mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
* Enforce join token locks for agents When agents attempt to join with the the bound keypair join method and fail join state verification, a lock is created. This lock traditionally targeted only bots. While the lock target - the join token - is ostensibly not bot specific, we were not plumbing through the token name into host certificates, meaning the lock wasn't practically enforced for host identities. Future join attempts would still fail, but the existing agents wouldn't be locked. This change adds a test for agent locking, plumbs through the join token name in host certificates, and updates the lock message text for agents so it isn't bot specific. Note that agents do not have an analogous notion of renewable identities and don't have a generation counter - their identities last 10 years and don't renew. This means bound keypair agents only generate join state locks, not generation counter locks. * Code review feedback Switches to require.EventuallyWithT() * Remove fake clock * Convert TestJoinBoundKeypair_JoinStateFailure_Instance to synctest * Remove synctest in favor of inspecting the LockWatcher directly * Persist JoinToken cert field in GenerateHostCerts * Remove BuffconnListener