The Forwarder type has been replaced with the new GRPC/streaming based
session recording and was only used in tests.
The RecordSessions param is never consulted, as it was replaced with
AuditWriter's RecordOutput param a couple of years ago.
These events are remnants of the old system before our events
were strongly-typed protos, and were unused in the code
(save for a few tests, which were updated)
This changes prompt.ContextReader in the following ways:
Reads only happen as a response to Read methods being called. This allows
ContextReader to coexist with other readers as long as no reads are abandoned.
ReadPassword is now available, the underlying implementation being
term.ReadPassword. An abandoned password read may be turned into a clean read.
This gives us some UX flexibility when callers abandon password reads (looking
at you, PromptMFAChallenge). Turning clean reads into password reads is not
supported. It's tricky and I have a few ideas, but it's not paramount at this
moment.
This solves the woes caused by abandoned OTP reads followed by PIN reads in
different packages, such as client.PromptMFAChallenge followed by tsh mfa add's
implementation.
#9160
* Move ContextReader to its own file
* Refactor ContextReader and implement ReadPassword
* Test ReadPassword
* Fix typos
* Remove prompt.StdinSync()
prompt.Stdin() has the same behavior for non-abandoned reads.
* Group /x/term methods under a type
* Allow for probe timeouts to be configurable
When setting up a new Teleport enterprise cluster on GCP,
I noticed that I needed to set the probe timeouts to get the
cluster to be healthy. This seems to be a known issue (https://github.com/kubernetes/kubernetes/issues/89898).
As a "stopgap", I've updated the helm chart to allow for end users
to be able to configure these timeouts.
* Update configuration option name and add documentation
* Update docs/pages/kubernetes-access/helm/reference.mdx
Co-authored-by: Gus Luxton <gus@goteleport.com>
* Add tests for probeTimeoutSeconds
* Add probeTimeoutSeconds to required values
* Add probeTimeoutSeconds to teleport-kube-agent
* Add tests for probeTimeoutSeconds to teleport-kube-agent
* Add probeTimeoutSeconds to teleport-kube-agent reference
Co-authored-by: Hunter Madison <hunter.madison@instana.com>
Co-authored-by: Hunter Madison <hmadison@users.noreply.github.com>
* helm: Update NOTES.txt for AWS ACM
* Add support for separate Postgres/MongoDB listeners in teleport-cluster chart
* Special case backend listener protocol based on presence of ACM annotation
* Add tests for separate listeners
* Add tests for ACM annotation setting backend protocol
* Don't add AWS annotations when not in AWS mode
* Adds for separatePostgresListener/separateMongoListener
Also adds missing example for setitng proxyListenerMode
* Add continuous backups permission to DynamoDB policy
Fixes#11411
Our API getting started guide includes a go snippet that ends with
"EOF," which is not a Go keyword. If the reader isn't familiar with
Go but wants to follow this guide, the Go compiler will return a syntax
error.
This change removes the line.
* Split the AWS Node Joining guide
This is to better address users with different scopes (see #10633).
Since the EC2 method is irrelevant for Cloud users, this approach makes
it straightforward to add an edition warning to the top of the EC2 join
method guide and scoped Tabs components to the IAM join method guide.
The alternative was to add nested Tabs components, with the top level
including Cloud vs. Self-Hosted TabItems and the inner level including
TabItems for the IAM and EC2 join methods. This looked pretty
unattractive and couldn't accommodate the final section on using the
EC2 method with multiple AWS accounts.
* Respond to PR feedback
Co-authored-by: Nic Klaassen <nic@goteleport.com>
* Respond to PR feedback
Co-authored-by: Nic Klaassen <nic@goteleport.com>
* Metrics guide
Add separate Tabs for self-hosted and Cloud editions
* Prepare the metrics reference for Cloud users
Arrange metrics into H2 sections, both making the page easier to
navigate and making it clear which metrics are relevant to Cloud
users.
Add a warning that in Cloud, the Auth and Proxy do not expose
metrics endpoints.
* Respond to PR feedback
- Move the certificate_mismatch_total to a more appropriate place
with a more accurate description
- Correct gcs_ metric categories
- Make the rx and tx metric descriptions a bit more accurate
- Also perform light copy-editing on metric descriptions
When we deprecated the password_file option for Teleport 9, we left
the configuration property in the config so that we could give v8
users who had recently upgraded a nice error message letting them
know that we deprecated this field.
For Teleport 10, everyone coming from v9 will have already removed
this property, so the deprecation warning is no longer necessary.
Passwordless login is enabled by the global `--pwdless` flag. Registration gets
a new prompt and an `--allow-passwordless` flag.
UX messages were tweaked to follow the descriptions on RFD 53: Passwordless
FIDO2[1].
Passwordless login requires two touches for all devices (both PIN and biometric).
I'd like to get it down to a single touch, at least for the most common
situations, but that'll be a follow up to this work.
Passwordless support requires `tsh` to be compiled with the `libfido2` tag, try
`go build -tags=libfido2 ./tool/tsh`.
#9160
[1] https://github.com/gravitational/teleport/blob/master/rfd/0053-passwordless-fido2.md#ux
* Allow reuse of devices for passwordless
* Implement passwordless registration in tsh
* Add better tracing to FIDO2 filters
* Implement passwordless logins in tsh
* Make --pwdless a global flag
* Fix lint errors
* Fix U2F tests
* Use initClient's URL as origin
* Distinguish whether --allow-passwordless is set or unset
Provide a note that Teleport Cloud does not require license file management. Also provides fyi that when downloading you will see the licensed products. Gives example warning message when attempting to use unlicensed products.