This fixes a corner case where a docs review who submits a PR that
touches code or examples is treated as an external author instead
of an internal employee.
Fixes#14577
Update the guide and make it easier to use:
- Give this guide the structure of the Slack guide, adding stepped
headings and a section on configuring Access Requests, to make this
guide easier to follow step by step.
- Add the initial Access Request RBAC setup as a partial
- Indicate that this has been tested with Mattermost v7.0.1
- Add clarity tweaks throughout
- Update the instructions for editing the plugin configuration. The
configuration fields have changed since guide was written.
An earlier commit erroneously removed the /user-manual redirect, causing
404s for several pages on the goteleport site that still point to this
outdated URL. This change reinstates the redirect.
* Add Machine ID Kubernetes guide and partial Apps guide
* Small wording tweaks to the k8s guide
* Rename menu titles to match convention
* Fix inaccurate CA cert recommendation on the API access guide
* Tidy up the Kubernetes guide
* Finish up first pass on Apps guide
* Remove empty admonition
* Address review feedback
* Fix doctest lints
* Apply suggestions from code review
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Address a batch of review comments
* Apply suggestions from code review
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Address further review comments
* Apply suggestions from code review
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
The code attempts to wait on an existing download if one is already
in progress rather than starting a concurrent download of the same
session. If this code path runs, we incorrectly defer a call to a
nil function, triggering a panic.
This bug was introduced in #7360.
* Support user traits in impersonated role certificates
* Add param to tctl bots add for specifying logins
* Update comment on desiredAccessInfoForRoleRequest to be mroe accurate
* Update docs for --logins support with Machine ID
* Rearrange bot tests and name them more in-line with standards
* Add test coverage for Server.createBot
* Test role impersonation preserves user traits
* pass traits directly into desiredAccessInfoForRoleRequests
* Drop underscores from test names
* Remove unnecessary initialization of traits
* Address PR comments
* Update docs/pages/machine-id/getting-started.mdx
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Update docs/pages/machine-id/getting-started.mdx
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Update docs/pages/machine-id/getting-started.mdx
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
Fix TLS usage across multiple protocols like SPDY used in `kube exec` or WebSockets for moderated sessions that require HTTP/1.1 as the initial protocol while other requests like get/edit/delete rely on HTTP/2 protocol.
The same `*tls.Config` was reused for mixed protocol, causing several issues including a data race while manipulating `*tls.Config.NextProtos` without any lock.
This commit clones the `*tls.Config` per request to prevent mixups between connection protocols.
Fixes#15076
* Add RBAC instructions for DB tctl auth sign
Fixes#13768
Add a `Details` box to the `tctl auth sign` entry in the Database Access
CLI reference explaining how to set up your user's Teleport roles in
order to enable running `tctl auth sign` for database-specific
certificate formats.
* Update docs/pages/database-access/reference/cli.mdx
Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
* Add instructions for backporting PRs
Our docs contribution guide already includes instructions for
backporting manually, but doesn't document the two automatic backport
method we support: backporting via GitHub labels and backporting via
`make`.
* Respond to PR feedback
* Respond to PR feedback
This change replaces all `Tile`s in the docs with lists of links. This
achieves two things:
- Helps us move toward a more text-focused look and feel for the docs.
See gravitational/docs#93.
- Makes it easier to reorganize the docs. Currently, there's no linting
for internal links in `Tile` hrefs (See gravitational/docs#100).
I used this script to edit each docs page, invoking the script for all
MDX files in docs/pages:
```
gawk '
BEGIN{inopentag=0; indesc=0; desc=""; title=""; href="";}
/<\/?TileSet>/{next;}
/<Tile/ {
inopentag=1;
}
inopentag==1 && /title=/{
title=gensub(/.*title="([^"]+)".*/, "\\1", "g", $0);
}
inopentag==1 && /href=/{
href=gensub(/.*href="([^"]+)".*/, "\\1", "g", $0);
}
inopentag==1 && />/ {
inopentag=0;
indesc=1;
next;
}
indesc==1 && !/<\/Tile/{
gsub(/(\n|\t|\s{2,})/," ",$0);
desc=desc ($0);
next;
}
/<\/Tile/{
print "- [" title "](" href "):" desc;
indesc=0;
desc="";
title="";
href="";
next;
}
inopentag==0 && indesc==0{ print $0 }
' $1 > "$1.tmp";
cat "$1.tmp" > "$1";
rm "$1.tmp";
```
I then cleaned up each file changed by the script and fixed any
incorrect URLs.
Improve the error message for libfido2 error 60 (UV blocked) and automatically
retry error 63 (UV invalid).
libfido2 error 63 happens with some frequency with Yubikey Bio. The biometric
sensor is a bit finicky, so if the finger is a bit off it tends to happen.
Fixes#13900.
* Simulate libfido2 errors 60 and 63
* Add better handling for common libfido2 errors
Websockets are a message-based protocol, but our combination of
an io.Writer wrapper and io.Copy means some TDP messages may
get broken up and emitted as separate message events in the browser.
Our UI assumes that each 'message' event is a single TDP message,
so we make sure that each TDP message we send corresponds to a
single WriteMessage call.
For Teleport Discover, the user will be able to test connecting to a
resource right after adding it.
The flow should look like this:
- User selects the resource type - in this case Server/Nodes
- WebUI generates a new Token
- WebUI shows the `sudo bash .../<token>/install.sh` to the user
- When the user runs this command, and assuming everything works out,
the WebUI should be able to receive the Server/Node that was
generated from that specific Token.
To achieve this, here's a more detailed flow, which this PR implements
- User selects the resource type - in this case Server/Nodes
- WebUI generates a new Token
This generates a Provision Token which contains a RefResourceID
WebUI receives back that ID
- WebUI shows the `sudo bash .../<token>/install.sh` to the user
This generates a script which includes setting the labels as part of
the `teleport configure` command:
`$ teleport configure ... --labels teleport.internal/resource-id=<refResourceID> ...`
- User runs the provided command on the target host
- WebUI should be able to query the Servers/Nodes which contain that
specific `<resource-id>` and allow the user to connect to it.
Demo:
