Files
teleport/docs/pages/database-access/reference/configuration.mdx
T

118 lines
3.7 KiB
Plaintext

---
title: Database Access Configuration Reference
description: Configuration reference for Teleport Database Access.
---
## Database service configuration
The following snippet shows full YAML configuration of a Database Service
appearing in `teleport.yaml` configuration file:
```yaml
(!docs/pages/includes/database-access/database-config.yaml!)
```
## Proxy configuration
The following Proxy service configuration is relevant for Database Access:
<Admonition
type="warning"
title="Proxy TLS Warning for PostgreSQL"
>
The PostgreSQL connection requires TLS enabled for the SSL connection that operates on the `web_listen_addr`.
Do not set `--insecure-no-tls` for the proxy Teleport instances as a parameter. If you are terminating TLS at a
Application Load Balancer (ALB) or other service that may require enabling a backend protocol of HTTPS for the target address.
</Admonition>
```yaml
proxy_service:
enabled: "yes"
# PostgreSQL proxy is listening on the regular web proxy port.
web_listen_addr: "0.0.0.0:3080"
# MySQL proxy is listening on a separate port and needs to be enabled
# on the proxy server.
mysql_listen_addr: "0.0.0.0:3036"
# Postgres proxy listening address. If provided, proxy will use a separate listener
# instead of multiplexing Postgres protocol on web_listener_addr.
# postgres_listen_addr: "0.0.0.0:5432"
# Mongo proxy listening address. If provided, proxy will use a separate listener
# instead of multiplexing Mongo protocol on web_listener_addr.
# mongo_listen_addr: "0.0.0.0:27017"
# By default database clients will be connecting to the Proxy over this
# hostname. To override public address for specific database protocols
# use postgres_public_addr and mysql_public_addr.
public_addr: "teleport.example.com:3080"
# Address advertised to MySQL clients. If not set, public_addr is used.
mysql_public_addr: "mysql.teleport.example.com:3306"
# Address advertised to PostgreSQL clients. If not set, public_addr is used.
postgres_public_addr: "postgres.teleport.example.com:443"
# Address advertised to Mongo clients. If not set, public_addr is used.
mongo_public_addr: "mongo.teleport.example.com:443"
```
## Database resource
Full YAML spec of database resources managed by `tctl` resource commands:
```yaml
kind: db
version: v3
metadata:
# Database resource name.
name: example
# Database resource description.
description: "Example database"
# Database resource static labels.
labels:
env: example
spec:
# Database protocol.
protocol: "postgres"
# Database connection endpoint.
uri: "localhost:5432"
# Optional CA for validating the database certificate.
ca_cert: |
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
# Optional AWS configuration for RDS/Aurora/Redshift. Can be auto-detected from the endpoint.
aws:
# Region the database is deployed in.
region: "us-east-1"
# Redshift specific configuration.
redshift:
# Redshift cluster identifier.
cluster_id: "redshift-cluster-1"
# Optional GCP configuration for Cloud SQL.
gcp:
# GCP project ID.
project_id: "xxx-1234"
# Cloud SQL instance ID.
instance_id: "example"
# Settings specific to Active Directory authentication e.g. for SQL Server.
ad:
# Path to Kerberos keytab file.
keytab_file: /path/to/keytab
# Active Directory domain name.
domain: EXAMPLE.COM
# Service Principal Name to obtain Kerberos tickets for.
spn: MSSQLSvc/ec2amaz-4kn05du.dbadir.teleportdemo.net:1433
# Optional path to Kerberos configuration file. Defaults to /etc/krb5.conf.
krb5_file: /etc/krb5.conf
# Optional dynamic labels.
dynamic_labels:
- name: "hostname"
command: ["hostname"]
period: 1m0s
```