Files
teleport/lib/utils
Sasha Klizhentas c623aa4dc5 Add cluster labels
Fixes #3604

This commit adds support for cluster_labels
role parameter limiting access to remote clusters by label.
New tctl update rc provides interface to set labels on remote clusters.

Consider two clusers, `one` - root and `remote` - leaf.

```bash
$ tsh clusters
Cluster Name Status
------------ ------
one          online
two          online
```

Create the trusted cluster join token with labels:

```bash
$ tctl tokens add --type=trusted_cluster --labels=env=prod
```

Every cluster joined using this token will inherit env:prod labels.

Alternatively, update remote cluster labels by modifying
`rc` command. Letting remote clusters to propagate their labels
creates a problem of rogue clusters updating their labels to bad values.

Instead, administrator of root cluster control the labels
using remote clusters API without fear of override:

```bash
$ tctl get rc

kind: remote_cluster
metadata:
  name: two
status:
  connection: online
  last_heartbeat: "2020-09-14T03:13:59.35518164Z"
version: v3
```

```bash
$ tctl update rc/two --set-labels=env=prod

cluster two has been updated
```

```bash
$ tctl get rc
kind: remote_cluster
metadata:
  labels:
    env: prod
  name: two
status:
  connection: online
  last_heartbeat: "2020-09-14T03:13:59.35518164Z"
```

Update the role to deny access to prod env:

```yaml
kind: role
metadata:
  name: dev
spec:
  allow:
    logins: [root]
    node_labels:
      '*': '*'

    # Cluster labels control what clusters user can connect to. The wildcard ('*') means
    # any cluster. If no role in the role set is using labels and cluster is not labeled,
    # the cluster labels check is not applied. Otherwise, cluster labels are always enforced.
    # This makes the feature backwards-compatible.
    cluster_labels:
      'env': 'staging'
  deny:
    # cluster labels control what clusters user can connect to. The wildcard ('*') means
    # any cluster. By default none is set in deny rules to preserve backwards compatibility
    cluster_labels:
      'env': 'prod'
```

```bash
$ tctl create -f dev.yaml
```

Cluster two is now invisible to user with `dev` role.

```bash
$ tsh clusters
Cluster Name Status
------------ ------
one          online
```
2020-11-03 16:10:15 -08:00
..
2018-08-03 11:06:08 -07:00
2020-05-27 19:36:38 +00:00
2019-09-24 14:01:30 -07:00
2018-01-09 10:30:19 -08:00
2020-10-13 00:22:49 +00:00
2020-04-17 20:05:38 +00:00
2020-05-27 19:36:38 +00:00
2020-09-28 23:08:56 -07:00
2020-05-11 16:44:27 +00:00
2020-11-03 16:10:15 -08:00
2019-05-07 14:17:11 -07:00
2018-08-03 11:06:08 -07:00
2020-11-03 14:32:13 -08:00
2016-12-08 18:43:37 -08:00
2017-01-17 14:17:03 -08:00
2020-09-28 23:08:56 -07:00
2019-05-07 14:17:11 -07:00
2016-12-08 18:43:37 -08:00
2020-09-28 23:08:56 -07:00
2020-01-02 17:56:53 -08:00
2020-09-28 23:08:56 -07:00
2020-11-03 14:32:13 -08:00