - in this case Server/Nodes
- WebUI generates a new Token
  This generates a Provision Token which contains a RefResourceID
  WebUI receives back that ID
- WebUI shows the `sudo bash .../<token>/install.sh` to the user
  This generates a script which includes setting the labels as part of
  the `teleport configure` command:
  `$ teleport configure ... --labels teleport.internal/resource-id=<refResourceID> ...`
- User runs the provided command on the target host
- WebUI should be able to query the Servers/Nodes which contain that
  specific `<resource-id>` and allow the user to connect to it.

Demo:
![image](https://user-images.githubusercontent.com/689271/182440692-97c75ae0-1e14-4f76-b9ff-d41060c73ed0.png)
2022-08-08 17:06:41 +00:00