Files
teleport/lib/modules/modules.go
T
Sasha Klizhentas 013f9680c9 OSS RBAC
Implements RFD #7

https://github.com/gravitational/teleport/blob/master/rfd/0007-rbac-oss.md

OSS users can use roles. Some FedRamp related role options
are limited to enterprise.

All users are migrated to a new role "ossuser".

This role is a limited access role downgrading all users
from OSS role "admin".

All trusted clusters are mapped to "ossuser" as well.

Github connector maps teams to generated roles.

For transition period, format `tctl users add alice` works
alongside with `tctl users add alice --roles=admin`, but prints
a warning.
2021-02-17 17:04:03 -08:00

113 lines
2.8 KiB
Go

/*
Copyright 2017-2021 Gravitational, Inc.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
// package modules allows external packages override certain behavioral
// aspects of teleport
package modules
import (
"fmt"
"runtime"
"sync"
"github.com/gravitational/teleport"
)
// Features provides supported and unsupported features
type Features struct {
// Kubernetes enables Kubernetes Access product
Kubernetes bool
// App enables Application Access product
App bool
// DB enables database access product
DB bool
// OIDC enables OIDC connectors
OIDC bool
// SAML enables SAML connectors
SAML bool
// AccessControls enables FIPS access controls
AccessControls bool
// AdvancedAccessWorkflows enables advanced access workflows
AdvancedAccessWorkflows bool
// Cloud enables some cloud-related features
Cloud bool
}
// Modules defines interface that external libraries can implement customizing
// default teleport behavior
type Modules interface {
// PrintVersion prints teleport version
PrintVersion()
// IsBoringBinary checks if the binary was compiled with BoringCrypto.
IsBoringBinary() bool
// Features returns supported features
Features() Features
// BuildType returns build type (OSS or Enterprise)
BuildType() string
}
const (
// BuildOSS specifies open source build type
BuildOSS = "oss"
// BuildEnterprise specifies enterprise build type
BuildEnterprise = "ent"
)
// SetModules sets the modules interface
func SetModules(m Modules) {
mutex.Lock()
defer mutex.Unlock()
modules = m
}
// GetModules returns the modules interface
func GetModules() Modules {
mutex.Lock()
defer mutex.Unlock()
return modules
}
type defaultModules struct{}
// BuildType returns build type (OSS or Enterprise)
func (p *defaultModules) BuildType() string {
return BuildOSS
}
// PrintVersion prints the Teleport version.
func (p *defaultModules) PrintVersion() {
fmt.Printf("Teleport v%s git:%s %s\n", teleport.Version, teleport.Gitref, runtime.Version())
}
// Features returns supported features
func (p *defaultModules) Features() Features {
return Features{
Kubernetes: true,
DB: true,
App: true,
}
}
// IsBoringBinary checks if the binary was compiled with BoringCrypto.
func (p *defaultModules) IsBoringBinary() bool {
return false
}
var (
mutex sync.Mutex
modules Modules = &defaultModules{}
)