mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
If user running teleport is a member of adm group create the directory and all subdirectories accessible to admins. Remove obsolete migrations required for pre 2.3 releases.
229 lines
6.8 KiB
Go
229 lines
6.8 KiB
Go
package teleport
|
|
|
|
import (
|
|
"time"
|
|
)
|
|
|
|
// WebAPIVersion is a current webapi version
|
|
const WebAPIVersion = "v1"
|
|
|
|
// ForeverTTL means that object TTL will not expire unless deleted
|
|
const ForeverTTL time.Duration = 0
|
|
|
|
const (
|
|
// SSHAuthSock is the environment variable pointing to the
|
|
// Unix socket the SSH agent is running on.
|
|
SSHAuthSock = "SSH_AUTH_SOCK"
|
|
// SSHAgentPID is the environment variable pointing to the agent
|
|
// process ID
|
|
SSHAgentPID = "SSH_AGENT_PID"
|
|
|
|
// SSHTeleportUser is the current Teleport user that is logged in.
|
|
SSHTeleportUser = "SSH_TELEPORT_USER"
|
|
|
|
// SSHSessionWebproxyAddr is the address the web proxy.
|
|
SSHSessionWebproxyAddr = "SSH_SESSION_WEBPROXY_ADDR"
|
|
|
|
// SSHTeleportClusterName is the name of the cluster this node belongs to.
|
|
SSHTeleportClusterName = "SSH_TELEPORT_CLUSTER_NAME"
|
|
|
|
// SSHTeleportHostUUID is the UUID of the host.
|
|
SSHTeleportHostUUID = "SSH_TELEPORT_HOST_UUID"
|
|
|
|
// SSHSessionID is the UUID of the current session.
|
|
SSHSessionID = "SSH_SESSION_ID"
|
|
)
|
|
|
|
const (
|
|
// HTTPSProxy is an environment variable pointing to a HTTPS proxy.
|
|
HTTPSProxy = "HTTPS_PROXY"
|
|
|
|
// HTTPProxy is an environment variable pointing to a HTTP proxy.
|
|
HTTPProxy = "HTTP_PROXY"
|
|
)
|
|
|
|
const (
|
|
// TOTPValidityPeriod is the number of seconds a TOTP token is valid.
|
|
TOTPValidityPeriod uint = 30
|
|
|
|
// TOTPSkew adds that many periods before and after to the validity window.
|
|
TOTPSkew uint = 1
|
|
)
|
|
|
|
const (
|
|
// ComponentReverseTunnelServer is reverse tunnel server
|
|
// that together with agent establish a bi-directional SSH revers tunnel
|
|
// to bypass firewall restrictions
|
|
ComponentReverseTunnelServer = "proxy:server"
|
|
|
|
// ComponentReverseTunnel is reverse tunnel agent
|
|
// that together with server establish a bi-directional SSH revers tunnel
|
|
// to bypass firewall restrictions
|
|
ComponentReverseTunnelAgent = "proxy:agent"
|
|
|
|
// ComponentAuth is the cluster CA node (auth server API)
|
|
ComponentAuth = "auth"
|
|
|
|
// ComponentNode is SSH node (SSH server serving requests)
|
|
ComponentNode = "node"
|
|
|
|
// ComponentProxy is SSH proxy (SSH server forwarding connections)
|
|
ComponentProxy = "proxy"
|
|
|
|
// ComponentTunClient is a tunnel client
|
|
ComponentTunClient = "client:tunnel"
|
|
|
|
// ComponentCachingClient is a caching auth client
|
|
ComponentCachingClient = "client:cache"
|
|
|
|
// ComponentSubsystemProxy is the proxy subsystem.
|
|
ComponentSubsystemProxy = "subsystem:proxy"
|
|
|
|
// ComponentAuditLog is audit log component
|
|
ComponentAuditLog = "auditlog"
|
|
|
|
// DebugEnvVar tells tests to use verbose debug output
|
|
DebugEnvVar = "DEBUG"
|
|
|
|
// VerboseLogEnvVar forces all logs to be verbose (down to DEBUG level)
|
|
VerboseLogsEnvVar = "TELEPORT_DEBUG"
|
|
|
|
// DefaultTerminalWidth defines the default width of a server-side allocated
|
|
// pseudo TTY
|
|
DefaultTerminalWidth = 80
|
|
|
|
// DefaultTerminalHeight defines the default height of a server-side allocated
|
|
// pseudo TTY
|
|
DefaultTerminalHeight = 25
|
|
|
|
// SafeTerminalType is the fall-back TTY type to fall back to (when $TERM
|
|
// is not defined)
|
|
SafeTerminalType = "xterm"
|
|
|
|
// ConnectorOIDC means connector type OIDC
|
|
ConnectorOIDC = "oidc"
|
|
|
|
// ConnectorSAML means connector type SAML
|
|
ConnectorSAML = "oidc"
|
|
|
|
// DataDirParameterName is the name of the data dir configuration parameter passed
|
|
// to all backends during initialization
|
|
DataDirParameterName = "data_dir"
|
|
|
|
// SSH request type to keep the connection alive. A client and a server keep
|
|
// pining each other with it:
|
|
KeepAliveReqType = "keepalive@openssh.com"
|
|
|
|
// RecordingProxyReqType is the name of a global request which returns if
|
|
// the proxy is recording sessions or not.
|
|
RecordingProxyReqType = "recording-proxy@teleport.com"
|
|
|
|
// OTP means One-time Password Algorithm for Two-Factor Authentication.
|
|
OTP = "otp"
|
|
|
|
// TOTP means Time-based One-time Password Algorithm. for Two-Factor Authentication.
|
|
TOTP = "totp"
|
|
|
|
// HOTP means HMAC-based One-time Password Algorithm.for Two-Factor Authentication.
|
|
HOTP = "hotp"
|
|
|
|
// U2F means Universal 2nd Factor.for Two-Factor Authentication.
|
|
U2F = "u2f"
|
|
|
|
// OFF means no second factor.for Two-Factor Authentication.
|
|
OFF = "off"
|
|
|
|
// Local means authentication will happen locally within the Teleport cluster.
|
|
Local = "local"
|
|
|
|
// OIDC means authentication will happen remotly using an OIDC connector.
|
|
OIDC = "oidc"
|
|
|
|
// SAML means authentication will happen remotly using an SAML connector.
|
|
SAML = "saml"
|
|
|
|
// JSON means JSON serialization format
|
|
JSON = "json"
|
|
|
|
// LinuxAdminGID is the ID of the standard adm group on linux
|
|
LinuxAdminGID = 4
|
|
|
|
// LinuxOS is the name of the linux OS
|
|
LinuxOS = "linux"
|
|
|
|
// DirMaskSharedGroup is the mask for a directory accessible
|
|
// by the owner and group
|
|
DirMaskSharedGroup = 0770
|
|
)
|
|
|
|
const (
|
|
// AuthorizedKeys are public keys that check against User CAs.
|
|
AuthorizedKeys = "authorized_keys"
|
|
// KnownHosts are public keys that check against Host CAs.
|
|
KnownHosts = "known_hosts"
|
|
)
|
|
|
|
const (
|
|
// CertExtensionPermitAgentForwarding allows agent forwarding for certificate
|
|
CertExtensionPermitAgentForwarding = "permit-agent-forwarding"
|
|
// CertExtensionPermitPTY allows user to request PTY
|
|
CertExtensionPermitPTY = "permit-pty"
|
|
// CertExtensionPermitPortForwarding allows user to request port forwarding
|
|
CertExtensionPermitPortForwarding = "permit-port-forwarding"
|
|
// CertExtensionTeleportRoles is used to propagate teleport roles
|
|
CertExtensionTeleportRoles = "teleport-roles"
|
|
)
|
|
|
|
const (
|
|
// NetIQ is an identity provider.
|
|
NetIQ = "netiq"
|
|
// ADFS is Microsoft Active Directory Federation Services
|
|
ADFS = "adfs"
|
|
)
|
|
|
|
const (
|
|
// RemoteCommandSuccess is returned when a command has successfully executed.
|
|
RemoteCommandSuccess = 0
|
|
// RemoteCommandFailure is returned when a command has failed to execute and
|
|
// we don't have another status code for it.
|
|
RemoteCommandFailure = 255
|
|
)
|
|
|
|
// MaxEnvironmentFileLines is the maximum number of lines in a environment file.
|
|
const MaxEnvironmentFileLines = 1000
|
|
|
|
const (
|
|
// CompatibilityOldSSH is used to make Teleport interoperate with older
|
|
// versions of OpenSSH.
|
|
CompatibilityOldSSH = "oldssh"
|
|
|
|
// CompatibilityNone is used for normal Teleport operation without any
|
|
// compatibility modes.
|
|
CompatibilityNone = ""
|
|
)
|
|
|
|
const (
|
|
// TraitInternalPrefix is the role variable prefix that indicates it's for
|
|
// local accounts.
|
|
TraitInternalPrefix = "internal"
|
|
|
|
// TraitLogins is the name the role variable used to store
|
|
// allowed logins.
|
|
TraitLogins = "logins"
|
|
|
|
// TraitInternalRoleVariable is the role variable used to store allowed
|
|
// logins for local accounts.
|
|
TraitInternalRoleVariable = "{{internal.logins}}"
|
|
)
|
|
|
|
// Root is *nix system administrator account name.
|
|
const Root = "root"
|
|
|
|
// DefaultRole is the name of the default admin role for all local users if
|
|
// another role is not explicitly assigned (Enterprise only).
|
|
const AdminRoleName = "admin"
|
|
|
|
// DefaultImplicitRole is implicit role that gets added to all service.RoleSet
|
|
// objects.
|
|
const DefaultImplicitRole = "default-implicit-role"
|