Scopes: support tpm joining (#289)

Export-Source-Commit: 395143602db02eeaf5f8e9f2f4ca3e951fcb11ce
This commit is contained in:
Tim Buckley
2026-08-25 11:35:10 -05:00
committed by Gus Rivera
parent 95cea18a8e
commit 642aa16ecf
14 changed files with 1331 additions and 219 deletions
@@ -278,7 +278,9 @@ type ScopedTokenSpec struct {
// Configuration specific to the "github" join method.
Github *Github `protobuf:"bytes,17,opt,name=github,proto3" json:"github,omitempty"`
// Configuration specific to the "gitlab" join method.
Gitlab *GitLab `protobuf:"bytes,18,opt,name=gitlab,proto3" json:"gitlab,omitempty"`
Gitlab *GitLab `protobuf:"bytes,18,opt,name=gitlab,proto3" json:"gitlab,omitempty"`
// Configuration specific to the "tpm" join method.
Tpm *TPM `protobuf:"bytes,19,opt,name=tpm,proto3" json:"tpm,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
@@ -420,6 +422,13 @@ func (x *ScopedTokenSpec) GetGitlab() *GitLab {
return nil
}
func (x *ScopedTokenSpec) GetTpm() *TPM {
if x != nil {
return x.Tpm
}
return nil
}
func (x *ScopedTokenSpec) SetAssignedScope(v string) {
x.AssignedScope = v
}
@@ -484,6 +493,10 @@ func (x *ScopedTokenSpec) SetGitlab(v *GitLab) {
x.Gitlab = v
}
func (x *ScopedTokenSpec) SetTpm(v *TPM) {
x.Tpm = v
}
func (x *ScopedTokenSpec) HasImmutableLabels() bool {
if x == nil {
return false
@@ -561,6 +574,13 @@ func (x *ScopedTokenSpec) HasGitlab() bool {
return x.Gitlab != nil
}
func (x *ScopedTokenSpec) HasTpm() bool {
if x == nil {
return false
}
return x.Tpm != nil
}
func (x *ScopedTokenSpec) ClearImmutableLabels() {
x.ImmutableLabels = nil
}
@@ -605,6 +625,10 @@ func (x *ScopedTokenSpec) ClearGitlab() {
x.Gitlab = nil
}
func (x *ScopedTokenSpec) ClearTpm() {
x.Tpm = nil
}
type ScopedTokenSpec_builder struct {
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
@@ -653,6 +677,8 @@ type ScopedTokenSpec_builder struct {
Github *Github
// Configuration specific to the "gitlab" join method.
Gitlab *GitLab
// Configuration specific to the "tpm" join method.
Tpm *TPM
}
func (b0 ScopedTokenSpec_builder) Build() *ScopedTokenSpec {
@@ -675,6 +701,7 @@ func (b0 ScopedTokenSpec_builder) Build() *ScopedTokenSpec {
x.GenericOidc = b.GenericOidc
x.Github = b.Github
x.Gitlab = b.Gitlab
x.Tpm = b.Tpm
return m0
}
@@ -2900,6 +2927,94 @@ func (b0 GitLab_builder) Build() *GitLab {
return m0
}
// Configuration specific to TPM tokens.
type TPM struct {
state protoimpl.MessageState `protogen:"hybrid.v1"`
// A list of Rules, the presented delegated identity must match one allow rule
// to permit joining.
Allow []*TPM_Rule `protobuf:"bytes,1,rep,name=allow,proto3" json:"allow,omitempty"`
// A list of CA certificates that will be used to validate TPM EKCerts.
// When specified, joining TPMs must present an EKCert signed by one of the
// specified CAs. TPMs that do not present an EKCert will be not permitted to
// join.
// When unspecified, TPMs will be allowed to join with either an EKCert or an
// EKPubHash.
EkcertAllowedCas []string `protobuf:"bytes,2,rep,name=ekcert_allowed_cas,json=ekcertAllowedCas,proto3" json:"ekcert_allowed_cas,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *TPM) Reset() {
*x = TPM{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[20]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *TPM) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*TPM) ProtoMessage() {}
func (x *TPM) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[20]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
func (x *TPM) GetAllow() []*TPM_Rule {
if x != nil {
return x.Allow
}
return nil
}
func (x *TPM) GetEkcertAllowedCas() []string {
if x != nil {
return x.EkcertAllowedCas
}
return nil
}
func (x *TPM) SetAllow(v []*TPM_Rule) {
x.Allow = v
}
func (x *TPM) SetEkcertAllowedCas(v []string) {
x.EkcertAllowedCas = v
}
type TPM_builder struct {
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
// A list of Rules, the presented delegated identity must match one allow rule
// to permit joining.
Allow []*TPM_Rule
// A list of CA certificates that will be used to validate TPM EKCerts.
// When specified, joining TPMs must present an EKCert signed by one of the
// specified CAs. TPMs that do not present an EKCert will be not permitted to
// join.
// When unspecified, TPMs will be allowed to join with either an EKCert or an
// EKPubHash.
EkcertAllowedCas []string
}
func (b0 TPM_builder) Build() *TPM {
m0 := &TPM{}
b, x := &b0, m0
_, _ = b, x
x.Allow = b.Allow
x.EkcertAllowedCas = b.EkcertAllowedCas
return m0
}
// A rule that a joining node must match in order to use the associated token
// with AWS join methods.
type AWS_Rule struct {
@@ -2924,7 +3039,7 @@ type AWS_Rule struct {
func (x *AWS_Rule) Reset() {
*x = AWS_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[21]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -2936,7 +3051,7 @@ func (x *AWS_Rule) String() string {
func (*AWS_Rule) ProtoMessage() {}
func (x *AWS_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[21]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3049,7 +3164,7 @@ type GCP_Rule struct {
func (x *GCP_Rule) Reset() {
*x = GCP_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3061,7 +3176,7 @@ func (x *GCP_Rule) String() string {
func (*GCP_Rule) ProtoMessage() {}
func (x *GCP_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3142,7 +3257,7 @@ type Azure_Rule struct {
func (x *Azure_Rule) Reset() {
*x = Azure_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3154,7 +3269,7 @@ func (x *Azure_Rule) String() string {
func (*Azure_Rule) ProtoMessage() {}
func (x *Azure_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3261,7 +3376,7 @@ type AzureDevops_Rule struct {
func (x *AzureDevops_Rule) Reset() {
*x = AzureDevops_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3273,7 +3388,7 @@ func (x *AzureDevops_Rule) String() string {
func (*AzureDevops_Rule) ProtoMessage() {}
func (x *AzureDevops_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3445,7 +3560,7 @@ type Oracle_Rule struct {
func (x *Oracle_Rule) Reset() {
*x = Oracle_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3457,7 +3572,7 @@ func (x *Oracle_Rule) String() string {
func (*Oracle_Rule) ProtoMessage() {}
func (x *Oracle_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3551,7 +3666,7 @@ type Kubernetes_StaticJWKSConfig struct {
func (x *Kubernetes_StaticJWKSConfig) Reset() {
*x = Kubernetes_StaticJWKSConfig{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3563,7 +3678,7 @@ func (x *Kubernetes_StaticJWKSConfig) String() string {
func (*Kubernetes_StaticJWKSConfig) ProtoMessage() {}
func (x *Kubernetes_StaticJWKSConfig) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3616,7 +3731,7 @@ type Kubernetes_OIDCConfig struct {
func (x *Kubernetes_OIDCConfig) Reset() {
*x = Kubernetes_OIDCConfig{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3628,7 +3743,7 @@ func (x *Kubernetes_OIDCConfig) String() string {
func (*Kubernetes_OIDCConfig) ProtoMessage() {}
func (x *Kubernetes_OIDCConfig) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3708,7 +3823,7 @@ type Kubernetes_Rule struct {
func (x *Kubernetes_Rule) Reset() {
*x = Kubernetes_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3720,7 +3835,7 @@ func (x *Kubernetes_Rule) String() string {
func (*Kubernetes_Rule) ProtoMessage() {}
func (x *Kubernetes_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3823,7 +3938,7 @@ type BoundKeypairSpec_OnboardingSpec struct {
func (x *BoundKeypairSpec_OnboardingSpec) Reset() {
*x = BoundKeypairSpec_OnboardingSpec{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3835,7 +3950,7 @@ func (x *BoundKeypairSpec_OnboardingSpec) String() string {
func (*BoundKeypairSpec_OnboardingSpec) ProtoMessage() {}
func (x *BoundKeypairSpec_OnboardingSpec) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3958,7 +4073,7 @@ type BoundKeypairSpec_RecoverySpec struct {
func (x *BoundKeypairSpec_RecoverySpec) Reset() {
*x = BoundKeypairSpec_RecoverySpec{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3970,7 +4085,7 @@ func (x *BoundKeypairSpec_RecoverySpec) String() string {
func (*BoundKeypairSpec_RecoverySpec) ProtoMessage() {}
func (x *BoundKeypairSpec_RecoverySpec) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4051,7 +4166,7 @@ type GenericOIDC_ConditionEq struct {
func (x *GenericOIDC_ConditionEq) Reset() {
*x = GenericOIDC_ConditionEq{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4063,7 +4178,7 @@ func (x *GenericOIDC_ConditionEq) String() string {
func (*GenericOIDC_ConditionEq) ProtoMessage() {}
func (x *GenericOIDC_ConditionEq) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4111,7 +4226,7 @@ type GenericOIDC_ConditionNotEq struct {
func (x *GenericOIDC_ConditionNotEq) Reset() {
*x = GenericOIDC_ConditionNotEq{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4123,7 +4238,7 @@ func (x *GenericOIDC_ConditionNotEq) String() string {
func (*GenericOIDC_ConditionNotEq) ProtoMessage() {}
func (x *GenericOIDC_ConditionNotEq) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4171,7 +4286,7 @@ type GenericOIDC_ConditionIn struct {
func (x *GenericOIDC_ConditionIn) Reset() {
*x = GenericOIDC_ConditionIn{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4183,7 +4298,7 @@ func (x *GenericOIDC_ConditionIn) String() string {
func (*GenericOIDC_ConditionIn) ProtoMessage() {}
func (x *GenericOIDC_ConditionIn) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4231,7 +4346,7 @@ type GenericOIDC_ConditionNotIn struct {
func (x *GenericOIDC_ConditionNotIn) Reset() {
*x = GenericOIDC_ConditionNotIn{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4243,7 +4358,7 @@ func (x *GenericOIDC_ConditionNotIn) String() string {
func (*GenericOIDC_ConditionNotIn) ProtoMessage() {}
func (x *GenericOIDC_ConditionNotIn) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4300,7 +4415,7 @@ type GenericOIDC_Condition struct {
func (x *GenericOIDC_Condition) Reset() {
*x = GenericOIDC_Condition{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4312,7 +4427,7 @@ func (x *GenericOIDC_Condition) String() string {
func (*GenericOIDC_Condition) ProtoMessage() {}
func (x *GenericOIDC_Condition) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4468,7 +4583,7 @@ type GenericOIDC_Rule struct {
func (x *GenericOIDC_Rule) Reset() {
*x = GenericOIDC_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4480,7 +4595,7 @@ func (x *GenericOIDC_Rule) String() string {
func (*GenericOIDC_Rule) ProtoMessage() {}
func (x *GenericOIDC_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4597,7 +4712,7 @@ type Github_Rule struct {
func (x *Github_Rule) Reset() {
*x = Github_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4609,7 +4724,7 @@ func (x *Github_Rule) String() string {
func (*Github_Rule) ProtoMessage() {}
func (x *Github_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4877,7 +4992,7 @@ type GitLab_Rule struct {
func (x *GitLab_Rule) Reset() {
*x = GitLab_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[39]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4889,7 +5004,7 @@ func (x *GitLab_Rule) String() string {
func (*GitLab_Rule) ProtoMessage() {}
func (x *GitLab_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[39]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -5189,6 +5304,117 @@ func (b0 GitLab_Rule_builder) Build() *GitLab_Rule {
return m0
}
// A rule for TPM joining tokens, of which one must match for a join attempt
// to be allowed.
type TPM_Rule struct {
state protoimpl.MessageState `protogen:"hybrid.v1"`
// A human-readable description of the rule. It has no bearing on whether or
// not a TPM is allowed to join, but can be used to associate a rule with a
// specific host (e.g the asset tag of the server in which the TPM resides).
// Example: "build-server-100"
Description string `protobuf:"bytes,1,opt,name=description,proto3" json:"description,omitempty"`
// The SHA256 hash of the EKPub marshaled in PKIX format and encoded in
// hexadecimal. This value will also be checked when a TPM has submitted an
// EKCert, and the public key in the EKCert will be used for this check.
// Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
EkPublicHash string `protobuf:"bytes,2,opt,name=ek_public_hash,json=ekPublicHash,proto3" json:"ek_public_hash,omitempty"`
// The serial number of the EKCert in hexadecimal with colon separated
// nibbles. This value will not be checked when a TPM does not have an
// EKCert configured.
// Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
EkCertificateSerial string `protobuf:"bytes,3,opt,name=ek_certificate_serial,json=ekCertificateSerial,proto3" json:"ek_certificate_serial,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *TPM_Rule) Reset() {
*x = TPM_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[40]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *TPM_Rule) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*TPM_Rule) ProtoMessage() {}
func (x *TPM_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[40]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
func (x *TPM_Rule) GetDescription() string {
if x != nil {
return x.Description
}
return ""
}
func (x *TPM_Rule) GetEkPublicHash() string {
if x != nil {
return x.EkPublicHash
}
return ""
}
func (x *TPM_Rule) GetEkCertificateSerial() string {
if x != nil {
return x.EkCertificateSerial
}
return ""
}
func (x *TPM_Rule) SetDescription(v string) {
x.Description = v
}
func (x *TPM_Rule) SetEkPublicHash(v string) {
x.EkPublicHash = v
}
func (x *TPM_Rule) SetEkCertificateSerial(v string) {
x.EkCertificateSerial = v
}
type TPM_Rule_builder struct {
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
// A human-readable description of the rule. It has no bearing on whether or
// not a TPM is allowed to join, but can be used to associate a rule with a
// specific host (e.g the asset tag of the server in which the TPM resides).
// Example: "build-server-100"
Description string
// The SHA256 hash of the EKPub marshaled in PKIX format and encoded in
// hexadecimal. This value will also be checked when a TPM has submitted an
// EKCert, and the public key in the EKCert will be used for this check.
// Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
EkPublicHash string
// The serial number of the EKCert in hexadecimal with colon separated
// nibbles. This value will not be checked when a TPM does not have an
// EKCert configured.
// Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
EkCertificateSerial string
}
func (b0 TPM_Rule_builder) Build() *TPM_Rule {
m0 := &TPM_Rule{}
b, x := &b0, m0
_, _ = b, x
x.Description = b.Description
x.EkPublicHash = b.EkPublicHash
x.EkCertificateSerial = b.EkCertificateSerial
return m0
}
var File_teleport_scopes_joining_v1_token_proto protoreflect.FileDescriptor
const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
@@ -5201,7 +5427,7 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
"\bmetadata\x18\x04 \x01(\v2\x1c.teleport.header.v1.MetadataR\bmetadata\x12\x14\n" +
"\x05scope\x18\x05 \x01(\tR\x05scope\x12?\n" +
"\x04spec\x18\x06 \x01(\v2+.teleport.scopes.joining.v1.ScopedTokenSpecR\x04spec\x12E\n" +
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\x9f\a\n" +
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\xd2\a\n" +
"\x0fScopedTokenSpec\x12%\n" +
"\x0eassigned_scope\x18\x01 \x01(\tR\rassignedScope\x12\x14\n" +
"\x05roles\x18\x02 \x03(\tR\x05roles\x12\x1f\n" +
@@ -5223,7 +5449,8 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
"\x03bot\x18\x0f \x01(\tR\x03bot\x12J\n" +
"\fgeneric_oidc\x18\x10 \x01(\v2'.teleport.scopes.joining.v1.GenericOIDCR\vgenericOidc\x12:\n" +
"\x06github\x18\x11 \x01(\v2\".teleport.scopes.joining.v1.GithubR\x06github\x12:\n" +
"\x06gitlab\x18\x12 \x01(\v2\".teleport.scopes.joining.v1.GitLabR\x06gitlabJ\x04\b\r\x10\x0eJ\x04\b\x0e\x10\x0fR\bbot_nameR\tbot_scope\"\xb6\x01\n" +
"\x06gitlab\x18\x12 \x01(\v2\".teleport.scopes.joining.v1.GitLabR\x06gitlab\x121\n" +
"\x03tpm\x18\x13 \x01(\v2\x1f.teleport.scopes.joining.v1.TPMR\x03tpmJ\x04\b\r\x10\x0eJ\x04\b\x0e\x10\x0fR\bbot_nameR\tbot_scope\"\xb6\x01\n" +
"\x0eHostCertParams\x12\x17\n" +
"\ahost_id\x18\x01 \x01(\tR\x06hostId\x12\x1b\n" +
"\tnode_name\x18\x02 \x01(\tR\bnodeName\x12\x12\n" +
@@ -5418,9 +5645,16 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
"\x0fdeployment_tier\x18\x0f \x01(\tR\x0edeploymentTier\x12-\n" +
"\x12project_visibility\x18\x10 \x01(\tR\x11projectVisibilityB\x10\n" +
"\x0e_ref_protectedB\x18\n" +
"\x16_environment_protectedBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
"\x16_environment_protected\"\xf4\x01\n" +
"\x03TPM\x12:\n" +
"\x05allow\x18\x01 \x03(\v2$.teleport.scopes.joining.v1.TPM.RuleR\x05allow\x12,\n" +
"\x12ekcert_allowed_cas\x18\x02 \x03(\tR\x10ekcertAllowedCas\x1a\x82\x01\n" +
"\x04Rule\x12 \n" +
"\vdescription\x18\x01 \x01(\tR\vdescription\x12$\n" +
"\x0eek_public_hash\x18\x02 \x01(\tR\fekPublicHash\x122\n" +
"\x15ek_certificate_serial\x18\x03 \x01(\tR\x13ekCertificateSerialBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 39)
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 41)
var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
(*ScopedToken)(nil), // 0: teleport.scopes.joining.v1.ScopedToken
(*ScopedTokenSpec)(nil), // 1: teleport.scopes.joining.v1.ScopedTokenSpec
@@ -5442,31 +5676,33 @@ var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
(*GenericOIDC)(nil), // 17: teleport.scopes.joining.v1.GenericOIDC
(*Github)(nil), // 18: teleport.scopes.joining.v1.Github
(*GitLab)(nil), // 19: teleport.scopes.joining.v1.GitLab
nil, // 20: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
(*AWS_Rule)(nil), // 21: teleport.scopes.joining.v1.AWS.Rule
(*GCP_Rule)(nil), // 22: teleport.scopes.joining.v1.GCP.Rule
(*Azure_Rule)(nil), // 23: teleport.scopes.joining.v1.Azure.Rule
(*AzureDevops_Rule)(nil), // 24: teleport.scopes.joining.v1.AzureDevops.Rule
(*Oracle_Rule)(nil), // 25: teleport.scopes.joining.v1.Oracle.Rule
(*Kubernetes_StaticJWKSConfig)(nil), // 26: teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
(*Kubernetes_OIDCConfig)(nil), // 27: teleport.scopes.joining.v1.Kubernetes.OIDCConfig
(*Kubernetes_Rule)(nil), // 28: teleport.scopes.joining.v1.Kubernetes.Rule
(*BoundKeypairSpec_OnboardingSpec)(nil), // 29: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
(*BoundKeypairSpec_RecoverySpec)(nil), // 30: teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
(*GenericOIDC_ConditionEq)(nil), // 31: teleport.scopes.joining.v1.GenericOIDC.ConditionEq
(*GenericOIDC_ConditionNotEq)(nil), // 32: teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
(*GenericOIDC_ConditionIn)(nil), // 33: teleport.scopes.joining.v1.GenericOIDC.ConditionIn
(*GenericOIDC_ConditionNotIn)(nil), // 34: teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
(*GenericOIDC_Condition)(nil), // 35: teleport.scopes.joining.v1.GenericOIDC.Condition
(*GenericOIDC_Rule)(nil), // 36: teleport.scopes.joining.v1.GenericOIDC.Rule
(*Github_Rule)(nil), // 37: teleport.scopes.joining.v1.Github.Rule
(*GitLab_Rule)(nil), // 38: teleport.scopes.joining.v1.GitLab.Rule
(*v1.Metadata)(nil), // 39: teleport.header.v1.Metadata
(*timestamppb.Timestamp)(nil), // 40: google.protobuf.Timestamp
(*structpb.Struct)(nil), // 41: google.protobuf.Struct
(*TPM)(nil), // 20: teleport.scopes.joining.v1.TPM
nil, // 21: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
(*AWS_Rule)(nil), // 22: teleport.scopes.joining.v1.AWS.Rule
(*GCP_Rule)(nil), // 23: teleport.scopes.joining.v1.GCP.Rule
(*Azure_Rule)(nil), // 24: teleport.scopes.joining.v1.Azure.Rule
(*AzureDevops_Rule)(nil), // 25: teleport.scopes.joining.v1.AzureDevops.Rule
(*Oracle_Rule)(nil), // 26: teleport.scopes.joining.v1.Oracle.Rule
(*Kubernetes_StaticJWKSConfig)(nil), // 27: teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
(*Kubernetes_OIDCConfig)(nil), // 28: teleport.scopes.joining.v1.Kubernetes.OIDCConfig
(*Kubernetes_Rule)(nil), // 29: teleport.scopes.joining.v1.Kubernetes.Rule
(*BoundKeypairSpec_OnboardingSpec)(nil), // 30: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
(*BoundKeypairSpec_RecoverySpec)(nil), // 31: teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
(*GenericOIDC_ConditionEq)(nil), // 32: teleport.scopes.joining.v1.GenericOIDC.ConditionEq
(*GenericOIDC_ConditionNotEq)(nil), // 33: teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
(*GenericOIDC_ConditionIn)(nil), // 34: teleport.scopes.joining.v1.GenericOIDC.ConditionIn
(*GenericOIDC_ConditionNotIn)(nil), // 35: teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
(*GenericOIDC_Condition)(nil), // 36: teleport.scopes.joining.v1.GenericOIDC.Condition
(*GenericOIDC_Rule)(nil), // 37: teleport.scopes.joining.v1.GenericOIDC.Rule
(*Github_Rule)(nil), // 38: teleport.scopes.joining.v1.Github.Rule
(*GitLab_Rule)(nil), // 39: teleport.scopes.joining.v1.GitLab.Rule
(*TPM_Rule)(nil), // 40: teleport.scopes.joining.v1.TPM.Rule
(*v1.Metadata)(nil), // 41: teleport.header.v1.Metadata
(*timestamppb.Timestamp)(nil), // 42: google.protobuf.Timestamp
(*structpb.Struct)(nil), // 43: google.protobuf.Struct
}
var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
39, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
41, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
1, // 1: teleport.scopes.joining.v1.ScopedToken.spec:type_name -> teleport.scopes.joining.v1.ScopedTokenSpec
5, // 2: teleport.scopes.joining.v1.ScopedToken.status:type_name -> teleport.scopes.joining.v1.ScopedTokenStatus
6, // 3: teleport.scopes.joining.v1.ScopedTokenSpec.immutable_labels:type_name -> teleport.scopes.joining.v1.ImmutableLabels
@@ -5480,44 +5716,46 @@ var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
17, // 11: teleport.scopes.joining.v1.ScopedTokenSpec.generic_oidc:type_name -> teleport.scopes.joining.v1.GenericOIDC
18, // 12: teleport.scopes.joining.v1.ScopedTokenSpec.github:type_name -> teleport.scopes.joining.v1.Github
19, // 13: teleport.scopes.joining.v1.ScopedTokenSpec.gitlab:type_name -> teleport.scopes.joining.v1.GitLab
40, // 14: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
40, // 15: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
2, // 16: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
3, // 17: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
16, // 18: teleport.scopes.joining.v1.UsageStatus.bound_keypair:type_name -> teleport.scopes.joining.v1.BoundKeypairStatus
4, // 19: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
20, // 20: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
39, // 21: teleport.scopes.joining.v1.StaticScopedTokens.metadata:type_name -> teleport.header.v1.Metadata
8, // 22: teleport.scopes.joining.v1.StaticScopedTokens.spec:type_name -> teleport.scopes.joining.v1.StaticScopedTokensSpec
0, // 23: teleport.scopes.joining.v1.StaticScopedTokensSpec.tokens:type_name -> teleport.scopes.joining.v1.ScopedToken
21, // 24: teleport.scopes.joining.v1.AWS.allow:type_name -> teleport.scopes.joining.v1.AWS.Rule
22, // 25: teleport.scopes.joining.v1.GCP.allow:type_name -> teleport.scopes.joining.v1.GCP.Rule
23, // 26: teleport.scopes.joining.v1.Azure.allow:type_name -> teleport.scopes.joining.v1.Azure.Rule
24, // 27: teleport.scopes.joining.v1.AzureDevops.allow:type_name -> teleport.scopes.joining.v1.AzureDevops.Rule
25, // 28: teleport.scopes.joining.v1.Oracle.allow:type_name -> teleport.scopes.joining.v1.Oracle.Rule
28, // 29: teleport.scopes.joining.v1.Kubernetes.allow:type_name -> teleport.scopes.joining.v1.Kubernetes.Rule
26, // 30: teleport.scopes.joining.v1.Kubernetes.static_jwks:type_name -> teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
27, // 31: teleport.scopes.joining.v1.Kubernetes.oidc:type_name -> teleport.scopes.joining.v1.Kubernetes.OIDCConfig
29, // 32: teleport.scopes.joining.v1.BoundKeypairSpec.onboarding:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
30, // 33: teleport.scopes.joining.v1.BoundKeypairSpec.recovery:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
40, // 34: teleport.scopes.joining.v1.BoundKeypairSpec.rotate_after:type_name -> google.protobuf.Timestamp
40, // 35: teleport.scopes.joining.v1.BoundKeypairStatus.last_recovered_at:type_name -> google.protobuf.Timestamp
40, // 36: teleport.scopes.joining.v1.BoundKeypairStatus.last_rotated_at:type_name -> google.protobuf.Timestamp
41, // 37: teleport.scopes.joining.v1.GenericOIDC.must_match_fields:type_name -> google.protobuf.Struct
36, // 38: teleport.scopes.joining.v1.GenericOIDC.allow_any:type_name -> teleport.scopes.joining.v1.GenericOIDC.Rule
37, // 39: teleport.scopes.joining.v1.Github.allow:type_name -> teleport.scopes.joining.v1.Github.Rule
38, // 40: teleport.scopes.joining.v1.GitLab.allow:type_name -> teleport.scopes.joining.v1.GitLab.Rule
40, // 41: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec.must_register_before:type_name -> google.protobuf.Timestamp
31, // 42: teleport.scopes.joining.v1.GenericOIDC.Condition.eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionEq
32, // 43: teleport.scopes.joining.v1.GenericOIDC.Condition.not_eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
33, // 44: teleport.scopes.joining.v1.GenericOIDC.Condition.in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionIn
34, // 45: teleport.scopes.joining.v1.GenericOIDC.Condition.not_in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
35, // 46: teleport.scopes.joining.v1.GenericOIDC.Rule.conditions:type_name -> teleport.scopes.joining.v1.GenericOIDC.Condition
47, // [47:47] is the sub-list for method output_type
47, // [47:47] is the sub-list for method input_type
47, // [47:47] is the sub-list for extension type_name
47, // [47:47] is the sub-list for extension extendee
0, // [0:47] is the sub-list for field type_name
20, // 14: teleport.scopes.joining.v1.ScopedTokenSpec.tpm:type_name -> teleport.scopes.joining.v1.TPM
42, // 15: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
42, // 16: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
2, // 17: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
3, // 18: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
16, // 19: teleport.scopes.joining.v1.UsageStatus.bound_keypair:type_name -> teleport.scopes.joining.v1.BoundKeypairStatus
4, // 20: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
21, // 21: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
41, // 22: teleport.scopes.joining.v1.StaticScopedTokens.metadata:type_name -> teleport.header.v1.Metadata
8, // 23: teleport.scopes.joining.v1.StaticScopedTokens.spec:type_name -> teleport.scopes.joining.v1.StaticScopedTokensSpec
0, // 24: teleport.scopes.joining.v1.StaticScopedTokensSpec.tokens:type_name -> teleport.scopes.joining.v1.ScopedToken
22, // 25: teleport.scopes.joining.v1.AWS.allow:type_name -> teleport.scopes.joining.v1.AWS.Rule
23, // 26: teleport.scopes.joining.v1.GCP.allow:type_name -> teleport.scopes.joining.v1.GCP.Rule
24, // 27: teleport.scopes.joining.v1.Azure.allow:type_name -> teleport.scopes.joining.v1.Azure.Rule
25, // 28: teleport.scopes.joining.v1.AzureDevops.allow:type_name -> teleport.scopes.joining.v1.AzureDevops.Rule
26, // 29: teleport.scopes.joining.v1.Oracle.allow:type_name -> teleport.scopes.joining.v1.Oracle.Rule
29, // 30: teleport.scopes.joining.v1.Kubernetes.allow:type_name -> teleport.scopes.joining.v1.Kubernetes.Rule
27, // 31: teleport.scopes.joining.v1.Kubernetes.static_jwks:type_name -> teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
28, // 32: teleport.scopes.joining.v1.Kubernetes.oidc:type_name -> teleport.scopes.joining.v1.Kubernetes.OIDCConfig
30, // 33: teleport.scopes.joining.v1.BoundKeypairSpec.onboarding:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
31, // 34: teleport.scopes.joining.v1.BoundKeypairSpec.recovery:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
42, // 35: teleport.scopes.joining.v1.BoundKeypairSpec.rotate_after:type_name -> google.protobuf.Timestamp
42, // 36: teleport.scopes.joining.v1.BoundKeypairStatus.last_recovered_at:type_name -> google.protobuf.Timestamp
42, // 37: teleport.scopes.joining.v1.BoundKeypairStatus.last_rotated_at:type_name -> google.protobuf.Timestamp
43, // 38: teleport.scopes.joining.v1.GenericOIDC.must_match_fields:type_name -> google.protobuf.Struct
37, // 39: teleport.scopes.joining.v1.GenericOIDC.allow_any:type_name -> teleport.scopes.joining.v1.GenericOIDC.Rule
38, // 40: teleport.scopes.joining.v1.Github.allow:type_name -> teleport.scopes.joining.v1.Github.Rule
39, // 41: teleport.scopes.joining.v1.GitLab.allow:type_name -> teleport.scopes.joining.v1.GitLab.Rule
40, // 42: teleport.scopes.joining.v1.TPM.allow:type_name -> teleport.scopes.joining.v1.TPM.Rule
42, // 43: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec.must_register_before:type_name -> google.protobuf.Timestamp
32, // 44: teleport.scopes.joining.v1.GenericOIDC.Condition.eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionEq
33, // 45: teleport.scopes.joining.v1.GenericOIDC.Condition.not_eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
34, // 46: teleport.scopes.joining.v1.GenericOIDC.Condition.in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionIn
35, // 47: teleport.scopes.joining.v1.GenericOIDC.Condition.not_in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
36, // 48: teleport.scopes.joining.v1.GenericOIDC.Rule.conditions:type_name -> teleport.scopes.joining.v1.GenericOIDC.Condition
49, // [49:49] is the sub-list for method output_type
49, // [49:49] is the sub-list for method input_type
49, // [49:49] is the sub-list for extension type_name
49, // [49:49] is the sub-list for extension extendee
0, // [0:49] is the sub-list for field type_name
}
func init() { file_teleport_scopes_joining_v1_token_proto_init() }
@@ -5529,14 +5767,14 @@ func file_teleport_scopes_joining_v1_token_proto_init() {
(*UsageStatus_SingleUse)(nil),
(*UsageStatus_BoundKeypair)(nil),
}
file_teleport_scopes_joining_v1_token_proto_msgTypes[38].OneofWrappers = []any{}
file_teleport_scopes_joining_v1_token_proto_msgTypes[39].OneofWrappers = []any{}
type x struct{}
out := protoimpl.TypeBuilder{
File: protoimpl.DescBuilder{
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
RawDescriptor: unsafe.Slice(unsafe.StringData(file_teleport_scopes_joining_v1_token_proto_rawDesc), len(file_teleport_scopes_joining_v1_token_proto_rawDesc)),
NumEnums: 0,
NumMessages: 39,
NumMessages: 41,
NumExtensions: 0,
NumServices: 0,
},
@@ -243,6 +243,7 @@ type ScopedTokenSpec struct {
xxx_hidden_GenericOidc *GenericOIDC `protobuf:"bytes,16,opt,name=generic_oidc,json=genericOidc,proto3"`
xxx_hidden_Github *Github `protobuf:"bytes,17,opt,name=github,proto3"`
xxx_hidden_Gitlab *GitLab `protobuf:"bytes,18,opt,name=gitlab,proto3"`
xxx_hidden_Tpm *TPM `protobuf:"bytes,19,opt,name=tpm,proto3"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
@@ -384,6 +385,13 @@ func (x *ScopedTokenSpec) GetGitlab() *GitLab {
return nil
}
func (x *ScopedTokenSpec) GetTpm() *TPM {
if x != nil {
return x.xxx_hidden_Tpm
}
return nil
}
func (x *ScopedTokenSpec) SetAssignedScope(v string) {
x.xxx_hidden_AssignedScope = v
}
@@ -448,6 +456,10 @@ func (x *ScopedTokenSpec) SetGitlab(v *GitLab) {
x.xxx_hidden_Gitlab = v
}
func (x *ScopedTokenSpec) SetTpm(v *TPM) {
x.xxx_hidden_Tpm = v
}
func (x *ScopedTokenSpec) HasImmutableLabels() bool {
if x == nil {
return false
@@ -525,6 +537,13 @@ func (x *ScopedTokenSpec) HasGitlab() bool {
return x.xxx_hidden_Gitlab != nil
}
func (x *ScopedTokenSpec) HasTpm() bool {
if x == nil {
return false
}
return x.xxx_hidden_Tpm != nil
}
func (x *ScopedTokenSpec) ClearImmutableLabels() {
x.xxx_hidden_ImmutableLabels = nil
}
@@ -569,6 +588,10 @@ func (x *ScopedTokenSpec) ClearGitlab() {
x.xxx_hidden_Gitlab = nil
}
func (x *ScopedTokenSpec) ClearTpm() {
x.xxx_hidden_Tpm = nil
}
type ScopedTokenSpec_builder struct {
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
@@ -617,6 +640,8 @@ type ScopedTokenSpec_builder struct {
Github *Github
// Configuration specific to the "gitlab" join method.
Gitlab *GitLab
// Configuration specific to the "tpm" join method.
Tpm *TPM
}
func (b0 ScopedTokenSpec_builder) Build() *ScopedTokenSpec {
@@ -639,6 +664,7 @@ func (b0 ScopedTokenSpec_builder) Build() *ScopedTokenSpec {
x.xxx_hidden_GenericOidc = b.GenericOidc
x.xxx_hidden_Github = b.Github
x.xxx_hidden_Gitlab = b.Gitlab
x.xxx_hidden_Tpm = b.Tpm
return m0
}
@@ -2695,6 +2721,88 @@ func (b0 GitLab_builder) Build() *GitLab {
return m0
}
// Configuration specific to TPM tokens.
type TPM struct {
state protoimpl.MessageState `protogen:"opaque.v1"`
xxx_hidden_Allow *[]*TPM_Rule `protobuf:"bytes,1,rep,name=allow,proto3"`
xxx_hidden_EkcertAllowedCas []string `protobuf:"bytes,2,rep,name=ekcert_allowed_cas,json=ekcertAllowedCas,proto3"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *TPM) Reset() {
*x = TPM{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[20]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *TPM) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*TPM) ProtoMessage() {}
func (x *TPM) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[20]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
func (x *TPM) GetAllow() []*TPM_Rule {
if x != nil {
if x.xxx_hidden_Allow != nil {
return *x.xxx_hidden_Allow
}
}
return nil
}
func (x *TPM) GetEkcertAllowedCas() []string {
if x != nil {
return x.xxx_hidden_EkcertAllowedCas
}
return nil
}
func (x *TPM) SetAllow(v []*TPM_Rule) {
x.xxx_hidden_Allow = &v
}
func (x *TPM) SetEkcertAllowedCas(v []string) {
x.xxx_hidden_EkcertAllowedCas = v
}
type TPM_builder struct {
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
// A list of Rules, the presented delegated identity must match one allow rule
// to permit joining.
Allow []*TPM_Rule
// A list of CA certificates that will be used to validate TPM EKCerts.
// When specified, joining TPMs must present an EKCert signed by one of the
// specified CAs. TPMs that do not present an EKCert will be not permitted to
// join.
// When unspecified, TPMs will be allowed to join with either an EKCert or an
// EKPubHash.
EkcertAllowedCas []string
}
func (b0 TPM_builder) Build() *TPM {
m0 := &TPM{}
b, x := &b0, m0
_, _ = b, x
x.xxx_hidden_Allow = &b.Allow
x.xxx_hidden_EkcertAllowedCas = b.EkcertAllowedCas
return m0
}
// A rule that a joining node must match in order to use the associated token
// with AWS join methods.
type AWS_Rule struct {
@@ -2710,7 +2818,7 @@ type AWS_Rule struct {
func (x *AWS_Rule) Reset() {
*x = AWS_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[21]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -2722,7 +2830,7 @@ func (x *AWS_Rule) String() string {
func (*AWS_Rule) ProtoMessage() {}
func (x *AWS_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[21]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -2832,7 +2940,7 @@ type GCP_Rule struct {
func (x *GCP_Rule) Reset() {
*x = GCP_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -2844,7 +2952,7 @@ func (x *GCP_Rule) String() string {
func (*GCP_Rule) ProtoMessage() {}
func (x *GCP_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -2922,7 +3030,7 @@ type Azure_Rule struct {
func (x *Azure_Rule) Reset() {
*x = Azure_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -2934,7 +3042,7 @@ func (x *Azure_Rule) String() string {
func (*Azure_Rule) ProtoMessage() {}
func (x *Azure_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3017,7 +3125,7 @@ type AzureDevops_Rule struct {
func (x *AzureDevops_Rule) Reset() {
*x = AzureDevops_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3029,7 +3137,7 @@ func (x *AzureDevops_Rule) String() string {
func (*AzureDevops_Rule) ProtoMessage() {}
func (x *AzureDevops_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3194,7 +3302,7 @@ type Oracle_Rule struct {
func (x *Oracle_Rule) Reset() {
*x = Oracle_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3206,7 +3314,7 @@ func (x *Oracle_Rule) String() string {
func (*Oracle_Rule) ProtoMessage() {}
func (x *Oracle_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3298,7 +3406,7 @@ type Kubernetes_StaticJWKSConfig struct {
func (x *Kubernetes_StaticJWKSConfig) Reset() {
*x = Kubernetes_StaticJWKSConfig{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3310,7 +3418,7 @@ func (x *Kubernetes_StaticJWKSConfig) String() string {
func (*Kubernetes_StaticJWKSConfig) ProtoMessage() {}
func (x *Kubernetes_StaticJWKSConfig) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3359,7 +3467,7 @@ type Kubernetes_OIDCConfig struct {
func (x *Kubernetes_OIDCConfig) Reset() {
*x = Kubernetes_OIDCConfig{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3371,7 +3479,7 @@ func (x *Kubernetes_OIDCConfig) String() string {
func (*Kubernetes_OIDCConfig) ProtoMessage() {}
func (x *Kubernetes_OIDCConfig) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3440,7 +3548,7 @@ type Kubernetes_Rule struct {
func (x *Kubernetes_Rule) Reset() {
*x = Kubernetes_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3452,7 +3560,7 @@ func (x *Kubernetes_Rule) String() string {
func (*Kubernetes_Rule) ProtoMessage() {}
func (x *Kubernetes_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3537,7 +3645,7 @@ type BoundKeypairSpec_OnboardingSpec struct {
func (x *BoundKeypairSpec_OnboardingSpec) Reset() {
*x = BoundKeypairSpec_OnboardingSpec{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3549,7 +3657,7 @@ func (x *BoundKeypairSpec_OnboardingSpec) String() string {
func (*BoundKeypairSpec_OnboardingSpec) ProtoMessage() {}
func (x *BoundKeypairSpec_OnboardingSpec) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3651,7 +3759,7 @@ type BoundKeypairSpec_RecoverySpec struct {
func (x *BoundKeypairSpec_RecoverySpec) Reset() {
*x = BoundKeypairSpec_RecoverySpec{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3663,7 +3771,7 @@ func (x *BoundKeypairSpec_RecoverySpec) String() string {
func (*BoundKeypairSpec_RecoverySpec) ProtoMessage() {}
func (x *BoundKeypairSpec_RecoverySpec) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3743,7 +3851,7 @@ type GenericOIDC_ConditionEq struct {
func (x *GenericOIDC_ConditionEq) Reset() {
*x = GenericOIDC_ConditionEq{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3755,7 +3863,7 @@ func (x *GenericOIDC_ConditionEq) String() string {
func (*GenericOIDC_ConditionEq) ProtoMessage() {}
func (x *GenericOIDC_ConditionEq) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3802,7 +3910,7 @@ type GenericOIDC_ConditionNotEq struct {
func (x *GenericOIDC_ConditionNotEq) Reset() {
*x = GenericOIDC_ConditionNotEq{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3814,7 +3922,7 @@ func (x *GenericOIDC_ConditionNotEq) String() string {
func (*GenericOIDC_ConditionNotEq) ProtoMessage() {}
func (x *GenericOIDC_ConditionNotEq) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3861,7 +3969,7 @@ type GenericOIDC_ConditionIn struct {
func (x *GenericOIDC_ConditionIn) Reset() {
*x = GenericOIDC_ConditionIn{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3873,7 +3981,7 @@ func (x *GenericOIDC_ConditionIn) String() string {
func (*GenericOIDC_ConditionIn) ProtoMessage() {}
func (x *GenericOIDC_ConditionIn) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3920,7 +4028,7 @@ type GenericOIDC_ConditionNotIn struct {
func (x *GenericOIDC_ConditionNotIn) Reset() {
*x = GenericOIDC_ConditionNotIn{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3932,7 +4040,7 @@ func (x *GenericOIDC_ConditionNotIn) String() string {
func (*GenericOIDC_ConditionNotIn) ProtoMessage() {}
func (x *GenericOIDC_ConditionNotIn) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -3983,7 +4091,7 @@ type GenericOIDC_Condition struct {
func (x *GenericOIDC_Condition) Reset() {
*x = GenericOIDC_Condition{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -3995,7 +4103,7 @@ func (x *GenericOIDC_Condition) String() string {
func (*GenericOIDC_Condition) ProtoMessage() {}
func (x *GenericOIDC_Condition) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4145,7 +4253,7 @@ type GenericOIDC_Rule struct {
func (x *GenericOIDC_Rule) Reset() {
*x = GenericOIDC_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4157,7 +4265,7 @@ func (x *GenericOIDC_Rule) String() string {
func (*GenericOIDC_Rule) ProtoMessage() {}
func (x *GenericOIDC_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4235,7 +4343,7 @@ type Github_Rule struct {
func (x *Github_Rule) Reset() {
*x = Github_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4247,7 +4355,7 @@ func (x *Github_Rule) String() string {
func (*Github_Rule) ProtoMessage() {}
func (x *Github_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4470,7 +4578,7 @@ type GitLab_Rule struct {
func (x *GitLab_Rule) Reset() {
*x = GitLab_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[39]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -4482,7 +4590,7 @@ func (x *GitLab_Rule) String() string {
func (*GitLab_Rule) ProtoMessage() {}
func (x *GitLab_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[39]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -4792,6 +4900,105 @@ func (b0 GitLab_Rule_builder) Build() *GitLab_Rule {
return m0
}
// A rule for TPM joining tokens, of which one must match for a join attempt
// to be allowed.
type TPM_Rule struct {
state protoimpl.MessageState `protogen:"opaque.v1"`
xxx_hidden_Description string `protobuf:"bytes,1,opt,name=description,proto3"`
xxx_hidden_EkPublicHash string `protobuf:"bytes,2,opt,name=ek_public_hash,json=ekPublicHash,proto3"`
xxx_hidden_EkCertificateSerial string `protobuf:"bytes,3,opt,name=ek_certificate_serial,json=ekCertificateSerial,proto3"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *TPM_Rule) Reset() {
*x = TPM_Rule{}
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[40]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *TPM_Rule) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*TPM_Rule) ProtoMessage() {}
func (x *TPM_Rule) ProtoReflect() protoreflect.Message {
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[40]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
func (x *TPM_Rule) GetDescription() string {
if x != nil {
return x.xxx_hidden_Description
}
return ""
}
func (x *TPM_Rule) GetEkPublicHash() string {
if x != nil {
return x.xxx_hidden_EkPublicHash
}
return ""
}
func (x *TPM_Rule) GetEkCertificateSerial() string {
if x != nil {
return x.xxx_hidden_EkCertificateSerial
}
return ""
}
func (x *TPM_Rule) SetDescription(v string) {
x.xxx_hidden_Description = v
}
func (x *TPM_Rule) SetEkPublicHash(v string) {
x.xxx_hidden_EkPublicHash = v
}
func (x *TPM_Rule) SetEkCertificateSerial(v string) {
x.xxx_hidden_EkCertificateSerial = v
}
type TPM_Rule_builder struct {
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
// A human-readable description of the rule. It has no bearing on whether or
// not a TPM is allowed to join, but can be used to associate a rule with a
// specific host (e.g the asset tag of the server in which the TPM resides).
// Example: "build-server-100"
Description string
// The SHA256 hash of the EKPub marshaled in PKIX format and encoded in
// hexadecimal. This value will also be checked when a TPM has submitted an
// EKCert, and the public key in the EKCert will be used for this check.
// Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
EkPublicHash string
// The serial number of the EKCert in hexadecimal with colon separated
// nibbles. This value will not be checked when a TPM does not have an
// EKCert configured.
// Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
EkCertificateSerial string
}
func (b0 TPM_Rule_builder) Build() *TPM_Rule {
m0 := &TPM_Rule{}
b, x := &b0, m0
_, _ = b, x
x.xxx_hidden_Description = b.Description
x.xxx_hidden_EkPublicHash = b.EkPublicHash
x.xxx_hidden_EkCertificateSerial = b.EkCertificateSerial
return m0
}
var File_teleport_scopes_joining_v1_token_proto protoreflect.FileDescriptor
const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
@@ -4804,7 +5011,7 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
"\bmetadata\x18\x04 \x01(\v2\x1c.teleport.header.v1.MetadataR\bmetadata\x12\x14\n" +
"\x05scope\x18\x05 \x01(\tR\x05scope\x12?\n" +
"\x04spec\x18\x06 \x01(\v2+.teleport.scopes.joining.v1.ScopedTokenSpecR\x04spec\x12E\n" +
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\x9f\a\n" +
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\xd2\a\n" +
"\x0fScopedTokenSpec\x12%\n" +
"\x0eassigned_scope\x18\x01 \x01(\tR\rassignedScope\x12\x14\n" +
"\x05roles\x18\x02 \x03(\tR\x05roles\x12\x1f\n" +
@@ -4826,7 +5033,8 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
"\x03bot\x18\x0f \x01(\tR\x03bot\x12J\n" +
"\fgeneric_oidc\x18\x10 \x01(\v2'.teleport.scopes.joining.v1.GenericOIDCR\vgenericOidc\x12:\n" +
"\x06github\x18\x11 \x01(\v2\".teleport.scopes.joining.v1.GithubR\x06github\x12:\n" +
"\x06gitlab\x18\x12 \x01(\v2\".teleport.scopes.joining.v1.GitLabR\x06gitlabJ\x04\b\r\x10\x0eJ\x04\b\x0e\x10\x0fR\bbot_nameR\tbot_scope\"\xb6\x01\n" +
"\x06gitlab\x18\x12 \x01(\v2\".teleport.scopes.joining.v1.GitLabR\x06gitlab\x121\n" +
"\x03tpm\x18\x13 \x01(\v2\x1f.teleport.scopes.joining.v1.TPMR\x03tpmJ\x04\b\r\x10\x0eJ\x04\b\x0e\x10\x0fR\bbot_nameR\tbot_scope\"\xb6\x01\n" +
"\x0eHostCertParams\x12\x17\n" +
"\ahost_id\x18\x01 \x01(\tR\x06hostId\x12\x1b\n" +
"\tnode_name\x18\x02 \x01(\tR\bnodeName\x12\x12\n" +
@@ -5021,9 +5229,16 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
"\x0fdeployment_tier\x18\x0f \x01(\tR\x0edeploymentTier\x12-\n" +
"\x12project_visibility\x18\x10 \x01(\tR\x11projectVisibilityB\x10\n" +
"\x0e_ref_protectedB\x18\n" +
"\x16_environment_protectedBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
"\x16_environment_protected\"\xf4\x01\n" +
"\x03TPM\x12:\n" +
"\x05allow\x18\x01 \x03(\v2$.teleport.scopes.joining.v1.TPM.RuleR\x05allow\x12,\n" +
"\x12ekcert_allowed_cas\x18\x02 \x03(\tR\x10ekcertAllowedCas\x1a\x82\x01\n" +
"\x04Rule\x12 \n" +
"\vdescription\x18\x01 \x01(\tR\vdescription\x12$\n" +
"\x0eek_public_hash\x18\x02 \x01(\tR\fekPublicHash\x122\n" +
"\x15ek_certificate_serial\x18\x03 \x01(\tR\x13ekCertificateSerialBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 39)
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 41)
var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
(*ScopedToken)(nil), // 0: teleport.scopes.joining.v1.ScopedToken
(*ScopedTokenSpec)(nil), // 1: teleport.scopes.joining.v1.ScopedTokenSpec
@@ -5045,31 +5260,33 @@ var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
(*GenericOIDC)(nil), // 17: teleport.scopes.joining.v1.GenericOIDC
(*Github)(nil), // 18: teleport.scopes.joining.v1.Github
(*GitLab)(nil), // 19: teleport.scopes.joining.v1.GitLab
nil, // 20: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
(*AWS_Rule)(nil), // 21: teleport.scopes.joining.v1.AWS.Rule
(*GCP_Rule)(nil), // 22: teleport.scopes.joining.v1.GCP.Rule
(*Azure_Rule)(nil), // 23: teleport.scopes.joining.v1.Azure.Rule
(*AzureDevops_Rule)(nil), // 24: teleport.scopes.joining.v1.AzureDevops.Rule
(*Oracle_Rule)(nil), // 25: teleport.scopes.joining.v1.Oracle.Rule
(*Kubernetes_StaticJWKSConfig)(nil), // 26: teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
(*Kubernetes_OIDCConfig)(nil), // 27: teleport.scopes.joining.v1.Kubernetes.OIDCConfig
(*Kubernetes_Rule)(nil), // 28: teleport.scopes.joining.v1.Kubernetes.Rule
(*BoundKeypairSpec_OnboardingSpec)(nil), // 29: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
(*BoundKeypairSpec_RecoverySpec)(nil), // 30: teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
(*GenericOIDC_ConditionEq)(nil), // 31: teleport.scopes.joining.v1.GenericOIDC.ConditionEq
(*GenericOIDC_ConditionNotEq)(nil), // 32: teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
(*GenericOIDC_ConditionIn)(nil), // 33: teleport.scopes.joining.v1.GenericOIDC.ConditionIn
(*GenericOIDC_ConditionNotIn)(nil), // 34: teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
(*GenericOIDC_Condition)(nil), // 35: teleport.scopes.joining.v1.GenericOIDC.Condition
(*GenericOIDC_Rule)(nil), // 36: teleport.scopes.joining.v1.GenericOIDC.Rule
(*Github_Rule)(nil), // 37: teleport.scopes.joining.v1.Github.Rule
(*GitLab_Rule)(nil), // 38: teleport.scopes.joining.v1.GitLab.Rule
(*v1.Metadata)(nil), // 39: teleport.header.v1.Metadata
(*timestamppb.Timestamp)(nil), // 40: google.protobuf.Timestamp
(*structpb.Struct)(nil), // 41: google.protobuf.Struct
(*TPM)(nil), // 20: teleport.scopes.joining.v1.TPM
nil, // 21: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
(*AWS_Rule)(nil), // 22: teleport.scopes.joining.v1.AWS.Rule
(*GCP_Rule)(nil), // 23: teleport.scopes.joining.v1.GCP.Rule
(*Azure_Rule)(nil), // 24: teleport.scopes.joining.v1.Azure.Rule
(*AzureDevops_Rule)(nil), // 25: teleport.scopes.joining.v1.AzureDevops.Rule
(*Oracle_Rule)(nil), // 26: teleport.scopes.joining.v1.Oracle.Rule
(*Kubernetes_StaticJWKSConfig)(nil), // 27: teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
(*Kubernetes_OIDCConfig)(nil), // 28: teleport.scopes.joining.v1.Kubernetes.OIDCConfig
(*Kubernetes_Rule)(nil), // 29: teleport.scopes.joining.v1.Kubernetes.Rule
(*BoundKeypairSpec_OnboardingSpec)(nil), // 30: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
(*BoundKeypairSpec_RecoverySpec)(nil), // 31: teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
(*GenericOIDC_ConditionEq)(nil), // 32: teleport.scopes.joining.v1.GenericOIDC.ConditionEq
(*GenericOIDC_ConditionNotEq)(nil), // 33: teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
(*GenericOIDC_ConditionIn)(nil), // 34: teleport.scopes.joining.v1.GenericOIDC.ConditionIn
(*GenericOIDC_ConditionNotIn)(nil), // 35: teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
(*GenericOIDC_Condition)(nil), // 36: teleport.scopes.joining.v1.GenericOIDC.Condition
(*GenericOIDC_Rule)(nil), // 37: teleport.scopes.joining.v1.GenericOIDC.Rule
(*Github_Rule)(nil), // 38: teleport.scopes.joining.v1.Github.Rule
(*GitLab_Rule)(nil), // 39: teleport.scopes.joining.v1.GitLab.Rule
(*TPM_Rule)(nil), // 40: teleport.scopes.joining.v1.TPM.Rule
(*v1.Metadata)(nil), // 41: teleport.header.v1.Metadata
(*timestamppb.Timestamp)(nil), // 42: google.protobuf.Timestamp
(*structpb.Struct)(nil), // 43: google.protobuf.Struct
}
var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
39, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
41, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
1, // 1: teleport.scopes.joining.v1.ScopedToken.spec:type_name -> teleport.scopes.joining.v1.ScopedTokenSpec
5, // 2: teleport.scopes.joining.v1.ScopedToken.status:type_name -> teleport.scopes.joining.v1.ScopedTokenStatus
6, // 3: teleport.scopes.joining.v1.ScopedTokenSpec.immutable_labels:type_name -> teleport.scopes.joining.v1.ImmutableLabels
@@ -5083,44 +5300,46 @@ var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
17, // 11: teleport.scopes.joining.v1.ScopedTokenSpec.generic_oidc:type_name -> teleport.scopes.joining.v1.GenericOIDC
18, // 12: teleport.scopes.joining.v1.ScopedTokenSpec.github:type_name -> teleport.scopes.joining.v1.Github
19, // 13: teleport.scopes.joining.v1.ScopedTokenSpec.gitlab:type_name -> teleport.scopes.joining.v1.GitLab
40, // 14: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
40, // 15: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
2, // 16: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
3, // 17: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
16, // 18: teleport.scopes.joining.v1.UsageStatus.bound_keypair:type_name -> teleport.scopes.joining.v1.BoundKeypairStatus
4, // 19: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
20, // 20: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
39, // 21: teleport.scopes.joining.v1.StaticScopedTokens.metadata:type_name -> teleport.header.v1.Metadata
8, // 22: teleport.scopes.joining.v1.StaticScopedTokens.spec:type_name -> teleport.scopes.joining.v1.StaticScopedTokensSpec
0, // 23: teleport.scopes.joining.v1.StaticScopedTokensSpec.tokens:type_name -> teleport.scopes.joining.v1.ScopedToken
21, // 24: teleport.scopes.joining.v1.AWS.allow:type_name -> teleport.scopes.joining.v1.AWS.Rule
22, // 25: teleport.scopes.joining.v1.GCP.allow:type_name -> teleport.scopes.joining.v1.GCP.Rule
23, // 26: teleport.scopes.joining.v1.Azure.allow:type_name -> teleport.scopes.joining.v1.Azure.Rule
24, // 27: teleport.scopes.joining.v1.AzureDevops.allow:type_name -> teleport.scopes.joining.v1.AzureDevops.Rule
25, // 28: teleport.scopes.joining.v1.Oracle.allow:type_name -> teleport.scopes.joining.v1.Oracle.Rule
28, // 29: teleport.scopes.joining.v1.Kubernetes.allow:type_name -> teleport.scopes.joining.v1.Kubernetes.Rule
26, // 30: teleport.scopes.joining.v1.Kubernetes.static_jwks:type_name -> teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
27, // 31: teleport.scopes.joining.v1.Kubernetes.oidc:type_name -> teleport.scopes.joining.v1.Kubernetes.OIDCConfig
29, // 32: teleport.scopes.joining.v1.BoundKeypairSpec.onboarding:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
30, // 33: teleport.scopes.joining.v1.BoundKeypairSpec.recovery:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
40, // 34: teleport.scopes.joining.v1.BoundKeypairSpec.rotate_after:type_name -> google.protobuf.Timestamp
40, // 35: teleport.scopes.joining.v1.BoundKeypairStatus.last_recovered_at:type_name -> google.protobuf.Timestamp
40, // 36: teleport.scopes.joining.v1.BoundKeypairStatus.last_rotated_at:type_name -> google.protobuf.Timestamp
41, // 37: teleport.scopes.joining.v1.GenericOIDC.must_match_fields:type_name -> google.protobuf.Struct
36, // 38: teleport.scopes.joining.v1.GenericOIDC.allow_any:type_name -> teleport.scopes.joining.v1.GenericOIDC.Rule
37, // 39: teleport.scopes.joining.v1.Github.allow:type_name -> teleport.scopes.joining.v1.Github.Rule
38, // 40: teleport.scopes.joining.v1.GitLab.allow:type_name -> teleport.scopes.joining.v1.GitLab.Rule
40, // 41: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec.must_register_before:type_name -> google.protobuf.Timestamp
31, // 42: teleport.scopes.joining.v1.GenericOIDC.Condition.eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionEq
32, // 43: teleport.scopes.joining.v1.GenericOIDC.Condition.not_eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
33, // 44: teleport.scopes.joining.v1.GenericOIDC.Condition.in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionIn
34, // 45: teleport.scopes.joining.v1.GenericOIDC.Condition.not_in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
35, // 46: teleport.scopes.joining.v1.GenericOIDC.Rule.conditions:type_name -> teleport.scopes.joining.v1.GenericOIDC.Condition
47, // [47:47] is the sub-list for method output_type
47, // [47:47] is the sub-list for method input_type
47, // [47:47] is the sub-list for extension type_name
47, // [47:47] is the sub-list for extension extendee
0, // [0:47] is the sub-list for field type_name
20, // 14: teleport.scopes.joining.v1.ScopedTokenSpec.tpm:type_name -> teleport.scopes.joining.v1.TPM
42, // 15: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
42, // 16: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
2, // 17: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
3, // 18: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
16, // 19: teleport.scopes.joining.v1.UsageStatus.bound_keypair:type_name -> teleport.scopes.joining.v1.BoundKeypairStatus
4, // 20: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
21, // 21: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
41, // 22: teleport.scopes.joining.v1.StaticScopedTokens.metadata:type_name -> teleport.header.v1.Metadata
8, // 23: teleport.scopes.joining.v1.StaticScopedTokens.spec:type_name -> teleport.scopes.joining.v1.StaticScopedTokensSpec
0, // 24: teleport.scopes.joining.v1.StaticScopedTokensSpec.tokens:type_name -> teleport.scopes.joining.v1.ScopedToken
22, // 25: teleport.scopes.joining.v1.AWS.allow:type_name -> teleport.scopes.joining.v1.AWS.Rule
23, // 26: teleport.scopes.joining.v1.GCP.allow:type_name -> teleport.scopes.joining.v1.GCP.Rule
24, // 27: teleport.scopes.joining.v1.Azure.allow:type_name -> teleport.scopes.joining.v1.Azure.Rule
25, // 28: teleport.scopes.joining.v1.AzureDevops.allow:type_name -> teleport.scopes.joining.v1.AzureDevops.Rule
26, // 29: teleport.scopes.joining.v1.Oracle.allow:type_name -> teleport.scopes.joining.v1.Oracle.Rule
29, // 30: teleport.scopes.joining.v1.Kubernetes.allow:type_name -> teleport.scopes.joining.v1.Kubernetes.Rule
27, // 31: teleport.scopes.joining.v1.Kubernetes.static_jwks:type_name -> teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
28, // 32: teleport.scopes.joining.v1.Kubernetes.oidc:type_name -> teleport.scopes.joining.v1.Kubernetes.OIDCConfig
30, // 33: teleport.scopes.joining.v1.BoundKeypairSpec.onboarding:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
31, // 34: teleport.scopes.joining.v1.BoundKeypairSpec.recovery:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
42, // 35: teleport.scopes.joining.v1.BoundKeypairSpec.rotate_after:type_name -> google.protobuf.Timestamp
42, // 36: teleport.scopes.joining.v1.BoundKeypairStatus.last_recovered_at:type_name -> google.protobuf.Timestamp
42, // 37: teleport.scopes.joining.v1.BoundKeypairStatus.last_rotated_at:type_name -> google.protobuf.Timestamp
43, // 38: teleport.scopes.joining.v1.GenericOIDC.must_match_fields:type_name -> google.protobuf.Struct
37, // 39: teleport.scopes.joining.v1.GenericOIDC.allow_any:type_name -> teleport.scopes.joining.v1.GenericOIDC.Rule
38, // 40: teleport.scopes.joining.v1.Github.allow:type_name -> teleport.scopes.joining.v1.Github.Rule
39, // 41: teleport.scopes.joining.v1.GitLab.allow:type_name -> teleport.scopes.joining.v1.GitLab.Rule
40, // 42: teleport.scopes.joining.v1.TPM.allow:type_name -> teleport.scopes.joining.v1.TPM.Rule
42, // 43: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec.must_register_before:type_name -> google.protobuf.Timestamp
32, // 44: teleport.scopes.joining.v1.GenericOIDC.Condition.eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionEq
33, // 45: teleport.scopes.joining.v1.GenericOIDC.Condition.not_eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
34, // 46: teleport.scopes.joining.v1.GenericOIDC.Condition.in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionIn
35, // 47: teleport.scopes.joining.v1.GenericOIDC.Condition.not_in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
36, // 48: teleport.scopes.joining.v1.GenericOIDC.Rule.conditions:type_name -> teleport.scopes.joining.v1.GenericOIDC.Condition
49, // [49:49] is the sub-list for method output_type
49, // [49:49] is the sub-list for method input_type
49, // [49:49] is the sub-list for extension type_name
49, // [49:49] is the sub-list for extension extendee
0, // [0:49] is the sub-list for field type_name
}
func init() { file_teleport_scopes_joining_v1_token_proto_init() }
@@ -5132,14 +5351,14 @@ func file_teleport_scopes_joining_v1_token_proto_init() {
(*usageStatus_SingleUse)(nil),
(*usageStatus_BoundKeypair)(nil),
}
file_teleport_scopes_joining_v1_token_proto_msgTypes[38].OneofWrappers = []any{}
file_teleport_scopes_joining_v1_token_proto_msgTypes[39].OneofWrappers = []any{}
type x struct{}
out := protoimpl.TypeBuilder{
File: protoimpl.DescBuilder{
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
RawDescriptor: unsafe.Slice(unsafe.StringData(file_teleport_scopes_joining_v1_token_proto_rawDesc), len(file_teleport_scopes_joining_v1_token_proto_rawDesc)),
NumEnums: 0,
NumMessages: 39,
NumMessages: 41,
NumExtensions: 0,
NumServices: 0,
},
@@ -114,6 +114,9 @@ message ScopedTokenSpec {
// Configuration specific to the "gitlab" join method.
GitLab gitlab = 18;
// Configuration specific to the "tpm" join method.
TPM tpm = 19;
}
// The host certificate parameters that should be cached and leveraged for
@@ -844,3 +847,40 @@ message GitLab {
string project_visibility = 16;
}
}
// Configuration specific to TPM tokens.
message TPM {
// A rule for TPM joining tokens, of which one must match for a join attempt
// to be allowed.
message Rule {
// A human-readable description of the rule. It has no bearing on whether or
// not a TPM is allowed to join, but can be used to associate a rule with a
// specific host (e.g the asset tag of the server in which the TPM resides).
// Example: "build-server-100"
string description = 1;
// The SHA256 hash of the EKPub marshaled in PKIX format and encoded in
// hexadecimal. This value will also be checked when a TPM has submitted an
// EKCert, and the public key in the EKCert will be used for this check.
// Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
string ek_public_hash = 2;
// The serial number of the EKCert in hexadecimal with colon separated
// nibbles. This value will not be checked when a TPM does not have an
// EKCert configured.
// Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
string ek_certificate_serial = 3;
}
// A list of Rules, the presented delegated identity must match one allow rule
// to permit joining.
repeated Rule allow = 1;
// A list of CA certificates that will be used to validate TPM EKCerts.
// When specified, joining TPMs must present an EKCert signed by one of the
// specified CAs. TPMs that do not present an EKCert will be not permitted to
// join.
// When unspecified, TPMs will be allowed to join with either an EKCert or an
// EKPubHash.
repeated string ekcert_allowed_cas = 2;
}
+7
View File
@@ -182,6 +182,8 @@ type ProvisionToken interface {
GetGithub() *ProvisionTokenSpecV2GitHub
// GetGitLab returns gitlab-specific configuration for this token.
GetGitLab() *ProvisionTokenSpecV2GitLab
// GetTPM returns the TPM-specific configuration for this token.
GetTPM() *ProvisionTokenSpecV2TPM
// GetAWSIIDTTL returns the TTL of EC2 IIDs
GetAWSIIDTTL() Duration
// GetJoinMethod returns joining method that must be used with this token.
@@ -635,6 +637,11 @@ func (p *ProvisionTokenV2) GetGitLab() *ProvisionTokenSpecV2GitLab {
return p.Spec.GitLab
}
// GetTPM returns the TPM-specific configuration for this token.
func (p *ProvisionTokenV2) GetTPM() *ProvisionTokenSpecV2TPM {
return p.Spec.TPM
}
// GetJoinMethod returns joining method that must be used with this token.
func (p *ProvisionTokenV2) GetJoinMethod() JoinMethod {
return p.Spec.JoinMethod
@@ -46,6 +46,7 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|kubernetes|[object](#speckubernetes)|The Kubernetes-specific configuration used with the "kubernetes" join method.|
|oracle|[object](#specoracle)|The Oracle-specific configuration used with the "oracle" join method.|
|roles|[]string|The list of roles associated with the token. They will be converted to metadata in the SSH and X509 certificates issued to the user of the token.|
|tpm|[object](#spectpm)|Configuration specific to the "tpm" join method.|
|usage_mode|string|The usage mode of the token. Can be "single_use" or "unlimited". Single use tokens can only be used to provision a single resource. Unlimited tokens can be be used to provision any number of resources until it expires.|
### spec.aws
@@ -301,3 +302,18 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|regions|[]string||
|tenancy|string||
### spec.tpm
|Field|Type|Description|
|---|---|---|
|allow|[][object](#spectpmallow-items)|A list of Rules, the presented delegated identity must match one allow rule to permit joining.|
|ekcert_allowed_cas|[]string|A list of CA certificates that will be used to validate TPM EKCerts. When specified, joining TPMs must present an EKCert signed by one of the specified CAs. TPMs that do not present an EKCert will be not permitted to join. When unspecified, TPMs will be allowed to join with either an EKCert or an EKPubHash.|
### spec.tpm.allow items
|Field|Type|Description|
|---|---|---|
|description|string||
|ek_certificate_serial|string||
|ek_public_hash|string||
@@ -69,6 +69,7 @@ Optional:
- `immutable_labels` (Attributes) Immutable labels that should be applied to any resulting resources provisioned using this token. (see [below for nested schema](#nested-schema-for-specimmutable_labels))
- `kubernetes` (Attributes) The Kubernetes-specific configuration used with the "kubernetes" join method. (see [below for nested schema](#nested-schema-for-speckubernetes))
- `oracle` (Attributes) The Oracle-specific configuration used with the "oracle" join method. (see [below for nested schema](#nested-schema-for-specoracle))
- `tpm` (Attributes) Configuration specific to the "tpm" join method. (see [below for nested schema](#nested-schema-for-spectpm))
### Nested Schema for `spec.aws`
@@ -342,3 +343,20 @@ Optional:
- `regions` (List of String) A list of regions an instance is allowed to join from. Both full region names ("us-phoenix-1") and abbreviations ("phx") are allowed. If empty, any region is allowed.
- `tenancy` (String) The OCID of the instance's tenancy. Required.
### Nested Schema for `spec.tpm`
Optional:
- `allow` (Attributes List) A list of Rules, the presented delegated identity must match one allow rule to permit joining. (see [below for nested schema](#nested-schema-for-spectpmallow))
- `ekcert_allowed_cas` (List of String) A list of CA certificates that will be used to validate TPM EKCerts. When specified, joining TPMs must present an EKCert signed by one of the specified CAs. TPMs that do not present an EKCert will be not permitted to join. When unspecified, TPMs will be allowed to join with either an EKCert or an EKPubHash.
### Nested Schema for `spec.tpm.allow`
Optional:
- `description` (String) A human-readable description of the rule. It has no bearing on whether or not a TPM is allowed to join, but can be used to associate a rule with a specific host (e.g the asset tag of the server in which the TPM resides). Example: "build-server-100"
- `ek_certificate_serial` (String) The serial number of the EKCert in hexadecimal with colon separated nibbles. This value will not be checked when a TPM does not have an EKCert configured. Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
- `ek_public_hash` (String) The SHA256 hash of the EKPub marshaled in PKIX format and encoded in hexadecimal. This value will also be checked when a TPM has submitted an EKCert, and the public key in the EKCert will be used for this check. Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
@@ -113,6 +113,7 @@ Optional:
- `immutable_labels` (Attributes) Immutable labels that should be applied to any resulting resources provisioned using this token. (see [below for nested schema](#nested-schema-for-specimmutable_labels))
- `kubernetes` (Attributes) The Kubernetes-specific configuration used with the "kubernetes" join method. (see [below for nested schema](#nested-schema-for-speckubernetes))
- `oracle` (Attributes) The Oracle-specific configuration used with the "oracle" join method. (see [below for nested schema](#nested-schema-for-specoracle))
- `tpm` (Attributes) Configuration specific to the "tpm" join method. (see [below for nested schema](#nested-schema-for-spectpm))
### Nested Schema for `spec.aws`
@@ -385,3 +386,20 @@ Optional:
- `parent_compartments` (List of String) A list of the OCIDs of compartments an instance is allowed to join from. Only direct parents are allowed, i.e. no nested compartments. If empty, any compartment is allowed.
- `regions` (List of String) A list of regions an instance is allowed to join from. Both full region names ("us-phoenix-1") and abbreviations ("phx") are allowed. If empty, any region is allowed.
- `tenancy` (String) The OCID of the instance's tenancy. Required.
### Nested Schema for `spec.tpm`
Optional:
- `allow` (Attributes List) A list of Rules, the presented delegated identity must match one allow rule to permit joining. (see [below for nested schema](#nested-schema-for-spectpmallow))
- `ekcert_allowed_cas` (List of String) A list of CA certificates that will be used to validate TPM EKCerts. When specified, joining TPMs must present an EKCert signed by one of the specified CAs. TPMs that do not present an EKCert will be not permitted to join. When unspecified, TPMs will be allowed to join with either an EKCert or an EKPubHash.
### Nested Schema for `spec.tpm.allow`
Optional:
- `description` (String) A human-readable description of the rule. It has no bearing on whether or not a TPM is allowed to join, but can be used to associate a rule with a specific host (e.g the asset tag of the server in which the TPM resides). Example: "build-server-100"
- `ek_certificate_serial` (String) The serial number of the EKCert in hexadecimal with colon separated nibbles. This value will not be checked when a TPM does not have an EKCert configured. Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
- `ek_public_hash` (String) The SHA256 hash of the EKPub marshaled in PKIX format and encoded in hexadecimal. This value will also be checked when a TPM has submitted an EKCert, and the public key in the EKCert will be used for this check. Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
@@ -567,6 +567,35 @@ spec:
type: string
nullable: true
type: array
tpm:
description: Configuration specific to the "tpm" join method.
nullable: true
properties:
allow:
description: A list of Rules, the presented delegated identity
must match one allow rule to permit joining.
items:
properties:
description:
type: string
ek_certificate_serial:
type: string
ek_public_hash:
type: string
type: object
nullable: true
type: array
ekcert_allowed_cas:
description: A list of CA certificates that will be used to validate
TPM EKCerts. When specified, joining TPMs must present an EKCert
signed by one of the specified CAs. TPMs that do not present
an EKCert will be not permitted to join. When unspecified, TPMs
will be allowed to join with either an EKCert or an EKPubHash.
items:
type: string
nullable: true
type: array
type: object
usage_mode:
description: The usage mode of the token. Can be "single_use" or "unlimited".
Single use tokens can only be used to provision a single resource.
@@ -567,6 +567,35 @@ spec:
type: string
nullable: true
type: array
tpm:
description: Configuration specific to the "tpm" join method.
nullable: true
properties:
allow:
description: A list of Rules, the presented delegated identity
must match one allow rule to permit joining.
items:
properties:
description:
type: string
ek_certificate_serial:
type: string
ek_public_hash:
type: string
type: object
nullable: true
type: array
ekcert_allowed_cas:
description: A list of CA certificates that will be used to validate
TPM EKCerts. When specified, joining TPMs must present an EKCert
signed by one of the specified CAs. TPMs that do not present
an EKCert will be not permitted to join. When unspecified, TPMs
will be allowed to join with either an EKCert or an EKPubHash.
items:
type: string
nullable: true
type: array
type: object
usage_mode:
description: The usage mode of the token. Can be "single_use" or "unlimited".
Single use tokens can only be used to provision a single resource.
@@ -870,6 +870,48 @@ func GenSchemaScopedToken(ctx context.Context) (github_com_hashicorp_terraform_p
Required: true,
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
},
"tpm": {
Attributes: github_com_hashicorp_terraform_plugin_framework_tfsdk.SingleNestedAttributes(map[string]github_com_hashicorp_terraform_plugin_framework_tfsdk.Attribute{
"allow": {
Attributes: github_com_hashicorp_terraform_plugin_framework_tfsdk.ListNestedAttributes(map[string]github_com_hashicorp_terraform_plugin_framework_tfsdk.Attribute{
"description": {
Computed: true,
Description: "A human-readable description of the rule. It has no bearing on whether or not a TPM is allowed to join, but can be used to associate a rule with a specific host (e.g the asset tag of the server in which the TPM resides). Example: \"build-server-100\"",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"ek_certificate_serial": {
Computed: true,
Description: "The serial number of the EKCert in hexadecimal with colon separated nibbles. This value will not be checked when a TPM does not have an EKCert configured. Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"ek_public_hash": {
Computed: true,
Description: "The SHA256 hash of the EKPub marshaled in PKIX format and encoded in hexadecimal. This value will also be checked when a TPM has submitted an EKCert, and the public key in the EKCert will be used for this check. Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
}),
Computed: true,
Description: "A list of Rules, the presented delegated identity must match one allow rule to permit joining.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
},
"ekcert_allowed_cas": {
Computed: true,
Description: "A list of CA certificates that will be used to validate TPM EKCerts. When specified, joining TPMs must present an EKCert signed by one of the specified CAs. TPMs that do not present an EKCert will be not permitted to join. When unspecified, TPMs will be allowed to join with either an EKCert or an EKPubHash.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
},
}),
Description: "Configuration specific to the \"tpm\" join method.",
Optional: true,
},
"usage_mode": {
Description: "The usage mode of the token. Can be \"single_use\" or \"unlimited\". Single use tokens can only be used to provision a single resource. Unlimited tokens can be be used to provision any number of resources until it expires.",
Required: true,
@@ -3295,6 +3337,131 @@ func CopyScopedTokenFromTerraform(_ context.Context, tf github_com_hashicorp_ter
}
}
}
{
a, ok := tf.Attrs["tpm"]
if !ok {
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.Object)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm", "github.com/hashicorp/terraform-plugin-framework/types.Object"})
} else {
obj.Tpm = nil
if !v.Null && !v.Unknown {
tf := v
obj.Tpm = &github_com_gravitational_teleport_api_gen_proto_go_teleport_scopes_joining_v1.TPM{}
obj := obj.Tpm
{
a, ok := tf.Attrs["allow"]
if !ok {
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.allow"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow", "github.com/hashicorp/terraform-plugin-framework/types.List"})
} else {
obj.Allow = make([]*github_com_gravitational_teleport_api_gen_proto_go_teleport_scopes_joining_v1.TPM_Rule, len(v.Elems))
if !v.Null && !v.Unknown {
for k, a := range v.Elems {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.Object)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow", "github_com_hashicorp_terraform_plugin_framework_types.Object"})
} else {
var t *github_com_gravitational_teleport_api_gen_proto_go_teleport_scopes_joining_v1.TPM_Rule
if !v.Null && !v.Unknown {
tf := v
t = &github_com_gravitational_teleport_api_gen_proto_go_teleport_scopes_joining_v1.TPM_Rule{}
obj := t
{
a, ok := tf.Attrs["description"]
if !ok {
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.allow.description"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow.description", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.Description = t
}
}
}
{
a, ok := tf.Attrs["ek_public_hash"]
if !ok {
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.allow.ek_public_hash"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow.ek_public_hash", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.EkPublicHash = t
}
}
}
{
a, ok := tf.Attrs["ek_certificate_serial"]
if !ok {
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.EkCertificateSerial = t
}
}
}
}
obj.Allow[k] = t
}
}
}
}
}
}
{
a, ok := tf.Attrs["ekcert_allowed_cas"]
if !ok {
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github.com/hashicorp/terraform-plugin-framework/types.List"})
} else {
obj.EkcertAllowedCas = make([]string, len(v.Elems))
if !v.Null && !v.Unknown {
for k, a := range v.Elems {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github_com_hashicorp_terraform_plugin_framework_types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.EkcertAllowedCas[k] = t
}
}
}
}
}
}
}
}
}
}
}
}
}
@@ -7729,6 +7896,249 @@ func CopyScopedTokenToTerraformPreserveUnknown(ctx context.Context, obj *github_
}
}
}
{
a, ok := tf.AttrTypes["tpm"]
if !ok {
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ObjectType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm", "github.com/hashicorp/terraform-plugin-framework/types.ObjectType"})
} else {
v, ok := tf.Attrs["tpm"].(github_com_hashicorp_terraform_plugin_framework_types.Object)
if !ok {
v = github_com_hashicorp_terraform_plugin_framework_types.Object{
AttrTypes: o.AttrTypes,
Attrs: make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(o.AttrTypes)),
}
} else {
if v.Attrs == nil {
v.Attrs = make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(tf.AttrTypes))
}
}
if obj.Tpm == nil {
v.Null = true
} else {
v.Null = false
obj := obj.Tpm
tf := &v
{
a, ok := tf.AttrTypes["allow"]
if !ok {
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.allow"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.allow", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
} else {
c, ok := tf.Attrs["allow"].(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
c = github_com_hashicorp_terraform_plugin_framework_types.List{
ElemType: o.ElemType,
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Allow)),
Null: true,
}
} else {
if c.Elems == nil {
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Allow))
}
}
{
o := o.ElemType.(github_com_hashicorp_terraform_plugin_framework_types.ObjectType)
if len(obj.Allow) != len(c.Elems) {
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Allow))
copy(newElems, c.Elems)
c.Elems = newElems
}
for k, a := range obj.Allow {
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.Object)
if !ok {
v = github_com_hashicorp_terraform_plugin_framework_types.Object{
AttrTypes: o.AttrTypes,
Attrs: make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(o.AttrTypes)),
}
} else {
if v.Attrs == nil {
v.Attrs = make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(tf.AttrTypes))
}
}
if a == nil {
v.Null = true
} else {
v.Null = false
obj := a
tf := &v
{
t, ok := tf.AttrTypes["description"]
if !ok {
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.allow.description"})
} else {
v, ok := tf.Attrs["description"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if tf.Attrs["description"] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"ScopedToken.spec.tpm.allow.description", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"ScopedToken.spec.tpm.allow.description", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.allow.description", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(obj.Description)
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["description"] = v
}
}
{
t, ok := tf.AttrTypes["ek_public_hash"]
if !ok {
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.allow.ek_public_hash"})
} else {
v, ok := tf.Attrs["ek_public_hash"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if tf.Attrs["ek_public_hash"] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"ScopedToken.spec.tpm.allow.ek_public_hash", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"ScopedToken.spec.tpm.allow.ek_public_hash", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.allow.ek_public_hash", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(obj.EkPublicHash)
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["ek_public_hash"] = v
}
}
{
t, ok := tf.AttrTypes["ek_certificate_serial"]
if !ok {
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial"})
} else {
v, ok := tf.Attrs["ek_certificate_serial"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if tf.Attrs["ek_certificate_serial"] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"ScopedToken.spec.tpm.allow.ek_certificate_serial", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(obj.EkCertificateSerial)
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["ek_certificate_serial"] = v
}
}
}
if !preserveUnknown {
v.Unknown = false
}
c.Elems[k] = v
}
}
c.Null = false
if !preserveUnknown {
c.Unknown = false
}
tf.Attrs["allow"] = c
}
}
}
{
a, ok := tf.AttrTypes["ekcert_allowed_cas"]
if !ok {
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
} else {
c, ok := tf.Attrs["ekcert_allowed_cas"].(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
c = github_com_hashicorp_terraform_plugin_framework_types.List{
ElemType: o.ElemType,
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.EkcertAllowedCas)),
Null: true,
}
} else {
if c.Elems == nil {
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.EkcertAllowedCas))
}
}
{
t := o.ElemType
if len(obj.EkcertAllowedCas) != len(c.Elems) {
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.EkcertAllowedCas))
copy(newElems, c.Elems)
c.Elems = newElems
}
for k, a := range obj.EkcertAllowedCas {
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if c.Elems[k] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"ScopedToken.spec.tpm.ekcert_allowed_cas", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(a)
if !preserveUnknown {
v.Unknown = false
}
c.Elems[k] = v
}
}
c.Null = false
if !preserveUnknown {
c.Unknown = false
}
tf.Attrs["ekcert_allowed_cas"] = c
}
}
}
}
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["tpm"] = v
}
}
}
}
if !preserveUnknown {
v.Unknown = false
+2
View File
@@ -83,4 +83,6 @@ type Token interface {
GetGithub() *types.ProvisionTokenSpecV2GitHub
// GetGitLab returns the GitLab-specific configuration for this token.
GetGitLab() *types.ProvisionTokenSpecV2GitLab
// GetTPM returns the TPM-specific configuration for this token.
GetTPM() *types.ProvisionTokenSpecV2TPM
}
+1 -7
View File
@@ -21,7 +21,6 @@ import (
"github.com/gravitational/trace"
workloadidentityv1 "github.com/gravitational/teleport/api/gen/proto/go/teleport/workloadidentity/v1"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/join/internal/authz"
"github.com/gravitational/teleport/lib/join/internal/diagnostic"
"github.com/gravitational/teleport/lib/join/internal/messages"
@@ -49,11 +48,6 @@ func (s *Server) handleTPMJoin(
clientInit *messages.ClientInit,
provisionToken provision.Token,
) (messages.Response, error) {
ptv2, ok := provisionToken.(*types.ProvisionTokenV2)
if !ok {
return nil, trace.BadParameter("TPM joining only supports types.ProvisionTokenV2, got %T", provisionToken)
}
// Receive the TPMInit message from the client.
tpmInit, err := messages.RecvRequest[*messages.TPMInit](stream)
if err != nil {
@@ -78,7 +72,7 @@ func (s *Server) handleTPMJoin(
}
validatedEK, err := tpmjoin.CheckTPMRequest(stream.Context(), s.cfg.Modules, tpmjoin.CheckTPMRequestParams{
Token: ptv2,
Token: provisionToken,
TPMValidator: s.cfg.AuthService.GetTPMValidator(),
EKCert: tpmInit.EKCert,
EKKey: tpmInit.EKKey,
+8 -5
View File
@@ -24,6 +24,7 @@ import (
"github.com/gravitational/trace"
"github.com/gravitational/teleport/api/types"
"github.com/gravitational/teleport/lib/join/provision"
"github.com/gravitational/teleport/lib/modules"
"github.com/gravitational/teleport/lib/services"
"github.com/gravitational/teleport/lib/tpm"
@@ -35,7 +36,7 @@ type TPMValidator func(ctx context.Context, params tpm.ValidateParams) (*tpm.Val
// CheckTPMRequestParams holds all parameters for CheckTPMRequest.
type CheckTPMRequestParams struct {
// Token is the provision token used to validate the request.
Token *types.ProvisionTokenV2
Token provision.Token
// TPMValidator is a function that will be called to validate the presented TPM.
TPMValidator TPMValidator
@@ -79,20 +80,22 @@ func CheckTPMRequest(ctx context.Context, m modules.Modules, params CheckTPMRequ
return nil, trace.AccessDenied("validating TPM: %v", err)
}
if err := checkTPMAllowRules(validatedEK, params.Token.Spec.TPM.Allow); err != nil {
if err := checkTPMAllowRules(validatedEK, params.Token.GetTPM().Allow); err != nil {
return validatedEK, trace.Wrap(err)
}
return validatedEK, nil
}
func buildCertPool(token *types.ProvisionTokenV2) (*x509.CertPool, error) {
if len(token.Spec.TPM.EKCertAllowedCAs) == 0 {
func buildCertPool(token provision.Token) (*x509.CertPool, error) {
cfg := token.GetTPM()
if len(cfg.EKCertAllowedCAs) == 0 {
// Certs are not validated if no CAs were configured.
return nil, nil
}
certPool := x509.NewCertPool()
for i, ca := range token.Spec.TPM.EKCertAllowedCAs {
for i, ca := range cfg.EKCertAllowedCAs {
if ok := certPool.AppendCertsFromPEM([]byte(ca)); !ok {
return nil, trace.BadParameter(
"ekcert_allowed_cas[%d] has an invalid or malformed PEM", i,
+89
View File
@@ -19,9 +19,11 @@ package joining
import (
"cmp"
"crypto/sha256"
"crypto/x509"
"encoding/base64"
"encoding/binary"
"encoding/hex"
"encoding/pem"
"net/url"
"slices"
"strings"
@@ -415,6 +417,71 @@ func validateGitLab(spec *joiningv1.GitLab, tokenUsageMode TokenUsageMode) error
return nil
}
// validateTPM validates the TPM-specific scoped token configuration. Note that
// checks from ProvisionTokenSpecV2TPM.validate() are replicated here.
func validateTPM(spec *joiningv1.TPM) error {
if spec == nil {
return trace.BadParameter("tpm: the .spec.tpm field is required for this join method")
}
for i, caData := range spec.GetEkcertAllowedCas() {
p, _ := pem.Decode([]byte(caData))
if p == nil {
return trace.BadParameter(
"ekcert_allowed_cas[%d]: no pem block found",
i,
)
}
if p.Type != "CERTIFICATE" {
return trace.BadParameter(
"ekcert_allowed_cas[%d]: pem block is not 'CERTIFICATE' type",
i,
)
}
if _, err := x509.ParseCertificate(p.Bytes); err != nil {
return trace.Wrap(
err,
"ekcert_allowed_cas[%d]: parsing certificate",
i,
)
}
}
if len(spec.GetAllow()) == 0 {
return trace.BadParameter(
"allow: at least one rule must be set",
)
}
hasCAs := len(spec.GetEkcertAllowedCas()) > 0
for i, allowRule := range spec.GetAllow() {
if len(allowRule.GetEkPublicHash()) == 0 && len(allowRule.GetEkCertificateSerial()) == 0 {
return trace.BadParameter(
"allow[%d]: at least one of ['ek_public_hash', 'ek_certificate_serial'] must be set",
i,
)
}
// This is ported from services/local/provisioning.go's
// validateTPMToken() which was deliberately separate from the overall
// CheckAndSetDefaults() -> validate() path so as to not affect existing
// tokens. There are no existing scoped TPM tokens, so we can safely
// inline it here.
//
// This check doesn't apply if CAs are present: per the source impl,
// serials are not trustworthy when certificates are verified against a
// configured CA, so they're optional if CAs are also set.
hasSerialWithoutHash := allowRule.GetEkCertificateSerial() != "" && allowRule.GetEkPublicHash() == ""
if !hasCAs && hasSerialWithoutHash {
return trace.BadParameter(
"allow[%d]: ek_certificate_serial requires ek_public_hash or "+
"ekcert_allowed_cas to be set so that the EK certificate "+
"can be verified", i)
}
}
return nil
}
// validates per join method token configurations
func validateJoinMethod(token *joiningv1.ScopedToken) error {
switch types.JoinMethod(token.GetSpec().GetJoinMethod()) {
@@ -446,6 +513,8 @@ func validateJoinMethod(token *joiningv1.ScopedToken) error {
}
case types.JoinMethodGitLab:
return trace.Wrap(validateGitLab(token.GetSpec().GetGitlab(), TokenUsageMode(token.GetSpec().GetUsageMode())), "gitlab join method")
case types.JoinMethodTPM:
return trace.Wrap(validateTPM(token.GetSpec().GetTpm()), "tpm join method")
default:
return trace.BadParameter("join method %q does not support scoping", token.GetSpec().GetJoinMethod())
}
@@ -1141,6 +1210,26 @@ func (t *Token) GetGitLab() *types.ProvisionTokenSpecV2GitLab {
}
}
// GetTPM returns the TPM configuration for this token. Returns an empty but
// not nil value if TPM was not configured.
func (t *Token) GetTPM() *types.ProvisionTokenSpecV2TPM {
spec := t.scoped.GetSpec().GetTpm()
allow := make([]*types.ProvisionTokenSpecV2TPM_Rule, len(spec.GetAllow()))
for i, rule := range spec.GetAllow() {
allow[i] = &types.ProvisionTokenSpecV2TPM_Rule{
Description: rule.GetDescription(),
EKPublicHash: rule.GetEkPublicHash(),
EKCertificateSerial: rule.GetEkCertificateSerial(),
}
}
return &types.ProvisionTokenSpecV2TPM{
Allow: allow,
EKCertAllowedCAs: spec.GetEkcertAllowedCas(),
}
}
// GetScoped returns the inner scoped token wrapped by this [provision.Token].
func (t *Token) GetScoped() *joiningv1.ScopedToken {
return t.scoped