Commit Graph
7 Commits
Author SHA1 Message Date
Alan Parra dba49bfad6 Lint and fix missing license headers (#8075)
Introduce new make targets to check and add license headers to files
("make lint-license" and "make fix-license"). License checking is now a part of
"make lint" as well.

Initial attempts used goheader, but it caused "make lint-go" to become about 9x
slower (if not more), plus it only targets go files. Google's addlicense is fast
enough and targets however many file types we want.

Existing files that were missing licenses got the header added, using the
current year as the license date.

* Introduce lint-license and fix-license make targets
* Ignore generated files
* Add license to go files
* Replace irregular licenses with standard copyright/license
* Add license to proto files
* Install addlicense in build.assets Dockerfile
2021-08-30 09:44:09 -07:00
a-palchikov b6f4d6fc71 Log traits to role mapping warnings on case-insensitive matches (#6209)
* Compute warnings when mapping traits to roles
* Log warnings for case-insensitive traits to role matches.
Updates https://github.com/gravitational/teleport/issues/6016.
Co-authored-by: Andrew Lytvynov <andrew@goteleport.com>
2021-05-25 08:39:22 -07:00
Andrew Lytvynov 01516c5744 Partial revert of negative regexps in RBAC labels
This change was not backwards compatible - variable interpolation should
work in node_labels.

This commit partially reverts
https://github.com/gravitational/teleport/pull/4253 and
https://github.com/gravitational/teleport/pull/4430
2020-10-15 21:46:06 +00:00
Andrew Lytvynov 75d7fbb508 Migrate services.MatchLabels to parse.Matcher
This should be backwards-compatible plus add the {{regexp.match(...)}}
and {{regexp.not_match(...)}} functions.
2020-09-29 21:25:50 +00:00
Russell Jones 037d0bf32e Refactor regexp node labels. 2018-10-15 11:59:17 -07:00
ksuzuki ca3786eb79 wrote a test and fix a problem 2018-10-15 11:59:17 -07:00
Sasha Klizhentas 045490de25 External traits in node labels and regexp role map
This commit adds two extensions to template variables
in roles and adds support for regular expressions
and group captures in role mapping of trusted clusters.

1. Roles node_labels can expand variables from traits:

allow:
  node_labels:
    '{{external.key}}': '{{external.val}}'
deny:
  node_labels:
    '{{external.key}}': '{{external.val}}'

If traits variable is not found, label key pair in allow or
deny rule will be set to empty key or value, so if 'external.val'
trait is missing, the resulting role will not match
allow or deny rule:

allow:
  node_labels:
    '': 'val'
deny:
  node_labels:
    '': 'val'

Same thing will happen for missing value:

allow:
  node_labels:
    'key': ''
deny:
  node_labels:
    'key': ''

2. Trusted cluster role mapping can now
support advanced expressions:

a. Glob values will math any string, including
empty one

   role_map:
   - remote: 'cluster-*'
     local: [clusteradmin]

a. Regular expression syntax is supported:

Syntax: https://github.com/google/re2/wiki/Syntax

Brackets can be used as a capture group and referred
to with expand variable:

   role_map:
   - remote: '^clusteradmin-(.*)$'
     local: [unprivileged-$1]

Will map incoming role 'clusteradmin-account-1' to 'guest-account-1'.

3. Same regular expression syntax is supported for SAML and OIDC
mappings:

a. Glob matches of values instead of static matches:

  claims_to_roles:
      - {claim: "roles", value: "gravitational/*", roles: ["clusteradmin"]}

b. Regexp matches with subgroup expands:

  attributes_to_roles:
      - {name: "roles", value: "^gravitational/(.*)$", roles: ["cluster-$1"]}
2018-07-02 16:13:12 -07:00