mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Implements RFD #7 https://github.com/gravitational/teleport/blob/master/rfd/0007-rbac-oss.md OSS users can use roles. Some FedRamp related role options are limited to enterprise. All users are migrated to a new role "ossuser". This role is a limited access role downgrading all users from OSS role "admin". All trusted clusters are mapped to "ossuser" as well. Github connector maps teams to generated roles. For transition period, format `tctl users add alice` works alongside with `tctl users add alice --roles=admin`, but prints a warning.
113 lines
2.8 KiB
Go
113 lines
2.8 KiB
Go
/*
|
|
Copyright 2017-2021 Gravitational, Inc.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
// package modules allows external packages override certain behavioral
|
|
// aspects of teleport
|
|
package modules
|
|
|
|
import (
|
|
"fmt"
|
|
"runtime"
|
|
"sync"
|
|
|
|
"github.com/gravitational/teleport"
|
|
)
|
|
|
|
// Features provides supported and unsupported features
|
|
type Features struct {
|
|
// Kubernetes enables Kubernetes Access product
|
|
Kubernetes bool
|
|
// App enables Application Access product
|
|
App bool
|
|
// DB enables database access product
|
|
DB bool
|
|
// OIDC enables OIDC connectors
|
|
OIDC bool
|
|
// SAML enables SAML connectors
|
|
SAML bool
|
|
// AccessControls enables FIPS access controls
|
|
AccessControls bool
|
|
// AdvancedAccessWorkflows enables advanced access workflows
|
|
AdvancedAccessWorkflows bool
|
|
// Cloud enables some cloud-related features
|
|
Cloud bool
|
|
}
|
|
|
|
// Modules defines interface that external libraries can implement customizing
|
|
// default teleport behavior
|
|
type Modules interface {
|
|
// PrintVersion prints teleport version
|
|
PrintVersion()
|
|
// IsBoringBinary checks if the binary was compiled with BoringCrypto.
|
|
IsBoringBinary() bool
|
|
// Features returns supported features
|
|
Features() Features
|
|
// BuildType returns build type (OSS or Enterprise)
|
|
BuildType() string
|
|
}
|
|
|
|
const (
|
|
// BuildOSS specifies open source build type
|
|
BuildOSS = "oss"
|
|
// BuildEnterprise specifies enterprise build type
|
|
BuildEnterprise = "ent"
|
|
)
|
|
|
|
// SetModules sets the modules interface
|
|
func SetModules(m Modules) {
|
|
mutex.Lock()
|
|
defer mutex.Unlock()
|
|
modules = m
|
|
}
|
|
|
|
// GetModules returns the modules interface
|
|
func GetModules() Modules {
|
|
mutex.Lock()
|
|
defer mutex.Unlock()
|
|
return modules
|
|
}
|
|
|
|
type defaultModules struct{}
|
|
|
|
// BuildType returns build type (OSS or Enterprise)
|
|
func (p *defaultModules) BuildType() string {
|
|
return BuildOSS
|
|
}
|
|
|
|
// PrintVersion prints the Teleport version.
|
|
func (p *defaultModules) PrintVersion() {
|
|
fmt.Printf("Teleport v%s git:%s %s\n", teleport.Version, teleport.Gitref, runtime.Version())
|
|
}
|
|
|
|
// Features returns supported features
|
|
func (p *defaultModules) Features() Features {
|
|
return Features{
|
|
Kubernetes: true,
|
|
DB: true,
|
|
App: true,
|
|
}
|
|
}
|
|
|
|
// IsBoringBinary checks if the binary was compiled with BoringCrypto.
|
|
func (p *defaultModules) IsBoringBinary() bool {
|
|
return false
|
|
}
|
|
|
|
var (
|
|
mutex sync.Mutex
|
|
modules Modules = &defaultModules{}
|
|
)
|