Commit Graph
106 Commits
Author SHA1 Message Date
Steven Martin f00a4e2b66 Makes a common login error troubleshooting for sso docs (#11277)
* Incorporates a common login error troubleshooting include. Changed to show
the audit log screen in the web console initially.
2022-03-27 02:38:27 +00:00
Carson AndersonandPaul Gottschling 4054c79c7e Add metric to track number ssh connect attempts (#11240)
* add ssh connect attempts metric

* fix help message wording

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-24 20:34:00 +00:00
Brian Joerger 11c66d23be [Docs] Add teleport.yaml docs for x11 forwarding (#10561) 2022-03-24 18:05:04 +00:00
Steven Martin 6c1aa75f3b Add in version string definition for role in Terraform reference (#10609)
* Add in version string definition for role
2022-03-24 01:48:11 +00:00
Paul GottschlingandNic Klaassen 77314ab4c2 Split the AWS Node Joining guide (#11081)
* Split the AWS Node Joining guide

This is to better address users with different scopes (see #10633).

Since the EC2 method is irrelevant for Cloud users, this approach makes
it straightforward to add an edition warning to the top of the EC2 join
method guide and scoped Tabs components to the IAM join method guide.

The alternative was to add nested Tabs components, with the top level
including Cloud vs. Self-Hosted TabItems and the inner level including
TabItems for the IAM and EC2 join methods. This looked pretty
unattractive and couldn't accommodate the final section on using the
EC2 method with multiple AWS accounts.

* Respond to PR feedback

Co-authored-by: Nic Klaassen <nic@goteleport.com>

* Respond to PR feedback

Co-authored-by: Nic Klaassen <nic@goteleport.com>
2022-03-23 21:09:26 +00:00
Paul Gottschling 9575f0e942 Prepare the metrics reference for Cloud users (#10880)
* Metrics guide

Add separate Tabs for self-hosted and Cloud editions

* Prepare the metrics reference for Cloud users

Arrange metrics into H2 sections, both making the page easier to
navigate and making it clear which metrics are relevant to Cloud
users.

Add a warning that in Cloud, the Auth and Proxy do not expose
metrics endpoints.

* Respond to PR feedback

- Move the certificate_mismatch_total to a more appropriate place
  with a more accurate description
- Correct gcs_ metric categories
- Make the rx and tx metric descriptions a bit more accurate
- Also perform light copy-editing on metric descriptions
2022-03-23 20:52:59 +00:00
Steven Martin 4f09a8ade3 Teleport cloud license info and other info (#11093)
Provide a note that Teleport Cloud does not require license file management.  Also provides fyi that when downloading you will see the licensed products.  Gives example warning message when attempting to use unlicensed products.
2022-03-23 13:43:21 +00:00
Steven Martin df69628802 Added all token types in tctl reference (#11254) 2022-03-23 13:13:52 +00:00
Paul Gottschling 973cb8aac0 Edit three guides for Cloud users (#11115)
See #10633

Terraform Provider guide

- Add tabbed prerequisites so users only see information relevant to
  their scopes.

- Add the impersonation section as an H3 rather than an Admonition. If
  users are learning how to use our Terraform provider, they likely
  will not have enabled impersonation for the Terraform user, and would
  always need to read the Admonition, so this would work better as an
  H3.

- Add a scoped Notice indicating which address to use for the cluster
  address in the sample Terraform config.

Fluentd plugin guide

- Add tabbed instructions for users of different scopes.

- Move the impersonation Admonition to an H3 so readers can configure
  impersonation without running into an error.

- Misc clarity/style edits.

Certificate Authority Rotation

- Add tabbed prerequisites so users of one scope don't see information
  intended for other scopes.
2022-03-21 22:34:34 +00:00
Lisa Kim f39e3bf180 Add doc for filter support for CLI tools (#11012)
For the flags --search, --query, and labels
2022-03-18 08:36:26 -07:00
Paul Gottschling 2cb0b66f7b Add Cloud-specific instructions to two guides (#10674)
* Add Cloud-specific instructions to two guides

Ensure that users of a particular scope don't see irrelevant info

See #10633

GitHub SSO guide
 - Edit the tctl partial to show only scope-relevant info.
 - Use tabs in the Prerequisites
 - Light edits for clarity

Adding Nodes
- Use Tabs for prerequisites
- Move sections specific to self-hosted deployments into Details
  boxes that are hidden for Cloud users
- Use Tabs components to offer Cloud-specific alternatives to
  examples of commands that presuppose a self-hosted deployment
- Misc clarity edits

* Respond to PR feedback

* Fix linter issues
2022-03-17 22:10:21 +00:00
Zac BergquistandPaul Gottschling 072956e4a0 docs: clarify /healthz and /readyz (#11085)
- Rename the page, since it's about diagnostics rather than metrics
  alone
- Change major section headings to H2s so they apper in the table of
  contents
- Move information about heartbeats and recovery to an H3 so it's
  more visible

Updates #10799

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-17 16:46:12 +00:00
Paul Gottschling 2c728d9d65 Mention Cloud compatibility in three guides (#10021)
* Mention Cloud compatibility in three guides

Server Access getting started:
- Remove the instructions to install and set up the Auth
  Service, and add references to main Getting Started guides
  and Cloud signup page.
- Add a prerequisite to have deployed the Auth Service and
  Proxy Service.

EC2 joining guide: make it explicit that the Cloud is not
compatible with this. Also make small style tweaks.

App Access getting started page:
- The guide assumes that you are running the Auth Service,
  Proxy Service, and App Service via the same binary, which
  does not work for Cloud users.

* Respond to PR feedback

- Add newlines after headings
- Use teleport app start instead of teleport start --roles=app
- Fix incorrect Ubuntu version number
- Add a Details box explaining tctl usage for Cloud
- Correctly capitalize "Node"
2022-03-17 21:15:45 +05:30
Zac Bergquist 74bc1fbed9 Remove mention of max ttl for tctl tokens command (#11148)
The 48h maximum is enforced for `tctl users add`,
not `tctl tokens add`.

Fixes #11137
2022-03-15 20:46:10 +00:00
Logan Davis 823fc293bf Add documentation for tsh proxy app (#10924) 2022-03-14 13:56:18 +00:00
Gus Luxton d617f2a177 Change token example to add node only (#11004)
* Change token example to add node only

Given that it's not possible to join a proxy server via proxy address (`teleport.example.com:443`) and there relatively few circumstances where people would want to add both `node` and `proxy` services on one cluster, I think this example is likely to cause more confusion than anything else.

* Update adding-nodes.mdx

Remove static token example and tidy up
2022-03-10 18:46:07 +00:00
Krzysztof Skrzętnicki 45529e9890 Update suggested systemctl command (#10733)
Contrary to current wording `systemctl restart teleport` is *NOT* graceful. The graceful equivalent is `systemctl reload teleport`.
2022-03-04 10:27:59 +01:00
Zac Bergquist fddedb00d2 docs: update CA rotation page (#10419) 2022-03-03 16:09:17 +00:00
Paul Gottschling 10e8346b10 Fix meta description clash (#10621)
* Fix meta description clash

Two docs pages had the same meta description, which hurts SEO.
This changes the meta description of one of the page and uses
this opportunity to do some light copy editing.

Fixes #8713

* Respond to PR feedback
2022-03-02 22:25:12 +00:00
Steven Martin add50d67fb Update logging severity values in config reference (#10562)
* Update logging severity values

* mention error is recommended for production
2022-02-28 16:14:54 +00:00
Nic Klaassen 6e3b328a7e [Docs update] Mention unsupported scenarios for IAM join method (#10530) 2022-02-25 23:07:17 +00:00
Albert Lloveras 29bb38b348 TF provider configuration environment variables (#10417)
* TF provider configuration environment variables

* PR feedback
2022-02-23 15:42:32 +00:00
Roman Tkachenko 8ea2c70996 Add SQL Server guide (#10293) 2022-02-18 22:37:29 +00:00
Carson Anderson e18c59975d Add teleport_audit_emit_event prometheus metric (#9134)
Adds a metric tracking the total number audit events emitted to track against failures. Fixes scenario where failure counter will be incremented twice.
2022-02-18 15:55:12 +00:00
Paul Gottschling 0553d3d021 Address Cloud users in guides (#9962)
- Edit the Google Workspace SSO guide to mention Teleport
  Cloud in the Prerequisites and add scoped Tabs components.
  Also add clarity edits.

- Edit the Azure AD SSO guide to mention Teleport Cloud and
  included scoped Tabs components.

- Add compabitility warning to the HSM guide, scaling guide,
  Docker guide, restricted session, and aws-terraform guide.

- Mention the cloud in session recording prerequisites.
2022-02-17 21:35:57 +00:00
Paul Gottschling df63e622ba Mention Teleport Cloud in some of our guides (#9989)
* Mention Teleport Cloud in some of our guides

- Mention Teleport Cloud in the  Desktop Access guide
  prerequisites
- Minor style tweak to the K8s Agent guide
- Add a Cloud compatibility note to the Kubernetes cluster
  guide
- Make Cloud compatibility more explicit in the multiple-clusters
  guide
- Clarify the EC2 tag guide's relationship to Cloud (also add some
  general clarity tweaks)

* Respond to PR feedback
2022-02-17 21:26:29 +00:00
Paul Gottschling b647592dec Add a prominent warning to the config reference (#9558)
Readers may be tempted to copy the entire reference configuration
for their own Teleport deployments. This changes the config
reference to include a more explicit and prominent warning against
doing so, and recommends using the "teleport configure" command.

Closes #3244
2022-02-17 21:01:18 +00:00
Nic Klaassen ab56808339 IAM Joining Docs: Set join_method in token.yaml (#10433) 2022-02-17 10:56:49 -08:00
Carson Anderson 266811f33e add teleport_connected_resources metric (#9603)
This adds the Prometheus metric teleport_connected_resources. Gauge increments when the keepalive is established and will decrement whenever the connection is broken/closed.
2022-02-16 20:19:28 +00:00
Nic Klaassen 26ae806a59 Add docs for IAM join method (#8899) 2022-02-11 17:11:05 +00:00
Carson Anderson edff37226c Add Prometheus metrics cache events and stale events (#9826)
This adds two Prometheus metrics teleport_cache_events and teleport_cache_stale_events with one label indicating the service.
2022-02-11 09:14:42 -07:00
Joel ddee244cde Add documentation for moderated sessions (#9425) 2022-02-11 14:12:00 +01:00
Rafał Cieślak de73212820 Trusted clusters doc: Use wildcard for spec.allow.cluster_labels.env
`staging` isn't mentioned anywhere else in the doc, the comment just
before it explains what a wildcard is and just before the whole snippet
we say:

> We want administrators from "root" (but not regular users!) to have
> restricted access to "leaf". We want to deny them access to machines
> with "environment=production" and any Government cluster labeled
> "customer=gov"

Again, nothing about staging, which leads me to believe it's just
a minor oversight.
2022-02-11 10:44:43 +01:00
Rafał Cieślak 92dbdab703 Authentication options doc: wrap on in quotes 2022-02-11 00:54:20 +01:00
Zac Bergquist ab24cbde54 Document desktop role options for Teleport 9 (#10227) 2022-02-10 15:33:27 +00:00
Trent Clarke 7bbbdbdd27 Fixes DocTest CI (#10117)
The linting applied to file via the tools in next appears to vary if the files are outside the /src directory: If the files are under /src, a rigorous lint is applied. If the files are outside of /src, a "less-rigorous" lint is applied, letting many legitimate issues slip through.

This patch alters the CI script to symlink the /workspace directory (the mount-point that GCB uses to inject code into the container running a build step) under the next image's /src/content directory, so that the correct, rigorous lint will be applied.

It also fixes the lint errors that have crept in during the time the linter was being incorrectly lenient.

See-Also: #9600
See-Also: #10107
2022-02-04 10:16:27 -05:00
Alan Parra b1bed7f38f Remove broken links to /admin-guide/#public-addr (#10057)
Remove a silent broken link to /docs/admin-guide/#public-addr.

The link above redirects to the "Cluster Administration Guides" page, which
doesn't seem to contain any content relevant for public_addr.
2022-02-03 17:09:00 +00:00
Andrew Burke c45263195f Update S3 canned ACL docs (#10072) 2022-02-02 21:58:42 +00:00
Carson AndersonandPaul Gottschling b384de6007 Add teleport_reverse_tunnels_connected Prometheus metric (#9698)
Adds teleport_reverse_tunnels_connected Prometheus metric which tracks reverse tunnels connected to the proxy server by type.

* Update prometheus help

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>

* Update metrics wording

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-02-02 20:52:19 +00:00
a8a57b19f8 Add metric tracking number of Teleport agents joined to cluster (#9749)
Adds the Prometheus metric teleport_registered_servers which is a gauge indicating the unique number of Teleport instances connected to the cluster by version. 

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-02-02 18:47:21 +00:00
STeve Huang adf7200787 Documentation update for Redshift auto discovery support (#9990) 2022-02-01 14:42:47 +00:00
Steven Martin 905ed92948 add desktop and tip on assigned ports for networking ref (#9957)
* add desktop and tip on assigned ports.
2022-01-26 21:17:23 +00:00
Steven Martin e37e52ec81 Add diag addr, web idle timeout, token clarification (#8489) 2022-01-25 17:32:34 +00:00
Gus Luxton 7ca5f97822 [docs] Add region and use of SSM decryption to Terraform docs (#8907) 2022-01-14 17:48:00 -08:00
Zac Bergquist 304571955f docs: recommend a highly available LDAP endpoint. (#9744)
* Recommend a highly available LDAP endpoint.

Early versions of our docs were worded in such a way that suggested
pointing Teleport at a single domain controller, which would result
in issues if a DC goes down for maintenance or due to error.

We also used to make insecure LDAP connections on port 389, and then
upgrade them using a STARTTLS operation. This is no longer supported.

Fix both of these issues by recommending a highly available LDAP
server and removing references to port 389.

* Add note about direct vs IoT mode

* Move the desktop config reference to a shared includes file

This will prevent the desktop access config examples from diverging
in different parts of the docs.

Additionally, simplify the example in the getting started guide,
as the goal of that guide is to get up and running quickly, not
to provide an exhaustive reference of all the configuration options.
2022-01-14 01:10:38 +00:00
Roman Tkachenko b05664017c Add note about TLS routing backwards compatibility (#9630) 2022-01-06 16:50:42 +00:00
Carson Anderson 6e3c703ddb Add teleport_build_info Prometheus metric to Teleport (#9595)
Adds teleport_build_info metric to Teleport providing the gitref, version, and Go version.
2022-01-05 21:17:54 +00:00
Jakub Nyckowski f5d5323f1f Specify level of TLS verification for database connections (#9197)
Now 'verify-full', 'verify-ca' and 'insecure' modes can be used when connecting to a database. 'verify-full` is the default on and it's the most strict. 'verify-ca' skips the server-name check. 'insecure' accepts any certificate provided by a database.
2022-01-05 16:41:49 +00:00
Isaiah Becker-Mayer de893cf65c Adds the windows_desktop_service section to the meta teleport.yaml (#9573) 2021-12-29 19:31:27 +00:00
Isaiah Becker-Mayer fb23a39fcc removes experimental note from example config (#9195) 2021-12-21 16:22:50 +00:00