mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
169 lines
4.5 KiB
Go
169 lines
4.5 KiB
Go
/*
|
|
Copyright 2017-2021 Gravitational, Inc.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
// package modules allows external packages override certain behavioral
|
|
// aspects of teleport
|
|
package modules
|
|
|
|
import (
|
|
"crypto/sha256"
|
|
"fmt"
|
|
"reflect"
|
|
"runtime"
|
|
"sync"
|
|
|
|
"github.com/gravitational/teleport"
|
|
"github.com/gravitational/teleport/api/client/proto"
|
|
"github.com/gravitational/teleport/api/constants"
|
|
"github.com/gravitational/teleport/api/types"
|
|
|
|
"github.com/gravitational/trace"
|
|
)
|
|
|
|
// Features provides supported and unsupported features
|
|
type Features struct {
|
|
// Kubernetes enables Kubernetes Access product
|
|
Kubernetes bool
|
|
// App enables Application Access product
|
|
App bool
|
|
// DB enables database access product
|
|
DB bool
|
|
// OIDC enables OIDC connectors
|
|
OIDC bool
|
|
// SAML enables SAML connectors
|
|
SAML bool
|
|
// AccessControls enables FIPS access controls
|
|
AccessControls bool
|
|
// AdvancedAccessWorkflows enables advanced access workflows
|
|
AdvancedAccessWorkflows bool
|
|
// Cloud enables some cloud-related features
|
|
Cloud bool
|
|
// HSM enables PKCS#11 HSM support
|
|
HSM bool
|
|
// Desktop enables desktop access product
|
|
Desktop bool
|
|
}
|
|
|
|
// ToProto converts Features into proto.Features
|
|
func (f Features) ToProto() *proto.Features {
|
|
return &proto.Features{
|
|
Kubernetes: f.Kubernetes,
|
|
App: f.App,
|
|
DB: f.DB,
|
|
OIDC: f.OIDC,
|
|
SAML: f.SAML,
|
|
AccessControls: f.AccessControls,
|
|
AdvancedAccessWorkflows: f.AdvancedAccessWorkflows,
|
|
Cloud: f.Cloud,
|
|
HSM: f.HSM,
|
|
Desktop: f.Desktop,
|
|
}
|
|
}
|
|
|
|
// Modules defines interface that external libraries can implement customizing
|
|
// default teleport behavior
|
|
type Modules interface {
|
|
// PrintVersion prints teleport version
|
|
PrintVersion()
|
|
// IsBoringBinary checks if the binary was compiled with BoringCrypto.
|
|
IsBoringBinary() bool
|
|
// Features returns supported features
|
|
Features() Features
|
|
// BuildType returns build type (OSS or Enterprise)
|
|
BuildType() string
|
|
}
|
|
|
|
const (
|
|
// BuildOSS specifies open source build type
|
|
BuildOSS = "oss"
|
|
// BuildEnterprise specifies enterprise build type
|
|
BuildEnterprise = "ent"
|
|
)
|
|
|
|
// SetModules sets the modules interface
|
|
func SetModules(m Modules) {
|
|
mutex.Lock()
|
|
defer mutex.Unlock()
|
|
modules = m
|
|
}
|
|
|
|
// GetModules returns the modules interface
|
|
func GetModules() Modules {
|
|
mutex.Lock()
|
|
defer mutex.Unlock()
|
|
return modules
|
|
}
|
|
|
|
// ValidateResource performs additional resource checks.
|
|
func ValidateResource(res types.Resource) error {
|
|
// All checks below are Cloud-specific.
|
|
if !GetModules().Features().Cloud {
|
|
return nil
|
|
}
|
|
|
|
switch r := res.(type) {
|
|
case types.AuthPreference:
|
|
switch r.GetSecondFactor() {
|
|
case constants.SecondFactorOff, constants.SecondFactorOptional:
|
|
return trace.BadParameter("cannot disable two-factor authentication on Cloud")
|
|
}
|
|
case types.SessionRecordingConfig:
|
|
switch r.GetMode() {
|
|
case types.RecordAtProxy, types.RecordAtProxySync:
|
|
return trace.BadParameter("cannot set proxy recording mode on Cloud")
|
|
}
|
|
if !r.GetProxyChecksHostKeys() {
|
|
return trace.BadParameter("cannot disable strict host key checking on Cloud")
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
type defaultModules struct{}
|
|
|
|
// BuildType returns build type (OSS or Enterprise)
|
|
func (p *defaultModules) BuildType() string {
|
|
return BuildOSS
|
|
}
|
|
|
|
// PrintVersion prints the Teleport version.
|
|
func (p *defaultModules) PrintVersion() {
|
|
fmt.Printf("Teleport v%s git:%s %s\n", teleport.Version, teleport.Gitref, runtime.Version())
|
|
}
|
|
|
|
// Features returns supported features
|
|
func (p *defaultModules) Features() Features {
|
|
return Features{
|
|
Kubernetes: true,
|
|
DB: true,
|
|
App: true,
|
|
Desktop: true,
|
|
}
|
|
}
|
|
|
|
func (p *defaultModules) IsBoringBinary() bool {
|
|
// Check the package name for one of the boring primitives, if the package
|
|
// path is from BoringCrypto, we know this binary was compiled against the
|
|
// dev.boringcrypto branch of Go.
|
|
hash := sha256.New()
|
|
return reflect.TypeOf(hash).Elem().PkgPath() == "crypto/internal/boring"
|
|
}
|
|
|
|
var (
|
|
mutex sync.Mutex
|
|
modules Modules = &defaultModules{}
|
|
)
|