mirror of
https://github.com/gravitational/teleport.git
synced 2026-10-11 22:49:54 +00:00
Remove RFDs (#240)
Export-Source-Commit: c091c8a66a40c100dc8a427d72da1196c5d2d47e
This commit is contained in:
committed by
Gus Rivera
parent
0d7267b3ed
commit
a9e65b44ec
@@ -14,7 +14,7 @@
|
||||
- Data corruption, durability failures, or irreversible loss scenarios
|
||||
- Concurrency hazards that can cause outages or data races
|
||||
- Reliability regressions: crash loops, panics, deadlocks, unbounded retries, nil pointer dereferences
|
||||
- Adherence to the guidelines defined in [RFD 153](./rfd/0153-resource-guidelines.md) of Teleport resource definitations, gRPC, backend storage, and cache APIs.
|
||||
- Adherence to the guidelines defined in [RFD 153](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0153-resource-guidelines.md) of Teleport resource definitions, gRPC, backend storage, and cache APIs.
|
||||
|
||||
### Documentation
|
||||
|
||||
|
||||
@@ -120,9 +120,9 @@ The framework is organized into four layers that build on each other: identity,
|
||||
Agents operate on behalf of principals while preserving approval/authorization workflows.
|
||||
<hr />
|
||||
<ul>
|
||||
<li><a href="https://github.com/gravitational/teleport/blob/master/rfd/0238-delegating-access-to-ai-workloads.md">Delegation Flows</a></li>
|
||||
<li><a href="https://github.com/gravitational/teleport/blob/master/rfd/0238-delegating-access-to-ai-workloads.md#starting-a-session-from-tsh">Session Management</a></li>
|
||||
<li><a href="https://github.com/gravitational/teleport/blob/master/rfd/0238-delegating-access-to-ai-workloads.md#access-controls">Access Control</a></li>
|
||||
<li><a href="https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0238-delegating-access-to-ai-workloads.md">Delegation Flows</a></li>
|
||||
<li><a href="https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0238-delegating-access-to-ai-workloads.md#starting-a-session-from-tsh">Session Management</a></li>
|
||||
<li><a href="https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0238-delegating-access-to-ai-workloads.md#access-controls">Access Control</a></li>
|
||||
</ul>
|
||||
</Method>
|
||||
<Method
|
||||
|
||||
@@ -429,5 +429,5 @@ To gather logs from Teleport Connect, attach all files from
|
||||
|
||||
- Read our VNet configuration [guide](../../enroll-resources/application-access/vnet.mdx)
|
||||
to learn how to configure VNet access to your applications.
|
||||
- Read [RFD 163](https://github.com/gravitational/teleport/blob/master/rfd/0163-vnet.md) to learn how VNet works on a technical level.
|
||||
- Read [RFD 207](https://github.com/gravitational/teleport/blob/master/rfd/0207-vnet-ssh.md) to learn how VNet SSH access works.
|
||||
- Read [RFD 163](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0163-vnet.md) to learn how VNet works on a technical level.
|
||||
- Read [RFD 207](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0207-vnet-ssh.md) to learn how VNet SSH access works.
|
||||
|
||||
@@ -191,4 +191,4 @@ clients.
|
||||
|
||||
- Read our VNet usage [guide](../../connect-your-client/teleport-clients/vnet.mdx) for end-users
|
||||
accessing your applications with VNet.
|
||||
- Read [RFD 163](https://github.com/gravitational/teleport/blob/master/rfd/0163-vnet.md) to learn how VNet works on a technical level.
|
||||
- Read [RFD 163](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0163-vnet.md) to learn how VNet works on a technical level.
|
||||
|
||||
@@ -75,4 +75,4 @@ Users created within the database will:
|
||||
|
||||
- Connect using your [GUI database client](../../../connect-your-client/third-party/gui-clients.mdx).
|
||||
- Learn about [role templating](../../../zero-trust-access/rbac-get-started/role-templates.mdx).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/master/rfd/0113-automatic-database-users.md).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0113-automatic-database-users.md).
|
||||
|
||||
@@ -170,4 +170,4 @@ database queries in the Teleport Audit Logs, when the Teleport username is over
|
||||
|
||||
- Connect using your [GUI database client](../../../connect-your-client/third-party/gui-clients.mdx).
|
||||
- Learn about [role templating](../../../zero-trust-access/rbac-get-started/role-templates.mdx).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/master/rfd/0113-automatic-database-users.md).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0113-automatic-database-users.md).
|
||||
|
||||
@@ -150,4 +150,4 @@ Users created within the database will:
|
||||
- Learn more about MongoDB [built-in roles](https://www.mongodb.com/docs/manual/reference/built-in-roles/) and [User-Defined Roles](https://www.mongodb.com/docs/manual/core/security-user-defined-roles/).
|
||||
- Connect using your [GUI database client](../../../connect-your-client/third-party/gui-clients.mdx).
|
||||
- Learn about [role templating](../../../zero-trust-access/rbac-get-started/role-templates.mdx).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/master/rfd/0113-automatic-database-users.md).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0113-automatic-database-users.md).
|
||||
|
||||
@@ -170,4 +170,4 @@ endpoints. Please use auto-user provisioning on the primary endpoints.
|
||||
|
||||
- Connect using your [GUI database client](../../../connect-your-client/third-party/gui-clients.mdx).
|
||||
- Learn about [role templating](../../../zero-trust-access/rbac-get-started/role-templates.mdx).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/master/rfd/0113-automatic-database-users.md).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0113-automatic-database-users.md).
|
||||
|
||||
@@ -320,8 +320,8 @@ admin user through Teleport.
|
||||
client](../../../connect-your-client/third-party/gui-clients.mdx).
|
||||
- Learn about [role
|
||||
templating](../../../zero-trust-access/rbac-get-started/role-templates.mdx).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/master/rfd/0113-automatic-database-users.md).
|
||||
- Read database permission management [RFD](https://github.com/gravitational/teleport/blob/master/rfd/0151-database-permission-management.md).
|
||||
- Read automatic user provisioning [RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0113-automatic-database-users.md).
|
||||
- Read database permission management [RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0151-database-permission-management.md).
|
||||
- The `internal.db_roles` traits we illustrated in this guide
|
||||
are replaced with values from the Teleport local user database. For full
|
||||
details on how variable expansion works in Teleport roles, see the [Teleport
|
||||
|
||||
@@ -230,9 +230,9 @@ Web UI. Based on these messages, the Teleport Web UI advertises information
|
||||
about—or performs modifications on—the shared directory.
|
||||
|
||||
You can read more about TDP in [Teleport RFD
|
||||
37](https://github.com/gravitational/teleport/blob/master/rfd/0037-desktop-access-protocol.md)
|
||||
37](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0037-desktop-access-protocol.md)
|
||||
and how Directory Sharing uses it in [RFD
|
||||
67](https://github.com/gravitational/teleport/blob/master/rfd/0067-desktop-access-file-system-sharing.md).
|
||||
67](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0067-desktop-access-file-system-sharing.md).
|
||||
|
||||
#### In Teleport Connect
|
||||
|
||||
|
||||
@@ -31,7 +31,7 @@ The OpenSSH server will be set up to trust connections from the Proxy Service ra
|
||||
connections from users. This ensures that all connections to OpenSSH servers go through the
|
||||
Proxy Service, where session IO and audit events can be recorded and RBAC can be enforced.
|
||||
|
||||
For deeper details as to how this works, you may be interested in the [Registered OpenSSH Nodes RFD](https://github.com/gravitational/teleport/blob/master/rfd/0098-registered-openssh-nodes.md)
|
||||
For deeper details as to how this works, you may be interested in the [Registered OpenSSH Nodes RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0098-registered-openssh-nodes.md)
|
||||
Below are some key details from the RFD:
|
||||
- The Proxy Service is uniquely able to request certificates signed by the Auth Service with the Teleport OpenSSH CA on behalf of users, and the OpenSSH server is set up to only trust certificates signed by this CA. Therefore, in order to connect to an OpenSSH server, a user must connect through the Proxy Service to request and use an OpenSSH certificate.
|
||||
- Before connecting the user to the OpenSSH server, the Proxy Service performs RBAC checks to see if the user should be allowed to access it.
|
||||
|
||||
@@ -29,7 +29,7 @@ The OpenSSH server will be set up to trust connections from the Proxy Service ra
|
||||
connections from users. This ensures that all connections to OpenSSH servers go through the
|
||||
Proxy Service, where session IO and audit events can be recorded and RBAC can be enforced.
|
||||
|
||||
For deeper details as to how this works, you may be interested in the [Registered OpenSSH Nodes RFD](https://github.com/gravitational/teleport/blob/master/rfd/0098-registered-openssh-nodes.md)
|
||||
For deeper details as to how this works, you may be interested in the [Registered OpenSSH Nodes RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0098-registered-openssh-nodes.md)
|
||||
Below are some key details from the RFD:
|
||||
- The Proxy Service is uniquely able to request certificates signed by the Auth Service with the Teleport OpenSSH CA on behalf of users, and the OpenSSH server is set up to only trust certificates signed by this CA. Therefore, in order to connect to an OpenSSH server, a user must connect through the Proxy to request and use an OpenSSH certificate.
|
||||
- Before connecting the user to the OpenSSH server, the Proxy Service performs RBAC checks to see if the user should be allowed to access it.
|
||||
|
||||
@@ -13,7 +13,7 @@ inner workings.
|
||||
|
||||
The initial specification and design for Machine & Workload Identity can be
|
||||
found in
|
||||
[the Request For Discussion.](https://github.com/gravitational/teleport/blob/master/rfd/0064-bot-for-cert-renewals.md)
|
||||
[the Request For Discussion.](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0064-bot-for-cert-renewals.md)
|
||||
|
||||
## What is a bot?
|
||||
|
||||
|
||||
@@ -268,4 +268,4 @@ behind layer 7 load balancers.
|
||||
|
||||
- See [migration guide](../../zero-trust-access/management/tls-routing.mdx) to learn how to
|
||||
upgrade an existing cluster to use TLS routing.
|
||||
- Read through TLS routing design document [RFD](https://github.com/gravitational/teleport/blob/master/rfd/0039-sni-alpn-teleport-proxy-routing.md).
|
||||
- Read through TLS routing design document [RFD](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0039-sni-alpn-teleport-proxy-routing.md).
|
||||
|
||||
@@ -279,7 +279,7 @@ The `identity/key-agent` service provides similar functionality to the
|
||||
`identity` output service, but makes it impossible to steal or exfiltrate the
|
||||
generated identity by keeping private key material entirely in memory.
|
||||
|
||||
It works similarly to the [Hardware Key Agent](https://github.com/gravitational/teleport/blob/master/rfd/0199-hardware-key-agent.md)
|
||||
It works similarly to the [Hardware Key Agent](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0199-hardware-key-agent.md)
|
||||
in that it runs a gRPC service on a Unix socket, which the Teleport Client calls
|
||||
to perform cryptographic signing operations.
|
||||
|
||||
|
||||
@@ -301,4 +301,4 @@ the file transfer automatically begins.
|
||||
|
||||
## See also
|
||||
|
||||
- [Moderated Sessions](https://github.com/gravitational/teleport/blob/master/rfd/0043-kubeaccess-multiparty.md)
|
||||
- [Moderated Sessions](https://github.com/gravitational/teleport/blob/8ff3d34581424302182c217e4d8d3be45bf2b0b7/rfd/0043-kubeaccess-multiparty.md)
|
||||
|
||||
Reference in New Issue
Block a user