types: Declare all app_resources fields (#69500)

* types: Declare all app_resources fields in the proto

Declare the eight reserved AppResource fields (paths, methods, where,
allow_encoded, allow_code, allow_reason, deny_code_hint,
deny_reason_hint) and the AppResourcesExpressions role condition, and
regenerate the proto stubs, the role CRDs, the Terraform schema and
docs, and the derived equality functions. Declaring the fields before
the fine-grained matcher merges lets every client of this version name
them, so a client that round-trips a role written by a newer auth
preserves the fields instead of silently dropping them on write-back,
which would widen the rule.

Tighten IsAllowAllOnly to require every declared field besides
allow_all to be unset. Without this, a rule such as {allow_all: true,
methods: [GET]} written by a newer auth would pass the check once the
fields are named, and this version would treat a method-restricted
rule as unrestricted.

Add GetAppResourcesExpressions to the Role interface, and read it in
decideMinimalV9 so the app agent denies a request governed by a
predicate it cannot evaluate. A predicate restricts the rules it
accompanies, so a role that pairs allow_all with one is not
unrestricted, and a deny-side predicate blocks another role's
allow_all the same way a deny-side rule does. Auth already treats both
as restricting when it downgrades a role for a pre-v9 client, so
without this the agent and auth disagree about the same role.

Strip AppResourcesExpressions in the v9-to-v8 downgrade alongside
AppResources, and reject it at write, so a role can neither reach a
pre-v9 client with the restriction silently removed nor be stored
while this version cannot enforce it.

* docs: List the declared app_resources fields

Honour the docs review on the app-resources reference page. A run of
inline code-style field names inside a sentence is hard to scan, so the
eight rejected `app_resources` fields become a list, and
`app_resources_expressions` gets its own sentence rather than trailing
the same run.

* buf: Trim the reserved-deletion except comment

Drop the two sentences explaining why buf's ignore lists cannot scope the
except. The rule name and the removal condition are what a reader needs
here, and the scoping attempts are recorded on the pull request.

* types: Reword the app_resources_expressions and Methods docs

Honour the review on the proto field comments. Drop "desugared" from
`AppResourcesExpressions`, which needs the RFD to gloss, and state the
relation between the two forms directly instead. Open `Methods` with the
plural, matching `Paths` on the row above.

Regenerate the proto stubs, the role CRDs, the Terraform schema and docs.
This commit is contained in:
Julia Ogris
2026-08-12 05:19:01 +00:00
committed by GitHub
parent 5dd08bd2e2
commit 677b0d6e1c
32 changed files with 6052 additions and 2484 deletions
+83 -16
View File
@@ -4422,34 +4422,101 @@ message RoleConditions {
// to beams.
string BeamLabelsExpression = 51 [(gogoproto.jsontag) = "beam_labels_expression,omitempty"];
// AppResources is the list of rules controlling access to an app's
// resources on each HTTP request. It is valid only in role version v9 and
// above, and only under allow.
// AppResources is a list of rules controlling access to an app's
// resources on each HTTP request. It is valid only in role version v9
// and above, and only under allow.
//
// This version implements allow_all only and rejects a rule that sets
// any other field. The other fields are declared so that version skew
// or a rollback cannot silently drop one and widen a role's access.
repeated AppResource AppResources = 52 [
(gogoproto.nullable) = false,
(gogoproto.jsontag) = "app_resources,omitempty"
];
// Field 53 is reserved for AppResourcesExpressions, the predicate
// counterpart of the declarative AppResources rules.
reserved 53;
reserved "AppResourcesExpressions";
// AppResourcesExpressions is a list of predicates controlling access to
// an app's resources on each HTTP request. It is valid only in role
// version v9 and above, and only under allow. Every AppResource rule can
// be written as an expression, but not the reverse.
//
// This version does not implement app_resources_expressions and rejects
// a role that sets it. The field is declared so that version skew or a
// rollback cannot silently drop it and widen a role's access.
repeated string AppResourcesExpressions = 53 [(gogoproto.jsontag) = "app_resources_expressions,omitempty"];
}
// AppResource is one rule under a role's app_resources. The only supported
// rule form is allow_all, which grants unrestricted access.
// AppResource is one rule under a role's app_resources. It allows an HTTP
// request that matches it to reach an app's resources.
//
// This version implements allow_all only, which grants unrestricted access
// to the app, and rejects a rule that sets any other field. The other
// fields are declared so that version skew or a rollback cannot silently
// drop one and widen a role's access.
message AppResource {
// Fields 1 to 4 and 6 to 9 are reserved for the upcoming fine-grained
// rule fields (paths, methods, where, allow_encoded, allow_code,
// allow_reason, deny_code_hint, deny_reason_hint). Unreserving one means
// re-evaluating AppResource.IsAllowAllOnly, which decides whether a rule
// is unrestricted.
reserved 1 to 4, 6 to 9;
reserved "Paths", "Methods", "Where", "AllowEncoded", "AllowCode", "AllowReason", "DenyCodeHint", "DenyReasonHint";
// Paths are the path patterns the rule matches, for example:
//
// `paths: ["/api/projects/{project}/**"]`
//
// The `{project}` segment is captured, and the rule's Where reads it as
// `vars.project`. A rule sets either Paths or AllowAll.
//
// This version declares the field but rejects a rule that sets it.
repeated string Paths = 1 [(gogoproto.jsontag) = "paths,omitempty"];
// Methods are the HTTP methods the rule matches, compared
// case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH,
// DELETE, OPTIONS, and TRACE. An empty list matches any of them.
//
// This version declares the field but rejects a rule that sets it.
repeated string Methods = 2 [(gogoproto.jsontag) = "methods,omitempty"];
// Where is a predicate over the caller identity and the rule's path
// captures, for example matching a captured project against a user's
// traits:
//
// `where: contains(user.traits["projects"], vars.project)`
//
// This version declares the field but rejects a rule that sets it.
string Where = 3 [(gogoproto.jsontag) = "where,omitempty"];
// AllowEncoded lists the characters a request path may carry in
// percent-encoded form for the rule to match. The only supported value
// is "/", which allows the encoded slash, %2F or %2f.
//
// This version declares the field but rejects a rule that sets it.
repeated string AllowEncoded = 4 [(gogoproto.jsontag) = "allow_encoded,omitempty"];
// AllowAll grants unrestricted access to every path and method. It
// cannot be combined with any other field.
bool AllowAll = 5 [(gogoproto.jsontag) = "allow_all,omitempty"];
// AllowCode is the code recorded on the allow audit event when the rule
// matches. If it is not set, no allow audit event is recorded. A code may
// not start with the reserved "teleport_" prefix.
//
// This version declares the field but rejects a rule that sets it.
string AllowCode = 6 [(gogoproto.jsontag) = "allow_code,omitempty"];
// AllowReason is the explanation recorded alongside AllowCode. A rule
// sets it only together with AllowCode.
//
// This version declares the field but rejects a rule that sets it.
string AllowReason = 7 [(gogoproto.jsontag) = "allow_reason,omitempty"];
// DenyCodeHint is the code added to the deny decision when the rule's
// path and method match but the Where predicate does not. A denied
// request collects a code from every such rule, so one decision can
// record several codes. A code may not start with the reserved
// "teleport_" prefix.
//
// This version declares the field but rejects a rule that sets it.
string DenyCodeHint = 8 [(gogoproto.jsontag) = "deny_code_hint,omitempty"];
// DenyReasonHint is the explanation recorded alongside DenyCodeHint. A
// rule sets it only together with DenyCodeHint.
//
// This version declares the field but rejects a rule that sets it.
string DenyReasonHint = 9 [(gogoproto.jsontag) = "deny_reason_hint,omitempty"];
}
// IdentityCenterAccountAssignment captures an AWS Identity Center account
+12 -3
View File
@@ -17,11 +17,20 @@ limitations under the License.
package types
// IsAllowAllOnly reports whether the rule sets allow_all and no other
// field, known or unknown. Fields unknown to this version could
// restrict the rule, so a rule carrying any does not count as
// field, known or unknown. This version enforces no field except
// allow_all, so a rule that sets any other field does not count as
// unrestricted.
func (a AppResource) IsAllowAllOnly() bool {
return a.AllowAll && len(a.XXX_unrecognized) == 0
return a.AllowAll &&
len(a.Paths) == 0 &&
len(a.Methods) == 0 &&
a.Where == "" &&
len(a.AllowEncoded) == 0 &&
a.AllowCode == "" &&
a.AllowReason == "" &&
a.DenyCodeHint == "" &&
a.DenyReasonHint == "" &&
len(a.XXX_unrecognized) == 0
}
// AppResourcesAllowAll reports whether a role's app rules grant full
+48 -9
View File
@@ -36,7 +36,36 @@ func TestAppResourceFields(t *testing.T) {
fields = append(fields, f.Name)
}
}
require.Equal(t, []string{"AllowAll"}, fields)
want := []string{
"Paths", "Methods", "Where", "AllowEncoded", "AllowAll",
"AllowCode", "AllowReason", "DenyCodeHint", "DenyReasonHint",
}
require.Equal(t, want, fields)
}
// TestIsAllowAllOnly checks that every declared field besides allow_all
// disqualifies a rule from counting as unrestricted. A rule a newer
// version wrote with a restricting field must deny, never widen to
// allow_all, on a version that does not enforce the field.
func TestIsAllowAllOnly(t *testing.T) {
require.True(t, AppResource{AllowAll: true}.IsAllowAllOnly())
require.False(t, AppResource{}.IsAllowAllOnly())
for name, rule := range map[string]AppResource{
"paths": {AllowAll: true, Paths: []string{"/api/**"}},
"methods": {AllowAll: true, Methods: []string{"GET"}},
"where": {AllowAll: true, Where: "true"},
"allow_encoded": {AllowAll: true, AllowEncoded: []string{"/"}},
"allow_code": {AllowAll: true, AllowCode: "all"},
"allow_reason": {AllowAll: true, AllowReason: "All."},
"deny_code_hint": {AllowAll: true, DenyCodeHint: "no"},
"deny_reason_hint": {AllowAll: true, DenyReasonHint: "No."},
"unknown field": {AllowAll: true, XXX_unrecognized: []byte{0x50, 0x01}},
} {
t.Run(name, func(t *testing.T) {
require.False(t, rule.IsAllowAllOnly())
})
}
}
// TestAppResourcesRequireV9 covers the read-path check in
@@ -88,6 +117,24 @@ func TestAppResourcesRequireV9(t *testing.T) {
deny: RoleConditions{AppResources: []AppResource{{AllowAll: true}}},
assertErr: errContains("requires role version"),
},
{
name: "app_resources_expressions on v8 role",
version: V8,
allow: RoleConditions{AppResourcesExpressions: []string{"true"}},
assertErr: errContains("requires role version"),
},
{
name: "app_resources_expressions under deny on v8 role",
version: V8,
deny: RoleConditions{AppResourcesExpressions: []string{"true"}},
assertErr: errContains("requires role version"),
},
{
name: "v9 app_resources_expressions passes read validation",
version: V9,
allow: RoleConditions{AppResourcesExpressions: []string{"true"}},
assertErr: require.NoError,
},
}
for _, test := range tests {
@@ -102,14 +149,6 @@ func TestAppResourcesRequireV9(t *testing.T) {
}
}
func TestIsAllowAllOnly(t *testing.T) {
require.True(t, AppResource{AllowAll: true}.IsAllowAllOnly())
require.False(t, AppResource{}.IsAllowAllOnly())
// Unknown fields from a newer auth server must not grant access.
withUnknownField := AppResource{AllowAll: true, XXX_unrecognized: []byte{0x0a, 0x01, 0x2f}}
require.False(t, withUnknownField.IsAllowAllOnly())
}
func TestAppResourcesAllowAll(t *testing.T) {
allowAll := AppResource{AllowAll: true}
require.True(t, AppResourcesAllowAll([]AppResource{allowAll}, nil))
+11 -2
View File
@@ -1235,7 +1235,8 @@ func deriveTeleportEqual_65(this, that *RoleConditions) bool {
this.LinuxDesktopLabelsExpression == that.LinuxDesktopLabelsExpression &&
deriveTeleportEqual_62(this.BeamLabels, that.BeamLabels) &&
this.BeamLabelsExpression == that.BeamLabelsExpression &&
deriveTeleportEqual_110(this.AppResources, that.AppResources)
deriveTeleportEqual_110(this.AppResources, that.AppResources) &&
deriveTeleportEqual_2(this.AppResourcesExpressions, that.AppResourcesExpressions)
}
// deriveTeleportEqual_66 returns whether this and that are equal.
@@ -2094,7 +2095,15 @@ func deriveTeleportEqual_140(this, that *GitHubPermission) bool {
func deriveTeleportEqual_141(this, that *AppResource) bool {
return (this == nil && that == nil) ||
this != nil && that != nil &&
this.AllowAll == that.AllowAll
deriveTeleportEqual_2(this.Paths, that.Paths) &&
deriveTeleportEqual_2(this.Methods, that.Methods) &&
this.Where == that.Where &&
deriveTeleportEqual_2(this.AllowEncoded, that.AllowEncoded) &&
this.AllowAll == that.AllowAll &&
this.AllowCode == that.AllowCode &&
this.AllowReason == that.AllowReason &&
this.DenyCodeHint == that.DenyCodeHint &&
this.DenyReasonHint == that.DenyReasonHint
}
// deriveTeleportEqual_142 returns whether this and that are equal.
+28 -6
View File
@@ -121,9 +121,16 @@ type Role interface {
SetAppLabels(RoleConditionType, Labels)
// GetAppResources gets the per-request app access rules this role defines
// for the given condition. Only v9+ roles set them, and only under allow.
// under the allow or the deny RoleConditions. Only v9 roles set them, and
// only under allow.
GetAppResources(RoleConditionType) []AppResource
// GetAppResourcesExpressions gets the per-request app access predicates
// this role defines under the allow or the deny RoleConditions. A caller
// deciding what a role grants must read these as well as
// GetAppResources. Only v9 roles set them, and only under allow.
GetAppResourcesExpressions(RoleConditionType) []string
// GetClusterLabels gets the map of cluster labels this role is allowed or denied access to.
GetClusterLabels(RoleConditionType) Labels
// SetClusterLabels sets the map of cluster labels this role is allowed or denied access to.
@@ -852,8 +859,9 @@ func (r *RoleV6) SetAppLabels(rct RoleConditionType, labels Labels) {
}
}
// GetAppResources gets the per-request app access rules this role defines for
// the given condition. Only v9 roles set them, and only under allow.
// GetAppResources gets the per-request app access rules this role defines
// under the allow or the deny RoleConditions. Only v9 roles set them, and
// only under allow.
func (r *RoleV6) GetAppResources(rct RoleConditionType) []AppResource {
if rct == Allow {
return r.Spec.Allow.AppResources
@@ -861,6 +869,16 @@ func (r *RoleV6) GetAppResources(rct RoleConditionType) []AppResource {
return r.Spec.Deny.AppResources
}
// GetAppResourcesExpressions gets the per-request app access predicates this
// role defines under the allow or the deny RoleConditions. Only v9 roles set
// them, and only under allow.
func (r *RoleV6) GetAppResourcesExpressions(rct RoleConditionType) []string {
if rct == Allow {
return r.Spec.Allow.AppResourcesExpressions
}
return r.Spec.Deny.AppResourcesExpressions
}
// GetClusterLabels gets the map of cluster labels this role is allowed or denied access to.
func (r *RoleV6) GetClusterLabels(rct RoleConditionType) Labels {
if rct == Allow {
@@ -1609,9 +1627,10 @@ func (r *RoleV6) CheckAndSetDefaults() error {
return nil
}
// checkAppResources rejects app_resources on roles below version v9, but
// accepts any rule content for forward compatibility. Validation on create
// and update applies the remaining checks.
// checkAppResources rejects app_resources and app_resources_expressions on
// roles below version v9, but accepts any rule content for forward
// compatibility. Validation on create and update applies the remaining
// checks.
func (r *RoleV6) checkAppResources() error {
if r.Version == V9 {
return nil
@@ -1619,6 +1638,9 @@ func (r *RoleV6) checkAppResources() error {
if len(r.Spec.Allow.AppResources) > 0 || len(r.Spec.Deny.AppResources) > 0 {
return trace.BadParameter("app_resources requires role version %q, got %q", V9, r.Version)
}
if len(r.Spec.Allow.AppResourcesExpressions) > 0 || len(r.Spec.Deny.AppResourcesExpressions) > 0 {
return trace.BadParameter("app_resources_expressions requires role version %q, got %q", V9, r.Version)
}
return nil
}
+2839 -2357
View File
File diff suppressed because it is too large Load Diff
+5
View File
@@ -91,6 +91,11 @@ breaking:
use:
- ENUM_VALUE_NO_DELETE
- WIRE_JSON
# TODO(juliaogris): Remove the except once the buf breaking baseline no
# longer holds the app_resources reservations. They were never in a
# release, so deleting them breaks no released wire or JSON format.
except:
- RESERVED_MESSAGE_NO_DELETE
ignore:
# TODO(codingllama): Remove ignore once the PDP API is stable.
- api/proto/teleport/decision/v1alpha1
@@ -32,6 +32,22 @@ spec:
- allow_all: true
```
Teleport 19 rejects a role that sets any of the following `app_resources`
fields. The role schema still declares them so that version skew or a rollback
cannot silently drop one and widen the access a role grants.
- `paths`
- `methods`
- `where`
- `allow_encoded`
- `allow_code`
- `allow_reason`
- `deny_code_hint`
- `deny_reason_hint`
Teleport 19 rejects `spec.allow.app_resources_expressions` on the same grounds.
It expresses the same rules as predicates.
When a v9 role and a v8 or older role both grant the same application, Teleport
drops the older roles from the decision, so they cannot restore unrestricted
access to an application a v9 role restricts.
@@ -41,7 +41,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specallowaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specallowapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specallowbeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -107,6 +108,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.allow.beam_labels
@@ -336,7 +345,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specdenyaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specdenyapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specdenybeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -402,6 +412,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.deny.beam_labels
@@ -735,7 +753,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specallowaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specallowapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specallowbeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -801,6 +820,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.allow.beam_labels
@@ -1030,7 +1057,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specdenyaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specdenyapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specdenybeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -1096,6 +1124,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.deny.beam_labels
@@ -41,7 +41,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specallowaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specallowapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specallowbeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -107,6 +108,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.allow.beam_labels
@@ -336,7 +345,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specdenyaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specdenyapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specdenybeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -402,6 +412,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.deny.beam_labels
@@ -41,7 +41,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specallowaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specallowapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specallowbeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -107,6 +108,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.allow.beam_labels
@@ -336,7 +345,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specdenyaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specdenyapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specdenybeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -402,6 +412,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.deny.beam_labels
@@ -41,7 +41,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specallowaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specallowapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specallowbeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -107,6 +108,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.allow.beam_labels
@@ -336,7 +345,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specdenyaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specdenyapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specdenybeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -402,6 +412,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.deny.beam_labels
@@ -41,7 +41,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specallowaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specallowapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specallowapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specallowbeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -107,6 +108,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.allow.beam_labels
@@ -336,7 +345,8 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|account_assignments|[][object](#specdenyaccount_assignments-items)|AccountAssignments holds the list of account assignments affected by this condition.|
|app_labels|[object](#specdenyapp_labels)|AppLabels is a map of labels used as part of the RBAC system.|
|app_labels_expression|string|AppLabelsExpression is a predicate expression used to allow/deny access to Apps.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.|
|app_resources|[][object](#specdenyapp_resources-items)|AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.|
|app_resources_expressions|[]string|AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.|
|aws_role_arns|[]string|AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.|
|azure_identities|[]string|AzureIdentities is a list of Azure identities this role is allowed to assume.|
|beam_labels|[object](#specdenybeam_labels)|BeamLabels are used in the RBAC system to allow/deny access to beams.|
@@ -402,6 +412,14 @@ resource, which you can apply after installing the Teleport Kubernetes operator.
|Field|Type|Description|
|---|---|---|
|allow_all|boolean|AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.|
|allow_code|string|AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|allow_encoded|[]string|AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.|
|allow_reason|string|AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.|
|deny_code_hint|string|DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.|
|deny_reason_hint|string|DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.|
|methods|[]string|Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.|
|paths|[]string|Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.|
|where|string|Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.|
### spec.deny.beam_labels
@@ -60,7 +60,8 @@ Optional:
- `account_assignments` (Attributes List) AccountAssignments holds the list of account assignments affected by this condition. (see [below for nested schema](#nested-schema-for-specallowaccount_assignments))
- `app_labels` (Map of List of String) AppLabels is a map of labels used as part of the RBAC system.
- `app_labels_expression` (String) AppLabelsExpression is a predicate expression used to allow/deny access to Apps.
- `app_resources` (Attributes List) AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. (see [below for nested schema](#nested-schema-for-specallowapp_resources))
- `app_resources` (Attributes List) AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access. (see [below for nested schema](#nested-schema-for-specallowapp_resources))
- `app_resources_expressions` (List of String) AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.
- `aws_role_arns` (List of String) AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.
- `azure_identities` (List of String) AzureIdentities is a list of Azure identities this role is allowed to assume.
- `beam_labels` (Map of List of String) BeamLabels are used in the RBAC system to allow/deny access to beams.
@@ -120,6 +121,14 @@ Optional:
Optional:
- `allow_all` (Boolean) AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.
- `allow_code` (String) AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.
- `allow_encoded` (List of String) AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.
- `allow_reason` (String) AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.
- `deny_code_hint` (String) DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.
- `deny_reason_hint` (String) DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.
- `methods` (List of String) Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.
- `paths` (List of String) Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.
- `where` (String) Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.
### Nested Schema for `spec.allow.db_permissions`
@@ -283,6 +292,7 @@ Optional:
- `account_assignments` (Attributes List) AccountAssignments holds the list of account assignments affected by this condition. (see [below for nested schema](#nested-schema-for-specdenyaccount_assignments))
- `app_labels` (Map of List of String) AppLabels is a map of labels used as part of the RBAC system.
- `app_labels_expression` (String) AppLabelsExpression is a predicate expression used to allow/deny access to Apps.
- `app_resources_expressions` (List of String) AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.
- `aws_role_arns` (List of String) AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.
- `azure_identities` (List of String) AzureIdentities is a list of Azure identities this role is allowed to assume.
- `beam_labels` (Map of List of String) BeamLabels are used in the RBAC system to allow/deny access to beams.
@@ -122,7 +122,8 @@ Optional:
- `account_assignments` (Attributes List) AccountAssignments holds the list of account assignments affected by this condition. (see [below for nested schema](#nested-schema-for-specallowaccount_assignments))
- `app_labels` (Map of List of String) AppLabels is a map of labels used as part of the RBAC system.
- `app_labels_expression` (String) AppLabelsExpression is a predicate expression used to allow/deny access to Apps.
- `app_resources` (Attributes List) AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. (see [below for nested schema](#nested-schema-for-specallowapp_resources))
- `app_resources` (Attributes List) AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access. (see [below for nested schema](#nested-schema-for-specallowapp_resources))
- `app_resources_expressions` (List of String) AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.
- `aws_role_arns` (List of String) AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.
- `azure_identities` (List of String) AzureIdentities is a list of Azure identities this role is allowed to assume.
- `beam_labels` (Map of List of String) BeamLabels are used in the RBAC system to allow/deny access to beams.
@@ -182,6 +183,14 @@ Optional:
Optional:
- `allow_all` (Boolean) AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.
- `allow_code` (String) AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.
- `allow_encoded` (List of String) AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is "/", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.
- `allow_reason` (String) AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.
- `deny_code_hint` (String) DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved "teleport_" prefix. This version declares the field but rejects a rule that sets it.
- `deny_reason_hint` (String) DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.
- `methods` (List of String) Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.
- `paths` (List of String) Paths are the path patterns the rule matches, for example: `paths: ["/api/projects/{project}/**"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.
- `where` (String) Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits["projects"], vars.project)` This version declares the field but rejects a rule that sets it.
### Nested Schema for `spec.allow.db_permissions`
@@ -345,6 +354,7 @@ Optional:
- `account_assignments` (Attributes List) AccountAssignments holds the list of account assignments affected by this condition. (see [below for nested schema](#nested-schema-for-specdenyaccount_assignments))
- `app_labels` (Map of List of String) AppLabels is a map of labels used as part of the RBAC system.
- `app_labels_expression` (String) AppLabelsExpression is a predicate expression used to allow/deny access to Apps.
- `app_resources_expressions` (List of String) AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.
- `aws_role_arns` (List of String) AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.
- `azure_identities` (List of String) AzureIdentities is a list of Azure identities this role is allowed to assume.
- `beam_labels` (Map of List of String) BeamLabels are used in the RBAC system to allow/deny access to beams.
@@ -58,9 +58,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -68,8 +71,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -724,9 +806,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -734,8 +819,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -1692,9 +1856,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -1702,8 +1869,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -2358,9 +2604,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -2368,8 +2617,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -61,9 +61,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -71,8 +74,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -727,9 +809,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -737,8 +822,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -61,9 +61,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -71,8 +74,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -727,9 +809,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -737,8 +822,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -61,9 +61,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -71,8 +74,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -727,9 +809,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -737,8 +822,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -61,9 +61,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -71,8 +74,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -727,9 +809,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -737,8 +822,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -58,9 +58,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -68,8 +71,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -724,9 +806,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -734,8 +819,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -1692,9 +1856,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -1702,8 +1869,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -2358,9 +2604,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -2368,8 +2617,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -61,9 +61,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -71,8 +74,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -727,9 +809,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -737,8 +822,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -61,9 +61,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -71,8 +74,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -727,9 +809,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -737,8 +822,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -61,9 +61,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -71,8 +74,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -727,9 +809,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -737,8 +822,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -61,9 +61,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -71,8 +74,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -727,9 +809,12 @@ spec:
to allow/deny access to Apps.
type: string
app_resources:
description: AppResources is the list of rules controlling access
description: AppResources is a list of rules controlling access
to an app's resources on each HTTP request. It is valid only
in role version v9 and above, and only under allow.
in role version v9 and above, and only under allow. This version
implements allow_all only and rejects a rule that sets any other
field. The other fields are declared so that version skew or
a rollback cannot silently drop one and widen a role's access.
items:
properties:
allow_all:
@@ -737,8 +822,87 @@ spec:
path and method. It cannot be combined with any other
field.
type: boolean
allow_code:
description: AllowCode is the code recorded on the allow
audit event when the rule matches. If it is not set, no
allow audit event is recorded. A code may not start with
the reserved "teleport_" prefix. This version declares
the field but rejects a rule that sets it.
type: string
allow_encoded:
description: AllowEncoded lists the characters a request
path may carry in percent-encoded form for the rule to
match. The only supported value is "/", which allows the
encoded slash, %2F or %2f. This version declares the
field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
allow_reason:
description: AllowReason is the explanation recorded alongside
AllowCode. A rule sets it only together with AllowCode. This
version declares the field but rejects a rule that sets
it.
type: string
deny_code_hint:
description: DenyCodeHint is the code added to the deny
decision when the rule's path and method match but the
Where predicate does not. A denied request collects a
code from every such rule, so one decision can record
several codes. A code may not start with the reserved
"teleport_" prefix. This version declares the field but
rejects a rule that sets it.
type: string
deny_reason_hint:
description: DenyReasonHint is the explanation recorded
alongside DenyCodeHint. A rule sets it only together with
DenyCodeHint. This version declares the field but rejects
a rule that sets it.
type: string
methods:
description: Methods are the HTTP methods the rule matches,
compared case-insensitively. A rule may list only GET,
HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An
empty list matches any of them. This version declares
the field but rejects a rule that sets it.
items:
type: string
nullable: true
type: array
paths:
description: 'Paths are the path patterns the rule matches,
for example: `paths: ["/api/projects/{project}/**"]` The
`{project}` segment is captured, and the rule''s Where
reads it as `vars.project`. A rule sets either Paths or
AllowAll. This version declares the field but rejects
a rule that sets it.'
items:
type: string
nullable: true
type: array
where:
description: 'Where is a predicate over the caller identity
and the rule''s path captures, for example matching a
captured project against a user''s traits: `where: contains(user.traits["projects"],
vars.project)` This version declares the field but rejects
a rule that sets it.'
type: string
type: object
type: array
app_resources_expressions:
description: AppResourcesExpressions is a list of predicates controlling
access to an app's resources on each HTTP request. It is valid
only in role version v9 and above, and only under allow. Every
AppResource rule can be written as an expression, but not the
reverse. This version does not implement app_resources_expressions
and rejects a role that sets it. The field is declared so that
version skew or a rollback cannot silently drop it and widen
a role's access.
items:
type: string
nullable: true
type: array
aws_role_arns:
description: AWSRoleARNs is a list of AWS role ARNs this role
is allowed to assume.
@@ -3679,18 +3679,83 @@ func GenSchemaRoleV6(ctx context.Context) (github_com_hashicorp_terraform_plugin
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"app_resources": {
Attributes: github_com_hashicorp_terraform_plugin_framework_tfsdk.ListNestedAttributes(map[string]github_com_hashicorp_terraform_plugin_framework_tfsdk.Attribute{"allow_all": {
Computed: true,
Description: "AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.BoolType,
}}),
Attributes: github_com_hashicorp_terraform_plugin_framework_tfsdk.ListNestedAttributes(map[string]github_com_hashicorp_terraform_plugin_framework_tfsdk.Attribute{
"allow_all": {
Computed: true,
Description: "AllowAll grants unrestricted access to every path and method. It cannot be combined with any other field.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.BoolType,
},
"allow_code": {
Computed: true,
Description: "AllowCode is the code recorded on the allow audit event when the rule matches. If it is not set, no allow audit event is recorded. A code may not start with the reserved \"teleport_\" prefix. This version declares the field but rejects a rule that sets it.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"allow_encoded": {
Computed: true,
Description: "AllowEncoded lists the characters a request path may carry in percent-encoded form for the rule to match. The only supported value is \"/\", which allows the encoded slash, %2F or %2f. This version declares the field but rejects a rule that sets it.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
},
"allow_reason": {
Computed: true,
Description: "AllowReason is the explanation recorded alongside AllowCode. A rule sets it only together with AllowCode. This version declares the field but rejects a rule that sets it.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"deny_code_hint": {
Computed: true,
Description: "DenyCodeHint is the code added to the deny decision when the rule's path and method match but the Where predicate does not. A denied request collects a code from every such rule, so one decision can record several codes. A code may not start with the reserved \"teleport_\" prefix. This version declares the field but rejects a rule that sets it.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"deny_reason_hint": {
Computed: true,
Description: "DenyReasonHint is the explanation recorded alongside DenyCodeHint. A rule sets it only together with DenyCodeHint. This version declares the field but rejects a rule that sets it.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"methods": {
Computed: true,
Description: "Methods are the HTTP methods the rule matches, compared case-insensitively. A rule may list only GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, and TRACE. An empty list matches any of them. This version declares the field but rejects a rule that sets it.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
},
"paths": {
Computed: true,
Description: "Paths are the path patterns the rule matches, for example: `paths: [\"/api/projects/{project}/**\"]` The `{project}` segment is captured, and the rule's Where reads it as `vars.project`. A rule sets either Paths or AllowAll. This version declares the field but rejects a rule that sets it.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
},
"where": {
Computed: true,
Description: "Where is a predicate over the caller identity and the rule's path captures, for example matching a captured project against a user's traits: `where: contains(user.traits[\"projects\"], vars.project)` This version declares the field but rejects a rule that sets it.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
}),
Computed: true,
Description: "AppResources is the list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow.",
Description: "AppResources is a list of rules controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. This version implements allow_all only and rejects a rule that sets any other field. The other fields are declared so that version skew or a rollback cannot silently drop one and widen a role's access.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
},
"app_resources_expressions": {
Computed: true,
Description: "AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
},
"aws_role_arns": {
Computed: true,
Description: "AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.",
@@ -4438,6 +4503,13 @@ func GenSchemaRoleV6(ctx context.Context) (github_com_hashicorp_terraform_plugin
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"app_resources_expressions": {
Computed: true,
Description: "AppResourcesExpressions is a list of predicates controlling access to an app's resources on each HTTP request. It is valid only in role version v9 and above, and only under allow. Every AppResource rule can be written as an expression, but not the reverse. This version does not implement app_resources_expressions and rejects a role that sets it. The field is declared so that version skew or a rollback cannot silently drop it and widen a role's access.",
Optional: true,
PlanModifiers: []github_com_hashicorp_terraform_plugin_framework_tfsdk.AttributePlanModifier{github_com_hashicorp_terraform_plugin_framework_tfsdk.UseStateForUnknown()},
Type: github_com_hashicorp_terraform_plugin_framework_types.ListType{ElemType: github_com_hashicorp_terraform_plugin_framework_types.StringType},
},
"aws_role_arns": {
Computed: true,
Description: "AWSRoleARNs is a list of AWS role ARNs this role is allowed to assume.",
@@ -37281,6 +37353,104 @@ func CopyRoleV6FromTerraform(_ context.Context, tf github_com_hashicorp_terrafor
if !v.Null && !v.Unknown {
tf := v
obj := &t
{
a, ok := tf.Attrs["paths"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResources.Paths"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Paths", "github.com/hashicorp/terraform-plugin-framework/types.List"})
} else {
obj.Paths = make([]string, len(v.Elems))
if !v.Null && !v.Unknown {
for k, a := range v.Elems {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Paths", "github_com_hashicorp_terraform_plugin_framework_types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.Paths[k] = t
}
}
}
}
}
}
{
a, ok := tf.Attrs["methods"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResources.Methods"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Methods", "github.com/hashicorp/terraform-plugin-framework/types.List"})
} else {
obj.Methods = make([]string, len(v.Elems))
if !v.Null && !v.Unknown {
for k, a := range v.Elems {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Methods", "github_com_hashicorp_terraform_plugin_framework_types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.Methods[k] = t
}
}
}
}
}
}
{
a, ok := tf.Attrs["where"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResources.Where"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Where", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.Where = t
}
}
}
{
a, ok := tf.Attrs["allow_encoded"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResources.AllowEncoded"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.AllowEncoded", "github.com/hashicorp/terraform-plugin-framework/types.List"})
} else {
obj.AllowEncoded = make([]string, len(v.Elems))
if !v.Null && !v.Unknown {
for k, a := range v.Elems {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.AllowEncoded", "github_com_hashicorp_terraform_plugin_framework_types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.AllowEncoded[k] = t
}
}
}
}
}
}
{
a, ok := tf.Attrs["allow_all"]
if !ok {
@@ -37298,6 +37468,74 @@ func CopyRoleV6FromTerraform(_ context.Context, tf github_com_hashicorp_terrafor
}
}
}
{
a, ok := tf.Attrs["allow_code"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResources.AllowCode"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.AllowCode", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.AllowCode = t
}
}
}
{
a, ok := tf.Attrs["allow_reason"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResources.AllowReason"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.AllowReason", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.AllowReason = t
}
}
}
{
a, ok := tf.Attrs["deny_code_hint"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResources.DenyCodeHint"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.DenyCodeHint", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.DenyCodeHint = t
}
}
}
{
a, ok := tf.Attrs["deny_reason_hint"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResources.DenyReasonHint"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.DenyReasonHint", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.DenyReasonHint = t
}
}
}
}
obj.AppResources[k] = t
}
@@ -37306,6 +37544,33 @@ func CopyRoleV6FromTerraform(_ context.Context, tf github_com_hashicorp_terrafor
}
}
}
{
a, ok := tf.Attrs["app_resources_expressions"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Allow.AppResourcesExpressions"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResourcesExpressions", "github.com/hashicorp/terraform-plugin-framework/types.List"})
} else {
obj.AppResourcesExpressions = make([]string, len(v.Elems))
if !v.Null && !v.Unknown {
for k, a := range v.Elems {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Allow.AppResourcesExpressions", "github_com_hashicorp_terraform_plugin_framework_types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.AppResourcesExpressions[k] = t
}
}
}
}
}
}
}
}
}
@@ -39532,6 +39797,33 @@ func CopyRoleV6FromTerraform(_ context.Context, tf github_com_hashicorp_terrafor
}
}
}
{
a, ok := tf.Attrs["app_resources_expressions"]
if !ok {
diags.Append(attrReadMissingDiag{"RoleV6.Spec.Deny.AppResourcesExpressions"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Deny.AppResourcesExpressions", "github.com/hashicorp/terraform-plugin-framework/types.List"})
} else {
obj.AppResourcesExpressions = make([]string, len(v.Elems))
if !v.Null && !v.Unknown {
for k, a := range v.Elems {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"RoleV6.Spec.Deny.AppResourcesExpressions", "github_com_hashicorp_terraform_plugin_framework_types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.AppResourcesExpressions[k] = t
}
}
}
}
}
}
}
}
}
@@ -45575,6 +45867,217 @@ func CopyRoleV6ToTerraformPreserveUnknown(ctx context.Context, obj *github_com_g
v.Null = false
obj := a
tf := &v
{
a, ok := tf.AttrTypes["paths"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResources.Paths"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Paths", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
} else {
c, ok := tf.Attrs["paths"].(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
c = github_com_hashicorp_terraform_plugin_framework_types.List{
ElemType: o.ElemType,
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Paths)),
Null: true,
}
} else {
if c.Elems == nil {
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Paths))
}
}
{
t := o.ElemType
if len(obj.Paths) != len(c.Elems) {
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Paths))
copy(newElems, c.Elems)
c.Elems = newElems
}
for k, a := range obj.Paths {
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if c.Elems[k] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResources.Paths", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResources.Paths", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Paths", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(a)
if !preserveUnknown {
v.Unknown = false
}
c.Elems[k] = v
}
}
c.Null = false
if !preserveUnknown {
c.Unknown = false
}
tf.Attrs["paths"] = c
}
}
}
{
a, ok := tf.AttrTypes["methods"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResources.Methods"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Methods", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
} else {
c, ok := tf.Attrs["methods"].(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
c = github_com_hashicorp_terraform_plugin_framework_types.List{
ElemType: o.ElemType,
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Methods)),
Null: true,
}
} else {
if c.Elems == nil {
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Methods))
}
}
{
t := o.ElemType
if len(obj.Methods) != len(c.Elems) {
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.Methods))
copy(newElems, c.Elems)
c.Elems = newElems
}
for k, a := range obj.Methods {
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if c.Elems[k] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResources.Methods", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResources.Methods", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Methods", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(a)
if !preserveUnknown {
v.Unknown = false
}
c.Elems[k] = v
}
}
c.Null = false
if !preserveUnknown {
c.Unknown = false
}
tf.Attrs["methods"] = c
}
}
}
{
t, ok := tf.AttrTypes["where"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResources.Where"})
} else {
v, ok := tf.Attrs["where"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if tf.Attrs["where"] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResources.Where", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResources.Where", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.Where", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(obj.Where)
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["where"] = v
}
}
{
a, ok := tf.AttrTypes["allow_encoded"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResources.AllowEncoded"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.AllowEncoded", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
} else {
c, ok := tf.Attrs["allow_encoded"].(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
c = github_com_hashicorp_terraform_plugin_framework_types.List{
ElemType: o.ElemType,
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AllowEncoded)),
Null: true,
}
} else {
if c.Elems == nil {
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AllowEncoded))
}
}
{
t := o.ElemType
if len(obj.AllowEncoded) != len(c.Elems) {
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AllowEncoded))
copy(newElems, c.Elems)
c.Elems = newElems
}
for k, a := range obj.AllowEncoded {
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if c.Elems[k] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResources.AllowEncoded", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResources.AllowEncoded", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.AllowEncoded", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(a)
if !preserveUnknown {
v.Unknown = false
}
c.Elems[k] = v
}
}
c.Null = false
if !preserveUnknown {
c.Unknown = false
}
tf.Attrs["allow_encoded"] = c
}
}
}
{
t, ok := tf.AttrTypes["allow_all"]
if !ok {
@@ -45603,6 +46106,118 @@ func CopyRoleV6ToTerraformPreserveUnknown(ctx context.Context, obj *github_com_g
tf.Attrs["allow_all"] = v
}
}
{
t, ok := tf.AttrTypes["allow_code"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResources.AllowCode"})
} else {
v, ok := tf.Attrs["allow_code"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if tf.Attrs["allow_code"] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResources.AllowCode", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResources.AllowCode", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.AllowCode", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(obj.AllowCode)
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["allow_code"] = v
}
}
{
t, ok := tf.AttrTypes["allow_reason"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResources.AllowReason"})
} else {
v, ok := tf.Attrs["allow_reason"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if tf.Attrs["allow_reason"] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResources.AllowReason", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResources.AllowReason", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.AllowReason", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(obj.AllowReason)
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["allow_reason"] = v
}
}
{
t, ok := tf.AttrTypes["deny_code_hint"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResources.DenyCodeHint"})
} else {
v, ok := tf.Attrs["deny_code_hint"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if tf.Attrs["deny_code_hint"] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResources.DenyCodeHint", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResources.DenyCodeHint", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.DenyCodeHint", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(obj.DenyCodeHint)
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["deny_code_hint"] = v
}
}
{
t, ok := tf.AttrTypes["deny_reason_hint"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResources.DenyReasonHint"})
} else {
v, ok := tf.Attrs["deny_reason_hint"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if tf.Attrs["deny_reason_hint"] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResources.DenyReasonHint", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResources.DenyReasonHint", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResources.DenyReasonHint", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(obj.DenyReasonHint)
if !preserveUnknown {
v.Unknown = false
}
tf.Attrs["deny_reason_hint"] = v
}
}
}
if !preserveUnknown {
v.Unknown = false
@@ -45618,6 +46233,67 @@ func CopyRoleV6ToTerraformPreserveUnknown(ctx context.Context, obj *github_com_g
}
}
}
{
a, ok := tf.AttrTypes["app_resources_expressions"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Allow.AppResourcesExpressions"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResourcesExpressions", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
} else {
c, ok := tf.Attrs["app_resources_expressions"].(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
c = github_com_hashicorp_terraform_plugin_framework_types.List{
ElemType: o.ElemType,
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AppResourcesExpressions)),
Null: true,
}
} else {
if c.Elems == nil {
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AppResourcesExpressions))
}
}
{
t := o.ElemType
if len(obj.AppResourcesExpressions) != len(c.Elems) {
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AppResourcesExpressions))
copy(newElems, c.Elems)
c.Elems = newElems
}
for k, a := range obj.AppResourcesExpressions {
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if c.Elems[k] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Allow.AppResourcesExpressions", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Allow.AppResourcesExpressions", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Allow.AppResourcesExpressions", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(a)
if !preserveUnknown {
v.Unknown = false
}
c.Elems[k] = v
}
}
c.Null = false
if !preserveUnknown {
c.Unknown = false
}
tf.Attrs["app_resources_expressions"] = c
}
}
}
}
if !preserveUnknown {
v.Unknown = false
@@ -50091,6 +50767,67 @@ func CopyRoleV6ToTerraformPreserveUnknown(ctx context.Context, obj *github_com_g
tf.Attrs["beam_labels_expression"] = v
}
}
{
a, ok := tf.AttrTypes["app_resources_expressions"]
if !ok {
diags.Append(attrWriteMissingDiag{"RoleV6.Spec.Deny.AppResourcesExpressions"})
} else {
o, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.ListType)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Deny.AppResourcesExpressions", "github.com/hashicorp/terraform-plugin-framework/types.ListType"})
} else {
c, ok := tf.Attrs["app_resources_expressions"].(github_com_hashicorp_terraform_plugin_framework_types.List)
if !ok {
c = github_com_hashicorp_terraform_plugin_framework_types.List{
ElemType: o.ElemType,
Elems: make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AppResourcesExpressions)),
Null: true,
}
} else {
if c.Elems == nil {
c.Elems = make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AppResourcesExpressions))
}
}
{
t := o.ElemType
if len(obj.AppResourcesExpressions) != len(c.Elems) {
newElems := make([]github_com_hashicorp_terraform_plugin_framework_attr.Value, len(obj.AppResourcesExpressions))
copy(newElems, c.Elems)
c.Elems = newElems
}
for k, a := range obj.AppResourcesExpressions {
v, ok := c.Elems[k].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
if c.Elems[k] != nil {
diags.Append(attrWriteUnexpectedExistingTypeDiag{"RoleV6.Spec.Deny.AppResourcesExpressions", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"RoleV6.Spec.Deny.AppResourcesExpressions", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"RoleV6.Spec.Deny.AppResourcesExpressions", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
}
v.Null = false
v.Value = string(a)
if !preserveUnknown {
v.Unknown = false
}
c.Elems[k] = v
}
}
c.Null = false
if !preserveUnknown {
c.Unknown = false
}
tf.Attrs["app_resources_expressions"] = c
}
}
}
}
if !preserveUnknown {
v.Unknown = false
+4 -1
View File
@@ -2358,7 +2358,8 @@ func maybeDowngradeRoleVersionToV8(ctx context.Context, role *types.RoleV6, clie
role.Version = types.V8
detail := "The allow_all rule grants exactly the v8 app access, so app access is unchanged."
if !types.AppResourcesAllowAll(role.Spec.Allow.AppResources, role.Spec.Deny.AppResources) {
if !types.AppResourcesAllowAll(role.Spec.Allow.AppResources, role.Spec.Deny.AppResources) ||
len(role.Spec.Allow.AppResourcesExpressions) > 0 || len(role.Spec.Deny.AppResourcesExpressions) > 0 {
if denyDowngradedAppAccess(role) {
slog.WarnContext(ctx,
"Downgraded v9 role already denied apps by label, so its app access was denied with a wildcard on this pre-v9 client; this also denies apps the role did not govern",
@@ -2368,6 +2369,8 @@ func maybeDowngradeRoleVersionToV8(ctx context.Context, role *types.RoleV6, clie
}
role.Spec.Allow.AppResources = nil
role.Spec.Deny.AppResources = nil
role.Spec.Allow.AppResourcesExpressions = nil
role.Spec.Deny.AppResourcesExpressions = nil
reason := fmt.Sprintf("Role v9 is only supported from client version %q and above. %s", minSupportedRoleV9Version, detail)
if role.Metadata.Labels == nil {
+16
View File
@@ -7209,6 +7209,22 @@ func TestMaybeDowngradeRoleVersionToV8(t *testing.T) {
require.Empty(t, got.Spec.Deny.AppResources)
})
t.Run("allow expressions strip app access even with allow_all", func(t *testing.T) {
input := newV9Role(allowAll)
input.Spec.Allow.AppResourcesExpressions = []string{`path.match(literal("api"))`}
got := auth.MaybeDowngradeRoleVersionToV8(t.Context(), input, clientVersion(t, "18.1.2"))
assertAppAccessDenied(t, got)
require.Empty(t, got.Spec.Allow.AppResourcesExpressions)
})
t.Run("deny expressions strip app access even with allow_all", func(t *testing.T) {
input := newV9Role(allowAll)
input.Spec.Deny.AppResourcesExpressions = []string{`path.match(literal("admin"))`}
got := auth.MaybeDowngradeRoleVersionToV8(t.Context(), input, clientVersion(t, "18.1.2"))
assertAppAccessDenied(t, got)
require.Empty(t, got.Spec.Deny.AppResourcesExpressions)
})
t.Run("deny scopes to the role's own labels, not a blanket wildcard", func(t *testing.T) {
input := newV9Role(ruleWithoutAllowAll)
input.Spec.Allow.AppLabels = types.Labels{"vendor": []string{"gitlab"}}
+10 -3
View File
@@ -297,18 +297,25 @@ func ValidateRole(r types.Role) error {
}
// validateAppResources rejects an app_resources rule set that this version
// cannot enforce, for example a rule with an unknown field. It runs on create
// and update only, not on read.
// cannot enforce, for example a rule with an unknown field. It also rejects
// any app_resources_expressions. It runs on create and update only, not on
// read.
func validateAppResources(r types.Role) error {
if len(r.GetAppResources(types.Deny)) > 0 {
return trace.BadParameter("app_resources is not allowed under deny")
}
if len(r.GetAppResourcesExpressions(types.Deny)) > 0 {
return trace.BadParameter("app_resources_expressions is not allowed under deny")
}
if len(r.GetAppResourcesExpressions(types.Allow)) > 0 {
return trace.BadParameter("app_resources_expressions is not supported in this version, only app_resources with allow_all is honored")
}
allow := r.GetAppResources(types.Allow)
for i, rule := range allow {
// The backend JSON marshal drops unknown fields. Storing such a
// rule would silently widen it to unrestricted access.
if !rule.IsAllowAllOnly() {
return trace.BadParameter("app_resources[%d]: a rule must set allow_all and nothing else; paths, methods, and where rules are not yet supported", i)
return trace.BadParameter("app_resources[%d]: this version implements allow_all only, so a rule must set allow_all and nothing else", i)
}
}
// Every rule sets allow_all at this point, so more than one rule can
+23 -2
View File
@@ -1748,19 +1748,40 @@ func TestValidateRoleAppResources(t *testing.T) {
require.NoError(t, err)
err = ValidateRole(newV9Role([]types.AppResource{{AllowAll: true}, {}}, nil))
require.ErrorContains(t, err, "app_resources[1]: a rule must set allow_all")
require.ErrorContains(t, err, "app_resources[1]: this version implements allow_all only")
err = ValidateRole(newV9Role([]types.AppResource{{AllowAll: true}, {AllowAll: true}}, nil))
require.ErrorContains(t, err, "app_resources: a rule setting allow_all must be the only rule")
// Unknown proto bytes from a newer client must be rejected. The JSON
// marshal into the backend would drop them and widen the rule.
combined := types.AppResource{AllowAll: true, XXX_unrecognized: []byte{0x0a, 0x01, 0x2f}}
combined := types.AppResource{AllowAll: true, XXX_unrecognized: []byte{0x50, 0x01}}
err = ValidateRole(newV9Role([]types.AppResource{combined}, nil))
require.ErrorContains(t, err, "a rule must set allow_all and nothing else")
err = ValidateRole(newV9Role(nil, []types.AppResource{{AllowAll: true}}))
require.ErrorContains(t, err, "app_resources is not allowed under deny")
// A declared field is rejected at write, so a stored rule is never
// wider than the agent honors.
for name, rule := range map[string]types.AppResource{
"paths": {AllowAll: true, Paths: []string{"/api/**"}},
"methods": {AllowAll: true, Methods: []string{"GET"}},
"where": {AllowAll: true, Where: "true"},
} {
err := ValidateRole(newV9Role([]types.AppResource{rule}, nil))
require.ErrorContains(t, err, "a rule must set allow_all and nothing else", "field %s", name)
}
exprRole := newV9Role([]types.AppResource{{AllowAll: true}}, nil).(*types.RoleV6)
exprRole.Spec.Allow.AppResourcesExpressions = []string{`path.match(literal("api"))`}
err = ValidateRole(exprRole)
require.ErrorContains(t, err, "app_resources_expressions is not supported")
denyExprRole := newV9Role(nil, nil).(*types.RoleV6)
denyExprRole.Spec.Deny.AppResourcesExpressions = []string{"true"}
err = ValidateRole(denyExprRole)
require.ErrorContains(t, err, "app_resources_expressions is not allowed under deny")
}
func TestValidateRoleName(t *testing.T) {
+24 -15
View File
@@ -47,10 +47,11 @@ type minimalV9Decision struct {
// droppedRoles names the pre-v9 roles dropped because a v9 role grants
// the same app. They are logged, never allowed to re-open access.
droppedRoles []string
// versionSkew is true when the roles carry app rules or versions a
// newer Teleport wrote and this version cannot evaluate: deny-side
// rules, allow rules beyond a single pure allow_all, or a role
// version above v9.
// versionSkew is true when the roles set app rules, predicates, or
// versions a newer Teleport wrote and this version cannot evaluate.
// The cases are deny-side rules or predicates, allow rules beyond a
// single pure allow_all, allow-side predicates, and a role version
// above v9.
versionSkew bool
}
@@ -67,20 +68,21 @@ func roleVersionPredatesV9(version string) bool {
// decideMinimalV9 applies the minimal v9 policy to the caller's roles that
// grant app. If only pre-v9 roles grant it, the request keeps full v8
// behavior. Otherwise pre-v9 roles granting the app are dropped and the
// request is denied unless a granting v9 role holds a single allow_all rule
// and no role carries deny-side app rules. A role newer than v9 still
// enforces but never allows, since it may carry restrictions this version
// cannot evaluate.
// request is denied unless a granting v9 role holds a single allow_all rule,
// sets no app_resources_expressions, and no role sets a deny-side rule or
// predicate. A role newer than v9 still enforces but never allows, since it
// may set restrictions this version cannot evaluate.
//
// TODO(@juliaogris): Replace with per-request rule matching from the
// upcoming lib/appresource engine package.
func decideMinimalV9(roles []types.Role, app types.Application, username string, traits wrappers.Traits) minimalV9Decision {
// This version cannot evaluate deny-side app rules, which could only
// occur in roles from newer versions. Deny beats allow across the
// whole role set, so any role carrying them blocks allow_all
// and the request is denied.
// This version cannot evaluate deny-side app rules or predicates, which
// could only occur in roles from newer versions. Deny beats allow across
// the whole role set, so any role that sets either blocks allow_all and
// the request is denied.
denyAppRules := slices.ContainsFunc(roles, func(role types.Role) bool {
return len(role.GetAppResources(types.Deny)) > 0
return len(role.GetAppResources(types.Deny)) > 0 ||
len(role.GetAppResourcesExpressions(types.Deny)) > 0
})
decision := minimalV9Decision{versionSkew: denyAppRules}
@@ -101,9 +103,16 @@ func decideMinimalV9(roles []types.Role, app types.Application, username string,
continue
}
allow := role.GetAppResources(types.Allow)
if types.AppResourcesAllowAll(allow, role.GetAppResources(types.Deny)) {
allowExpressions := role.GetAppResourcesExpressions(types.Allow)
switch {
case len(allowExpressions) > 0:
// A predicate restricts the rules it accompanies, and this
// version cannot evaluate one, so the role denies whether or
// not its declarative rules read as allow_all.
decision.versionSkew = true
case types.AppResourcesAllowAll(allow, role.GetAppResources(types.Deny)):
decision.allowed = !denyAppRules
} else if len(allow) > 0 {
case len(allow) > 0:
// This version can only write a single pure allow_all rule, so
// any other non-empty rule set must come from a newer version.
decision.versionSkew = true
+30
View File
@@ -105,6 +105,21 @@ func TestDecideMinimalV9(t *testing.T) {
AppLabels: prodLabels,
})
v9OtherDenyRules.(*types.RoleV6).Spec.Deny.AppResources = []types.AppResource{{}}
// A predicate restricts the rules it accompanies, so allow_all next to
// one is not unrestricted.
v9AllowAllWithExpressions := newTestRole(t, "v9-allow-all-expressions", types.V9, types.RoleConditions{
AppLabels: devLabels,
AppResources: []types.AppResource{{AllowAll: true}},
})
v9AllowAllWithExpressions.(*types.RoleV6).Spec.Allow.AppResourcesExpressions = []string{`path.match(literal("api"))`}
v9ExpressionsOnly := newTestRole(t, "v9-expressions-only", types.V9, types.RoleConditions{
AppLabels: devLabels,
})
v9ExpressionsOnly.(*types.RoleV6).Spec.Allow.AppResourcesExpressions = []string{`path.match(literal("api"))`}
v9DenyExpressions := newTestRole(t, "v9-deny-expressions", types.V9, types.RoleConditions{
AppLabels: prodLabels,
})
v9DenyExpressions.(*types.RoleV6).Spec.Deny.AppResourcesExpressions = []string{`path.match(literal("admin"))`}
for _, tc := range []struct {
desc string
@@ -166,6 +181,21 @@ func TestDecideMinimalV9(t *testing.T) {
roles: []types.Role{v9AllowAll, v9OtherDenyRules},
want: minimalV9Decision{enforced: true, versionSkew: true},
},
{
desc: "allow expressions block allow_all",
roles: []types.Role{v9AllowAllWithExpressions},
want: minimalV9Decision{enforced: true, versionSkew: true},
},
{
desc: "allow expressions without rules deny",
roles: []types.Role{v9ExpressionsOnly},
want: minimalV9Decision{enforced: true, versionSkew: true},
},
{
desc: "deny expressions in another role block allow_all",
roles: []types.Role{v9AllowAll, v9DenyExpressions},
want: minimalV9Decision{enforced: true, versionSkew: true},
},
} {
t.Run(tc.desc, func(t *testing.T) {
require.Equal(t, tc.want, decideMinimalV9(tc.roles, app, "alice", nil))