------------------------------------------------------------------- Thu Jun 22 05:14:09 UTC 2023 - kastl@b1-systems.de - Update to version 13.1.2: * Release 13.1.2 (#28124) * [v13] update message on empty tsh ls results (#28120) * Add skip-confirm flag for headless approval. (#27823) (#27864) * bump e (#28101) * Fix invalid command example. (#28018) * AWS OIDC Integration: Deploy DB Service in a single click (#27035) (#28051) * fix: Ignore staticcheck false positive on darwin (#28042) * Update ssh-approval-slack.mdx (#28081) * Add reviewer and requester roles. (#28076) * [v13] Okta service docs only show in enterprise and cloud. (#28069) * [v13] Docs: Update Okta SSO Guide (#27950) * docs: mention required scope for GitHub app (#27910) * Provide client login IP when SSO initiated in a browser. (#27896) * [v13] Update e ref. (#28060) * Add mapping between user groups and applications. (#27962) * [v13] Add a delete confirmation step to SyncInventory (#27961) * Add HasPluginType to plugins interface. (#28052) * update eref (#28044) * [v13] Fix `Assist` import so it does not break storybook (#28047) * [v13] Connect: Fix overlapping placeholder and keyboard shortcut in the search bar (#28048) * Reorder resource filters in the search bar (#28034) * [v13] Update Electron to 25.1 and TypeScript to 5.1 (#28027) * [v13] Fix `tsh` relogin on not found errors (#27974) * add saml wizard to ui (#27949) * [v13] Update e ref. (#28036) * docs: include tsh install in connect your client tsh page (#27971) * [v13] Gracefully handle errors in Assist frontend (#27669) (#27935) * OpenSearch AWS autodiscovery (#27537) (#27942) * [v13] helm: Use local auth server address in auth pod to prevent extra connections (#27980) * [v13] Vendors the `pagerduty` plugin source into `teleport` (#27612) * [v13] helm: add hostAliases support (#27880) * [v13] docs: update cloud downloads (#27963) * Make Teleport config instructions easier to follow (#27968) * Add a diagram to the Linux Server guide (#27808) * Temporarily ignore Device Trust deprecation warnings (#27969) * Ensure SSH_SESSION_WEBPROXY_ADDR is set for all sessions (#27865) * Add more accurate info to cloud download page re: `tbot` (#27946) * [v13] Device Trust: `tsh` privilege elevation for TPM enrollment (#27959) * [v13] Fixes the "Run as different user" window freezing (#27874) * design updates for team gated features (#27756) (#27897) * [v13] Make use of keepAliveInterval in terminal handler (#27914) * [v13] CHANGELOG spelling fixes (#27955) * [v13] Add Machine ID tip when `tctl auth sign` is used (#27928) * chore: Bump golangci-lint to v1.53.3 (#27898) (#27911) * [v13] MongoDB Atlas IAM authentication docs (#27493) * Added 06/15 Upcoming Releases Update (#27901) * docs: update version (#27917) * [v13] Docs: Update ADFS SSO guide (#27891) * [v13] Pass context through `UpsertAuthServer` (#27887) * [v13] [Assist] New UI & rewrite (#27791) * [v13] docs: document label expressions (#27878) * [v13] Update e ref. (#27883) * [v13] Add the notion of friendly names to access request details. (#27803) * [v13] docs: Fix more installation commands on Windows (#27877) * [v13] chore: Bump Buf and Go versions (#27860) * [v13] Omit empty fields from DeviceCredential resources (#27869) * Fix `TestDiagnoseSSHConnection` flakiness (#27762) (#27849) * [v13] fix: Observe accurate `backend_read_seconds` duration (#27857) * [v13] Update Locking docs to refer `server-id` (#27845) ------------------------------------------------------------------- Wed Jun 14 18:37:49 UTC 2023 - kastl@b1-systems.de - Update to version 13.1.1: * [v13] Fix an issue ALPN handshake test does not respect "HTTPS_PROXY" (#27810) * Set default limit for ListResourcesRequest (#27839) * [v13] Trim yum release version in install-linux.mdx (#27777) * Move Cloud Matchers to proto (#27162) (#27530) * [v13] bump e (#27818) * [v13] Add Proto types for storing TPM Platform Attestation in Collected Data (#27757) * bump e (#27806) * [v13] Delete proxy heartbeats on graceful shutdown (#27786) * [v13] Fix an issue kube local proxy requirement is wrong in separate port mode (#27732) * Fix: time.Since should not be used directly after a defer statement (#27795) * Default to SymlinksTrySecure rather than SymlinksSecure (#27784) * [v13] bump e-ref (#27736) * app access: fix broken docs link in error message (#27766) * Don't use WithError() when logging "Missing session cookie" (#27768) * [v13] Docs: document labels for trusted clusters (#27738) * [v13] Fix flaky test `TestHeadlessAuthenticationWatcher_WaitForUpdate` (#27765) * [v13] MongoDB Protocol Hardening (#27741) * docs: Fix curl commands on Windows (#27759) * remove confusing variable delineation (#27746) * [v13] docs: update desktop session recording reference (#27749) * [v13] Change Campaign to utm_campaign (#27706) * Implement in-memory vector DB (#27587) * Add UI `node` lock to use `server_id` instead (#27621) * Fix Teleport Connect assume roles (#27723) * [v13] Abort reverse tunnel connections early if the proxy is already claimed (#27699) * Add scaling warning re: DynamoDB (#27600) * [v13] helm: Add conditional RBAC/ServiceAccount to `teleport-kube-agent` post-delete hook (#27637) * [v13] docs: update navigation instructions for sso audit log troubleshooting (#27675) * add styles to tooltip for team pages (#27417) (#27642) * Set UID/GID for ARC runner builds (#27638) (#27689) * Fix TestAuthorizeWithLocksForLocalUser flakiness (#27687) * usagereporter: add context check in RunSubmitter (#27678) * [v13] feat: label expressions (#27641) * Bump vite from 4.2.0 to 4.2.3 (#27670) * Fix redirects (#27593) * add new CTA event property (#27216) (#27643) * [v13] export etcd event processing metrics (#27220) * Added 06/08 Upcoming Releases Update (#27631) * [v13] Update description of Roles UI (#27539) * Update e (#27640) * [v13] Bump cloud version to v13.1.0 (#27633) * [Docs] Assist built-in role access (#27602) * [Docs] Assist - remove MFA section (#27603) * [v13] Web: Plugin tweaks and new plugin icons #27427 (#27576) * [v13] feat: label expression protobuf types (#26977) * fix: record applied login rules in github login event (#27607) * [v13] Add deprecation note to PAM user creation guide (#27626) * [v13] update agentless docs to use 'teleport join openssh' (#27624) * [v13] Update docker images (#27502) * [v13] docs: provide information on local user locks from login attempts (#27609) * Update `github.com/gravitational/predicate` to `v1.3.1` (#27483) * [v13] Docs: Trusted Clusters - Mention the correct expiration time as per tctl command (Buddy PR) (#27498) * [v13] use proxy port in openssh config (#27545) * [v13] Proxy Templates overwrite CLI cluster value (#27581) * docs: add headless auth as faq question (#27584) * docs: adds configuration and helm chart to app access getting started (#27529) * [v13] Fix not being able to "login" with auth type set to sso but no connectors set yet (#27589) * Primarily changes "match: '^.*\.dev\.example\.com$'" to "match: '^.*\.dev\.example\.com'" so that users aren't mistakenly guided towards eliminating the implicit ":3389" from their regex matches (#27516) * Fix the default `teleport-kube-agent` upgrade server (#27572) * Only fallback to SSH_TELEPORT_ env variables for proxy, user, and cluster name when used with headless. (#27507) * Support authenticating with AWS IAM role for MongoDB Atlas (#26439) (#27494) * Bump e (#27501) * [v13] Implement leaf app access: `tsh app login --cluster=leaf` (#27197) * [v13] Backport hardened AMI resources (#27454) * [v13] include changelog for docs tests (#27479) * [v13] Docs: GCP join method (#27487) * Fix SEO issues (#27242) * [v13] Document all installer script template vars (#27482) * Create api handler specifically for FormData (#27408) * [v13] Docs: improve Postgres in GCP (#27471) * Propagate proxy public addr in Web UI ssh session. (#27058) (#27420) * [v13] Document new Okta import rule regexes. (#27453) * [v13] docs: add enterprise value for kube agent reference (#27472) * docs: update version (#27473) * Extend host lock enforcement to other built in roles besides `Node` (#27018) (#27442) * Build change for when go caching should be used (#27209) (#27284) * chore: Bump golangci-lint to v1.53.2 (#27456) * [v13] WebDiscover: Check for RDS length before setting a limit for listing DBs (#27415) * Jamf config for PluginSpecV1 (#26374) (#27459) * [v13] loadtesting automation improvements (#27438) * Add prometheus endpoint to tbot (#27432) * [v13] Add docs for database auto user provisioning (#27289) ------------------------------------------------------------------- Mon Jun 12 20:37:19 UTC 2023 - kastl@b1-systems.de - Update to version 13.1.0: * Release 13.1.0 (#27418) * [v13] [Assist] Do not parse event data is there is none (#27435) * [v13] Update e (#27430) * [v13] Add Assist to the access role (#27424) * [v13] Adds info on exporting requirements for impersonated certs (#27403) * chore: Bump Buf to v1.20.0 (#27400) * [v13] Add IAM auth info to ElastiCache guide (#27306) * Move and update Proxy Template docs. (#27350) * specify supported architectures (#27279) * [v13] docs: Formatting/grammar fixes for TLS routing (#27391) * [v13] Update e ref. (#27388) * tncon: Remove unused return variables (#27386) * Add plugin static credentials getter. (#27301) * Minor updates to Server Access Getting Started (#27253) * [v13] WebPublicAddr includes user specified port. (#27376) * [v13] Web: Emit integration events (aws oidc) and touch ups (#27172) * [v13] cache parsed role template expressions (#27326) * add circle icon helper (#27185) (#27286) * [v13] Update e ref (#27375) * Reply with a user-friendly message on verification errors (#27270) * [v13] Assist docs (#27260) * [v13] docs: update enrollment steps for active dir (#27357) * Add endpoints to export AuditEvents as unstructured data (#27290) * [v13] Docs: Update GitHub SSO (#27273) * Add kube credentials lockfile to prevent possibility of excessive login attempts (#27366) * [v13] Use the proper check for the SAML IdP session. (#27314) * Get fresh cluster features to `config.js` (#26785) (#27362) * [v13] Assist bug fixes (#27356) * [v13] Get locks in tctl get all (#27294) * [v13] flaky test detector: override skipped tests (#27274) * Only wait for headless authentication watcher initialization in tests. (#27298) * [v13] Assist backport (#27243) * Replace global testing variables for device trust with pluggable ceremony interface. (#27239) * [v13] Web: Fix local storage clearing (#27296) * Disable GHA cache (#27305) (#27315) * [v13] Pin golangci-lint to `v1.53.1` and upgrade `depguard` config to `v2` (#27293) * Speedup OpenSSL build (#27056) (#27261) * tctl: allow creating desktops from YAML file (#27250) * Fix TeleportClient.ConnectToProxy logic error with closed context. (#27140) * Dont load ForwardedPorts from profile, only recieve them from the cli (#27208) * backport device trust and okta provider docs (#27218) * Ignore ENOENT error on group check (#27231) * Add support for automatic database users for Postgres (#26555) * [v13] lib/kube/proxy/server.go: Fix potential mutex deadlock on error (#27237) * docs: mention locking as an alternative to CA rotation for revoking access (#27248) * docs: add troubleshooting step for standard RDP security (#27245) * [v13] Fix headless server access requests (#27241) * tncon.c: Switch all size variables to size_t (#27234) * update access controls table (#27226) * Add static credentials reference to plugin credentials. (#27225) * [v13] docs: update fluentd output and correct docs link (#27202) * Add elasticache:Connect AWS permission to auto-IAM (#27188) * Updated Cloud SQL guides with more info about 'Allow only SSL connections' option (#27224) * docs: update version (#27219) * Add information about the cert-format flag (#27167) * Update cloud version to 12.4.5 (#27214) * return an error if a moderated session is created for an agentless node (#25721) * [v13] Add docs for shell completion (#27093) * add section for username_claim (#27006) * [v13] helm: Switch custom deployment guide to standalone rather than scratch (#27177) ------------------------------------------------------------------- Thu Jun 01 11:46:13 UTC 2023 - kastl@b1-systems.de - Update to version 13.0.4: * Introduce the Plugin Static Credentials object. (#27121) (#27163) * Added 05/25 Upcoming Releases Update (#26910) * [v13] Update Terraform reference docs to 13.0.3 (#27034) * Correct grammar in role removal error message (#27142) * [v13] feat: label expression parser (#26970) * [v13] docs: correction and note on direct mode for desktop (#27149) * TLS Routing behind ALB: tsh kube subcommands UX (#26305) (#27155) * [v13] helm: Tidy standalone cluster setup docs (#27154) * [v13] `buf breaking` CI action (#26833) * Fetch ClusterAlerts a single time during login (#27110) * [v13] docs: remove duplicative k8s access guide (#27128) * [v13] Update title for proxy peering architecture (#27041) * Refactor test globals out of lib/devicetrust/enroll (#27133) * Switch to recommending identity file in terraform guide (#27068) * [v13] Add `tsh kubectl` support for tracer exporter (#27130) * [v13] docs: Update GSLB docs for changes missed from master (#27132) * chore: Bump OpenSSL to 3.0.9 (#27123) * changes ldapDialTimeout from 5 to 15 seconds (#27045) * Okta Import Rules use Teleport style regexes. (#27126) * Fix `TestKube/Join` data race (#26619) (#27124) * [v13] Refresh port descriptions (#26936) * [v13] Support ElastiCache Redis IAM auth (#26990) * Fix "unnecessary conversion" in lib/devicetrust/native (#27077) * [v13] Automatically perform `tsh app login`. (#26820) * docs: offer alternative aws methods for joining for aws db guides (#26939) * docs: update kube access for enterprise setting and agent updates (#26941) * [v13] Windows TPM Device Authentication (#27085) * Close clients when done. (#27104) * [v13] Expand Go docs for label prefixes (#27102) * Update `e` (#27087) * [v13] Update `kingpin` & allow autocompletion (#26238) (#26999) * Device Trust: TPM Enrollment support EKCerts (#27070) (#27082) * Remove initCommand from DocumentPtySession (#27003) * Search user groups by description. (#27021) * [v13] update lib/utils/parse to leverage lib/utils/typical (#26967) * use uri path for config dump (#26992) * [v13] feat: library for building predicate parsers (#26915) * [v13] Update kube operator with more details and troubleshooting (#27050) * Update CHANGELOG.md to include Helm image change (#26822) (#27000) * operator: allow operator to edit tokens (#27001) * Docs: replace static mermaid images with rendered charts (#23458) (#26094) * Clean up LDAP error handling (#26984) * docs: mention missing delete permission for GCS buckets (#26735) * Yarn updates for `terser` and `minimatch` (#26919) (#27025) * Make tctl command descriptions consistent (#26937) * Use root client for headless authentication. (#26878) * [v13] remove warning on unpopulated ssh proxy address (#27015) * [v13] update ui and config to refer to service as Teleport Service (#27011) * [v13] AWS Route 53 GSLB Multi-Region Proxy Peering High Availability Deployment Guide (#26743) * Add a guide to reviewing docs PRs (#26913) * Use WIRE_JSON in buf breaking (#26793) * docs: update version (#26988) * fix console node list scroll and close session join dialog (#26622) (#26906) * [v13] athena audit logs - use otel traces in querier (#26900) * [v13] Remove useProfileLogin from makeClient in tsh (#26975) * [v13] athena audit logs - add metrics (#26920) * [v13] helm: Fail to install if `clusterName` contains a colon (#26973) * Add a watcher for agentless EC2 nodes (#26888) * [v13] Add MDM and TPM fields to device resources (#26838) * Add integration enroll usage event (#26880) (#26930) * Fix bug where the system agent is not forwarded in combination with (#26929) * Add diagrams to Access Request plugin guides (#26924) * Update dependencies for `build.assets/tooling` (#26907) (#26918) * fix GitHub connector API endpoint URL path getting ignored when making HTTP requests (#26863) * [v13] Collect MDM data from macOS (#26897) * [v13] integrations/operator: Use a dedicated scheme in tests (#26883) * Backport #26366 to branch/v13 (#26738) * [v13] Web: Add back buttons and remove exit buttons (discover & integrations) (#26727) * [v13] skip rdpclient build in integration tests (#26526) * [v13] Spawn gateway CLI client directly (#26751) * bump cloud to 12.4.3 (#26899) * correct discovery bootstrap command description (#26894) * [v13] Add a codegen-focused buildbox (#26739) * [v13] Proxy Templates update: cluster switching and tsh ssh parity (#26852) * app access: improve error logging (#26869) * [v13] docs: include Enterprise in tctl version for ent, cloud prereq (#26847) * Bump github.com/docker/distribution (#26107) (#26855) ------------------------------------------------------------------- Thu May 25 06:35:23 UTC 2023 - kastl@b1-systems.de - Update to version 13.0.3: * Release 13.0.3 (#26846) * add rbac for cluster alerts (#26423) (#26789) * docs: correct faq answer on editions (#26842) * [v13] use stable/cloud repo for cloud tenants (#26841) * [v13] Add a few convenience toggles to genproto.sh (#26672) * include db in tsh play and consistent description ends (#26816) * add polyfill for randomuuid (#26611) * athena audit logs - always pass utc to query (#26821) * [v13] docs: update to machine-id file list and edits (#26800) * Remove 'preview' from tcp app access guides (#26813) * [v13] [docs] add image for moderated file transfer (#26808) * Introduce group and app name Okta import rule regexes. (#26799) * fix TestALPNProxyHTTPProxyBasicAuthDial flakiness (#26713) * docs: add missing server_name to LDAP config (#26692) * athena audit logs - sent checksum on s3 write (#26748) * Amazon RDS converter: extract Subnets (#26621) (#26675) * [v13] Don't unmount `cgroup2` when restarting (#26728) * docs: update agent updates (#26731) * Windows TPM enrollment support (#25801) (#26736) * Fix link to CA Pinning information (#26690) * [v13] Add mermaid diagram to the HA guide (#26697) * docs: remove old starting from message (#26717) * Describe `tsh ls` support for multiple labels (#26539) * add upgrader to inventory hello (#26454) (#26479) * Define the "jamf_service" configuration (#26478) (#26700) * [v13] operator: ProvisionToken support (#26618) * Fix port forwarding when using a label based target (#26701) * [v13] Refresh Kubernetes Access Getting Started diagram (#26536) * [v13] Edit the docs UI reference (#26533) * [v13] refactor tsh db (#26651) * Remove intel label from macOS (#26698) * [v13] Make the Linux Server guide less SSH-centric (#26631) * [v13] Adds an admonition about Teleport not currently supporting Azure AD (#26556) * [v13] Docs: Patch Register Cluster page (#26686) * [V13] Add certificate rotation to `teleport join openssh` oneshot command (#26674) * [v13] docs: Add Msft SQL Server client examples and link in sql server guide (#26558) * docs: update reference to Teleport systemd (#26680) * chore: Bump Buf to v1.19.0 (#26645) * [v13] athena audit logs - pass teleport user as top level field (#26661) * Extend `kubectl auth can-i` support for `kubernetes_resources` RBAC rules (#26584) * Update e ref (#26664) * [v13] auditlog - pass context and rework search params (#26587) * expose firehose emulator host env in tests (#26592) * [v13] Update SyncInventory RPC documentation (#26629) * [v13] Add Teleport Team docs (#26639) * [v13] Docs: mark Okta application access as preview (#26627) * suggest machine id in plugins partial (#26624) * [v13] docs: remove starting from messages older then 10.0 (#26553) * [v13] changes openssh addr validation to allow hosts (#26549) * [docs] Amazon Athena guide for Application Access (#25329) (#26505) * [v13] Desktop access improvements (#26413) * Add RoleInstance to TestLocalServiceRolesHavePermissionsForUploaderService (#26597) * Update backends.mdx to remove incorrect comment (#26600) * Bump golangci-lint to v1.52.2 (#26593) * Add in Okta plugin type. (#26458) * [v13] Do not run the uploader with the MDM role (#26514) * Show dev-related tools only in dev mode (#26495) * update db and app service role permissions (#26519) * [v13] WebDiscover: Revert deleting the app wizard (#26457) * bump-e-ref (#26545) * add AWS cross-account db access guide (#26468) * docs: update version (#26509) * Update `gravitational/protobuf` fork tag (#26373) (#26488) * Add the JamfSpecV1 proto (#26391) (#26448) * [v13] Add in extra Okta audit event fields. (#26370) * Install Script: add Darwin ARM64 support (#26504) * Update AMI usage instructions (#26453) * [v13] Docs: Adjust curl examples (#26472) * athena audit logs - integration tests (#26494) * [v13] add assume_role_arn and external_id docs reference (#26030) * bypass lint and os-compatibility for md and mdx files (#26480) * [v13] Add and map the MDM system role (#26471) * Install Node Script: respect version variable (#26322) * [v13] add list of applied login rules to user login event (#26474) * bump eref (#26465) * bump docs for cloud to 12.4.2 (#26466) ------------------------------------------------------------------- Thu May 18 07:51:39 UTC 2023 - kastl@b1-systems.de - Update to version 13.0.2: * Release 13.0.2 (#26469) * [v13] docs: include DynamoDB streams as required in storage backend (#26381) * changelog spellfixes (#26431) * [v13] Web: Provide accurate actionable steps with duplicate db name error (#26399) * fix tsh db connect to active cassandra db (#26378) * [v13] Add in plugin bearer token credentials. (#26436) * [v13] docs: fix curl usage (#26411) * athena audit logs - run on single auth (#26443) * [v13] athena audit logs - delete from sqs (#26424) * athena audit logs - parquet writer (#26240) ------------------------------------------------------------------- Wed May 17 04:58:46 UTC 2023 - kastl@b1-systems.de - Update to version 13.0.1: * Release 13.0.1 (#26418) * bump eref (#26406) * [v13] Change TestDeleteMFADeviceSync to do per-delete assertions (#26390) * Update version in tsh.app Info.plist (#26314) * Remove the Adopters page (#26362) * remove opened var when set to false (#26367) * Update e ref (#26389) * check for empty name part in role arn (#26376) * Refresh the teleport-cluster Helm guide (#26172) * update video banner (#26384) * [v13] Web: Integrations touchups (#26152) * Add params to CTA redirect URL (#26086) (#26340) * [v13] fix azure db user auth check (#26317) * [v13] Proto and Go module changes for Windows TPM support (#26325) (#26348) * Update config.json (#26258) * bump e-ref (#26355) * [v13] docs: add mongo port in high availability and k8s operator doc (#26357) * [v13] docs: enroll auto updates fixes (#26352) * Remove our replacement for Logrus (#26241) (#26304) * [v13] Update `electron` and `electron-builder` (#26327) * [v13] Replace GetConnectCommandNoAbsPath with os.exec.Cmd.Args (#26328) * [v13] Disable "Open new terminal" if there's no active workspace (#26333) * athena audit logs - query rate limiter (#26221) * Fix twoClustersTunnel flakiness (#26254) * [v13] TLS Routing behind ALB: `tsh kube join` (#26283) * Update e ref (#26306) * Decrease test timeout (#26267) * Allow aws svg icon to take on the themes main color (#26039) * Revert usage of grpc error interceptors in `lib/client` (#26271) * [v13] docs: Make Amazon Linux name usage consistent (#26192) * Make PAM user creation script copy/pasteable (#26275) * [v13] docs: expand admonition for additional DB types (#26260) * [v13] docs: add tip on Kubernetes resources (#26278) * [v13] - Backport docker distribution update #26108 and #26109 (#26249) * [docs] Include File Transfers in moderated sessions docs (#26032) (#26265) * Restore Kubernetes Integration tests (#26186) * [v13] Populate the time locked status value when local user locked (#26255) * [v13] Add GCP Join Method (#26165) * athena audit logs - support athena engine v2 (#26222) * [v13] docs: reword dynamic guides language to more active (#26227) * athena audit logs - sqs receive (#26220) * Get rid of update on unmounted component in ResultList (#26230) * [v13] Remove privileged APIs from window after app initialization (#26213) * [v13] only show windows domain in audit log ui if applicable (#26078) * athena audit logs - query (#24740) * [v13] Add pprof diagnostics endpoints to `tbot` (#26117) * docs: Fix link to standalone Windows auth service (#26179) * Fix Helm chart Join token secret creation (#26055) (#26175) * [v13] Fix panic when using proxy peering (#26174) * [v13] Clarify Auth Service backend permissions (#26076) * Update e ref (#26163) * docs: fix invalid characters in kubernetes service example in discovery troubleshooting (#26157) * Modify error messages for customer portal to Teleport account (#26139) * TLS Routing behind ALB: access request Kube Pod search (#26128) * Set Cloud version to 12.3.3 (#26036) * [v13] Search bar: Take cluster filter into account when listing offline clusters (#26127) * Backport Assist UI (#26145) * Move the favicon so Teleport serves the static file (#26144) * [v13] Fix GoRoutine leak in `authclient.Connect` (#26125) * [v13] docs: update plugin and docker version (#26113) * [v13] provides info on Oracle Wallet location when using Oracle Orapki generation (#26133) * [v13] Fixes a SharedDirectoryAnnounce incompatibility (#26090) * Return a better message on "lacks registered credentials" errors (#26103) * docs: add note about curl on Windows (#26088) * [v13] Moderation Session docs update (#26082) * [v13] Use os.UserHomeDir where possible (#25999) * bump e-ref (#26101) * [v13] [docs] TLS routing behind l7 load balancer preview (#26077) * [v13] usagereporter: split the `ssh_port` session start into `ssh_port_v2`, `k8s_port` (#26062) * push the feature check to ctx.init (#26007) (#26071) * Use the correct value for DeviceAuthenticateEvent (#26068) * [v13] Show resource search errors in search bar when fetching a preview (#26073) * create e-imports package (#25992) (#26044) * [v13] docs: clarify host labeling for Windows desktops (#25524) * Clean up staticConfig mocks (#26059) * [v13] Document how to open a local terminal in Teleport Connect (#26061) * docs: AWS OpenSearch (#26051) * Improve AWS OIDC Integration extensibility (#26050) * [v13] tctl: improve alert ack flows (#26040) * docs: Update MySQL Server Version (#26052) * [v13] Add in Okta audit events. (#26000) * Add docker cli to buildbox (#25975) * gh-trigger-workflow: Retry transient server errors (#25972) * [v13] Change Helm reference `--set` formatting (#25509) * [v13] Okta assignment targets/statuses are human readable in the CLI. (#26023) * [v13] fix: truncate YubiHSM2 key IDs (#25816) * [v13] Note that the SAML IdP now supports HSM. (#26005) * [v13] fix: use errors.Is for all EOF comparisons (#26017) * Install Scripts: add updater package (#25971) * Provide client address information in transport request (#25993) * Add events to cta clicks (#25325) (#25986) * [v13] TLS Routing behind ALB Connect support for SSH and Database access. (#25899) * [v13] Allow adding 'locked' features to menu items and routes (#25952) * [v13] Upgrade TypeScript to 5.0.4 (#25983) * [v13] Introduce inventory service counts. (#25944) * Remove test case which uses local profile. (#25969) * [v13] add redirect to windows user creation instructions to host user creation doc (#25965) * build: Scope RUST_VERSION var to single target (#25962) * [v13] warn about v13 repos not containing v14 Teleport (#25954) * [v13] don't delete unit schedule file (#25943) * Bump Buf to 1.18.0 (#25888) * Update the supported versions table (#25902) * helm: warn about teleportVersionOverride and scratch risks (#25601) (#25914) * [v13] docs: instruct users to use `apt`/`yum`/`dnf` instead of `dpkg`/`rpm` (#25937) * [v13] backport team plan CSP and RBAC (#25928) * [v13] Okta documentation. (#25940) * [v13] Team plan CTAs (#25073) (#25701) * Add t_source to be standard (#25720) * [v13] Add the debug command `tsh fido2 attobj` (#25923) * Makefile: cache `go env` values (#25894) * docs: document the updater (#24628) (#25913) * [v13] check for correct kube and ssh listen address in starting message (#25907) * provide starting message for tar ball install (#25904) * Add IsUsageBased to features and send it to web UI (#25465) (#25860) * [v13] Remove code related to the command bar from Connect (#25898) * Simplify the Getting Started experience (#25519) * [v13] Make TS a dev dep of root package.json, fix design dev deps (#25875) * [v13] Fix flaky resolveNetworkAddress test (#25874) * [v13] enable acl in single aws terraform s3 (#25854) * Add ability to enable trace logging level (#25833) * Remove `not a valid Unix login` logging (#25838) * Fix application resource headers rewrite spec (#25863) * Add ability to enable trace logging level (#25833) * Remove `not a valid Unix login` logging (#25838) * Fix application resource headers rewrite spec (#25863) * Update docs version vars for v13 (#25352) ------------------------------------------------------------------- Thu May 11 12:52:08 UTC 2023 - kastl@b1-systems.de - Update to version 13.0.0: changelog to big, please find it here: https://github.com/gravitational/teleport/releases/tag/v13.0.0 - BuildRequire go1.20 (github.com/gravitational/teleport/lib/events/athena ------------------------------------------------------------------- Tue May 09 05:23:00 UTC 2023 - kastl@b1-systems.de - Update to version 12.3.3: * Release 12.3.3 (#25835)) * Fix access to leaf resources (#25694) (#25862) * fix auditlog error (#25843) * [v12] Include teleport-windows-auth in OSS releases (#25846) * make some chatty dynamodb logs trace (#25821) * Update e ref (#25831) * Correct SAML IdP session read permission. (#25798) * Fix Web UI error message when host is offline (#25661) * [v12] Update e ref. (#25812) * [v12] Add `SetFeatures` method to modules (#25653) * add agent config scaling section (#25796) * Update change log to include desktop access fix in 12.3.2 (#25793) * [v12] docs: document "and" logic for labels (#25750) * [v12] Log troubleshooting information when InvalidInstanceID errors are found during EC2 discovery (#25641) * [v12] docs: provide instructions on getting enterprise file from new license Teleport Account (#25753) * [v12] WebDiscover: Enroll RDS Databases and Hookup RDS flow (#25604) * Try to fix TestAgentPoolConnectionCount (#24616) (#25695) * Support additional expected instance roles. (#25742) * [v12] Use the GHA base container for Lint (Docs) (#25716) * update eref (#25733) * [v12] Add client compatibility to installation guide (#25685) * [v12] Improve API client connection failure feedback (#25563) * [v12] Refresh the HA guide (#25670) * [v12] docs: fix claims to roles description in access controls reference (#25633) * Ensure useDocumentGateway creates the gateway only on mount (#25626) * [v12] docs: update cloud proxy service architecture language (#25724) * [v12] docs: move docs links from absolute to relative (#25736) * [v12] use "google.golang.org/protobuf" to clone protobuf messages (#25714) * refactor theme in v12 (#25650) * Add UserGroups to RequestableResourceKinds. (#25708) * Don't report usage for KubeServiceV2 keepalives (#25656) * docs: mention Machine ID where tctl auth sign is used (#25610) * [v12] Update e-ref and icomoon library (#25665) * backport missing deps (#25662) * Update role-templates.mdx (#25628) * Reuse auth connection for Okta client (#25622) (#25646) * [v12] WebDiscover: Enroll aws integrations (#25594) ------------------------------------------------------------------- Fri May 05 05:09:38 UTC 2023 - kastl@b1-systems.de - Update to version 12.3.2: * Release 12.3.2 (#25647) * Update e-ref (#25636) * docs: correct gcp install headers (#25426) * Define a new DeviceEvent proto with the usual embeds (#25353) (#25555) * Use new device event layout in Web UI (#25355) (#25558) * [v12] Add specific message for network errors on app launch (Web UI) (#25606) * [v12] Add missing user groups entry to getEmptyResource state. (#25612) * Do not change proto user on make grpc (#24847) * Update metrics docs (#25591) * Make ProtoPostgres support PROXY protocol (#25529) * [v12] Support UI methods for user groups, label match user groups in API. (#25578) * [v12] docs: update version (#25577) * [v12] docs: update CloudHSM docs (#25570) * Web:Discover Refactor resource selector screen (#23018) (#25556) * [v12] Team plan CTAs (#25073) (#25572) * [v12] Add integrations access rule to user context (#25516) * Disallow OktaAssignment deletion from tctl. (#25463) * [v12] New Usage Events (#25493) * add billing to navigation (#25192) (#25487) * [v12] banner dependencies (#25194) * [v12] Document HA for Access Request plugins (#25551) * Capitalize Teleport in command/args (#25545) * Remove Origin from cloud converters (#24977) (#25459) * Updates distroless Dockerfile to handle fips realeases (#25451) ------------------------------------------------------------------- Wed May 03 04:48:12 UTC 2023 - kastl@b1-systems.de - Update to version 12.3.1: * Release 12.3.1 (amended) (#25517) * [v12] darwin: Use notarytool to notarize instead of altool (#25455) * [v12] chore: Bump Go to 1.20.4 (#25506) * Release 12.3.1 (#25502) * Allow unknown fields when unmarshaling types.MFADevice (#25445) * Fix backwards compatability of GenerateUserSingleUseCerts (#25486) * [v12] Update e ref. (#25474) * Return friendly errors when sessions are prevented due to a lock (#25482) * docs: automatic user creation for windows desktops (#25364) * Add missing Connection header for ALPN connection upgrade (#25346) (#25411) * [v12] WebAPI: thumbprint endpoint (#25338) ------------------------------------------------------------------- Tue May 02 05:32:47 UTC 2023 - kastl@b1-systems.de - Update to version 12.3.0: * Release 12.3.0 (#25443) * [v12] Bump e-ref (#25440) * [v12] docs: update YubiHSM2 docs (#25359) * Fix issuing credentials for non SSH protocols (#25430) * docs: remove dynamic database resource in example aws dynamodb (#25340) * webapi cleanup (#24363) (#25368) * [v12] docs: update docker guide to allow for server access and show troubleshooting (#25345) * [v12] Windows user creation (#24780) (#25348) * [branch/v12] Add building Windows Authentication Package to Drone (#23811) (#25311) * terraform: enable ACLs in the certs bucket (#25335) * Define distinct types for all device events (#25320) * docs: update onelogin screenshot (#25331) ------------------------------------------------------------------- Sun Apr 30 07:15:36 UTC 2023 - kastl@b1-systems.de - Update to version 12.2.5: * Release 12.2.5 (#25326) * Integrations: AWS OIDC - ListDatabases action (#24877) * Record and verify WebAuthn RPIDs (#25238) (#25289) * [v12] Fuzz TDP protocol, fix two issues. (#25308) * Add option to override kube context on `tsh kube login` (#25253) * Fix `TestAuthSignKubeconfig` test (#25269) * Update Electron to 22.3.6 (#25184) * Fix cluster alerts timeout (#25300) * Properly handle SAML IdP enable/disable. (#25309) * Addresses #23554 (#25296) * Do not try to verify PROXY signature for non-Teleport TLVs (#25302) * Bump gh-trigger-workflow timeout to 2h30m (#25174) * [v12] Clean up Drone slack notifcations (#25217) * Use the correct emitter in auth.TLSServer (#25272) * Fix `underlying reader not a terminal` issues (#25102) (#25242) * [v12] docs: Login Rule k8s operator docs (#25158) * [v12] Show <1m for remaining tsh status valid time for last minute (#25225) * Move db cert renewal message to debug log (#25222) * docs: add information on viewing status and logs for systemd service (#25199) * * Save ssh_service.public_addr values to Server.PublicAddrs instead of discarding them (#25223) * Add new field to license spec (#23194) (#25197) * fix: avoid inadvertent deletion of active HSM keys (#25208) * [v12] Update headless tsh command descriptions (#25148) * [v12] Update e ref. (#25205) * Connect: Fix logout sequence (#24978) (#25182) * Avoid prompting users for mfa when using `tsh ssh --headless` (#24701) (#25187) * [v12] Simplify Okta assignment statuses. (#25189) * Improve performance of MFA ceremony (#24804) * Headless Login explicit username (#24689) (#25112) * Alphabetize the GUI Client page (#25120) * [v12] Document relative link paths in partials (#25117) * [v12] docs: append cluster name for example ansible hosts list (#25124) * [v12] Order sudoers file lines by role name (#24792) * [web] Add storeUser to console context (#24159) (#24809) * Add login hooks. (#24828) (#25105) * Join Script: fix tarball folder for ent builds (#25076) * fix github url formatting (#25089) (#25098) * Add key attestation to generate user certs to catch non-login flows. (#24867) (#24956) * add comment specifying kubernetes user (#24916) * docs: Add warning about TLS multiplexing to Kubernetes IAM joining (#24820) * OktaAssignment and UserGroup in auth cache. (#25067) * docs: fix spelling and remove misspelled word from spellcheck skip (#25030) * Add in group labels for role conditions. (#25080) * Log informative messages for device authn failures (#24912) * [v12] docs: Change `listen_addr` to `web_listen_addr` in custom Helm deployment guide (#24974) * docs: fix directory instruction for docs contributing (#24994) * docs: Adds common Teleport configure,start and helm charts for non-iam db access guides (#25001) * Pass the auth.Server itself to inventory.NewController (#25007) * [v12] local proxy not required for mysql separate port (#24827) * replace 'machine' with 'host' or 'workstation' (#24986) * clarify tctl command location and secret destination (#24982) * Make tsh check SSH_ user, proxy, and cluster env variables if not already set. (#24470) * [v12] docs: update version (#24957) * [v12] Proxy Client (#24734) * docs: make adopters table markdown for cleaner look (#24951) * Fix example API client imports (#24375) * docs: remove unneeded sudo for removing user data dirs (#24919) * [v12] Makes the `Per Role` per session mfa example accurate (#24927) * [v12] docs: remove duplicate content in oracle guide (#24907) * docs: bump cloud to 12.2.3 (#24769) (#24843) * [v12] docs: provide warning on Amazon Linux 2023 installations (#24853) * Update e ref (#24894) * Use apt.releases to fetch pub key (#24875) * [v12] Update crewjam/saml dependency. (#24898) * [v12] Edit Homebrew installation instructions (#24824) * Remove unnecessary sudo from Connect uninstall docs (#24888) * Update Cloud FAQ doc to remove latency note (#24891) * refactor how 'tsh scp' destinations are parsed (#24861) * [v12] docs: provider faq answer for configurable maintenance times for cloud (#24855) ------------------------------------------------------------------- Thu Apr 20 14:35:02 UTC 2023 - kastl@b1-systems.de - Update to version 12.2.4: * Release 12.2.4 (#24844) * [v12] docs: document error with older SSM agent version (#24833) * OS packaging and auto updates backport - v12 (#24781) * [v12] SFTP fixes (#24831) * [v12] Checks proxy server and token set for join openssh (#24745) * [v12] Fix `TestHeadlessAuthenticationWatcher` flakiness (#24705) * [v12] docs: make consistent access request plugins helm configuration and instructions (#24760) * Add docs subsection about joining services (#24756) * Update embedded video (#24699) * [web] Add isModeratedSession flag to web ssh session (#24238) (#24806) * [v12] Backport Mac build GitHub Actions support (#24432) * Backport --raw version flag (#24772) * Acquire user certs from root cluster during web file transfers (#24768) * Fix memory leak on Kubernetes port-forwarding (#24763) * [v12] Use CompareAndSwap for OktaAssignments instead of lock. (#24748) * Tweak protogen to not change protos from cloud (#24688) (#24739) * Tweak messaging to anticipate a new linter (#24411) * docs: Login Rules Terraform docs (#24674) * [v12] reduce cache retry load (#23025) (#24719) * Change port-forwarding completion logs to debug (#24658) * [v12] Make audit log details dialog larger. (#24722) * stop handling SIGINT, SIGTERM in tctl (#24681) * Add Okta assignment update statuses to Okta access point. (#24735) * [v12] docs: remove ignored user parameter in tsh login example (#24624) * [v12] Check Okta action transitions during update, allow failed -> pending. (#24685) * Prevent multiple discovery agents to race against each other (#24214) (#24716) * Document `discovery_group` parameter (#24713) * Add cleanup time and last transition time to OktaAssignment. (#24725) * Add in a Okta assignments copy method. (#24694) * refresh vscode guide (#24697) * helm: fix `teleport-kube-agent` telemetry (#24471) (#24680) * allow redundant security release alert suppression (#24692) * [v12] Tag output from teleport configure as ERROR or WARNING if applies (#24676) * [v12] Introduce an OktaAssignmentsGetter and use it in the watcher. (#24584) * Ensure that proxy services join by dialing auth (#24668) * docs: update audit results faq for cloud (#24633) * Pull kube proxy address from proxy ping endpoint (#24516) * docs version (#24622) * [v12] docs: kubernetes joining guide + reference (#24545) * [v12] docs: update k8s gke discovery to use zone variable consistently (#24613) * [v12] Hosted plugins frontend / user-facing parts (#24597) * Make the OpenSSH guide more prominent (#24568) * Edit the SSH Key Extensions guide prereqs (#24537) * Add top-level redirects to intro pages (#24565) * Add architectural clarity to the AD guide (#24569) * [v12] Renders user auth types in User List in expected capitalization (#24604) * [v12] docs: simplify tokens generation examples (#24497) * [v12] Update relcli to fix publishing of release notes (#24438) (#24529) * [v12] Fix authenticated conn metrics for http reporter (#24570) * only call 'user.Current' when we really need to (#24573) * update aws configurator (#24362) (#24494) ------------------------------------------------------------------- Fri Apr 14 06:52:08 UTC 2023 - kastl@b1-systems.de - Update to version 12.2.3: * Release 12.2.3 (#24546) * Machine ID: Add ability to request RouteToCluster in generated certs (#23838) (#24544) * Update e reference (#24550) * [v12] spelling fixes and ignore adds (#24539) * Added 03/13 Upcoming Releases Update (#24547) * Document alert acknowledgement (#24489) * Add info to the Directory Sharing guide (#24487) * Update e ref. (#24542) * Fix IP pinning for SSO login (#24541) * [v12] docs: include Amazon Linux in BPF-supported distributions (#24480) * Allow the Okta role to read the cluster name. (#24540) * Integrations: web API and tctl (#24145) (#24458) * [v12] Ensure the Okta service can connect through the reverse tunnel. (#24524) * Update FAQ for on-prem data collection (#24512) * Support app servers on different types of tunnels. (#23749) (#24525) * Attempt ssh connections with and without mfa at the same time (#24371) * Fix relaxed moderator joining for Kube Access (#23674) (#23993) * [v12] Hosted plugin manager prerequisites (#23922) (#24390) * Add check for nil auth.local in ping response. (#24490) * Docs: adjust Active Directory (manual) guide (#24071) (#24462) * Docs: Standardize prerequisite partial use. (#23394) (#24452) * Create a partial for Event Handler role/user (#24469) ------------------------------------------------------------------- Thu Apr 13 07:08:02 UTC 2023 - kastl@b1-systems.de - Update to version 12.2.2: * Release 12.2.2 (#24478) * docs: bump cloud to 12.2.1 (#24475) * Unlock keychain in drone (#24474) * [v12] Add CA, Role, Lock AuthPreference RO persmissions to RoleOkta. (#24397) * Add caveat re: the audit event list (#24406) * helm: support setting proxyListenerMode to emptystring (#24426) * Clarify that "local" is not an auth connector (#24455) * [v12] Integration: add service to server and client (#24133) (#24439) * [v12] Return enroll_status unspecified for empty status (#24435) * [v12] docs: correct rds proxy policy example (#24423) * Restore MajorVersion template var for Installers (#24388) (#24434) * [v12] usagereporter: enable on-prem user activity reporting (#24433) * reduce log spam when AWS Aurora engine name is not recognized (#24413) * [v12] Distroless doc updates (#24036) * * Fix Hardware Key support docs when scoped for Open Source. (#24408) * * Add --mlock flag with auto, off, best_effort, and strict options. (#24236) (#24410) * Add new `reporting` license flag (#21928) (#24396) * Fix log output in aggregating.Reporter (#24391) * Move docs builds down in GitHub Actions (#24385) * Remove unnecessary query string (#24289) * [v12] Updates access plane to access platform and operator def (#24389) * Expose CopyAndConfigureTLS. (#24384) * [v12] Fields in WebAuthn comments (#24354) * chore: Bump Buf from 1.16.0 to 1.17.0 (#24351) * * Fix headless authentication watcher race condition on wait condition (#24361) * Add longer meta descriptions to high-traffic pages (#24334) * Update e reference. (#24341) * [v12] Support spellchecking in docs content (#24304) * Allow Okta role to heartbeat app servers. (#24329) * Constrict app.FindPublicAddr client. (#24331) * docs: correct header in changelog (#24308) * [v12] Update to Teleport Access Platform name in teleport,tctl (#24300) * purge extra newlines (#24283) * fix protocol name for elasticsearch guide (#24280) * [v12] Fixes to metrics docs (#24290) * add Datadog to audit events index (#24274) * Make react-router-dom and @types versions consistent (#24201) (#24272) * docs: use teleport systemd include for start mongodb (#24258) * [v12] Fix package names for v1 protos, misc proto changes (#24183) (#24263) * Connect: Do not include staging feedback address in prod CSP (#24189) * Add missing continue and handle error in the test echo SSH server (#24243) * Added 04/03 Upcoming Releases Update (#24215) * [v12] Bump cloud docs to 12.1.5 (#24204) * Include correct identity in post-renewal log message (#24246) * docs: use teleport systemd include for start (#24248) * update Makefile to use cargo sparse protocol in all cargo commands (#23856) (#24225) * GHA: Update path filters to include workflow files and Makefile (#24252) * Lowercase "Teleport Service" (#24219) * [v12] Disable `build-macos` and `build-windows` on PR (#24233) * bump teleport version in docs (#24205) * usagereporter: on-prem dial home (#23916) (#24196) * Fix tctl test timeouts (#24216) * [v12] Add configuration options for hosted plugin runtime (#22320) (#24112) * [v12] [docs] Add documentation page for IP pinning (#23897) * Integrations service for CRUD operations (#23989) (#24144) * Add local guidance for Linux Server guide users (#24140) * [v12] Fix panic when incoming request is nil (#24199) * Fix panic for when `/web/launch` is requested (#24132) * Add systemctl instructions to Connecting Apps (#24137) * Make TestTeleportProcess_reconnectToAuth less flaky (#24191) * ClusterItem: Remove usage of colors.secondary.lighter (#24182) * add `set -eu` to discovery installer (#24034) * Clarify how to decide undocumented style questions (#24085) * update eref (#24165) * [v12] docs: update mfa docs (#24157) * Include year in cert rotate examples docs (#24153) * Send tunnel reconnects before waiting for sessions to drain (#24141) * [v12] Fix improper report of status on success (#24155) * refactor theme (#23876) * update eref (#24148) * helm: Propagate securityContext and nodeSelector to Job hooks (#24012) (#24134) * Remove no longer used Teleport enterprise yaml example (#24150) * Remove the Access Controls FAQ (#24081) * fix flaky tests (#24126) * [V12] Integration resource: proto (#24057) * Fix TestTerminal_KillUnderlyingShell (#24125) * [v12] Docs: Remove Details block from tctl partial. (#24072) * docs: Oracle Database Access (#24119) * [v12] Update gosaml2 to 0.9.1 (#24079) * Bump Cloud SLA to 99.9% (#24093) ------------------------------------------------------------------- Thu Apr 06 03:50:15 UTC 2023 - kastl@b1-systems.de - Update to version 12.2.1: * Release 12.2.1 (#24098) * [v12] helm: Add support for imagePullSecrets to teleport-cluster chart (#24017) * [v12] chore: Bump Go to 1.20.3 (#24062) * Show the server name (instead of UUID) in errors (#23724) (#23935) ------------------------------------------------------------------- Thu Apr 06 03:29:52 UTC 2023 - kastl@b1-systems.de - Update to version 12.2.0: * Release 12.2.0 (#24056) * fix joining moderated sessions in ui (#24018) * revert marshal database tls mode (#24063) * helm: delete hook-related resource on re-apply (#24068) * Fix listing of participant modes in UI (#24029) * [v12] Add a guide to creating Teleport roles via the API (#24003) * docs: correct mongodb atlas example config (#24044) * Add Azure auto-join docs (#23944) * Replace "Spotlight Search" with "Cross-Cluster Search" (#24049) * Recommend Proxy Service in event-handler guides (#23937) * Add missing `join_method` in azure joining docs (#24031) * [v12] docs: device trust edits (#24025) * [v12] Define an explicit device resource as DeviceV1 (#24024) * [v12] Connect: Collect protocol origin (#24039) * [v12] docs: update version (#24027) * Close auth clients in tctl tests (#24014) * docs: add description of config versions (#23936) * [v12] Headless Login (#23360) * [v12] tsh: Fix redundant error in PPK generation on relogin (#23984) * Allow getting client ip from ProxyHelloSignature for compatibility (#23419) * Update e reference (#24006) * [v12] docs: include enable teleport service in systemctl start (#23988) * [v12] Docs: prefer `curl .../auth/export` instead of `tctl auth export` (#23982) * [v12] docs: Add advisory and troubleshooting on non-tls mode for machineid kube (#23951) * [v12] Backport IP pinning for Kube and DB access (#23418) * Update e reference (#23994) * [v12] GitLab Delegated Joining docs (#23981) * Add Support for Oracle protocol (#23892) * [v12] Metrics: add IsSSO to Discover Events (#23902) * [v12] Add Docker Hub login to Drone's Kubernetes pipelines (#23958) ------------------------------------------------------------------- Mon Apr 03 13:17:55 UTC 2023 - kastl@b1-systems.de - Update to version 12.1.5: * Release 12.1.5 (#23945) * Reduce DefaultIdleTimeout to 30s (#23950) * [v12] Update e ref. (#23939) * Backport #22817 to branch/v12 (#23881) * split and notate new vs existing mysql user (#23930) ------------------------------------------------------------------- Mon Apr 03 13:06:43 UTC 2023 - kastl@b1-systems.de - Update to version 12.1.4: * Release 12.1.4 (#23929) * [v12] feat: Operator support for Login Rules (#23885) * Backport #23405 to branch/v12 (#23883) * [v12] Prevent unknown ssh requests from terminating sessions (#23904) * Allow a tsh aws to proxy any command (#19941) (#23835) * Return exit code from SFTP subsystem (#23729) * [v12] Allow Okta service reverse tunnel access. (#23853) * chore: Bump Buf from 1.15.1 to 1.16.0 (#23870) * [v12] Add gRPC service definition for Plugin resources (#21750) (#23780) * Added 03/30 Upcoming Releases Update (#23868) * Expose process.OnHeartbeat. (#23852) * Add Copy to AccessRequest. (#23638) (#23712) * Update e ref (#23845) * [v12] Remove `push` workflow for jobs that already run on PR and merge (#23862) * Machine ID FIPS support (#23563) (#23850) ------------------------------------------------------------------- Mon Apr 03 13:03:05 UTC 2023 - kastl@b1-systems.de - Update to version 12.1.3: * Release 12.1.3 (#23847) * update makefile (#23818) * support readable enum values in database tls mode (#23601) (#23808) * [v12] Fix the navigation only ever linking to the root cluster (#23708) * [v12] Improve fluentd exported by configuring buffer (#23841) * [v12] docs: Add Uninstall Instructions for Teleport Connect (#23822) * [v12] Reduce time spent setting ssh session envs (#23834) * docs: modify teleport binary reference to non-path specific in ec2 discovery (#23812) * Allow app server origin of Okta if added by Okta built in role. (#23794) * Add cluster flag to `tsh kube sessions` (#23825) * ALPN handshake test improvements (#23348) (#23798) * docs: Remove Open Source from Try out Teleport on a linux server (#23744) * docs: label enterprise prereq as Teleport Enterprise, not just Teleport (#23792) * [v12] docs: use commercial pre-req for enterprise only windows only users (#23803) * [v12] Use stable/cloud when Automatic Upgrades is on (#23395) (#23752) * Add Okta import rules, Okta assignments, and user groups to CLI. (#23722) * Clarify wording of Connect's Telemetry FAQ (#23413) (#23739) * Expose SingleProcessModeResolver and GetRotation. (#23772) * helm: Clarify port requirement for publicAddr (#23743) * Add new status to OktaAssignment, supporting service methods. (#23714) * Fix multiple profile handling for kube credentials (#23716) * [v12] Create an OktaAssignment watcher. (#23721) * Prevent races creating web api session context (#23691) (#23733) * Correct linux download name of Teleport Connect (#23604) (#23737) * [docs] Change scrollback_length to scrollback_lines (#23725) * reorder prehog credential events (#23254) (#23640) * [v12] Add SFTP subsystem fails note to server access FAQ (#23362) * Fix H1 Issues in Docs (#23328) (#23690) * Docs: Overhaul Okta SAML guide. (#23053) (#23673) * Docs: fix saml role addition partial. (#23186) (#23701) * feat(aws/config): Support configuring auth_service.proxy_listener_mode (#23678) * docs: Mention lack of signing with Homebrew (#23681) * Improve performance of `ListResources` (#23534) (#23596) * [v12] usagereporter: resource heartbeats (#23632) * [docs] Change ui_config to ui (#23672) * Cherry pick from v11 Backport of dependabot CVE updates (#23580) (#23582) * docs: configure windows service to listen on all interfaces (#23664) * Ignore unused-parameter on revive/golangci-lint (#23656) (#23661) * Bump cloud version to 12.1.2 (#23410) * [v12] fix: close all proxy listeners (#23647) * update github.com/pelletier/go-toml to v1.9.5 (#23658) * docs: point to release 12.1.1 for exe download for windows local users (#23629) * [v12] Increase DialTimeout when testing SSH Connection Diagnostics (#23635) * [v12] Remove the Houston enforcer (#23633) * Use RUNNER_TEMP to download teleport bins * Revert resty to a version to match teleport-plugins * Rename 'operator' pipeline file to 'integrations' * [v12] Vendor slack plugin and supporting libraries (#23045) * Add integrations/ * Fixed profiling documentation. * Updated Application Access documentation. * Added docs for Auth/Proxy LB configuration * Updated Cloud FAQ for IP allowlists. * Updated Cloud FAQ * [v12] Spell fix (#23594) * [v12] Allow for resource limits and requests for pre-deployment jobs (#23126) * docs: Remove note about not supporting Win Server 2022 (#23584) * [v12] Refactor UserGroups local service to use generic service. (#23579) * Fix agent pool test flakiness (#23572) * Attempt to build the docs in "Lint (Docs)" (#23530) * [v12] Add application RW permissions to the Okta role. (#23566) * allow users to specify separate API URL for github connectors (#23568) * Fix JSON reference in Azure Command (#23562) * [v12] Fetch kubernetes git version with disabled service account (#23559) * Update generated protos (#23545) * chore: Bump protoc-gen-go and protoc-gen-grpc-go (#23326) * Refactor data dir config params for `tbot` to support memory (#23447) (#23495) * Add missing GetPriority function to Okta import rules. (#23501) * minor refactor to replace localProxyOpts with alpnproxy.LocalProxyConfigOpt (#23302) (#23468) * [v12] support postgres cancel request (#23467) * Add Azure join method docs (#23526) * GHA: Cache tweaks (#23540) * Added Teleport Usage Script (#23543) * Validate proxy peer identity (#23506) * Enable minimal web handler when proxy protocol is enabled (#22753) (#23487) * Add hardware key support guide to access control guide list. (#23488) * improve aws utils and database validation (#23157) (#23482) * Plugins service no longer accepts getBackend(). (#23520) * [v12] Spell fix IAM docs (#23521) * docs: indicate which role options are enterprise only (#23298) * Add Teleport 12 features to comparison matrix (#23484) * Add proxy peering metrics to docs (#23015) (#23393) * [v12] Spell fix API comments (#23499) * Use GitHub camelcase for UI, examples and Messages (#23490) * [v12] Fix ProvisionToken incompatibility with BootstrapResources (#23474) * Handle getBackend() or backend argument for plugins. (#23438) * [v12] Add the Okta origin constant. (#23456) * docs: clarify directory sharing audit events (#23295) * add webui page with active session section (#23398) * Include teleport-msteams start in plugin docs (#23459) * [v12] update tsh proxy db cert and key file flags (#23466) * [v12] Add the Okta access point for the Okta service. (#23463) * Introduce Okta objects into the cache. (#23377) * Add `srv.ConnectionMonitor` to unify connection monitoring logic (#23465) * [v12] Add EKS guide to install agents using IAM joining (#23451) * docs: clarify app access debug app (#23297) * Add Okta client import for Okta service. (#23437) * [v12] Set serviceStarted if enterprise services are enabled. (#23402) * [v12] Docs: Update Terraform reference (#23439) * [v12] Filter out internal teleport defined logins (#23411) * [v12] Fix incorrect report of active sessions (#23444) * Do not log errors if metadata extraction fails (#23424) * Add user group read/write access to the Okta role. (#23370) * [v12] - Deprecate `site` param in `auth/export` HTTP endpoint (#23309) * [v12] Machine ID trusted cluster enhancements (#23390) * Fix links with long redirect chains (#22503) * Support Azure delegated joining for Machine ID (#23112) (#23391) * App Agent adjust connection noise logs (#23365) * Expose process ID for enterprise services. (#23383) * [v12] [Docs] Fix documentation for the `roles` field in the Moderated Sessions join policy reference (#23313) * Update e reference. (#23381) * Disable application launch in minimal handler (#22816) (#23332) * Fix docs mentioning connectors updates without secrets (#23344) * Include year in tctl status dates (#23371) * Fix tsh kube credentials fails on remove cluster for the first time (#23252) (#23354) * Add Headless SSO note to upcoming releases (#23339) * [v12] Use Helm DynamoDB policy in Backends reference (#23183) * Remove unused Expires column for tsh database list in verbose (#23318) * [v12] Fix DB Query always return success false in audit log (#23274) * App access: rewrite redirects to public app address from leaf cluster. (#21067) (#23220) * Fix docs link in changelog (#22452) * Export additional functions for enterprise use. (#23245) * Remove older-versions from docs (#23246) * Remove extraneous subheading in DB guides page (#23208) * Add Okta service configuration. (#23236) * fix link for troubleshooting (#23241) * [v12] build.assets Dockerfiles: Remove unnecessary ENV NODE_URL, pass fsSL to curl (#23188) * [v12] doc: add troubleshooting for RDS maximum policy size exceeded errors (#23231) * [v12] Access Mgmt Login Rule and IDP doc updates (#23217) * [v12] Notification improvements (#23223) * Fix navigation redirecting to the wrong page on category change (#23213) * Improve error message to label Enterprise version as FIPS for fips error (#23214) * [v12] Connect: Allow config customization (#23197) * GitLab Delegated Joining (#22705) (#23191) * adding video to k8s doc (#23171) * Allow webauthn to be passed when issuing certs for web-based scp (#22864) (#23195) * fix heartbeatv2 test (#23203) * Add anonymized device ID to tp.user.login event (#23055) * Decouple SkipLocalAuth, UseKeyPrincipal, and static auth methods. (#21182) (#23198) * Establish the Okta service role. (#23173) * [v12] Make Desktop Acess setup script idempotent (#23176) * Updated config to include HA guide (#23155) * [v12] tsh: Silent webauthnwin warning on app init (#23161) * [v12] Support App access behind load balancer (#23054) * [v12] Backport of `crypto` update (#23150) * [v12] Bump Cloud to 12.1.1 (#23129) * Use serverUID for web scp target (#23124) (#23152) * Add `app_server` support to tctl get/rm commands (#23136) * [v12] docs: Add instructions on uninstalling Teleport (#23135) * Added 03/15 Upcoming Releases Update (#23127) * Remove ossfuzz from CI (#23113) * Update Rust to 1.68.0 (#23101) * [v12] Introduce the Okta service. (#23071) * [v12] Backport Access Request plugin guide (#23085) * [v12] Backport #23024 and #23079 (#23080) * Changed Upcoming Releases format. (#23020) * Update docs version (#23083) * add bypasses for lint go and lint docs (#23078) * [v12] Document that GitHub username is added to internal.logins (#23060) * [v12] Backport #23008 and #23006 (#23021) * Introduce Okta gRPC and client interfaces. (#22733) (#23057) * [v12] chore: Bump Go to 1.20.2 (#22997) * [v12] Update the docs style guide (#23001) * Provide more context in the docs intro page (#23003) * [v12] usagereporter: Use the batched event ingest RPC (#23027) * Update Electron to 22.3.2 (#23048) * Add a getter for the backend in `auth.GRPCServer`. (#23043) * Log Connect version on startup (#23036) * [v12] Fix uncaught exception handling in Connect's shared process (#22986) * [v12] Backport Distroless OCI builds (#22814) * [v12] Fix unresponsive terminal in Connect on Windows Server 2019 (#22996) * Fixed enterprise and fips OS packages not uploading to OS package repositories when promoting in the context of private git repos (#21163) (#23012) ------------------------------------------------------------------- Tue Mar 21 08:51:11 UTC 2023 - Johannes Kastl - BuildRequire go1.19 ------------------------------------------------------------------- Tue Mar 14 07:12:37 UTC 2023 - kastl@b1-systems.de - Update to version 12.1.1: * Release 12.1.1 (#23016) * [v12] Hide upgrade-related alerts from dashboards (#22991) * Hide download center when not on dashboards and prevent license gRPC endpoint from being called (#22965) (#22980) * Web-Discover: Add support for connection testers with per-session MFA enabled (#22529) (#22943) * [v12] Add docs for Connect usage reporting (#22661) * fix leave session command (#22795) * Fix usagereporter tests (#22968) * [v12] Remove docs reference and video that users can approve/deny within PagerDuty (#22939) * [v12] Export CRL and Database CA in DER format (#22896) * docs: include a separate page for OSS access requests (#22946) * macOS-compatible grep (#22759) * Use 13px font size in a `Notification` (#22870) * [v12] Swap out select for poll (#22676) and Loop for poll (#22746) (#22798) * [Web] Make language on mfa verify step dialog more clear (#20825) (#22924) * Fix panic when AuditWriter fails on moderated sessions (#22930) * [v12] Add per-session mfa support to connection testers (#22918) * update eref (#22937) * fix select box sizing (#22686) * Make the NodeWatcher more robust (#22910) * Add idle connection timeouts to http clients and servers (#22885) (#22908) * Remove the permissions alias. (#22909) * [v12] chore: Bump gci and golangci-lint (#22900) * Drop local_auth/second_factor warning (#22859) * Update e ref. (#22905) * [v12] Connect: Provide prehog address for prod env (#22876) * [v12] Emit new `AgentMetadataEvent` (#22879) * chore: Bump Buf to v1.15.1 (#22856) * Ensure that the `webclient` closes connections (#22832) (#22893) * [v12] Connect: Remove leftovers from resource cache removal (#22884) * docs: mention how to get the correct API version (#22812) * [v12] Return Public Web Port in TLS mode for postgres when listen addr specified. (#22889) * Idp Docs Fixes (#22853) * Added 03/09 Upcoming Releases Update (#22846) * [v12] Add documentation for tsh --trace-exporter (#22837) * Move the authorizer into its own package. (#22825) * [v12] Interface for processing SAML IdP request signing on auth server. (#22801) * Do not check os groups when user exits (#22805) * [v12] Deduplicate multiplexer detection errors over 1-minute windows (#22802) * Validate static labels assigned to Kubernetes service (#22701) (#22777) * [v12] AWS Terraform doc updates (#22786) * Cherry-pick 6c58a9e (#22785) * usagereporter: Allow multiple batch submissions in a row (#22711) (#22788) * [v12] Use the teleport-ent package on enterprise clusters in the discovery installer (#22769) * Add correct link in place of placeholder for Telemetry docs (#22781) * Docs teleport and golang version (#22765) * [v12] Docs: Fix AWS Terraform Snippets (#22743) * The SAML IdP CA will be handled during auth.Init. (#22721) * [v12] Improve error messages for tsh login connectivity and ssh port (#22763) * [v12] Reorganize the config reference (#22271) * [v12] chore: Bump Go to 1.19.7 (#22725) * [v12] SAML identity provider docs. (#22625) * NodeJoin Script: clear yum repo cache (#22585) * Improve tctl auth export docs/help (#22681) ------------------------------------------------------------------- Tue Mar 07 05:48:42 UTC 2023 - kastl@b1-systems.de - Update to version 12.1.0: * Release 12.1.0 (#22694) * (v12) Downgrade Go to 1.19.6 (#22691) * Add MaxRetryPeriod for cachePolicy config to use in tests (#22656) (#22692) * [v12] temporarily disable TestHSMDualAuthRotation (#22682) * [v12] Docs: Add Datadog guide. (#22677) * Update node listing troubleshooting (#22678) * [v12] Update access request enterprise description (#22621) * [v12] Machine ID Agent Anonymous Analytics (#22658) * test keyword frontmatter (#22666) * Machine ID telemetry docs (#22541) (#22660) * SCP - Change file attrs only when requested (#22579) (#22609) * Fix broken Teleterm stories (#22665) * spell fixes and discord config fix (#22617) * Remove network I/O from database_service collection apply (#22588) * [v12] Add OSS repo name to github actions trigger (#22653) * Update e (#22608) * Refresh remote cluster connection status periodically (#22575) * bump cloud version (#22542) * fix typo in image (#22138) (#22552) * Bump e ref. (#22602) ------------------------------------------------------------------- Sat Mar 04 08:45:41 UTC 2023 - kastl@b1-systems.de - Update to version 12.0.5: * Release 12.0.5 (#22599) * Add SAML IdP service providers to default allow rules. (#22600) * [v12] node hb and watcher scalability improvements (#21495) * Add in SAML IdP service provider session metadata to auth attempts. (#22544) (#22562) * update eref (#22596) * [Web] Refactor serverside filtering and pagination (#20823) (#22432) * fix video link (#22576) * Use `btree.BTreeG` directly in memory backend (#22409) * [v12] Add GCP Service Account parameter to tctl users add reference (#22543) * [v12] Add Telnet into docker to test connectivity for cloud getting started (#22570) * Allow all alert severities to be acknowledged (#22582) * add github.com/google/go-attestation/attest to e imports #2 (#22465) * Fix compilation on ARM (#22569) * [v12] Refresh the Access Controls menu (#22523) * [v12] update e ref to latest branch/v12 (#22566) * Added 03/02 Upcoming Releases Update (#22547) * [v12] Enable BPF on ARM64 (#22550) * Teleport 12 Videos (#22527) * Add Azure auto-joining (#21087) (#22521) * [v12] Unify x86/ARM64 build process (#22495) * Fix pickDefaultAddr not respecting HTTPS_PROXY (#22492) * Set `create_as_resource` in device-related `tctl` RPCs (#22415) (#22518) * Improve `tsh kube credentials` read operations (#22508) * [v12] SAML IdP audit events. (#22510) * [v12] `lib/usagereporter` refactor and consolidation (#22512) * [v12] Make curl fail on server error when downloading binaries in buildbox (#22380) (#22442) * add known STS endpoint for ap-southeast-4 (#22486) * [v12] Server Access RBAC Docs page (#22500) * Okta local service. (#22434) (#22513) * chore: Bump Buf to v1.15.0 (#22430) (#22472) * [v12] Allow devices writes with resource-like semantics (#22470) * Initial Okta objects. (#22151) (#22431) * [v12] Update to libbpf 1.0.1 (#22424) * Automatically parse entity ID from SAML SP during CLI creation. (#22101) (#22368) * [v12] Add static and dynamic web ui configuration options (#22422) * [v12] feat: add LoginRule methods to api/client (#22426) * [v12] Add docs steps to create machine-id data dir and systemd enablement (#22477) * [v12] Remove non-applicable roles from teleport start --roles reference (#22311) * [v12] Use developer-friendly and precise technical language in docs (#22412) * docs: use approved terminology for desktop access w/ local users (#22418) * [v12] Add CLI doc changes after new client only parameter for tsh version (#22392) * Export runtime traces from tsh (#22406) * [v12] fixes #21970 - remove broken config validation check in scratch mode (#22423) * [v12] sshserver: Correctly handle PuTTY winadj channel requests (#22420) * Docs: Device Trust role and locking support (#21915) (#22416) * [v12] update e-ref (#22381) * Install libbpf 1.0.1 in buildboxes (#22317) * [v12] Update to default k8s deployment docs (#22396) * Update docs Teleport version and golang (#22384) * Add caching to web assets (#22183) * [v12] Connect: Remove resource cache (#22316) * Machine ID readme example script fix (#22394) * Add Azure join method (#22204) * [v12] Bump versions in docker images to 12 (#22375) * Updates to enable merge queue (#22370) * Fix incorrect login options for Windows Desktops (#22118) (#22333) * [v12] Update eref (#22343) * Add WEBASSETS_SKIP_BUILD to Makefile (#22337) * Always include webassets_embed when building teleport (#22339) * Add `isDashboard` to web config object (#20830) (#22329) * [v12] [Web] Add custom element support to SearchPanel (#22325) * Fix SAML IdP service provider CLI bug. (#22322) * [v12] [web] Move filtering out cloud and tcp apps to the frontend (#22324) ------------------------------------------------------------------- Tue Feb 28 07:52:01 UTC 2023 - kastl@b1-systems.de - Update to version 12.0.4: * Release 12.0.4 (#22321) * Terminate the local shell when a session closes (#22222) * Ignore all node_module paths when running shellcheck lint. (#22233) * [v12] Enable xterm links and clean up MFA modal (#22278) * [v12] Web: Fix regression for not able to create or reset users (#22267) * Mark Proxy Peering as in Preview (#22209) * [v12] helm: allow to set security contexts in `teleport-kube-agent` (#21535) * Format collected data in the device tctl resource nicely (#22198) (#22258) * Fix `disconnect_expired_cert` and `client_idle_timeout` description (#22255) * spell fix kubernetes resource doc (#22259) ------------------------------------------------------------------- Tue Feb 28 06:52:22 UTC 2023 - kastl@b1-systems.de - Update to version 12.0.3: * Release 12.0.3 (#22250) * [v12] Fix Kube impersonation header overwrite when dealing with remote clusters (#22244) * Fix an issue Redis protocol not handling nil response (#22200) (#22228) * preserve explicit local auth disable * Create a generic local backend service. (#22236) * [v12] Adds `kubernetes_resources` references (#22217) * User group API and cache. (#21956) (#22147) * [v12] Provide flag to only display tsh binary version (#22167) * [v12] Extend security context to proxy init container wait-auth-update. (#22064) * createPtyProcess: Return early on error (#22190) * ClustersService: Remove internal logins when syncing root clusters (#22187) * [v12] Implement tctl resource commands for Device Trust (#22157) * Added 02/23 Upcoming Releases Update * [v12] Add docs for Device Trust tctl commands (#22201) * Inherit `kubernetes_resources` from roles when using access requests to kube_cluster * [v12] Add service for "plugin" resources (#21210) (#22185) * [v12] Add Security-Kerberos Event Log for Desktop Troubleshooting (#22170) * add MFA type and Login flow to register challenge event (#22112) (#22159) * add bypassses for UI GHA's (#22105) (#22141) * Add expire time to SAML session creation. (#22135) * [v12] Add Plugin resource schema, methods (#20990) (#22177) * [v12] Connect: Enable font configuration (#22122) * Update e (#22156) * Spell fix previews page (#22152) * Add in WrapContextWithUserFromTLSConnState. (#22136) * [v12] Bump cloud version to 11.3.4 (#22114) * disable MFA TTL limit for local proxy tunnel (#21661) * [v12] Document silent install of Connect on Windows (#22119) * Clarifications in Okta SSO doc (#22036) * [v12] Docs: update fluentd guide (#22077) * Remove usage of lodash methods (#21567) (#22102) * Discover: install ent image when cluster is enterprise (#22109) * [v12] Install deb/yum repos when using node-join script (#22108) * Ensure UpdateRemoteCluster updates all fields (#22024) (#22088) * fix: improve tsh logs when skipping auto Access Request (#22094) * Add DatabaseService KeepAlive type (#22042) (#22087) * SAML IdP sessions added to the API and cache. (#22098) * Correctly handle LOCAL command of PROXY protocol v2 in multiplexer (#22092) * Import jest-canvas-mock in teleport tests which import xterm paths (#22074) * Refresh Introduction Page (#21261) (#22032) * [v12] Add non-HA Teleport cluster to Deploy with Helm links (#22039) * Emit usage events for `port`, `kube.request`, `sftp` (#21740) (#22016) * Relay child exit code in g-build (#21898) * [v12] [Web:Discover] Add missing checks (#22029) * Align AWS assume-role request duration with cert expiration (#21670) (#21994) * Support assumed roles for "tsh proxy aws" (#20568) (#21990) * [doc] Update app access reserved headers X-Teleport-* (#21000) (#21993) * [v12] Change init logger to include timestamp for debug level (#21996) * Add minor improvements to `lib/kube/proxy` (#21917) * [v12] Support proxy reading of SAML IdP CA. (#22030) * Mention --mfa-mode in the `tsh mfa add` flow (#22018) (#22034) * [docs] add a note on `rds:DescribeDBClusters` (#22007) (#22025) * Improve formatting for TLS cert requests (#22013) * CI: bypass OS compatibility check for some changes (#21989) (#22021) * [v12] Updates to windows getting started (#22019) * [v12] SAML IdP access checker. (#21955) * Expose access point in web handler. (#21957) * Include Enterprise in output of tctl version for commercial pre-req (#22004) * [v12] Fix Moderated session on leave pause action. (#21974) * [v12] [Web] Fix missing --request-id= flag in UI for Kubernetes login instructions (#21445) * [v12] Connect: Use SSH server UUID instead of hostname for file transfer (#21962) * [v12] Fix uncaught errors in Desktop's Discover flow (#21756) * Added 02/16 Upcoming Releases Update * Add metrics to track connection ingress (#19734) (#21771) * Switch CodeQL to scheduled (#21942) * Refer to tsh apps subcommand (#21857) * Adjust clientIP/pinnedIP fields according to IP pinning RFD (#21906) * Update Go toolchain to 1.20.1 (#21931) * [v12] Docs/TF: Identity as b64 (#21933) * Docs: Remove Jira Custom Field reference (#21908) * Update role > lock and add missing word." (#21897) * Reduce etcd requests performed by a KeepAlive (#21926) * Update Teleport Enterprise Cloud compare description (#21922) * [v12] Update teleterm README (#21879) * Disable instance heartbeats by default (#21901) (#21905) * [v12] Add docs references to `tsh request search --kind=pod` (#21887) * [v12] Add more info re: AWS credentials to the docs (#21776) * [v12] Include enterprise in tctl prereqs for ent and cloud (#21890) * Initial user group object. (#21657) * [v12] Add SAML query functions to auth preferences. (#21825) * SAML IdP session objects. (#21758) * [v12] Update troubleshooting docs (#21762) * [v12] Change error response formatting for "/version" endpoint (#21846) * Update download link (#21674) * use Enterprise over Commercial (#21370) * Improve webpack "exclude" expressions (#21663) (#21725) * [doc] allow either role name or full ARN for AWS IAM role db_users (#21240) (#21837) * helm: fix proxy and auth config referring to the same subdict (#21768) * Fixup teleport db configure create (#20968) (#21690) * spell fixes (#21855) * Bump Buf to v1.14.0 (#21842) * Run reviewers check on (un)labeled PR events (#21814) (#21819) * [v12] docs: login rule docs (#21829) * Remove deprecated warning when proxy starts (#21817) * [v12] Move CentOS 7 assets to GitHub repo (#21784) * feat: early feedback for successful security key taps (#21780) * set SessionExpires on new sessions (#21688) (#21733) * [v12] Skip deleting server heartbeats during in-process restart (#21807) * Remove code related to restarting lib/teleterm gateways (#21533) * AWS IAM role matching for database users (#20610) (#21251) * Add device lock support (#21667) (#21751) * [v12] Turn off parallelization of teleterm's integration tests (#21737) * [v12] Remove support for DEBUG_ASSETS_PATH (#21473) * Remove required cluster name when using `tsh kube login --all` (#21765) * [v12] Moderated sessions request is not forwarded into the leaf cluster (#21612) * Role access requests available for all scopes (#21752) * Update docs link to master db access rfd (#21736) * Cache etcd lease ttl (#21496) * Fix linter issues (#21748) * [v12] Update Go toolchain to 1.20 (#21680) * Add Pod resource search web API (#21595) * Update docs version (#21744) * [v12] Make UsageSessionStart report TCP app access separately (#21711) * [v12] Connect: Link to docs in `UsageData` dialog (#21730) * Delete assets/aws/cloudformation directory (#21696) * lib/utils/fs.go: Do not remove lockfiles on Windows * Update SQL Server library (#21065) (#21638) * Update database config samples (#21480) (#21543) * Change debug commands during discover flow (#21557) * [v12] Ask for job role on the second launch (#21640) * Correct namespace name in k8s doc (#21589) * Remove version warnings for EOL Teleport versions (#21665) ------------------------------------------------------------------- Mon Feb 13 15:53:03 UTC 2023 - kastl@b1-systems.de - Update to version 12.0.2: * Release 12.0.2 (#21679) * Bump cloud version to 11.3.3 (#21672) * Fix kube agent shutdown during upgrades (#21617) * [v12] Updates port validation to restrict to valid port numbers 1-65535 (#21651) * Improve listing resources across clusters (#21003) (#21577) * [v12] Skip deleting database servers on agent shutdown during binary upgrade (#21635) * [v12] Update JS grpc-tools to 1.12.4 (#21532) * capture custom role creation in prehog (#21123) (#21599) * Verify if proxy can handle application requests when creating session (#21615) * Extract entity ID when creating SAML service provider. (#21603) * Allow invalid namespaces in role templates (#21573) * Remove GCB checks (#21593) * [v12] Compare TLS and SSH principals independent of order (#21578) * [v12] Skip device authz when issuing App or Windows certs (#21571) * fix link in troubleshooting guide (#21581) * [v12] Use test IP addresses for auth_proxy_test. (#21576) * Remove unused `CheckResourceUpsertableByError` function (#21562) * refactor db local proxy logic (#21335) * Add field to user cert request (#21474) * Fix k8s docs links (#21553) * Bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp (#21514) * Bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp (#21513) * [v12] Update e-ref (#21547) * [v12] Add SAML IdP service providers to the cache and CLI. (#21471) * [v12] Improve error message when trying to rename resource (#21179) * [v12] Remove Auth/Proxy instructions from DB guides (#21333) * properly resolve conflict (#21409) * [v12] Update okta.mdx (#21410) * [v12] helm-docs: Separate cert-manager and ACM values for clarity in AWS guide (#21361) * Rename protoEqual and add a big warning (#21505) * [v12] Connect: return logged in user in `ListRootClusters` (#21467) * Run go mod tidy in CI (#21140) (#21482) * Align the Okta and Auth Connector configuration examples in Okta SSO guide (#21475) * [v12] Add in file configuration for the SAML IdP. (#21486) * improve 'tsh scp' error message when no remote path is specified (#21373) * Add `tsh request search --kind=pod` support (#21456) * Removes the "overflow: auto" from StyledXterm (#20868) * fix partial links (#21470) * Reduce CPU usage in enhanced session * update contribute instructions to use major version (#21462) * [v12] [Docs] update Desktop Access introduction for v12 (#21458) * Update the version support table for v12 (#21428) * single-source access control guides list (#21415) * [v12] Move Connect-specific MenuLogin story out of shared package (#21386) * Fix flaky tctl UT - allocate network listener (#21390) * Add RBAC labels for Database Services access (#21093) (#21244) * Enable role-based device authz for DB, k8s and SSH (#20640) (#21432) * [v12] Bump OpenSSL and libcbor (#21425) * [v12] Require flag for dynamic resources matching "tsh db configure create" (#21395) * [v12] Allow role-based device verification in AccessChecker (#20846) * Bump forked go-libfido2 (#21175) * fix k8s docs links (#21414) * Show enterprise installs for Cloud scope MacOS Installs (#19669) (#21368) * Update docs version to 12 (#21418) * [v12] Add missing license headers to files. (#21405) * correct tsh scp docs (#21378) * Docs: AWS RDS Proxy Guide (#21322) (#21401) * [v12] Update security information in docs. (#21358) * Updated Dronegen for v12 release (#21355) * [v12] Fix the navigation not listening to the back button (#21236) * Spelling fix and app access link fix (#21397) * [v12] Remove deprecated `/webapi/nodes/token` endpoint (#21152) * Add gRPC Kubernetes Service (#21359) ------------------------------------------------------------------- Wed Feb 08 08:08:12 UTC 2023 - kastl@b1-systems.de - Update to version 12.0.1: * Release 12.0.1 (#21372) * Fix operator build (#21369) * fix lint-breaking spacing (#21356) * [v12] Preview Page (#21283) ------------------------------------------------------------------- Wed Feb 08 07:53:13 UTC 2023 - kastl@b1-systems.de - Update to version 12.0.0: Full changelog is available at https://github.com/gravitational/teleport/releases/tag/v12.0.0 Teleport 12 brings the following marquee features and improvements: - Device Trust (Preview, Enterprise only) - Passwordless Windows access for local users (Preview, Enterprise only) - Per-pod RBAC for Kubernetes Access (Preview) - Azure and GCP CLI support for Application Access (Preview) - Support for more databases in Database Access: - AWS DynamoDB - AWS Redshift Serverless - AWS RDS Proxy for PostgreSQL/MySQL - Azure SQLServer Auto Discovery - Azure Flexible Servers - Refactored Helm charts (Preview) - Dropped support for SHA1 in Server Access - Signed/notarized macOS binaries * Azure and GCP CLI support for Application Access (Preview) In Teleport 12 administrators can interact with Azure and GCP APIs through Application Access using `tsh az` and `tsh gcloud` CLI commands, or using standard `az` and `gcloud` tools through the local application proxy. * Support for more databases in Database Access Database Access in Teleport 12 brings a number of new integrations to AWS-hosted databases such as DynamoDB (now with audit log support), Redshift Serverless and RDS Proxy for PostgreSQL/MySQL. On Azure, Database Access adds SQLServer auto-discovery and support for Azure Flexible Server for PostgreSQL/MySQL. * Refactored Helm charts (Preview) The “teleport-cluster” Helm chart underwent significant refactoring in Teleport 12 to provide better scalability and UX. Proxy and Auth are now separate deployments and the new “scratch” chart mode makes it easier to provide a custom Teleport config. “Custom” mode users should follow the migration guide: https://goteleport.com/docs/ver/12.x/deploy-a-cluster/helm-deployments/migration-v12/ * Dropped support for SHA1 in Server Access Newer OpenSSH clients connecting to Teleport 12 clusters no longer need the “PubAcceptedKeyTypes” workaround to include the deprecated “sha” algorithm. * Signed/notarized macOS binaries Users who download Teleport 12 Darwin binaries would no longer get an untrusted software warning from macOS. * tctl edit tctl now supports an edit subcommand, allowing you to edit resources directly in your preferred text editor. * Breaking Changes Please familiarize yourself with the following potentially disruptive changes in Teleport 12 before upgrading. - Helm charts The teleport-cluster Helm chart underwent significant changes in Teleport 12. To upgrade from an older version of the Helm chart deployed in “custom” mode, use the following migration guide: https://goteleport.com/docs/ver/12.x/deploy-a-cluster/helm-deployments/migration-v12/ Additionally, PSPs are removed from the chart when installing on Kubernetes 1.23 and higher to account for the deprecation/removal of PSPs by Kubernetes. - tctl auth export The tctl auth export command only exports the private key when passing the --keys flag. Previously it would output the certificate and private key together. - Desktop Access Windows Desktop sessions disable the wallpaper by default, improving performance. To restore the previous behavior, add `show_desktop_wallpaper: true` to your windows_desktop_service config. ------------------------------------------------------------------- Thu Feb 02 06:59:38 UTC 2023 - kastl@b1-systems.de - remove non-breakable-space character from changes file - Update to version 11.3.2: * Release 11.3.2 (#21121) * Update ec2-tags.mdx (#21115) * Fix MongoDB readHeaderAndPayload BSON max size (#21113) * [v11] Fix direct node dial from WebUI (#20928) * Update docker-compose docs (#21045) * Use CDN links for install node scripts (#20985) (#21057) * [v11] Remove CentOS6 and RHEL6 as valid distros (#20986) * Skip TestBot_Run_CARotation (#20944) * Use `SameSiteNoneMode` for application access cookies (#21049) * Fix data race when closing listener (#21040) * Conditionally build the UI if there are changes. (#20489) (#21018) * [v11] Use the webassets directory at the root of the project for the web ui. (#21016) * remove quotes from messages in makefile (#20740) * Open Support links in UI to new page (#20984) * [v11] Merge backports (#20997) * [v11] Enable building teleport with the new UI location (#20965) * Elasticsearch: explicitly require `--db-user`. (#20695) (#20919) * Use concurrent streams for SFTP connections (#20953) * update docs version (#20973) * Disable disk-based logging for TestResizeTerminal (#20871) * Fix language for try out teleport intro (#20948) * Use a GitHub app for the check and backport workflows (#20873) (#20958) * [v11] Add node and yarn to the buildboxes in preparation for the webapps merge (#20952) * Hardware Key UX fixes (#20949) * Update Rust to 1.67.0 (#20883) * [v11] chore: Bump Buf to v1.13.1 (#20921) * Added 01/26 Upcoming Releases Update * [v11] fix `tsh proxy aws --endpoint-url` (#20880) * Temporarily ignore the web directory when linting for license headers. * [v11] Migrate AppLauncher tests into webapps. (#1532) * Rearrange buildbox layers for faster updates (#20838) * Use ghcr image for doc tests (#20876) * Update app tests for rewritten headers (#20801) * [v11] Add support for Moderated Sessions in the Web UI (#1540) * [v11] [Discover] Enable mysql flow (#1539) * [v11] feat: login rule audit events (#1537) * [v11] Connect: Add useWorkspaceLoggedInUser (#1536) * [v11] Update eref (#1534) * Decode URL encoded values from AppLauncher's ARN. (#1530) * Update e ref (#1528) * Add --quiet to eslint package.json script (#1510) (#1523) * Update webapps.e reference to latest commit (#1522) * Fix clipboard permissions apparent inconsistency (#1509) (#1513) * Change the application access authentication flow (#1515) * capture additional prehog events (#1508) * [v11] backport #1505 (Revert "Use sessionStorage for Authentication Bearer Token) (#1506) * Add lazy loading for desktop sessions (#1503) * Add lazy loading for session playback (#1502) * Update e ref (#1500) * Make trusted cluster screen hidden based on user roles (#1484) (#1494) * Update Electron to 22.0.0 (#1498) (#1499) * [v11] Discover: Implement Day 1 Database Postgres Flow (#1487) * Update sessionPath value to new endpoint (#1486) (#1492) * [v11] [Connect] requestableRoles and suggestedReviewers on LoggedInUser (#1485) * [v11] Make bundled tsh available outside of Connect (#1488) * Connect: Add missing modal stories, misc modal fixes (#1479) (#1482) * Include session id in Session Uploaded event display (#1476) * awaits the file write and close to avoid data corruption (#1471) (#1472) * Fix websocket close (#1463) (#1470) * [v11] add app access dynamodb event (#1462) * [v11] backport #1275 (Use sessionStorage for Authentication Bearer Token) (#1458) * Adds a status code to the closing of the tdp client's websocket (#1442) (#1455) * [v11] [Connect] Use resourcesList in review access request table (#1456) * Add support for InstanceJoin and BotJoin audit events (#1414) (#1440) * Update electron-builder to 24.0.0-alpha.5 (#1434) (#1438) * Connect: Use typed URIs (#1394) (#1436) * Fix Connect stories (#1422) (#1435) * Connect: Implement tshd event handlers for db cert renewal (#1383) (#1416) * Add `recoveryCodesEnabled` (#1408) (#1419) * Add subject value to app sessions (#1413) (#1426) * alert convention matches grpc (#1424) (#1425) * [Connect] Async autocomplete (#1406) (#1423) * Fix large file corruption (#1382) (#1421) * capture events from webapps (#1344) (#1411) * Connect: Tell fpm to not use symlinks when building the rpm package (#1407) (#1410) * useAsync: Add support for abort signal (#1377) (#1409) * Update xterm to 5.0.0 (#1400) (#1401) * [v11] backport #1321 (Add checkbox component to design package) (#1393) * Lazy load Telemetry only when needed (#1399) * Fix alerts from not disappearing on route changes (#1395) (#1397) * Display `verb`, `request_path` & `response_code` in `kube.request` events (#1384) (#1391) * [v11] Use a single websocket for SSH connections (#1361) (#1392) * Pass clusterUri rather than documentUri to retryWithRelogin (#1385) (#1386) * [v11] [Connect] Use server side search in resource tables (Advanced Search) (#1381) * [v11] Forward SSH agent (#1366) (#1370) * [v11] Update to Electron 21 (#1351) (#1360) * Fix iterating over null array for sshLogins from fetched nodes (#1356) * [Discover] Refactor SetupAccess Screens (#1310) * Prevent non-https protocol from opening external windows (#1343) (#1345) * Shared Directory Audit Events (#1290) (#1348) * Connect: Set up tshd events server for tshd-initiated communication (#1285) (#1339) * [v11] retryWithRelogin: Enable use outside of document context (#1341) * Show all kinds of active sessions (#1337) * [v11] Log shared process `stdout` and `stderr` (#1046) (#1336) * [v11] Discover: Add back button for `TestConnection` screens (#1329) * Update ensureBaseUrl to use URL constructors only (#1328) (#1330) * Update ensureBaseUrl conditional (#1320) (#1322) * [v11] Handle private key policy errors and config (#1298) (#1311) * Warn user when desktop is active (#1297) (#1312) * Connect: Use gap instead of margins for