mirror of
https://github.com/gravitational/teleport.git
synced 2026-10-11 22:49:54 +00:00
Scopes: support tpm joining (#289)
Export-Source-Commit: 395143602db02eeaf5f8e9f2f4ca3e951fcb11ce
This commit is contained in:
@@ -278,7 +278,9 @@ type ScopedTokenSpec struct {
|
||||
// Configuration specific to the "github" join method.
|
||||
Github *Github `protobuf:"bytes,17,opt,name=github,proto3" json:"github,omitempty"`
|
||||
// Configuration specific to the "gitlab" join method.
|
||||
Gitlab *GitLab `protobuf:"bytes,18,opt,name=gitlab,proto3" json:"gitlab,omitempty"`
|
||||
Gitlab *GitLab `protobuf:"bytes,18,opt,name=gitlab,proto3" json:"gitlab,omitempty"`
|
||||
// Configuration specific to the "tpm" join method.
|
||||
Tpm *TPM `protobuf:"bytes,19,opt,name=tpm,proto3" json:"tpm,omitempty"`
|
||||
unknownFields protoimpl.UnknownFields
|
||||
sizeCache protoimpl.SizeCache
|
||||
}
|
||||
@@ -420,6 +422,13 @@ func (x *ScopedTokenSpec) GetGitlab() *GitLab {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) GetTpm() *TPM {
|
||||
if x != nil {
|
||||
return x.Tpm
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) SetAssignedScope(v string) {
|
||||
x.AssignedScope = v
|
||||
}
|
||||
@@ -484,6 +493,10 @@ func (x *ScopedTokenSpec) SetGitlab(v *GitLab) {
|
||||
x.Gitlab = v
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) SetTpm(v *TPM) {
|
||||
x.Tpm = v
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) HasImmutableLabels() bool {
|
||||
if x == nil {
|
||||
return false
|
||||
@@ -561,6 +574,13 @@ func (x *ScopedTokenSpec) HasGitlab() bool {
|
||||
return x.Gitlab != nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) HasTpm() bool {
|
||||
if x == nil {
|
||||
return false
|
||||
}
|
||||
return x.Tpm != nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) ClearImmutableLabels() {
|
||||
x.ImmutableLabels = nil
|
||||
}
|
||||
@@ -605,6 +625,10 @@ func (x *ScopedTokenSpec) ClearGitlab() {
|
||||
x.Gitlab = nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) ClearTpm() {
|
||||
x.Tpm = nil
|
||||
}
|
||||
|
||||
type ScopedTokenSpec_builder struct {
|
||||
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
|
||||
|
||||
@@ -653,6 +677,8 @@ type ScopedTokenSpec_builder struct {
|
||||
Github *Github
|
||||
// Configuration specific to the "gitlab" join method.
|
||||
Gitlab *GitLab
|
||||
// Configuration specific to the "tpm" join method.
|
||||
Tpm *TPM
|
||||
}
|
||||
|
||||
func (b0 ScopedTokenSpec_builder) Build() *ScopedTokenSpec {
|
||||
@@ -675,6 +701,7 @@ func (b0 ScopedTokenSpec_builder) Build() *ScopedTokenSpec {
|
||||
x.GenericOidc = b.GenericOidc
|
||||
x.Github = b.Github
|
||||
x.Gitlab = b.Gitlab
|
||||
x.Tpm = b.Tpm
|
||||
return m0
|
||||
}
|
||||
|
||||
@@ -2900,6 +2927,94 @@ func (b0 GitLab_builder) Build() *GitLab {
|
||||
return m0
|
||||
}
|
||||
|
||||
// Configuration specific to TPM tokens.
|
||||
type TPM struct {
|
||||
state protoimpl.MessageState `protogen:"hybrid.v1"`
|
||||
// A list of Rules, the presented delegated identity must match one allow rule
|
||||
// to permit joining.
|
||||
Allow []*TPM_Rule `protobuf:"bytes,1,rep,name=allow,proto3" json:"allow,omitempty"`
|
||||
// A list of CA certificates that will be used to validate TPM EKCerts.
|
||||
// When specified, joining TPMs must present an EKCert signed by one of the
|
||||
// specified CAs. TPMs that do not present an EKCert will be not permitted to
|
||||
// join.
|
||||
// When unspecified, TPMs will be allowed to join with either an EKCert or an
|
||||
// EKPubHash.
|
||||
EkcertAllowedCas []string `protobuf:"bytes,2,rep,name=ekcert_allowed_cas,json=ekcertAllowedCas,proto3" json:"ekcert_allowed_cas,omitempty"`
|
||||
unknownFields protoimpl.UnknownFields
|
||||
sizeCache protoimpl.SizeCache
|
||||
}
|
||||
|
||||
func (x *TPM) Reset() {
|
||||
*x = TPM{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[20]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
|
||||
func (x *TPM) String() string {
|
||||
return protoimpl.X.MessageStringOf(x)
|
||||
}
|
||||
|
||||
func (*TPM) ProtoMessage() {}
|
||||
|
||||
func (x *TPM) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[20]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
return ms
|
||||
}
|
||||
return mi.MessageOf(x)
|
||||
}
|
||||
|
||||
func (x *TPM) GetAllow() []*TPM_Rule {
|
||||
if x != nil {
|
||||
return x.Allow
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *TPM) GetEkcertAllowedCas() []string {
|
||||
if x != nil {
|
||||
return x.EkcertAllowedCas
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *TPM) SetAllow(v []*TPM_Rule) {
|
||||
x.Allow = v
|
||||
}
|
||||
|
||||
func (x *TPM) SetEkcertAllowedCas(v []string) {
|
||||
x.EkcertAllowedCas = v
|
||||
}
|
||||
|
||||
type TPM_builder struct {
|
||||
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
|
||||
|
||||
// A list of Rules, the presented delegated identity must match one allow rule
|
||||
// to permit joining.
|
||||
Allow []*TPM_Rule
|
||||
// A list of CA certificates that will be used to validate TPM EKCerts.
|
||||
// When specified, joining TPMs must present an EKCert signed by one of the
|
||||
// specified CAs. TPMs that do not present an EKCert will be not permitted to
|
||||
// join.
|
||||
// When unspecified, TPMs will be allowed to join with either an EKCert or an
|
||||
// EKPubHash.
|
||||
EkcertAllowedCas []string
|
||||
}
|
||||
|
||||
func (b0 TPM_builder) Build() *TPM {
|
||||
m0 := &TPM{}
|
||||
b, x := &b0, m0
|
||||
_, _ = b, x
|
||||
x.Allow = b.Allow
|
||||
x.EkcertAllowedCas = b.EkcertAllowedCas
|
||||
return m0
|
||||
}
|
||||
|
||||
// A rule that a joining node must match in order to use the associated token
|
||||
// with AWS join methods.
|
||||
type AWS_Rule struct {
|
||||
@@ -2924,7 +3039,7 @@ type AWS_Rule struct {
|
||||
|
||||
func (x *AWS_Rule) Reset() {
|
||||
*x = AWS_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[21]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -2936,7 +3051,7 @@ func (x *AWS_Rule) String() string {
|
||||
func (*AWS_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *AWS_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[21]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3049,7 +3164,7 @@ type GCP_Rule struct {
|
||||
|
||||
func (x *GCP_Rule) Reset() {
|
||||
*x = GCP_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3061,7 +3176,7 @@ func (x *GCP_Rule) String() string {
|
||||
func (*GCP_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *GCP_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3142,7 +3257,7 @@ type Azure_Rule struct {
|
||||
|
||||
func (x *Azure_Rule) Reset() {
|
||||
*x = Azure_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3154,7 +3269,7 @@ func (x *Azure_Rule) String() string {
|
||||
func (*Azure_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *Azure_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3261,7 +3376,7 @@ type AzureDevops_Rule struct {
|
||||
|
||||
func (x *AzureDevops_Rule) Reset() {
|
||||
*x = AzureDevops_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3273,7 +3388,7 @@ func (x *AzureDevops_Rule) String() string {
|
||||
func (*AzureDevops_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *AzureDevops_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3445,7 +3560,7 @@ type Oracle_Rule struct {
|
||||
|
||||
func (x *Oracle_Rule) Reset() {
|
||||
*x = Oracle_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3457,7 +3572,7 @@ func (x *Oracle_Rule) String() string {
|
||||
func (*Oracle_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *Oracle_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3551,7 +3666,7 @@ type Kubernetes_StaticJWKSConfig struct {
|
||||
|
||||
func (x *Kubernetes_StaticJWKSConfig) Reset() {
|
||||
*x = Kubernetes_StaticJWKSConfig{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3563,7 +3678,7 @@ func (x *Kubernetes_StaticJWKSConfig) String() string {
|
||||
func (*Kubernetes_StaticJWKSConfig) ProtoMessage() {}
|
||||
|
||||
func (x *Kubernetes_StaticJWKSConfig) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3616,7 +3731,7 @@ type Kubernetes_OIDCConfig struct {
|
||||
|
||||
func (x *Kubernetes_OIDCConfig) Reset() {
|
||||
*x = Kubernetes_OIDCConfig{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3628,7 +3743,7 @@ func (x *Kubernetes_OIDCConfig) String() string {
|
||||
func (*Kubernetes_OIDCConfig) ProtoMessage() {}
|
||||
|
||||
func (x *Kubernetes_OIDCConfig) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3708,7 +3823,7 @@ type Kubernetes_Rule struct {
|
||||
|
||||
func (x *Kubernetes_Rule) Reset() {
|
||||
*x = Kubernetes_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3720,7 +3835,7 @@ func (x *Kubernetes_Rule) String() string {
|
||||
func (*Kubernetes_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *Kubernetes_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3823,7 +3938,7 @@ type BoundKeypairSpec_OnboardingSpec struct {
|
||||
|
||||
func (x *BoundKeypairSpec_OnboardingSpec) Reset() {
|
||||
*x = BoundKeypairSpec_OnboardingSpec{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3835,7 +3950,7 @@ func (x *BoundKeypairSpec_OnboardingSpec) String() string {
|
||||
func (*BoundKeypairSpec_OnboardingSpec) ProtoMessage() {}
|
||||
|
||||
func (x *BoundKeypairSpec_OnboardingSpec) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3958,7 +4073,7 @@ type BoundKeypairSpec_RecoverySpec struct {
|
||||
|
||||
func (x *BoundKeypairSpec_RecoverySpec) Reset() {
|
||||
*x = BoundKeypairSpec_RecoverySpec{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3970,7 +4085,7 @@ func (x *BoundKeypairSpec_RecoverySpec) String() string {
|
||||
func (*BoundKeypairSpec_RecoverySpec) ProtoMessage() {}
|
||||
|
||||
func (x *BoundKeypairSpec_RecoverySpec) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4051,7 +4166,7 @@ type GenericOIDC_ConditionEq struct {
|
||||
|
||||
func (x *GenericOIDC_ConditionEq) Reset() {
|
||||
*x = GenericOIDC_ConditionEq{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4063,7 +4178,7 @@ func (x *GenericOIDC_ConditionEq) String() string {
|
||||
func (*GenericOIDC_ConditionEq) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_ConditionEq) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4111,7 +4226,7 @@ type GenericOIDC_ConditionNotEq struct {
|
||||
|
||||
func (x *GenericOIDC_ConditionNotEq) Reset() {
|
||||
*x = GenericOIDC_ConditionNotEq{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4123,7 +4238,7 @@ func (x *GenericOIDC_ConditionNotEq) String() string {
|
||||
func (*GenericOIDC_ConditionNotEq) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_ConditionNotEq) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4171,7 +4286,7 @@ type GenericOIDC_ConditionIn struct {
|
||||
|
||||
func (x *GenericOIDC_ConditionIn) Reset() {
|
||||
*x = GenericOIDC_ConditionIn{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4183,7 +4298,7 @@ func (x *GenericOIDC_ConditionIn) String() string {
|
||||
func (*GenericOIDC_ConditionIn) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_ConditionIn) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4231,7 +4346,7 @@ type GenericOIDC_ConditionNotIn struct {
|
||||
|
||||
func (x *GenericOIDC_ConditionNotIn) Reset() {
|
||||
*x = GenericOIDC_ConditionNotIn{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4243,7 +4358,7 @@ func (x *GenericOIDC_ConditionNotIn) String() string {
|
||||
func (*GenericOIDC_ConditionNotIn) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_ConditionNotIn) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4300,7 +4415,7 @@ type GenericOIDC_Condition struct {
|
||||
|
||||
func (x *GenericOIDC_Condition) Reset() {
|
||||
*x = GenericOIDC_Condition{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4312,7 +4427,7 @@ func (x *GenericOIDC_Condition) String() string {
|
||||
func (*GenericOIDC_Condition) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_Condition) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4468,7 +4583,7 @@ type GenericOIDC_Rule struct {
|
||||
|
||||
func (x *GenericOIDC_Rule) Reset() {
|
||||
*x = GenericOIDC_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4480,7 +4595,7 @@ func (x *GenericOIDC_Rule) String() string {
|
||||
func (*GenericOIDC_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4597,7 +4712,7 @@ type Github_Rule struct {
|
||||
|
||||
func (x *Github_Rule) Reset() {
|
||||
*x = Github_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4609,7 +4724,7 @@ func (x *Github_Rule) String() string {
|
||||
func (*Github_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *Github_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4877,7 +4992,7 @@ type GitLab_Rule struct {
|
||||
|
||||
func (x *GitLab_Rule) Reset() {
|
||||
*x = GitLab_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[39]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4889,7 +5004,7 @@ func (x *GitLab_Rule) String() string {
|
||||
func (*GitLab_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *GitLab_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[39]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -5189,6 +5304,117 @@ func (b0 GitLab_Rule_builder) Build() *GitLab_Rule {
|
||||
return m0
|
||||
}
|
||||
|
||||
// A rule for TPM joining tokens, of which one must match for a join attempt
|
||||
// to be allowed.
|
||||
type TPM_Rule struct {
|
||||
state protoimpl.MessageState `protogen:"hybrid.v1"`
|
||||
// A human-readable description of the rule. It has no bearing on whether or
|
||||
// not a TPM is allowed to join, but can be used to associate a rule with a
|
||||
// specific host (e.g the asset tag of the server in which the TPM resides).
|
||||
// Example: "build-server-100"
|
||||
Description string `protobuf:"bytes,1,opt,name=description,proto3" json:"description,omitempty"`
|
||||
// The SHA256 hash of the EKPub marshaled in PKIX format and encoded in
|
||||
// hexadecimal. This value will also be checked when a TPM has submitted an
|
||||
// EKCert, and the public key in the EKCert will be used for this check.
|
||||
// Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
|
||||
EkPublicHash string `protobuf:"bytes,2,opt,name=ek_public_hash,json=ekPublicHash,proto3" json:"ek_public_hash,omitempty"`
|
||||
// The serial number of the EKCert in hexadecimal with colon separated
|
||||
// nibbles. This value will not be checked when a TPM does not have an
|
||||
// EKCert configured.
|
||||
// Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
|
||||
EkCertificateSerial string `protobuf:"bytes,3,opt,name=ek_certificate_serial,json=ekCertificateSerial,proto3" json:"ek_certificate_serial,omitempty"`
|
||||
unknownFields protoimpl.UnknownFields
|
||||
sizeCache protoimpl.SizeCache
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) Reset() {
|
||||
*x = TPM_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[40]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) String() string {
|
||||
return protoimpl.X.MessageStringOf(x)
|
||||
}
|
||||
|
||||
func (*TPM_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *TPM_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[40]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
return ms
|
||||
}
|
||||
return mi.MessageOf(x)
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) GetDescription() string {
|
||||
if x != nil {
|
||||
return x.Description
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) GetEkPublicHash() string {
|
||||
if x != nil {
|
||||
return x.EkPublicHash
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) GetEkCertificateSerial() string {
|
||||
if x != nil {
|
||||
return x.EkCertificateSerial
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) SetDescription(v string) {
|
||||
x.Description = v
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) SetEkPublicHash(v string) {
|
||||
x.EkPublicHash = v
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) SetEkCertificateSerial(v string) {
|
||||
x.EkCertificateSerial = v
|
||||
}
|
||||
|
||||
type TPM_Rule_builder struct {
|
||||
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
|
||||
|
||||
// A human-readable description of the rule. It has no bearing on whether or
|
||||
// not a TPM is allowed to join, but can be used to associate a rule with a
|
||||
// specific host (e.g the asset tag of the server in which the TPM resides).
|
||||
// Example: "build-server-100"
|
||||
Description string
|
||||
// The SHA256 hash of the EKPub marshaled in PKIX format and encoded in
|
||||
// hexadecimal. This value will also be checked when a TPM has submitted an
|
||||
// EKCert, and the public key in the EKCert will be used for this check.
|
||||
// Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
|
||||
EkPublicHash string
|
||||
// The serial number of the EKCert in hexadecimal with colon separated
|
||||
// nibbles. This value will not be checked when a TPM does not have an
|
||||
// EKCert configured.
|
||||
// Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
|
||||
EkCertificateSerial string
|
||||
}
|
||||
|
||||
func (b0 TPM_Rule_builder) Build() *TPM_Rule {
|
||||
m0 := &TPM_Rule{}
|
||||
b, x := &b0, m0
|
||||
_, _ = b, x
|
||||
x.Description = b.Description
|
||||
x.EkPublicHash = b.EkPublicHash
|
||||
x.EkCertificateSerial = b.EkCertificateSerial
|
||||
return m0
|
||||
}
|
||||
|
||||
var File_teleport_scopes_joining_v1_token_proto protoreflect.FileDescriptor
|
||||
|
||||
const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
|
||||
@@ -5201,7 +5427,7 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
|
||||
"\bmetadata\x18\x04 \x01(\v2\x1c.teleport.header.v1.MetadataR\bmetadata\x12\x14\n" +
|
||||
"\x05scope\x18\x05 \x01(\tR\x05scope\x12?\n" +
|
||||
"\x04spec\x18\x06 \x01(\v2+.teleport.scopes.joining.v1.ScopedTokenSpecR\x04spec\x12E\n" +
|
||||
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\x9f\a\n" +
|
||||
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\xd2\a\n" +
|
||||
"\x0fScopedTokenSpec\x12%\n" +
|
||||
"\x0eassigned_scope\x18\x01 \x01(\tR\rassignedScope\x12\x14\n" +
|
||||
"\x05roles\x18\x02 \x03(\tR\x05roles\x12\x1f\n" +
|
||||
@@ -5223,7 +5449,8 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
|
||||
"\x03bot\x18\x0f \x01(\tR\x03bot\x12J\n" +
|
||||
"\fgeneric_oidc\x18\x10 \x01(\v2'.teleport.scopes.joining.v1.GenericOIDCR\vgenericOidc\x12:\n" +
|
||||
"\x06github\x18\x11 \x01(\v2\".teleport.scopes.joining.v1.GithubR\x06github\x12:\n" +
|
||||
"\x06gitlab\x18\x12 \x01(\v2\".teleport.scopes.joining.v1.GitLabR\x06gitlabJ\x04\b\r\x10\x0eJ\x04\b\x0e\x10\x0fR\bbot_nameR\tbot_scope\"\xb6\x01\n" +
|
||||
"\x06gitlab\x18\x12 \x01(\v2\".teleport.scopes.joining.v1.GitLabR\x06gitlab\x121\n" +
|
||||
"\x03tpm\x18\x13 \x01(\v2\x1f.teleport.scopes.joining.v1.TPMR\x03tpmJ\x04\b\r\x10\x0eJ\x04\b\x0e\x10\x0fR\bbot_nameR\tbot_scope\"\xb6\x01\n" +
|
||||
"\x0eHostCertParams\x12\x17\n" +
|
||||
"\ahost_id\x18\x01 \x01(\tR\x06hostId\x12\x1b\n" +
|
||||
"\tnode_name\x18\x02 \x01(\tR\bnodeName\x12\x12\n" +
|
||||
@@ -5418,9 +5645,16 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
|
||||
"\x0fdeployment_tier\x18\x0f \x01(\tR\x0edeploymentTier\x12-\n" +
|
||||
"\x12project_visibility\x18\x10 \x01(\tR\x11projectVisibilityB\x10\n" +
|
||||
"\x0e_ref_protectedB\x18\n" +
|
||||
"\x16_environment_protectedBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
|
||||
"\x16_environment_protected\"\xf4\x01\n" +
|
||||
"\x03TPM\x12:\n" +
|
||||
"\x05allow\x18\x01 \x03(\v2$.teleport.scopes.joining.v1.TPM.RuleR\x05allow\x12,\n" +
|
||||
"\x12ekcert_allowed_cas\x18\x02 \x03(\tR\x10ekcertAllowedCas\x1a\x82\x01\n" +
|
||||
"\x04Rule\x12 \n" +
|
||||
"\vdescription\x18\x01 \x01(\tR\vdescription\x12$\n" +
|
||||
"\x0eek_public_hash\x18\x02 \x01(\tR\fekPublicHash\x122\n" +
|
||||
"\x15ek_certificate_serial\x18\x03 \x01(\tR\x13ekCertificateSerialBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
|
||||
|
||||
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 39)
|
||||
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 41)
|
||||
var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
|
||||
(*ScopedToken)(nil), // 0: teleport.scopes.joining.v1.ScopedToken
|
||||
(*ScopedTokenSpec)(nil), // 1: teleport.scopes.joining.v1.ScopedTokenSpec
|
||||
@@ -5442,31 +5676,33 @@ var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
|
||||
(*GenericOIDC)(nil), // 17: teleport.scopes.joining.v1.GenericOIDC
|
||||
(*Github)(nil), // 18: teleport.scopes.joining.v1.Github
|
||||
(*GitLab)(nil), // 19: teleport.scopes.joining.v1.GitLab
|
||||
nil, // 20: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
|
||||
(*AWS_Rule)(nil), // 21: teleport.scopes.joining.v1.AWS.Rule
|
||||
(*GCP_Rule)(nil), // 22: teleport.scopes.joining.v1.GCP.Rule
|
||||
(*Azure_Rule)(nil), // 23: teleport.scopes.joining.v1.Azure.Rule
|
||||
(*AzureDevops_Rule)(nil), // 24: teleport.scopes.joining.v1.AzureDevops.Rule
|
||||
(*Oracle_Rule)(nil), // 25: teleport.scopes.joining.v1.Oracle.Rule
|
||||
(*Kubernetes_StaticJWKSConfig)(nil), // 26: teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
|
||||
(*Kubernetes_OIDCConfig)(nil), // 27: teleport.scopes.joining.v1.Kubernetes.OIDCConfig
|
||||
(*Kubernetes_Rule)(nil), // 28: teleport.scopes.joining.v1.Kubernetes.Rule
|
||||
(*BoundKeypairSpec_OnboardingSpec)(nil), // 29: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
|
||||
(*BoundKeypairSpec_RecoverySpec)(nil), // 30: teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
|
||||
(*GenericOIDC_ConditionEq)(nil), // 31: teleport.scopes.joining.v1.GenericOIDC.ConditionEq
|
||||
(*GenericOIDC_ConditionNotEq)(nil), // 32: teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
|
||||
(*GenericOIDC_ConditionIn)(nil), // 33: teleport.scopes.joining.v1.GenericOIDC.ConditionIn
|
||||
(*GenericOIDC_ConditionNotIn)(nil), // 34: teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
|
||||
(*GenericOIDC_Condition)(nil), // 35: teleport.scopes.joining.v1.GenericOIDC.Condition
|
||||
(*GenericOIDC_Rule)(nil), // 36: teleport.scopes.joining.v1.GenericOIDC.Rule
|
||||
(*Github_Rule)(nil), // 37: teleport.scopes.joining.v1.Github.Rule
|
||||
(*GitLab_Rule)(nil), // 38: teleport.scopes.joining.v1.GitLab.Rule
|
||||
(*v1.Metadata)(nil), // 39: teleport.header.v1.Metadata
|
||||
(*timestamppb.Timestamp)(nil), // 40: google.protobuf.Timestamp
|
||||
(*structpb.Struct)(nil), // 41: google.protobuf.Struct
|
||||
(*TPM)(nil), // 20: teleport.scopes.joining.v1.TPM
|
||||
nil, // 21: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
|
||||
(*AWS_Rule)(nil), // 22: teleport.scopes.joining.v1.AWS.Rule
|
||||
(*GCP_Rule)(nil), // 23: teleport.scopes.joining.v1.GCP.Rule
|
||||
(*Azure_Rule)(nil), // 24: teleport.scopes.joining.v1.Azure.Rule
|
||||
(*AzureDevops_Rule)(nil), // 25: teleport.scopes.joining.v1.AzureDevops.Rule
|
||||
(*Oracle_Rule)(nil), // 26: teleport.scopes.joining.v1.Oracle.Rule
|
||||
(*Kubernetes_StaticJWKSConfig)(nil), // 27: teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
|
||||
(*Kubernetes_OIDCConfig)(nil), // 28: teleport.scopes.joining.v1.Kubernetes.OIDCConfig
|
||||
(*Kubernetes_Rule)(nil), // 29: teleport.scopes.joining.v1.Kubernetes.Rule
|
||||
(*BoundKeypairSpec_OnboardingSpec)(nil), // 30: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
|
||||
(*BoundKeypairSpec_RecoverySpec)(nil), // 31: teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
|
||||
(*GenericOIDC_ConditionEq)(nil), // 32: teleport.scopes.joining.v1.GenericOIDC.ConditionEq
|
||||
(*GenericOIDC_ConditionNotEq)(nil), // 33: teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
|
||||
(*GenericOIDC_ConditionIn)(nil), // 34: teleport.scopes.joining.v1.GenericOIDC.ConditionIn
|
||||
(*GenericOIDC_ConditionNotIn)(nil), // 35: teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
|
||||
(*GenericOIDC_Condition)(nil), // 36: teleport.scopes.joining.v1.GenericOIDC.Condition
|
||||
(*GenericOIDC_Rule)(nil), // 37: teleport.scopes.joining.v1.GenericOIDC.Rule
|
||||
(*Github_Rule)(nil), // 38: teleport.scopes.joining.v1.Github.Rule
|
||||
(*GitLab_Rule)(nil), // 39: teleport.scopes.joining.v1.GitLab.Rule
|
||||
(*TPM_Rule)(nil), // 40: teleport.scopes.joining.v1.TPM.Rule
|
||||
(*v1.Metadata)(nil), // 41: teleport.header.v1.Metadata
|
||||
(*timestamppb.Timestamp)(nil), // 42: google.protobuf.Timestamp
|
||||
(*structpb.Struct)(nil), // 43: google.protobuf.Struct
|
||||
}
|
||||
var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
|
||||
39, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
|
||||
41, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
|
||||
1, // 1: teleport.scopes.joining.v1.ScopedToken.spec:type_name -> teleport.scopes.joining.v1.ScopedTokenSpec
|
||||
5, // 2: teleport.scopes.joining.v1.ScopedToken.status:type_name -> teleport.scopes.joining.v1.ScopedTokenStatus
|
||||
6, // 3: teleport.scopes.joining.v1.ScopedTokenSpec.immutable_labels:type_name -> teleport.scopes.joining.v1.ImmutableLabels
|
||||
@@ -5480,44 +5716,46 @@ var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
|
||||
17, // 11: teleport.scopes.joining.v1.ScopedTokenSpec.generic_oidc:type_name -> teleport.scopes.joining.v1.GenericOIDC
|
||||
18, // 12: teleport.scopes.joining.v1.ScopedTokenSpec.github:type_name -> teleport.scopes.joining.v1.Github
|
||||
19, // 13: teleport.scopes.joining.v1.ScopedTokenSpec.gitlab:type_name -> teleport.scopes.joining.v1.GitLab
|
||||
40, // 14: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
|
||||
40, // 15: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
|
||||
2, // 16: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
|
||||
3, // 17: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
|
||||
16, // 18: teleport.scopes.joining.v1.UsageStatus.bound_keypair:type_name -> teleport.scopes.joining.v1.BoundKeypairStatus
|
||||
4, // 19: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
|
||||
20, // 20: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
|
||||
39, // 21: teleport.scopes.joining.v1.StaticScopedTokens.metadata:type_name -> teleport.header.v1.Metadata
|
||||
8, // 22: teleport.scopes.joining.v1.StaticScopedTokens.spec:type_name -> teleport.scopes.joining.v1.StaticScopedTokensSpec
|
||||
0, // 23: teleport.scopes.joining.v1.StaticScopedTokensSpec.tokens:type_name -> teleport.scopes.joining.v1.ScopedToken
|
||||
21, // 24: teleport.scopes.joining.v1.AWS.allow:type_name -> teleport.scopes.joining.v1.AWS.Rule
|
||||
22, // 25: teleport.scopes.joining.v1.GCP.allow:type_name -> teleport.scopes.joining.v1.GCP.Rule
|
||||
23, // 26: teleport.scopes.joining.v1.Azure.allow:type_name -> teleport.scopes.joining.v1.Azure.Rule
|
||||
24, // 27: teleport.scopes.joining.v1.AzureDevops.allow:type_name -> teleport.scopes.joining.v1.AzureDevops.Rule
|
||||
25, // 28: teleport.scopes.joining.v1.Oracle.allow:type_name -> teleport.scopes.joining.v1.Oracle.Rule
|
||||
28, // 29: teleport.scopes.joining.v1.Kubernetes.allow:type_name -> teleport.scopes.joining.v1.Kubernetes.Rule
|
||||
26, // 30: teleport.scopes.joining.v1.Kubernetes.static_jwks:type_name -> teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
|
||||
27, // 31: teleport.scopes.joining.v1.Kubernetes.oidc:type_name -> teleport.scopes.joining.v1.Kubernetes.OIDCConfig
|
||||
29, // 32: teleport.scopes.joining.v1.BoundKeypairSpec.onboarding:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
|
||||
30, // 33: teleport.scopes.joining.v1.BoundKeypairSpec.recovery:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
|
||||
40, // 34: teleport.scopes.joining.v1.BoundKeypairSpec.rotate_after:type_name -> google.protobuf.Timestamp
|
||||
40, // 35: teleport.scopes.joining.v1.BoundKeypairStatus.last_recovered_at:type_name -> google.protobuf.Timestamp
|
||||
40, // 36: teleport.scopes.joining.v1.BoundKeypairStatus.last_rotated_at:type_name -> google.protobuf.Timestamp
|
||||
41, // 37: teleport.scopes.joining.v1.GenericOIDC.must_match_fields:type_name -> google.protobuf.Struct
|
||||
36, // 38: teleport.scopes.joining.v1.GenericOIDC.allow_any:type_name -> teleport.scopes.joining.v1.GenericOIDC.Rule
|
||||
37, // 39: teleport.scopes.joining.v1.Github.allow:type_name -> teleport.scopes.joining.v1.Github.Rule
|
||||
38, // 40: teleport.scopes.joining.v1.GitLab.allow:type_name -> teleport.scopes.joining.v1.GitLab.Rule
|
||||
40, // 41: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec.must_register_before:type_name -> google.protobuf.Timestamp
|
||||
31, // 42: teleport.scopes.joining.v1.GenericOIDC.Condition.eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionEq
|
||||
32, // 43: teleport.scopes.joining.v1.GenericOIDC.Condition.not_eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
|
||||
33, // 44: teleport.scopes.joining.v1.GenericOIDC.Condition.in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionIn
|
||||
34, // 45: teleport.scopes.joining.v1.GenericOIDC.Condition.not_in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
|
||||
35, // 46: teleport.scopes.joining.v1.GenericOIDC.Rule.conditions:type_name -> teleport.scopes.joining.v1.GenericOIDC.Condition
|
||||
47, // [47:47] is the sub-list for method output_type
|
||||
47, // [47:47] is the sub-list for method input_type
|
||||
47, // [47:47] is the sub-list for extension type_name
|
||||
47, // [47:47] is the sub-list for extension extendee
|
||||
0, // [0:47] is the sub-list for field type_name
|
||||
20, // 14: teleport.scopes.joining.v1.ScopedTokenSpec.tpm:type_name -> teleport.scopes.joining.v1.TPM
|
||||
42, // 15: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
|
||||
42, // 16: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
|
||||
2, // 17: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
|
||||
3, // 18: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
|
||||
16, // 19: teleport.scopes.joining.v1.UsageStatus.bound_keypair:type_name -> teleport.scopes.joining.v1.BoundKeypairStatus
|
||||
4, // 20: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
|
||||
21, // 21: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
|
||||
41, // 22: teleport.scopes.joining.v1.StaticScopedTokens.metadata:type_name -> teleport.header.v1.Metadata
|
||||
8, // 23: teleport.scopes.joining.v1.StaticScopedTokens.spec:type_name -> teleport.scopes.joining.v1.StaticScopedTokensSpec
|
||||
0, // 24: teleport.scopes.joining.v1.StaticScopedTokensSpec.tokens:type_name -> teleport.scopes.joining.v1.ScopedToken
|
||||
22, // 25: teleport.scopes.joining.v1.AWS.allow:type_name -> teleport.scopes.joining.v1.AWS.Rule
|
||||
23, // 26: teleport.scopes.joining.v1.GCP.allow:type_name -> teleport.scopes.joining.v1.GCP.Rule
|
||||
24, // 27: teleport.scopes.joining.v1.Azure.allow:type_name -> teleport.scopes.joining.v1.Azure.Rule
|
||||
25, // 28: teleport.scopes.joining.v1.AzureDevops.allow:type_name -> teleport.scopes.joining.v1.AzureDevops.Rule
|
||||
26, // 29: teleport.scopes.joining.v1.Oracle.allow:type_name -> teleport.scopes.joining.v1.Oracle.Rule
|
||||
29, // 30: teleport.scopes.joining.v1.Kubernetes.allow:type_name -> teleport.scopes.joining.v1.Kubernetes.Rule
|
||||
27, // 31: teleport.scopes.joining.v1.Kubernetes.static_jwks:type_name -> teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
|
||||
28, // 32: teleport.scopes.joining.v1.Kubernetes.oidc:type_name -> teleport.scopes.joining.v1.Kubernetes.OIDCConfig
|
||||
30, // 33: teleport.scopes.joining.v1.BoundKeypairSpec.onboarding:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
|
||||
31, // 34: teleport.scopes.joining.v1.BoundKeypairSpec.recovery:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
|
||||
42, // 35: teleport.scopes.joining.v1.BoundKeypairSpec.rotate_after:type_name -> google.protobuf.Timestamp
|
||||
42, // 36: teleport.scopes.joining.v1.BoundKeypairStatus.last_recovered_at:type_name -> google.protobuf.Timestamp
|
||||
42, // 37: teleport.scopes.joining.v1.BoundKeypairStatus.last_rotated_at:type_name -> google.protobuf.Timestamp
|
||||
43, // 38: teleport.scopes.joining.v1.GenericOIDC.must_match_fields:type_name -> google.protobuf.Struct
|
||||
37, // 39: teleport.scopes.joining.v1.GenericOIDC.allow_any:type_name -> teleport.scopes.joining.v1.GenericOIDC.Rule
|
||||
38, // 40: teleport.scopes.joining.v1.Github.allow:type_name -> teleport.scopes.joining.v1.Github.Rule
|
||||
39, // 41: teleport.scopes.joining.v1.GitLab.allow:type_name -> teleport.scopes.joining.v1.GitLab.Rule
|
||||
40, // 42: teleport.scopes.joining.v1.TPM.allow:type_name -> teleport.scopes.joining.v1.TPM.Rule
|
||||
42, // 43: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec.must_register_before:type_name -> google.protobuf.Timestamp
|
||||
32, // 44: teleport.scopes.joining.v1.GenericOIDC.Condition.eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionEq
|
||||
33, // 45: teleport.scopes.joining.v1.GenericOIDC.Condition.not_eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
|
||||
34, // 46: teleport.scopes.joining.v1.GenericOIDC.Condition.in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionIn
|
||||
35, // 47: teleport.scopes.joining.v1.GenericOIDC.Condition.not_in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
|
||||
36, // 48: teleport.scopes.joining.v1.GenericOIDC.Rule.conditions:type_name -> teleport.scopes.joining.v1.GenericOIDC.Condition
|
||||
49, // [49:49] is the sub-list for method output_type
|
||||
49, // [49:49] is the sub-list for method input_type
|
||||
49, // [49:49] is the sub-list for extension type_name
|
||||
49, // [49:49] is the sub-list for extension extendee
|
||||
0, // [0:49] is the sub-list for field type_name
|
||||
}
|
||||
|
||||
func init() { file_teleport_scopes_joining_v1_token_proto_init() }
|
||||
@@ -5529,14 +5767,14 @@ func file_teleport_scopes_joining_v1_token_proto_init() {
|
||||
(*UsageStatus_SingleUse)(nil),
|
||||
(*UsageStatus_BoundKeypair)(nil),
|
||||
}
|
||||
file_teleport_scopes_joining_v1_token_proto_msgTypes[38].OneofWrappers = []any{}
|
||||
file_teleport_scopes_joining_v1_token_proto_msgTypes[39].OneofWrappers = []any{}
|
||||
type x struct{}
|
||||
out := protoimpl.TypeBuilder{
|
||||
File: protoimpl.DescBuilder{
|
||||
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
|
||||
RawDescriptor: unsafe.Slice(unsafe.StringData(file_teleport_scopes_joining_v1_token_proto_rawDesc), len(file_teleport_scopes_joining_v1_token_proto_rawDesc)),
|
||||
NumEnums: 0,
|
||||
NumMessages: 39,
|
||||
NumMessages: 41,
|
||||
NumExtensions: 0,
|
||||
NumServices: 0,
|
||||
},
|
||||
|
||||
@@ -243,6 +243,7 @@ type ScopedTokenSpec struct {
|
||||
xxx_hidden_GenericOidc *GenericOIDC `protobuf:"bytes,16,opt,name=generic_oidc,json=genericOidc,proto3"`
|
||||
xxx_hidden_Github *Github `protobuf:"bytes,17,opt,name=github,proto3"`
|
||||
xxx_hidden_Gitlab *GitLab `protobuf:"bytes,18,opt,name=gitlab,proto3"`
|
||||
xxx_hidden_Tpm *TPM `protobuf:"bytes,19,opt,name=tpm,proto3"`
|
||||
unknownFields protoimpl.UnknownFields
|
||||
sizeCache protoimpl.SizeCache
|
||||
}
|
||||
@@ -384,6 +385,13 @@ func (x *ScopedTokenSpec) GetGitlab() *GitLab {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) GetTpm() *TPM {
|
||||
if x != nil {
|
||||
return x.xxx_hidden_Tpm
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) SetAssignedScope(v string) {
|
||||
x.xxx_hidden_AssignedScope = v
|
||||
}
|
||||
@@ -448,6 +456,10 @@ func (x *ScopedTokenSpec) SetGitlab(v *GitLab) {
|
||||
x.xxx_hidden_Gitlab = v
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) SetTpm(v *TPM) {
|
||||
x.xxx_hidden_Tpm = v
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) HasImmutableLabels() bool {
|
||||
if x == nil {
|
||||
return false
|
||||
@@ -525,6 +537,13 @@ func (x *ScopedTokenSpec) HasGitlab() bool {
|
||||
return x.xxx_hidden_Gitlab != nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) HasTpm() bool {
|
||||
if x == nil {
|
||||
return false
|
||||
}
|
||||
return x.xxx_hidden_Tpm != nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) ClearImmutableLabels() {
|
||||
x.xxx_hidden_ImmutableLabels = nil
|
||||
}
|
||||
@@ -569,6 +588,10 @@ func (x *ScopedTokenSpec) ClearGitlab() {
|
||||
x.xxx_hidden_Gitlab = nil
|
||||
}
|
||||
|
||||
func (x *ScopedTokenSpec) ClearTpm() {
|
||||
x.xxx_hidden_Tpm = nil
|
||||
}
|
||||
|
||||
type ScopedTokenSpec_builder struct {
|
||||
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
|
||||
|
||||
@@ -617,6 +640,8 @@ type ScopedTokenSpec_builder struct {
|
||||
Github *Github
|
||||
// Configuration specific to the "gitlab" join method.
|
||||
Gitlab *GitLab
|
||||
// Configuration specific to the "tpm" join method.
|
||||
Tpm *TPM
|
||||
}
|
||||
|
||||
func (b0 ScopedTokenSpec_builder) Build() *ScopedTokenSpec {
|
||||
@@ -639,6 +664,7 @@ func (b0 ScopedTokenSpec_builder) Build() *ScopedTokenSpec {
|
||||
x.xxx_hidden_GenericOidc = b.GenericOidc
|
||||
x.xxx_hidden_Github = b.Github
|
||||
x.xxx_hidden_Gitlab = b.Gitlab
|
||||
x.xxx_hidden_Tpm = b.Tpm
|
||||
return m0
|
||||
}
|
||||
|
||||
@@ -2695,6 +2721,88 @@ func (b0 GitLab_builder) Build() *GitLab {
|
||||
return m0
|
||||
}
|
||||
|
||||
// Configuration specific to TPM tokens.
|
||||
type TPM struct {
|
||||
state protoimpl.MessageState `protogen:"opaque.v1"`
|
||||
xxx_hidden_Allow *[]*TPM_Rule `protobuf:"bytes,1,rep,name=allow,proto3"`
|
||||
xxx_hidden_EkcertAllowedCas []string `protobuf:"bytes,2,rep,name=ekcert_allowed_cas,json=ekcertAllowedCas,proto3"`
|
||||
unknownFields protoimpl.UnknownFields
|
||||
sizeCache protoimpl.SizeCache
|
||||
}
|
||||
|
||||
func (x *TPM) Reset() {
|
||||
*x = TPM{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[20]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
|
||||
func (x *TPM) String() string {
|
||||
return protoimpl.X.MessageStringOf(x)
|
||||
}
|
||||
|
||||
func (*TPM) ProtoMessage() {}
|
||||
|
||||
func (x *TPM) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[20]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
return ms
|
||||
}
|
||||
return mi.MessageOf(x)
|
||||
}
|
||||
|
||||
func (x *TPM) GetAllow() []*TPM_Rule {
|
||||
if x != nil {
|
||||
if x.xxx_hidden_Allow != nil {
|
||||
return *x.xxx_hidden_Allow
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *TPM) GetEkcertAllowedCas() []string {
|
||||
if x != nil {
|
||||
return x.xxx_hidden_EkcertAllowedCas
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *TPM) SetAllow(v []*TPM_Rule) {
|
||||
x.xxx_hidden_Allow = &v
|
||||
}
|
||||
|
||||
func (x *TPM) SetEkcertAllowedCas(v []string) {
|
||||
x.xxx_hidden_EkcertAllowedCas = v
|
||||
}
|
||||
|
||||
type TPM_builder struct {
|
||||
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
|
||||
|
||||
// A list of Rules, the presented delegated identity must match one allow rule
|
||||
// to permit joining.
|
||||
Allow []*TPM_Rule
|
||||
// A list of CA certificates that will be used to validate TPM EKCerts.
|
||||
// When specified, joining TPMs must present an EKCert signed by one of the
|
||||
// specified CAs. TPMs that do not present an EKCert will be not permitted to
|
||||
// join.
|
||||
// When unspecified, TPMs will be allowed to join with either an EKCert or an
|
||||
// EKPubHash.
|
||||
EkcertAllowedCas []string
|
||||
}
|
||||
|
||||
func (b0 TPM_builder) Build() *TPM {
|
||||
m0 := &TPM{}
|
||||
b, x := &b0, m0
|
||||
_, _ = b, x
|
||||
x.xxx_hidden_Allow = &b.Allow
|
||||
x.xxx_hidden_EkcertAllowedCas = b.EkcertAllowedCas
|
||||
return m0
|
||||
}
|
||||
|
||||
// A rule that a joining node must match in order to use the associated token
|
||||
// with AWS join methods.
|
||||
type AWS_Rule struct {
|
||||
@@ -2710,7 +2818,7 @@ type AWS_Rule struct {
|
||||
|
||||
func (x *AWS_Rule) Reset() {
|
||||
*x = AWS_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[21]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -2722,7 +2830,7 @@ func (x *AWS_Rule) String() string {
|
||||
func (*AWS_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *AWS_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[21]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -2832,7 +2940,7 @@ type GCP_Rule struct {
|
||||
|
||||
func (x *GCP_Rule) Reset() {
|
||||
*x = GCP_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -2844,7 +2952,7 @@ func (x *GCP_Rule) String() string {
|
||||
func (*GCP_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *GCP_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[22]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -2922,7 +3030,7 @@ type Azure_Rule struct {
|
||||
|
||||
func (x *Azure_Rule) Reset() {
|
||||
*x = Azure_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -2934,7 +3042,7 @@ func (x *Azure_Rule) String() string {
|
||||
func (*Azure_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *Azure_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[23]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3017,7 +3125,7 @@ type AzureDevops_Rule struct {
|
||||
|
||||
func (x *AzureDevops_Rule) Reset() {
|
||||
*x = AzureDevops_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3029,7 +3137,7 @@ func (x *AzureDevops_Rule) String() string {
|
||||
func (*AzureDevops_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *AzureDevops_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[24]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3194,7 +3302,7 @@ type Oracle_Rule struct {
|
||||
|
||||
func (x *Oracle_Rule) Reset() {
|
||||
*x = Oracle_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3206,7 +3314,7 @@ func (x *Oracle_Rule) String() string {
|
||||
func (*Oracle_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *Oracle_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[25]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3298,7 +3406,7 @@ type Kubernetes_StaticJWKSConfig struct {
|
||||
|
||||
func (x *Kubernetes_StaticJWKSConfig) Reset() {
|
||||
*x = Kubernetes_StaticJWKSConfig{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3310,7 +3418,7 @@ func (x *Kubernetes_StaticJWKSConfig) String() string {
|
||||
func (*Kubernetes_StaticJWKSConfig) ProtoMessage() {}
|
||||
|
||||
func (x *Kubernetes_StaticJWKSConfig) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[26]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3359,7 +3467,7 @@ type Kubernetes_OIDCConfig struct {
|
||||
|
||||
func (x *Kubernetes_OIDCConfig) Reset() {
|
||||
*x = Kubernetes_OIDCConfig{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3371,7 +3479,7 @@ func (x *Kubernetes_OIDCConfig) String() string {
|
||||
func (*Kubernetes_OIDCConfig) ProtoMessage() {}
|
||||
|
||||
func (x *Kubernetes_OIDCConfig) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[27]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3440,7 +3548,7 @@ type Kubernetes_Rule struct {
|
||||
|
||||
func (x *Kubernetes_Rule) Reset() {
|
||||
*x = Kubernetes_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3452,7 +3560,7 @@ func (x *Kubernetes_Rule) String() string {
|
||||
func (*Kubernetes_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *Kubernetes_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[28]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3537,7 +3645,7 @@ type BoundKeypairSpec_OnboardingSpec struct {
|
||||
|
||||
func (x *BoundKeypairSpec_OnboardingSpec) Reset() {
|
||||
*x = BoundKeypairSpec_OnboardingSpec{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3549,7 +3657,7 @@ func (x *BoundKeypairSpec_OnboardingSpec) String() string {
|
||||
func (*BoundKeypairSpec_OnboardingSpec) ProtoMessage() {}
|
||||
|
||||
func (x *BoundKeypairSpec_OnboardingSpec) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[29]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3651,7 +3759,7 @@ type BoundKeypairSpec_RecoverySpec struct {
|
||||
|
||||
func (x *BoundKeypairSpec_RecoverySpec) Reset() {
|
||||
*x = BoundKeypairSpec_RecoverySpec{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3663,7 +3771,7 @@ func (x *BoundKeypairSpec_RecoverySpec) String() string {
|
||||
func (*BoundKeypairSpec_RecoverySpec) ProtoMessage() {}
|
||||
|
||||
func (x *BoundKeypairSpec_RecoverySpec) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[30]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3743,7 +3851,7 @@ type GenericOIDC_ConditionEq struct {
|
||||
|
||||
func (x *GenericOIDC_ConditionEq) Reset() {
|
||||
*x = GenericOIDC_ConditionEq{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3755,7 +3863,7 @@ func (x *GenericOIDC_ConditionEq) String() string {
|
||||
func (*GenericOIDC_ConditionEq) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_ConditionEq) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[31]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3802,7 +3910,7 @@ type GenericOIDC_ConditionNotEq struct {
|
||||
|
||||
func (x *GenericOIDC_ConditionNotEq) Reset() {
|
||||
*x = GenericOIDC_ConditionNotEq{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3814,7 +3922,7 @@ func (x *GenericOIDC_ConditionNotEq) String() string {
|
||||
func (*GenericOIDC_ConditionNotEq) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_ConditionNotEq) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[32]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3861,7 +3969,7 @@ type GenericOIDC_ConditionIn struct {
|
||||
|
||||
func (x *GenericOIDC_ConditionIn) Reset() {
|
||||
*x = GenericOIDC_ConditionIn{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3873,7 +3981,7 @@ func (x *GenericOIDC_ConditionIn) String() string {
|
||||
func (*GenericOIDC_ConditionIn) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_ConditionIn) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[33]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3920,7 +4028,7 @@ type GenericOIDC_ConditionNotIn struct {
|
||||
|
||||
func (x *GenericOIDC_ConditionNotIn) Reset() {
|
||||
*x = GenericOIDC_ConditionNotIn{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3932,7 +4040,7 @@ func (x *GenericOIDC_ConditionNotIn) String() string {
|
||||
func (*GenericOIDC_ConditionNotIn) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_ConditionNotIn) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[34]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -3983,7 +4091,7 @@ type GenericOIDC_Condition struct {
|
||||
|
||||
func (x *GenericOIDC_Condition) Reset() {
|
||||
*x = GenericOIDC_Condition{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -3995,7 +4103,7 @@ func (x *GenericOIDC_Condition) String() string {
|
||||
func (*GenericOIDC_Condition) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_Condition) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[35]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4145,7 +4253,7 @@ type GenericOIDC_Rule struct {
|
||||
|
||||
func (x *GenericOIDC_Rule) Reset() {
|
||||
*x = GenericOIDC_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4157,7 +4265,7 @@ func (x *GenericOIDC_Rule) String() string {
|
||||
func (*GenericOIDC_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *GenericOIDC_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[36]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4235,7 +4343,7 @@ type Github_Rule struct {
|
||||
|
||||
func (x *Github_Rule) Reset() {
|
||||
*x = Github_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4247,7 +4355,7 @@ func (x *Github_Rule) String() string {
|
||||
func (*Github_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *Github_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[37]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4470,7 +4578,7 @@ type GitLab_Rule struct {
|
||||
|
||||
func (x *GitLab_Rule) Reset() {
|
||||
*x = GitLab_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[39]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -4482,7 +4590,7 @@ func (x *GitLab_Rule) String() string {
|
||||
func (*GitLab_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *GitLab_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[38]
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[39]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -4792,6 +4900,105 @@ func (b0 GitLab_Rule_builder) Build() *GitLab_Rule {
|
||||
return m0
|
||||
}
|
||||
|
||||
// A rule for TPM joining tokens, of which one must match for a join attempt
|
||||
// to be allowed.
|
||||
type TPM_Rule struct {
|
||||
state protoimpl.MessageState `protogen:"opaque.v1"`
|
||||
xxx_hidden_Description string `protobuf:"bytes,1,opt,name=description,proto3"`
|
||||
xxx_hidden_EkPublicHash string `protobuf:"bytes,2,opt,name=ek_public_hash,json=ekPublicHash,proto3"`
|
||||
xxx_hidden_EkCertificateSerial string `protobuf:"bytes,3,opt,name=ek_certificate_serial,json=ekCertificateSerial,proto3"`
|
||||
unknownFields protoimpl.UnknownFields
|
||||
sizeCache protoimpl.SizeCache
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) Reset() {
|
||||
*x = TPM_Rule{}
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[40]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) String() string {
|
||||
return protoimpl.X.MessageStringOf(x)
|
||||
}
|
||||
|
||||
func (*TPM_Rule) ProtoMessage() {}
|
||||
|
||||
func (x *TPM_Rule) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_teleport_scopes_joining_v1_token_proto_msgTypes[40]
|
||||
if x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
return ms
|
||||
}
|
||||
return mi.MessageOf(x)
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) GetDescription() string {
|
||||
if x != nil {
|
||||
return x.xxx_hidden_Description
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) GetEkPublicHash() string {
|
||||
if x != nil {
|
||||
return x.xxx_hidden_EkPublicHash
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) GetEkCertificateSerial() string {
|
||||
if x != nil {
|
||||
return x.xxx_hidden_EkCertificateSerial
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) SetDescription(v string) {
|
||||
x.xxx_hidden_Description = v
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) SetEkPublicHash(v string) {
|
||||
x.xxx_hidden_EkPublicHash = v
|
||||
}
|
||||
|
||||
func (x *TPM_Rule) SetEkCertificateSerial(v string) {
|
||||
x.xxx_hidden_EkCertificateSerial = v
|
||||
}
|
||||
|
||||
type TPM_Rule_builder struct {
|
||||
_ [0]func() // Prevents comparability and use of unkeyed literals for the builder.
|
||||
|
||||
// A human-readable description of the rule. It has no bearing on whether or
|
||||
// not a TPM is allowed to join, but can be used to associate a rule with a
|
||||
// specific host (e.g the asset tag of the server in which the TPM resides).
|
||||
// Example: "build-server-100"
|
||||
Description string
|
||||
// The SHA256 hash of the EKPub marshaled in PKIX format and encoded in
|
||||
// hexadecimal. This value will also be checked when a TPM has submitted an
|
||||
// EKCert, and the public key in the EKCert will be used for this check.
|
||||
// Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
|
||||
EkPublicHash string
|
||||
// The serial number of the EKCert in hexadecimal with colon separated
|
||||
// nibbles. This value will not be checked when a TPM does not have an
|
||||
// EKCert configured.
|
||||
// Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
|
||||
EkCertificateSerial string
|
||||
}
|
||||
|
||||
func (b0 TPM_Rule_builder) Build() *TPM_Rule {
|
||||
m0 := &TPM_Rule{}
|
||||
b, x := &b0, m0
|
||||
_, _ = b, x
|
||||
x.xxx_hidden_Description = b.Description
|
||||
x.xxx_hidden_EkPublicHash = b.EkPublicHash
|
||||
x.xxx_hidden_EkCertificateSerial = b.EkCertificateSerial
|
||||
return m0
|
||||
}
|
||||
|
||||
var File_teleport_scopes_joining_v1_token_proto protoreflect.FileDescriptor
|
||||
|
||||
const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
|
||||
@@ -4804,7 +5011,7 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
|
||||
"\bmetadata\x18\x04 \x01(\v2\x1c.teleport.header.v1.MetadataR\bmetadata\x12\x14\n" +
|
||||
"\x05scope\x18\x05 \x01(\tR\x05scope\x12?\n" +
|
||||
"\x04spec\x18\x06 \x01(\v2+.teleport.scopes.joining.v1.ScopedTokenSpecR\x04spec\x12E\n" +
|
||||
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\x9f\a\n" +
|
||||
"\x06status\x18\a \x01(\v2-.teleport.scopes.joining.v1.ScopedTokenStatusR\x06status\"\xd2\a\n" +
|
||||
"\x0fScopedTokenSpec\x12%\n" +
|
||||
"\x0eassigned_scope\x18\x01 \x01(\tR\rassignedScope\x12\x14\n" +
|
||||
"\x05roles\x18\x02 \x03(\tR\x05roles\x12\x1f\n" +
|
||||
@@ -4826,7 +5033,8 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
|
||||
"\x03bot\x18\x0f \x01(\tR\x03bot\x12J\n" +
|
||||
"\fgeneric_oidc\x18\x10 \x01(\v2'.teleport.scopes.joining.v1.GenericOIDCR\vgenericOidc\x12:\n" +
|
||||
"\x06github\x18\x11 \x01(\v2\".teleport.scopes.joining.v1.GithubR\x06github\x12:\n" +
|
||||
"\x06gitlab\x18\x12 \x01(\v2\".teleport.scopes.joining.v1.GitLabR\x06gitlabJ\x04\b\r\x10\x0eJ\x04\b\x0e\x10\x0fR\bbot_nameR\tbot_scope\"\xb6\x01\n" +
|
||||
"\x06gitlab\x18\x12 \x01(\v2\".teleport.scopes.joining.v1.GitLabR\x06gitlab\x121\n" +
|
||||
"\x03tpm\x18\x13 \x01(\v2\x1f.teleport.scopes.joining.v1.TPMR\x03tpmJ\x04\b\r\x10\x0eJ\x04\b\x0e\x10\x0fR\bbot_nameR\tbot_scope\"\xb6\x01\n" +
|
||||
"\x0eHostCertParams\x12\x17\n" +
|
||||
"\ahost_id\x18\x01 \x01(\tR\x06hostId\x12\x1b\n" +
|
||||
"\tnode_name\x18\x02 \x01(\tR\bnodeName\x12\x12\n" +
|
||||
@@ -5021,9 +5229,16 @@ const file_teleport_scopes_joining_v1_token_proto_rawDesc = "" +
|
||||
"\x0fdeployment_tier\x18\x0f \x01(\tR\x0edeploymentTier\x12-\n" +
|
||||
"\x12project_visibility\x18\x10 \x01(\tR\x11projectVisibilityB\x10\n" +
|
||||
"\x0e_ref_protectedB\x18\n" +
|
||||
"\x16_environment_protectedBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
|
||||
"\x16_environment_protected\"\xf4\x01\n" +
|
||||
"\x03TPM\x12:\n" +
|
||||
"\x05allow\x18\x01 \x03(\v2$.teleport.scopes.joining.v1.TPM.RuleR\x05allow\x12,\n" +
|
||||
"\x12ekcert_allowed_cas\x18\x02 \x03(\tR\x10ekcertAllowedCas\x1a\x82\x01\n" +
|
||||
"\x04Rule\x12 \n" +
|
||||
"\vdescription\x18\x01 \x01(\tR\vdescription\x12$\n" +
|
||||
"\x0eek_public_hash\x18\x02 \x01(\tR\fekPublicHash\x122\n" +
|
||||
"\x15ek_certificate_serial\x18\x03 \x01(\tR\x13ekCertificateSerialBYZWgithub.com/gravitational/teleport/api/gen/proto/go/teleport/scopes/joining/v1;joiningv1b\x06proto3"
|
||||
|
||||
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 39)
|
||||
var file_teleport_scopes_joining_v1_token_proto_msgTypes = make([]protoimpl.MessageInfo, 41)
|
||||
var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
|
||||
(*ScopedToken)(nil), // 0: teleport.scopes.joining.v1.ScopedToken
|
||||
(*ScopedTokenSpec)(nil), // 1: teleport.scopes.joining.v1.ScopedTokenSpec
|
||||
@@ -5045,31 +5260,33 @@ var file_teleport_scopes_joining_v1_token_proto_goTypes = []any{
|
||||
(*GenericOIDC)(nil), // 17: teleport.scopes.joining.v1.GenericOIDC
|
||||
(*Github)(nil), // 18: teleport.scopes.joining.v1.Github
|
||||
(*GitLab)(nil), // 19: teleport.scopes.joining.v1.GitLab
|
||||
nil, // 20: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
|
||||
(*AWS_Rule)(nil), // 21: teleport.scopes.joining.v1.AWS.Rule
|
||||
(*GCP_Rule)(nil), // 22: teleport.scopes.joining.v1.GCP.Rule
|
||||
(*Azure_Rule)(nil), // 23: teleport.scopes.joining.v1.Azure.Rule
|
||||
(*AzureDevops_Rule)(nil), // 24: teleport.scopes.joining.v1.AzureDevops.Rule
|
||||
(*Oracle_Rule)(nil), // 25: teleport.scopes.joining.v1.Oracle.Rule
|
||||
(*Kubernetes_StaticJWKSConfig)(nil), // 26: teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
|
||||
(*Kubernetes_OIDCConfig)(nil), // 27: teleport.scopes.joining.v1.Kubernetes.OIDCConfig
|
||||
(*Kubernetes_Rule)(nil), // 28: teleport.scopes.joining.v1.Kubernetes.Rule
|
||||
(*BoundKeypairSpec_OnboardingSpec)(nil), // 29: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
|
||||
(*BoundKeypairSpec_RecoverySpec)(nil), // 30: teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
|
||||
(*GenericOIDC_ConditionEq)(nil), // 31: teleport.scopes.joining.v1.GenericOIDC.ConditionEq
|
||||
(*GenericOIDC_ConditionNotEq)(nil), // 32: teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
|
||||
(*GenericOIDC_ConditionIn)(nil), // 33: teleport.scopes.joining.v1.GenericOIDC.ConditionIn
|
||||
(*GenericOIDC_ConditionNotIn)(nil), // 34: teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
|
||||
(*GenericOIDC_Condition)(nil), // 35: teleport.scopes.joining.v1.GenericOIDC.Condition
|
||||
(*GenericOIDC_Rule)(nil), // 36: teleport.scopes.joining.v1.GenericOIDC.Rule
|
||||
(*Github_Rule)(nil), // 37: teleport.scopes.joining.v1.Github.Rule
|
||||
(*GitLab_Rule)(nil), // 38: teleport.scopes.joining.v1.GitLab.Rule
|
||||
(*v1.Metadata)(nil), // 39: teleport.header.v1.Metadata
|
||||
(*timestamppb.Timestamp)(nil), // 40: google.protobuf.Timestamp
|
||||
(*structpb.Struct)(nil), // 41: google.protobuf.Struct
|
||||
(*TPM)(nil), // 20: teleport.scopes.joining.v1.TPM
|
||||
nil, // 21: teleport.scopes.joining.v1.ImmutableLabels.SshEntry
|
||||
(*AWS_Rule)(nil), // 22: teleport.scopes.joining.v1.AWS.Rule
|
||||
(*GCP_Rule)(nil), // 23: teleport.scopes.joining.v1.GCP.Rule
|
||||
(*Azure_Rule)(nil), // 24: teleport.scopes.joining.v1.Azure.Rule
|
||||
(*AzureDevops_Rule)(nil), // 25: teleport.scopes.joining.v1.AzureDevops.Rule
|
||||
(*Oracle_Rule)(nil), // 26: teleport.scopes.joining.v1.Oracle.Rule
|
||||
(*Kubernetes_StaticJWKSConfig)(nil), // 27: teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
|
||||
(*Kubernetes_OIDCConfig)(nil), // 28: teleport.scopes.joining.v1.Kubernetes.OIDCConfig
|
||||
(*Kubernetes_Rule)(nil), // 29: teleport.scopes.joining.v1.Kubernetes.Rule
|
||||
(*BoundKeypairSpec_OnboardingSpec)(nil), // 30: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
|
||||
(*BoundKeypairSpec_RecoverySpec)(nil), // 31: teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
|
||||
(*GenericOIDC_ConditionEq)(nil), // 32: teleport.scopes.joining.v1.GenericOIDC.ConditionEq
|
||||
(*GenericOIDC_ConditionNotEq)(nil), // 33: teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
|
||||
(*GenericOIDC_ConditionIn)(nil), // 34: teleport.scopes.joining.v1.GenericOIDC.ConditionIn
|
||||
(*GenericOIDC_ConditionNotIn)(nil), // 35: teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
|
||||
(*GenericOIDC_Condition)(nil), // 36: teleport.scopes.joining.v1.GenericOIDC.Condition
|
||||
(*GenericOIDC_Rule)(nil), // 37: teleport.scopes.joining.v1.GenericOIDC.Rule
|
||||
(*Github_Rule)(nil), // 38: teleport.scopes.joining.v1.Github.Rule
|
||||
(*GitLab_Rule)(nil), // 39: teleport.scopes.joining.v1.GitLab.Rule
|
||||
(*TPM_Rule)(nil), // 40: teleport.scopes.joining.v1.TPM.Rule
|
||||
(*v1.Metadata)(nil), // 41: teleport.header.v1.Metadata
|
||||
(*timestamppb.Timestamp)(nil), // 42: google.protobuf.Timestamp
|
||||
(*structpb.Struct)(nil), // 43: google.protobuf.Struct
|
||||
}
|
||||
var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
|
||||
39, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
|
||||
41, // 0: teleport.scopes.joining.v1.ScopedToken.metadata:type_name -> teleport.header.v1.Metadata
|
||||
1, // 1: teleport.scopes.joining.v1.ScopedToken.spec:type_name -> teleport.scopes.joining.v1.ScopedTokenSpec
|
||||
5, // 2: teleport.scopes.joining.v1.ScopedToken.status:type_name -> teleport.scopes.joining.v1.ScopedTokenStatus
|
||||
6, // 3: teleport.scopes.joining.v1.ScopedTokenSpec.immutable_labels:type_name -> teleport.scopes.joining.v1.ImmutableLabels
|
||||
@@ -5083,44 +5300,46 @@ var file_teleport_scopes_joining_v1_token_proto_depIdxs = []int32{
|
||||
17, // 11: teleport.scopes.joining.v1.ScopedTokenSpec.generic_oidc:type_name -> teleport.scopes.joining.v1.GenericOIDC
|
||||
18, // 12: teleport.scopes.joining.v1.ScopedTokenSpec.github:type_name -> teleport.scopes.joining.v1.Github
|
||||
19, // 13: teleport.scopes.joining.v1.ScopedTokenSpec.gitlab:type_name -> teleport.scopes.joining.v1.GitLab
|
||||
40, // 14: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
|
||||
40, // 15: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
|
||||
2, // 16: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
|
||||
3, // 17: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
|
||||
16, // 18: teleport.scopes.joining.v1.UsageStatus.bound_keypair:type_name -> teleport.scopes.joining.v1.BoundKeypairStatus
|
||||
4, // 19: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
|
||||
20, // 20: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
|
||||
39, // 21: teleport.scopes.joining.v1.StaticScopedTokens.metadata:type_name -> teleport.header.v1.Metadata
|
||||
8, // 22: teleport.scopes.joining.v1.StaticScopedTokens.spec:type_name -> teleport.scopes.joining.v1.StaticScopedTokensSpec
|
||||
0, // 23: teleport.scopes.joining.v1.StaticScopedTokensSpec.tokens:type_name -> teleport.scopes.joining.v1.ScopedToken
|
||||
21, // 24: teleport.scopes.joining.v1.AWS.allow:type_name -> teleport.scopes.joining.v1.AWS.Rule
|
||||
22, // 25: teleport.scopes.joining.v1.GCP.allow:type_name -> teleport.scopes.joining.v1.GCP.Rule
|
||||
23, // 26: teleport.scopes.joining.v1.Azure.allow:type_name -> teleport.scopes.joining.v1.Azure.Rule
|
||||
24, // 27: teleport.scopes.joining.v1.AzureDevops.allow:type_name -> teleport.scopes.joining.v1.AzureDevops.Rule
|
||||
25, // 28: teleport.scopes.joining.v1.Oracle.allow:type_name -> teleport.scopes.joining.v1.Oracle.Rule
|
||||
28, // 29: teleport.scopes.joining.v1.Kubernetes.allow:type_name -> teleport.scopes.joining.v1.Kubernetes.Rule
|
||||
26, // 30: teleport.scopes.joining.v1.Kubernetes.static_jwks:type_name -> teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
|
||||
27, // 31: teleport.scopes.joining.v1.Kubernetes.oidc:type_name -> teleport.scopes.joining.v1.Kubernetes.OIDCConfig
|
||||
29, // 32: teleport.scopes.joining.v1.BoundKeypairSpec.onboarding:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
|
||||
30, // 33: teleport.scopes.joining.v1.BoundKeypairSpec.recovery:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
|
||||
40, // 34: teleport.scopes.joining.v1.BoundKeypairSpec.rotate_after:type_name -> google.protobuf.Timestamp
|
||||
40, // 35: teleport.scopes.joining.v1.BoundKeypairStatus.last_recovered_at:type_name -> google.protobuf.Timestamp
|
||||
40, // 36: teleport.scopes.joining.v1.BoundKeypairStatus.last_rotated_at:type_name -> google.protobuf.Timestamp
|
||||
41, // 37: teleport.scopes.joining.v1.GenericOIDC.must_match_fields:type_name -> google.protobuf.Struct
|
||||
36, // 38: teleport.scopes.joining.v1.GenericOIDC.allow_any:type_name -> teleport.scopes.joining.v1.GenericOIDC.Rule
|
||||
37, // 39: teleport.scopes.joining.v1.Github.allow:type_name -> teleport.scopes.joining.v1.Github.Rule
|
||||
38, // 40: teleport.scopes.joining.v1.GitLab.allow:type_name -> teleport.scopes.joining.v1.GitLab.Rule
|
||||
40, // 41: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec.must_register_before:type_name -> google.protobuf.Timestamp
|
||||
31, // 42: teleport.scopes.joining.v1.GenericOIDC.Condition.eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionEq
|
||||
32, // 43: teleport.scopes.joining.v1.GenericOIDC.Condition.not_eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
|
||||
33, // 44: teleport.scopes.joining.v1.GenericOIDC.Condition.in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionIn
|
||||
34, // 45: teleport.scopes.joining.v1.GenericOIDC.Condition.not_in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
|
||||
35, // 46: teleport.scopes.joining.v1.GenericOIDC.Rule.conditions:type_name -> teleport.scopes.joining.v1.GenericOIDC.Condition
|
||||
47, // [47:47] is the sub-list for method output_type
|
||||
47, // [47:47] is the sub-list for method input_type
|
||||
47, // [47:47] is the sub-list for extension type_name
|
||||
47, // [47:47] is the sub-list for extension extendee
|
||||
0, // [0:47] is the sub-list for field type_name
|
||||
20, // 14: teleport.scopes.joining.v1.ScopedTokenSpec.tpm:type_name -> teleport.scopes.joining.v1.TPM
|
||||
42, // 15: teleport.scopes.joining.v1.SingleUseStatus.used_at:type_name -> google.protobuf.Timestamp
|
||||
42, // 16: teleport.scopes.joining.v1.SingleUseStatus.reusable_until:type_name -> google.protobuf.Timestamp
|
||||
2, // 17: teleport.scopes.joining.v1.SingleUseStatus.host_cert_params:type_name -> teleport.scopes.joining.v1.HostCertParams
|
||||
3, // 18: teleport.scopes.joining.v1.UsageStatus.single_use:type_name -> teleport.scopes.joining.v1.SingleUseStatus
|
||||
16, // 19: teleport.scopes.joining.v1.UsageStatus.bound_keypair:type_name -> teleport.scopes.joining.v1.BoundKeypairStatus
|
||||
4, // 20: teleport.scopes.joining.v1.ScopedTokenStatus.usage:type_name -> teleport.scopes.joining.v1.UsageStatus
|
||||
21, // 21: teleport.scopes.joining.v1.ImmutableLabels.ssh:type_name -> teleport.scopes.joining.v1.ImmutableLabels.SshEntry
|
||||
41, // 22: teleport.scopes.joining.v1.StaticScopedTokens.metadata:type_name -> teleport.header.v1.Metadata
|
||||
8, // 23: teleport.scopes.joining.v1.StaticScopedTokens.spec:type_name -> teleport.scopes.joining.v1.StaticScopedTokensSpec
|
||||
0, // 24: teleport.scopes.joining.v1.StaticScopedTokensSpec.tokens:type_name -> teleport.scopes.joining.v1.ScopedToken
|
||||
22, // 25: teleport.scopes.joining.v1.AWS.allow:type_name -> teleport.scopes.joining.v1.AWS.Rule
|
||||
23, // 26: teleport.scopes.joining.v1.GCP.allow:type_name -> teleport.scopes.joining.v1.GCP.Rule
|
||||
24, // 27: teleport.scopes.joining.v1.Azure.allow:type_name -> teleport.scopes.joining.v1.Azure.Rule
|
||||
25, // 28: teleport.scopes.joining.v1.AzureDevops.allow:type_name -> teleport.scopes.joining.v1.AzureDevops.Rule
|
||||
26, // 29: teleport.scopes.joining.v1.Oracle.allow:type_name -> teleport.scopes.joining.v1.Oracle.Rule
|
||||
29, // 30: teleport.scopes.joining.v1.Kubernetes.allow:type_name -> teleport.scopes.joining.v1.Kubernetes.Rule
|
||||
27, // 31: teleport.scopes.joining.v1.Kubernetes.static_jwks:type_name -> teleport.scopes.joining.v1.Kubernetes.StaticJWKSConfig
|
||||
28, // 32: teleport.scopes.joining.v1.Kubernetes.oidc:type_name -> teleport.scopes.joining.v1.Kubernetes.OIDCConfig
|
||||
30, // 33: teleport.scopes.joining.v1.BoundKeypairSpec.onboarding:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec
|
||||
31, // 34: teleport.scopes.joining.v1.BoundKeypairSpec.recovery:type_name -> teleport.scopes.joining.v1.BoundKeypairSpec.RecoverySpec
|
||||
42, // 35: teleport.scopes.joining.v1.BoundKeypairSpec.rotate_after:type_name -> google.protobuf.Timestamp
|
||||
42, // 36: teleport.scopes.joining.v1.BoundKeypairStatus.last_recovered_at:type_name -> google.protobuf.Timestamp
|
||||
42, // 37: teleport.scopes.joining.v1.BoundKeypairStatus.last_rotated_at:type_name -> google.protobuf.Timestamp
|
||||
43, // 38: teleport.scopes.joining.v1.GenericOIDC.must_match_fields:type_name -> google.protobuf.Struct
|
||||
37, // 39: teleport.scopes.joining.v1.GenericOIDC.allow_any:type_name -> teleport.scopes.joining.v1.GenericOIDC.Rule
|
||||
38, // 40: teleport.scopes.joining.v1.Github.allow:type_name -> teleport.scopes.joining.v1.Github.Rule
|
||||
39, // 41: teleport.scopes.joining.v1.GitLab.allow:type_name -> teleport.scopes.joining.v1.GitLab.Rule
|
||||
40, // 42: teleport.scopes.joining.v1.TPM.allow:type_name -> teleport.scopes.joining.v1.TPM.Rule
|
||||
42, // 43: teleport.scopes.joining.v1.BoundKeypairSpec.OnboardingSpec.must_register_before:type_name -> google.protobuf.Timestamp
|
||||
32, // 44: teleport.scopes.joining.v1.GenericOIDC.Condition.eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionEq
|
||||
33, // 45: teleport.scopes.joining.v1.GenericOIDC.Condition.not_eq:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotEq
|
||||
34, // 46: teleport.scopes.joining.v1.GenericOIDC.Condition.in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionIn
|
||||
35, // 47: teleport.scopes.joining.v1.GenericOIDC.Condition.not_in:type_name -> teleport.scopes.joining.v1.GenericOIDC.ConditionNotIn
|
||||
36, // 48: teleport.scopes.joining.v1.GenericOIDC.Rule.conditions:type_name -> teleport.scopes.joining.v1.GenericOIDC.Condition
|
||||
49, // [49:49] is the sub-list for method output_type
|
||||
49, // [49:49] is the sub-list for method input_type
|
||||
49, // [49:49] is the sub-list for extension type_name
|
||||
49, // [49:49] is the sub-list for extension extendee
|
||||
0, // [0:49] is the sub-list for field type_name
|
||||
}
|
||||
|
||||
func init() { file_teleport_scopes_joining_v1_token_proto_init() }
|
||||
@@ -5132,14 +5351,14 @@ func file_teleport_scopes_joining_v1_token_proto_init() {
|
||||
(*usageStatus_SingleUse)(nil),
|
||||
(*usageStatus_BoundKeypair)(nil),
|
||||
}
|
||||
file_teleport_scopes_joining_v1_token_proto_msgTypes[38].OneofWrappers = []any{}
|
||||
file_teleport_scopes_joining_v1_token_proto_msgTypes[39].OneofWrappers = []any{}
|
||||
type x struct{}
|
||||
out := protoimpl.TypeBuilder{
|
||||
File: protoimpl.DescBuilder{
|
||||
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
|
||||
RawDescriptor: unsafe.Slice(unsafe.StringData(file_teleport_scopes_joining_v1_token_proto_rawDesc), len(file_teleport_scopes_joining_v1_token_proto_rawDesc)),
|
||||
NumEnums: 0,
|
||||
NumMessages: 39,
|
||||
NumMessages: 41,
|
||||
NumExtensions: 0,
|
||||
NumServices: 0,
|
||||
},
|
||||
|
||||
@@ -114,6 +114,9 @@ message ScopedTokenSpec {
|
||||
|
||||
// Configuration specific to the "gitlab" join method.
|
||||
GitLab gitlab = 18;
|
||||
|
||||
// Configuration specific to the "tpm" join method.
|
||||
TPM tpm = 19;
|
||||
}
|
||||
|
||||
// The host certificate parameters that should be cached and leveraged for
|
||||
@@ -844,3 +847,40 @@ message GitLab {
|
||||
string project_visibility = 16;
|
||||
}
|
||||
}
|
||||
|
||||
// Configuration specific to TPM tokens.
|
||||
message TPM {
|
||||
// A rule for TPM joining tokens, of which one must match for a join attempt
|
||||
// to be allowed.
|
||||
message Rule {
|
||||
// A human-readable description of the rule. It has no bearing on whether or
|
||||
// not a TPM is allowed to join, but can be used to associate a rule with a
|
||||
// specific host (e.g the asset tag of the server in which the TPM resides).
|
||||
// Example: "build-server-100"
|
||||
string description = 1;
|
||||
|
||||
// The SHA256 hash of the EKPub marshaled in PKIX format and encoded in
|
||||
// hexadecimal. This value will also be checked when a TPM has submitted an
|
||||
// EKCert, and the public key in the EKCert will be used for this check.
|
||||
// Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
|
||||
string ek_public_hash = 2;
|
||||
|
||||
// The serial number of the EKCert in hexadecimal with colon separated
|
||||
// nibbles. This value will not be checked when a TPM does not have an
|
||||
// EKCert configured.
|
||||
// Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
|
||||
string ek_certificate_serial = 3;
|
||||
}
|
||||
|
||||
// A list of Rules, the presented delegated identity must match one allow rule
|
||||
// to permit joining.
|
||||
repeated Rule allow = 1;
|
||||
|
||||
// A list of CA certificates that will be used to validate TPM EKCerts.
|
||||
// When specified, joining TPMs must present an EKCert signed by one of the
|
||||
// specified CAs. TPMs that do not present an EKCert will be not permitted to
|
||||
// join.
|
||||
// When unspecified, TPMs will be allowed to join with either an EKCert or an
|
||||
// EKPubHash.
|
||||
repeated string ekcert_allowed_cas = 2;
|
||||
}
|
||||
|
||||
@@ -182,6 +182,8 @@ type ProvisionToken interface {
|
||||
GetGithub() *ProvisionTokenSpecV2GitHub
|
||||
// GetGitLab returns gitlab-specific configuration for this token.
|
||||
GetGitLab() *ProvisionTokenSpecV2GitLab
|
||||
// GetTPM returns the TPM-specific configuration for this token.
|
||||
GetTPM() *ProvisionTokenSpecV2TPM
|
||||
// GetAWSIIDTTL returns the TTL of EC2 IIDs
|
||||
GetAWSIIDTTL() Duration
|
||||
// GetJoinMethod returns joining method that must be used with this token.
|
||||
@@ -635,6 +637,11 @@ func (p *ProvisionTokenV2) GetGitLab() *ProvisionTokenSpecV2GitLab {
|
||||
return p.Spec.GitLab
|
||||
}
|
||||
|
||||
// GetTPM returns the TPM-specific configuration for this token.
|
||||
func (p *ProvisionTokenV2) GetTPM() *ProvisionTokenSpecV2TPM {
|
||||
return p.Spec.TPM
|
||||
}
|
||||
|
||||
// GetJoinMethod returns joining method that must be used with this token.
|
||||
func (p *ProvisionTokenV2) GetJoinMethod() JoinMethod {
|
||||
return p.Spec.JoinMethod
|
||||
|
||||
+16
@@ -46,6 +46,7 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|
||||
|kubernetes|[object](#speckubernetes)|The Kubernetes-specific configuration used with the "kubernetes" join method.|
|
||||
|oracle|[object](#specoracle)|The Oracle-specific configuration used with the "oracle" join method.|
|
||||
|roles|[]string|The list of roles associated with the token. They will be converted to metadata in the SSH and X509 certificates issued to the user of the token.|
|
||||
|tpm|[object](#spectpm)|Configuration specific to the "tpm" join method.|
|
||||
|usage_mode|string|The usage mode of the token. Can be "single_use" or "unlimited". Single use tokens can only be used to provision a single resource. Unlimited tokens can be be used to provision any number of resources until it expires.|
|
||||
|
||||
### spec.aws
|
||||
@@ -301,3 +302,18 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|
||||
|regions|[]string||
|
||||
|tenancy|string||
|
||||
|
||||
### spec.tpm
|
||||
|
||||
|Field|Type|Description|
|
||||
|---|---|---|
|
||||
|allow|[][object](#spectpmallow-items)|A list of Rules, the presented delegated identity must match one allow rule to permit joining.|
|
||||
|ekcert_allowed_cas|[]string|A list of CA certificates that will be used to validate TPM EKCerts. When specified, joining TPMs must present an EKCert signed by one of the specified CAs. TPMs that do not present an EKCert will be not permitted to join. When unspecified, TPMs will be allowed to join with either an EKCert or an EKPubHash.|
|
||||
|
||||
### spec.tpm.allow items
|
||||
|
||||
|Field|Type|Description|
|
||||
|---|---|---|
|
||||
|description|string||
|
||||
|ek_certificate_serial|string||
|
||||
|ek_public_hash|string||
|
||||
|
||||
|
||||
+18
@@ -69,6 +69,7 @@ Optional:
|
||||
- `immutable_labels` (Attributes) Immutable labels that should be applied to any resulting resources provisioned using this token. (see [below for nested schema](#nested-schema-for-specimmutable_labels))
|
||||
- `kubernetes` (Attributes) The Kubernetes-specific configuration used with the "kubernetes" join method. (see [below for nested schema](#nested-schema-for-speckubernetes))
|
||||
- `oracle` (Attributes) The Oracle-specific configuration used with the "oracle" join method. (see [below for nested schema](#nested-schema-for-specoracle))
|
||||
- `tpm` (Attributes) Configuration specific to the "tpm" join method. (see [below for nested schema](#nested-schema-for-spectpm))
|
||||
|
||||
### Nested Schema for `spec.aws`
|
||||
|
||||
@@ -342,3 +343,20 @@ Optional:
|
||||
- `regions` (List of String) A list of regions an instance is allowed to join from. Both full region names ("us-phoenix-1") and abbreviations ("phx") are allowed. If empty, any region is allowed.
|
||||
- `tenancy` (String) The OCID of the instance's tenancy. Required.
|
||||
|
||||
|
||||
|
||||
### Nested Schema for `spec.tpm`
|
||||
|
||||
Optional:
|
||||
|
||||
- `allow` (Attributes List) A list of Rules, the presented delegated identity must match one allow rule to permit joining. (see [below for nested schema](#nested-schema-for-spectpmallow))
|
||||
- `ekcert_allowed_cas` (List of String) A list of CA certificates that will be used to validate TPM EKCerts. When specified, joining TPMs must present an EKCert signed by one of the specified CAs. TPMs that do not present an EKCert will be not permitted to join. When unspecified, TPMs will be allowed to join with either an EKCert or an EKPubHash.
|
||||
|
||||
### Nested Schema for `spec.tpm.allow`
|
||||
|
||||
Optional:
|
||||
|
||||
- `description` (String) A human-readable description of the rule. It has no bearing on whether or not a TPM is allowed to join, but can be used to associate a rule with a specific host (e.g the asset tag of the server in which the TPM resides). Example: "build-server-100"
|
||||
- `ek_certificate_serial` (String) The serial number of the EKCert in hexadecimal with colon separated nibbles. This value will not be checked when a TPM does not have an EKCert configured. Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
|
||||
- `ek_public_hash` (String) The SHA256 hash of the EKPub marshaled in PKIX format and encoded in hexadecimal. This value will also be checked when a TPM has submitted an EKCert, and the public key in the EKCert will be used for this check. Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
|
||||
|
||||
|
||||
+18
@@ -113,6 +113,7 @@ Optional:
|
||||
- `immutable_labels` (Attributes) Immutable labels that should be applied to any resulting resources provisioned using this token. (see [below for nested schema](#nested-schema-for-specimmutable_labels))
|
||||
- `kubernetes` (Attributes) The Kubernetes-specific configuration used with the "kubernetes" join method. (see [below for nested schema](#nested-schema-for-speckubernetes))
|
||||
- `oracle` (Attributes) The Oracle-specific configuration used with the "oracle" join method. (see [below for nested schema](#nested-schema-for-specoracle))
|
||||
- `tpm` (Attributes) Configuration specific to the "tpm" join method. (see [below for nested schema](#nested-schema-for-spectpm))
|
||||
|
||||
### Nested Schema for `spec.aws`
|
||||
|
||||
@@ -385,3 +386,20 @@ Optional:
|
||||
- `parent_compartments` (List of String) A list of the OCIDs of compartments an instance is allowed to join from. Only direct parents are allowed, i.e. no nested compartments. If empty, any compartment is allowed.
|
||||
- `regions` (List of String) A list of regions an instance is allowed to join from. Both full region names ("us-phoenix-1") and abbreviations ("phx") are allowed. If empty, any region is allowed.
|
||||
- `tenancy` (String) The OCID of the instance's tenancy. Required.
|
||||
|
||||
|
||||
|
||||
### Nested Schema for `spec.tpm`
|
||||
|
||||
Optional:
|
||||
|
||||
- `allow` (Attributes List) A list of Rules, the presented delegated identity must match one allow rule to permit joining. (see [below for nested schema](#nested-schema-for-spectpmallow))
|
||||
- `ekcert_allowed_cas` (List of String) A list of CA certificates that will be used to validate TPM EKCerts. When specified, joining TPMs must present an EKCert signed by one of the specified CAs. TPMs that do not present an EKCert will be not permitted to join. When unspecified, TPMs will be allowed to join with either an EKCert or an EKPubHash.
|
||||
|
||||
### Nested Schema for `spec.tpm.allow`
|
||||
|
||||
Optional:
|
||||
|
||||
- `description` (String) A human-readable description of the rule. It has no bearing on whether or not a TPM is allowed to join, but can be used to associate a rule with a specific host (e.g the asset tag of the server in which the TPM resides). Example: "build-server-100"
|
||||
- `ek_certificate_serial` (String) The serial number of the EKCert in hexadecimal with colon separated nibbles. This value will not be checked when a TPM does not have an EKCert configured. Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4
|
||||
- `ek_public_hash` (String) The SHA256 hash of the EKPub marshaled in PKIX format and encoded in hexadecimal. This value will also be checked when a TPM has submitted an EKCert, and the public key in the EKCert will be used for this check. Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6
|
||||
|
||||
+29
@@ -567,6 +567,35 @@ spec:
|
||||
type: string
|
||||
nullable: true
|
||||
type: array
|
||||
tpm:
|
||||
description: Configuration specific to the "tpm" join method.
|
||||
nullable: true
|
||||
properties:
|
||||
allow:
|
||||
description: A list of Rules, the presented delegated identity
|
||||
must match one allow rule to permit joining.
|
||||
items:
|
||||
properties:
|
||||
description:
|
||||
type: string
|
||||
ek_certificate_serial:
|
||||
type: string
|
||||
ek_public_hash:
|
||||
type: string
|
||||
type: object
|
||||
nullable: true
|
||||
type: array
|
||||
ekcert_allowed_cas:
|
||||
description: A list of CA certificates that will be used to validate
|
||||
TPM EKCerts. When specified, joining TPMs must present an EKCert
|
||||
signed by one of the specified CAs. TPMs that do not present
|
||||
an EKCert will be not permitted to join. When unspecified, TPMs
|
||||
will be allowed to join with either an EKCert or an EKPubHash.
|
||||
items:
|
||||
type: string
|
||||
nullable: true
|
||||
type: array
|
||||
type: object
|
||||
usage_mode:
|
||||
description: The usage mode of the token. Can be "single_use" or "unlimited".
|
||||
Single use tokens can only be used to provision a single resource.
|
||||
|
||||
@@ -567,6 +567,35 @@ spec:
|
||||
type: string
|
||||
nullable: true
|
||||
type: array
|
||||
tpm:
|
||||
description: Configuration specific to the "tpm" join method.
|
||||
nullable: true
|
||||
properties:
|
||||
allow:
|
||||
description: A list of Rules, the presented delegated identity
|
||||
must match one allow rule to permit joining.
|
||||
items:
|
||||
properties:
|
||||
description:
|
||||
type: string
|
||||
ek_certificate_serial:
|
||||
type: string
|
||||
ek_public_hash:
|
||||
type: string
|
||||
type: object
|
||||
nullable: true
|
||||
type: array
|
||||
ekcert_allowed_cas:
|
||||
description: A list of CA certificates that will be used to validate
|
||||
TPM EKCerts. When specified, joining TPMs must present an EKCert
|
||||
signed by one of the specified CAs. TPMs that do not present
|
||||
an EKCert will be not permitted to join. When unspecified, TPMs
|
||||
will be allowed to join with either an EKCert or an EKPubHash.
|
||||
items:
|
||||
type: string
|
||||
nullable: true
|
||||
type: array
|
||||
type: object
|
||||
usage_mode:
|
||||
description: The usage mode of the token. Can be "single_use" or "unlimited".
|
||||
Single use tokens can only be used to provision a single resource.
|
||||
|
||||
@@ -870,6 +870,48 @@ func GenSchemaScopedToken(ctx context.Context) (github_com_hashicorp_terraform_p
|
||||
Required: true,
|
||||
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
|
||||
},
|
||||
"tpm": {
|
||||
Attributes: github_com_hashicorp_terraform_plugin_framework_tfsdk.SingleNestedAttributes(map[string]github_com_hashicorp_terraform_plugin_framework_tfsdk.Attribute{
|
||||
"allow": {
|
||||
Attributes: github_com_hashicorp_terraform_plugin_framework_tfsdk.ListNestedAttributes(map[string]github_com_hashicorp_terraform_plugin_framework_tfsdk.Attribute{
|
||||
"description": {
|
||||
Computed: true,
|
||||
Description: "A human-readable description of the rule. It has no bearing on whether or not a TPM is allowed to join, but can be used to associate a rule with a specific host (e.g the asset tag of the server in which the TPM resides). Example: \"build-server-100\"",
|
||||
Optional: true,
|
||||
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
|
||||
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
|
||||
},
|
||||
"ek_certificate_serial": {
|
||||
Computed: true,
|
||||
Description: "The serial number of the EKCert in hexadecimal with colon separated nibbles. This value will not be checked when a TPM does not have an EKCert configured. Example: 73:df:dc:bd:af:ef:8a:d8:15:2e:96:71:7a:3e:7f:a4",
|
||||
Optional: true,
|
||||
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
|
||||
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
|
||||
},
|
||||
"ek_public_hash": {
|
||||
Computed: true,
|
||||
Description: "The SHA256 hash of the EKPub marshaled in PKIX format and encoded in hexadecimal. This value will also be checked when a TPM has submitted an EKCert, and the public key in the EKCert will be used for this check. Example: d4b45864d9d6fabfc568d74f26c35ababde2105337d7af9a6605e1c56c891aa6",
|
||||
Optional: true,
|
||||
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
|
||||
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
|
||||
},
|
||||
}),
|
||||
Computed: true,
|
||||
Description: "A list of Rules, the presented delegated identity must match one allow rule to permit joining.",
|
||||
Optional: true,
|
||||
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
|
||||
},
|
||||
"ekcert_allowed_cas": {
|
||||
Computed: true,
|
||||
Description: "A list of CA certificates that will be used to validate TPM EKCerts. When specified, joining TPMs must present an EKCert signed by one of the specified CAs. TPMs that do not present an EKCert will be not permitted to join. When unspecified, TPMs will be allowed to join with either an EKCert or an EKPubHash.",
|
||||
Optional: true,
|
||||
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
|
||||
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
|
||||
},
|
||||
}),
|
||||
Description: "Configuration specific to the \"tpm\" join method.",
|
||||
Optional: true,
|
||||
},
|
||||
"usage_mode": {
|
||||
Description: "The usage mode of the token. Can be \"single_use\" or \"unlimited\". Single use tokens can only be used to provision a single resource. Unlimited tokens can be be used to provision any number of resources until it expires.",
|
||||
Required: true,
|
||||
@@ -3295,6 +3337,131 @@ func CopyScopedTokenFromTerraform(_ context.Context, tf github_com_hashicorp_ter
|
||||
}
|
||||
}
|
||||
}
|
||||
{
|
||||
a, ok := tf.Attrs["tpm"]
|
||||
if !ok {
|
||||
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm"})
|
||||
} else {
|
||||
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.Object)
|
||||
if !ok {
|
||||
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm", "github.com/hashicorp/terraform-plugin-framework/types.Object"})
|
||||
} else {
|
||||
obj.Tpm = nil
|
||||
if !v.Null && !v.Unknown {
|
||||
tf := v
|
||||
obj.Tpm = &github_com_gravitational_teleport_api_gen_proto_go_teleport_scopes_joining_v1.TPM{}
|
||||
obj := obj.Tpm
|
||||
{
|
||||
a, ok := tf.Attrs["allow"]
|
||||
if !ok {
|
||||
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.allow"})
|
||||
} else {
|
||||
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
|
||||
if !ok {
|
||||
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow", "github.com/hashicorp/terraform-plugin-framework/types.List"})
|
||||
} else {
|
||||
obj.Allow = make([]*github_com_gravitational_teleport_api_gen_proto_go_teleport_scopes_joining_v1.TPM_Rule, len(v.Elems))
|
||||
if !v.Null && !v.Unknown {
|
||||
for k, a := range v.Elems {
|
||||
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.Object)
|
||||
if !ok {
|
||||
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow", "github_com_hashicorp_terraform_plugin_framework_types.Object"})
|
||||
} else {
|
||||
var t *github_com_gravitational_teleport_api_gen_proto_go_teleport_scopes_joining_v1.TPM_Rule
|
||||
if !v.Null && !v.Unknown {
|
||||
tf := v
|
||||
t = &github_com_gravitational_teleport_api_gen_proto_go_teleport_scopes_joining_v1.TPM_Rule{}
|
||||
obj := t
|
||||
{
|
||||
a, ok := tf.Attrs["description"]
|
||||
if !ok {
|
||||
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.allow.description"})
|
||||
} else {
|
||||
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow.description", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
} else {
|
||||
var t string
|
||||
if !v.Null && !v.Unknown {
|
||||
t = string(v.Value)
|
||||
}
|
||||
obj.Description = t
|
||||
}
|
||||
}
|
||||
}
|
||||
{
|
||||
a, ok := tf.Attrs["ek_public_hash"]
|
||||
if !ok {
|
||||
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.allow.ek_public_hash"})
|
||||
} else {
|
||||
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow.ek_public_hash", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
} else {
|
||||
var t string
|
||||
if !v.Null && !v.Unknown {
|
||||
t = string(v.Value)
|
||||
}
|
||||
obj.EkPublicHash = t
|
||||
}
|
||||
}
|
||||
}
|
||||
{
|
||||
a, ok := tf.Attrs["ek_certificate_serial"]
|
||||
if !ok {
|
||||
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial"})
|
||||
} else {
|
||||
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
} else {
|
||||
var t string
|
||||
if !v.Null && !v.Unknown {
|
||||
t = string(v.Value)
|
||||
}
|
||||
obj.EkCertificateSerial = t
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
obj.Allow[k] = t
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
{
|
||||
a, ok := tf.Attrs["ekcert_allowed_cas"]
|
||||
if !ok {
|
||||
diags.Append(attrReadMissingDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas"})
|
||||
} else {
|
||||
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
|
||||
if !ok {
|
||||
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github.com/hashicorp/terraform-plugin-framework/types.List"})
|
||||
} else {
|
||||
obj.EkcertAllowedCas = make([]string, len(v.Elems))
|
||||
if !v.Null && !v.Unknown {
|
||||
for k, a := range v.Elems {
|
||||
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
diags.Append(attrReadConversionFailureDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github_com_hashicorp_terraform_plugin_framework_types.String"})
|
||||
} else {
|
||||
var t string
|
||||
if !v.Null && !v.Unknown {
|
||||
t = string(v.Value)
|
||||
}
|
||||
obj.EkcertAllowedCas[k] = t
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -7729,6 +7896,249 @@ func CopyScopedTokenToTerraformPreserveUnknown(ctx context.Context, obj *github_
|
||||
}
|
||||
}
|
||||
}
|
||||
{
|
||||
a, ok := tf.AttrTypes["tpm"]
|
||||
if !ok {
|
||||
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm"})
|
||||
} else {
|
||||
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ObjectType)
|
||||
if !ok {
|
||||
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm", "github.com/hashicorp/terraform-plugin-framework/types.ObjectType"})
|
||||
} else {
|
||||
v, ok := tf.Attrs["tpm"].(github_com_hashicorp_terraform_plugin_framework_types.Object)
|
||||
if !ok {
|
||||
v = github_com_hashicorp_terraform_plugin_framework_types.Object{
|
||||
|
||||
AttrTypes: o.AttrTypes,
|
||||
Attrs: make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(o.AttrTypes)),
|
||||
}
|
||||
} else {
|
||||
if v.Attrs == nil {
|
||||
v.Attrs = make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(tf.AttrTypes))
|
||||
}
|
||||
}
|
||||
if obj.Tpm == nil {
|
||||
v.Null = true
|
||||
} else {
|
||||
v.Null = false
|
||||
obj := obj.Tpm
|
||||
tf := &v
|
||||
{
|
||||
a, ok := tf.AttrTypes["allow"]
|
||||
if !ok {
|
||||
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.allow"})
|
||||
} else {
|
||||
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
|
||||
if !ok {
|
||||
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.allow", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
|
||||
} else {
|
||||
c, ok := tf.Attrs["allow"].(github_com_hashicorp_terraform_plugin_framework_types.List)
|
||||
if !ok {
|
||||
c = github_com_hashicorp_terraform_plugin_framework_types.List{
|
||||
|
||||
ElemType: o.ElemType,
|
||||
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Allow)),
|
||||
Null: true,
|
||||
}
|
||||
} else {
|
||||
if c.Elems == nil {
|
||||
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Allow))
|
||||
}
|
||||
}
|
||||
{
|
||||
o := o.ElemType.(github_com_hashicorp_terraform_plugin_framework_types.ObjectType)
|
||||
if len(obj.Allow) != len(c.Elems) {
|
||||
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Allow))
|
||||
copy(newElems, c.Elems)
|
||||
c.Elems = newElems
|
||||
}
|
||||
for k, a := range obj.Allow {
|
||||
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.Object)
|
||||
if !ok {
|
||||
v = github_com_hashicorp_terraform_plugin_framework_types.Object{
|
||||
|
||||
AttrTypes: o.AttrTypes,
|
||||
Attrs: make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(o.AttrTypes)),
|
||||
}
|
||||
} else {
|
||||
if v.Attrs == nil {
|
||||
v.Attrs = make(map[string]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(tf.AttrTypes))
|
||||
}
|
||||
}
|
||||
if a == nil {
|
||||
v.Null = true
|
||||
} else {
|
||||
v.Null = false
|
||||
obj := a
|
||||
tf := &v
|
||||
{
|
||||
t, ok := tf.AttrTypes["description"]
|
||||
if !ok {
|
||||
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.allow.description"})
|
||||
} else {
|
||||
v, ok := tf.Attrs["description"].(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
if tf.Attrs["description"] != nil {
|
||||
diags.Append(attrWriteUnexpectedExistingTypeDiag{"ScopedToken.spec.tpm.allow.description", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
}
|
||||
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
|
||||
if err != nil {
|
||||
diags.Append(attrWriteGeneralError{"ScopedToken.spec.tpm.allow.description", err})
|
||||
}
|
||||
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.allow.description", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
}
|
||||
}
|
||||
|
||||
v.Null = false
|
||||
v.Value = string(obj.Description)
|
||||
if !preserveUnknown {
|
||||
v.Unknown = false
|
||||
}
|
||||
tf.Attrs["description"] = v
|
||||
}
|
||||
}
|
||||
{
|
||||
t, ok := tf.AttrTypes["ek_public_hash"]
|
||||
if !ok {
|
||||
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.allow.ek_public_hash"})
|
||||
} else {
|
||||
v, ok := tf.Attrs["ek_public_hash"].(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
if tf.Attrs["ek_public_hash"] != nil {
|
||||
diags.Append(attrWriteUnexpectedExistingTypeDiag{"ScopedToken.spec.tpm.allow.ek_public_hash", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
}
|
||||
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
|
||||
if err != nil {
|
||||
diags.Append(attrWriteGeneralError{"ScopedToken.spec.tpm.allow.ek_public_hash", err})
|
||||
}
|
||||
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.allow.ek_public_hash", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
}
|
||||
}
|
||||
|
||||
v.Null = false
|
||||
v.Value = string(obj.EkPublicHash)
|
||||
if !preserveUnknown {
|
||||
v.Unknown = false
|
||||
}
|
||||
tf.Attrs["ek_public_hash"] = v
|
||||
}
|
||||
}
|
||||
{
|
||||
t, ok := tf.AttrTypes["ek_certificate_serial"]
|
||||
if !ok {
|
||||
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial"})
|
||||
} else {
|
||||
v, ok := tf.Attrs["ek_certificate_serial"].(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
if tf.Attrs["ek_certificate_serial"] != nil {
|
||||
diags.Append(attrWriteUnexpectedExistingTypeDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
}
|
||||
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
|
||||
if err != nil {
|
||||
diags.Append(attrWriteGeneralError{"ScopedToken.spec.tpm.allow.ek_certificate_serial", err})
|
||||
}
|
||||
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.allow.ek_certificate_serial", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
}
|
||||
}
|
||||
|
||||
v.Null = false
|
||||
v.Value = string(obj.EkCertificateSerial)
|
||||
if !preserveUnknown {
|
||||
v.Unknown = false
|
||||
}
|
||||
tf.Attrs["ek_certificate_serial"] = v
|
||||
}
|
||||
}
|
||||
}
|
||||
if !preserveUnknown {
|
||||
v.Unknown = false
|
||||
}
|
||||
c.Elems[k] = v
|
||||
}
|
||||
}
|
||||
c.Null = false
|
||||
if !preserveUnknown {
|
||||
c.Unknown = false
|
||||
}
|
||||
tf.Attrs["allow"] = c
|
||||
}
|
||||
}
|
||||
}
|
||||
{
|
||||
a, ok := tf.AttrTypes["ekcert_allowed_cas"]
|
||||
if !ok {
|
||||
diags.Append(attrWriteMissingDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas"})
|
||||
} else {
|
||||
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
|
||||
if !ok {
|
||||
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
|
||||
} else {
|
||||
c, ok := tf.Attrs["ekcert_allowed_cas"].(github_com_hashicorp_terraform_plugin_framework_types.List)
|
||||
if !ok {
|
||||
c = github_com_hashicorp_terraform_plugin_framework_types.List{
|
||||
|
||||
ElemType: o.ElemType,
|
||||
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.EkcertAllowedCas)),
|
||||
Null: true,
|
||||
}
|
||||
} else {
|
||||
if c.Elems == nil {
|
||||
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.EkcertAllowedCas))
|
||||
}
|
||||
}
|
||||
{
|
||||
t := o.ElemType
|
||||
if len(obj.EkcertAllowedCas) != len(c.Elems) {
|
||||
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.EkcertAllowedCas))
|
||||
copy(newElems, c.Elems)
|
||||
c.Elems = newElems
|
||||
}
|
||||
for k, a := range obj.EkcertAllowedCas {
|
||||
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
if c.Elems[k] != nil {
|
||||
diags.Append(attrWriteUnexpectedExistingTypeDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
}
|
||||
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
|
||||
if err != nil {
|
||||
diags.Append(attrWriteGeneralError{"ScopedToken.spec.tpm.ekcert_allowed_cas", err})
|
||||
}
|
||||
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
|
||||
if !ok {
|
||||
diags.Append(attrWriteConversionFailureDiag{"ScopedToken.spec.tpm.ekcert_allowed_cas", "github.com/hashicorp/terraform-plugin-framework/types.String"})
|
||||
}
|
||||
}
|
||||
|
||||
v.Null = false
|
||||
v.Value = string(a)
|
||||
if !preserveUnknown {
|
||||
v.Unknown = false
|
||||
}
|
||||
c.Elems[k] = v
|
||||
}
|
||||
}
|
||||
c.Null = false
|
||||
if !preserveUnknown {
|
||||
c.Unknown = false
|
||||
}
|
||||
tf.Attrs["ekcert_allowed_cas"] = c
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
if !preserveUnknown {
|
||||
v.Unknown = false
|
||||
}
|
||||
tf.Attrs["tpm"] = v
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
if !preserveUnknown {
|
||||
v.Unknown = false
|
||||
|
||||
@@ -83,4 +83,6 @@ type Token interface {
|
||||
GetGithub() *types.ProvisionTokenSpecV2GitHub
|
||||
// GetGitLab returns the GitLab-specific configuration for this token.
|
||||
GetGitLab() *types.ProvisionTokenSpecV2GitLab
|
||||
// GetTPM returns the TPM-specific configuration for this token.
|
||||
GetTPM() *types.ProvisionTokenSpecV2TPM
|
||||
}
|
||||
|
||||
@@ -21,7 +21,6 @@ import (
|
||||
"github.com/gravitational/trace"
|
||||
|
||||
workloadidentityv1 "github.com/gravitational/teleport/api/gen/proto/go/teleport/workloadidentity/v1"
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/join/internal/authz"
|
||||
"github.com/gravitational/teleport/lib/join/internal/diagnostic"
|
||||
"github.com/gravitational/teleport/lib/join/internal/messages"
|
||||
@@ -49,11 +48,6 @@ func (s *Server) handleTPMJoin(
|
||||
clientInit *messages.ClientInit,
|
||||
provisionToken provision.Token,
|
||||
) (messages.Response, error) {
|
||||
ptv2, ok := provisionToken.(*types.ProvisionTokenV2)
|
||||
if !ok {
|
||||
return nil, trace.BadParameter("TPM joining only supports types.ProvisionTokenV2, got %T", provisionToken)
|
||||
}
|
||||
|
||||
// Receive the TPMInit message from the client.
|
||||
tpmInit, err := messages.RecvRequest[*messages.TPMInit](stream)
|
||||
if err != nil {
|
||||
@@ -78,7 +72,7 @@ func (s *Server) handleTPMJoin(
|
||||
}
|
||||
|
||||
validatedEK, err := tpmjoin.CheckTPMRequest(stream.Context(), s.cfg.Modules, tpmjoin.CheckTPMRequestParams{
|
||||
Token: ptv2,
|
||||
Token: provisionToken,
|
||||
TPMValidator: s.cfg.AuthService.GetTPMValidator(),
|
||||
EKCert: tpmInit.EKCert,
|
||||
EKKey: tpmInit.EKKey,
|
||||
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
"github.com/gravitational/trace"
|
||||
|
||||
"github.com/gravitational/teleport/api/types"
|
||||
"github.com/gravitational/teleport/lib/join/provision"
|
||||
"github.com/gravitational/teleport/lib/modules"
|
||||
"github.com/gravitational/teleport/lib/services"
|
||||
"github.com/gravitational/teleport/lib/tpm"
|
||||
@@ -35,7 +36,7 @@ type TPMValidator func(ctx context.Context, params tpm.ValidateParams) (*tpm.Val
|
||||
// CheckTPMRequestParams holds all parameters for CheckTPMRequest.
|
||||
type CheckTPMRequestParams struct {
|
||||
// Token is the provision token used to validate the request.
|
||||
Token *types.ProvisionTokenV2
|
||||
Token provision.Token
|
||||
// TPMValidator is a function that will be called to validate the presented TPM.
|
||||
TPMValidator TPMValidator
|
||||
|
||||
@@ -79,20 +80,22 @@ func CheckTPMRequest(ctx context.Context, m modules.Modules, params CheckTPMRequ
|
||||
return nil, trace.AccessDenied("validating TPM: %v", err)
|
||||
}
|
||||
|
||||
if err := checkTPMAllowRules(validatedEK, params.Token.Spec.TPM.Allow); err != nil {
|
||||
if err := checkTPMAllowRules(validatedEK, params.Token.GetTPM().Allow); err != nil {
|
||||
return validatedEK, trace.Wrap(err)
|
||||
}
|
||||
|
||||
return validatedEK, nil
|
||||
}
|
||||
|
||||
func buildCertPool(token *types.ProvisionTokenV2) (*x509.CertPool, error) {
|
||||
if len(token.Spec.TPM.EKCertAllowedCAs) == 0 {
|
||||
func buildCertPool(token provision.Token) (*x509.CertPool, error) {
|
||||
cfg := token.GetTPM()
|
||||
|
||||
if len(cfg.EKCertAllowedCAs) == 0 {
|
||||
// Certs are not validated if no CAs were configured.
|
||||
return nil, nil
|
||||
}
|
||||
certPool := x509.NewCertPool()
|
||||
for i, ca := range token.Spec.TPM.EKCertAllowedCAs {
|
||||
for i, ca := range cfg.EKCertAllowedCAs {
|
||||
if ok := certPool.AppendCertsFromPEM([]byte(ca)); !ok {
|
||||
return nil, trace.BadParameter(
|
||||
"ekcert_allowed_cas[%d] has an invalid or malformed PEM", i,
|
||||
|
||||
@@ -19,9 +19,11 @@ package joining
|
||||
import (
|
||||
"cmp"
|
||||
"crypto/sha256"
|
||||
"crypto/x509"
|
||||
"encoding/base64"
|
||||
"encoding/binary"
|
||||
"encoding/hex"
|
||||
"encoding/pem"
|
||||
"net/url"
|
||||
"slices"
|
||||
"strings"
|
||||
@@ -415,6 +417,71 @@ func validateGitLab(spec *joiningv1.GitLab, tokenUsageMode TokenUsageMode) error
|
||||
return nil
|
||||
}
|
||||
|
||||
// validateTPM validates the TPM-specific scoped token configuration. Note that
|
||||
// checks from ProvisionTokenSpecV2TPM.validate() are replicated here.
|
||||
func validateTPM(spec *joiningv1.TPM) error {
|
||||
if spec == nil {
|
||||
return trace.BadParameter("tpm: the .spec.tpm field is required for this join method")
|
||||
}
|
||||
|
||||
for i, caData := range spec.GetEkcertAllowedCas() {
|
||||
p, _ := pem.Decode([]byte(caData))
|
||||
if p == nil {
|
||||
return trace.BadParameter(
|
||||
"ekcert_allowed_cas[%d]: no pem block found",
|
||||
i,
|
||||
)
|
||||
}
|
||||
if p.Type != "CERTIFICATE" {
|
||||
return trace.BadParameter(
|
||||
"ekcert_allowed_cas[%d]: pem block is not 'CERTIFICATE' type",
|
||||
i,
|
||||
)
|
||||
}
|
||||
if _, err := x509.ParseCertificate(p.Bytes); err != nil {
|
||||
return trace.Wrap(
|
||||
err,
|
||||
"ekcert_allowed_cas[%d]: parsing certificate",
|
||||
i,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
if len(spec.GetAllow()) == 0 {
|
||||
return trace.BadParameter(
|
||||
"allow: at least one rule must be set",
|
||||
)
|
||||
}
|
||||
|
||||
hasCAs := len(spec.GetEkcertAllowedCas()) > 0
|
||||
for i, allowRule := range spec.GetAllow() {
|
||||
if len(allowRule.GetEkPublicHash()) == 0 && len(allowRule.GetEkCertificateSerial()) == 0 {
|
||||
return trace.BadParameter(
|
||||
"allow[%d]: at least one of ['ek_public_hash', 'ek_certificate_serial'] must be set",
|
||||
i,
|
||||
)
|
||||
}
|
||||
|
||||
// This is ported from services/local/provisioning.go's
|
||||
// validateTPMToken() which was deliberately separate from the overall
|
||||
// CheckAndSetDefaults() -> validate() path so as to not affect existing
|
||||
// tokens. There are no existing scoped TPM tokens, so we can safely
|
||||
// inline it here.
|
||||
//
|
||||
// This check doesn't apply if CAs are present: per the source impl,
|
||||
// serials are not trustworthy when certificates are verified against a
|
||||
// configured CA, so they're optional if CAs are also set.
|
||||
hasSerialWithoutHash := allowRule.GetEkCertificateSerial() != "" && allowRule.GetEkPublicHash() == ""
|
||||
if !hasCAs && hasSerialWithoutHash {
|
||||
return trace.BadParameter(
|
||||
"allow[%d]: ek_certificate_serial requires ek_public_hash or "+
|
||||
"ekcert_allowed_cas to be set so that the EK certificate "+
|
||||
"can be verified", i)
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// validates per join method token configurations
|
||||
func validateJoinMethod(token *joiningv1.ScopedToken) error {
|
||||
switch types.JoinMethod(token.GetSpec().GetJoinMethod()) {
|
||||
@@ -446,6 +513,8 @@ func validateJoinMethod(token *joiningv1.ScopedToken) error {
|
||||
}
|
||||
case types.JoinMethodGitLab:
|
||||
return trace.Wrap(validateGitLab(token.GetSpec().GetGitlab(), TokenUsageMode(token.GetSpec().GetUsageMode())), "gitlab join method")
|
||||
case types.JoinMethodTPM:
|
||||
return trace.Wrap(validateTPM(token.GetSpec().GetTpm()), "tpm join method")
|
||||
default:
|
||||
return trace.BadParameter("join method %q does not support scoping", token.GetSpec().GetJoinMethod())
|
||||
}
|
||||
@@ -1141,6 +1210,26 @@ func (t *Token) GetGitLab() *types.ProvisionTokenSpecV2GitLab {
|
||||
}
|
||||
}
|
||||
|
||||
// GetTPM returns the TPM configuration for this token. Returns an empty but
|
||||
// not nil value if TPM was not configured.
|
||||
func (t *Token) GetTPM() *types.ProvisionTokenSpecV2TPM {
|
||||
spec := t.scoped.GetSpec().GetTpm()
|
||||
|
||||
allow := make([]*types.ProvisionTokenSpecV2TPM_Rule, len(spec.GetAllow()))
|
||||
for i, rule := range spec.GetAllow() {
|
||||
allow[i] = &types.ProvisionTokenSpecV2TPM_Rule{
|
||||
Description: rule.GetDescription(),
|
||||
EKPublicHash: rule.GetEkPublicHash(),
|
||||
EKCertificateSerial: rule.GetEkCertificateSerial(),
|
||||
}
|
||||
}
|
||||
|
||||
return &types.ProvisionTokenSpecV2TPM{
|
||||
Allow: allow,
|
||||
EKCertAllowedCAs: spec.GetEkcertAllowedCas(),
|
||||
}
|
||||
}
|
||||
|
||||
// GetScoped returns the inner scoped token wrapped by this [provision.Token].
|
||||
func (t *Token) GetScoped() *joiningv1.ScopedToken {
|
||||
return t.scoped
|
||||
|
||||
Reference in New Issue
Block a user