Skip to content

Restricting GUI user access to SSH nodes without labels #37251

Closed Answered by zmb3
evrynet1 asked this question in Q&A
Discussion options

You must be logged in to vote

Is there any option to restrict teleport user access to certain SSH nodes based on the "Host" name rather than using node labels?

No, Teleport's RBAC system is based on labels and not other attributes.

Since they have root access to the SSH nodes they can easily adjust the client config [...] allowing them full access to all SSH nodes in the cluster

Can you elaborate a bit on this? I understand with root access they could change the labels of the node they already have access to, but I don't see how it applies to nodes they don't have access to.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by evrynet1
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants