Commit Graph
102 Commits
Author SHA1 Message Date
Forrest Marshall 50d767d304 improve cache test perf 2022-03-24 12:52:20 -07:00
rosstimothy 550d23d15d Fix goroutine and memory leak in watchCertAuthorities (#10871)
* Fix goroutine and memory leak in watchCertAuthorities

The CA Watcher was blocking both on writing to a channel when the watcher
was closed and on HTTP calls that had no request timeout or context passed
to cause cancellation.

All resourceWatcher implementations that had a bug which may cause them to block
on writing to a channel forever were fixed by selecting on the write and ctx.Done.

Adding context.Context to all Get/Put/Post/Delete methods on the auth HTTPClient to
force callers to propagate context. Prior all calls used context.TODO which
prevents requests from being properly cancelled.

Add context propagation to RotateCertAuthority, RotateExternalCertAuthority,
GetCertAuthority, GetCertAuthorities. This is needed to get the correct ctx
from the CertAtuhorityWatcher all the way down to the HTTPClient that makes
the call.

Closes #10648
2022-03-10 11:05:39 -05:00
Brian Joerger 600022b290 Change NewRole to use V5 by default, old consumers now user NewRoleV3. (#10884) 2022-03-08 21:11:53 +00:00
Lisa Kim 632d851783 Add KindWindowsDesktops to ListResources (#10769)
* Also add windows desktops sorter and its type converters
* Use forked vulcand/predicate library: allows traversing
  by embedded fields

Part of RFD 55
2022-03-07 08:58:26 -08:00
Lisa Kim e7eb6c4af8 Return filtered total count with ListResources (#10573)
* The web UI needed to show the total count of resources available after filter
* ListResources response returns as a struct to make adding extra fields easier
2022-02-28 21:51:19 +00:00
Edoardo Spadolini 6033148096 CertAuthority watcher filtering (#10020) 2022-02-19 00:48:16 +00:00
Alex McGrathandZac Bergquist 611c05106f Add support for windows desktop services proxying different desktops (#10101)
* Add support for windows desktop services proxying different desktops

* Add filter to GetWindowsDesktops, remove GetWindowsDesktop and GetWindowsDesktopByName

* Cache cleanup

* Fix cache deletes for Windows desktops

For deletes, the cache only gets the backend key, not the entire
resource. Do what database access does, which is to extract the
host ID from the path, and stuff it in the description field of
the resource header.

* Godoc cleanup

* Fix lint

* Address review comments

* Send error message if no desktop found

* Revert to x/net/websocket

This got converted to gorilla/websocket as part of moderated sessions.
We'll do a more intentional conversion post-release.

* fix lint

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2022-02-18 00:01:08 +00:00
Lisa Kim 74a21212c3 Implement resource sorter for server, appserver, dbserver (#10243)
* Define sorters for resource Server, AppServer, and DbServer
* Add sorting to ListResources in caching and presence layer
* ListResources now returns nextKey set to the limit+1th item,
  previously it returned a possible next key, where there
  may or may not be more results.
2022-02-17 00:42:03 +00:00
Joel ea810d30d9 Implement Moderated Sessions (#8563)
* Implement Moderated Sessions
2022-02-15 17:02:10 +01:00
Carson Anderson edff37226c Add Prometheus metrics cache events and stale events (#9826)
This adds two Prometheus metrics teleport_cache_events and teleport_cache_stale_events with one label indicating the service.
2022-02-11 09:14:42 -07:00
Forrest Marshall ba317929d4 active node inventory cleanup 2022-02-10 17:13:32 -08:00
Carson Anderson cc1e13154c Add keepalive heartbeat to kubernetes service (#9584)
This adds an rpc UpsertKubeServiceV2 to replace UpsertKubeService. Currently, kubernetes service does not have a keepalive heartbeat unlike app, db, and windows service. This brings functionality in line with the others. This would allow for future use of the keepalive to track connected agents via prometheus metrics.
2022-02-10 14:54:03 -07:00
rosstimothy 6cb13715ba Dynamically resolve reverse tunnel address (#9958)
* Dynamically resolve reverse tunnel address

The reverse tunnel address is currently a static string that is
retrieved from config and passed around for the duration of a
services lifetime. When the `tunnel_public_address` is changed
on the proxy and the proxy is then restarted, all established
reverse tunnels over the old address will fail indefinintely.
As a means to get around this, #8102 introduced a mechanism
that would cause nodes to restart if their connection to the
auth server was down for a period of time. While this did
allow the nodes to pickup the new address after the nodes
restarted it was meant to be a stop gap until a more robust
solution could be applid.

Instead of using a static address, the reverse tunnel address
is now resolved via a `reversetunnel.Resolver`. Anywhere that
previoulsy relied on the static proxy address now will fetch
the actual reverse tunnel address via the webclient by using
the Resolver. In addition this builds on the refactoring done
in #4290 to further simplify the reversetunnel package. Since
we no longer track multiple proxies, all the left over bits
that did so have been removed to accomodate using a dynamic
reverse tunnel address.
2022-02-03 16:24:48 +00:00
Gabriel Corado e426b782a9 feat: add KubeService and Node to ListResources (#9613) 2022-01-25 15:48:13 +00:00
JoelandZac Bergquist 62173e096b use google/uuid instead of pborman/uuid (#9793)
* replace imports

* use google/uuid

* fix test

* reverse changelog changes

* update gomod

* zac steps

* tidy

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2022-01-19 23:44:48 +00:00
rosstimothy dbc039c39d Fix Flaky Retry Tests (#9516)
Fix flaky unit tests
Addresses issues causing failures in TestCache_Backoff, TestTeleportProcess_reconnectToAuth
and TestResourceWatcher_Backoff. By utilizing FakeClock.BlockUntil tests ensure that the clock
will not be advanced until retry.After has been called. Move retry duration channels to config in order to allow them to be buffered by tests.
2022-01-05 12:33:58 -05:00
Forrest Marshall b0c76236ae fallback to calling origin if rc is missing from cache 2021-12-23 10:44:10 -08:00
rosstimothy ab857001de Add jitter and backoff to prevent thundering herd on auth (#9133)
Move cache and resourceWatcher watchers from a 10s retry to a jittered backoff retry up to ~1min. Replace the
reconnectToAuthService interval with a retry to add jitter and backoff there as well for when a node restarts due to
changes introduced in #8102.

Fixes #6889.
2021-12-16 11:41:08 -05:00
Gabriel Corado 5f403562ab feat: ListResources gRPC rpc (#9096) 2021-12-15 18:09:21 +00:00
Forrest Marshall 6f3ce8d3f5 improve Cache.ListNodes perf 2021-12-09 13:01:35 -08:00
Forrest Marshall dfd3732c6b improve concurrent watcher registration perf 2021-12-09 13:01:35 -08:00
Zac Bergquist 031fae2c6e Replace "loose" with "lose" (#9284) 2021-12-09 03:12:15 +00:00
rosstimothy 5cd7c3c294 Split auth.AccessPoint into variant specific interfaces (#8471) 2021-11-04 09:42:14 -04:00
Forrest Marshall 1944e62cc5 improve tests 2021-10-22 16:42:33 -07:00
Forrest Marshall 7f39084def fix nits 2021-10-22 16:42:33 -07:00
Forrest Marshall babd6b07dd remove OnlyRecent behavior 2021-10-22 16:42:33 -07:00
Forrest Marshall 78b0d8c726 ttl-based fallback caching 2021-10-22 16:42:33 -07:00
Forrest Marshall 19c5768873 server-side filtering 2021-10-22 16:42:33 -07:00
Zac Bergquist 01ced111f4 Add RBAC for Windows desktop access (#8520)
* Add RBAC for Windows desktop access

This commit adds RBAC checks for Windows Desktops as described in
RFD 33 and RFD 34:

- add Windows desktop logins & labels to role definition
- introduce new file config for host labels based on a regexp match
- auth server API performs access checking for Windows desktop resources
- add RDP client callback to authorize the user
- support user/role locks
- respect the client idle timeout setting

Note: in cases where an connection is terminated to to RBAC, the web UI
currently displays "websocket connection failed" because the connection
is closed from the server. We'll need to follow up with a nice error
message for the client side to improve the UX here.

Other changes:

* Remove OSS RBAC migration marked for deletion
* Stop creating a default admin role
* add wildcard desktop access to the preset access role

Updates #7761
2021-10-12 14:52:59 -06:00
Brian Joerger 2c8342c9de Remove RoleConditions type alias from lib/services. (#8441) 2021-10-05 14:04:18 -07:00
Andrej Tokarčík bddc54d8c4 Remove ClusterConfig resource (#8150) 2021-09-23 13:56:35 -07:00
Roman Tkachenko 6502a12f1f Add API and CLI for managing application resources (#8185) 2021-09-20 08:44:13 -07:00
Roman Tkachenko 4ea2ecdcfc Introduce app server and app resources (#8140) 2021-09-09 14:19:02 -07:00
Roman Tkachenko 3410bc8594 Dynamically register/unregister database resources (#7957) 2021-09-01 15:27:02 -07:00
Andrew Lytvynov f2cda7b3ee Split UpsertWindowsDesktop into Create/Update 2021-08-18 18:44:41 +00:00
Andrew Lytvynov e9351457ba Address review comments, batch 1 2021-08-18 18:44:41 +00:00
Andrew Lytvynov ab062428b1 Windows desktop service boilerplate
Boilerplate for a new service and API objects:
- windows_desktop_service config section
- service registration and heartbeats
- static host registration and heartbeats
- caching, permissions, etc
- "tctl get" support

For new connections the service aborts after authentication, since the
RDP client implementation is not ready yet (pending in
https://github.com/gravitational/teleport/pull/7824).

Tested that the service starts, registers (both over a tunnel and
directly) and creates the API objects.
2021-08-18 18:44:41 +00:00
Andrej Tokarčík 5db9c689cd Don't log warning for all remoteSite.periodicUpdateLocks failures (#7908) 2021-08-17 11:36:15 -07:00
Andrej Tokarčík a649db6746 Re-add GetLock methods for auth server cache (#7861) 2021-08-11 12:02:53 -07:00
Andrej Tokarčík 7d9067da24 Replicate locks to remote clusters (#7737) 2021-08-09 11:59:10 -07:00
Forrest Marshall 5864da793f fix stale event logging 2021-08-06 17:46:12 -07:00
Roman Tkachenko 629042ed30 Decouple database server from database (#7771) 2021-08-05 01:50:21 -07:00
Brian Joerger 9b8b9d6d0c rollback - Upgrade api version. (#7751) 2021-07-30 15:34:19 -07:00
Brian Joerger c040aca4c1 Upgrade api version. (#7609) 2021-07-28 13:51:21 -07:00
Andrej Tokarčík 7d878fff24 Enforce locks in auth.Authorize (#7625) 2021-07-28 18:54:21 +02:00
Andrej Tokarčík c782838c3a Fix ClusterConfig caching with pre-v7 remote clusters (#7698) 2021-07-27 15:15:05 +02:00
Andrej Tokarčík d5ca862280 Apply locks to connections tracked by srv.Monitor (#7506) 2021-07-23 14:11:50 +02:00
Forrest Marshall 530430e232 improve etcd event processing 2021-07-21 14:35:04 -07:00
Andrej Tokarčík 006c149001 Remove GetLock methods from Cache/ReadAccessPoint (#7593)
The cache system does not provide freshness guarantees required
for proper lock propagation.
2021-07-21 12:51:23 +02:00
Eugene Yakubovich 67c0eb3b4c Add restricted session
Adds the ability to block network traffic on SSH sessions.
The deny/allow lists of IPs are specified in teleport.yaml file.
Supports both IPv4 and IPv6 communication.

This feature currently relies on enhanced recording for
cgroup management so that needs to be enabled as well.

-- Design rationale:
This patch uses Linux Security Module (LSM) hooks, specifically
security_socket_connect and security_socket_sendmsg, to control
egress traffic. The LSM provides two advantages over socket filtering
program types.
- It's executed early enough that the task information is available.
  This makes it easy to report PID, COMM, etc.
- It becomes a model for extending restrictions beyond networking.

The set of enforced cgroups is stored in a BPF hash map and the
deny/allow lists are stored in BPF trie maps. An IP address is
first checked against the allow list. If found, it's checked for
an override in the deny list. The policy is default deny. However,
the absence of the NetworkRestrictions API object is allow all.

IPv4 addresses are additionally registered in IPv6 trie (as mapped)
to account for dual stacks. However it is unclear if this is sufficient
as 4-to-6 transition methods utilize a multitude of translation and
tunneling methods.
2021-07-16 16:49:04 -07:00