* Replace multi-line ScopedBlocks with Tabs
Contributes to #30268
The documentation scope switcher tends to confuse users, and the
ScopedBlock component hides docs content based on the scope switcher. To
help remove ScopedBlocks from the docs site, this change replaces
multi-line ScopedBlocks with Tabs components if they include variations
for different scopes.
While most multi-line ScopedBlocks function like Tabs, there are a few
edge cases, which this change addresses individually.
Note that this change does not intend to remove all ScopedBlocks that
are placed inline within a paragraph. That will be the goal of a
separate change.
* Remove more ScopedBlocks (#30623)
This builds on the work done in #30616 and contributes to #30616.
In gravitational/docs#238, we will add a linter that lints for incorrect
usage of Teleport terms. This change fixes linter violations to
anticipate this new linter.
Changes include:
- Ensuring that Teleport service names are capitalized
- No longer using the "[Resource] Access" terminology. Instead, talk
about adding resources, using Teleport services, etc.
* Require a new flag for enabling dynamic resources matching for "tsh db configure create"
* rename flag to --dynamic-resources-labels
* make naming more consistent
* Add port number to cloud address examples for proxy server
* fix port example
* Include 443 port in cloud proxy examples
* use 443 instead of 3080 for cloud examples
* Add RBAC instructions for DB tctl auth sign
Fixes#13768
Add a `Details` box to the `tctl auth sign` entry in the Database Access
CLI reference explaining how to set up your user's Teleport roles in
order to enable running `tctl auth sign` for database-specific
certificate formats.
* Update docs/pages/database-access/reference/cli.mdx
Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
Fixes#10976
This change helps to remedy two issues with the documentation:
- Much of the documentation was written when Teleport's services
consisted of the Auth Service, Proxy Service, and Nodes/SSH Service.
There are some places in the docs where a reader can mistake the
Node Service to mean "any resource service."
- Users often associate the term "agent" with a daemon that must run on
every host in their infrastructure, and usage of this term can make
Teleport seem more resource intensive than it actually is.
This change corrects mentions of "Node" that stand in for "any service
that access resources in your infrastructure" to account for Teleport's
other resource services. It also replaces mentions of the term "agent"
with "instance," the name of a resource service, or simply "Teleport."
Also edits the "agentless" question in the FAQ to include more detailed
information about each of Teleport's resource services.
This change also does some light copy-editing to correct the
capitalization of service names. It doesn't aim to be comprehensive,
though, since the main purpose of this change is to fix potentially
misleading mentions of "Node" and "agents".
Finally, this change deletes the production.mdx guide, as there is
no way to access this guide due to redirects. This guide includes
some outdated usage of "Nodes".
* Update error message returned when user is not allowed to sign db certs
* Update lib/auth/auth_with_roles.go
Co-authored-by: Nic Klaassen <nic@goteleport.com>
* Update docs
* Fix docs
* Update error for snowflake cert signing
* Update docs/pages/database-access/reference/cli.mdx
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Update docs/pages/database-access/reference/cli.mdx
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
* Edit tctl instructions to clarify remote login
Closes#11464
- Ensure that all example tctl commands are accompanied either by
instructions to log in to the cluster or the tctl.mdx partial.
- Edit the guides in the Architecture section to remove notes that
tctl can only be used locally to the Auth Service.
- Edit the user-client-rereqs partial to mention tctl for all
editions, since you can log in to tctl remotely for all editions.
Not editing guides where:
- tctl is run via kubectl exec
- tctl is not mentioned in a code block, i.e., only in passing, and
a reader isn't expected to run the command on their own while
following the guide.
- The user is already expected to run tctl on the Auth Service. The
docker-compose Getting Started guide is an example of this.
* Respond to PR feedback
- Provide more context on authenticating with tctl in the CLI reference
- Update the link to more information re: tctl in the architecture
overview, and indicate that tctl users must authenticate.
- Minor tweaks.
* Respond to PR feedback
- Rephrase the authentication paragraph in the Architecture Overview.
* Add Cloud instructions to five guides
See #10637
Database Access FAQ
- Add tabbed instructions where answers differ for Cloud/Self-Hosted
- Style/grammar tweaks
Dynamic Registration
- While this guide is edition agnostic, I have added the tctl.mdx
partial so Cloud users know to log in to Teleport before running
tctl commands.
Configuration reference
- The only part that required different instructions for Cloud users
was the reference configuration for the Proxy Service. I have
supplied the values hardcoded in Teleport Cloud.
CLI reference
- Add ScopedBlocks where examples mention proxy.example.com--use a
Cloud tenant address for Cloud readers.
- Light style/grammar edits
Architecture
- This guide is mostly edition agnostic. After the overview diagram,
I used a ScopedBlock to make it clear to Cloud users that the Proxy
Service uses the Teleport Cloud tenant address.
* Respond to PR feedback
Also remove mongo_public_addr from the Cloud proxy_service config,
since this was included incorrectly.
* Use `mongosh` client when available.
* Document `mongosh` as default client from 9.0 and `mongo` being the fallback.
Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>