* Allow for probe timeouts to be configurable
When setting up a new Teleport enterprise cluster on GCP,
I noticed that I needed to set the probe timeouts to get the
cluster to be healthy. This seems to be a known issue (https://github.com/kubernetes/kubernetes/issues/89898).
As a "stopgap", I've updated the helm chart to allow for end users
to be able to configure these timeouts.
* Update configuration option name and add documentation
* Update docs/pages/kubernetes-access/helm/reference.mdx
Co-authored-by: Gus Luxton <gus@goteleport.com>
* Add tests for probeTimeoutSeconds
* Add probeTimeoutSeconds to required values
* Add probeTimeoutSeconds to teleport-kube-agent
* Add tests for probeTimeoutSeconds to teleport-kube-agent
* Add probeTimeoutSeconds to teleport-kube-agent reference
Co-authored-by: Hunter Madison <hunter.madison@instana.com>
Co-authored-by: Hunter Madison <hmadison@users.noreply.github.com>
* helm: Update NOTES.txt for AWS ACM
* Add support for separate Postgres/MongoDB listeners in teleport-cluster chart
* Special case backend listener protocol based on presence of ACM annotation
* Add tests for separate listeners
* Add tests for ACM annotation setting backend protocol
* Don't add AWS annotations when not in AWS mode
* Adds for separatePostgresListener/separateMongoListener
Also adds missing example for setitng proxyListenerMode
* Add continuous backups permission to DynamoDB policy
Fixes#11411
Our API getting started guide includes a go snippet that ends with
"EOF," which is not a Go keyword. If the reader isn't familiar with
Go but wants to follow this guide, the Go compiler will return a syntax
error.
This change removes the line.
* Split the AWS Node Joining guide
This is to better address users with different scopes (see #10633).
Since the EC2 method is irrelevant for Cloud users, this approach makes
it straightforward to add an edition warning to the top of the EC2 join
method guide and scoped Tabs components to the IAM join method guide.
The alternative was to add nested Tabs components, with the top level
including Cloud vs. Self-Hosted TabItems and the inner level including
TabItems for the IAM and EC2 join methods. This looked pretty
unattractive and couldn't accommodate the final section on using the
EC2 method with multiple AWS accounts.
* Respond to PR feedback
Co-authored-by: Nic Klaassen <nic@goteleport.com>
* Respond to PR feedback
Co-authored-by: Nic Klaassen <nic@goteleport.com>
* Metrics guide
Add separate Tabs for self-hosted and Cloud editions
* Prepare the metrics reference for Cloud users
Arrange metrics into H2 sections, both making the page easier to
navigate and making it clear which metrics are relevant to Cloud
users.
Add a warning that in Cloud, the Auth and Proxy do not expose
metrics endpoints.
* Respond to PR feedback
- Move the certificate_mismatch_total to a more appropriate place
with a more accurate description
- Correct gcs_ metric categories
- Make the rx and tx metric descriptions a bit more accurate
- Also perform light copy-editing on metric descriptions
Provide a note that Teleport Cloud does not require license file management. Also provides fyi that when downloading you will see the licensed products. Gives example warning message when attempting to use unlicensed products.
This will make it easier to navigate to different values settings for
each chart, since values can have their own H2 sections that are
distinct from chart names. (Previously, both chart names and values
settings were organized into H2 section headings.)
This will also mean that edition warnings for Cloud users can be more
visible, since we can place them at the top of a page for a given chart.
See #10636
See #10633
Terraform Provider guide
- Add tabbed prerequisites so users only see information relevant to
their scopes.
- Add the impersonation section as an H3 rather than an Admonition. If
users are learning how to use our Terraform provider, they likely
will not have enabled impersonation for the Terraform user, and would
always need to read the Admonition, so this would work better as an
H3.
- Add a scoped Notice indicating which address to use for the cluster
address in the sample Terraform config.
Fluentd plugin guide
- Add tabbed instructions for users of different scopes.
- Move the impersonation Admonition to an H3 so readers can configure
impersonation without running into an error.
- Misc clarity/style edits.
Certificate Authority Rotation
- Add tabbed prerequisites so users of one scope don't see information
intended for other scopes.
See #10636
Introduction
- Remove unnecessary mention of Access Requests in a paragraph that is
otherwise relevant for all editions.
- Minor style/grammar tweaks
Standalone Teleport
- Add tabbed instructions for different scopes where applicable.
- Minor style/grammar tweaks
Connect Kubernetes Cluster to Teleport
- Use Tabbed instructions and a Notice box so users with one scope
do not see instructions for other scopes.
- Remove irrelevant details that are specific to self-hosted deployments.
Federation
- Add a Tabs component to separate instructions for Cloud and Self-
Hosted users
- Minor style tweaks
Multiple Clusters
- Add tabbed instructions for Cloud/Self-Hosted users.
* Add notes about wildcard certificates
Guides to getting started with Teleport on various platforms
recommend creating a DNS record for *.teleport.com. It would help
prospective users to know why this is needed. This change adds
context for why Application Access requires a wildcard subdomain.
Fixes#5378
* Respond to PR feedback
- Move information into a partial
- Mention that you can create a DNS A record for each application-
specific subdomain
* Restore DNS-related cloud provider commands
* Fix broken link in the ADFS guide
This was hurting SEO. Since the link was not intended to be
used for navigation, I turned it into code-style text instead.
Also took this opportunity to do some light copy-editing of the
ADFS guide.
Fixes#8714
* Incorporate PR feedback
Also adds a few minor tweaks.
While addressing #10636, I noticed that the Details box that appears
for Cloud users when they visit some of our Helm guides is in a slightly
odd location, in the middle of a Prerequisites item. I have moved this to
the top of each guide instead.
I have also refactored the helm-install.mdx partial to split it into
multiple partials, which allows us to use the "Step n/d" format in our
Helm guides.
Also adds a Cloud warning to the Digital Ocean Helm guide.
* Situate the Installation guide more clearly
For a reader who begins their journey through the Teleport docs
with the Installation guide, it can be difficult to determine
what to do after following the guide. This change makes the
relationship between the Installation page and other docs pages
clearer by:
- Adding an Admonition to read the Getting Started guides if you
have not yet tried Teleport. These guides include installation
instructions, so they can be our recommended starting place.
- Adding a Next Steps section that links to instructions on
enabling Teleport for different infrastructure resources.
Closes#9355
* Respond to PR feedback
Since we no longer support version 5, including this guide only
risks misleading current/prospective users. This change removes
the v5 migration guide and redirects the path to the Kubernetes Access
Introduction page.
* Add Cloud-specific instructions to two guides
Ensure that users of a particular scope don't see irrelevant info
See #10633
GitHub SSO guide
- Edit the tctl partial to show only scope-relevant info.
- Use tabs in the Prerequisites
- Light edits for clarity
Adding Nodes
- Use Tabs for prerequisites
- Move sections specific to self-hosted deployments into Details
boxes that are hidden for Cloud users
- Use Tabs components to offer Cloud-specific alternatives to
examples of commands that presuppose a self-hosted deployment
- Misc clarity edits
* Respond to PR feedback
* Fix linter issues
* helm: Adds extraArgs and extraEnv to teleport-kube-agent
These were present in teleport-cluster but not teleport-kube-agent. This PR fixes that.
* Line breaks
* Also add to StatefulSet
- Rename the page, since it's about diagnostics rather than metrics
alone
- Change major section headings to H2s so they apper in the table of
contents
- Move information about heartbeats and recovery to an H3 so it's
more visible
Updates #10799
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Mention Cloud compatibility in three guides
Server Access getting started:
- Remove the instructions to install and set up the Auth
Service, and add references to main Getting Started guides
and Cloud signup page.
- Add a prerequisite to have deployed the Auth Service and
Proxy Service.
EC2 joining guide: make it explicit that the Cloud is not
compatible with this. Also make small style tweaks.
App Access getting started page:
- The guide assumes that you are running the Auth Service,
Proxy Service, and App Service via the same binary, which
does not work for Cloud users.
* Respond to PR feedback
- Add newlines after headings
- Use teleport app start instead of teleport start --roles=app
- Fix incorrect Ubuntu version number
- Add a Details box explaining tctl usage for Cloud
- Correctly capitalize "Node"
* Fix bot_name in Machine ID docs
Follow-up to #11039, this fixes the bot_name token field to use the
revised value (bot name rather than bot username, to match the field
name).
See also #10854
* Remove outdated comment warning
* Change token example to add node only
Given that it's not possible to join a proxy server via proxy address (`teleport.example.com:443`) and there relatively few circumstances where people would want to add both `node` and `proxy` services on one cluster, I think this example is likely to cause more confusion than anything else.
* Update adding-nodes.mdx
Remove static token example and tidy up
start-auth-proxy.mdx is a partial used by a number of Database Access
guides. After PR #9556, the partial included garbled instructions for
setting up Teleport with Let's Encrypt. This change edits these
instructions for clarity.