dynamo

package
v2.3.3+incompatible Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2017 License: Apache-2.0 Imports: 13 Imported by: 0

README

DynamoDB backend implementation for Teleport.

Introduction

This package enables Teleport auth server to store secrets in DynamoDB on AWS.

WARNING: Using DynamoDB involves reccuring charge from AWS.

The table created by the backend will provision 5/5 R/W capacity. It should be covered by the free tier.

Building

DynamoDB backend is not enabled by default. To enable it you have to compile Teleport with dynamo build flag.

To build Teleport with DynamoDB enabled, run:

ADDFLAGS='-tags dynamodb' make teleport

Quick Start

Add this storage configuration in teleport section of the config file (by default it's /etc/teleport.yaml):

teleport:
  storage:
    type: dynamodb
    region: eu-west-1
    table_name: teleport.state
    access_key: XXXXXXXXXXXXXXXXXXXXX
    secret_key: YYYYYYYYYYYYYYYYYYYYY

Replace region and table_name with your own settings. Teleport will create the table automatically.

AWS IAM Role

You can use IAM role instead of hard coded access and secret key (IAM role is recommended). You must apply correct policy in order to the auth to create/get/update K/V in DynamoDB.

Example of a typical policy (change region and account ID):

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AllAPIActionsOnTeleportAuth",
            "Effect": "Allow",
            "Action": "dynamodb:*",
            "Resource": "arn:aws:dynamodb:eu-west-1:123456789012:table/prod.teleport.auth"
        }
    ]
}

Get Help

This backend has been contributed by https://github.com/apestel

Documentation

Overview

Package dynamodbDynamoDBBackend implements DynamoDB storage backend for Teleport auth service, similar to etcd backend.

dynamo package implements the DynamoDB storage back-end for the auth server. Originally contributed by https://github.com/apestel

limitations:

  • Paging is not implemented, hence all range operations are limited to 1MB result set

Copyright 2015 Gravitational, Inc.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func GetName

func GetName() string

GetName() is a part of backend API and it returns DynamoDB backend type as it appears in `storage/type` section of Teleport YAML

func New

func New(params backend.Params) (backend.Backend, error)

New returns new instance of DynamoDB backend. It's an implementation of backend API's NewFunc

Types

type DynamoConfig

type DynamoConfig struct {
	// Region is where DynamoDB Table will be used to store k/v
	Region string `json:"region,omitempty"`
	// AWS AccessKey used to authenticate DynamoDB queries (prefer IAM role instead of hardcoded value)
	AccessKey string `json:"access_key,omitempty"`
	// AWS SecretKey used to authenticate DynamoDB queries (prefer IAM role instead of hardcoded value)
	SecretKey string `json:"secret_key,omitempty"`
	// Tablename where to store K/V in DynamoDB
	Tablename string `json:"table_name,omitempty"`
}

DynamoConfig structure represents DynamoDB confniguration as appears in `storage` section of Teleport YAML

type DynamoDBBackend

type DynamoDBBackend struct {
	// contains filtered or unexported fields
}

DynamoDBBackend struct

func (*DynamoDBBackend) AcquireLock

func (b *DynamoDBBackend) AcquireLock(token string, ttl time.Duration) error

AcquireLock for a token

func (*DynamoDBBackend) Clock

func (b *DynamoDBBackend) Clock() clockwork.Clock

Clock returns wall clock

func (*DynamoDBBackend) Close

func (b *DynamoDBBackend) Close() error

Close the DynamoDB driver

func (*DynamoDBBackend) CreateVal

func (b *DynamoDBBackend) CreateVal(path []string, key string, val []byte, ttl time.Duration) error

CreateVal create a key with defined value

func (*DynamoDBBackend) DeleteBucket

func (b *DynamoDBBackend) DeleteBucket(path []string, key string) error

DeleteBucket remove all prefixed keys WARNING: there is no bucket feature, deleting "bucket" mean a deletion one by one

func (*DynamoDBBackend) DeleteKey

func (b *DynamoDBBackend) DeleteKey(path []string, key string) error

DeleteKey remove a key

func (*DynamoDBBackend) GetKeys

func (b *DynamoDBBackend) GetKeys(path []string) ([]string, error)

GetKeys retrieve all keys matching specific path

func (*DynamoDBBackend) GetVal

func (b *DynamoDBBackend) GetVal(path []string, key string) ([]byte, error)

GetVal retrieve a value from a key

func (*DynamoDBBackend) ReleaseLock

func (b *DynamoDBBackend) ReleaseLock(token string) error

ReleaseLock for a token

func (*DynamoDBBackend) UpsertVal

func (b *DynamoDBBackend) UpsertVal(path []string, key string, val []byte, ttl time.Duration) error

UpsertVal update or create a key with defined value (refresh TTL if already exist)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL