Commit Graph
1142 Commits
Author SHA1 Message Date
Zac Bergquist bd7e7a84f0 Remove events.Forwarder and RecordSessions config param
The Forwarder type has been replaced with the new GRPC/streaming based
session recording and was only used in tests.

The RecordSessions param is never consulted, as it was replaced with
AuditWriter's RecordOutput param a couple of years ago.
2022-03-25 15:21:22 -06:00
Andrew Burke 4543bfd98d Respect HTTP_PROXY/HTTPS_PROXY (#10209)
This change allows tsh to use HTTP proxies when HTTP_PROXY/HTTPS_PROXY is set in the environment.
2022-03-23 19:58:19 +00:00
Zac Bergquist 6277ef8620 Remove LDAP password_file from configuration (#11331)
When we deprecated the password_file option for Teleport 9, we left
the configuration property in the config so that we could give v8
users who had recently upgraded a nice error message letting them
know that we deprecated this field.

For Teleport 10, everyone coming from v9 will have already removed
this property, so the deprecation warning is no longer necessary.
2022-03-23 19:34:30 +00:00
Alan Parra b2c5c8ecb0 Add FIDO2 passwordless login and registration to tsh (#11321)
Passwordless login is enabled by the global `--pwdless` flag. Registration gets
a new prompt and an `--allow-passwordless` flag.

UX messages were tweaked to follow the descriptions on RFD 53: Passwordless
FIDO2[1].

Passwordless login requires two touches for all devices (both PIN and biometric).
I'd like to get it down to a single touch, at least for the most common
situations, but that'll be a follow up to this work.

Passwordless support requires `tsh` to be compiled with the `libfido2` tag, try
`go build -tags=libfido2 ./tool/tsh`.

#9160

[1] https://github.com/gravitational/teleport/blob/master/rfd/0053-passwordless-fido2.md#ux

* Allow reuse of devices for passwordless
* Implement passwordless registration in tsh
* Add better tracing to FIDO2 filters
* Implement passwordless logins in tsh
* Make --pwdless a global flag
* Fix lint errors
* Fix U2F tests
* Use initClient's URL as origin
* Distinguish whether --allow-passwordless is set or unset
2022-03-23 18:38:10 +00:00
Zac Bergquist 8521b388f2 Remove legacy JSON API for host certs (#11330)
This is a follow up to e256170d60.
Now that Teleport 9 is out, we can remove the last traces of
this API for Teleport 10.
2022-03-23 17:57:22 +01:00
Alan Parra 023f533be2 Wire FIDO2 into tsh login and registration (#11241)
Seamlessly change the public API of lib/auth/webauthncli to use the
libfido2-backed implementation, as long as the binary was compiled with the
libfido2 build tag.

A few adjustments are necessary to "wancli" methods to allow users to provide
prompt callbacks and to return the credential user (not applicable here, but
will be in following PRs).

Additional changes are made to tsh mfa add in order to avoid stdin hijacking by
ContextReader, since we now may require PIN reads for authenticators.

#9160

* Move U2F logic to u2f_* files
* Split U2F API from general l/a/webauthncli API
* Move FIDO2 public API to fido2_common.go, introduce IsFIDO2Available
* Introduce prompt.SyncReader

Sync reads allow prompt calls to be mixed with term.ReadPassword calls.

* Wire FIDO2 into MFA login
* Wire FIDO2 into MFA registration
2022-03-21 14:35:08 +00:00
Alan Parra 84127a557d Implement FIDO2 login and registration (#11166)
Implements CLI login and registration using go-libfido2. Covers both MFA and
passwordless use cases.

The FIDO2 implementation is akin to the existing U2F Login / Registration logic,
including a similar "device detection" loop. A few notable differences are:

A filtered "device search" step that ends as soon a suitable device is found A
more explicit "device selection" step, which makes it easier to implement PIN
flows The MFA UX for end-users should remain mostly unaltered.

There are no separate methods for MFA and passwordless, as much of the logic
would be the same. Instead, the methods react to the assertion/credential
parameters accordingly.

At this moment this code is isolated from other callers, as well as from our
build processes via the libfido2 tag. This is to avoid impact to other
developers, as go-libfido2 has a few requirements before it can be downloaded or
executed.

#9160

* Import github.com/keys-pub/go-libfido2
* Implement FIDO2 login
* Add login tests
* Implement FIDO2 registration
* Add registration tests
2022-03-18 15:14:24 +00:00
Edoardo Spadolini 257d005ca3 Revert "Only allow access request deletion through static roles' permissions (#9540)" (#11220)
This reverts commit 8db6aa5883.
2022-03-17 16:18:16 +00:00
Edoardo Spadolini 160df0086a Support role bootstrapping in OSS (#11175)
* Add role bootstrapping

* Test coverage

* Better variable names

* Remove spurious log, add better error messages
2022-03-17 10:12:18 +00:00
Zac Bergquist 3f507dfd06 Remove uses of deprecated ioutil package 2022-03-16 15:05:42 -06:00
Edoardo Spadolini d83886e9c3 Address problems in concurrent sqlite access (#10706)
* Use BEGIN IMMEDIATE to start transactions

This makes it so all transactions grab a write lock
rather than a read lock that can be upgraded in case of
a write; in case of multiple writers (which, in our
case, can only happen during a restart as the new
process reopens the same sqlite database) this will
prevent two transactions from attempting to upgrade
their lock, which would cause a SQLITE_BUSY error in
one of them. In regular operation this shouldn't cause
a performance hit, as we're using a single connection
to the sqlite database (guarded by locks in the go side)
anyway.

* Escape path in sqlite connection URL

This makes it so that the sqlite backend supports paths with ? in them.

* Close process storage on TeleportProcess shutdown

This aligns the behavior of Shutdown with that of Close.

* Allow specifying the journal mode in sqlite

This will let sqlite backend users specify WAL mode in their config
file, and will allow us to specify alternate journal modes for our
on-disk caches in the future.

This also removes sqlite memory mode, as it's not used anywhere because
of its poor query performance compared to our in-memory backend, and
cleans up a bit of old cruft, and runs process storage in FULL sync
mode - it's very seldom written to and holds important data.
2022-03-15 16:54:48 +00:00
Alex McGrath 26f7f179cb Fix certificate extension not being included in tctl auth sign 2022-03-15 14:10:29 +00:00
Lisa Kim 628564c801 Update 'tctl apps/db/nodes ls' to accept filter flags (#11003) 2022-03-11 17:57:40 +00:00
Joel 92543d9b3e Moderated Sessions improvements (#10991) 2022-03-10 23:04:12 +00:00
Tim Buckley 34fbced61d Fix meaning of bot_name in bot join tokens (#11039)
The `BotName` / `bot_name` was previously used to refer to the bot
_username_ rather than the bot name as entered by users. This leads
to confusion as the username is an implemention detail not obviously
visible to users.

This changes the meaning of the `bot_name` parameter to instead
consistently accept a bot name, which is converted to a username on
the backend where needed.
2022-03-10 22:08:07 +00:00
rosstimothy 550d23d15d Fix goroutine and memory leak in watchCertAuthorities (#10871)
* Fix goroutine and memory leak in watchCertAuthorities

The CA Watcher was blocking both on writing to a channel when the watcher
was closed and on HTTP calls that had no request timeout or context passed
to cause cancellation.

All resourceWatcher implementations that had a bug which may cause them to block
on writing to a channel forever were fixed by selecting on the write and ctx.Done.

Adding context.Context to all Get/Put/Post/Delete methods on the auth HTTPClient to
force callers to propagate context. Prior all calls used context.TODO which
prevents requests from being properly cancelled.

Add context propagation to RotateCertAuthority, RotateExternalCertAuthority,
GetCertAuthority, GetCertAuthorities. This is needed to get the correct ctx
from the CertAtuhorityWatcher all the way down to the HTTPClient that makes
the call.

Closes #10648
2022-03-10 11:05:39 -05:00
Marek Smoliński 923e131d91 Regenerate server identity if APIDomain not present (#10904) 2022-03-10 09:49:36 +00:00
Lisa Kim 350ea5bb95 Updates tsh ls for node/app/db/kube to accept new filter flags (#10980)
* Also adds a search keyword parser that takes in different
  delimiters (comma is used for tsh, space is used for web UI)

part of RFD 55
2022-03-09 23:56:55 +00:00
Brian Joerger 600022b290 Change NewRole to use V5 by default, old consumers now user NewRoleV3. (#10884) 2022-03-08 21:11:53 +00:00
Lisa Kim b868ccce5f Add sorting for kube cluster (#10702)
Part of RFD 55
2022-03-07 09:54:58 -08:00
Lisa Kim 632d851783 Add KindWindowsDesktops to ListResources (#10769)
* Also add windows desktops sorter and its type converters
* Use forked vulcand/predicate library: allows traversing
  by embedded fields

Part of RFD 55
2022-03-07 08:58:26 -08:00
Alan Parra 5023235909 Add passwordless login/registration to auth and web (#10632)
Wire passwordless registration and authorization into Auth and Proxy APIs, thus
making passwordless logins possible.

API changes are described by RFD 52: Passwordless [1].

#9160

[1] https://github.com/gravitational/teleport/blob/master/rfd/0052-passwordless.md#authentication-api-changes

* Add passwordless settings to Auth protos
* Update generated protos
* Register: Apply DeviceUsage in lib/auth
* Register: Apply DeviceUsage in lib/web
* Login: Generate passwordless challenge
* Login: Allow passwordless authentication
* Wire passwordless in lib/web endpoints
* Make mocku2f passwordless setup a bit nicer
2022-03-04 18:41:35 +00:00
Brian Joerger 8d71ba0fc9 Fix missing identity in certs logic (#10673) 2022-03-03 14:22:23 -08:00
Alan Parra f4b0b5b3ac Add rate limiting to passwordless endpoints (#10737)
Passwordless endpoints are rate limited because they allow unauthenticated
challenge generation. The endpoint rate limits are applied in addition to
(pre-existing) storage limits.

Setting limits to Auth only would be sufficient, but it seems best to apply
limits to Proxy as well, so we may spare Auth of unnecessary load.

Auth already has a framework for RPC rate limiting, so we took advantage of it.
The solution for the Proxy is rather simple - the handler is decorated with the
appropriate limits.

#9160

* Fix shadowing of grpcServer variable
* Add rate limiting for CreateAuthenticateChallenge
* Add rate limiting for /mfa/login/begin
* Safe parallel tests
2022-03-03 13:44:06 +00:00
Edoardo Spadolini 8983ededb4 Leaf cluster CA sanitizing (#10741)
* Enforce that a leaf cluster has sent us just a single host CA

* Test coverage for validateTrustedCluster

* Add `tctl rm cert_authority/kind/name`

* Check against existing trusted clusters
2022-03-03 11:46:19 +00:00
Nic Klaassen 6e16ad6627 IAM join method support for tbot (#10535) 2022-03-01 00:35:34 +00:00
Lisa Kim e7eb6c4af8 Return filtered total count with ListResources (#10573)
* The web UI needed to show the total count of resources available after filter
* ListResources response returns as a struct to make adding extra fields easier
2022-02-28 21:51:19 +00:00
Zac Bergquist 06d488ff31 Fix desktop session playback RBAC (#10570)
The RBAC for sessions code was using SSH-specific queries to check
for session end events. Migrate to the newer search, which is both
more efficient and supports desktop events as well.

Fixes #10507
2022-02-28 14:05:31 -07:00
Alan Parra bac0ccdc99 Remove U2F support (#10476)
Follows up on #10466 by removing remaining U2F references, including proto/gRPC
surface and the lib/auth/u2f package itself.

#10375

* Remove U2F from lib/auth/ (1)
* Remove U2F from lib/auth/ (2)
* Remove U2F from lib/auth/ (3)
* Remove U2F from lib/services/
* Remove U2F from tsh mfa add suggestions
* Remove U2F protos
* Update generated protos
* Cleanup a few stragglers
* Remove lib/auth/u2f package
* Fix references to auth.MFAAuthenticateChallenge
* Revert needless lib/auth/password.go change
* Update e/ to ad8fd4a (U2F cleanup)
* Fix stragglers from latest master rebase
* Fix lint and compile failures
2022-02-24 19:54:28 +00:00
Alan Parra f8b7b330ad Alias "u2f" to "webauthn" and partially cleanup (#10466)
Alias the "u2f" second factor mode to "webauthn", effectively sunsetting U2F in
favor of WebAuthn.

The change effectively disables "U2F mode" server-side, making Teleport use
WebAuthn instead. This is in line with our compatibility promise, as Teleport
8.x clients are already WebAuthn-capable (and thus have no problems talking to
the cluster).

I have cleaned up a good chunk of U2F references in lib/web and lib/client, plus
a few other places. Changes on lib/auth are just the necessary to get the tests
back to good standing. There is more work to be done, but this seems enough for
a single PR.

#10375

* Remove "Disabled" field from types.Webauthn
* Update generated protos
* Treat second_factor "u2f" as "webauthn"
* Remove references to Webauthn.Disabled
* Remove U2F from lib/web/
* Remove U2F from lib/client/
* Remove U2F from lib/auth/ (partially)
* Fix issues after rebase on master
* Fix typo
2022-02-23 14:10:13 +00:00
Alan Parra e46840a883 Add passwordless login/registration support to lib/auth/webauthn (#10372)
I've opted to keep MFA and passwordless authorization interfaces separate, as
they have slight interface differences, storage needs, and allow for different
use-cases.

LoginFlow, the existing API, is now focused on MFA. A new type,
PasswordlessFlow, provides support for passwordless authorization. Both
implementations are backed by a private loginFlow type, refactored from the guts
of the old LoginFlow, which is a superset of MFA and Passwordless.

All registration use-cases are provided by the existing RegistrationFlow. In
this case the change is simpler, as a single passwordless parameter suffices.
Registration is always performed by a previously-authorized user, so it's
storage interactions remain uniform.

Finally, login methods won't create a WebAuthn ID anymore, instead they rely on
registration to do it. The simplification relies on the fact that user handles
are not mandatory. (They do matter for resident key registration, which does
provide them.)

#9160

* Add verification support to mocku2f
* Support passwordless login on lib/auth/webauthn
* Support passwordless registration on lib/auth/webauthn
* Refactor web ID creation
2022-02-22 19:01:46 +00:00
bb121d7b1e Certificate renewal bot (#10099)
* Add certificate renewal bot

This adds a new `tbot` tool to continuously renew a set of
certificates after registering with a Teleport cluster using a
similar process to standard node joining.

This makes some modifications to user certificate generation to allow
for certificates that can be renewed beyond their original TTL, and
exposes new gRPC endpoints:
 * `CreateBotJoinToken` creates a join token for a bot user
 * `GenerateInitialRenewableUserCerts` exchanges a token for a set of
   certificates with a new `renewable` flag set

A new `tctl` command, `tctl bots add`, creates a bot user and calls
`CreateBotJoinToken` to issue a token. A bot instance can then be
started using a provided command.

* Cert bot refactoring pass

* Use role requests to split renewable certs from end-user certs
* Add bot configuration file
* Use `teleport.dev/bot` label
* Remove `impersonator` flag on initial bot certs
* Remove unnecessary `renew` package
* Misc other cleanup

* Do not pass through `renewable` flag when role requests are set

This adds additional restrictions on when a certificate's `renewable`
flag is carried over to a new certificate. In particular, it now also
denies the flag when either role requests are present, or the
`disallowReissue` flag has been previously set.

In practice `disallow-reissue` would have prevented any undesired
behavior but this improves consistency and resolves a TODO.

* Various tbot UX improvements; render SSH config

* Fully flesh out config template rendering
* Fix rendering for SSH configuration templates
* Added `String()` impls for destination types
* Improve certificate renewal logging; show more detail
* Properly fall back to default (all) roles
* Add mode hints for files
* Add/update copyright headers

* Add stubs for tbot init and watch commands

* Add gRPC endpoints for managing bots

* Add `CreateBot`, `DeleteBot`, and `GetBotUsers` gRPC endpoints
* Replace `tctl bot (add|rm|ls)` implementations with gRPC calls
* Define a few new constants, `DefaultBotJoinTTL`, `BotLabel`,
  `BotGenerationLabel`

* Fix outdated destination flag in example tbot command

* Bugfix pass for demo

* Fixed a few nil pointer derefs when using config from CLI args
* Properly create destination if `--destination-dir` flag is used
* Remove improper default on CLI flag
* `DestinationConfig` is now a list of pointers

* Address first wave of review feedback

Fixes the majority of smaller issues caught by reviewers, thanks all!

* Add doc comments for bot.go functions

* Return the token TTL from CreateBot

* Split initial user cert issuance from `generateUserCerts()`

Issuing initial renewable certificate ended up requiring a lot of
hacks to skip checks that prevented anonymous bots from getting
certs even though we'd verified their identity elsewhere (via token).

This reverts all those hacks and splits initial bot cert logic into a
dedicated `generateInitialRenewableUserCerts()` function which should
make the whole process much easier to follow.

* Set bot traits to silence log messages

* tbot log message consistency pass

* Resolve lints

* Add config tests

* Remove CreateBotJoinToken endpoint

Users should instead use the CreateBot/DeleteBot endpoints.

* Create a fresh private key for every impersonated identity renewal

* Hide `config` subcommand

* Rename bot label prefix to `teleport.internal/`

* Use types.NewRole() to create bot roles

* Clean up error handling in custom YAML unmarshallers

Also, add notes about the supported YAML shapes.

* Fetch proxy host via gRPC Ping() instead of GetProxies()

* Update lib/auth/bot.go

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Fix some review comments

* Add renewable certificate generation checks (#10098)

* Add renewable certificate generation checks

This adds a new validation check for renewable certificates that
maintains a renewal counter as both a certificate extension and a
user label. This counter is used to ensure only a single certificate
lineage can exist: for example, if a renewable certificate is stolen,
only one copy of the certificate can be renewed as the generation
counter will not match

When renewing a certificate, first the generation counter presented
by the user (via their TLS identity) is compared to a value stored
with the associated user (in a new `teleport.dev/bot-generation`
label field). If they aren't equal, the renewal attempt fails.
Otherwise, the generation counter is incremented by 1, stored to the
database using a `CompareAndSwap()` to ensure atomicity, and set on
the generated certificate for use in future renewals.

* Add unit tests for the generation counter

This adds new unit tests to exercise the generation counter checks.

Additionally, it fixes two other renewable cert tests that were
failing.

* Remove certRequestGeneration() function

* Emit audit event when cert generations don't match

* Fully implement `tctl bots lock`

* Show bot name in `tctl bots ls`

* Lock bots when a cert generation mismatch is found

* Make CompareFailed respones from validateGenerationLabel() more actionable

* Update lib/services/local/users.go

Co-authored-by: Nic Klaassen <nic@goteleport.com>

* Backend changes for tbot IoT and AWS joining (#10360)

* backend changes

* add token permission check

* pass ctx from caller

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* fix comment typo

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* use UserMetadata instead of Identity in RenewableCertificateGenerationMismatch event

* Client changes for tbot IoT joining (#10397)

* client changes

* delete replaced APIs

* delete unused tbot/auth.go

* add license header

* don't unecessarily fetch host CA

* log fixes

* s/tunnelling/tunneling/

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* auth server addresses may be proxies

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* comment typo fix

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* move *Server methods out of auth_with_roles.go (#10416)

Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Address another batch of review feedback

* Addres another batch of review feedback

Add `Role.SetMetadata()`, simplify more `trace.WrapWithMessage()`
calls, clear some TODOs and lints, and address other misc feedback
items.

* Fix lint

* Add missing doc comments to SaveIdentity / LoadIdentity

* Remove pam tag from tbot build

* Update note about bot lock deletion

* Another pass of review feedback

Ensure all requestable roles exist when creating a bot, adjust the
default renewable cert TTL down to 1 hour, and check types during
`CompareAndSwapUser()`

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
2022-02-19 02:41:45 +00:00
Edoardo Spadolini 6033148096 CertAuthority watcher filtering (#10020) 2022-02-19 00:48:16 +00:00
Marek Smoliński 28907e17a0 Add MFA for Windows Desktop web access (#10271) 2022-02-18 22:01:46 +00:00
Lisa Kim e82450b8ed Add missing action VerbRead to ListResources (#10422) 2022-02-18 20:51:37 +00:00
Alex McGrathandZac Bergquist 611c05106f Add support for windows desktop services proxying different desktops (#10101)
* Add support for windows desktop services proxying different desktops

* Add filter to GetWindowsDesktops, remove GetWindowsDesktop and GetWindowsDesktopByName

* Cache cleanup

* Fix cache deletes for Windows desktops

For deletes, the cache only gets the backend key, not the entire
resource. Do what database access does, which is to extract the
host ID from the path, and stuff it in the description field of
the resource header.

* Godoc cleanup

* Fix lint

* Address review comments

* Send error message if no desktop found

* Revert to x/net/websocket

This got converted to gorilla/websocket as part of moderated sessions.
We'll do a more intentional conversion post-release.

* fix lint

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2022-02-18 00:01:08 +00:00
Andrew Burke 4e3bd6c647 Clear terminal when auth server is in FIPS mode (#10095)
This change clears the terminal at the end of a session when the auth server is in FIPS mode, even if tsh isn't.
2022-02-17 10:16:36 -08:00
Joel a4cdce7240 Update version thresholds (#10426) 2022-02-17 18:50:46 +01:00
Alex McGrath 0abe3be6ee Add support for configurable ssh key extensions 2022-02-17 13:44:57 +00:00
Lisa Kim 74a21212c3 Implement resource sorter for server, appserver, dbserver (#10243)
* Define sorters for resource Server, AppServer, and DbServer
* Add sorting to ListResources in caching and presence layer
* ListResources now returns nextKey set to the limit+1th item,
  previously it returned a possible next key, where there
  may or may not be more results.
2022-02-17 00:42:03 +00:00
Carson Anderson 266811f33e add teleport_connected_resources metric (#9603)
This adds the Prometheus metric teleport_connected_resources. Gauge increments when the keepalive is established and will decrement whenever the connection is broken/closed.
2022-02-16 20:19:28 +00:00
Zac Bergquist e256170d60 Remove the legacy JSON API for requesting host certs
In Teleport 8 we migrated all uses of this API to GRPC, but left
the JSON API in place so that Teleport 7 nodes could still join
the cluster.

In Teleport 9, the oldest nodes we support are v8, which use the
GRPC API, so we can safely remove the old API.
2022-02-15 18:40:48 -07:00
Jim Bishopp 22e043c430 Add TestModules (#10369)
Allows tests to set fake values to be returned from modules.GetModules()
2022-02-15 21:54:40 +00:00
Joel ea810d30d9 Implement Moderated Sessions (#8563)
* Implement Moderated Sessions
2022-02-15 17:02:10 +01:00
Jim Bishopp 7767b8be2f Fix TestProcessKubeCSR (#10355)
Explicity set Kubernetes feature for the test.

The test requires the Kubernetes feature to be enabled while not
explicitly enabling it on its own. Sometimes it is enabled and other
times it is not, resulting in an error.
2022-02-14 16:55:11 -08:00
Zac Bergquist 9016d0cb18 Fix fake streamer implementation to match the real one (#10330) 2022-02-14 07:20:25 -07:00
c84b7f8142 Desktop session recording/playback (#9583)
* Record desktop sessions

Here we introduce a new protobuf type (DesktopRecording) that contains
an encoded TDP message, and update AuditWriter to treat these similarly
to SessionPrint events (which are used for SSH session recordings).

We also add desktop session playback endpoint, temporarily located at
/webapi/sites/:site/desktopplaybacktest/:session
which streams TDP messages from a recorded session over
a websocket interface.

* update session end (#9795)

* Updates SessionEnd event with fields needed for frontend

* removes the clock which didn't need to be passed

* Add `Recorded` field to `WindowsDesktopSessionEnd` (#9839)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* session recording websocket (#9908)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* Updates the websocket address

* updates desktopPlaybackHandle to restart playback once it reaches the end

* adds playback state and synchronization logic for ensuring that goroutines aren't leaked

* adds toggle functionality for play/pause

* fix for the fact that urls are case insensitive

* moves desktop_playback to its own file, fixes mistaken comment about how websocket.JSON.Receive works, fixes error messaging, wraps playbackState.Close in a sync.Once

* Adds a cond variable for the two goroutines, but doesn't solve the spinning loop problem for the hanging logic

* Adds a cancel-able context which is cancelled in ps.Close() in order to avoid a spinning loop in the websocket.Handler

* Moves the majority of playback logic into the playbackState, which is now renamed to the more accurate playbackPlayer.

* changes pp.hangWhilePaused to pp.waitWhilePaused

* Moves the context out of NewPlaybackPlayer and the playbackPlayer
struct, wraps playback goroutines in playbackPlayer.Play(ctx) in
order to comply with context semantics.

* removing unnecessary warnings

* touchups

* record screen size (#9992)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* Updates the websocket address

* updates desktopPlaybackHandle to restart playback once it reaches the end

* adds playback state and synchronization logic for ensuring that goroutines aren't leaked

* adds toggle functionality for play/pause

* fix for the fact that urls are case insensitive

* moves desktop_playback to its own file, fixes mistaken comment about how websocket.JSON.Receive works, fixes error messaging, wraps playbackState.Close in a sync.Once

* Adds a cond variable for the two goroutines, but doesn't solve the spinning loop problem for the hanging logic

* Adds a cancel-able context which is cancelled in ps.Close() in order to avoid a spinning loop in the websocket.Handler

* Moves the majority of playback logic into the playbackState, which is now renamed to the more accurate playbackPlayer.

* changes pp.hangWhilePaused to pp.waitWhilePaused

* Moves the context out of NewPlaybackPlayer and the playbackPlayer
struct, wraps playback goroutines in playbackPlayer.Play(ctx) in
order to comply with context semantics.

* removing unnecessary warnings

* Adds an OnRecv that's similar to OnSend, for emitting audit events for particular incoming tdp messages

* Send full `DesktopRecording` event as json over playback websocket. (#10052)

* playback websocket now sends a json representation of the DesktopRecording event rather than just the raw tdp message, in order for us to have timing data on the frontend

* updating json.Marshal to utils.FastMarshal

* Removing unnecessary comment

* playback end event (#10088)

* Adds an end event so that the playback player knows to set the progress bar to its end state

* making the end message a json

* if the marshal fails we don't want to send a message over websocket

* Use a static string

Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>

Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>

* Add participants to session end event

Desktop sessions are not joinable, so the participants list always
has a single member - the user who started the session.

This will ensure that our example role for RBAC for sessions
(which depends on the participants field) will work for desktop
sessions.

* Minor cleanup

* Only record sessions when enabled

In order for desktop sessions to be recorded, session recording
must be enabled in the cluster's session recording config and
at least one of the user's roles must enable it.

* Cleanup

* Start to address review comments

* Move TDP event handlers out of connectRDP

* Address more review comments and add some tests

* Add playback streaming test

* Consistent comments

* Fix tests

* Don't log PNG frames that exceed the size of a protobuf

Since the PNG frame message in our desktop protocol is unbounded,
it is theoretically possible for a message to exceed the size limit
of a single protobuf.

In practice, this is unlikely to occur with any legitimate RDP traffic,
as the bitmaps are at most 64x64 pixels and compressed in PNG form.
Rather than complicating the protocol to allow for PNGs to be split
across events, we simply refuse to log anything this big.

* Mark RFD 48 implemented

Co-authored-by: Isaiah Becker-Mayer <isaiah@goteleport.com>
Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>
2022-02-11 15:39:14 -07:00
Carson Anderson cc1e13154c Add keepalive heartbeat to kubernetes service (#9584)
This adds an rpc UpsertKubeServiceV2 to replace UpsertKubeService. Currently, kubernetes service does not have a keepalive heartbeat unlike app, db, and windows service. This brings functionality in line with the others. This would allow for future use of the keepalive to track connected agents via prometheus metrics.
2022-02-10 14:54:03 -07:00
Alex McGrath 34a087ff43 Convert auth test from gocheck to standard lib 2022-02-10 16:04:27 +00:00
Nic Klaassen bc441ef2cf IAM Join Method (gRPC service) (#10087) 2022-02-10 00:41:34 +00:00