Commit Graph
3 Commits
Author SHA1 Message Date
Russell Jones 037d0bf32e Refactor regexp node labels. 2018-10-15 11:59:17 -07:00
ksuzuki ca3786eb79 wrote a test and fix a problem 2018-10-15 11:59:17 -07:00
Sasha Klizhentas 045490de25 External traits in node labels and regexp role map
This commit adds two extensions to template variables
in roles and adds support for regular expressions
and group captures in role mapping of trusted clusters.

1. Roles node_labels can expand variables from traits:

allow:
  node_labels:
    '{{external.key}}': '{{external.val}}'
deny:
  node_labels:
    '{{external.key}}': '{{external.val}}'

If traits variable is not found, label key pair in allow or
deny rule will be set to empty key or value, so if 'external.val'
trait is missing, the resulting role will not match
allow or deny rule:

allow:
  node_labels:
    '': 'val'
deny:
  node_labels:
    '': 'val'

Same thing will happen for missing value:

allow:
  node_labels:
    'key': ''
deny:
  node_labels:
    'key': ''

2. Trusted cluster role mapping can now
support advanced expressions:

a. Glob values will math any string, including
empty one

   role_map:
   - remote: 'cluster-*'
     local: [clusteradmin]

a. Regular expression syntax is supported:

Syntax: https://github.com/google/re2/wiki/Syntax

Brackets can be used as a capture group and referred
to with expand variable:

   role_map:
   - remote: '^clusteradmin-(.*)$'
     local: [unprivileged-$1]

Will map incoming role 'clusteradmin-account-1' to 'guest-account-1'.

3. Same regular expression syntax is supported for SAML and OIDC
mappings:

a. Glob matches of values instead of static matches:

  claims_to_roles:
      - {claim: "roles", value: "gravitational/*", roles: ["clusteradmin"]}

b. Regexp matches with subgroup expands:

  attributes_to_roles:
      - {name: "roles", value: "^gravitational/(.*)$", roles: ["cluster-$1"]}
2018-07-02 16:13:12 -07:00