Commit Graph
7730 Commits
Author SHA1 Message Date
Steven Martin f00a4e2b66 Makes a common login error troubleshooting for sso docs (#11277)
* Incorporates a common login error troubleshooting include. Changed to show
the audit log screen in the web console initially.
2022-03-27 02:38:27 +00:00
Walt 90dde13ef0 Re-sign .drone.yml (#11478) 2022-03-26 01:26:59 +00:00
Russell Jones f6561cef2c Added Jenkins tile to documentation. 2022-03-25 17:01:31 -07:00
Russell JonesandPaul Gottschling 38765cb4cf Add Teleport Cloud downloads page.
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-25 15:57:21 -07:00
0c451e3efd Added Machine ID Jenkins Guide.
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-25 15:49:41 -07:00
Russell Jones 1503fded2b Update Machine ID icon to chip icon. 2022-03-25 15:29:01 -07:00
Zac Bergquist 82943f38dd AuditLog: Remove unused EventsC
This was used to test legacy audit log behavior, which has since
been removed.
2022-03-25 15:21:22 -06:00
Zac Bergquist 4e2e834b68 Remove unused DiskSessionLogger 2022-03-25 15:21:22 -06:00
Zac Bergquist bd7e7a84f0 Remove events.Forwarder and RecordSessions config param
The Forwarder type has been replaced with the new GRPC/streaming based
session recording and was only used in tests.

The RecordSessions param is never consulted, as it was replaced with
AuditWriter's RecordOutput param a couple of years ago.
2022-03-25 15:21:22 -06:00
Zac Bergquist 58b2aac411 Remove unused GRPC service 2022-03-25 15:21:22 -06:00
Zac Bergquist 3dc33ccc32 lib/events: remove more old code
This removes support for the pre-5.1.0 streaming directory, and
removes the unused Recorder type.
2022-03-25 15:21:22 -06:00
Zac Bergquist 62f687bef7 lib/events: remove legacy event types
These events are remnants of the old system before our events
were strongly-typed protos, and were unused in the code
(save for a few tests, which were updated)
2022-03-25 15:21:22 -06:00
fheineckeandGus Luxton 1daf7d2302 [master forward-port] Fixed RPMs using artifacts compiled against a too-new version of glibc (#11026)
* Fixed RPMs using artifacts compiled against a too-new version of glibc

* Fixed RPM naming issue

* Apply suggestions from code review

Co-authored-by: Gus Luxton <gus@goteleport.com>

Co-authored-by: Gus Luxton <gus@goteleport.com>
2022-03-25 20:55:31 +00:00
Gabriel Corado 58ca1bdbb0 fix(db): send initial heartbeat when there is no static dbs (#11160) 2022-03-25 20:17:54 +00:00
Russell Jones ce7b654615 Added admonition for Moderated Sessions. 2022-03-25 11:46:43 -07:00
Russell Jones 57d2b5f9b7 Reformatted Moderated Sessions Guide. 2022-03-25 11:46:43 -07:00
STeve (Xin) Huang fd12e934ee RDS & Redshfit support for AWS China regions (part 1?) (#10560) 2022-03-25 17:40:51 +00:00
Alan Parra 5a11006f81 Add ReadPassword functionality to ContextReader (#11436)
This changes prompt.ContextReader in the following ways:

Reads only happen as a response to Read methods being called. This allows
ContextReader to coexist with other readers as long as no reads are abandoned.
ReadPassword is now available, the underlying implementation being
term.ReadPassword. An abandoned password read may be turned into a clean read.
This gives us some UX flexibility when callers abandon password reads (looking
at you, PromptMFAChallenge). Turning clean reads into password reads is not
supported. It's tricky and I have a few ideas, but it's not paramount at this
moment.

This solves the woes caused by abandoned OTP reads followed by PIN reads in
different packages, such as client.PromptMFAChallenge followed by tsh mfa add's
implementation.

#9160

* Move ContextReader to its own file
* Refactor ContextReader and implement ReadPassword
* Test ReadPassword
* Fix typos
* Remove prompt.StdinSync()

prompt.Stdin() has the same behavior for non-abandoned reads.

* Group /x/term methods under a type
2022-03-25 17:17:20 +00:00
Marek Smoliński 335adf1f4e Don't respect HTTP_PROXY env in k8 forwarder (#11257) 2022-03-25 13:49:59 +01:00
Edoardo Spadolini 4384c354ff Reexec with /proc/self/exe on Linux (#11283)
* Reexec with `/proc/self/exe` on Linux

* Add a check for qemu-user

* Add comment
2022-03-25 10:16:43 +00:00
d2a656ef3f helm: Allow probe timeouts to be configurable (buddy merge of #11176) (#11396)
* Allow for probe timeouts to be configurable

When setting up a new Teleport enterprise cluster on GCP,
I noticed that I needed to set the probe timeouts to get the
cluster to be healthy. This seems to be a known issue (https://github.com/kubernetes/kubernetes/issues/89898).

As a "stopgap", I've updated the helm chart to allow for end users
to be able to configure these timeouts.

* Update configuration option name and add documentation

* Update docs/pages/kubernetes-access/helm/reference.mdx

Co-authored-by: Gus Luxton <gus@goteleport.com>

* Add tests for probeTimeoutSeconds

* Add probeTimeoutSeconds to required values

* Add probeTimeoutSeconds to teleport-kube-agent

* Add tests for probeTimeoutSeconds to teleport-kube-agent

* Add probeTimeoutSeconds to teleport-kube-agent reference

Co-authored-by: Hunter Madison <hunter.madison@instana.com>
Co-authored-by: Hunter Madison <hmadison@users.noreply.github.com>
2022-03-25 01:56:22 +00:00
Joel 90a0ff54b9 Limit stdout/stderr buffering in paused sessions (#11347) 2022-03-24 21:19:56 +00:00
Carson AndersonandPaul Gottschling 4054c79c7e Add metric to track number ssh connect attempts (#11240)
* add ssh connect attempts metric

* fix help message wording

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-24 20:34:00 +00:00
Forrest Marshall 50d767d304 improve cache test perf 2022-03-24 12:52:20 -07:00
Jeff Pihach 4c0df63633 Move the install.sh script into the oss version and import it on build instead of requiring a copy/paste to update. (#11352) 2022-03-24 19:22:48 +00:00
Gus Luxton e5cbd620ce helm: Add support for separate Postgres/Mongo listeners in teleport-cluster chart (#10858)
* helm: Update NOTES.txt for AWS ACM

* Add support for separate Postgres/MongoDB listeners in teleport-cluster chart

* Special case backend listener protocol based on presence of ACM annotation

* Add tests for separate listeners

* Add tests for ACM annotation setting backend protocol

* Don't add AWS annotations when not in AWS mode

* Adds for separatePostgresListener/separateMongoListener

Also adds missing example for setitng proxyListenerMode

* Add continuous backups permission to DynamoDB policy

Fixes #11411
2022-03-24 18:41:08 +00:00
Brian Joerger 11c66d23be [Docs] Add teleport.yaml docs for x11 forwarding (#10561) 2022-03-24 18:05:04 +00:00
Carson Anderson e577b41244 Change client dialOpts append order (#11322)
* change order of dialOpts to respect config provided opts
2022-03-24 15:17:25 +00:00
Joel 30647c455b Set podname before message uses it (#11286) 2022-03-24 14:42:00 +00:00
Joel 445d40d8a8 Sort sessions by creation date (#11345) 2022-03-24 12:58:49 +00:00
Joel 0bd0b234e3 Update cargo deps (#11400) 2022-03-24 12:15:13 +00:00
Joel b99613507b [RFD Update] Clarify RBAC rule application for session joining (#11223) 2022-03-24 07:10:54 +00:00
Steven Martin 6c1aa75f3b Add in version string definition for role in Terraform reference (#10609)
* Add in version string definition for role
2022-03-24 01:48:11 +00:00
Steven Martin 07a7baf713 desktop clipboard docs mention (#11245)
* added clipboard mention
2022-03-24 01:26:46 +00:00
STeve (Xin) Huang a9267d8ca7 Fix broken header img and update badge in Readme (#11395) 2022-03-23 23:57:09 +00:00
Forrest 5bd9434ab1 improve ca cmp (#10351) 2022-03-23 23:08:38 +00:00
James PerryandZac Bergquist 536671b541 set err to scanner.Err (#11100)
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
2022-03-23 22:31:38 +00:00
rosstimothy 487ba57a3c Fix panic in getWebConfig (#11389)
Refactored the usage of the types.AuthPreference returned from
GetAuthPreference so that it is only accessed if there were no
errors.
2022-03-23 17:54:25 -04:00
Paul Gottschling 9ff423ab89 Remove potentially confusing EOF line from snippet (#11325)
Our API getting started guide includes a go snippet that ends with
"EOF," which is not a Go keyword. If the reader isn't familiar with
Go but wants to follow this guide, the Go compiler will return a syntax
error.

This change removes the line.
2022-03-23 21:19:09 +00:00
Paul GottschlingandNic Klaassen 77314ab4c2 Split the AWS Node Joining guide (#11081)
* Split the AWS Node Joining guide

This is to better address users with different scopes (see #10633).

Since the EC2 method is irrelevant for Cloud users, this approach makes
it straightforward to add an edition warning to the top of the EC2 join
method guide and scoped Tabs components to the IAM join method guide.

The alternative was to add nested Tabs components, with the top level
including Cloud vs. Self-Hosted TabItems and the inner level including
TabItems for the IAM and EC2 join methods. This looked pretty
unattractive and couldn't accommodate the final section on using the
EC2 method with multiple AWS accounts.

* Respond to PR feedback

Co-authored-by: Nic Klaassen <nic@goteleport.com>

* Respond to PR feedback

Co-authored-by: Nic Klaassen <nic@goteleport.com>
2022-03-23 21:09:26 +00:00
Paul Gottschling 9575f0e942 Prepare the metrics reference for Cloud users (#10880)
* Metrics guide

Add separate Tabs for self-hosted and Cloud editions

* Prepare the metrics reference for Cloud users

Arrange metrics into H2 sections, both making the page easier to
navigate and making it clear which metrics are relevant to Cloud
users.

Add a warning that in Cloud, the Auth and Proxy do not expose
metrics endpoints.

* Respond to PR feedback

- Move the certificate_mismatch_total to a more appropriate place
  with a more accurate description
- Correct gcs_ metric categories
- Make the rx and tx metric descriptions a bit more accurate
- Also perform light copy-editing on metric descriptions
2022-03-23 20:52:59 +00:00
Nic Klaassen 8299903bd0 Fix typo in HSM docs (#11390)
s/compabitility/compatibility/
2022-03-23 20:27:32 +00:00
Andrew Burke 4543bfd98d Respect HTTP_PROXY/HTTPS_PROXY (#10209)
This change allows tsh to use HTTP proxies when HTTP_PROXY/HTTPS_PROXY is set in the environment.
2022-03-23 19:58:19 +00:00
Zac Bergquist 6277ef8620 Remove LDAP password_file from configuration (#11331)
When we deprecated the password_file option for Teleport 9, we left
the configuration property in the config so that we could give v8
users who had recently upgraded a nice error message letting them
know that we deprecated this field.

For Teleport 10, everyone coming from v9 will have already removed
this property, so the deprecation warning is no longer necessary.
2022-03-23 19:34:30 +00:00
STeve (Xin) Huang 3d7de736e3 Improve cli usage when command name is long (#10981) 2022-03-23 19:08:42 +00:00
Alan Parra b2c5c8ecb0 Add FIDO2 passwordless login and registration to tsh (#11321)
Passwordless login is enabled by the global `--pwdless` flag. Registration gets
a new prompt and an `--allow-passwordless` flag.

UX messages were tweaked to follow the descriptions on RFD 53: Passwordless
FIDO2[1].

Passwordless login requires two touches for all devices (both PIN and biometric).
I'd like to get it down to a single touch, at least for the most common
situations, but that'll be a follow up to this work.

Passwordless support requires `tsh` to be compiled with the `libfido2` tag, try
`go build -tags=libfido2 ./tool/tsh`.

#9160

[1] https://github.com/gravitational/teleport/blob/master/rfd/0053-passwordless-fido2.md#ux

* Allow reuse of devices for passwordless
* Implement passwordless registration in tsh
* Add better tracing to FIDO2 filters
* Implement passwordless logins in tsh
* Make --pwdless a global flag
* Fix lint errors
* Fix U2F tests
* Use initClient's URL as origin
* Distinguish whether --allow-passwordless is set or unset
2022-03-23 18:38:10 +00:00
Jakub Nyckowski 575f583355 Update Redis links in docs (#11391) 2022-03-23 14:13:33 -04:00
Zac Bergquist 8521b388f2 Remove legacy JSON API for host certs (#11330)
This is a follow up to e256170d60.
Now that Teleport 9 is out, we can remove the last traces of
this API for Teleport 10.
2022-03-23 17:57:22 +01:00
Alex McGrath 3d35263a6c Add a .tsh/config file and add support for configuring custom http headers 2022-03-23 14:19:07 +00:00
Steven Martin 4f09a8ade3 Teleport cloud license info and other info (#11093)
Provide a note that Teleport Cloud does not require license file management.  Also provides fyi that when downloading you will see the licensed products.  Gives example warning message when attempting to use unlicensed products.
2022-03-23 13:43:21 +00:00