Commit Graph
25 Commits
Author SHA1 Message Date
Zac Bergquist 44a6bb1933 Use pkg slices from the standard library (#35905)
Prefer the stdlib version of the experimental package.
Includes a depguard update to prevent future regressions,
as well as an e-ref update to appease depguard.

Generated with:

    $ gofmt -w -r '"golang.org/x/exp/slices" -> "slices"' . && \
        make fix-imports
2023-12-19 23:06:53 +00:00
rosstimothy 9be0b678c3 Add latency diagnostic to tsh (#35679)
The new `tsh latency` command allows visualizing latency to
resources in real time. Currently, supported is limited to SSH
instances, but may be extended to anything that implements a
`latency.Pinger` to support other protocols in the future.
2023-12-19 20:55:17 +00:00
Noah Stride 634de05c42 Remove Dialer(client.Config) from Credential interface (#34833)
* Remove `Dialer(client.Config)` from Credential interface

* Re-add support for address-less configuration

* Only use profile address if none are explicitly provided

* Try all methods with credential provided address

* Fall back to address from credential

* Remove log message

* Adjust log message

* Spell explicitly correctly

* Formalize CredentialsWithDefaultAddrs interface

* GetDefaultAddrs -> DefaultAddrs
2023-11-29 08:43:07 +00:00
dependabot[bot]andTim Ross 286ae03314 Bump the go group in /api with 6 updates (#34488)
* Bump the go group in /api with 6 updates

Bumps the go group in /api with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.45.0` | `0.46.0` |
| [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.45.0` | `0.46.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace](https://github.com/open-telemetry/opentelemetry-go) | `1.19.0` | `1.20.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc](https://github.com/open-telemetry/opentelemetry-go) | `1.19.0` | `1.20.0` |
| [golang.org/x/crypto](https://github.com/golang/crypto) | `0.14.0` | `0.15.0` |
| [golang.org/x/net](https://github.com/golang/net) | `0.17.0` | `0.18.0` |


Updates `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc` from 0.45.0 to 0.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-go-contrib/compare/zpages/v0.45.0...zpages/v0.46.0)

Updates `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` from 0.45.0 to 0.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-go-contrib/compare/zpages/v0.45.0...zpages/v0.46.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace` from 1.19.0 to 1.20.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.19.0...v1.20.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc` from 1.19.0 to 1.20.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.19.0...v1.20.0)

Updates `golang.org/x/crypto` from 0.14.0 to 0.15.0
- [Commits](https://github.com/golang/crypto/compare/v0.14.0...v0.15.0)

Updates `golang.org/x/net` from 0.17.0 to 0.18.0
- [Commits](https://github.com/golang/net/compare/v0.17.0...v0.18.0)

---
updated-dependencies:
- dependency-name: go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/crypto
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/net
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>

* Ignore otelgrpc deprecation notices

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Tim Ross <tim.ross@goteleport.com>
2023-11-13 20:15:09 +00:00
rosstimothy d5a796c056 Enable testify lint (#34222)
Updates our golangci-lint configuration to enable testifylint and
fixes all issues found.

Bump e ref to include gravitational/teleport.e#2567
2023-11-06 20:38:38 +00:00
Anton Miniailo 0111c24b1e Add PROXY header getter to the grpc proxy client (#31992) 2023-09-18 21:36:06 +00:00
Brian Joerger cf6473feb9 Add gRPC error interceptors to API client (#30578)
* Move gRPC error intercetpors to api/utils/grpc/interceptors.

* Use error interceptors in api client and mock server.

* Apply suggestions from CR.

* Unwrap FromGRPC errors in middleware.

* Use gRPC auth service in tests instead of external example service.

* It's gRPC!!!

* Fix unit test.

* Add error interceptor to proxy client.

* Fix merge conflict.
2023-08-24 23:27:06 +00:00
rosstimothy ff6a81a8bd Removes support for legacy ssh connections to the Proxy (#30043)
In preparation for v14 we can remove support for SSH connections
to the Proxy from the `api/proxy.Client` since all supported instances
should all be serving the TransportService.
2023-08-09 02:10:44 +00:00
rosstimothy 8f23cd40ad Use web address when appropriate for a jump host (#25237)
* Use web address when appropriate for a jump hosts

Determines whether the jump host provided via `tsh ssh -J` is belongs
to the Proxy SSH or Web server to ensure when using jump hosts that
connections are established directly on the target cluster.

Closes #25178

* Modify tsh tests to capture issues with jump hosts

Alters the root and leaf cluster and node names used by tsh tests
so that the root cluster is named `root` instead of `localhost` and
sets a unique `NodeName` for each cluster instead of reusing
`localnode` for both. This was masking problems in jump hosts tests
by connecting to the node in the root cluster instead of the leaf
cluster.

Some additional changes to tsh tests were made as a result of
changing the cluster and node names.

* fix proxy client tests

* update TestList to login once

* ignore TestList in flaky test detector
2023-05-02 18:03:35 +00:00
rosstimothy b6b57bcfe8 Unify errors returned from ProxyClient when targets are ambiguous (#25004)
Ensures that SSH and gRPC connections via `tsh` return the same
error when dialing a host fails.

Closes #24943
2023-04-21 20:36:47 +00:00
STeve (Xin) Huang b1941aaa85 TLS routing behind LB support for Auth, SSH, Reverse tunnel (#23866)
* ALPN connect test improvements

* fix typos

* remove extra period

* simplify error check

* moving things over

* tsh dials

* reverse tunnel

* fix auth connect

* move ping

* add ssh support

* add HTTP client support

* Move ALPN dialer, ALPN conn upgrade, Ping conn to api

* beatify

* add test

* beautify round 2

* fix timeout

* Implement alpn-ping upgrade for reversetunnel and ssh

* clean up

* fix proxy test

* minor refactor

* remove WebProxyAddr

* require IsALPNConnUpgradeRequiredFunc

* add tlsRoutingWithConnUpgradeConnect

* fix lint

* simplify

* remove debug log and change unknown upgrade type to 404

* Force new proxy client to use web proxy when TLS routing is enabled
2023-04-14 19:22:23 +00:00
rosstimothy a5898a2a99 Convert tsh ssh to use the proxy transport service instead of ssh (#23228)
* Convert tsh ssh to use the proxy transport service instead of ssh

In an effort to reduce latency establishing sessions `tsh ssh` is
migrating away from connecting to the Proxy via SSH in favor of
using gRPC. The SSH handshakes with the Proxy increase latency in
situations where the distance between geolocations of the client
and Proxy are large. TLS handshakes used by the gRPC service have
proven to reduce latency by ~20% in the same scenario.

A new `lib/client.ClusterClient` has been introduced that should
be used instead of `lib/client.ProxyClient` to connect to a Teleport
cluster. Most of the functionality within the `ClusterClient` was
a direct copy from the `ProxyClient`.

The `lib/client.TeleportClient` now has a `ConnectToCluster` method
which will connect to both the Proxy and Auth service via the
`api/client.ProxyClient` which first attempts to use gRPC and reverts
back to SSH to preserve backwards compatability. The `ClusterClient`
should be passed around and reused instead of following the
established pattern of `tc.ConnectToProxy` followed by a
`proxy.ConnectToCluster` to get an `auth.ClientI`.

Additionally some of the `agentless` package was refactored to reduce
dependencies and allow it to work with connections to the Proxy that
originated via gRPC instead of SSH.

Changes to the integration tests are mostly to accomodate IP Pinning
and ensure that it works for both connections established via SSH
and gPRC.

This is the final PR needed to complete #19812.

* fix typos and unify span attributes

* pass node name to ConnectToNode

* simplify jump host resetting
2023-04-04 21:31:39 +00:00
rosstimothy d3276b2caa Make proxy.Client infer the cluster name from Proxy (#23644)
Instead of relying on users to provide the cluster name, the client
now determines the cluster name by inspecting the certificate
presented by the Proxy during the TLS or SSH handshake. This is
required when connecting to a Proxy via a jump host since the
name of the cluster may not match the currently logged in cluster.

This is achieved by leveraging a custom `credentials.TransportCredentials`
when connecting via gRPC and a custom `ssh.HostKeyCallback` when
connecting SSH.
2023-04-03 12:34:43 +00:00
rosstimothy 1427e194af Refactor stream.Source implementations (#23351)
The interface smuggling within `stream.ReadWriter.Close` now checks
for `io.Closer` instead of `grpc.ClientStream` to allow clients
that need to perform additoinal closing logic besides sending a
`CloseSend` message to do so. All existing client implementations
of `stream.Source` now implement `io.Closer` so they are still
cleaned up properly.

The multiplexed ssh streams are now tied together to prevent attempts
to send a message at the same time. In addition, the client ssh
streams have been updated to only send a single `CloseSend` on which
ever protocol is terminated first.
2023-03-22 14:33:16 +00:00
rosstimothy da61e75b36 Reuse a single grpc server in transport client tests (#23148) 2023-03-16 19:44:07 +00:00
rosstimothy 1c3188a38a Add a dedicated client to communicate with the Proxy SSH server (#22629)
A new `api/client/proxy/Client` has been added to interact with
the SSH and gRPC servers that the Proxy serves on its SSH port.
The client will first try connecting to the gRPC server and if
that fails it will fall back to the SSH server.

Much of the SSH functionality mimics the existing behavior of the
`ProxyClient` in `lib/client`. This is the first part of phasing
out that client in favor of the new client. There will be a follow
up PR that migrates `lib/client` to make use of the new client instead.

Part of #19812
2023-03-15 13:41:56 +00:00
rosstimothy fa3bb9ac59 Ensure that the webclient closes connections (#22832)
The `http.Client.Transport` created in `newWebClient` wraps a
chain of `http.RoundTripper` over an underlying `http.Transport`.
Since we cannot guarantee that each `http.RoundTipper` has a
`CloseIdleConnections` method the usage of
`defer clt.CloseIdleConnections()` does not guarantee that the http
connections created during Find/Ping/etc are closed.

To prevent leaking connections implementations of `http.RoundTripper`
have added a `CloseIdleConnections` method added that forwards the
request on to the wrapped interface. The `otelhttp.Transport` does
not implement this method either so care has been taken to wrap it
in a `http.RoundTripper` which will call the root transport in
`enforceCloseIdleConnections`. An upstream issue has been filed
with otelhttp: https://github.com/open-telemetry/opentelemetry-go-contrib/issues/3543
to get the method added to their `Transport` implementation.

This wasn't noticed prior to upgrading to go1.20 becuase prior to
[this](https://github.com/golang/go/commit/4e7e7ae1406c70d9cc0809ec11105a55a60a0b70)
commit the `ReadHeaderTimeout` set on the Proxy web api http.Server
would cause the connection to appear idle and get terminated by the
server.

`TestWebClientClosesIdleConnections` was added to capture the leak
in connections as reported in #22757 and prevent any regressions.
2023-03-10 15:21:16 +00:00
rosstimothy a4da87b1e5 Run TestService_ProxySSH_Errors serially (#22612) 2023-03-07 16:13:53 +00:00
rosstimothy 48fe7172c0 Rename ProxyService to TransportService (#22405)
Changes the name to better align with the naming used by the rest
of the feature and to prevent ambiguity as the term proxy is quite
overloaded. This has not landed in a release yet so there are no
backward compatability concerns as nothing serves or consumes this
api yet.
2023-02-28 18:40:06 +00:00
rosstimothy 9440763235 Implement transport client (#21947)
Provides a client that can be used to connect to and interact with
the transport service in `lib/srv/transport`. The client abstracts
the fact that a gRPC stream is being used for the `net.Conn` created
by `DialCluster` and `DialHost`.

This also moves `lib/utils/grpc/stream` to `api/utils/grpc/stream`
so that the client and server can make use of the same stream
abstractions.

Part of #19812
2023-02-21 14:38:57 +00:00
Vitor Enes d72ac18247 Set extra proxy headers in all tsh HTTP requests (#19766)
Before this commit, the `tsh` HTTP requests that had the extra headers
were those that did not use `roundtrip`.
This commit leverages `http.RoundTripper.RoundTrip` to ensure that all
requests have the the extra headers.
2023-01-11 10:29:05 +00:00
Jakub NyckowskiandAlan Parra 9c80f3802e Enable nolintlint linter (#19406)
* Enable nolintlint linter

* Fix nolint comments in the api package

* Fix RDP client comment

* Address review comment

Co-authored-by: Alan Parra <alan.parra@goteleport.com>

* Allow unused for nolintlint linter

* Remove redundant casting

* Add comment on why allowed unused is enabled

Co-authored-by: Alan Parra <alan.parra@goteleport.com>

Co-authored-by: Alan Parra <alan.parra@goteleport.com>
2022-12-16 21:13:58 +00:00
NajiObeid 2aad238a12 Naji/12220 socks proxy client (#17976)
* add support for clients connecting through a socks proxy

* deps

* fixes nodes joining through socks proxyw

* linting

* linting x2

* linting x3

* address pr comments

* linting

* misspell

* pr comments

* pr comments

* linting and pr comments
2022-11-04 17:40:26 +00:00
Gavin Frazar 1858aafa15 Fix http proxy basic auth (#13140)
* Fix http proxy basic auth

* Update docs about HTTP CONNECT env var formats
2022-06-23 00:27:29 +00:00
Andrew Burke e3a8fb7a0f NO_PROXY port support + special case for proxying via localhost (#11403)
This change updates NO_PROXY handling to allow blocking specific host:port combinations, rather than just the host. It also adds a special case for downgrading requests to plain HTTP when --insecure is true and the request goes through a plain HTTP proxy at localhost (i.e. HTTP_PROXY=http://localhost).
2022-04-04 14:23:50 -07:00