mirror of
https://github.com/gravitational/teleport.git
synced 2026-10-11 22:49:54 +00:00
Add a Configuring Teleport docs section (#66255)
* Add a Configuring Teleport docs section Make the how-to guides for managing Teleport resources with Infrastructure as Code tools more prominent by placing them in a Configuring Teleport section next to other foundational docs sections, e.g., Installation and Upgrading. Frame the task of managing Teleport with IaC as part of the broader task of configuring Teleport. To do so, move the introduction of the "Static and Dynamic Resources" page to a landing page for the new Configuration section. Move the remaining part of that page to the References section, since it's an advanced guide and more of a reference than a set of how-to instructions. This change also structures the Infrastructure as Code landing page into a Configure Teleport landing page by including links to guides for static as well as dynamic configuration. This adds clarity to the docs since users won't immediately know that Teleport exposes these two configuration variants. * Update internal links * Fix issues with the Configuring Teleport section - Update the static/dynamic field table to use the correct field name, `spec.mode`. - Change "Managing Resources" to "Resource Guides" for clarity, since all sections in Configuring Teleport would be about managing resources. - Reorder Configuration sidebar sections to move Resource Guides last and tctl before Terraform and Kubernetes.
This commit is contained in:
+2
-2
@@ -3937,7 +3937,7 @@ access start time up to a week in advance.
|
||||
|
||||
The Teleport Terraform provider and Kubernetes operator now support declaring
|
||||
agentless OpenSSH and OpenSSH EC2 ICE servers. You can follow [this
|
||||
guide](docs/pages/zero-trust-access/infrastructure-as-code/managing-resources/agentless-ssh-servers.mdx)
|
||||
guide](docs/pages/configuration/resource-guides/agentless-ssh-servers.mdx)
|
||||
to register OpenSSH agents with infrastructure as code.
|
||||
|
||||
Setting up EC2 ICE automatic discovery with IaC will come in a future update.
|
||||
@@ -4317,7 +4317,7 @@ When deployed with the `teleport-cluster` chart, the operator now runs in a
|
||||
separate pod. This ensures that Teleport's availability won't be impacted if the
|
||||
operator becomes unready.
|
||||
|
||||
See [the Standalone Operator guide](docs/pages/zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator-standalone.mdx)
|
||||
See [the Standalone Operator guide](docs/pages/configuration/teleport-operator/teleport-operator-standalone.mdx)
|
||||
for installation instructions.
|
||||
|
||||
#### Roles v6 and v7 support for Kubernetes Operator
|
||||
|
||||
+192
-27
@@ -1027,112 +1027,112 @@
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/",
|
||||
"destination": "/configuration/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/managing-resources/agentless-ssh-servers/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/managing-resources/agentless-ssh-servers/",
|
||||
"destination": "/configuration/resource-guides/agentless-ssh-servers/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/managing-resources/import-existing-resources/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/import-existing-resources/",
|
||||
"destination": "/configuration/terraform-provider/import-existing-resources/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/managing-resources/login-rules-operator/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/managing-resources/login-rules-operator/",
|
||||
"destination": "/configuration/resource-guides/login-rules-operator/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/managing-resources/login-rules-terraform/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/managing-resources/login-rules-terraform/",
|
||||
"destination": "/configuration/resource-guides/login-rules-terraform/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/managing-resources/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/managing-resources/",
|
||||
"destination": "/configuration/resource-guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/managing-resources/trusted-cluster/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/managing-resources/trusted-cluster/",
|
||||
"destination": "/configuration/resource-guides/trusted-cluster/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/managing-resources/user-and-role/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/managing-resources/user-and-role/",
|
||||
"destination": "/configuration/resource-guides/user-and-role/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/teleport-operator/secret-lookup/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/teleport-operator/secret-lookup/",
|
||||
"destination": "/configuration/teleport-operator/secret-lookup/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/teleport-operator/teleport-operator-helm/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator-helm/",
|
||||
"destination": "/configuration/teleport-operator/teleport-operator-helm/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/teleport-operator/teleport-operator-standalone/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator-standalone/",
|
||||
"destination": "/configuration/teleport-operator/teleport-operator-standalone/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/teleport-operator/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/teleport-operator/",
|
||||
"destination": "/configuration/teleport-operator/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-provider/ci-or-cloud/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/ci-or-cloud/",
|
||||
"destination": "/configuration/terraform-provider/ci-or-cloud/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-provider/dedicated-server/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/dedicated-server/",
|
||||
"destination": "/configuration/terraform-provider/dedicated-server/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-provider/local/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/local/",
|
||||
"destination": "/configuration/terraform-provider/local/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-provider/long-lived-credentials/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/long-lived-credentials/",
|
||||
"destination": "/configuration/terraform-provider/long-lived-credentials/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-provider/spacelift/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/spacelift/",
|
||||
"destination": "/configuration/terraform-provider/spacelift/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-provider/terraform-cloud/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-cloud/",
|
||||
"destination": "/configuration/terraform-provider/terraform-cloud/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-provider/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/",
|
||||
"destination": "/configuration/terraform-provider/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-starter/enroll-resources/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started/",
|
||||
"destination": "/configuration/terraform-provider/terraform-getting-started/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-starter/rbac/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started/",
|
||||
"destination": "/configuration/terraform-provider/terraform-getting-started/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/admin-guides/infrastructure-as-code/terraform-starter/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started/",
|
||||
"destination": "/configuration/terraform-provider/terraform-getting-started/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -2547,17 +2547,17 @@
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-starter/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started/",
|
||||
"destination": "/configuration/terraform-provider/terraform-getting-started/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-starter/enroll-resources/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started/",
|
||||
"destination": "/configuration/terraform-provider/terraform-getting-started/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-starter/rbac/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started/",
|
||||
"destination": "/configuration/terraform-provider/terraform-getting-started/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -3097,7 +3097,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/import-existing-resources/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/terraform-provider/import-existing-resources/",
|
||||
"destination": "/configuration/terraform-provider/import-existing-resources/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -3532,7 +3532,7 @@
|
||||
},
|
||||
{
|
||||
"source": "/identity-governance/access-lists/terraform/",
|
||||
"destination": "/zero-trust-access/infrastructure-as-code/managing-resources/access-list/",
|
||||
"destination": "/configuration/resource-guides/access-list/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
@@ -3819,6 +3819,171 @@
|
||||
"source": "/reference/infrastructure-as-code/teleport-resources/db/",
|
||||
"destination": "/reference/infrastructure-as-code/teleport-resources/database-v3/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/",
|
||||
"destination": "/configuration/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/access-list/",
|
||||
"destination": "/configuration/resource-guides/access-list/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/agentless-ssh-servers/",
|
||||
"destination": "/configuration/resource-guides/agentless-ssh-servers/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/kubernetes-oidc-join-token/",
|
||||
"destination": "/configuration/resource-guides/kubernetes-oidc-join-token/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/login-rules-operator/",
|
||||
"destination": "/configuration/resource-guides/login-rules-operator/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/login-rules-terraform/",
|
||||
"destination": "/configuration/resource-guides/login-rules-terraform/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/",
|
||||
"destination": "/configuration/resource-guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/trusted-cluster/",
|
||||
"destination": "/configuration/resource-guides/trusted-cluster/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/managing-resources/user-and-role/",
|
||||
"destination": "/configuration/resource-guides/user-and-role/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/static-and-dynamic-configuration/",
|
||||
"destination": "/reference/deployment/static-and-dynamic-configuration/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/teleport-operator/secret-lookup/",
|
||||
"destination": "/configuration/teleport-operator/secret-lookup/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator-helm/",
|
||||
"destination": "/configuration/teleport-operator/teleport-operator-helm/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator-standalone/",
|
||||
"destination": "/configuration/teleport-operator/teleport-operator-standalone/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/teleport-operator/",
|
||||
"destination": "/configuration/teleport-operator/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/ci-or-cloud/",
|
||||
"destination": "/configuration/terraform-provider/ci-or-cloud/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/dedicated-server/",
|
||||
"destination": "/configuration/terraform-provider/dedicated-server/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/env0/",
|
||||
"destination": "/configuration/terraform-provider/env0/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/import-existing-resources/",
|
||||
"destination": "/configuration/terraform-provider/import-existing-resources/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/local/",
|
||||
"destination": "/configuration/terraform-provider/local/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/long-lived-credentials/",
|
||||
"destination": "/configuration/terraform-provider/long-lived-credentials/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/spacelift/",
|
||||
"destination": "/configuration/terraform-provider/spacelift/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-cloud/",
|
||||
"destination": "/configuration/terraform-provider/terraform-cloud/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started/",
|
||||
"destination": "/configuration/terraform-provider/terraform-getting-started/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/terraform-provider/",
|
||||
"destination": "/configuration/terraform-provider/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/zero-trust-access/infrastructure-as-code/using-tctl/",
|
||||
"destination": "/configuration/using-tctl/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/configuration/managing-resources/access-list/",
|
||||
"destination": "/configuration/resource-guides/access-list/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/configuration/managing-resources/agentless-ssh-servers/",
|
||||
"destination": "/configuration/resource-guides/agentless-ssh-servers/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/configuration/managing-resources/kubernetes-oidc-join-token/",
|
||||
"destination": "/configuration/resource-guides/kubernetes-oidc-join-token/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/configuration/managing-resources/login-rules-operator/",
|
||||
"destination": "/configuration/resource-guides/login-rules-operator/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/configuration/managing-resources/login-rules-terraform/",
|
||||
"destination": "/configuration/resource-guides/login-rules-terraform/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/configuration/managing-resources/",
|
||||
"destination": "/configuration/resource-guides/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/configuration/managing-resources/trusted-cluster/",
|
||||
"destination": "/configuration/resource-guides/trusted-cluster/",
|
||||
"permanent": true
|
||||
},
|
||||
{
|
||||
"source": "/configuration/managing-resources/user-and-role/",
|
||||
"destination": "/configuration/resource-guides/user-and-role/",
|
||||
"permanent": true
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -0,0 +1,271 @@
|
||||
---
|
||||
title: Configure Teleport
|
||||
description: Configure users, roles, authentication connectors, and more with tctl, Terraform, and Kubernetes resources.
|
||||
template: doc-page
|
||||
sidebar_label: Configuration
|
||||
tags:
|
||||
- infrastructure-as-code
|
||||
- conceptual
|
||||
- zero-trust
|
||||
---
|
||||
import Resources from "@site/src/components/Pages/Homepage/Resources";
|
||||
|
||||
import terraformSvg from "@site/src/components/Icon/svg/terraform.svg";
|
||||
import kubernetesClustersSvg from "@site/src/components/Icon/teleport-svg/kubernetes-clusters.svg";
|
||||
import cliSvg from "@site/src/components/Icon/teleport-svg/cli.svg";
|
||||
import userListSvg from "@site/src/components/Icon/svg/user-list.svg";
|
||||
import hardDrivesSvg from "@site/src/components/Icon/svg/hard-drives.svg";
|
||||
import kubernetesPurpleSvg from "@site/src/components/Icon/svg/kubernetes-purple.svg";
|
||||
import keyholePurpleSvg from "@site/src/components/Icon/svg/keyhole-purple.svg";
|
||||
import graphSvg from "@site/src/components/Icon/svg/graph.svg";
|
||||
import bookOpenSvg from "@site/src/components/Icon/teleport-svg/book-open.svg";
|
||||
import teleportSvg from "@site/src/components/Icon/teleport-svg/teleport.svg";
|
||||
import linuxServersSvg from "@site/src/components/Icon/teleport-svg/linux-servers.svg";
|
||||
|
||||
Teleport supports two ways to configure a cluster:
|
||||
|
||||
- **Static configuration file:** At startup, a Teleport process reads a
|
||||
configuration file from the local filesystem (the default path is
|
||||
`/etc/teleport.yaml`). Static configuration settings control aspects of a
|
||||
specific instance of a service, such as the Teleport Auth Service, Teleport
|
||||
Proxy Service, or a single Teleport Agent.
|
||||
- **Dynamic resources:** Dynamic resources control aspects of your cluster that
|
||||
are likely to change over time, such as roles, local users, and
|
||||
Teleport-protected infrastructure resources. Dynamic resources do not
|
||||
configure specific services, but rather the cluster as a whole.
|
||||
|
||||
Use static configuration if you want to configure the services that run in your
|
||||
cluster, including cluster-wide options that you do not expect to change very
|
||||
often. For day-to-day configuration updates, such as new Teleport roles, you
|
||||
likely need a dynamic resource.
|
||||
|
||||

|
||||
|
||||
<Resources
|
||||
title="Static configuration"
|
||||
secondaryTitle=""
|
||||
description="Learn how to add a static configuration file for a specific Teleport service."
|
||||
desktopColumnsCount={3}
|
||||
variant="doc"
|
||||
titleSize="h2"
|
||||
iconsSize="small"
|
||||
descriptionsFontSize="lg"
|
||||
resources={[
|
||||
{
|
||||
title: "Teleport Agents",
|
||||
description: "Teleport Agents proxy connections to and from infrastructure like servers and databases. See how to get started configuring each Teleport Agent service.",
|
||||
iconComponent: teleportSvg,
|
||||
href: "../enroll-resources/",
|
||||
links: [
|
||||
{
|
||||
title: "Teleport Application Service",
|
||||
href: "../enroll-resources/application-access/getting-started/"
|
||||
},
|
||||
{
|
||||
title: "Teleport Database Service",
|
||||
href: "../enroll-resources/database-access/getting-started/"
|
||||
},
|
||||
{
|
||||
title: "Teleport Desktop Service",
|
||||
href: "../enroll-resources/desktop-access/getting-started/"
|
||||
},
|
||||
{
|
||||
title: "Teleport Kubernetes Service",
|
||||
href: "../enroll-resources/kubernetes-access/getting-started/"
|
||||
},
|
||||
{
|
||||
title: "Teleport SSH Service",
|
||||
href: "../enroll-resources/server-access/getting-started/"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
title: "Teleport Control Plane",
|
||||
description: "If you host your own Teleport cluster, learn how to configure the Teleport Auth Service and Proxy Service.",
|
||||
iconComponent: kubernetesClustersSvg,
|
||||
href: "../installation/self-hosted/",
|
||||
links: [
|
||||
{
|
||||
title: "High Availability Cluster",
|
||||
href: "../installation/self-hosted/deployments/high-availability/",
|
||||
|
||||
},
|
||||
{
|
||||
title: "Single-Machine Cluster",
|
||||
href: "../get-started/deploy-community/"
|
||||
}
|
||||
],
|
||||
},
|
||||
{
|
||||
title: "Configuration Reference",
|
||||
description: "Configuration settings for all Teleport services.",
|
||||
iconComponent: bookOpenSvg,
|
||||
href: "../reference/deployment/config/",
|
||||
}
|
||||
]}
|
||||
/>
|
||||
|
||||
<Resources
|
||||
title="Dynamic configuration tools"
|
||||
secondaryTitle=""
|
||||
description="Teleport provides three methods for managing Teleport with infrastructure as code tools."
|
||||
desktopColumnsCount={3}
|
||||
variant="doc"
|
||||
titleSize="h2"
|
||||
iconsSize="small"
|
||||
descriptionsFontSize="lg"
|
||||
resources={[
|
||||
{
|
||||
title: "Teleport Terraform Provider",
|
||||
description: "Manage dynamic Teleport resources with Terraform.",
|
||||
iconComponent: terraformSvg,
|
||||
href: "./terraform-provider/",
|
||||
links: [
|
||||
{
|
||||
title: "Get started",
|
||||
href: "./terraform-provider/terraform-getting-started/"
|
||||
},
|
||||
{
|
||||
title: "Setup guides",
|
||||
href: "./terraform-provider/"
|
||||
},
|
||||
{
|
||||
title: "Import Teleport resources",
|
||||
href: "./terraform-provider/import-existing-resources/"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
title: "Teleport Kubernetes Operator",
|
||||
description: `
|
||||
Manage Teleport resources directly from Kubernetes using the <a href="https://kubernetes.io/docs/concepts/extend-kubernetes/operator/" rel="noopener noreferrer" target="_blank">operator pattern</a>.
|
||||
`,
|
||||
iconComponent: kubernetesClustersSvg,
|
||||
href: "./teleport-operator/",
|
||||
links: [
|
||||
{
|
||||
title: "Deploy with a cluster",
|
||||
href: "./teleport-operator/teleport-operator-helm/"
|
||||
},
|
||||
{
|
||||
title: "Deploy without a cluster",
|
||||
href: "./teleport-operator/teleport-operator-standalone/"
|
||||
},
|
||||
{
|
||||
title: "Secret lookup",
|
||||
href: "./teleport-operator/secret-lookup/"
|
||||
},
|
||||
{
|
||||
title: "Troubleshooting",
|
||||
href: "./teleport-operator/#troubleshooting"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
title: "tctl client tool",
|
||||
description: "<code>tctl</code> is a command-line client for managing dynamic resources. Learn how to get started with <code>tctl</code>.",
|
||||
iconComponent: cliSvg,
|
||||
href: "./using-tctl/"
|
||||
}
|
||||
]}
|
||||
/>
|
||||
|
||||
<Resources
|
||||
title="Dynamic resource management guides"
|
||||
description="Follow step-by-step instructions for using Infrastructure as Code tools to manage the most commonly needed Teleport resources."
|
||||
secondaryTitle=""
|
||||
desktopColumnsCount={3}
|
||||
variant="doc"
|
||||
titleSize="h2"
|
||||
iconsSize="small"
|
||||
descriptionsFontSize="lg"
|
||||
resources={[
|
||||
{
|
||||
title: "Access Lists",
|
||||
description: "Centrally configured assignments of users to roles.",
|
||||
href: "./resource-guides/access-list/",
|
||||
iconComponent: userListSvg,
|
||||
},
|
||||
{
|
||||
title: "Agentless OpenSSH servers",
|
||||
description: "OpenSSH servers registered without the Teleport SSH Service.",
|
||||
href: "./resource-guides/agentless-ssh-servers/",
|
||||
iconComponent: hardDrivesSvg,
|
||||
},
|
||||
{
|
||||
title: "Kubernetes OIDC joining",
|
||||
description: "Teleport Agents running on Kubernetes that join the cluster with no shared secrets.",
|
||||
href: "./resource-guides/kubernetes-oidc-join-token/",
|
||||
iconComponent: kubernetesPurpleSvg,
|
||||
},
|
||||
{
|
||||
title: "Login Rules (Kubernetes Operator)",
|
||||
description: "Data transformations for users who authenticate via a single sign-on provider.",
|
||||
href: "./resource-guides/login-rules-operator/",
|
||||
iconComponent: keyholePurpleSvg,
|
||||
},
|
||||
{
|
||||
title: "Login Rules (Terraform Provider)",
|
||||
description: "Login rules, managed via Terraform.",
|
||||
href: "./resource-guides/login-rules-terraform/",
|
||||
iconComponent: keyholePurpleSvg,
|
||||
},
|
||||
{
|
||||
title: "Trusted clusters",
|
||||
description: "Teleport clusters configured to trust users in a root cluster.",
|
||||
href: "./resource-guides/trusted-cluster/",
|
||||
iconComponent: graphSvg,
|
||||
},
|
||||
{
|
||||
title: "Users and roles",
|
||||
description: "Who can authenticate to your Teleport cluster and what permissions they have.",
|
||||
href: "./resource-guides/user-and-role/",
|
||||
iconComponent: bookOpenSvg,
|
||||
},
|
||||
]}
|
||||
/>
|
||||
|
||||
<Resources
|
||||
title="Dynamic resource references"
|
||||
secondaryTitle=""
|
||||
description="Comprehensive lists of Teleport configuration options."
|
||||
desktopColumnsCount={3}
|
||||
variant="doc"
|
||||
titleSize="h2"
|
||||
iconsSize="small"
|
||||
descriptionsFontSize="lg"
|
||||
resources={[
|
||||
{
|
||||
title: "tctl resources",
|
||||
description: "Comprehensive guide to fields in the dynamic resources you can manage with the <code>tctl</code> command-line tool.",
|
||||
iconComponent: cliSvg,
|
||||
href: "../reference/infrastructure-as-code/teleport-resources/",
|
||||
},
|
||||
{
|
||||
title: "tctl command reference",
|
||||
description: "List of commands, arguments, and flags for the <code>tctl</code> command-line tool.",
|
||||
iconComponent: cliSvg,
|
||||
href: "../reference/cli/tctl/",
|
||||
},
|
||||
{
|
||||
title: "Teleport Terraform Provider",
|
||||
description: "Comprehensive lists of resource and data source fields available to the Teleport Terraform provider.",
|
||||
iconComponent: terraformSvg,
|
||||
href: "../reference/infrastructure-as-code/terraform-provider/",
|
||||
},
|
||||
{
|
||||
title: "Teleport Kubernetes Operator",
|
||||
description: "Comprehensive lists of resources available to the Teleport Kubernetes Operator.",
|
||||
iconComponent: kubernetesPurpleSvg,
|
||||
href: "../reference/infrastructure-as-code/operator-resources/",
|
||||
},
|
||||
{
|
||||
title: "Reconciling Static and Dynamic Configuration",
|
||||
description: "How Teleport merges overlapping options.",
|
||||
iconComponent: bookOpenSvg,
|
||||
href: "../reference/deployment/static-and-dynamic-configuration/",
|
||||
}
|
||||
]}
|
||||
/>
|
||||
|
||||
|
||||
+6
-6
@@ -282,7 +282,7 @@ You can log in as alice and add `bob` to the `support-engineers` Access List.
|
||||
Log in as `alice` in the Web UI, Zero Trust Access, select Access Lists, and click on your Access List.
|
||||
Click "Add new Members or Access Lists or Access Lists" and add `bob`.
|
||||
|
||||

|
||||

|
||||
|
||||
</TabItem>
|
||||
<TabItem label="CLI">
|
||||
@@ -433,9 +433,9 @@ a nested Access List within `support-engineers`.
|
||||
### Give access to an Okta or Microsoft Entra ID group
|
||||
|
||||
The Okta integration allows [synchronizing Okta groups and
|
||||
apps](../../../identity-governance/integrations/okta/app-and-group-sync.mdx) as Teleport Access Lists, while the
|
||||
apps](../../identity-governance/integrations/okta/app-and-group-sync.mdx) as Teleport Access Lists, while the
|
||||
Microsoft Entra ID integration allows [synchronizing
|
||||
groups](../../../identity-governance/integrations/entra-id/entra-id.mdx) as Teleport Access Lists.
|
||||
groups](../../identity-governance/integrations/entra-id/entra-id.mdx) as Teleport Access Lists.
|
||||
|
||||
To give permissions to an Access List based on these integrations in Terraform,
|
||||
navigate to the Access List in the Web UI, and from its URL (e.g.
|
||||
@@ -471,8 +471,8 @@ It is usually not possible to import Access Lists created using the Web UI into
|
||||
a Terraform module. Any Access List can be imported, but Access Lists created in
|
||||
the UI are not of the static type, so their members can't be managed with Terraform.
|
||||
The same applies to Access Lists created by an integration (e.g.
|
||||
[Okta](../../../identity-governance/integrations/okta/app-and-group-sync.mdx) or
|
||||
[Microsoft Entra ID](../../../identity-governance/integrations/entra-id/entra-id.mdx)). An
|
||||
[Okta](../../identity-governance/integrations/okta/app-and-group-sync.mdx) or
|
||||
[Microsoft Entra ID](../../identity-governance/integrations/entra-id/entra-id.mdx)). An
|
||||
existing static list created by another Terraform setup (with a different state)
|
||||
could be imported, and its members can be managed by Terraform, but this
|
||||
situation is unusual.
|
||||
@@ -485,4 +485,4 @@ of the existing Access List.
|
||||
## Next steps
|
||||
|
||||
You can see all supported Access List fields
|
||||
[in the Access List reference](../../../reference/access-controls/access-lists.mdx).
|
||||
[in the Access List reference](../../reference/access-controls/access-lists.mdx).
|
||||
+5
-5
@@ -24,7 +24,7 @@ dynamically create resources from code:
|
||||
Teleport can route SSH connections through the Teleport Proxy Service to SSH
|
||||
nodes. Once you have configured your SSH nodes to trust the Teleport certificate
|
||||
authority for OpenSSH (see the [Agentless OpenSSH
|
||||
guide](../../../enroll-resources/server-access/openssh/openssh-agentless.mdx),
|
||||
guide](../../enroll-resources/server-access/openssh/openssh-agentless.mdx),
|
||||
the Proxy Service can present a Teleport-signed certificate to the node and
|
||||
establish a connection. For this to work, the Teleport Proxy Service must be
|
||||
able to dial the node.
|
||||
@@ -77,7 +77,7 @@ A functional Teleport Terraform provider by following [the Terraform provider gu
|
||||
<Admonition type="tip">
|
||||
If you want to add a private SSH server (e.g. behind a NAT, in a private
|
||||
network, protected by a firewall blocking inbound traffic, ...) you can
|
||||
[install a Teleport Agent](../../../enroll-resources/server-access/getting-started.mdx). The
|
||||
[install a Teleport Agent](../../enroll-resources/server-access/getting-started.mdx). The
|
||||
Teleport Agent opens a tunnel to the Teleport Proxy Service, allowing any user
|
||||
to connect to it by going through the Proxy Service.
|
||||
</Admonition>
|
||||
@@ -93,7 +93,7 @@ You must also choose a set of labels for the server. Those labels can be used to
|
||||
describe the server and control which users can access the server. They can be
|
||||
dynamically changed later, without having to reconfigure openSSH.
|
||||
|
||||
See the [Access Controls for Servers](../../../enroll-resources/server-access/rbac.mdx) page for
|
||||
See the [Access Controls for Servers](../../enroll-resources/server-access/rbac.mdx) page for
|
||||
more details about labels and how to control access to your servers.
|
||||
|
||||
In the rest of this guide, the labels will be:
|
||||
@@ -306,9 +306,9 @@ infrastructure and tooling (you can configure the SSH CA in the VM image, use
|
||||
custom startup scripts, provision servers with Ansible, ...).
|
||||
|
||||
A step-by-step manual setup is described
|
||||
in [the OpenSSH manual installation guide](../../../enroll-resources/server-access/openssh/openssh-manual-install.mdx)
|
||||
in [the OpenSSH manual installation guide](../../enroll-resources/server-access/openssh/openssh-manual-install.mdx)
|
||||
starting with the Step 2.
|
||||
|
||||
## Next steps
|
||||
|
||||
- [Setup RBAC](../../../enroll-resources/server-access/rbac.mdx) to control which user can SSH on which server.
|
||||
- [Setup RBAC](../../enroll-resources/server-access/rbac.mdx) to control which user can SSH on which server.
|
||||
+2
-2
@@ -21,7 +21,7 @@ computer or your CI environment
|
||||
## How it works
|
||||
|
||||
This guide relies on the OIDC variant of
|
||||
[the Kubernetes join method](../../../reference/deployment/join-methods.mdx#kubernetes-oidc).
|
||||
[the Kubernetes join method](../../reference/deployment/join-methods.mdx#kubernetes-oidc).
|
||||
Most Kubernetes clusters use an OpenID Connect (OIDC) provider to sign their
|
||||
Service Account tokens.
|
||||
|
||||
@@ -327,5 +327,5 @@ You must have the following information:
|
||||
|
||||
## Next steps
|
||||
|
||||
Look at [the `teleport-kube-agent` Helm chart reference](../../../reference/helm-reference/teleport-kube-agent.mdx)
|
||||
Look at [the `teleport-kube-agent` Helm chart reference](../../reference/helm-reference/teleport-kube-agent.mdx)
|
||||
for the list of supported values.
|
||||
+1
-1
@@ -260,5 +260,5 @@ logins:
|
||||
|
||||
- Read the [Teleport Operator Guide](../teleport-operator/teleport-operator.mdx) to
|
||||
learn more about the Teleport Operator.
|
||||
- Read the [Login Rules reference](../../../reference/access-controls/login-rules.mdx) to learn more about the
|
||||
- Read the [Login Rules reference](../../reference/access-controls/login-rules.mdx) to learn more about the
|
||||
Login Rule expression syntax.
|
||||
+1
-1
@@ -168,5 +168,5 @@ logins:
|
||||
|
||||
- Read the [Terraform Guide](../terraform-provider/terraform-provider.mdx) to
|
||||
learn more about configuring the Terraform provider.
|
||||
- Read the [Login Rules reference](../../../reference/access-controls/login-rules.mdx) to learn more about the
|
||||
- Read the [Login Rules reference](../../reference/access-controls/login-rules.mdx) to learn more about the
|
||||
Login Rule expression syntax.
|
||||
+3
-3
@@ -1,7 +1,7 @@
|
||||
---
|
||||
title: "Managing Resources with Infrastructure as Code"
|
||||
sidebar_label: Managing Resources
|
||||
sidebar_position: 1
|
||||
title: Dynamic Resource Management Guides
|
||||
sidebar_label: Resource Guides
|
||||
sidebar_position: 4
|
||||
description: Provides instructions on managing specific dynamic resources with tctl and the Teleport Terraform provider and Kubernetes operator.
|
||||
template: "no-toc"
|
||||
tags:
|
||||
+3
-3
@@ -28,7 +28,7 @@ Teleport supports three ways to dynamically create resources from code:
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Access to **two** Teleport cluster instances. Follow the [Run a Self-Hosted Demo Cluster](../../../get-started/deploy-community.mdx)
|
||||
- Access to **two** Teleport cluster instances. Follow the [Run a Self-Hosted Demo Cluster](../../get-started/deploy-community.mdx)
|
||||
guide to learn how to deploy a self-hosted Teleport cluster on a Linux server.
|
||||
|
||||
The two clusters should be at the same version or, at most, the leaf cluster can be one major version
|
||||
@@ -36,9 +36,9 @@ Teleport supports three ways to dynamically create resources from code:
|
||||
|
||||
- A Teleport SSH server that is joined to the cluster you plan to use as the **leaf cluster**.
|
||||
For information about how to enroll a resource in your cluster, see
|
||||
[Join Services to your Cluster](../../../installation/agents/agents.mdx).
|
||||
[Join Services to your Cluster](../../installation/agents/agents.mdx).
|
||||
|
||||
- Read through the [Configure Trusted Clusters](../../management/trustedclusters.mdx)
|
||||
- Read through the [Configure Trusted Clusters](../../zero-trust-access/management/trustedclusters.mdx)
|
||||
guide to understand how trusted clusters works.
|
||||
|
||||
- The `tctl` admin tool and `tsh` client tool.
|
||||
+5
-5
@@ -207,7 +207,7 @@ We will create 2 users:
|
||||
Users created from manifests are local users, as opposed to users coming from
|
||||
an external SAML/OIDC/GitHub Identity Provider (IdP).
|
||||
|
||||
See [the user type reference](../../../reference/access-controls/user-types.mdx) for more details.
|
||||
See [the user type reference](../../reference/access-controls/user-types.mdx) for more details.
|
||||
</Admonition>
|
||||
|
||||
<Tabs>
|
||||
@@ -492,13 +492,13 @@ resource "teleport_user" "bob" {
|
||||
- Allow users with the `manager` role to grant access to production servers to
|
||||
some `engineers` via Access Lists. Manager will need to justify and review
|
||||
granted access periodically.
|
||||
See [the Access List documentation](../../../identity-governance/access-lists/access-lists.mdx) for
|
||||
See [the Access List documentation](../../identity-governance/access-lists/access-lists.mdx) for
|
||||
a high-level explanation of the feature,
|
||||
and [the Access List IaC guide](access-list.mdx) for a step by step IaC
|
||||
AccessList setup.
|
||||
- Allow users with the `engineer` role to request temporary access to
|
||||
production, and have users with the `manager` role validate the requests.
|
||||
See [the Access Requests documentation](../../../identity-governance/access-requests/access-requests.mdx)
|
||||
See [the Access Requests documentation](../../identity-governance/access-requests/access-requests.mdx)
|
||||
- You can see all supported fields in the references
|
||||
of [the user resource](../../../reference/infrastructure-as-code/teleport-resources/teleport-resources.mdx)
|
||||
and [the role resource](../../../reference/infrastructure-as-code/teleport-resources/teleport-resources.mdx).
|
||||
of [the user resource](../../reference/infrastructure-as-code/teleport-resources/teleport-resources.mdx)
|
||||
and [the role resource](../../reference/infrastructure-as-code/teleport-resources/teleport-resources.mdx).
|
||||
+3
-3
@@ -114,13 +114,13 @@ $ kubectl get pods -n <Var name="teleport-cluster"/>
|
||||
|
||||
## Next steps
|
||||
|
||||
Follow [the user and role IaC guide](../managing-resources/user-and-role.mdx) to use your newly
|
||||
Follow [the user and role IaC guide](../resource-guides/user-and-role.mdx) to use your newly
|
||||
deployed Teleport Kubernetes Operator to create Teleport users and grant them
|
||||
roles.
|
||||
|
||||
Helm Chart parameters are documented in the [`teleport-cluster` Helm chart reference](../../../reference/helm-reference/teleport-cluster.mdx).
|
||||
Helm Chart parameters are documented in the [`teleport-cluster` Helm chart reference](../../reference/helm-reference/teleport-cluster.mdx).
|
||||
|
||||
See the [Helm Deployment guides](../../../installation/self-hosted/helm-deployments/helm-deployments.mdx) detailing specific setups like running Teleport on AWS or GCP.
|
||||
See the [Helm Deployment guides](../../installation/self-hosted/helm-deployments/helm-deployments.mdx) detailing specific setups like running Teleport on AWS or GCP.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
+2
-2
@@ -150,11 +150,11 @@ At this point, you can configure and run the operator:
|
||||
|
||||
## Next steps
|
||||
|
||||
Follow [the user and role IaC guide](../managing-resources/user-and-role.mdx) to use your newly
|
||||
Follow [the user and role IaC guide](../resource-guides/user-and-role.mdx) to use your newly
|
||||
deployed Teleport Kubernetes Operator to create Teleport users and grant them
|
||||
roles.
|
||||
|
||||
Helm Chart parameters are documented in the [`teleport-operator` Helm chart reference](../../../reference/helm-reference/teleport-operator.mdx).
|
||||
Helm Chart parameters are documented in the [`teleport-operator` Helm chart reference](../../reference/helm-reference/teleport-operator.mdx).
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
+3
-3
@@ -29,7 +29,7 @@ Only one operator deployment should run against a Teleport cluster. Else, differ
|
||||
could cause instability and non-deterministic behaviour.
|
||||
</Admonition>
|
||||
|
||||
Supported Teleport resources are listed in [the Operator Reference Page](../../../reference/infrastructure-as-code/operator-resources/operator-resources.mdx).
|
||||
Supported Teleport resources are listed in [the Operator Reference Page](../../reference/infrastructure-as-code/operator-resources/operator-resources.mdx).
|
||||
|
||||
## Setting up the operator
|
||||
|
||||
@@ -83,5 +83,5 @@ See [the dedicated guide](secret-lookup.mdx) for more details.
|
||||
|
||||
## Next steps
|
||||
|
||||
- Follow the ["Managing users and roles with IaC" guide](../managing-resources/user-and-role.mdx).
|
||||
- Check out [access controls documentation](../../authentication/authentication.mdx).
|
||||
- Follow the ["Managing users and roles with IaC" guide](../resource-guides/user-and-role.mdx).
|
||||
- Check out [access controls documentation](../../zero-trust-access/authentication/authentication.mdx).
|
||||
+6
-6
@@ -25,9 +25,9 @@ and on servers with Trusted Platform Module (TPM). While those setups are not de
|
||||
you can follow their regular Machine & Workload Identity guides and replace the "Configure `tbot`" step by passing the
|
||||
join method and token to the provider.
|
||||
|
||||
- [Azure Machine & Workload Identity guide](../../../machine-workload-identity/deployment/azure.mdx)
|
||||
- [Kubernetes Machine & Workload Identity guide](../../../machine-workload-identity/deployment/kubernetes.mdx)
|
||||
- [TPM Machine & Workload Identity guide](../../../machine-workload-identity/deployment/linux-tpm.mdx)
|
||||
- [Azure Machine & Workload Identity guide](../../machine-workload-identity/deployment/azure.mdx)
|
||||
- [Kubernetes Machine & Workload Identity guide](../../machine-workload-identity/deployment/kubernetes.mdx)
|
||||
- [TPM Machine & Workload Identity guide](../../machine-workload-identity/deployment/linux-tpm.mdx)
|
||||
|
||||
HCP Terraform (Terraform Cloud) and self-hosted Terraform Enterprise are
|
||||
supported but require special configuration, so refer to our
|
||||
@@ -48,7 +48,7 @@ In this setup, there is no `tbot` daemon involved as the Terraform provider can
|
||||
and join the Teleport cluster.
|
||||
|
||||
The setup only works for select runtimes which Teleport
|
||||
has [a delegated join method](../../../reference/deployment/join-methods.mdx#delegated-join-methods) for (e.g. GitHub Actions,
|
||||
has [a delegated join method](../../reference/deployment/join-methods.mdx#delegated-join-methods) for (e.g. GitHub Actions,
|
||||
GitLab CI, ...)
|
||||
|
||||
## Prerequisites
|
||||
@@ -63,7 +63,7 @@ You also need:
|
||||
|
||||
## Step 1/4. Create the Terraform provider bot
|
||||
|
||||
In this step you will create [a bot](../../../reference/architecture/machine-id-architecture.mdx#what-is-a-bot) named `terraform`.
|
||||
In this step you will create [a bot](../../reference/architecture/machine-id-architecture.mdx#what-is-a-bot) named `terraform`.
|
||||
|
||||
Create a file named `terraform-bot.yaml`:
|
||||
|
||||
@@ -104,7 +104,7 @@ In this step you will create a token allowing a process to connect to Teleport a
|
||||
earlier.
|
||||
|
||||
The token type and configuration depends on where the Terraform provider is running.
|
||||
See [the joining reference](../../../reference/deployment/join-methods.mdx) for more details about the joining process,
|
||||
See [the joining reference](../../reference/deployment/join-methods.mdx) for more details about the joining process,
|
||||
the different join methods, types of tokens, and the fields they support.
|
||||
|
||||
<Tabs>
|
||||
+3
-3
@@ -45,7 +45,7 @@ Terraform provider. The daemon stores its identity on the disk and refresh the t
|
||||
|
||||
- `tbot` installed on your server and joined to your Teleport cluster. Follow
|
||||
[the `tbot` deployment guide for
|
||||
Linux](../../../machine-workload-identity/deployment/linux.mdx).
|
||||
Linux](../../machine-workload-identity/deployment/linux.mdx).
|
||||
|
||||
## Step 1/3. Configure RBAC
|
||||
|
||||
@@ -159,7 +159,7 @@ $ tctl get role/terraform-test
|
||||
## Next steps
|
||||
|
||||
- Explore the
|
||||
[Terraform provider resource reference](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx)
|
||||
[Terraform provider resource reference](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx)
|
||||
to discover what can be configured with the Teleport Terraform provider.
|
||||
- Read the [tbot configuration reference](../../../reference/machine-workload-identity/configuration.mdx) to explore
|
||||
- Read the [tbot configuration reference](../../reference/machine-workload-identity/configuration.mdx) to explore
|
||||
all the available `tbot` configuration options.
|
||||
+2
-2
@@ -217,7 +217,7 @@ $ tctl get role/test
|
||||
|
||||
- Now that you know how to manage Teleport configuration resources with
|
||||
Terraform and env zero, read the [Terraform resource
|
||||
reference](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx) so
|
||||
reference](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx) so
|
||||
you can flesh out your configuration.
|
||||
- To find out more about env zero's OIDC implementation, which Machine &
|
||||
Workload ID uses to authenticate to your Teleport cluster, read
|
||||
@@ -225,5 +225,5 @@ $ tctl get role/test
|
||||
|
||||
[env zero]: https://www.env0.com/
|
||||
[oidc]: https://docs.envzero.com/guides/integrations/oidc-integrations
|
||||
[reference]: ../../../reference/deployment/join-methods.mdx#env0-env0
|
||||
[reference]: ../../reference/deployment/join-methods.mdx#env0-env0
|
||||
[remote-plan]: https://docs.envzero.com/guides/admin-guide/remote-backend/remote-plan
|
||||
+3
-3
@@ -26,7 +26,7 @@ As with any compliant Terraform provider, the Teleport provider allows you to
|
||||
generate a Terraform configuration based on existing resources that the Teleport
|
||||
Auth Service has stored on its backend. For all of the Teleport resources that
|
||||
the Terraform provider supports, see the [Terraform resource
|
||||
reference](../../../reference/infrastructure-as-code/terraform-provider/resources/resources.mdx).
|
||||
reference](../../reference/infrastructure-as-code/terraform-provider/resources/resources.mdx).
|
||||
|
||||
## Step 1/3. Add an `import` block
|
||||
|
||||
@@ -94,9 +94,9 @@ reference](../../../reference/infrastructure-as-code/terraform-provider/resource
|
||||
|
||||
## Next steps
|
||||
|
||||
- Follow [the user and role IaC guide](../managing-resources/user-and-role.mdx) to use the Terraform
|
||||
- Follow [the user and role IaC guide](../resource-guides/user-and-role.mdx) to use the Terraform
|
||||
Provider to create Teleport users and grant them roles.
|
||||
- Explore the full list of supported [Terraform provider
|
||||
resources](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
resources](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
- See [the list of supported Teleport Terraform
|
||||
setups](../terraform-provider/terraform-provider.mdx).
|
||||
+3
-3
@@ -59,7 +59,7 @@ provider. The bot will exist for one hour and will be granted the default `terra
|
||||
resource the TF provider supports.
|
||||
|
||||
`tctl` will then obtain credentials for the temporary bot and export them in your shell's environment variables.
|
||||
If [MFA for Administrative Actions](../../authentication/mfa-for-admin-actions.mdx)
|
||||
If [MFA for Administrative Actions](../../zero-trust-access/authentication/mfa-for-admin-actions.mdx)
|
||||
is enabled on your cluster, `tctl` will prompt for your MFA.
|
||||
|
||||
Run the following command, do not remove the `eval` as it is required to load credentials in your shell:
|
||||
@@ -160,11 +160,11 @@ Do not forget to obtain new temporary credentials every hour by re-running `eval
|
||||
|
||||
## Next steps
|
||||
|
||||
- Follow [the user and role IaC guide](../managing-resources/user-and-role.mdx) to use the Terraform
|
||||
- Follow [the user and role IaC guide](../resource-guides/user-and-role.mdx) to use the Terraform
|
||||
Provider to create Teleport users and grant them roles.
|
||||
- Consult the list of Terraform-supported
|
||||
resources [in the Terraform
|
||||
reference](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
reference](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
- Once you have working Terraform code that configures your Teleport cluster,
|
||||
you might want to run it in the CI or from a bastion instead of running it
|
||||
locally. To do this, please follow the dedicated guides:
|
||||
+4
-4
@@ -15,7 +15,7 @@ for it. The Teleport Terraform Provider can then use those credentials to intera
|
||||
|
||||
A Teleport administrator defines a role for the Teleport Terraform provider, as
|
||||
well as a role that can
|
||||
[impersonate](../../authentication/impersonation.mdx)
|
||||
[impersonate](../../zero-trust-access/authentication/impersonation.mdx)
|
||||
the Terraform provider role. A Teleport user assumes the impersonator role and
|
||||
executes a `tctl` command to instruct the Teleport Auth Service to sign a user
|
||||
certificate for the Terraform provider. The provider then loads the certificate
|
||||
@@ -221,8 +221,8 @@ To apply the configuration:
|
||||
## Next steps
|
||||
|
||||
- Explore the full list of supported [Terraform provider
|
||||
resources](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
resources](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
- Learn [how to manage users and roles with
|
||||
IaC](../managing-resources/user-and-role.mdx)
|
||||
IaC](../resource-guides/user-and-role.mdx)
|
||||
- Read more about
|
||||
[impersonation](../../authentication/impersonation.mdx).
|
||||
[impersonation](../../zero-trust-access/authentication/impersonation.mdx).
|
||||
+3
-3
@@ -196,7 +196,7 @@ the PR you opened.
|
||||
You should see a Terraform plan that includes the user and role you defined
|
||||
earlier:
|
||||
|
||||

|
||||

|
||||
|
||||
When running `terraform plan`, the Teleport Terraform Provider uses Machine &
|
||||
Workload Identity to generate the short-lived credentials necessary to
|
||||
@@ -208,7 +208,7 @@ the run. Click **Confirm** to begin applying your Terraform plan.
|
||||
|
||||
You should see output indicating success:
|
||||
|
||||

|
||||

|
||||
|
||||
Verify that Spacelift has created the new user and role by running the following
|
||||
commands, which should return YAML data for each resource:
|
||||
@@ -222,7 +222,7 @@ $ tctl get users/terraform-test
|
||||
|
||||
- Now that you know how to manage Teleport configuration resources with
|
||||
Terraform and Spacelift, read the [Terraform resource
|
||||
reference](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx) so
|
||||
reference](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx) so
|
||||
you can flesh out your configuration.
|
||||
- To find out more about Spacelift's OIDC implementation, which Machine &
|
||||
Workload Identity uses to authenticate to your Teleport cluster, read
|
||||
+1
-1
@@ -186,7 +186,7 @@ To do so:
|
||||
|
||||
The end result should look like this:
|
||||
|
||||

|
||||

|
||||
|
||||
Once this variable is set, all subsequent runs in this workspace will be issued
|
||||
JWTs with the audience configured in the variable value, i.e.
|
||||
+20
-20
@@ -24,9 +24,9 @@ for infrastructure resources.
|
||||
|
||||
An Agent is a Teleport instance configured to run one or more Teleport services
|
||||
in order to proxy infrastructure resources (see [Introduction to Teleport
|
||||
Agents](../../../installation/agents/agents.mdx)). There are several methods
|
||||
Agents](../../installation/agents/agents.mdx)). There are several methods
|
||||
you can use to join a Teleport Agent to your cluster, which we discuss in the
|
||||
[Joining Services to your Cluster](../../../installation/agents/agents.mdx)
|
||||
[Joining Services to your Cluster](../../installation/agents/agents.mdx)
|
||||
guide. In this guide, we will use the **join token** method, where the operator
|
||||
stores a secure token on the Auth Service, and an Agent presents the token in
|
||||
order to join a cluster.
|
||||
@@ -48,14 +48,14 @@ Sign-On provider.
|
||||
## Prerequisites
|
||||
|
||||
- A running Teleport (v16.2.0 or higher) cluster. If you do not have one, read
|
||||
[Getting Started](../../../get-started/get-started.mdx).
|
||||
[Getting Started](../../get-started/get-started.mdx).
|
||||
|
||||
<Admonition type="tip">
|
||||
|
||||
We recommend following this guide on a fresh Teleport demo cluster. After you
|
||||
are familiar with the setup, apply the lessons from this guide to protect your
|
||||
infrastructure. You can get started with a demo cluster using:
|
||||
- A demo deployment on a [Linux server](../../../get-started/deploy-community.mdx)
|
||||
- A demo deployment on a [Linux server](../../get-started/deploy-community.mdx)
|
||||
- A [Teleport Enterprise (Cloud) trial](https://goteleport.com/signup)
|
||||
|
||||
</Admonition>
|
||||
@@ -84,13 +84,13 @@ infrastructure. You can get started with a demo cluster using:
|
||||
you how to set up your IdP to support the SAML or OIDC authentication
|
||||
connector. **Read only the linked section**, since these guides assume you are
|
||||
using `tctl` instead of Terraform to manage authentication connectors:
|
||||
- [AD FS](../../sso/integrate-idp/adfs.mdx#step-13-configure-adfs)
|
||||
- [GitLab](../../sso/integrate-idp/gitlab.mdx#step-13-configure-gitlab)
|
||||
- [AD FS](../../zero-trust-access/sso/integrate-idp/adfs.mdx#step-13-configure-adfs)
|
||||
- [GitLab](../../zero-trust-access/sso/integrate-idp/gitlab.mdx#step-13-configure-gitlab)
|
||||
- [Google
|
||||
Workspace](../../sso/integrate-idp/google-workspace.mdx#step-13-configure-google-workspace)
|
||||
- [OneLogin](../../sso/integrate-idp/one-login.mdx#step-13-create-teleport-application-in-onelogin)
|
||||
- [Entra ID](../../sso/integrate-idp/entra-id.mdx#step-13-configure-microsoft-entra-id)
|
||||
- [Okta](../../sso/integrate-idp/okta.mdx#step-13-configure-okta)
|
||||
Workspace](../../zero-trust-access/sso/integrate-idp/google-workspace.mdx#step-13-configure-google-workspace)
|
||||
- [OneLogin](../../zero-trust-access/sso/integrate-idp/one-login.mdx#step-13-create-teleport-application-in-onelogin)
|
||||
- [Entra ID](../../zero-trust-access/sso/integrate-idp/entra-id.mdx#step-13-configure-microsoft-entra-id)
|
||||
- [Okta](../../zero-trust-access/sso/integrate-idp/okta.mdx#step-13-configure-okta)
|
||||
|
||||
- To help with troubleshooting, we recommend completing the setup steps in this
|
||||
guide with a local user that has the preset `editor` and `auditor` roles. In
|
||||
@@ -673,7 +673,7 @@ do so, you can:
|
||||
`dev_access` and `prod_access` roles (see the
|
||||
[documentation](import-existing-resources.mdx)).
|
||||
- Create a new `teleport_user` resource that includes the roles
|
||||
([documentation](../managing-resources/user-and-role.mdx).
|
||||
([documentation](../resource-guides/user-and-role.mdx).
|
||||
|
||||
If you plan to skip this step, make sure to remove the `module "saml"` or
|
||||
`module "oidc"` block from your Terraform configuration.
|
||||
@@ -1065,7 +1065,7 @@ To configure the Teleport Discovery Service:
|
||||
|
||||
1. Edit the userdata script run by the Agent instances managed in the Terraform
|
||||
starter module. Follow the [Auto-Discovery
|
||||
guides](../../../enroll-resources/auto-discovery/auto-discovery.mdx) guides
|
||||
guides](../../enroll-resources/auto-discovery/auto-discovery.mdx) guides
|
||||
to configure the Discovery Service and enable your Agents to proxy the
|
||||
resources that the service enrolls.
|
||||
1. Add the `Discovery` role to the join token resource you created earlier. In
|
||||
@@ -1073,7 +1073,7 @@ To configure the Teleport Discovery Service:
|
||||
1. Add roles to the join token resource that corresponds to the Agent services
|
||||
you want to proxy discovered resources. The roles to add depend on the
|
||||
resources you want to automatically enroll based on the [Auto-Discovery
|
||||
guides](../../../enroll-resources/auto-discovery/auto-discovery.mdx) guides.
|
||||
guides](../../enroll-resources/auto-discovery/auto-discovery.mdx) guides.
|
||||
|
||||
### Enroll resources manually
|
||||
|
||||
@@ -1081,14 +1081,14 @@ You can also enroll resources manually, instructing Agents to proxy specific
|
||||
endpoints in your infrastructure. For information about manual enrollment, read
|
||||
the documentation section for each kind of resource you would like to enroll:
|
||||
|
||||
- [Databases](../../../enroll-resources/database-access/database-access.mdx)
|
||||
- [Databases](../../enroll-resources/database-access/database-access.mdx)
|
||||
- [Windows
|
||||
desktops](../../../enroll-resources/desktop-access/desktop-access.mdx)
|
||||
desktops](../../enroll-resources/desktop-access/desktop-access.mdx)
|
||||
- [Kubernetes
|
||||
clusters](../../../enroll-resources/kubernetes-access/kubernetes-access.mdx)
|
||||
- [Linux servers](../../../enroll-resources/server-access/server-access.mdx)
|
||||
clusters](../../enroll-resources/kubernetes-access/kubernetes-access.mdx)
|
||||
- [Linux servers](../../enroll-resources/server-access/server-access.mdx)
|
||||
- [Web applications and cloud provider
|
||||
APIs](../../../enroll-resources/application-access/application-access.mdx)
|
||||
APIs](../../enroll-resources/application-access/application-access.mdx)
|
||||
|
||||
Once you are familiar with the process of enrolling a resource manually, you can
|
||||
edit your Terraform module to:
|
||||
@@ -1100,7 +1100,7 @@ edit your Terraform module to:
|
||||
1. **Change the userdata script** to enable additional Agent services additional
|
||||
infrastructure resources for your Agents to proxy.
|
||||
1. **Deploy dynamic resources:** Consult the [Terraform provider
|
||||
reference](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx) for
|
||||
reference](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx) for
|
||||
Terraform resources that you can apply in order to enroll dynamic resources
|
||||
in your infrastructure.
|
||||
|
||||
@@ -1108,4 +1108,4 @@ edit your Terraform module to:
|
||||
|
||||
Now that you have configured RBAC in your Terraform demo cluster, fine-tune your
|
||||
setup by reading the comprehensive [Terraform provider
|
||||
reference](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
reference](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
+3
-2
@@ -3,6 +3,7 @@ title: Using the Teleport Terraform Provider
|
||||
sidebar_label: Terraform Provider
|
||||
description: How to manage dynamic resources using the Teleport Terraform provider.
|
||||
videoBanner: YgNHD4SS8dg
|
||||
sidebar_position: 2
|
||||
tags:
|
||||
- infrastructure-as-code
|
||||
- conceptual
|
||||
@@ -51,10 +52,10 @@ configure your resources with it.
|
||||
|
||||
For instructions on managing specific Teleport dynamic resources with Terraform,
|
||||
read [Managing Resources with Infrastructure as
|
||||
Code](../managing-resources/managing-resources.mdx).
|
||||
Code](../resource-guides/resource-guides.mdx).
|
||||
|
||||
The list of supported resources and their fields is available [in the Terraform
|
||||
reference](../../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
reference](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
|
||||
Finally, you can [import your existing resources in Terraform](import-existing-resources.mdx).
|
||||
|
||||
+8
-8
@@ -2,7 +2,7 @@
|
||||
title: "Getting Started with tctl"
|
||||
sidebar_label: tctl Admin Tool
|
||||
description: Provides a conceptual overview of tctl, the Teleport administrative client tool.
|
||||
sidebar_position: 2
|
||||
sidebar_position: 1
|
||||
tags:
|
||||
- conceptual
|
||||
- platform-wide
|
||||
@@ -12,10 +12,10 @@ This guide provides an overview of `tctl`, a command-line tool for managing
|
||||
Teleport dynamic resources.
|
||||
|
||||
For an overview of what a dynamic resource is, see [Infrastructure as
|
||||
Code](infrastructure-as-code.mdx).
|
||||
Code](configuration.mdx).
|
||||
|
||||
For a comprehensive list of `tctl` commands, arguments, flag, and environment
|
||||
variables, see the [`tctl` CLI Reference](../../reference/cli/tctl.mdx).
|
||||
variables, see the [`tctl` CLI Reference](../reference/cli/tctl.mdx).
|
||||
|
||||
## When to use tctl
|
||||
|
||||
@@ -24,7 +24,7 @@ following Teleport Auth Service clients can also manage dynamic resources:
|
||||
|
||||
- [Teleport Terraform provider](./terraform-provider/terraform-provider.mdx)
|
||||
- [Teleport Kubernetes operator](./teleport-operator/teleport-operator.mdx)
|
||||
- [Custom API clients](../api/api.mdx)
|
||||
- [Custom API clients](../zero-trust-access/api/api.mdx)
|
||||
|
||||
`tctl` is best suited for ad hoc operations such as retrieving data about your
|
||||
cluster or unanticipated configuration changes. You can also use it to manage
|
||||
@@ -54,7 +54,7 @@ allow:
|
||||
```
|
||||
|
||||
See-the [Role
|
||||
Reference](../../reference/access-controls/roles.mdx#rbac-for-dynamic-teleport-resources)
|
||||
Reference](../reference/access-controls/roles.mdx#rbac-for-dynamic-teleport-resources)
|
||||
for more information on configuring access to Teleport resources.
|
||||
|
||||
## Audit log
|
||||
@@ -65,7 +65,7 @@ event to determine which resource modifications took place using `tctl` and
|
||||
which ones occurred with the Terraform provider, Kubernetes operator, or custom
|
||||
API clients.
|
||||
|
||||
See the [audit event reference](../../reference/audit-events.mdx) for a full
|
||||
See the [audit event reference](../reference/audit-events.mdx) for a full
|
||||
list of events.
|
||||
|
||||
## Authentication
|
||||
@@ -77,7 +77,7 @@ cluster. You can authenticate to your cluster by running the following command:
|
||||
$ tsh login --user=TELEPORT_USER --proxy=PROXY_SERVICE_ADDRESS
|
||||
```
|
||||
|
||||
See the [`tsh login`](../../reference/cli/tsh.mdx#tsh-login) reference entry for
|
||||
See the [`tsh login`](../reference/cli/tsh.mdx#tsh-login) reference entry for
|
||||
a full list of `tsh login` flags.
|
||||
|
||||
### Using the local Auth Service backend
|
||||
@@ -111,7 +111,7 @@ logs will show that it was performed by the Auth Service itself.
|
||||
|
||||
To provide an accurate audit trail, it is important to limit direct SSH access
|
||||
to the Auth Service with
|
||||
[Access Controls](../../zero-trust-access/authentication/authentication.mdx) and ensure that
|
||||
[Access Controls](../zero-trust-access/authentication/authentication.mdx) and ensure that
|
||||
admins use `tctl` remotely instead.
|
||||
|
||||
### Using an identity file
|
||||
+2
-2
@@ -142,10 +142,10 @@ $ tsh login
|
||||
$ eval "$(tctl terraform env)"
|
||||
```
|
||||
|
||||
See the [Local Demo](../../../../zero-trust-access/infrastructure-as-code/terraform-provider/local.mdx)
|
||||
See the [Local Demo](../../../../configuration/terraform-provider/local.mdx)
|
||||
guide for more detail on local setup. If you are running Terraform in CI,
|
||||
Spacelift, or another remote environment, refer to [Using the Teleport
|
||||
Terraform Provider](../../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx)
|
||||
Terraform Provider](../../../../configuration/terraform-provider/terraform-provider.mdx)
|
||||
for the appropriate guide.
|
||||
|
||||
### Step 3/5. Configure the Terraform module inputs
|
||||
|
||||
+2
-2
@@ -138,7 +138,7 @@ at the scope where the `teleport-discovery-azure` module will create resources:
|
||||
|
||||
### Configure Teleport Terraform provider
|
||||
|
||||
There are several ways to configure the Teleport Terraform provider depending on how you intend to run Terraform, for example in CI, Spacelift, or some other remote environment, but for a quick start, see the [Local Demo](../../../../zero-trust-access/infrastructure-as-code/terraform-provider/local.mdx) guide.
|
||||
There are several ways to configure the Teleport Terraform provider depending on how you intend to run Terraform, for example in CI, Spacelift, or some other remote environment, but for a quick start, see the [Local Demo](../../../../configuration/terraform-provider/local.mdx) guide.
|
||||
|
||||
The local demo guide walks through configuring the Teleport Terraform provider with local Teleport credentials, which typically requires logging in with `tsh` and running a `tctl` command from the same shell that you use to run `terraform` commands:
|
||||
|
||||
@@ -147,7 +147,7 @@ $ tsh login
|
||||
$ eval "$(tctl terraform env)"
|
||||
```
|
||||
|
||||
If you are running Terraform in a remote environment, such as a cloud VM, an on-prem server, or CI/CD pipelines, refer to [Using the Teleport Terraform Provider](../../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx) to find the appropriate guide for your use case.
|
||||
If you are running Terraform in a remote environment, such as a cloud VM, an on-prem server, or CI/CD pipelines, refer to [Using the Teleport Terraform Provider](../../../../configuration/terraform-provider/terraform-provider.mdx) to find the appropriate guide for your use case.
|
||||
|
||||
### Configure the Terraform module inputs
|
||||
|
||||
|
||||
+2
-2
@@ -189,7 +189,7 @@ The AWS Terraform provider will need the following AWS IAM permissions to manage
|
||||
|
||||
### Step 2/5. Configure Teleport Terraform provider
|
||||
|
||||
There are several ways to configure the Teleport Terraform provider depending on how you intend to run Terraform, for example in CI, Spacelift, or some other remote environment, but for a quick start, see the [Local Demo](../../../../zero-trust-access/infrastructure-as-code/terraform-provider/local.mdx) guide.
|
||||
There are several ways to configure the Teleport Terraform provider depending on how you intend to run Terraform, for example in CI, Spacelift, or some other remote environment, but for a quick start, see the [Local Demo](../../../../configuration/terraform-provider/local.mdx) guide.
|
||||
|
||||
The local demo guide walks through configuring the Teleport Terraform provider with local Teleport credentials, which is typically as simple as logging in with `tsh` and running a `tctl` command from the same shell that you use to run `terraform` commands:
|
||||
|
||||
@@ -198,7 +198,7 @@ $ tsh login
|
||||
$ eval "$(tctl terraform env)"
|
||||
```
|
||||
|
||||
If you are running Terraform in a remote environment, such as a cloud VM, an on-prem server, or CI/CD pipelines, refer to [Using the Teleport Terraform Provider](../../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx) to find the appropriate guide for your use case.
|
||||
If you are running Terraform in a remote environment, such as a cloud VM, an on-prem server, or CI/CD pipelines, refer to [Using the Teleport Terraform Provider](../../../../configuration/terraform-provider/terraform-provider.mdx) to find the appropriate guide for your use case.
|
||||
|
||||
### Step 3/5. Configure the Terraform module inputs
|
||||
|
||||
|
||||
@@ -133,10 +133,10 @@ $ tctl rm db/example
|
||||
|
||||
Aside from `tctl`, dynamic resources can also be added by:
|
||||
- [Auto-Discovery](../../auto-discovery/databases/databases.mdx)
|
||||
- [Terraform Provider](../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx)
|
||||
- [Kubernetes Operator](../../../zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator.mdx)
|
||||
- [Terraform Provider](../../../configuration/terraform-provider/terraform-provider.mdx)
|
||||
- [Kubernetes Operator](../../../configuration/teleport-operator/teleport-operator.mdx)
|
||||
- [Teleport API](../../../zero-trust-access/api/api.mdx)
|
||||
|
||||
See [Using Dynamic Resources](../../../zero-trust-access/infrastructure-as-code/infrastructure-as-code.mdx) to learn
|
||||
See [Using Dynamic Resources](../../../configuration/configuration.mdx) to learn
|
||||
more about managing Teleport's dynamic resources in general.
|
||||
|
||||
|
||||
@@ -31,7 +31,7 @@ import mcpAndAiSvg from "@site/src/components/Icon/teleport-svg/mcp-and-ai.svg";
|
||||
{
|
||||
title: "Infrastructure as Code",
|
||||
description: "Manage resources as code with Terraform, Kubernetes operator, and tctl",
|
||||
href: "../zero-trust-access/infrastructure-as-code/managing-resources/",
|
||||
href: "../configuration/resource-guides/",
|
||||
icon: terminalWindowSvg,
|
||||
},
|
||||
{
|
||||
|
||||
@@ -102,7 +102,7 @@ $ tctl create openssh-node-resource.yaml
|
||||
<Admonition type="note">
|
||||
This step can be done with Infrastructure-as-Code (IaC) tools (tctl,
|
||||
Terraform, or Kubernetes Operator). This is described [in the OpenSSH server
|
||||
IaC guide](../../../zero-trust-access/infrastructure-as-code/managing-resources/agentless-ssh-servers.mdx).
|
||||
IaC guide](../../../configuration/resource-guides/agentless-ssh-servers.mdx).
|
||||
</Admonition>
|
||||
|
||||
## Step 2/5. Configure `sshd` to trust the Teleport CA
|
||||
|
||||
@@ -93,6 +93,6 @@ You can use the search above to locate content that best fits your specific situ
|
||||
Here are a few places to start:
|
||||
|
||||
- Explore just-in-time access with [Access Requests](../identity-governance/access-requests/access-requests.mdx) or longer-term, auditable access management with [Access Lists](../identity-governance/access-lists/access-lists.mdx)
|
||||
- Automate onboarding using [Terraform](../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx) or the [Kubernetes Operator](../zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator.mdx)
|
||||
- Automate onboarding using [Terraform](../configuration/terraform-provider/terraform-provider.mdx) or the [Kubernetes Operator](../configuration/teleport-operator/teleport-operator.mdx)
|
||||
- Integrate Teleport with your [SSO provider](../zero-trust-access/sso/sso.mdx) or even configure Teleport as an [IDP](../identity-governance/idps/idps.mdx)
|
||||
- Learn how to use [Teleport's API libraries](../zero-trust-access/api/api.mdx) to automate setup tasks such as registering agents with an external service discovery API, generating roles from an external RBAC system, or writing [Access Request plugins](../identity-governance/access-requests/plugins/plugins.mdx).
|
||||
@@ -96,6 +96,6 @@ the cluster, and should be able to interact with it as expected.
|
||||
## Next steps
|
||||
|
||||
- Read [Creating Access Lists with
|
||||
IaC](../../zero-trust-access/infrastructure-as-code/managing-resources/access-list.mdx) for instructions on managing Access Lists with the Teleport Terraform provider and Kubernetes operator.
|
||||
IaC](../../configuration/resource-guides/access-list.mdx) for instructions on managing Access Lists with the Teleport Terraform provider and Kubernetes operator.
|
||||
- Familiarize yourself with the CLI tooling available for managing Access Lists in the [reference](../../reference/access-controls/access-lists.mdx).
|
||||
- Learn how to work with nested Access Lists in the [nested Access Lists guide](./nested-access-lists.mdx).
|
||||
|
||||
@@ -104,7 +104,7 @@ import jamfProSvg from "@site/src/components/Icon/teleport-svg/jamf-pro.svg";
|
||||
{
|
||||
title: "Terraform",
|
||||
description: "Manage team Access Lists with Infrastructure as Code (IaC) using Terraform",
|
||||
href: "../zero-trust-access/infrastructure-as-code/managing-resources/access-list/",
|
||||
href: "../configuration/resource-guides/access-list/",
|
||||
iconColor: "#512FC91A",
|
||||
iconComponent: terraformSvg,
|
||||
},
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
One of the following client tools for managing Teleport resources:
|
||||
|
||||
- The `tctl` CLI, which you can install along with Teleport on your workstation ([documentation](../installation/single-machine/single-machine.mdx)) on your workstation.
|
||||
- [Teleport Terraform provider](../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx)
|
||||
- [Teleport Kubernetes operator](../zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator.mdx)
|
||||
- [Teleport Terraform provider](../configuration/terraform-provider/terraform-provider.mdx)
|
||||
- [Teleport Kubernetes operator](../configuration/terraform-provider/terraform-provider.mdx)
|
||||
|
||||
|
||||
@@ -191,7 +191,7 @@ import listBulletsSvg from "@site/src/components/Icon/teleport-svg/list-bullets.
|
||||
{
|
||||
title: 'Manage Clusters with IaC',
|
||||
description: 'Create, update, and manage Teleport in declarative code.',
|
||||
href: './zero-trust-access/infrastructure-as-code/'
|
||||
href: './configuration/'
|
||||
}
|
||||
]
|
||||
},
|
||||
@@ -216,7 +216,7 @@ import listBulletsSvg from "@site/src/components/Icon/teleport-svg/list-bullets.
|
||||
{
|
||||
title: 'Secure Infrastructure as Code',
|
||||
description: 'Manage IaC workflows in Terraform and Pulumi',
|
||||
href: './zero-trust-access/infrastructure-as-code/terraform-provider/'
|
||||
href: './configuration/terraform-provider/'
|
||||
},
|
||||
{
|
||||
title: 'Hybrid & Multi-Cloud Authentication',
|
||||
|
||||
@@ -365,7 +365,7 @@ You can set up a system to automate the process of assigning join tokens to
|
||||
agents, ensuring that all Teleport services you run have the correct join
|
||||
token permissions. Here are examples in the documentation:
|
||||
- [Enroll Infrastructure with
|
||||
Terraform](../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started.mdx):
|
||||
Terraform](../../configuration/terraform-provider/terraform-getting-started.mdx):
|
||||
Using Terraform to launch Teleport Agent instances that depend on join token
|
||||
resources.
|
||||
- [Automatically Register Resources with
|
||||
|
||||
@@ -22,7 +22,7 @@ the services that run on it.
|
||||

|
||||
|
||||
Read our guide for how to use Terraform to [deploy a pool of
|
||||
Agents](../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started.mdx).
|
||||
Agents](../../configuration/terraform-provider/terraform-getting-started.mdx).
|
||||
|
||||
For more information on the architecture of Teleport Agents, read
|
||||
[Teleport Agent Architecture](../../reference/architecture/agents.mdx).
|
||||
|
||||
@@ -92,7 +92,7 @@ infrastructure resources:
|
||||
resources for the agent to proxy.
|
||||
- **Dynamic resource watchers:** A list of filters the agent uses to fetch
|
||||
[dynamic
|
||||
resources](../../zero-trust-access/infrastructure-as-code/infrastructure-as-code.mdx)
|
||||
resources](../../configuration/configuration.mdx)
|
||||
from the Teleport Auth Service that represent applications, databases,
|
||||
Kubernetes clusters, and remote desktops. The agent proxies infrastructure
|
||||
resources that match its filters.
|
||||
|
||||
@@ -319,4 +319,4 @@ As next steps you can:
|
||||
[applications](../../../enroll-resources/application-access/getting-started.mdx),
|
||||
or [Windows desktops](../../../enroll-resources/desktop-access/desktop-access.mdx) into your Teleport cluster
|
||||
- check the [`teleport-cluster` Helm reference](../../../reference/helm-reference/teleport-cluster.mdx) for a list of supported values
|
||||
- use [the Teleport Kubernetes operator](../../../zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator.mdx) to control Teleport resources
|
||||
- use [the Teleport Kubernetes operator](../../../configuration/teleport-operator/teleport-operator.mdx) to control Teleport resources
|
||||
|
||||
@@ -140,7 +140,7 @@ out-of-date, become incompatible with the cluster, and eventually disconnect.
|
||||
|
||||
For an example Terraform module for deploying and configuring Teleport Agents,
|
||||
see [Deploy Agents with
|
||||
Terraform](../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-getting-started.mdx).
|
||||
Terraform](../../configuration/terraform-provider/terraform-getting-started.mdx).
|
||||
|
||||
### Run the cluster-specific installation script
|
||||
|
||||
|
||||
@@ -28,7 +28,7 @@ information on how to do so.
|
||||
## Specific Tools
|
||||
|
||||
- [tctl](tctl.mdx): How to use Machine & Workload Identity with `tctl` to manage your Teleport configuration.
|
||||
- [Teleport Terraform provider](../../zero-trust-access/infrastructure-as-code/terraform-provider/dedicated-server.mdx): How to use Machine & Workload Identity with the Teleport Terraform provider to manage your Teleport configuration as IaC.
|
||||
- [Teleport Terraform provider](../../configuration/terraform-provider/dedicated-server.mdx): How to use Machine & Workload Identity with the Teleport Terraform provider to manage your Teleport configuration as IaC.
|
||||
- [Ansible](ansible.mdx): How to use Machine & Workload Identity with Ansible.
|
||||
- [Ansible AWX](ansible-awx.mdx): How to use Machine & Workload Identity with Ansible AWX or
|
||||
Ansible Automation Platform.
|
||||
|
||||
@@ -175,12 +175,12 @@ and continuous deployment platform.
|
||||
},
|
||||
{
|
||||
icon: <Icon name="spacelift" size="xl" />,
|
||||
to: "../../zero-trust-access/infrastructure-as-code/terraform-provider/spacelift",
|
||||
to: "../../configuration/terraform-provider/spacelift",
|
||||
name: "Spacelift",
|
||||
},
|
||||
{
|
||||
icon: <Icon name="terraform" size="xl" />,
|
||||
to: "../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-cloud",
|
||||
to: "../../configuration/terraform-provider/terraform-cloud",
|
||||
name: "Terraform Cloud",
|
||||
},
|
||||
{
|
||||
|
||||
@@ -233,21 +233,21 @@ The following steps will help you get started with Machine and Workload Identity
|
||||
{
|
||||
title: 'Spacelift',
|
||||
description: 'Configure Teleport using Spacelift.',
|
||||
href: '../zero-trust-access/infrastructure-as-code/terraform-provider/spacelift/',
|
||||
href: '../configuration/terraform-provider/spacelift/',
|
||||
iconColor: '#F1F2F4',
|
||||
iconComponent: certificateSvg,
|
||||
},
|
||||
{
|
||||
title: 'Terraform',
|
||||
description: 'Configure Teleport using Terraform on a dedicated server.',
|
||||
href: '../zero-trust-access/infrastructure-as-code/terraform-provider/dedicated-server/',
|
||||
href: '../configuration/terraform-provider/dedicated-server/',
|
||||
iconColor: '#512FC91A',
|
||||
iconComponent: terraformSvg,
|
||||
},
|
||||
{
|
||||
title: 'Terraform Cloud',
|
||||
description: 'Configure Teleport using HCP Terraform or Terraform Enterprise.',
|
||||
href: '../zero-trust-access/infrastructure-as-code/terraform-provider/ci-or-cloud/',
|
||||
href: '../configuration/terraform-provider/ci-or-cloud/',
|
||||
iconColor: '#F1F2F4',
|
||||
iconComponent: cloudSvg,
|
||||
},
|
||||
|
||||
@@ -52,7 +52,7 @@ CI/CD pipelines.
|
||||
},
|
||||
{
|
||||
icon: <Icon name="spacelift" size="xl" />,
|
||||
to: "../../../zero-trust-access/infrastructure-as-code/terraform-provider/spacelift",
|
||||
to: "../../../configuration/terraform-provider/spacelift",
|
||||
name: "Spacelift",
|
||||
}
|
||||
]}
|
||||
|
||||
@@ -46,9 +46,9 @@ migrating from Teleport Enterprise to Teleport Community Edition.
|
||||
- An existing Teleport cluster.
|
||||
- The `tsh` and `tctl` client tools. This guide assumes that you are using
|
||||
`tctl` to manage dynamic resources, but it is also possible to use [Teleport
|
||||
Terraform provider](zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx) and
|
||||
Terraform provider](configuration/terraform-provider/terraform-provider.mdx) and
|
||||
[Kubernetes
|
||||
operator](zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator-standalone.mdx), in
|
||||
operator](configuration/teleport-operator/teleport-operator-standalone.mdx), in
|
||||
addition to custom scripts that use the [Teleport API](zero-trust-access/api/api.mdx)
|
||||
to manage the Teleport Auth Service backend.
|
||||
- If you are migrating to Teleport Enterprise (Cloud), you must not have an
|
||||
|
||||
@@ -27,7 +27,7 @@ resources:
|
||||
- [Custom API clients](../../zero-trust-access/api/rbac.mdx)
|
||||
|
||||
To read more about managing dynamic resources, see the [Dynamic
|
||||
Resources](../../zero-trust-access/infrastructure-as-code/infrastructure-as-code.mdx) guide.
|
||||
Resources](../../configuration/configuration.mdx) guide.
|
||||
|
||||
You can view all roles in your cluster on your local workstation by running the
|
||||
following commands:
|
||||
|
||||
@@ -20,7 +20,7 @@ in a cluster, including nodes, users, tokens, certificates, and devices.
|
||||
such as creating new user roles or connecting to trusted clusters.
|
||||
|
||||
For a conceptual overview of `tctl`, see [Getting Started with
|
||||
`tctl`](../../zero-trust-access/infrastructure-as-code/using-tctl.mdx).
|
||||
`tctl`](../../configuration/using-tctl.mdx).
|
||||
|
||||
```code
|
||||
$ tctl [<flags>] <command> [<args> ...]
|
||||
|
||||
@@ -383,7 +383,7 @@ The `env0` join method requires Teleport v18.4.0 or later.
|
||||
(!docs/pages/includes/provision-token/env0-spec.mdx!)
|
||||
|
||||
<Admonition type="note" title="See Also">
|
||||
- [Run the Teleport Terraform Provider on Env0](../../zero-trust-access/infrastructure-as-code/terraform-provider/env0.mdx)
|
||||
- [Run the Teleport Terraform Provider on Env0](../../configuration/terraform-provider/env0.mdx)
|
||||
</Admonition>
|
||||
|
||||
### GCP service account: `gcp`
|
||||
@@ -555,7 +555,7 @@ Support for self-hosted Terraform Enterprise requires Teleport Enterprise.
|
||||
(!docs/pages/includes/provision-token/terraform-spec.mdx!)
|
||||
|
||||
<Admonition type="note" title="See Also">
|
||||
- [Run the Teleport Terraform Provider on Terraform Cloud](../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-cloud.mdx)
|
||||
- [Run the Teleport Terraform Provider on Terraform Cloud](../../configuration/terraform-provider/terraform-cloud.mdx)
|
||||
</Admonition>
|
||||
|
||||
### Spacelift: `spacelift`
|
||||
@@ -567,7 +567,7 @@ deployments).
|
||||
(!docs/pages/includes/provision-token/spacelift-spec.mdx!)
|
||||
|
||||
<Admonition type="note" title="See Also">
|
||||
- [Run the Teleport Terraform Provider on Spacelift](../../zero-trust-access/infrastructure-as-code/terraform-provider/spacelift.mdx)
|
||||
- [Run the Teleport Terraform Provider on Spacelift](../../configuration/terraform-provider/spacelift.mdx)
|
||||
</Admonition>
|
||||
|
||||
### Bitbucket Pipelines: `bitbucket`
|
||||
|
||||
@@ -0,0 +1,100 @@
|
||||
---
|
||||
title: Reconciling Static and Dynamic Configuration
|
||||
description: Learn how Teleport reconciles static configuration files with dynamic resources managed through IaC tools.
|
||||
sidebar_position: 1
|
||||
sidebar_label: Reconciliation Configurations
|
||||
tags:
|
||||
- infrastructure-as-code
|
||||
- conceptual
|
||||
- zero-trust
|
||||
---
|
||||
|
||||
Some dynamic resources assign the same settings as fields within Teleport's
|
||||
static configuration file. For these fields, the Teleport Auth Service
|
||||
reconciles static and dynamic configurations on startup and when you create or
|
||||
remove a Teleport resource.
|
||||
|
||||
While Teleport Enterprise Cloud does not expose the static configuration file to
|
||||
operators, they do use a static configuration file for certain settings.
|
||||
|
||||
## Shared configuration fields
|
||||
|
||||
There are several dynamic resources that share fields with the static configuration file:
|
||||
|
||||
### session_recording_config
|
||||
|
||||
| Dynamic resource field | Static configuration field |
|
||||
|------------------------------------|--------------------------------------------|
|
||||
| `spec.mode` | `auth_service.session_recording` |
|
||||
| `spec.proxy_checks_host_keys` | `auth_service.proxy_checks_host_keys` |
|
||||
|
||||
### cluster_auth_preference
|
||||
|
||||
| Dynamic resource field | Static configuration field |
|
||||
|-------------------------------|---------------------------------------------------------|
|
||||
| `spec.type` | `auth_service.authentication.type` |
|
||||
| `spec.second_factors` | `auth_service.authentication.second_factors` |
|
||||
| `spec.connector_name` | `auth_service.authentication.connector_name` |
|
||||
| `spec.disconnect_expired_cert`| `auth_service.disconnect_expired_cert` |
|
||||
| `spec.allow_local_auth` | `auth_service.authentication.local_auth` |
|
||||
| `spec.message_of_the_day` | `auth_service.message_of_the_day` |
|
||||
| `spec.locking_mode` | `auth_service.authentication.locking_mode` |
|
||||
| `spec.webauthn` | `auth_service.authentication.webauthn` |
|
||||
| `spec.require_session_mfa` | `auth_service.authentication.require_session_mfa` |
|
||||
| `spec.allow_passwordless` | `auth_service.authentication.passwordless` |
|
||||
| `spec.device_trust` | `auth_service.authentication.device_trust` |
|
||||
| `spec.idp` | `proxy_service.idp` |
|
||||
| `spec.allow_headless` | `auth_service.authentication.headless` |
|
||||
|
||||
### cluster_networking_config
|
||||
|
||||
| Dynamic resource field | Static configuration field |
|
||||
|----------------------------------|----------------------------------------------|
|
||||
| `spec.client_idle_timeout` | `auth_service.client_idle_timeout` |
|
||||
| `spec.keep_alive_interval` | `auth_service.keep_alive_interval` |
|
||||
| `spec.keep_alive_count_max` | `auth_service.keep_alive_count_max` |
|
||||
| `spec.session_control_timeout` | `auth_service.session_control_timeout` |
|
||||
| `spec.idle_timeout_message` | `auth_service.client_idle_timeout_message` |
|
||||
| `spec.web_idle_timeout` | `auth_service.web_idle_timeout` |
|
||||
| `spec.proxy_listener_mode` | `auth_service.proxy_listener_mode` |
|
||||
| `spec.routing_strategy` | `auth_service.routing_strategy` |
|
||||
| `spec.tunnel_strategy` | `auth_service.tunnel_strategy` |
|
||||
| `spec.proxy_ping_interval` | `auth_service.proxy_ping_interval` |
|
||||
| `spec.case_insensitive_routing` | `auth_service.case_insensitive_routing` |
|
||||
|
||||
### ui_config
|
||||
|
||||
| Dynamic resource field | Static configuration field |
|
||||
|-------------------------------|--------------------------------------------|
|
||||
| `spec.scrollback_lines` | `proxy_service.ui.scrollback_lines` |
|
||||
| `spec.show_resources` | `proxy_service.ui.show_resources` |
|
||||
|
||||
## Origin labels
|
||||
|
||||
The Teleport Auth Service applies the `teleport.dev/origin` label to configuration resources to indicate whether they originated from the static configuration file, a dynamic configuration resource, or the default value.
|
||||
|
||||
Here are possible values of the teleport.dev/origin label:
|
||||
|
||||
- `defaults`
|
||||
- `config-file`
|
||||
- `dynamic`
|
||||
- `terraform`
|
||||
- `kubernetes`
|
||||
|
||||
When the Auth Service starts up, it looks up the values of static configuration fields that correspond to fields in dynamic configuration resources. If any of these have values, it creates the corresponding dynamic configuration resources and stores them in its backend.
|
||||
|
||||
For any static configuration fields without a value, the Auth Service checks whether the backend contains the corresponding dynamic configuration resource. If not, it creates one with default values and the `teleport.dev/origin=defaults` label.
|
||||
|
||||
If you attempt to create a dynamic configuration resource after the Auth Service has already loaded the configuration from a static configuration file, the Auth Service will return an error.
|
||||
|
||||
If you remove a dynamic configuration resource, the Auth Service will restore its configuration fields to the default values and add the `teleport.dev/origin=defaults` label.
|
||||
|
||||
<Admonition
|
||||
type="tip"
|
||||
title="Tip"
|
||||
>
|
||||
Teleport Cloud deployments use configuration files, but these are not available for operators to modify. Users of Teleport Enterprise Cloud may see configuration resources with the `teleport.dev/origin=config-file` label.
|
||||
</Admonition>
|
||||
|
||||
|
||||
|
||||
@@ -11,7 +11,7 @@ tags:
|
||||
The `teleport-operator` Helm chart deploys the Teleport Kubernetes Operator.
|
||||
When deployed via the chart, the operator can join Teleport clusters living in
|
||||
Kubernetes or remote ones (such as Teleport Cloud).
|
||||
See the [Kubernetes Operator for remote Teleport clusters guide](../../zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator-standalone.mdx)
|
||||
See the [Kubernetes Operator for remote Teleport clusters guide](../../configuration/teleport-operator/teleport-operator-standalone.mdx)
|
||||
for more details.
|
||||
|
||||
You can
|
||||
|
||||
+2
-2
@@ -17,13 +17,13 @@ comprehensive lists of fields for each supported resource.
|
||||
|
||||
If you are getting started with the Teleport Kubernetes operator, we recommend
|
||||
reading the [introductory
|
||||
guide](../../../zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator.mdx)
|
||||
guide](../../../configuration/teleport-operator/teleport-operator.mdx)
|
||||
to setting up and using the operator.
|
||||
|
||||
For guidance on using the Teleport Kubernetes operator to manage the dynamic
|
||||
resources that you would typically see in a Teleport cluster, such as roles and
|
||||
users, see [Managing
|
||||
Resources](../../../zero-trust-access/infrastructure-as-code/managing-resources/managing-resources.mdx).
|
||||
Resources](../../../configuration/resource-guides/resource-guides.mdx).
|
||||
|
||||
## Selecting a reference guide
|
||||
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@ tags:
|
||||
The guides in this section list fields within dynamic resources you can manage
|
||||
with Teleport. For more information on dynamic resources, see our guide to
|
||||
[Using Dynamic
|
||||
Resources](../../../zero-trust-access/infrastructure-as-code/infrastructure-as-code.mdx).
|
||||
Resources](../../../configuration/configuration.mdx).
|
||||
|
||||
Examples of applying dynamic resources with `tctl`:
|
||||
|
||||
|
||||
+1
-1
@@ -28,7 +28,7 @@ This Terraform module creates the AWS and Teleport cluster resources necessary f
|
||||
## Prerequisites
|
||||
|
||||
{/* lint ignore absolute-docs-links */}
|
||||
- [Configure Teleport Terraform Provider](https://goteleport.com/docs/zero-trust-access/infrastructure-as-code/terraform-provider/)
|
||||
- [Configure Teleport Terraform Provider](https://goteleport.com/docs/configuration/terraform-provider/)
|
||||
- [Configure AWS Terraform provider](https://registry.terraform.io/providers/hashicorp/aws/latest/docs)
|
||||
|
||||
## Usage
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@ This Terraform module creates the Azure and Teleport cluster resources necessary
|
||||
## Prerequisites
|
||||
|
||||
{/* lint ignore absolute-docs-links */}
|
||||
- [Install Teleport Terraform Provider](https://goteleport.com/docs/zero-trust-access/infrastructure-as-code/terraform-provider/)
|
||||
- [Install Teleport Terraform Provider](https://goteleport.com/docs/configuration/terraform-provider/)
|
||||
{/* lint ignore absolute-docs-links */}
|
||||
- Every Azure VM to be discovered must have a managed identity assigned to it with at least the Microsoft.Compute/virtualMachines/read permission. [Read more](https://goteleport.com/docs/enroll-resources/auto-discovery/servers/azure-vm-discovery/azure-vm-discovery-terraform/#setting-up-managed-identities-for-discovered-vms)
|
||||
|
||||
|
||||
+6
-6
@@ -19,9 +19,9 @@ It lists all the supported resources and their fields.
|
||||
|
||||
<Admonition type="tip">
|
||||
To get started with the Terraform provider, you must start with [the installation
|
||||
guide](../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
guide](../../../configuration/terraform-provider/terraform-provider.mdx).
|
||||
Once you got a working provider, we recommend you to follow the
|
||||
["Managing users and roles with IaC"](../../../zero-trust-access/infrastructure-as-code/managing-resources/user-and-role.mdx) guide.
|
||||
["Managing users and roles with IaC"](../../../configuration/resource-guides/user-and-role.mdx) guide.
|
||||
</Admonition>
|
||||
|
||||
The provider exposes Teleport resources both as Terraform data-sources and Terraform resources.
|
||||
@@ -85,7 +85,7 @@ provider "teleport" {
|
||||
This section lists the different ways of passing credentials to the Terraform provider.
|
||||
You can find which method fits your use case in
|
||||
the [Teleport Terraform provider setup
|
||||
page](../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx)
|
||||
page](../../../configuration/terraform-provider/terraform-provider.mdx)
|
||||
|
||||
### With an identity file
|
||||
|
||||
@@ -112,7 +112,7 @@ Detected security key tap
|
||||
```
|
||||
|
||||
You can find more information in
|
||||
the ["Run the Terraform provider locally" guide](../../../zero-trust-access/infrastructure-as-code/terraform-provider/local.mdx)
|
||||
the ["Run the Terraform provider locally" guide](../../../configuration/terraform-provider/local.mdx)
|
||||
|
||||
#### Obtaining an identity file via `tbot`
|
||||
|
||||
@@ -121,7 +121,7 @@ short-lived credentials. Such credentials are harder to exfiltrate, and you can
|
||||
which roles (e.g. you can allow only GitHub Actions pipelines targeting the `prod` environment to get certificates).
|
||||
|
||||
You can follow [the Terraform Provider
|
||||
guide](../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx) to setup `tbot`
|
||||
guide](../../../configuration/terraform-provider/terraform-provider.mdx) to setup `tbot`
|
||||
and have Terraform use its identity.
|
||||
|
||||
#### Obtaining an identity file via `tctl auth sign`
|
||||
@@ -149,7 +149,7 @@ You can use any [delegated join method](../../deployment/join-methods.mdx#delega
|
||||
both `join_method` and `join_token` in the provider configuration.
|
||||
|
||||
This setup is described in more details in
|
||||
the ["Run the Teleport Terraform provider in CI or Cloud" guide](../../../zero-trust-access/infrastructure-as-code/terraform-provider/ci-or-cloud.mdx).
|
||||
the ["Run the Teleport Terraform provider in CI or Cloud" guide](../../../configuration/terraform-provider/ci-or-cloud.mdx).
|
||||
|
||||
### With key, certificate, and CA certificate
|
||||
|
||||
|
||||
@@ -86,16 +86,16 @@ Each principle has many "Points of Focus" which will apply differently to differ
|
||||
| CC7.4 - Periodically Evaluates Incidents | Periodically, management reviews incidents related to security, availability, processing integrity, confidentiality, and privacy and identifies the need for system changes based on incident patterns and root causes. | [Use Session recording and audit logs to find patterns that lead to incidents.](../../enroll-resources/server-access/guides/bpf-session-recording.mdx) |
|
||||
| CC7.5 - Determines Root Cause of the Event | The root cause of the event is determined. | [Use Session recording and audit logs to find root cause.](../../enroll-resources/server-access/guides/bpf-session-recording.mdx) |
|
||||
| CC7.5 - Improves Response and Recovery Procedures | Lessons learned are analyzed and the incident-response plan and recovery procedures are improved. | [Replay Session recordings at your 'after action review' or postmortem meetings](../../enroll-resources/server-access/guides/bpf-session-recording.mdx) |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Manages changes throughout the system life cycle. | Enables a documented software development lifecycle through its integrations with [infrastructure as code tools](../infrastructure-as-code/infrastructure-as-code.mdx). |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Authorizes Changes, Identifies and Evaluates System Changes. | [Infrastructure as code](../infrastructure-as-code/infrastructure-as-code.mdx) integrations enable you to authorize changes using GitOps platforms. [Access Requests](../../identity-governance/access-requests/access-requests.mdx) enable authorization for elevated privileges. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Designs and Develops Changes. | [Infrastructure as code](../infrastructure-as-code/infrastructure-as-code.mdx) integrations allow you to specify infrastructure access controls as code. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Documents Changes. | [Infrastructure as code](../infrastructure-as-code/infrastructure-as-code.mdx) integrations allow for documenting configuration changes in version control system logs, and a [notification system](../../connect-your-client/teleport-clients/notifications.mdx) allows you to inform end users of system changes. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Tracks System Changes. | [Infrastructure as code](../infrastructure-as-code/infrastructure-as-code.mdx) integrations and audit logging allow you to track the history of configuration changes and [Access Request](../../identity-governance/access-requests/access-requests.mdx) approvals in a Teleport cluster. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Configures Software. | [Infrastructure as code](../infrastructure-as-code/infrastructure-as-code.mdx) support enables you to track dynamic resource configurations. [Helm support](../../reference/helm-reference/helm-reference.mdx) allows you to track configurations for Teleport services on Kubernetes. You can also use version control to manage Teleport [YAML configuration files](../../reference/deployment/config.mdx).|
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Manages changes throughout the system life cycle. | Enables a documented software development lifecycle through its integrations with [infrastructure as code tools](../../configuration/configuration.mdx). |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Authorizes Changes, Identifies and Evaluates System Changes. | [Infrastructure as code](../../configuration/configuration.mdx) integrations enable you to authorize changes using GitOps platforms. [Access Requests](../../identity-governance/access-requests/access-requests.mdx) enable authorization for elevated privileges. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Designs and Develops Changes. | [Infrastructure as code](../../configuration/configuration.mdx) integrations allow you to specify infrastructure access controls as code. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Documents Changes. | [Infrastructure as code](../../configuration/configuration.mdx) integrations allow for documenting configuration changes in version control system logs, and a [notification system](../../connect-your-client/teleport-clients/notifications.mdx) allows you to inform end users of system changes. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Tracks System Changes. | [Infrastructure as code](../../configuration/configuration.mdx) integrations and audit logging allow you to track the history of configuration changes and [Access Request](../../identity-governance/access-requests/access-requests.mdx) approvals in a Teleport cluster. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Configures Software. | [Infrastructure as code](../../configuration/configuration.mdx) support enables you to track dynamic resource configurations. [Helm support](../../reference/helm-reference/helm-reference.mdx) allows you to track configurations for Teleport services on Kubernetes. You can also use version control to manage Teleport [YAML configuration files](../../reference/deployment/config.mdx).|
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Tests System Changes. | Teleport's infrastructure as code support and [gRPC API](../api/api.mdx) make it possible to set up staging environments and automated tests for changes in a Teleport configuration. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Approves System Changes. | [Access Requests](../../identity-governance/access-requests/access-requests.mdx) allow approvals to proposed permissions changes, and infrastructure as code support enables you to set up an approval system for configurations. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Deploys System Changes. | [RBAC protections](../../reference/access-controls/roles.mdx#rbac-for-dynamic-teleport-resources) for API resources allow you to restrict configuration changes to an authorized continuous deployment runner. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Identifies Changes in the Infrastructure, Data, Software, and Procedures Required to Remediate Incidents. | [Infrastructure as code](../infrastructure-as-code/infrastructure-as-code.mdx) support enables you to revert changes. It is also possible for you to [back up the Auth Service backend](../management/backup-restore.mdx) on self-hosted clusters.|
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Creates Baseline Configuration of IT Technology. |[Infrastructure as code](../infrastructure-as-code/infrastructure-as-code.mdx) support enables you to set up a baseline configuration in a code repository. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Identifies Changes in the Infrastructure, Data, Software, and Procedures Required to Remediate Incidents.| [Infrastructure as code](../../configuration/configuration.mdx) support enables you to revert changes. It is also possible for you to [back up the Auth Service backend](../management/backup-restore.mdx) on self-hosted clusters.|
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Creates Baseline Configuration of IT Technology. |[Infrastructure as code](../../configuration/configuration.mdx) support enables you to set up a baseline configuration in a code repository. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Provides Changes Necessary in Emergency Situations. | Admins can use [Access Requests](../../identity-governance/access-requests/access-requests.mdx) to obtain temporarily elevated permissions in order to provide changes in emergency situations. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Manages Patch Changes. | [Infrastructure as code](../infrastructure-as-code/infrastructure-as-code.mdx) support enables regular patch changes to configurations. |
|
||||
| CC8.1 - Authorizes, designs, develops or acquires, configures, documents, tests, approves and implements changes to its infrastructure, data, software, and procedures to meet its objectives. | Manages Patch Changes. | [Infrastructure as code](../../configuration/configuration.mdx) support enables regular patch changes to configurations. |
|
||||
|
||||
@@ -20,7 +20,7 @@ and configure it to use the Teleport Kubernetes Operator to generate the credent
|
||||
|
||||
If your Teleport cluster does not have the Teleport Kubernetes Operator deployed, follow the
|
||||
[guide to set up the Teleport Kubernetes Operator
|
||||
](../../zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator.mdx).
|
||||
](../../configuration/teleport-operator/teleport-operator.mdx).
|
||||
If you wish to deploy the Teleport Event Handler Plugin in Kubernetes without the Teleport Kubernetes
|
||||
Operator, see [Set up the Event Handler with tctl](event-handler-setup.mdx).
|
||||
|
||||
@@ -45,7 +45,7 @@ the mutual TLS connection between the Event Handler and the Teleport cluster.
|
||||
|
||||
- A Kubernetes cluster to run the Teleport Event Handler plugin.
|
||||
|
||||
- [Teleport Kubernetes Operator](../../zero-trust-access/infrastructure-as-code/teleport-operator/teleport-operator.mdx)
|
||||
- [Teleport Kubernetes Operator](../../configuration/teleport-operator/teleport-operator.mdx)
|
||||
running in the Kubernetes cluster where you will install the plugin.
|
||||
|
||||
- [Helm](https://helm.sh/docs/intro/quickstart/)
|
||||
|
||||
@@ -1,186 +0,0 @@
|
||||
---
|
||||
title: Infrastructure as Code
|
||||
description: An introduction to managing Teleport with Infrastructure as Code tools, including Terraform and Kubernetes resources.
|
||||
sidebar_position: 5
|
||||
tags:
|
||||
- infrastructure-as-code
|
||||
- conceptual
|
||||
- zero-trust
|
||||
---
|
||||
|
||||
This section explains how to manage Teleport using infrastructure as code (IaC)
|
||||
tools.
|
||||
|
||||
Teleport provides three methods for managing Teleport with infrastructure as
|
||||
code tools:
|
||||
- [Teleport Terraform provider](terraform-provider/terraform-provider.mdx)
|
||||
- [Teleport Kubernetes operator](teleport-operator/teleport-operator.mdx)
|
||||
- [`tctl` client tool](using-tctl.mdx)
|
||||
|
||||
For instructions on managing users, roles, trusted clusters, and other resources
|
||||
with IaC tools, see [Managing Resources with Infrastructure as
|
||||
Code](managing-resources/managing-resources.mdx).
|
||||
|
||||
## How IaC works with Teleport
|
||||
|
||||
There are two ways to configure a Teleport cluster:
|
||||
|
||||
- **Static configuration file:** At startup, a Teleport process reads a
|
||||
configuration file from the local filesystem (the default path is
|
||||
`/etc/teleport.yaml`). Static configuration settings control aspects of a
|
||||
cluster that are not expected to change frequently, like the ports that
|
||||
services listen on. (See the [Configuration
|
||||
Reference](../../reference/deployment/config.mdx) for all static configuration
|
||||
options.)
|
||||
- **Dynamic resources:** Dynamic resources control aspects of your cluster that
|
||||
are likely to change over time, such as roles, local users, and
|
||||
Teleport-protected infrastructure resources.
|
||||
|
||||

|
||||
|
||||
The Teleport Auth Service stores dynamic resources on its cluster state backend,
|
||||
and clients can authenticate to the Auth Service to read or write dynamic
|
||||
resources, depending on their permissions. Infrastructure as code tools can
|
||||
authenticate to a Teleport cluster to manage dynamic resources.
|
||||
|
||||
## Reconciling static and dynamic configurations
|
||||
|
||||
Some dynamic resources assign the same settings as fields within
|
||||
Teleport's static configuration file. For these fields, the Teleport Auth
|
||||
Service reconciles static and dynamic configurations on startup and when you
|
||||
create or remove a Teleport resource.
|
||||
|
||||
While Teleport Enterprise Cloud does not expose the static configuration file to
|
||||
operators, they do use a static configuration file for certain settings.
|
||||
|
||||
### Configuration resources that apply to static configuration fields
|
||||
|
||||
There are four dynamic resources that share fields with the
|
||||
static configuration file:
|
||||
|
||||
- `session_recording_config`
|
||||
- `cluster_auth_preference`
|
||||
- `cluster_networking_config`
|
||||
- `ui_config`
|
||||
|
||||
#### `session_recording_config`
|
||||
|
||||
|Dynamic resource field|Static configuration field|
|
||||
|---|---|
|
||||
|`spec.mode`|`auth_service.session_recording`|
|
||||
|`spec.proxy_checks_host_keys`|`auth_service.proxy_checks_host_keys`|
|
||||
|
||||
#### `cluster_auth_preference`
|
||||
|
||||
|Dynamic resource field|Static configuration field|
|
||||
|---|---|
|
||||
|`spec.type`|`auth_service.authentication.type`|
|
||||
|`spec.second_factor`|`auth_service.authentication.second_factor`|
|
||||
|`spec.second_factors`|`auth_service.authentication.second_factors`|
|
||||
|`spec.connector_name`|`auth_service.authentication.connector_name`
|
||||
|`spec.u2f`|`auth_service.authentication.u2f`|
|
||||
|`spec.disconnect_expired_cert`|`auth_service.disconnect_expired_cert`|
|
||||
|`spec.allow_local_auth`|`auth_service.authentication.local_auth`|
|
||||
|`spec.message_of_the_day`|`auth_service.message_of_the_day`|
|
||||
|`spec.locking_mode`|`auth_service.authentication.locking_mode`|
|
||||
|`spec.webauthn`|`auth_service.authentication.webauthn`|
|
||||
|`spec.require_session_mfa`|`auth_service.authentication.require_session_mfa`|
|
||||
|`spec.allow_passwordless`|`auth_service.authentication.passwordless`|
|
||||
|`spec.device_trust`|`auth_service.authentication.device_trust`|
|
||||
|`spec.idp`|`proxy_service.idp`|
|
||||
|`spec.allow_headless`|`auth_service.authentication.headless`|
|
||||
|
||||
#### `cluster_networking_config`
|
||||
|
||||
|Dynamic resource field|Static configuration field|
|
||||
|---|---|
|
||||
|`spec.client_idle_timeout`|`auth_service.client_idle_timeout`|
|
||||
|`spec.keep_alive_interval`|`auth_service.keep_alive_interval`|
|
||||
|`spec.keep_alive_count_max`|`auth_service.keep_alive_count_max`|
|
||||
|`spec.session_control_timeout`|`auth_service.session_control_timeout`|
|
||||
|`spec.idle_timeout_message`|`auth_service.client_idle_timeout_message`|
|
||||
|`spec.web_idle_timeout`|`auth_service.web_idle_timeout`|
|
||||
|`spec.proxy_listener_mode`|`auth_service.proxy_listener_mode`|
|
||||
|`spec.routing_strategy`|`auth_service.routing_strategy`|
|
||||
|`spec.tunnel_strategy`|`auth_service.tunnel_strategy`|
|
||||
|`spec.proxy_ping_interval`|`auth_service.proxy_ping_interval`|
|
||||
|`spec.case_insensitive_routing`|`auth_service.case_insensitive_routing`|
|
||||
|
||||
#### `ui_config`
|
||||
|
||||
| Dynamic resource field | Static configuration field |
|
||||
| ----------------------- | ----------------------------------- |
|
||||
| `spec.scrollback_lines` | `proxy_service.ui.scrollback_lines` |
|
||||
| `spec.show_resources` | `proxy_service.ui.show_resources` |
|
||||
|
||||
## Origin labels
|
||||
|
||||
The Teleport Auth Service applies the `teleport.dev/origin` label to
|
||||
configuration resources to indicate whether they originated from the static
|
||||
configuration file, a dynamic configuration resource, or the default value.
|
||||
|
||||
Here are possible values of the `teleport.dev/origin` label:
|
||||
|
||||
- `defaults`
|
||||
- `config-file`
|
||||
- `dynamic`
|
||||
- `terraform`
|
||||
- `kubernetes`
|
||||
|
||||
When the Auth Service starts up, it looks up the values of static configuration
|
||||
fields that correspond to fields in dynamic configuration resources. If any of
|
||||
these have values, it creates the corresponding dynamic configuration resources
|
||||
and stores them in its backend.
|
||||
|
||||
For any static configuration fields without a value, the Auth Service checks
|
||||
whether the backend contains the corresponding dynamic configuration resource.
|
||||
If not, it creates one with default values and the
|
||||
`teleport.dev/origin=defaults` label.
|
||||
|
||||
If you attempt to create a dynamic configuration resource after the Auth Service
|
||||
has already loaded the configuration from a static configuration file, the Auth
|
||||
Service will return an error.
|
||||
|
||||
If you remove a dynamic configuration resource, the Auth Service will restore
|
||||
its configuration fields to the default values and add the
|
||||
`teleport.dev/origin=defaults` label.
|
||||
|
||||
<Admonition type="tip">
|
||||
|
||||
Cloud-hosted Teleport deployments use configuration files, but these are not
|
||||
available for operators to modify. Users of Teleport Enterprise Cloud may see
|
||||
configuration resources with the `teleport.dev/origin=config-file` label.
|
||||
|
||||
</Admonition>
|
||||
|
||||
## Dynamic resource references
|
||||
|
||||
Read the following reference guides for comprehensive lists of supported fields
|
||||
in Teleport dynamic resources:
|
||||
|
||||
### tctl resources
|
||||
|
||||
For reference guides to dynamic configuration resources available to apply using
|
||||
`tctl`, read the [Configuration Resource
|
||||
Reference](../../reference/infrastructure-as-code/teleport-resources/teleport-resources.mdx).
|
||||
There is also a dedicated configuration resource reference for
|
||||
[applications](../../enroll-resources/application-access/reference.mdx).
|
||||
|
||||
### Terraform resources and data sources
|
||||
|
||||
For comprehensive reference guides for resources and data sources you can manage
|
||||
with the Teleport Terraform provider, see [Teleport Terraform Provider
|
||||
References](../../reference/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
|
||||
### Kubernetes operator resources
|
||||
|
||||
For comprehensive reference guides for resources you can manage with the
|
||||
Kubernetes operator, see [Teleport Kubernetes Operator Resource
|
||||
References](../../reference/infrastructure-as-code/operator-resources/operator-resources.mdx).
|
||||
|
||||
## Other ways to use the dynamic resource API
|
||||
|
||||
The Teleport Kubernetes Operator, Terraform provider, and `tctl` are all clients
|
||||
of the Teleport Auth Service's gRPC API. To build your own API client to extend
|
||||
Teleport for your organization's needs, read our [API
|
||||
guides](../api/api.mdx).
|
||||
@@ -77,10 +77,10 @@ full explanation in [Storage Backends](../../reference/deployment/backends.mdx#e
|
||||
## Versioning dynamic resources with infrastructure as code
|
||||
|
||||
Teleport uses [dynamic
|
||||
resources](../infrastructure-as-code/infrastructure-as-code.mdx) for roles,
|
||||
local users, authentication connectors, and other configurations, and stores
|
||||
dynamic resource data on the cluster state backend. Backing up the cluster
|
||||
state backend protects your cluster against the loss of dynamic resource data.
|
||||
resources](../../configuration/configuration.mdx) for roles, local users,
|
||||
authentication connectors, and other configurations, and stores dynamic resource
|
||||
data on the cluster state backend. Backing up the cluster state backend protects
|
||||
your cluster against the loss of dynamic resource data.
|
||||
|
||||
For more control over the version of a dynamic resource that you back up and
|
||||
restore, we recommend storing dynamic resource manifests in a code repository
|
||||
@@ -96,9 +96,9 @@ Teleport provides the following infrastructure as code tools for managing
|
||||
dynamic resources:
|
||||
|
||||
- [Terraform
|
||||
provider](../infrastructure-as-code/terraform-provider/terraform-provider.mdx)
|
||||
provider](../../configuration/terraform-provider/terraform-provider.mdx)
|
||||
- [Kubernetes
|
||||
operator](../infrastructure-as-code/teleport-operator/teleport-operator.mdx)
|
||||
operator](../../configuration/teleport-operator/teleport-operator.mdx)
|
||||
|
||||
## Cloning a backend
|
||||
|
||||
|
||||
@@ -15,7 +15,7 @@ example, you can allow analytics team members to SSH into a MongoDB read
|
||||
replica, but not the main database.
|
||||
|
||||
Teleport **roles** are [dynamic
|
||||
resources](../infrastructure-as-code/infrastructure-as-code.mdx) that allow or
|
||||
resources](../../configuration/configuration.mdx) that allow or
|
||||
deny access to infrastructure resources, as well as to Teleport API operations
|
||||
like creating users or reviewing Access Requests.
|
||||
|
||||
|
||||
@@ -104,21 +104,6 @@ import mcpAndAiSvg from "@site/src/components/Icon/teleport-svg/mcp-and-ai.svg";
|
||||
},
|
||||
]
|
||||
},
|
||||
{
|
||||
title: "Infrastructure as Code",
|
||||
description: "Manage Teleport's Dynamic Resources using infrastructure as code tools, including Terraform, Helm and the Teleport tctl client tool.",
|
||||
href: "./infrastructure-as-code/",
|
||||
tags: [
|
||||
{
|
||||
name: "Terraform",
|
||||
href: "./infrastructure-as-code/terraform-provider/",
|
||||
},
|
||||
{
|
||||
name: "Kubernetes operator",
|
||||
href: "./infrastructure-as-code/teleport-operator/",
|
||||
},
|
||||
]
|
||||
},
|
||||
{
|
||||
title: "Security best practices",
|
||||
description: "Run Teleport Enterprise in your own infrastructure, with guides covering high availability and multi-region clusters, secure CA keys with KMS or HSM, and more.",
|
||||
@@ -203,12 +188,7 @@ import mcpAndAiSvg from "@site/src/components/Icon/teleport-svg/mcp-and-ai.svg";
|
||||
title: "Dual authorization capabilities",
|
||||
description: "Require approvals to perform critical actions",
|
||||
href: "../identity-governance/access-requests/",
|
||||
},
|
||||
{
|
||||
title: "Manage clusters with IaC",
|
||||
description: "Create, update, and manage Teleport in declarative code.",
|
||||
href: "./infrastructure-as-code/",
|
||||
},
|
||||
}
|
||||
]}
|
||||
/>
|
||||
|
||||
|
||||
@@ -77,6 +77,21 @@
|
||||
"id": "installation/installation"
|
||||
}
|
||||
},
|
||||
{
|
||||
"type": "category",
|
||||
"label": "Configuration",
|
||||
"collapsible": true,
|
||||
"items": [
|
||||
{
|
||||
"type": "autogenerated",
|
||||
"dirName": "configuration"
|
||||
}
|
||||
],
|
||||
"link": {
|
||||
"type": "doc",
|
||||
"id": "configuration/configuration"
|
||||
}
|
||||
},
|
||||
{
|
||||
"type": "category",
|
||||
"label": "Upgrading",
|
||||
|
||||
@@ -14,7 +14,7 @@ This Terraform module creates the AWS and Teleport cluster resources necessary f
|
||||
## Prerequisites
|
||||
|
||||
<!-- lint ignore absolute-docs-links -->
|
||||
- [Configure Teleport Terraform Provider](https://goteleport.com/docs/zero-trust-access/infrastructure-as-code/terraform-provider/)
|
||||
- [Configure Teleport Terraform Provider](https://goteleport.com/docs/configuration/terraform-provider/)
|
||||
- [Configure AWS Terraform provider](https://registry.terraform.io/providers/hashicorp/aws/latest/docs)
|
||||
|
||||
## Usage
|
||||
|
||||
@@ -12,7 +12,7 @@ This Terraform module creates the Azure and Teleport cluster resources necessary
|
||||
## Prerequisites
|
||||
|
||||
<!-- lint ignore absolute-docs-links -->
|
||||
- [Install Teleport Terraform Provider](https://goteleport.com/docs/zero-trust-access/infrastructure-as-code/terraform-provider/)
|
||||
- [Install Teleport Terraform Provider](https://goteleport.com/docs/configuration/terraform-provider/)
|
||||
<!-- lint ignore absolute-docs-links -->
|
||||
- Every Azure VM to be discovered must have a managed identity assigned to it with at least the Microsoft.Compute/virtualMachines/read permission. [Read more](https://goteleport.com/docs/enroll-resources/auto-discovery/servers/azure-vm-discovery/azure-vm-discovery-terraform/#setting-up-managed-identities-for-discovered-vms)
|
||||
|
||||
|
||||
@@ -19,9 +19,9 @@ It lists all the supported resources and their fields.
|
||||
|
||||
<Admonition type="tip">
|
||||
To get started with the Terraform provider, you must start with [the installation
|
||||
guide](../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx).
|
||||
guide](../../../configuration/terraform-provider/terraform-provider.mdx).
|
||||
Once you got a working provider, we recommend you to follow the
|
||||
["Managing users and roles with IaC"](../../../zero-trust-access/infrastructure-as-code/managing-resources/user-and-role.mdx) guide.
|
||||
["Managing users and roles with IaC"](../../../configuration/resource-guides/user-and-role.mdx) guide.
|
||||
</Admonition>
|
||||
|
||||
The provider exposes Teleport resources both as Terraform data-sources and Terraform resources.
|
||||
@@ -85,7 +85,7 @@ provider "teleport" {
|
||||
This section lists the different ways of passing credentials to the Terraform provider.
|
||||
You can find which method fits your use case in
|
||||
the [Teleport Terraform provider setup
|
||||
page](../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx)
|
||||
page](../../../configuration/terraform-provider/terraform-provider.mdx)
|
||||
|
||||
### With an identity file
|
||||
|
||||
@@ -112,7 +112,7 @@ Detected security key tap
|
||||
```
|
||||
|
||||
You can find more information in
|
||||
the ["Run the Terraform provider locally" guide](../../../zero-trust-access/infrastructure-as-code/terraform-provider/local.mdx)
|
||||
the ["Run the Terraform provider locally" guide](../../../configuration/terraform-provider/local.mdx)
|
||||
|
||||
#### Obtaining an identity file via `tbot`
|
||||
|
||||
@@ -121,7 +121,7 @@ short-lived credentials. Such credentials are harder to exfiltrate, and you can
|
||||
which roles (e.g. you can allow only GitHub Actions pipelines targeting the `prod` environment to get certificates).
|
||||
|
||||
You can follow [the Terraform Provider
|
||||
guide](../../../zero-trust-access/infrastructure-as-code/terraform-provider/terraform-provider.mdx) to setup `tbot`
|
||||
guide](../../../configuration/terraform-provider/terraform-provider.mdx) to setup `tbot`
|
||||
and have Terraform use its identity.
|
||||
|
||||
#### Obtaining an identity file via `tctl auth sign`
|
||||
@@ -149,7 +149,7 @@ You can use any [delegated join method](../../deployment/join-methods.mdx#delega
|
||||
both `join_method` and `join_token` in the provider configuration.
|
||||
|
||||
This setup is described in more details in
|
||||
the ["Run the Teleport Terraform provider in CI or Cloud" guide](../../../zero-trust-access/infrastructure-as-code/terraform-provider/ci-or-cloud.mdx).
|
||||
the ["Run the Teleport Terraform provider in CI or Cloud" guide](../../../configuration/terraform-provider/ci-or-cloud.mdx).
|
||||
|
||||
### With key, certificate, and CA certificate
|
||||
|
||||
|
||||
@@ -7,7 +7,7 @@ introduction: |-
|
||||
such as creating new user roles or connecting to trusted clusters.
|
||||
|
||||
For a conceptual overview of `tctl`, see [Getting Started with
|
||||
`tctl`](../../zero-trust-access/infrastructure-as-code/using-tctl.mdx).
|
||||
`tctl`](../../configuration/using-tctl.mdx).
|
||||
|
||||
flag_default_overrides:
|
||||
- full_command: tctl recordings download
|
||||
|
||||
Reference in New Issue
Block a user