mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
This commit hex encodes trusted cluster names in target addresses for kubernetes SNI proxy. For example, assuming public address of Teleport Kubernetes proxy is main.example.com, and trusted cluster is remote.example.com, resulting target address added to kubeconfig will look like k72656d6f74652e6578616d706c652e636f6d0a.main.example.com And Teleport Proxy's DNS Name will include wildcard: '*.main.example.com' in addition to 'main.example.com' Note that no dots are in the SNI address thanks to hex encoding. This will allow administrators to avoid manually updating list of public_addr sections every time the trusted cluster and use the wildcard DNS name. The following addr: remote.example.com.main.example.com would not have matched *.main.example.com per DNS wildcard spec.