* Split the AWS Node Joining guide
This is to better address users with different scopes (see #10633).
Since the EC2 method is irrelevant for Cloud users, this approach makes
it straightforward to add an edition warning to the top of the EC2 join
method guide and scoped Tabs components to the IAM join method guide.
The alternative was to add nested Tabs components, with the top level
including Cloud vs. Self-Hosted TabItems and the inner level including
TabItems for the IAM and EC2 join methods. This looked pretty
unattractive and couldn't accommodate the final section on using the
EC2 method with multiple AWS accounts.
* Respond to PR feedback
Co-authored-by: Nic Klaassen <nic@goteleport.com>
* Respond to PR feedback
Co-authored-by: Nic Klaassen <nic@goteleport.com>
* Metrics guide
Add separate Tabs for self-hosted and Cloud editions
* Prepare the metrics reference for Cloud users
Arrange metrics into H2 sections, both making the page easier to
navigate and making it clear which metrics are relevant to Cloud
users.
Add a warning that in Cloud, the Auth and Proxy do not expose
metrics endpoints.
* Respond to PR feedback
- Move the certificate_mismatch_total to a more appropriate place
with a more accurate description
- Correct gcs_ metric categories
- Make the rx and tx metric descriptions a bit more accurate
- Also perform light copy-editing on metric descriptions
Provide a note that Teleport Cloud does not require license file management. Also provides fyi that when downloading you will see the licensed products. Gives example warning message when attempting to use unlicensed products.
See #10633
Terraform Provider guide
- Add tabbed prerequisites so users only see information relevant to
their scopes.
- Add the impersonation section as an H3 rather than an Admonition. If
users are learning how to use our Terraform provider, they likely
will not have enabled impersonation for the Terraform user, and would
always need to read the Admonition, so this would work better as an
H3.
- Add a scoped Notice indicating which address to use for the cluster
address in the sample Terraform config.
Fluentd plugin guide
- Add tabbed instructions for users of different scopes.
- Move the impersonation Admonition to an H3 so readers can configure
impersonation without running into an error.
- Misc clarity/style edits.
Certificate Authority Rotation
- Add tabbed prerequisites so users of one scope don't see information
intended for other scopes.
* Add Cloud-specific instructions to two guides
Ensure that users of a particular scope don't see irrelevant info
See #10633
GitHub SSO guide
- Edit the tctl partial to show only scope-relevant info.
- Use tabs in the Prerequisites
- Light edits for clarity
Adding Nodes
- Use Tabs for prerequisites
- Move sections specific to self-hosted deployments into Details
boxes that are hidden for Cloud users
- Use Tabs components to offer Cloud-specific alternatives to
examples of commands that presuppose a self-hosted deployment
- Misc clarity edits
* Respond to PR feedback
* Fix linter issues
- Rename the page, since it's about diagnostics rather than metrics
alone
- Change major section headings to H2s so they apper in the table of
contents
- Move information about heartbeats and recovery to an H3 so it's
more visible
Updates #10799
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Mention Cloud compatibility in three guides
Server Access getting started:
- Remove the instructions to install and set up the Auth
Service, and add references to main Getting Started guides
and Cloud signup page.
- Add a prerequisite to have deployed the Auth Service and
Proxy Service.
EC2 joining guide: make it explicit that the Cloud is not
compatible with this. Also make small style tweaks.
App Access getting started page:
- The guide assumes that you are running the Auth Service,
Proxy Service, and App Service via the same binary, which
does not work for Cloud users.
* Respond to PR feedback
- Add newlines after headings
- Use teleport app start instead of teleport start --roles=app
- Fix incorrect Ubuntu version number
- Add a Details box explaining tctl usage for Cloud
- Correctly capitalize "Node"
* Change token example to add node only
Given that it's not possible to join a proxy server via proxy address (`teleport.example.com:443`) and there relatively few circumstances where people would want to add both `node` and `proxy` services on one cluster, I think this example is likely to cause more confusion than anything else.
* Update adding-nodes.mdx
Remove static token example and tidy up
* Fix meta description clash
Two docs pages had the same meta description, which hurts SEO.
This changes the meta description of one of the page and uses
this opportunity to do some light copy editing.
Fixes#8713
* Respond to PR feedback
Adds a metric tracking the total number audit events emitted to track against failures. Fixes scenario where failure counter will be incremented twice.
- Edit the Google Workspace SSO guide to mention Teleport
Cloud in the Prerequisites and add scoped Tabs components.
Also add clarity edits.
- Edit the Azure AD SSO guide to mention Teleport Cloud and
included scoped Tabs components.
- Add compabitility warning to the HSM guide, scaling guide,
Docker guide, restricted session, and aws-terraform guide.
- Mention the cloud in session recording prerequisites.
* Mention Teleport Cloud in some of our guides
- Mention Teleport Cloud in the Desktop Access guide
prerequisites
- Minor style tweak to the K8s Agent guide
- Add a Cloud compatibility note to the Kubernetes cluster
guide
- Make Cloud compatibility more explicit in the multiple-clusters
guide
- Clarify the EC2 tag guide's relationship to Cloud (also add some
general clarity tweaks)
* Respond to PR feedback
Readers may be tempted to copy the entire reference configuration
for their own Teleport deployments. This changes the config
reference to include a more explicit and prominent warning against
doing so, and recommends using the "teleport configure" command.
Closes#3244
This adds the Prometheus metric teleport_connected_resources. Gauge increments when the keepalive is established and will decrement whenever the connection is broken/closed.
`staging` isn't mentioned anywhere else in the doc, the comment just
before it explains what a wildcard is and just before the whole snippet
we say:
> We want administrators from "root" (but not regular users!) to have
> restricted access to "leaf". We want to deny them access to machines
> with "environment=production" and any Government cluster labeled
> "customer=gov"
Again, nothing about staging, which leads me to believe it's just
a minor oversight.
The linting applied to file via the tools in next appears to vary if the files are outside the /src directory: If the files are under /src, a rigorous lint is applied. If the files are outside of /src, a "less-rigorous" lint is applied, letting many legitimate issues slip through.
This patch alters the CI script to symlink the /workspace directory (the mount-point that GCB uses to inject code into the container running a build step) under the next image's /src/content directory, so that the correct, rigorous lint will be applied.
It also fixes the lint errors that have crept in during the time the linter was being incorrectly lenient.
See-Also: #9600
See-Also: #10107
Remove a silent broken link to /docs/admin-guide/#public-addr.
The link above redirects to the "Cluster Administration Guides" page, which
doesn't seem to contain any content relevant for public_addr.
Adds teleport_reverse_tunnels_connected Prometheus metric which tracks reverse tunnels connected to the proxy server by type.
* Update prometheus help
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Update metrics wording
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
Adds the Prometheus metric teleport_registered_servers which is a gauge indicating the unique number of Teleport instances connected to the cluster by version.
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Recommend a highly available LDAP endpoint.
Early versions of our docs were worded in such a way that suggested
pointing Teleport at a single domain controller, which would result
in issues if a DC goes down for maintenance or due to error.
We also used to make insecure LDAP connections on port 389, and then
upgrade them using a STARTTLS operation. This is no longer supported.
Fix both of these issues by recommending a highly available LDAP
server and removing references to port 389.
* Add note about direct vs IoT mode
* Move the desktop config reference to a shared includes file
This will prevent the desktop access config examples from diverging
in different parts of the docs.
Additionally, simplify the example in the getting started guide,
as the goal of that guide is to get up and running quickly, not
to provide an exhaustive reference of all the configuration options.
Now 'verify-full', 'verify-ca' and 'insecure' modes can be used when connecting to a database. 'verify-full` is the default on and it's the most strict. 'verify-ca' skips the server-name check. 'insecure' accepts any certificate provided by a database.