Commit Graph
55 Commits
Author SHA1 Message Date
Gus Luxton 0b5bff73b6 Improve help text and error messages for tctl rm, fixes #2594 (#2724)
* Improve help text and error messages for tctl rm, fixes #2594
* Change 'kind' to 'type' for consistency
* Changed examples from role/admin to connector/github
* Added link to Teleport Enterprise
* Update e ref
2019-05-28 19:18:28 -03:00
Sasha Klizhentas 8356ae6a74 Use in-memory cache for the auth server API.
This commit expands the usage of the caching layer
for auth server API:

* Introduces in-memory cache that is used to serve all
Auth server API requests. This is done to achieve scalability
on 10K+ node clusters, where each node fetches certificate authorities,
roles, users and join tokens. It is not possible to scale
DynamoDB backend or other backends on 10K reads per seconds
on a single shard or partition. The solution is to introduce
an in-memory cache of the backend state that is always used
for reads.

* In-memory cache has been expanded to support all resources
required by the auth server.

* Experimental `tctl top` command has been introduced to display
common single node metrics.

Replace SQLite Memory Backend with BTree

SQLite in memory backend was suffering from
high tail latencies under load (up to 8 seconds
in 99.9%-ile on load configurations).

This commit replaces the SQLite memory caching
backend with in-memory BTree backend that
brought down tail latencies to 2 seconds (99.9%-ile)
and brought overall performance improvement.
2019-04-12 14:23:09 -07:00
Russell Jones 599b8b73c9 Fix scp client vulnerabilities.
Fixed scp client vulnerabilities to a malicious server found by Harry
Sintonen. For more information, see the following:

https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
2019-02-11 14:57:57 -08:00
Sasha Klizhentas f40df845db Events and GRPC API
This commit introduces several key changes to
Teleport backend and API infrastructure
in order to achieve scalability improvements
on 10K+ node deployments.

Events and plain keyspace
--------------------------

New backend interface supports events,
pagination and range queries
and moves away from buckets to
plain keyspace, what better aligns
with DynamoDB and Etcd featuring similar
interfaces.

All backend implementations are
exposing Events API, allowing
multiple subscribers to consume the same
event stream and avoid polling database.

Replacing BoltDB, Dir with SQLite
-------------------------------

BoltDB backend does not support
having two processes access the database at the
same time. This prevented Teleport
using BoltDB backend to be live reloaded.

SQLite supports reads/writes by multiple
processes and makes Dir backend obsolete
as SQLite is more efficient on larger collections,
supports transactions and can detect data
corruption.

Teleport automatically migrates data from
Bolt and Dir backends into SQLite.

GRPC API and protobuf resources
-------------------------------

GRPC API has been introduced for
the auth server. The auth server now serves both GRPC
and JSON-HTTP API on the same TLS socket and uses
the same client certificate authentication.

All future API methods should use GRPC and HTTP-JSON
API is considered obsolete.

In addition to that some resources like
Server and CertificateAuthority are now
generated from protobuf service specifications in
a way that is fully backward compatible with
original JSON spec and schema, so the same resource
can be encoded and decoded from JSON, YAML
and protobuf.

All models should be refactored
into new proto specification over time.

Streaming presence service
--------------------------

In order to cut bandwidth, nodes
are sending full updates only when changes
to labels or spec have occured, otherwise
new light-weight GRPC keep alive updates are sent
over to the presence service, reducing
bandwidth usage on multi-node deployments.

In addition to that nodes are no longer polling
auth server for certificate authority rotation
updates, instead they subscribe to event updates
to detect updates as soon as they happen.

This is a new API, so the errors are inevitable,
that's why polling is still done, but
on a way slower rate.
2018-12-10 17:20:24 -08:00
Cove Schneider 8b299e9c28 spelling cleanup 2018-11-15 12:44:51 -08:00
Russell Jones 87fe7a397d Added tsh for Windows. 2018-08-03 11:06:08 -07:00
Justin Gerace 7cfc78bafc Add Windows-specific code to enable building on Windows 2018-08-03 11:06:08 -07:00
Sasha Klizhentas a4c86e0603 Add public_addr support for auth and ssh services.
This commit fixes #1803, fixes #1889

* Adds support for public_addr for Proxy and Auth
* Parameter advertise_ip now supports host:port format
* Fixes incorrect output for tctl get proxies
* Fixes duplicate output of some error messages.
2018-05-02 18:04:05 -07:00
Russell Jones ff436e2339 Updated error logging. 2018-03-26 17:55:43 -07:00
Sasha Klizhentas 7d05c05b5b Fix logging, collect status of forked processes
fixes #1785, fixes #1776

This commit fixes several issues with output:

First teleport start now prints output
matching quickstart guide and sets default
console logging to ERROR.

SIGCHLD handler now only collects
processes PID forked during live restart
to avoid confusing other wait calls that
have no process status to collect any more.
2018-03-19 16:46:10 -07:00
Sasha Klizhentas 0130c6aa41 Mutual TLS Auth server and clients.
This commit introduced mutual TLS authentication
for auth server API server.

Auth server multiplexes HTTP over SSH - existing
protocol and HTTP over TLS - new protocol
on the same listening socket.

Nodes and users authenticate with 2.5.0 Teleport
using TLS mutual TLS except backwards-compatibility
cases.
2017-12-27 11:37:19 -08:00
Sasha Klizhentas db4952b788 revendor trace and logger, fixes #1450 2017-11-20 12:08:56 -08:00
Sasha Klizhentas f2549155fd Update DynamoDB backend
* Add support for TTL
* Add support for Batch reads
* Update default values
* Use batch reads to retrieve nodes
2017-11-10 12:20:18 -08:00
Sasha Klizhentas 9543bf2208 Merge branch 'master' into sasha/curiosity 2017-10-12 16:57:41 -07:00
Sasha Klizhentas 8839b85539 update trace 2017-10-09 12:15:56 -07:00
Sasha Klizhentas bb5f77854e before refactoring 2017-10-08 18:07:01 -07:00
Sasha Klizhentas 53f4a0128e introduce curiosity protocol and fix logs 2017-10-06 15:38:15 -07:00
dmitri 1f63b8d596 Address review comments 2017-10-04 18:56:57 -07:00
Sasha Klizhentas 8b81a0c384 Migrate to golang/dep for dependency management
Update following packages:

* Replace Sirupsen/log with sirupsen/log everywhere
* Update etcd client to 3.2.4
* Update docker/term to moby/term
* Update kr/pty to v1.0.0 release
* Update K8s client to 2.0
2017-08-22 15:30:30 -07:00
Russell Jones 6e785c7260 Validate certificate chain upon startup and provide more details in
certificate error messages.
2017-08-09 17:42:25 -07:00
Sasha Klizhentas 2950677d8a Patch for TLP-01-005: Check user principal when joining session. 2017-05-03 12:18:45 -07:00
Ev Kontsevoy 1755870f27 Logging fixes and more
- Fixed logging. Closes #875
- Removed dead code
- Fixed 'exec' tests on OSX
2017-03-29 17:12:50 -07:00
Ev Kontsevoy 7b967d0c66 Nicer HTTPS error message on mismatched proxy hostname
It tells the user now exactly why they're getting x509 error and how to
fix it.
2017-01-28 18:48:51 -08:00
Ev Kontsevoy 123dbe8b56 This commit improves error reporting in tsh
It does two things:

1. Forwards the original HTTP error to the user without replacing it
   with generic "object not found". Related PR for trace package:
   https://github.com/gravitational/trace/pull/27

2. Adds proper handling for `-d` (debug) CLI flag. When passed, `tsh`
   will print the call stack along with the error message.
2017-01-22 18:31:52 -08:00
Ev Kontsevoy 21bd8caa4f Addressed PR comments
- Comments
- Error creation
- Moved from Mailgun's frozen time to clockwork
- Made tests more reliable
2016-12-25 23:26:16 -08:00
dmitri 9decde57cc tctl: do not create datadir/host_uuid if none has been found - if the
client runs with elevated permissions and the command fails (for
instance, when the auth server state has not yet been generated), it
will leave the file behind possibly making further attempts to properly
generate content in data directory by a lower-privilege process impossible.
2016-09-22 13:43:58 +02:00
Ev Kontsevoy a2c7b3c100 Version bump
Also improved the error message for self-signed certificates
Fixes #511
2016-09-15 16:57:00 -07:00
Ev Kontsevoy b4a6a4f972 Cleaned up Teleport logging
* Downgraded many messages from `Debug` to `Info`
* Edited messages so they're not verbose and not too short
* Added "context" to some
* Added logical teleport component as [COMPONENT] at the beginning of
  many, making logs **vastly** easier to read.
* Added one more logging level option when creating Teleport (only
  Teleconsole uses it for now)

The output with 'info' severity now look extremely clean.
This is startup, for example:

```
INFO[0000] [AUTH]  Auth service is starting on turing:32829  file=utils/cli.go:107
INFO[0000] [SSH:auth] listening socket: 127.0.0.1:32829  file=sshutils/server.go:119
INFO[0000] [SSH:auth] is listening on 127.0.0.1:32829    file=sshutils/server.go:144
INFO[0000] [Proxy] Successfully registered with the cluster  file=utils/cli.go:107
INFO[0000] [Node] Successfully registered with the cluster  file=utils/cli.go:107
INFO[0000] [AUTH] keyAuth: 127.0.0.1:56886->127.0.0.1:32829, user=turing  file=auth/tun.go:370
WARN[0000] unable to load the auth server cache: open /tmp/cluster-teleconsole-client781495771/authservers.json: no such file or directory  file=auth/tun.go:594
INFO[0000] [SSH:auth] new connection 127.0.0.1:56886 -> 127.0.0.1:32829 vesion: SSH-2.0-Go  file=sshutils/server.go:205
INFO[0000] [AUTH] keyAuth: 127.0.0.1:56888->127.0.0.1:32829, user=turing.teleconsole-client  file=auth/tun.go:370
INFO[0000] [AUTH] keyAuth: 127.0.0.1:56890->127.0.0.1:32829, user=turing.teleconsole-client  file=auth/tun.go:370
INFO[0000] [Node] turing connected to the cluster 'teleconsole-client'  file=service/service.go:158
INFO[0000] [AUTH] keyAuth: 127.0.0.1:56892->127.0.0.1:32829, user=turing  file=auth/tun.go:370
INFO[0000] [SSH:auth] new connection 127.0.0.1:56890 -> 127.0.0.1:32829 vesion: SSH-2.0-Go  file=sshutils/server.go:205
INFO[0000] [SSH:auth] new connection 127.0.0.1:56888 -> 127.0.0.1:32829 vesion: SSH-2.0-Go  file=sshutils/server.go:205
INFO[0000] [Node] turing.teleconsole-client connected to the cluster 'teleconsole-client'  file=service/service.go:158
INFO[0000] [Node] turing.teleconsole-client connected to the cluster 'teleconsole-client'  file=service/service.go:158
INFO[0000] [SSH] received event(SSHIdentity)             file=service/service.go:436
INFO[0000] [SSH] received event(ProxyIdentity)           file=service/service.go:563
```
You can easily tell that auth, ssh node and proxy have successfully started.
2016-09-02 17:28:18 -07:00
Ev Kontsevoy 48a74fbeca Intermediate commit (scp up/down works agaisnt openSSH servers) 2016-05-26 14:46:56 -07:00
Ev Kontsevoy 9c5235ac90 Minor changes 2016-05-23 23:56:45 -07:00
Ev Kontsevoy 2d566ecbe2 Intermediate commit 2016-05-23 15:50:53 -07:00
Ev Kontsevoy 389e0a1a75 Started working on multi-site, multi-cluster demo via Docker 2016-05-09 16:27:50 -07:00
Ev Kontsevoy fcb9e7e799 Tried to make the error message better
When a user tries to login with a non-existing mapping (local OS does
not know anything about 'vince') he gets an ugly message:

"ERROR: cannot start shell"

Instead I wanted to show a nicer "host 'turing' does not have a local
user 'vince'"

The closest I could get was a generic 'access denied' + an informative
logging message in teleport logs.
2016-05-06 22:49:03 -07:00
Ev Kontsevoy 5e80c2d662 Simple filesystem-based keystore for TSH
Started re-writing Teleport client keystore. From a buggy JSON-to-file
to a standard, directory/filebased API behind a standard interface to
allow for alternative implementations.

```
~/.tsh/
└── sessions
    └── localhost
        ├── cert
        ├── key
        └── pub
```
2016-04-18 22:56:21 -07:00
Ev Kontsevoy 3599d4025e In CLI mode without -d flag Teleport now logs with Error level 2016-03-15 18:18:18 -07:00
klizhentas 7a2a9e334f add support for TELEPORT_DEBUG_TESTS environment variable turning on verbose testing 2016-03-14 14:07:45 -07:00
klizhentas d4e741ffc7 report errors in case of SSH access denied, fixes #179 2016-03-08 16:29:08 -08:00
klizhentas 1eb952b89f properly propagate HTTP errors, fixes #172 2016-03-07 17:05:57 -08:00
alexlyulkov b6a489df66 Merge pull request #175 from gravitational/alex/fatal-error
Fixed tests, fixed fatal error
2016-02-29 13:35:24 +03:00
Alex Lyulkov 745916a11f fixed FatalError 2016-02-29 13:30:46 +03:00
Ev Kontsevoy 02c6786521 Intermediate commit 2016-02-28 14:22:52 -08:00
Alex Lyulkov 545e3cb497 Fixed tests, fixed FatalError 2016-02-29 00:16:26 +03:00
Ev Kontsevoy e834cb25ac Minor fixes 2016-02-26 16:49:05 -08:00
klizhentas 6a9ad7b820 check nodes names when inviting them, fixes #119 2016-02-18 14:55:39 -08:00
Ev Kontsevoy bcfcefa8e5 Fixed issue #126
Summary:

Sasha proposed to use the certificate principal instead of the host name
when establishing new SSH connections.

What I did:

Replaced `ReadKeys()` function in `auth/init.go` with `ReadIdentity()`
which, instead of a simple "key signer" returns a more comprehensive
structure called "Identity"

The structure has the `Cert` field which can be used to obtain "valid
principals".

The first principal is used as an SSH username, instead of the hostname
like before.
2016-02-13 18:47:58 -08:00
Ev Kontsevoy 8ba6b474c6 Fixes #122 and fixes the dockerized build 2016-02-13 17:09:05 -08:00
klizhentas 26b3dabaae fixed #121 2016-02-13 12:03:01 -08:00
Ev Kontsevoy 7592e974cf Merge branch 'ev/105' into ev/105-tctl
Conflicts:
	tool/tctl/main.go
2016-02-09 14:47:59 -08:00
Ev Kontsevoy 2db4d98213 Incorporated PR comments from here:
https://github.com/gravitational/teleport/pull/115
2016-02-09 13:46:34 -08:00
Ev Kontsevoy 1610105910 Started work on simplifying tctl CLI 2016-02-08 22:29:15 -08:00