mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
This commit implements #2543 In SSH terms ProxyJump is a shortcut for SSH client connecting the proxy/jumphost and requesting .port forwarding to the target node. This commit adds support for direct-tcpip request support in teleport proxy service that is an alias to the existing proxy subsystem and reuses most of the code. This commit also adds support to "route to cluster" metadata encoded in SSH certificate making it possible to have client SSH certificates to include the metadata that will cause the proxy to route the client requests to a specific cluster. `tsh ssh -J proxy:port ` is supported in a limited way: Only one jump host is supported (-J supports chaining that teleport does not utilise) and tsh will return with error in case of two jumphosts: -J a,b will not work. In case if `tsh ssh -J user@proxy` is used, it overrides the SSH proxy coming from the tsh profile and port-forwarding is used instead of the existing teleport proxy subsystem
59 lines
1.6 KiB
Go
59 lines
1.6 KiB
Go
/*
|
|
Copyright 2019 Gravitational, Inc.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package utils
|
|
|
|
import (
|
|
"regexp"
|
|
"strings"
|
|
|
|
"github.com/gravitational/trace"
|
|
)
|
|
|
|
var reProxyJump = regexp.MustCompile(
|
|
// optional username, note that outside group
|
|
`(?:(?P<username>[^@\:]+)@)?(?P<hostport>[^\@]+)`,
|
|
)
|
|
|
|
// JumpHost is a target jump host
|
|
type JumpHost struct {
|
|
// Username to login as
|
|
Username string
|
|
// Addr is a target addr
|
|
Addr NetAddr
|
|
}
|
|
|
|
// ParseProxyJump parses strings like user@host:port,bob@host:port
|
|
func ParseProxyJump(in string) ([]JumpHost, error) {
|
|
if in == "" {
|
|
return nil, trace.BadParameter("missing proxyjump")
|
|
}
|
|
parts := strings.Split(in, ",")
|
|
out := make([]JumpHost, 0, len(parts))
|
|
for _, part := range parts {
|
|
match := reProxyJump.FindStringSubmatch(strings.TrimSpace(part))
|
|
if len(match) == 0 {
|
|
return nil, trace.BadParameter("could not parse %q, expected format user@host:port,user@host:port", in)
|
|
}
|
|
addr, err := ParseAddr(match[2])
|
|
if err != nil {
|
|
return nil, trace.Wrap(err)
|
|
}
|
|
out = append(out, JumpHost{Username: match[1], Addr: *addr})
|
|
}
|
|
return out, nil
|
|
}
|