Commit Graph
403 Commits
Author SHA1 Message Date
Steven Martin f00a4e2b66 Makes a common login error troubleshooting for sso docs (#11277)
* Incorporates a common login error troubleshooting include. Changed to show
the audit log screen in the web console initially.
2022-03-27 02:38:27 +00:00
Russell Jones f6561cef2c Added Jenkins tile to documentation. 2022-03-25 17:01:31 -07:00
Russell JonesandPaul Gottschling 38765cb4cf Add Teleport Cloud downloads page.
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-25 15:57:21 -07:00
0c451e3efd Added Machine ID Jenkins Guide.
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-25 15:49:41 -07:00
Russell Jones ce7b654615 Added admonition for Moderated Sessions. 2022-03-25 11:46:43 -07:00
Russell Jones 57d2b5f9b7 Reformatted Moderated Sessions Guide. 2022-03-25 11:46:43 -07:00
d2a656ef3f helm: Allow probe timeouts to be configurable (buddy merge of #11176) (#11396)
* Allow for probe timeouts to be configurable

When setting up a new Teleport enterprise cluster on GCP,
I noticed that I needed to set the probe timeouts to get the
cluster to be healthy. This seems to be a known issue (https://github.com/kubernetes/kubernetes/issues/89898).

As a "stopgap", I've updated the helm chart to allow for end users
to be able to configure these timeouts.

* Update configuration option name and add documentation

* Update docs/pages/kubernetes-access/helm/reference.mdx

Co-authored-by: Gus Luxton <gus@goteleport.com>

* Add tests for probeTimeoutSeconds

* Add probeTimeoutSeconds to required values

* Add probeTimeoutSeconds to teleport-kube-agent

* Add tests for probeTimeoutSeconds to teleport-kube-agent

* Add probeTimeoutSeconds to teleport-kube-agent reference

Co-authored-by: Hunter Madison <hunter.madison@instana.com>
Co-authored-by: Hunter Madison <hmadison@users.noreply.github.com>
2022-03-25 01:56:22 +00:00
Carson AndersonandPaul Gottschling 4054c79c7e Add metric to track number ssh connect attempts (#11240)
* add ssh connect attempts metric

* fix help message wording

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-24 20:34:00 +00:00
Gus Luxton e5cbd620ce helm: Add support for separate Postgres/Mongo listeners in teleport-cluster chart (#10858)
* helm: Update NOTES.txt for AWS ACM

* Add support for separate Postgres/MongoDB listeners in teleport-cluster chart

* Special case backend listener protocol based on presence of ACM annotation

* Add tests for separate listeners

* Add tests for ACM annotation setting backend protocol

* Don't add AWS annotations when not in AWS mode

* Adds for separatePostgresListener/separateMongoListener

Also adds missing example for setitng proxyListenerMode

* Add continuous backups permission to DynamoDB policy

Fixes #11411
2022-03-24 18:41:08 +00:00
Brian Joerger 11c66d23be [Docs] Add teleport.yaml docs for x11 forwarding (#10561) 2022-03-24 18:05:04 +00:00
Steven Martin 6c1aa75f3b Add in version string definition for role in Terraform reference (#10609)
* Add in version string definition for role
2022-03-24 01:48:11 +00:00
Steven Martin 07a7baf713 desktop clipboard docs mention (#11245)
* added clipboard mention
2022-03-24 01:26:46 +00:00
Paul Gottschling 9ff423ab89 Remove potentially confusing EOF line from snippet (#11325)
Our API getting started guide includes a go snippet that ends with
"EOF," which is not a Go keyword. If the reader isn't familiar with
Go but wants to follow this guide, the Go compiler will return a syntax
error.

This change removes the line.
2022-03-23 21:19:09 +00:00
Paul GottschlingandNic Klaassen 77314ab4c2 Split the AWS Node Joining guide (#11081)
* Split the AWS Node Joining guide

This is to better address users with different scopes (see #10633).

Since the EC2 method is irrelevant for Cloud users, this approach makes
it straightforward to add an edition warning to the top of the EC2 join
method guide and scoped Tabs components to the IAM join method guide.

The alternative was to add nested Tabs components, with the top level
including Cloud vs. Self-Hosted TabItems and the inner level including
TabItems for the IAM and EC2 join methods. This looked pretty
unattractive and couldn't accommodate the final section on using the
EC2 method with multiple AWS accounts.

* Respond to PR feedback

Co-authored-by: Nic Klaassen <nic@goteleport.com>

* Respond to PR feedback

Co-authored-by: Nic Klaassen <nic@goteleport.com>
2022-03-23 21:09:26 +00:00
Paul Gottschling 9575f0e942 Prepare the metrics reference for Cloud users (#10880)
* Metrics guide

Add separate Tabs for self-hosted and Cloud editions

* Prepare the metrics reference for Cloud users

Arrange metrics into H2 sections, both making the page easier to
navigate and making it clear which metrics are relevant to Cloud
users.

Add a warning that in Cloud, the Auth and Proxy do not expose
metrics endpoints.

* Respond to PR feedback

- Move the certificate_mismatch_total to a more appropriate place
  with a more accurate description
- Correct gcs_ metric categories
- Make the rx and tx metric descriptions a bit more accurate
- Also perform light copy-editing on metric descriptions
2022-03-23 20:52:59 +00:00
Nic Klaassen 8299903bd0 Fix typo in HSM docs (#11390)
s/compabitility/compatibility/
2022-03-23 20:27:32 +00:00
Jakub Nyckowski 575f583355 Update Redis links in docs (#11391) 2022-03-23 14:13:33 -04:00
Steven Martin 4f09a8ade3 Teleport cloud license info and other info (#11093)
Provide a note that Teleport Cloud does not require license file management.  Also provides fyi that when downloading you will see the licensed products.  Gives example warning message when attempting to use unlicensed products.
2022-03-23 13:43:21 +00:00
Steven Martin df69628802 Added all token types in tctl reference (#11254) 2022-03-23 13:13:52 +00:00
Paul Gottschling 506da87a96 Split the Helm chart reference (#11292)
This will make it easier to navigate to different values settings for
each chart, since values can have their own H2 sections that are
distinct from chart names. (Previously, both chart names and values
settings were organized into H2 section headings.)

This will also mean that edition warnings for Cloud users can be more
visible, since we can place them at the top of a page for a given chart.

See #10636
2022-03-22 14:47:57 -03:00
Paul Gottschling 973cb8aac0 Edit three guides for Cloud users (#11115)
See #10633

Terraform Provider guide

- Add tabbed prerequisites so users only see information relevant to
  their scopes.

- Add the impersonation section as an H3 rather than an Admonition. If
  users are learning how to use our Terraform provider, they likely
  will not have enabled impersonation for the Terraform user, and would
  always need to read the Admonition, so this would work better as an
  H3.

- Add a scoped Notice indicating which address to use for the cluster
  address in the sample Terraform config.

Fluentd plugin guide

- Add tabbed instructions for users of different scopes.

- Move the impersonation Admonition to an H3 so readers can configure
  impersonation without running into an error.

- Misc clarity/style edits.

Certificate Authority Rotation

- Add tabbed prerequisites so users of one scope don't see information
  intended for other scopes.
2022-03-21 22:34:34 +00:00
Paul Gottschling 491dfe4ad9 Edit four Kubernetes Access guides for Cloud users (#11154)
See #10636

Introduction

- Remove unnecessary mention of Access Requests in a paragraph that is
  otherwise relevant for all editions.
- Minor style/grammar tweaks

Standalone Teleport

- Add tabbed instructions for different scopes where applicable.

- Minor style/grammar tweaks

Connect Kubernetes Cluster to Teleport

- Use Tabbed instructions and a Notice box so users with one scope
  do not see instructions for other scopes.

- Remove irrelevant details that are specific to self-hosted deployments.

Federation

- Add a Tabs component to separate instructions for Cloud and Self-
  Hosted users
- Minor style tweaks

Multiple Clusters

- Add tabbed instructions for Cloud/Self-Hosted users.
2022-03-21 21:39:47 +00:00
Russell JonesandPaul Gottschling 70474d9871 Added Machine ID CLI and configuration references.
Added Machine ID CLI and configuration references.

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-18 14:19:58 -07:00
Paul Gottschling 0aa6855c8f Add notes about wildcard certificates (#9454)
* Add notes about wildcard certificates

Guides to getting started with Teleport on various platforms
recommend creating a DNS record for *.teleport.com. It would help
prospective users to know why this is needed. This change adds
context for why Application Access requires a wildcard subdomain.

Fixes #5378

* Respond to PR feedback

- Move information into a partial
- Mention that you can create a DNS A record for each application-
  specific subdomain

* Restore DNS-related cloud provider commands
2022-03-18 18:19:36 +00:00
Paul Gottschling 775a3872c6 Fix broken link in the ADFS guide (#10626)
* Fix broken link in the ADFS guide

This was hurting SEO. Since the link was not intended to be
used for navigation, I turned it into code-style text instead.

Also took this opportunity to do some light copy-editing of the
ADFS guide.

Fixes #8714

* Incorporate PR feedback

Also adds a few minor tweaks.
2022-03-18 16:57:20 +00:00
Paul Gottschling fb1e246d75 Edit Helm installation instructions (#11177)
While addressing #10636, I noticed that the Details box that appears
for Cloud users when they visit some of our Helm guides is in a slightly
odd location, in the middle of a Prerequisites item. I have moved this to
the top of each guide instead.

I have also refactored the helm-install.mdx partial to split it into
multiple partials, which allows us to use the "Step n/d" format in our
Helm guides.

Also adds a Cloud warning to the Digital Ocean Helm guide.
2022-03-18 16:48:29 +00:00
Paul Gottschling a7efb81902 Situate the Installation guide more clearly (#9524)
* Situate the Installation guide more clearly

For a reader who begins their journey through the Teleport docs
with the Installation guide, it can be difficult to determine
what to do after following the guide. This change makes the
relationship between the Installation page and other docs pages
clearer by:

- Adding an Admonition to read the Getting Started guides if you
  have not yet tried Teleport. These guides include installation
  instructions, so they can be our recommended starting place.

- Adding a Next Steps section that links to instructions on
  enabling Teleport for different infrastructure resources.

Closes #9355

* Respond to PR feedback
2022-03-18 16:19:01 +00:00
Lisa Kim f39e3bf180 Add doc for filter support for CLI tools (#11012)
For the flags --search, --query, and labels
2022-03-18 08:36:26 -07:00
Paul Gottschling 4a6c44712d Remove the v5 Kubernetes migration guide (#11180)
Since we no longer support version 5, including this guide only
risks misleading current/prospective users. This change removes
the v5 migration guide and redirects the path to the Kubernetes Access
Introduction page.
2022-03-18 15:22:08 +00:00
Paul Gottschling 2cb0b66f7b Add Cloud-specific instructions to two guides (#10674)
* Add Cloud-specific instructions to two guides

Ensure that users of a particular scope don't see irrelevant info

See #10633

GitHub SSO guide
 - Edit the tctl partial to show only scope-relevant info.
 - Use tabs in the Prerequisites
 - Light edits for clarity

Adding Nodes
- Use Tabs for prerequisites
- Move sections specific to self-hosted deployments into Details
  boxes that are hidden for Cloud users
- Use Tabs components to offer Cloud-specific alternatives to
  examples of commands that presuppose a self-hosted deployment
- Misc clarity edits

* Respond to PR feedback

* Fix linter issues
2022-03-17 22:10:21 +00:00
Steven Martin f968393db4 corrects some powershell examples and put in code for linux commands to fix copy/paste (#11224) 2022-03-17 20:15:31 +00:00
Gus Luxton a463dacaf2 helm: Adds extraArgs and extraEnv to teleport-kube-agent (#11155)
* helm: Adds extraArgs and extraEnv to teleport-kube-agent

These were present in teleport-cluster but not teleport-kube-agent. This PR fixes that.

* Line breaks

* Also add to StatefulSet
2022-03-17 18:22:59 +00:00
Zac BergquistandPaul Gottschling 072956e4a0 docs: clarify /healthz and /readyz (#11085)
- Rename the page, since it's about diagnostics rather than metrics
  alone
- Change major section headings to H2s so they apper in the table of
  contents
- Move information about heartbeats and recovery to an H3 so it's
  more visible

Updates #10799

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-17 16:46:12 +00:00
Paul Gottschling 2c728d9d65 Mention Cloud compatibility in three guides (#10021)
* Mention Cloud compatibility in three guides

Server Access getting started:
- Remove the instructions to install and set up the Auth
  Service, and add references to main Getting Started guides
  and Cloud signup page.
- Add a prerequisite to have deployed the Auth Service and
  Proxy Service.

EC2 joining guide: make it explicit that the Cloud is not
compatible with this. Also make small style tweaks.

App Access getting started page:
- The guide assumes that you are running the Auth Service,
  Proxy Service, and App Service via the same binary, which
  does not work for Cloud users.

* Respond to PR feedback

- Add newlines after headings
- Use teleport app start instead of teleport start --roles=app
- Fix incorrect Ubuntu version number
- Add a Details box explaining tctl usage for Cloud
- Correctly capitalize "Node"
2022-03-17 21:15:45 +05:30
Tim Buckley 14a0fa37ee Fix bot_name in Machine ID docs (#11041)
* Fix bot_name in Machine ID docs

Follow-up to #11039, this fixes the bot_name token field to use the
revised value (bot name rather than bot username, to match the field
name).

See also #10854

* Remove outdated comment warning
2022-03-17 00:16:23 +00:00
Zac Bergquist 9c749e80e7 docs: add desktop session recording and clipboard sharing (#11005) 2022-03-16 22:35:11 +00:00
Russell JonesandPaul Gottschling cdc836df72 Refactored Ansible guide to work with Machine ID.
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-15 20:47:40 -07:00
Russell Jones 385780f91d Cleanup of Machine ID Getting Started Guide. 2022-03-15 20:36:11 -07:00
Zac Bergquist 74bc1fbed9 Remove mention of max ttl for tctl tokens command (#11148)
The 48h maximum is enforced for `tctl users add`,
not `tctl tokens add`.

Fixes #11137
2022-03-15 20:46:10 +00:00
Steven Martin cfa80a8a13 correct db connect example for postgres (#11095) 2022-03-15 02:29:14 +00:00
Zac Bergquist 0d9d75eecc Update docs for FIPS users
In order to configure WebAuthn on FIPS builds, you must set
local_auth to false and second_factor to optional.

Fixes #11080
2022-03-14 15:09:56 -06:00
Zac Bergquist e945e62d18 docs: add desktops to per-session-mfa page 2022-03-14 15:09:56 -06:00
Logan Davis 823fc293bf Add documentation for tsh proxy app (#10924) 2022-03-14 13:56:18 +00:00
86ad572b78 Add Redis docs (#10693)
Add Redis documentation on how to setup Redis.

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
Co-authored-by: Marek Smoliński <marek@goteleport.com>
2022-03-11 18:05:13 +00:00
Joel 92543d9b3e Moderated Sessions improvements (#10991) 2022-03-10 23:04:12 +00:00
Russell Jones 7fb9d71e90 Update dual-authz.mdx 2022-03-10 11:47:26 -08:00
Gus Luxton d617f2a177 Change token example to add node only (#11004)
* Change token example to add node only

Given that it's not possible to join a proxy server via proxy address (`teleport.example.com:443`) and there relatively few circumstances where people would want to add both `node` and `proxy` services on one cluster, I think this example is likely to cause more confusion than anything else.

* Update adding-nodes.mdx

Remove static token example and tidy up
2022-03-10 18:46:07 +00:00
Paul Gottschling f189f1b809 Fix ACME instructions in start-auth-proxy.mdx (#11015)
start-auth-proxy.mdx is a partial used by a number of Database Access
guides. After PR #9556, the partial included garbled instructions for
setting up Teleport with Let's Encrypt. This change edits these
instructions for clarity.
2022-03-10 18:38:41 +00:00
95e64b369f Added Machine ID docs.
Added Machine ID docs.

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Xin Ding <xinding33@gmail.com>
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-10 10:21:44 -08:00
Steven Martin 38d31a119a Access Control, K8s Cluster docs set scope and AWS first (#10721) 2022-03-10 04:30:04 +00:00