Commit Graph
355 Commits
Author SHA1 Message Date
Tiago Silva 723043621d sessionsearch[22]: add SearchMode enum to session search protos (#66205)
Adds a `SearchMode` enum to session search protos, allowing clients to choose the search mode that best fits their keywords.

Some searches perform better with embeddings only, while others work better with strict keyword matching. This change lets clients opt into their preferred search method, while keeping hybrid search as the default.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2026-04-27 14:30:35 +00:00
Tiago Silva d28831f04f prevent unauthorized uploads via encrypted recordings service (#66081)
Teleport Auth server allows clients that do not present a certificate to access parts of its API. This deliberate bypass exists to support joining methods or password logins where a user or server does not have a certificate yet but has a secret that can be exchanged for a certificate.

In order to keep the system compatible and reduce the permutations required, Teleport assigned these unauthenticated connections a role called `Nop`. This role has no permissions and the only reason why it exists is so we can still build a context and checker.

This role was historically embedded in a structure called `BuiltinRole`. This struct implements the `Identity` interface and by its documentation is used by teleport services that belong to this particular cluster.

Some of the Auth server handlers are restricted to server identities and the check consists in something like:

```go
	authCtx, err := s.authorizer.Authorize(ctx)
	if err != nil {
		return nil, trace.Wrap(err)
	}

	if b, ok := authCtx.Identity.(authz.BuiltinRole); !ok || !b.IsServer() {
		return nil, trace.AccessDenied("only server identities can verify validated MFA challenges")
	}

```

As seen above, part of the verification consists in type asserting the `authCtx.Identity` to confirm it belongs to a local server and then we check if the role belongs to an actual server.

In our codebase, we have a function called `IsLocalOrRemoteService` with the following body:

```go
// IsLocalOrRemoteService checks if the identity is either a local or remote service.
func IsLocalOrRemoteService(authContext Context) bool {
	switch authContext.UnmappedIdentity.(type) {
	case BuiltinRole, RemoteBuiltinRole:
		return true
	default:
		return false
	}
}
```

Given that unauthenticated users were wrapped in `BuiltinRole`, this function would return true for them. This caused the encrypted recordings service to authorize unauthenticated clients to access the upload handlers. This was the only access check applied, so the bug allowed any client to upload and replace files in the backend storage.

This change fixes that by enforcing proper RBAC checks in the encrypted recordings `CreateUpload`, `UploadPart` and `CompleteUpload` handlers. It also forbids `RemoteBuiltinRole` (remote/leaf cluster identity) from uploading files to root clusters.

This change also moves RoleNop out of the `SystemRole` type and into a new distinct type, `UnauthenticatedRole`, so the compiler prevents it from being used anywhere a real authenticated system role is expected. As a defence-in-depth measure, the middleware now rejects any TLS certificate that claims the Nop role in its Groups or SystemRoles fields.

This PR fixes a separate issue on top of the existing one where certificate rotation of encrypted sessions was available to unauthenticated users.

The protection introduced was `authCtx.AuthorizeAdminAction()`, which verifies if someone has completed the MFA challenge (if required). That was the intended idea, but given how Teleport handles unauthenticated users, they were marked with AdminActionAuthNotRequired, which bypassed MFA checks. Because of that, any client - authenticated or unauthenticated - with the ability to complete the MFA challenge (or if MFA was not required) could rotate the encryption keys for session recordings.

This doesn't significantly affect Teleport since the private keys are never exposed externally and previous keys always remain in the backend object, allowing old recordings to still be decrypted. The main concern is if the keys were rotated so many times that the backend item size exceeds the 400KB limit on DynamoDB. While this would cause the rotation to fail beforehand, it would also prevent any further rotations from succeeding.

This PR introduces proper RBAC for modifying types.KindRecordingEncryption and ensures that unauthenticated users are always assigned AdminActionAuthNotRequired.

Fixes https://github.com/gravitational/teleport-private/issues/2430
Fixes https://github.com/gravitational/teleport-private/issues/2429

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2026-04-27 09:40:39 +00:00
Erik Margetis 1450ade43b initial draft (#64972) 2026-04-22 23:40:37 +00:00
Kenneth 92d8f4f68d Remove device enrollment limits (#64226)
- Deprecate DevicesUsage field
- Remove DevicesUsage proto field
2026-04-22 21:44:19 +00:00
Tiago Silva 396ebf22f6 sessionsearch[13]: Add telemetry for session summary searches with filters (#65772)
* sessionsearch[13]: Add telemetry for session summary searches with filters

This adds session summary search events to Prehog and extends the
aggregated user activity report to capture both total search query
counts and how many of those queries were submitted with filters. It
also wires the new fields through anonymization, aggregation, generated
protobufs, and the related tests.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>

* handle review feedback

---------

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2026-04-20 21:02:48 +00:00
rhammonds-teleport d563443346 Desktop Access: Support Shared Directory Removal (Backend only) (#65101)
* Add support for removing shared directories to Windows Desktop Service (TDPB only)

* Advertise support for shared directory removal

* Gracefully handle unknown device errors when removing RDPDR devices, but log a warning as this is probably caused by a bug.
2026-04-14 18:45:00 +00:00
Tiago Silva 60a7e68e07 sessionsearch[9]: add session search proto definitions for Auth and Access Graph (#64711)
Adds two proto files that together define the session summary search
feature.

  proto/accessgraph/v1/session_search.proto — internal, Auth->Access Graph
    Used exclusively by the Auth server. Defines SessionRecordingService
    with two RPCs:
      - SearchSessionSummaries: a bidirectional streaming RPC the Auth
        server uses to paginate through session summaries stored in the
        Access Graph. The Auth server sends search_params on the first
        message, receives batches of SessionSummary results each
        terminated by a PageComplete, and sends FetchMore to advance pages.
        Each SessionSummary includes session_end_event — the raw audit
        event the Auth server evaluates against the requesting user's RBAC
        permissions before deciding whether to forward the result to client.
      - StoreSessionSummary: used by the summarizer pipeline to persist
        session summaries and their vector embeddings to the Access Graph.

  api/proto/teleport/sessionsearch/v1/session_search.proto — public, Client->Auth
    Used by Teleport clients (tsh, web UI handler, etc.). Defines
    SessionSearchService.SearchSessionSummaries as a unary-request /
    server-streaming RPC. The Auth server implements this service: it
    receives the client's filter criteria, fans out to the Access Graph
    via the internal bidi stream above (handling all pagination
    internally), filters each result using session_end_event, and streams
    only the permitted SessionSummary results back. Clients see a single
    continuous stream with no pagination mechanics exposed to them.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2026-04-13 13:27:12 +00:00
Tiago Silva f906ba7b01 sessionsearch[3]: wire summarizer resources into the cache layer (#64560)
Adds cache support for all summarizer resources (InferenceModel,
InferenceSecret, InferencePolicy, and RetrievalModel) by implementing
event parsers, cache collections, and read-through methods.

Part of https://github.com/gravitational/teleport.e/pull/8046

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2026-04-13 11:59:46 +00:00
Cam Hutchison 8a32b4d971 usagereporter: Add Identity Security streaming/aggregating events (#63753)
* proto/prehog: Sync from cloud repo for access graph usage

Sync the `prehog.v1` proto package sfrom the cloud
repo to bring in the changes for access graph usage events.

* proto/accessgraph: Extend EventsStreamV2 response for usage events

Extend the EventsStreamV2 response to allow usage events to be sent back
to teleport.

The usage events that can be sent back are currently all defined in the
`prehog.v1alpha` protobuf package. As this does not have a `go_package`
statement, we need to add a `M` flag to the buf config for generating
the Go code. There is no canonical package for the generated code as the
protos live and are generated in two repos (cloud and teleport).

* proto: Regenerate proto/grpc code for access graph usage events

Regenerate the generated proto code to include the changes for access
graph usage events. This includes the following packages:
- `prehog.v1` (Go and Typescript)
- `accessgraph.v1alpha` (Go)

The contents of this commit were auto-generated with:

    make grpc/host

* usagereporter: Add anonymizer for identity security events

Add types compatible with `Anonymizer` for the two identity security
events:
* `prehogv1a.IdentitySecurityGraphSizeEvent`
* `prehogv1a.IdentitySecurityAuditLogsIngestedEvent`

These events are directly transformed as they contain no anonymizable
data.

* usage: Aggregate access graph queries per user

Extend `aggregating.Reporter` to aggregate the number of access graph
queries per user so we can generate monthly user active reports of
access graph usage for self-hosted Teleport customers.

* aggregating: Rename some identitySecurity -> sessionSummary

Rename some variables and functions in the aggregating reporter to more
tightly scope the naming, using "sessionSummary" instead of
"identitySecurity". Another report is to be added named
"identitySecurity" as an aggregation of more general data about the
product.

The existing report defined in the proto -
`IdentitySecuritySummariesGeneratedReport` has been retained as that is
a larger change to make across repositories and with "Summaries" in the
name, is scoped enough to differentiate it from the upcoming report.

* aggregating: Aggregate identity security events into new report

Aggregate the `IdentitySecurityGraphSizeEvent` and
`IdentitySecurityAuditLogsIngestedEvent` events into the
`IdentitySecurityReport` aggregated report.

Aggregation for the graph size events is simply taking the last size of
each provider, as these are essentially guages reporting the size at a
point in time. Aggregation for the audit log events are an accumulation
by provider giving a total count over the report window.
2026-04-10 03:46:59 +00:00
Lisa Kim c097aca42b Emit UI access list related usage events (#63954)
* Define new access list UI related events

* Web: add access list related events

* Fix lint and review

* Address CR

* Address CR

- Added condition to check integrate is always defined for integrate event
- Added nil checks
2026-04-02 17:21:51 +00:00
Dan Share a9fbf8b910 [Browser MFA] Add Browser MFA to challenge request flow (#63936) 2026-03-26 12:24:12 +00:00
Nibras Ohin e69e793d5d fix: optimizing api call and allow searching db users with no-wildcards (#64449)
* fix: optimizing api call and allow searching db users with no-wildcards for db users

* chore: addressing pr comments on renaming var and updating comments

* chore: updated based on pr comments to add more tests

* chore: refactor connct button dropdown state rendering

* chore: using t.context() directly in the test

* chore: cleaner refactor of ActionButtons logic

* chore: updated unifiedresoruces test to re-use the existing mock auth client

* chore: removing fallback as not needed for connect

* chore: remove unused api

* chore: reworked test and updated no wildcard logic

* chore: remove unused GetAllowedDatabaseUsers method

* fix: put back test that verifies correct logins are returned for a leaf cluster with access request

* fix: updated parameterpicket to account for allowOnlySuggestions when filtering
2026-03-19 20:39:00 +00:00
Grzegorz Zdunek 030e483626 Connect: gracefully handle VNet service and app version mismatch (#64438)
* Add `VERSION_MISMATCH` status to `WindowsServiceStatus`

* Show error in UI

* Verify service compatibility with client

* Fix outdated comment

* Remove unnecessary stories

* Move `VerifyServiceInstalledAndMatchesClient` to separate file
2026-03-19 07:45:58 +00:00
charlestp 4c18fb78a2 Instrumentation of Discovery usage events for the new IAC flow (#64322) 2026-03-13 19:04:58 +00:00
Grzegorz Zdunek 90eabf6ee7 Connect: support MOTD (#64310)
* Add `message_of_the_day` to `AuthSettings`, remove unused `has_message_of_the_day`

* Support passing `whiteSpace` to `Text`

* Show MOTD before login

* Add tests and stories

* Remove `minHeight={0}`

* Move `MessageOfTheDay` to `ClusterLogin`

* Minor code style fix
2026-03-12 09:27:35 +00:00
Nic Klaassen 2a23ceb829 feat: add scoped roles field to access list types (#63919) 2026-03-10 23:29:33 +00:00
Maxim 01381a4c02 types: Add types for SSH Node Resource Constraints (#64287) 2026-03-06 21:13:43 +00:00
Nibras Ohin b8343ec963 feat: added support for db roles for auto user provisioning for teleport connect (#63818)
* feat: added support for db roles for auto user provisioning for teleport connect

* chore: added unit tests for the auto provisioned user support changes

* chore: added storybook tests

* chore: reflecting on pr comments

* fix: fixed loosing db roles on cert re-issue

* chore: add oneOf support for db roles in proto

* chore: udpated to do user transform in backend

* chore: updated to group auto provisioning fields together

* chore: updating to preset db user in search bar for auto user provisioning

* chore: making autoUserProvisioning type required to prevent future misses of setting it

* chore: updated to reflect on pr comments

* chore: updating to minimize new interface declaration
2026-03-06 15:20:11 +00:00
Dan Share 7c6057cce2 [Browser MFA] Add proto for Browser MFA feature (#64048) 2026-03-06 07:02:44 +00:00
Tiago Silva 0ad811bcbd add summaries_generated count to SessionSummariesGeneratedRecord (#64278)
Adds a new `summaries_generated` field to the `SessionSummariesGeneratedRecord`
proto message to track the number of session summaries generated per session
type and resource combination, in addition to the existing token counts.

Updates the reporter to increment this counter for each processed
summary event.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2026-03-04 21:27:47 +00:00
Cam Hutchison 6c454945ff proto/prehog: Sync with source of truth in cloud repo (#63752)
* proto/prehog: Sync with source of truth in cloud repo

Sync the prehog proto files from the cloud repo as they are the source
of truth. These have diverged a little, largely in non-functional ways.
The CTA enum was missing `CTA_USAGE_REPORT`, now added. The rest is just
comments and some ordering.

This makes it easier to keep in sync in future as the files can just be
copied without needing to manually move changes across.

* proto/prehog: Regenerate Go/TS proto code

Regenerate the Go / Typescript code from the prehog proto from the
resync changes. Performed with:

    make grpc/host
2026-03-04 04:54:43 +00:00
Dan Share 36120b30cc [Browser MFA] Add protobuf and config (#63831)
Improve comments

grpc, lint, test fix

Update tf docs

Update tf integration

Fix login test

Address comments

Fix test

Move ValidateBrowserMFAChallenge rpc to MFA service

Fix service test

Address comments

Don't materialise browser authentication

Remove browser auth materialisation in test

Convert validate browser mfa to complete browser mfa
2026-03-02 08:47:56 +00:00
Alan Parra 1b96139023 chore: Bump golangci-lint to v2.10.1 (#63939)
* Fix "builder.WriteString(fmt.Sprintf(...))" calls

* chore: Bump golangci-lint to v2.10.1

* Bump e/

* Fix a few more WriteString/Sprintf occurrences
2026-02-19 13:04:57 +00:00
Maxim 375ca9f296 [Connect] Update types for ResourceConstraints support (#63492)
* types: Update protos for Teleterm support of ResourceConstraints

* fixup: Resolve test/story type errors from proto field changes
2026-02-06 17:47:09 +00:00
Grzegorz Zdunek 34c079541e Connect: read automatic updates configuration from Windows registry (#63281)
* Replace `GetDownloadBaseUrl` RPC with `GetConfig`

* Implement reading ToolsVersion and CdnBaseUrl from system registry

* Read values from `getConfig()` instead of `getDownloadBaseUrl` and `process.env`

* Use UAC updater when app is configured with env vars

* Fix typos

* Handle tools version being 'off'

* Safely read values from `GetConfigResponse`

* Fix ordering in proto

* Non-official -> Unofficial

* Add TODO about docs

* Use switch-case instead of if-else

* Bring back if-else
2026-02-05 10:06:22 +00:00
Grzegorz Zdunek 336379e17f Connect: switch Windows installer to dual mode (#62910)
* Switch installer to dual-mode

* Customize NSIS updater to disallow attempts to update per-machine installations if update is triggered from per-user instance

* Make `assertTshInProgramFiles` more strict

Reading Program Files path should be done using Windows API instead of env var that can be overridden.

* Add RPC to check if VNet service is installed

* Show warning and disable auto-start if there is no VNet service

* `GetWindowsSystemService` -> `CheckPreRunRequirements`

* `CheckPreRunRequirements` -> `CheckInstallTimeRequirements`

* Customize `forAll` option with VNet message

* Check for per-machine installation in system registry

* Fix vars with PreRun in the name

* Link to source file from the electron-builder repo, add commit hash

* Read per-machine location from Go instead of via PowerShell

* `IsPerMachineInstallResponse` -> `GetInstallationMetadataResponse`

* Define `GetInstallationMetadata` handler in separate file

* Fix tests failing on "updates not wrapped into act"
2026-02-05 09:22:49 +00:00
Dustin Specker d1ca8ddee0 Add workload cluster service (#62865)
* feat(lib/services): add WorkloadCluster interfaces

* feat(lib/auth): add WorkloadCluster service

* feat(api/client): support WorkloadClusters

* feat(lib/services): add local workload cluster

* feat(lib/services): add workload cluster to preset editor role

* gen: run make dump-preset-roles

* feat(lib/services): support parsing workload cluster events

* feat(lib/auth): start non-cloud workload cluster service

* feat(lib/auth): initialize local workloadcluster service

* feat(web/packages): add WorkloadCluster
2026-01-28 16:35:22 +00:00
Tiago Silva 067be631a5 Add usage reporting for AI-generated session summaries (#63179)
This change adds tracking for AI-generated session summaries so we can monitor feature usage and token costs.

Two new events are introduced:

- `SessionSummaryAccessEvent` tracks when users view AI summaries and which session types and resources are accessed.
- `SessionSummaryCreateEvent` tracks when summaries are generated, including input and output token counts for cost and capacity planning.

Events are aggregated in 15-minute windows by session type (SSH, Kubernetes, database, desktop) and resource name.

User access data is added to `UserActivityReport` via a new `SessionSummariesAccessedRecord`. AI generation metrics are reported in a new `IdentitySecuritySummariesGeneratedReport`, which tracks token usage per resource.

All resource names are anonymized with HMAC-SHA-256 before submission.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2026-01-28 12:48:57 +00:00
Nick Marais 7b3fe4ce26 feat: GHA + K8s guide improvements (#62778)
* Add IaC info alert to welcome step

* Add conditional info alert to "allow any branch" input

* Rename "done" button (to "finish")

* Add repo restriction help text

* Ensure "refs/heads/" prefix for branch input

* Add code panel to Welcome step

* Add `inProgress` mode to CodePanel

* Shift CodePanel left on finish step

* De-emphasise final button and make prior steps clearer

* Explain how to apply terraform template

* Improve manual label entry

* Update labels field label

* Enforce wildcard label

* Update label values format (OR)

* Explain workflows on "main branch"

* Clarify prerequisites

* Improve groups and users entry

* Copy tweak on Configure Access step

* Add groups and users validation

* Add kubernetes cluster selector

* Fix Terraform template tests

* Move cluster select to Setup Workflow step

* Tweak copy warning wording

* With emphasis not clarity

* Replace "setup" with "set up"

* Make cluster selector async searchable

* Fix lint issue

* Fix lint issue (again)
2026-01-27 13:11:15 +00:00
af83bdc83a Implement TDPB Support for Proxy (#62591)
* saving progress

* Proxy working with legacy web client

* a bit of cleanup and refactoring. Removed unecessary 'WriteTo' implementations on TDP/TDPB messages.

* Refactoring and code cleanup around tdpb message handling and translation

* Get translation set up

* A bit more cleanup

* Update TDP MFA util to utilize new MFA service protos

* Remove MFA messages from translation interceptors. They're not needed since MFA is handled before we start proxying the connection.

* Add 'PingerFunc' adapter to latency monitor

* More cleanup and refactoring around TDP setup and translation.

* Added tests for desktop proxy with each permutation of client/server dialects.

* Remove redundant and/or dead code.

* More refactoring

* Advertise TDPB as a subprotocol when handling websocket upgrade requests

* Fixes from integration testing

* Update usage of LatencyStats after renaming some fields

* Add a few more TDPB unit tests

* Remove comment

* Add a couple tests for 'handshakeData'

* Light cleanup

* * Remove unnecessary warning logs from MFA flow
* Add test case for TDPB MFA flow
* Remove obsolete 'tdpMFACodec'

* Update Go TDPB implementation after protobuf 'oneof' refactor.

* more cleanup

* Proxy alpn and username fixes

* The great refactor

* refactor aftermath

* Add explicit strict/permissive TDPB Decode implementations and fix test case that validates permissive decoding

* Missed recording_export during refactor

* not yet

* Fix a few refactor typos

* Cleanup TDP/TDPB proxy handler by refactoring disparate TDP/TDPB client handling.

* last bit of cleanup

* Clean up tdp/tdpb translation

* Remove commented out code

* Attempt to reduce some noise by refactoring package aliases.

* update comment

* fix lint errors

* more lint fixes

* last lint fixes

* Fix race in test setup

* Add license headers to new files

* Apply suggestions from code review

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>

* Rename wsAdapter and re-implement it's 'ReadMessage' method with a re-usable buffer

* Move TDP/TDPB MFA ceremony implementations to tdp/tdpb/legacy packages.

* Improved godocs in tdpb package

* Address the lighter PR feedback.

* Drop tdp/legacy import aliasing

* fix unnecessary conversion

* Fix license

* Apply suggestions from code review

Co-authored-by: Przemko Robakowski <przemko.robakowski@goteleport.com>
Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>

* Fix ping/pong matching

* * Rename 'isMFAResponse' to 'asMFAResponse'
* Fix surrounding comments

* fix comment

* Do not send empty error messages to client

* Fix some TDPB/TDP translation layer oversights

* Fix incorrect protobuf representation of MouseWheel's 'delta'. Should be int32, not uint32.

* Fix quoting in error string

---------

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
Co-authored-by: Przemko Robakowski <przemko.robakowski@goteleport.com>
2026-01-26 15:00:24 +00:00
Hugo Shaka 22c4407c5d Allow editor preset to read autoupdate agent reports (#62947)
* Allow editor preset to read autoupdate agent reports

* update preset role dumps
2026-01-19 21:13:42 +00:00
dependabot[bot]andAlan Parra ec59f57287 chore(deps): bump github.com/sigstore/cosign/v3 from 3.0.3 to 3.0.4 (#62801)
* chore(deps): bump github.com/sigstore/cosign/v3 from 3.0.3 to 3.0.4

Bumps [github.com/sigstore/cosign/v3](https://github.com/sigstore/cosign) from 3.0.3 to 3.0.4.
- [Release notes](https://github.com/sigstore/cosign/releases)
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sigstore/cosign/compare/v3.0.3...v3.0.4)

---
updated-dependencies:
- dependency-name: github.com/sigstore/cosign/v3
  dependency-version: 3.0.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Tidy all modules

* fix: Bump google.golang.org/api to v0.259.0. Tidy.

* Address API deprecations

* Run `make grpc`

* Run `make grpc` again

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alan Parra <alan.parra@goteleport.com>
2026-01-14 16:34:57 +00:00
Grzegorz ZdunekandRafał Cieślak f0714decaf Fix launching AWS IC from Connect (#62796)
* Add `sub_kind` and `permission_sets` to `App` message

* Allow launching AWS IAM IC

* Add AWS domain to allowlist

* Fix makeApp helper

* Add story

* Validate path and host parts, add test

* Support US gov partition addresses

* Update proto message

* Use more realistic publicAddr in test

---------

Co-authored-by: Rafał Cieślak <rafal.cieslak@goteleport.com>
2026-01-14 14:57:48 +00:00
Tiago Silva c3c1425908 Add support for multiple Host CAs in AccessGraph registration (#62611)
Updates the RegisterRequest proto to support multiple Host CA certificates
by introducing a new host_ca_pems repeated field while maintaining backwards
compatibility by deprecating the existing host_ca_pem field. This enables
proper authentication during Host CA rotation and HSM scenarios where
multiple certificates may be active simultaneously.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2026-01-06 17:30:05 +00:00
a46f16d3ce TDPB Message Definitions (#62100)
* Add protobuf definitions for tdpb

* * Re-add separate announce/acknowledge shared directory messages
* Add missing 'bytes_written' field to 'SharedDirectoryResponse'
* Use new MFA service protos in MFA messages which will bring in fewer dependencies

* Add typescript generation of TDPB protos

* Refactor legacy/types.proto by pulling 'Metadata' and various MFA device messages definitions into their own files. This eliminates the new MFA service's dependency on legacy/types.proto and drastically reduces the transitive dependencies of tdpb.proto.

* Apply suggestions from code review

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
Co-authored-by: Dan Share <10600907+danielashare@users.noreply.github.com>

* Add '_ms' suffix to latency stats message.

* Update/add license headers

* Refresh protos and regenerate terraform docs

* Remove use of custom type option and 'MessageType' enums in favor of an 'Envelope' message utilizing oneof.
Follow the same approach for SharedDirectory request and response messages.

---------

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
Co-authored-by: Dan Share <10600907+danielashare@users.noreply.github.com>
2025-12-31 16:59:49 +00:00
Nick Marais a4ac509bc5 feat: Add user event tracking to GHA+K8s guide (#62192)
* Initial refactor existing guide (ssh)

* Add provider and state reducer

* Welcome step

* Connect GitHub step

* Configure access step

* Finish step

* Add guide to integrations

* Add completion confirmation

* Add .tf file formatting in TextEditor

* Support updating TextEditor content

* Fetch and generate templates

* Add CodePanel component

* Add code panel to GitHub step

* Add code panel to access step

* Add code panel to finish step

* Add Kubernetes labels select component

* Add labels to state

* Add labels selector to access step

* Add welcome step to tracking usage events

* Add `useTracking`

* Track start and stop events

* Track steps events

* Track section events

* Track field events

* Track link events

* Track code copy events

* Extend tests

* Update stories

* Simplify react context usage

* Rename `captureSuccess` to `userEventCaptureSuccess`

* Rename file `tracking-tester.ts` to `trackingTester.ts`

* fix: Allow `:` in label values

* Reference frontend label matching logic in backend

* Allow `:` in label names and values

* Use Set one-liner

* Remove unnecessary else

* Fix test

* Allow spaces in label values
2025-12-16 17:56:53 +00:00
rosstimothy a6a6284c88 Scopes: validate scope when dialing (#61859)
The scope of the certificate presented by agents to the reversetunnel
server is now tracked and stored with the remoteConn. Dial requests,
both local and via peers, are now populated with the scope the user
is logged into which the reversetunnel server uses to enforce that
dials for hosts are only honored if the target scope matches.
2025-12-13 00:12:57 +00:00
Dan Upton 3d54918ea2 Add usage events for the MWI GitHub Actions <> Kubernetes Wizard (#61919)
* Add integration type for GitHub Actions + Kubernetes wizard

* Add step definitions for GitHub Actions + Kubernetes wizard

* Add `tp.ui.integrationEnroll.sectionOpen` event type

* Add `tp.ui.integrationEnroll.fieldComplete` event type

* Add `tp.ui.integrationEnroll.codeCopy` event type

* Add `tp.ui.integrationEnroll.linkClick` event type

* Remove unnecessary GitHub enterprise URL field

* Run prettier
2025-12-08 12:07:25 +00:00
Gabriel Coradoandrosstimothy d247df02c0 Add app auth config backend service (#61688)
* feat: add app auth config backend service

* refactor: code review suggetions

* refactor: remove app auth config resource subkind usage

* fix(cache): add missing event and test definition

* Apply suggestions from code review

Co-authored-by: rosstimothy <39066650+rosstimothy@users.noreply.github.com>

* refactor: code review suggestions

* test(inventory): add missing app auth config service

---------

Co-authored-by: rosstimothy <39066650+rosstimothy@users.noreply.github.com>
2025-12-03 23:09:01 +00:00
ravicious 2e32fceeda Pass navigator.maxTouchPoints from Web UI to auth service (#61777)
* DocumentAuthorizeWebSession: Call tshd client directly

* Add api.postWithOptions for sending POST with custom headers

There's already post and postFormData. Similar to deleteWithOptions,
instead of adding just another positional arg with custom headers to
either post or postFormData, I've decided to create a third function
with a more flexible API.

We could deprecate the other two functions but I don't know when I'll
backport this change to v18 yet. The post function should be enough for
95% of cases.

* Send Max-Touch-Points header to endpoints which lead to Device Trust prompt

* Pass max touch points to auth service

* Add iOS and iPadOS as new OSType values

* Hardcode header name

* Mention availability of `ForwardedClientMetadata.MaxTouchPoints`

* Remove new OSes from OSType for now

* Remove leftover logger

* Change fake UA in tests to be more Surface-like instead of iPad-like

* Add separate TestCreateWebSession subtest for iPadOS
2025-12-02 10:07:18 +00:00
Forrest 21d1d0be59 scoped ssh access core (#60629) 2025-11-18 00:26:12 +00:00
STeve (Xin) Huang 619768968f [mcp] report transport type and egress auth type to prehog (#61397)
* [mcp] report transport type and egress auth type to prehog

* report unknown egress type and add more comments

* make grpc

* fix tests ( ̄▽ ̄;)
2025-11-17 18:54:05 +00:00
Grzegorz Zdunek 6615e42ecc Connect: close cluster clients when profile changes (#61090)
* Include expiration time in `LoggedInUser`

This will allow the profile watcher to detect when the user relogged.

* Display expiration time in UI

* Add `ClearStaleClusterClients` RPC

* Implement `ClearStaleClusterClients`

* Clear stale clients when profile changes

* Improve session expiration component

* Move refresh button back to top

* `ClearCachedStaleClientsForRoot` -> `ClearStaleCachedClientsForRoot`

* `unchanged` -> `stale`

* Make "closing stale clients" a subtest

* Add `clientcache` test

* Remove `getProfile` error wrapping

* Improve comment

* Convert story to controls
2025-11-17 11:02:40 +00:00
Edoardo Spadolini ded7698909 Kubernetes forwarding in the Relay Service (#60974)
* Add signaling for supported tunnel types to relay tunnel

* Enable relay tunnel client for kubernetes_service

* Add kube_server to the relay cache

* Add passive forwarder for kubernetes access through the relay

* Add wildcard SNI suffix to kube service SANs if a relay is configured

* Add SNI-dispatching grpc transport for the relay transport server

* Enable kubernetes forwarding in the relay service

* Advertise support for kube tunnels in the relay

* Add tests
2025-11-14 22:25:00 +00:00
dependabot[bot]andTim Ross 29743348a3 Bump the go group across 1 directory with 87 updates (#60972)
* Bump the go group across 1 directory with 87 updates

Bumps the go group with 67 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [cloud.google.com/go/alloydb](https://github.com/googleapis/google-cloud-go) | `1.18.0` | `1.19.0` |
| [cloud.google.com/go/cloudsqlconn](https://github.com/googlecloudplatform/cloud-sql-go-connector) | `1.18.1` | `1.19.0` |
| [cloud.google.com/go/compute](https://github.com/googleapis/google-cloud-go) | `1.48.0` | `1.49.1` |
| [cloud.google.com/go/container](https://github.com/googleapis/google-cloud-go) | `1.44.0` | `1.45.0` |
| [cloud.google.com/go/firestore](https://github.com/googleapis/google-cloud-go) | `1.18.0` | `1.20.0` |
| [cloud.google.com/go/iam](https://github.com/googleapis/google-cloud-go) | `1.5.2` | `1.5.3` |
| [cloud.google.com/go/kms](https://github.com/googleapis/google-cloud-go) | `1.23.0` | `1.23.2` |
| [cloud.google.com/go/spanner](https://github.com/googleapis/google-cloud-go) | `1.86.0` | `1.86.1` |
| [cloud.google.com/go/storage](https://github.com/googleapis/google-cloud-go) | `1.57.0` | `1.57.1` |
| [connectrpc.com/connect](https://github.com/connectrpc/connect-go) | `1.18.1` | `1.19.1` |
| [github.com/Azure/azure-sdk-for-go/sdk/azidentity](https://github.com/Azure/azure-sdk-for-go) | `1.12.0` | `1.13.0` |
| [github.com/Azure/azure-sdk-for-go/sdk/storage/azblob](https://github.com/Azure/azure-sdk-for-go) | `1.6.2` | `1.6.3` |
| [github.com/ClickHouse/ch-go](https://github.com/ClickHouse/ch-go) | `0.68.0` | `0.69.0` |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.39.2` | `1.39.5` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.31.12` | `1.31.16` |
| [github.com/aws/aws-sdk-go-v2/feature/dynamodb/attributevalue](https://github.com/aws/aws-sdk-go-v2) | `1.20.13` | `1.20.20` |
| [github.com/aws/aws-sdk-go-v2/feature/dynamodbstreams/attributevalue](https://github.com/aws/aws-sdk-go-v2) | `1.19.13` | `1.19.20` |
| [github.com/aws/aws-sdk-go-v2/feature/rds/auth](https://github.com/aws/aws-sdk-go-v2) | `1.6.9` | `1.6.12` |
| [github.com/aws/aws-sdk-go-v2/feature/s3/manager](https://github.com/aws/aws-sdk-go-v2) | `1.19.10` | `1.20.2` |
| [github.com/aws/aws-sdk-go-v2/service/applicationautoscaling](https://github.com/aws/aws-sdk-go-v2) | `1.40.5` | `1.41.1` |
| [github.com/aws/aws-sdk-go-v2/service/athena](https://github.com/aws/aws-sdk-go-v2) | `1.55.6` | `1.55.9` |
| [github.com/aws/aws-sdk-go-v2/service/bedrockruntime](https://github.com/aws/aws-sdk-go-v2) | `1.41.0` | `1.42.1` |
| [github.com/aws/aws-sdk-go-v2/service/dax](https://github.com/aws/aws-sdk-go-v2) | `1.29.1` | `1.29.4` |
| [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) | `1.254.1` | `1.261.0` |
| [github.com/aws/aws-sdk-go-v2/service/ec2instanceconnect](https://github.com/aws/aws-sdk-go-v2) | `1.32.5` | `1.32.8` |
| [github.com/aws/aws-sdk-go-v2/service/ecs](https://github.com/aws/aws-sdk-go-v2) | `1.65.0` | `1.67.1` |
| [github.com/aws/aws-sdk-go-v2/service/eks](https://github.com/aws/aws-sdk-go-v2) | `1.74.2` | `1.74.6` |
| [github.com/aws/aws-sdk-go-v2/service/elasticache](https://github.com/aws/aws-sdk-go-v2) | `1.50.5` | `1.51.0` |
| [github.com/aws/aws-sdk-go-v2/service/glue](https://github.com/aws/aws-sdk-go-v2) | `1.129.1` | `1.132.0` |
| [github.com/aws/aws-sdk-go-v2/service/iam](https://github.com/aws/aws-sdk-go-v2) | `1.47.7` | `1.49.1` |
| [github.com/aws/aws-sdk-go-v2/service/identitystore](https://github.com/aws/aws-sdk-go-v2) | `1.32.6` | `1.33.2` |
| [github.com/aws/aws-sdk-go-v2/service/kms](https://github.com/aws/aws-sdk-go-v2) | `1.45.6` | `1.47.0` |
| [github.com/aws/aws-sdk-go-v2/service/lambda](https://github.com/aws/aws-sdk-go-v2) | `1.77.6` | `1.81.0` |
| [github.com/aws/aws-sdk-go-v2/service/memorydb](https://github.com/aws/aws-sdk-go-v2) | `1.31.6` | `1.33.2` |
| [github.com/aws/aws-sdk-go-v2/service/opensearch](https://github.com/aws/aws-sdk-go-v2) | `1.52.5` | `1.52.9` |
| [github.com/aws/aws-sdk-go-v2/service/organizations](https://github.com/aws/aws-sdk-go-v2) | `1.45.3` | `1.46.1` |
| [github.com/aws/aws-sdk-go-v2/service/rds](https://github.com/aws/aws-sdk-go-v2) | `1.108.0` | `1.108.6` |
| [github.com/aws/aws-sdk-go-v2/service/redshift](https://github.com/aws/aws-sdk-go-v2) | `1.59.0` | `1.59.4` |
| [github.com/aws/aws-sdk-go-v2/service/redshiftserverless](https://github.com/aws/aws-sdk-go-v2) | `1.31.8` | `1.31.12` |
| [github.com/aws/aws-sdk-go-v2/service/resourcegroupstaggingapi](https://github.com/aws/aws-sdk-go-v2) | `1.30.6` | `1.30.10` |
| [github.com/aws/aws-sdk-go-v2/service/rolesanywhere](https://github.com/aws/aws-sdk-go-v2) | `1.21.6` | `1.21.9` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) | `1.39.6` | `1.39.10` |
| [github.com/aws/aws-sdk-go-v2/service/sns](https://github.com/aws/aws-sdk-go-v2) | `1.38.5` | `1.39.2` |
| [github.com/aws/aws-sdk-go-v2/service/sqs](https://github.com/aws/aws-sdk-go-v2) | `1.42.8` | `1.42.12` |
| [github.com/aws/aws-sdk-go-v2/service/ssm](https://github.com/aws/aws-sdk-go-v2) | `1.65.1` | `1.66.3` |
| [github.com/aws/aws-sdk-go-v2/service/ssoadmin](https://github.com/aws/aws-sdk-go-v2) | `1.36.2` | `1.36.5` |
| [github.com/aws/smithy-go/tracing/smithyoteltracing](https://github.com/aws/smithy-go) | `1.0.7` | `1.0.9` |
| [github.com/charmbracelet/huh](https://github.com/charmbracelet/huh) | `0.7.0` | `0.8.0` |
| [github.com/docker/cli](https://github.com/docker/cli) | `28.4.0+incompatible` | `28.5.1+incompatible` |
| [github.com/docker/docker](https://github.com/docker/docker) | `28.4.0+incompatible` | `28.5.1+incompatible` |
| [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.16.2` | `5.16.3` |
| [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) | `4.1.2` | `4.1.3` |
| [github.com/go-ldap/ldap/v3](https://github.com/go-ldap/ldap) | `3.4.11` | `3.4.12` |
| [github.com/gofrs/flock](https://github.com/gofrs/flock) | `0.12.1` | `0.13.0` |
| [github.com/google/go-attestation](https://github.com/google/go-attestation) | `0.5.1` | `0.6.0` |
| [github.com/gravitational/roundtrip](https://github.com/gravitational/roundtrip) | `1.0.2` | `1.0.3` |
| [github.com/mark3labs/mcp-go](https://github.com/mark3labs/mcp-go) | `0.41.1` | `0.43.0` |
| [github.com/oracle/oci-go-sdk/v65](https://github.com/oracle/oci-go-sdk) | `65.101.1` | `65.103.0` |
| [github.com/pkg/sftp](https://github.com/pkg/sftp) | `1.13.9` | `1.13.10` |
| [github.com/prometheus/common](https://github.com/prometheus/common) | `0.66.1` | `0.67.2` |
| [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) | `0.54.1` | `0.55.0` |
| [github.com/shirou/gopsutil/v4](https://github.com/shirou/gopsutil) | `4.25.9` | `4.25.10` |
| [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) | `2.6.0` | `2.6.1` |
| [gitlab.com/gitlab-org/api/client-go](https://gitlab.com/gitlab-org/api/client-go) | `0.143.3` | `0.158.0` |
| [go.opentelemetry.io/proto/otlp](https://github.com/open-telemetry/opentelemetry-proto-go) | `1.8.0` | `1.9.0` |
| [golang.org/x/mod](https://github.com/golang/mod) | `0.28.0` | `0.29.0` |
| [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) | `0.22.1` | `0.22.4` |



Updates `cloud.google.com/go/alloydb` from 1.18.0 to 1.19.0
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/documentai/CHANGES.md)
- [Commits](https://github.com/googleapis/google-cloud-go/compare/kms/v1.18.0...kms/v1.19.0)

Updates `cloud.google.com/go/cloudsqlconn` from 1.18.1 to 1.19.0
- [Release notes](https://github.com/googlecloudplatform/cloud-sql-go-connector/releases)
- [Changelog](https://github.com/GoogleCloudPlatform/cloud-sql-go-connector/blob/main/CHANGELOG.md)
- [Commits](https://github.com/googlecloudplatform/cloud-sql-go-connector/compare/v1.18.1...v1.19.0)

Updates `cloud.google.com/go/compute` from 1.48.0 to 1.49.1
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-cloud-go/compare/pubsub/v1.48.0...compute/v1.49.1)

Updates `cloud.google.com/go/container` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-cloud-go/compare/pubsub/v1.44.0...pubsub/v1.45.0)

Updates `cloud.google.com/go/firestore` from 1.18.0 to 1.20.0
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/documentai/CHANGES.md)
- [Commits](https://github.com/googleapis/google-cloud-go/compare/kms/v1.18.0...kms/v1.20.0)

Updates `cloud.google.com/go/iam` from 1.5.2 to 1.5.3
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-cloud-go/compare/iam/v1.5.2...iam/v1.5.3)

Updates `cloud.google.com/go/kms` from 1.23.0 to 1.23.2
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/documentai/CHANGES.md)
- [Commits](https://github.com/googleapis/google-cloud-go/compare/dlp/v1.23.0...kms/v1.23.2)

Updates `cloud.google.com/go/spanner` from 1.86.0 to 1.86.1
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-cloud-go/compare/spanner/v1.86.0...spanner/v1.86.1)

Updates `cloud.google.com/go/storage` from 1.57.0 to 1.57.1
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-cloud-go/compare/spanner/v1.57.0...storage/v1.57.1)

Updates `connectrpc.com/connect` from 1.18.1 to 1.19.1
- [Release notes](https://github.com/connectrpc/connect-go/releases)
- [Changelog](https://github.com/connectrpc/connect-go/blob/main/RELEASE.md)
- [Commits](https://github.com/connectrpc/connect-go/compare/v1.18.1...v1.19.1)

Updates `github.com/Azure/azure-sdk-for-go/sdk/azidentity` from 1.12.0 to 1.13.0
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases)
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azcore/v1.12.0...sdk/azcore/v1.13.0)

Updates `github.com/Azure/azure-sdk-for-go/sdk/storage/azblob` from 1.6.2 to 1.6.3
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases)
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/storage/azblob/v1.6.2...sdk/storage/azblob/v1.6.3)

Updates `github.com/ClickHouse/ch-go` from 0.68.0 to 0.69.0
- [Release notes](https://github.com/ClickHouse/ch-go/releases)
- [Commits](https://github.com/ClickHouse/ch-go/compare/v0.68.0...v0.69.0)

Updates `github.com/aws/aws-sdk-go-v2` from 1.39.2 to 1.39.5
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.39.2...v1.39.5)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.31.12 to 1.31.16
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.31.12...config/v1.31.16)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.18.16 to 1.18.20
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/config/v1.18.20/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.16...config/v1.18.20)

Updates `github.com/aws/aws-sdk-go-v2/feature/dynamodb/attributevalue` from 1.20.13 to 1.20.20
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/emr/v1.20.13...feature/dynamodb/attributevalue/v1.20.20)

Updates `github.com/aws/aws-sdk-go-v2/feature/dynamodbstreams/attributevalue` from 1.19.13 to 1.19.20
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/efs/v1.19.13...service/codebuild/v1.19.20)

Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.18.9 to 1.18.12
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.9...config/v1.18.12)

Updates `github.com/aws/aws-sdk-go-v2/feature/rds/auth` from 1.6.9 to 1.6.12
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/service/rum/v1.6.12/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/rum/v1.6.9...service/rum/v1.6.12)

Updates `github.com/aws/aws-sdk-go-v2/feature/s3/manager` from 1.19.10 to 1.20.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/sqs/v1.19.10...v1.20.2)

Updates `github.com/aws/aws-sdk-go-v2/service/applicationautoscaling` from 1.40.5 to 1.41.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/amp/v1.40.5...service/ecr/v1.41.1)

Updates `github.com/aws/aws-sdk-go-v2/service/athena` from 1.55.6 to 1.55.9
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/iot/v1.55.6...service/wafv2/v1.55.9)

Updates `github.com/aws/aws-sdk-go-v2/service/bedrockruntime` from 1.41.0 to 1.42.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.41.0...service/s3/v1.42.1)

Updates `github.com/aws/aws-sdk-go-v2/service/dax` from 1.29.1 to 1.29.4
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.29.1...config/v1.29.4)

Updates `github.com/aws/aws-sdk-go-v2/service/dynamodb` from 1.50.5 to 1.52.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ecr/v1.50.5...service/ssm/v1.52.3)

Updates `github.com/aws/aws-sdk-go-v2/service/dynamodbstreams` from 1.31.0 to 1.32.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.31.0...v1.32.1)

Updates `github.com/aws/aws-sdk-go-v2/service/ec2` from 1.254.1 to 1.261.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ec2/v1.254.1...service/ec2/v1.261.0)

Updates `github.com/aws/aws-sdk-go-v2/service/ec2instanceconnect` from 1.32.5 to 1.32.8
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.32.5...v1.32.8)

Updates `github.com/aws/aws-sdk-go-v2/service/ecs` from 1.65.0 to 1.67.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.65.0...service/s3/v1.67.1)

Updates `github.com/aws/aws-sdk-go-v2/service/eks` from 1.74.2 to 1.74.6
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/eks/v1.74.2...service/eks/v1.74.6)

Updates `github.com/aws/aws-sdk-go-v2/service/elasticache` from 1.50.5 to 1.51.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ecr/v1.50.5...service/s3/v1.51.0)

Updates `github.com/aws/aws-sdk-go-v2/service/glue` from 1.129.1 to 1.132.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/glue/v1.129.1...service/ec2/v1.132.0)

Updates `github.com/aws/aws-sdk-go-v2/service/iam` from 1.47.7 to 1.49.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.47.7...service/ssm/v1.49.1)

Updates `github.com/aws/aws-sdk-go-v2/service/identitystore` from 1.32.6 to 1.33.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.32.6...service/mq/v1.33.2)

Updates `github.com/aws/aws-sdk-go-v2/service/kms` from 1.45.6 to 1.47.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/kms/v1.45.6...service/s3/v1.47.0)

Updates `github.com/aws/aws-sdk-go-v2/service/lambda` from 1.77.6 to 1.81.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/lambda/v1.77.6...service/s3/v1.81.0)

Updates `github.com/aws/aws-sdk-go-v2/service/memorydb` from 1.31.6 to 1.33.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.31.6...service/mq/v1.33.2)

Updates `github.com/aws/aws-sdk-go-v2/service/opensearch` from 1.52.5 to 1.52.9
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ssm/v1.52.5...service/guardduty/v1.52.9)

Updates `github.com/aws/aws-sdk-go-v2/service/organizations` from 1.45.3 to 1.46.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/rds/v1.45.3...service/ssm/v1.46.1)

Updates `github.com/aws/aws-sdk-go-v2/service/rds` from 1.108.0 to 1.108.6
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ec2/v1.108.0...service/rds/v1.108.6)

Updates `github.com/aws/aws-sdk-go-v2/service/redshift` from 1.59.0 to 1.59.4
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.59.0...service/iot/v1.59.4)

Updates `github.com/aws/aws-sdk-go-v2/service/redshiftserverless` from 1.31.8 to 1.31.12
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.31.8...config/v1.31.12)

Updates `github.com/aws/aws-sdk-go-v2/service/resourcegroupstaggingapi` from 1.30.6 to 1.30.10
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.30.6...service/acm/v1.30.10)

Updates `github.com/aws/aws-sdk-go-v2/service/rolesanywhere` from 1.21.6 to 1.21.9
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/eks/v1.21.6...service/rum/v1.21.9)

Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.88.3 to 1.89.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.88.3...service/s3/v1.89.1)

Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.39.6 to 1.39.10
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/sfn/v1.39.6...service/emr/v1.39.10)

Updates `github.com/aws/aws-sdk-go-v2/service/sns` from 1.38.5 to 1.39.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.38.5...v1.39.2)

Updates `github.com/aws/aws-sdk-go-v2/service/sqs` from 1.42.8 to 1.42.12
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ivs/v1.42.8...service/sqs/v1.42.12)

Updates `github.com/aws/aws-sdk-go-v2/service/ssm` from 1.65.1 to 1.66.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.65.1...service/s3/v1.66.3)

Updates `github.com/aws/aws-sdk-go-v2/service/ssoadmin` from 1.36.2 to 1.36.5
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.36.2...v1.36.5)

Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.38.6 to 1.39.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/sts/v1.38.6...v1.39.0)

Updates `github.com/aws/smithy-go` from 1.23.0 to 1.23.1
- [Release notes](https://github.com/aws/smithy-go/releases)
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws/smithy-go/compare/v1.23.0...v1.23.1)

Updates `github.com/aws/smithy-go/tracing/smithyoteltracing` from 1.0.7 to 1.0.9
- [Release notes](https://github.com/aws/smithy-go/releases)
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws/smithy-go/compare/metrics/smithyotelmetrics/v1.0.7...metrics/smithyotelmetrics/v1.0.9)

Updates `github.com/charmbracelet/huh` from 0.7.0 to 0.8.0
- [Release notes](https://github.com/charmbracelet/huh/releases)
- [Commits](https://github.com/charmbracelet/huh/compare/v0.7.0...v0.8.0)

Updates `github.com/docker/cli` from 28.4.0+incompatible to 28.5.1+incompatible
- [Commits](https://github.com/docker/cli/compare/v28.4.0...v28.5.1)

Updates `github.com/docker/docker` from 28.4.0+incompatible to 28.5.1+incompatible
- [Release notes](https://github.com/docker/docker/releases)
- [Commits](https://github.com/docker/docker/compare/v28.4.0...v28.5.1)

Updates `github.com/go-git/go-git/v5` from 5.16.2 to 5.16.3
- [Release notes](https://github.com/go-git/go-git/releases)
- [Commits](https://github.com/go-git/go-git/compare/v5.16.2...v5.16.3)

Updates `github.com/go-jose/go-jose/v4` from 4.1.2 to 4.1.3
- [Release notes](https://github.com/go-jose/go-jose/releases)
- [Commits](https://github.com/go-jose/go-jose/compare/v4.1.2...v4.1.3)

Updates `github.com/go-ldap/ldap/v3` from 3.4.11 to 3.4.12
- [Release notes](https://github.com/go-ldap/ldap/releases)
- [Commits](https://github.com/go-ldap/ldap/compare/v3.4.11...v3.4.12)

Updates `github.com/gofrs/flock` from 0.12.1 to 0.13.0
- [Release notes](https://github.com/gofrs/flock/releases)
- [Commits](https://github.com/gofrs/flock/compare/v0.12.1...v0.13.0)

Updates `github.com/google/go-attestation` from 0.5.1 to 0.6.0
- [Release notes](https://github.com/google/go-attestation/releases)
- [Commits](https://github.com/google/go-attestation/compare/v0.5.1...v0.6.0)

Updates `github.com/google/go-tpm-tools` from 0.4.5 to 0.4.6
- [Release notes](https://github.com/google/go-tpm-tools/releases)
- [Changelog](https://github.com/google/go-tpm-tools/blob/main/.goreleaser.yaml)
- [Commits](https://github.com/google/go-tpm-tools/compare/v0.4.5...v0.4.6)

Updates `github.com/gravitational/roundtrip` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/gravitational/roundtrip/releases)
- [Commits](https://github.com/gravitational/roundtrip/compare/v1.0.2...v1.0.3)

Updates `github.com/mark3labs/mcp-go` from 0.41.1 to 0.43.0
- [Release notes](https://github.com/mark3labs/mcp-go/releases)
- [Commits](https://github.com/mark3labs/mcp-go/compare/v0.41.1...v0.43.0)

Updates `github.com/oracle/oci-go-sdk/v65` from 65.101.1 to 65.103.0
- [Release notes](https://github.com/oracle/oci-go-sdk/releases)
- [Changelog](https://github.com/oracle/oci-go-sdk/blob/master/CHANGELOG.md)
- [Commits](https://github.com/oracle/oci-go-sdk/compare/v65.101.1...v65.103.0)

Updates `github.com/pkg/sftp` from 1.13.9 to 1.13.10
- [Release notes](https://github.com/pkg/sftp/releases)
- [Commits](https://github.com/pkg/sftp/compare/v1.13.9...v1.13.10)

Updates `github.com/prometheus/common` from 0.66.1 to 0.67.2
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](https://github.com/prometheus/common/compare/v0.66.1...v0.67.2)

Updates `github.com/quic-go/quic-go` from 0.54.1 to 0.55.0
- [Release notes](https://github.com/quic-go/quic-go/releases)
- [Commits](https://github.com/quic-go/quic-go/compare/v0.54.1...v0.55.0)

Updates `github.com/shirou/gopsutil/v4` from 4.25.9 to 4.25.10
- [Release notes](https://github.com/shirou/gopsutil/releases)
- [Commits](https://github.com/shirou/gopsutil/compare/v4.25.9...v4.25.10)

Updates `github.com/sigstore/cosign/v2` from 2.6.0 to 2.6.1
- [Release notes](https://github.com/sigstore/cosign/releases)
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sigstore/cosign/compare/v2.6.0...v2.6.1)

Updates `github.com/sigstore/sigstore-go` from 1.1.2 to 1.1.3
- [Release notes](https://github.com/sigstore/sigstore-go/releases)
- [Commits](https://github.com/sigstore/sigstore-go/compare/v1.1.2...v1.1.3)

Updates `gitlab.com/gitlab-org/api/client-go` from 0.143.3 to 0.158.0
- [Release notes](https://gitlab.com/gitlab-org/api/client-go/tags)
- [Changelog](https://gitlab.com/gitlab-org/api/client-go/blob/main/CHANGELOG.md)
- [Commits](https://gitlab.com/gitlab-org/api/client-go/compare/v0.143.3...v0.158.0)

Updates `go.opentelemetry.io/proto/otlp` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-proto-go/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-proto-go/compare/v1.8.0...v1.9.0)

Updates `golang.org/x/crypto` from 0.42.0 to 0.43.0
- [Commits](https://github.com/golang/crypto/compare/v0.42.0...v0.43.0)

Updates `golang.org/x/mod` from 0.28.0 to 0.29.0
- [Commits](https://github.com/golang/mod/compare/v0.28.0...v0.29.0)

Updates `golang.org/x/net` from 0.44.0 to 0.46.0
- [Commits](https://github.com/golang/net/compare/v0.44.0...v0.46.0)

Updates `golang.org/x/oauth2` from 0.31.0 to 0.32.0
- [Commits](https://github.com/golang/oauth2/compare/v0.31.0...v0.32.0)

Updates `golang.org/x/sys` from 0.36.0 to 0.37.0
- [Commits](https://github.com/golang/sys/compare/v0.36.0...v0.37.0)

Updates `golang.org/x/term` from 0.35.0 to 0.36.0
- [Commits](https://github.com/golang/term/compare/v0.35.0...v0.36.0)

Updates `golang.org/x/text` from 0.29.0 to 0.30.0
- [Release notes](https://github.com/golang/text/releases)
- [Commits](https://github.com/golang/text/compare/v0.29.0...v0.30.0)

Updates `golang.org/x/time` from 0.13.0 to 0.14.0
- [Commits](https://github.com/golang/time/compare/v0.13.0...v0.14.0)

Updates `google.golang.org/api` from 0.251.0 to 0.253.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.251.0...v0.253.0)

Updates `google.golang.org/genproto/googleapis/rpc` from 0.0.0-20250929231259-57b25ae835d4 to 0.0.0-20251022142026-3a174f9686a8
- [Commits](https://github.com/googleapis/go-genproto/commits)

Updates `google.golang.org/grpc` from 1.75.1 to 1.76.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.75.1...v1.76.0)

Updates `google.golang.org/protobuf` from 1.36.9 to 1.36.10

Updates `sigs.k8s.io/controller-runtime` from 0.22.1 to 0.22.4
- [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases)
- [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md)
- [Commits](https://github.com/kubernetes-sigs/controller-runtime/compare/v0.22.1...v0.22.4)

---
updated-dependencies:
- dependency-name: cloud.google.com/go/alloydb
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: cloud.google.com/go/cloudsqlconn
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: cloud.google.com/go/compute
  dependency-version: 1.49.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: cloud.google.com/go/container
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: cloud.google.com/go/firestore
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: cloud.google.com/go/iam
  dependency-version: 1.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: cloud.google.com/go/kms
  dependency-version: 1.23.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: cloud.google.com/go/spanner
  dependency-version: 1.86.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: cloud.google.com/go/storage
  dependency-version: 1.57.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: connectrpc.com/connect
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azidentity
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/storage/azblob
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/ClickHouse/ch-go
  dependency-version: 0.69.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.39.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.31.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.18.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/dynamodb/attributevalue
  dependency-version: 1.20.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/dynamodbstreams/attributevalue
  dependency-version: 1.19.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
  dependency-version: 1.18.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/rds/auth
  dependency-version: 1.6.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/manager
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/applicationautoscaling
  dependency-version: 1.41.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/athena
  dependency-version: 1.55.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/bedrockruntime
  dependency-version: 1.42.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/dax
  dependency-version: 1.29.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/dynamodb
  dependency-version: 1.52.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/dynamodbstreams
  dependency-version: 1.32.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2
  dependency-version: 1.261.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2instanceconnect
  dependency-version: 1.32.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ecs
  dependency-version: 1.67.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/eks
  dependency-version: 1.74.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/elasticache
  dependency-version: 1.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/glue
  dependency-version: 1.132.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/iam
  dependency-version: 1.49.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/identitystore
  dependency-version: 1.33.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/kms
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/lambda
  dependency-version: 1.81.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/memorydb
  dependency-version: 1.33.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/opensearch
  dependency-version: 1.52.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/organizations
  dependency-version: 1.46.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/rds
  dependency-version: 1.108.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/redshift
  dependency-version: 1.59.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/redshiftserverless
  dependency-version: 1.31.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/resourcegroupstaggingapi
  dependency-version: 1.30.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/rolesanywhere
  dependency-version: 1.21.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
  dependency-version: 1.89.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.39.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sns
  dependency-version: 1.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sqs
  dependency-version: 1.42.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ssm
  dependency-version: 1.66.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ssoadmin
  dependency-version: 1.36.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
  dependency-version: 1.39.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/smithy-go
  dependency-version: 1.23.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/smithy-go/tracing/smithyoteltracing
  dependency-version: 1.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/charmbracelet/huh
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/docker/cli
  dependency-version: 28.5.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/docker/docker
  dependency-version: 28.5.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.16.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/go-jose/go-jose/v4
  dependency-version: 4.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/go-ldap/ldap/v3
  dependency-version: 3.4.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/gofrs/flock
  dependency-version: 0.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/google/go-attestation
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/google/go-tpm-tools
  dependency-version: 0.4.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/gravitational/roundtrip
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/mark3labs/mcp-go
  dependency-version: 0.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/oracle/oci-go-sdk/v65
  dependency-version: 65.103.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/pkg/sftp
  dependency-version: 1.13.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/prometheus/common
  dependency-version: 0.67.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/quic-go/quic-go
  dependency-version: 0.55.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/shirou/gopsutil/v4
  dependency-version: 4.25.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/sigstore/cosign/v2
  dependency-version: 2.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/sigstore/sigstore-go
  dependency-version: 1.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: gitlab.com/gitlab-org/api/client-go
  dependency-version: 0.158.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: go.opentelemetry.io/proto/otlp
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/crypto
  dependency-version: 0.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/mod
  dependency-version: 0.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/net
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/sys
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/term
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/text
  dependency-version: 0.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/time
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: google.golang.org/api
  dependency-version: 0.253.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: google.golang.org/genproto/googleapis/rpc
  dependency-version: 0.0.0-20251022142026-3a174f9686a8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: google.golang.org/grpc
  dependency-version: 1.76.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: google.golang.org/protobuf
  dependency-version: 1.36.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: sigs.k8s.io/controller-runtime
  dependency-version: 0.22.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>

* go mod tidy all

* make grpc

* make go-generate

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Tim Ross <tim.ross@goteleport.com>
2025-11-04 21:59:52 +00:00
alex hemard d0111b9408 feat: Added ListUserAccessLists rpc (#60367) 2025-10-29 21:04:30 +00:00
Grzegorz Zdunek 2d1bc7b909 Connect: make logout function idempotent (#60553)
* Remove `ClusterRemove` RPC, make logging out idempotent

* Move calling `removeKubeConfig` and `maybeRemoveAppUpdatesManagingCluster` to main process

The main process should not depend on the renderer to clean up its own resources.

* Remove cleaning up kube dir

* Lint
2025-10-28 13:17:55 +00:00
Grzegorz Zdunek 3ed1816dda Connect: do not use cluster from profile as root cluster name (#60473)
* Do not read root cluster name from profile's `cluster` field

* Update docs for `name` field

* Use profile name in places that refer to workspace

* Improve comments

* `clusterName` -> `profileName`

* Get rid of `nameOrProfile`

* Add JSDoc for `captureUserLogin`

* `cluster` -> `certificate`
2025-10-27 11:59:22 +00:00
Cam Hutchison e06e2e78f7 proto/accessgraph: Add RPC for sending k8s audit logs to Access Graph (#59566)
* proto/accessgraph: Add RPC for sending k8s audit logs to Access Graph

Add a `KubeAuditLogsStream()` rpc to the `AccessGraphService` for
streaming Kubernetes apiserver audit logs from the Teleport discovery
service to access graph. This is intended for EKS audit logs which are
made available via CloudWatch, but can accommodate other k8s services.

The audit log messages are represented as a `google.protobuf.Struct` so
as to not depend on the k8s.io .proto files, but also as k8s typically
uses protos internally only - the expectation is that we'll receive the
apiserver audit logs as json-encoded strings. This encode easily as a
`google.protobuf.Struct`.

* proto: Generate protos for accessgraph

Generate proto and grpc code for changes to accessgraph/v1alpha1:

    make grpc/host

These changes add the `KubeAuditLogsStream()` rpc and associated types.
2025-10-16 00:33:50 +00:00
Rafał Cieślak 51a2d4181a Connect: Close terminal tab if last input was Ctrl+D, even on non-zero exit code (#59836)
* Include the last input in the exit event

* Close terminal tab if last input was Ctrl+D

* Remove use of create functions
2025-10-14 11:00:27 +00:00