Skip to search

TeleportScopedTokenV1

resources.teleport.dev / v1

apiVersion: resources.teleport.dev/v1 kind: TeleportScopedTokenV1 metadata: name: example
View raw schema
apiVersion string
APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind string
Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata object
scope string
Scope is the scope of the token resource.
spec object
ScopedToken resource definition v1 from Teleport
assigned_scope string
The scope to which this token is assigned. Must be equivalent or descendent to the scope of the token itself.
aws object
The AWS-specific configuration used with the "ec2" and "iam" join methods.
allow []object
A list of Rules for allowing use of this token. A node must match at least one allow rule in order to use this token.
aws_account string
aws_arn string
aws_organization_id string
aws_regions []string
aws_role string
iid_ttl string
The TTL to use for AWS EC2 Instance Identity Documents used to join the cluster with this token. This should be a duration string such as "8h" or "6mo".
integration string
Integration name which provides credentials for validating join attempts. Currently only in use for validating the AWS Organization ID in the IAM Join method.
azure object
The Azure-specific configuration used with the "azure" join method.
allow []object
A list of Rules for allowing use of this token. A node must match at least one allow rule in order to use this token.
resource_groups []string
subscription string
tenant string
azure_devops object
The Azure Devops-specific configuration used with the "azure_devops" join method.
allow []object
A list of Rules for allowing use of this token. A node must match at least one allow rule in order to use this token.
definition_id string
pipeline_name string
project_id string
project_name string
repository_ref string
repository_uri string
repository_version string
sub string
organization_id string
The UUID of the Azure DevOps organization that this join token will grant access to. This is used to identify the correct issuer verification of the ID token. This is a required field.
bot string
The bot associated with this join token, if any, as a scope-qualified name of the form `<scope>::<bot-name>` (e.g. "/staging/west::mybot"). The scope component must be a descendant of or equivalent to the token's resource scope. Mutually exclusive with assigned_scope.
bound_keypair object
Configuration specific to the "bound_keypair" join method.
onboarding object
Parameters related to initial onboarding and keypair registration.
initial_public_key string
must_register_before string
format: date-time
registration_secret string
recovery object
Parameters related to recovery after identity expiration, including the initial join.
limit integer
format: int32
mode string
rotate_after string
An optional timestamp that forces clients to perform a keypair rotation on the next join or recovery attempt after the given date. If `LastRotatedAt` is unset or before this timestamp, a rotation will be requested. It is recommended to set this value to the current timestamp if a rotation should be triggered on the next join attempt.
format: date-time
gcp object
The GCP-specific configuration used with the "gcp" join method.
allow []object
A list of Rules for allowing use of this token. A node must match at least one allow rule in order to use this token.
locations []string
project_ids []string
service_accounts []string
generic_oidc object
Configuration specific to the "generic_oidc" join method.
allow_any []object
Complex rules evaluated using "OR" semantics. If any rules are specified, at least one rule must evaluate to `true` for the join attempt/ to be allowed. These rules are evaluated after `must_match_fields`, if any field matchers are specified in that block. Note that at least one rule, either in `must_match_fields` or `allow_any`, must be specified for any join attempts to succeed.
conditions []object
attribute string
eq object
value string
in object
values []string
not_eq object
value string
not_in object
values []string
expression string
audience string
The expected JWT audience value (required). This must match or be included in the list of `aud` values in the JWT provided by the client when joining. For providers that do not allow you to configure this value yourself (this is technically an OIDC spec violation, but is common), use the value they provide. Otherwise, we recommend using a value that uniquely identifies the Teleport cluster and join token. For example, you can use this scheme: $clusterName/$tokenName For a cluster named `example.teleport.sh` and a token named `example`, this would result in an audience of `example.teleport.sh/example`. If you prefer, you can also use a UUID instead of the token name. Note that you will need to configure the matching value with the issuer, usually at request time.
insecure_allow_http_issuer boolean
If set, disables the requirement that the issuer must use HTTPS.
issuer string
The expected `iss` value as written in the JWT you wish to trust. Unless `static_jwks` is configured, this issuer must be accessible over HTTPS to the Teleport cluster and must serve valid OIDC metadata, including discovery configuration and JWKS keys.
must_match_fields object
"Must match" fields perform simple comparison matches using "AND" semantics. Rules are specified by mirroring the structure of the JWT, using values that are expected to be equal to those on the incoming token. These field matching rules can only be used to compare simple values: strings, numbers, booleans, and nested fields. Complex values, including lists, will need to use `allow_any` expression rules instead. If any field match rules are specified, all must be equal to corresponding JWT fields for the join attempt to succeed. If complex rules are specified in `allow_any`, those are evaluated after `must_match_fields`. If `must_match_fields` is not specified or is empty, only rules in `allow_any` are evaluated. These rules can be used as "global" rules that apply to all join attempts. For example, you can use these to ensure all attempts originate from your organization, then use `allow_any` rules to allow individual repositories, pipelines, or workspaces. Note that at least one rule, either in `must_match_fields` or `allow_any`, must be specified for any join attempts to succeed.
static_jwks string
An optional static JWKS value that can be used to specify JWKS keys when either OIDC discovery is either not supported by the provider or the discovery configuration is not accessible to Teleport. When set, configuration and JWKS keys will not be fetched from the URL contained in `issuer` and JWTs will be validated using the key set specified here.
tls_ca string
A TLS CA certificate that should be used to verify requests for OIDC metadata from the issuer instead of Teleport's CA store, useful if the issuer is not public or otherwise uses a self-signed certificate. If unset, the standard web PKI root certificates will be used to verify the connection to the issuer when fetching OIDC metadata. Note that this value only applies to requests using this token, and will be used instead of and not in addition to the system CA store, and will need to be updated manually if the remote CA is updated.
github object
Configuration specific to the "github" join method.
allow []object
allow is a set of claim-matching fields evaluated against the GitHub Actions OIDC token.
actor string
enterprise string
enterprise_id string
environment string
ref string
ref_type string
repository string
repository_owner string
sub string
workflow string
enterprise_server_host string
enterprise_server_host allows joining from runners associated with a GitHub Enterprise Server instance. When unconfigured, tokens will be validated against github.com, but when configured to the host of a GHES instance, then the tokens will be validated against host. This value should be the hostname of the GHES instance, and should not include the scheme or a path. The instance must be accessible over HTTPS at this hostname and the certificate must be trusted by the Auth Service.
enterprise_slug string
enterprise_slug allows the slug of a GitHub Enterprise organisation to be included in the expected issuer of the OIDC tokens. This is for compatibility with the `include_enterprise_slug` option in GHE. This field should be set to the slug of your enterprise if this is enabled. If this is not enabled, then this field must be left empty. This field cannot be specified if `enterprise_server_host` is specified. See https://docs.github.com/en/enterprise-cloud@latest/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect#customizing-the-issuer-value-for-an-enterprise for more information about customized issuer values.
static_jwks string
static_jwks disables fetching of the GHES signing keys via the JWKS/OIDC endpoints, and allows them to be directly specified. This allows joining from GitHub Actions in GHES instances that are not reachable by the Teleport Auth Service.
immutable_labels object
Immutable labels that should be applied to any resulting resources provisioned using this token.
ssh object
Labels that should be applied to SSH nodes.
join_method string
The joining method required in order to use this token. Note that not all join methods support joining with scoped tokens.
kubernetes object
The Kubernetes-specific configuration used with the "kubernetes" join method.
allow []object
A list of Rules for allowing use of this token. A node must match at least one allow rule in order to use this token.
service_account string
service_account_name string
service_account_namespace string
oidc object
The configuration specific to the `oidc` type.
insecure_allow_http_issuer boolean
issuer string
static_jwks object
The configuration specific to the `static_jwks` type.
jwks string
type string
Controls which behavior should be used for validating the Kubernetes Service Account token. Supported values: - `in_cluster` - `static_jwks` - `oidc`
oracle object
The Oracle-specific configuration used with the "oracle" join method.
allow []object
A list of Rules for allowing use of this token. A node must match at least one allow rule in order to use this token.
instances []string
parent_compartments []string
regions []string
tenancy string
roles []string
The list of roles associated with the token. They will be converted to metadata in the SSH and X509 certificates issued to the user of the token.
usage_mode string
The usage mode of the token. Can be "single_use" or "unlimited". Single use tokens can only be used to provision a single resource. Unlimited tokens can be be used to provision any number of resources until it expires.
status object
Status defines the observed state of the Teleport resource
conditions []object
Conditions represent the latest available observations of an object's state
lastTransitionTime string required
lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
message string required
message is a human readable message indicating details about the transition. This may be an empty string.
maxLength: 32768
observedGeneration integer
observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
format: int64
minimum: 0
reason string required
reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
minLength: 1
maxLength: 1024
status string required
status of the condition, one of True, False, Unknown.
enum: True, False, Unknown
type string required
type of condition in CamelCase or in foo.example.com/CamelCase.
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
maxLength: 316
teleportResourceID integer
format: int64

No matches. Try .spec.assigned_scope for an exact path