Files
teleport/lib/utils/proxyjump.go
T
Sasha Klizhentas 838e75468c Add support for ProxyJump.
This commit implements #2543

In SSH terms ProxyJump is a shortcut for SSH client
connecting the proxy/jumphost and requesting .port forwarding to the
target node.

This commit adds support for direct-tcpip request support
in teleport proxy service that is an alias to the existing proxy
subsystem and reuses most of the code.

This commit also adds support to "route to cluster" metadata
encoded in SSH certificate making it possible to have client
SSH certificates to include the metadata that will cause the proxy
to route the client requests to a specific cluster.

`tsh ssh -J proxy:port ` is supported in a limited way:

Only one jump host is supported (-J supports chaining
that teleport does not utilise) and tsh will return with error
in case of two jumphosts: -J a,b will not work.

In case if `tsh ssh -J user@proxy` is used, it overrides
the SSH proxy coming from the tsh profile and port-forwarding
is used instead of the existing teleport proxy subsystem
2019-07-26 10:58:11 -07:00

59 lines
1.6 KiB
Go

/*
Copyright 2019 Gravitational, Inc.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package utils
import (
"regexp"
"strings"
"github.com/gravitational/trace"
)
var reProxyJump = regexp.MustCompile(
// optional username, note that outside group
`(?:(?P<username>[^@\:]+)@)?(?P<hostport>[^\@]+)`,
)
// JumpHost is a target jump host
type JumpHost struct {
// Username to login as
Username string
// Addr is a target addr
Addr NetAddr
}
// ParseProxyJump parses strings like user@host:port,bob@host:port
func ParseProxyJump(in string) ([]JumpHost, error) {
if in == "" {
return nil, trace.BadParameter("missing proxyjump")
}
parts := strings.Split(in, ",")
out := make([]JumpHost, 0, len(parts))
for _, part := range parts {
match := reProxyJump.FindStringSubmatch(strings.TrimSpace(part))
if len(match) == 0 {
return nil, trace.BadParameter("could not parse %q, expected format user@host:port,user@host:port", in)
}
addr, err := ParseAddr(match[2])
if err != nil {
return nil, trace.Wrap(err)
}
out = append(out, JumpHost{Username: match[1], Addr: *addr})
}
return out, nil
}