Teleport is a very easy tool for centralized access control to infrastructure. It has open-source and licensed under Apache 2.0, so it should be possible to integrate it into the system.
Website: https://goteleport.com/
Sources: https://github.com/gravitational/teleport
Description
Details
- Version
- -
- Is it a breaking change?
- Perfectly compatible
- Issue type
- Feature (new functionality)
Event Timeline
The Teleport can be run in a container:
https://goteleport.com/docs/setup/guides/docker/
This was blocked by the fact that Teleport changed its license to a modified Apache 2.0 that didn't allow unlimited distribution and limited usage to organizations below 100 employees and certain revenue thresholds.
However, the current README (https://github.com/gravitational/teleport?tab=readme-ov-file#license) says:
The Teleport API module (all code in this repository under /api) is available under the Apache 2.0 license. The remainder of the source code in this repository is available under the GNU Affero General Public License. Users compiling Teleport from source must comply with the terms of this license. Teleport Community Edition builds distributed on http://goteleport.com/download are available under a modified Apache 2.0 license.
Which implies that now it's only the official binary package that has usage restrictions, but if we build it from source, then it is open-source and redistributable.
Frankly, this doesn't make me feel safe to redistribute it, since they clearly want to limit its usage, if they kept official builds under a restricted license. My interpretation of the spirit of it is that they want to limit official build usage to small organizations and force organizations that have the resources to build it from source to make their own builds and share all modifications according to AGPLv3.
So it's difficult to predict how they will react if someone starts producing and distributing builds to general public. We can ask, of course.
Size and broad demand for this feature remain a concern for integrating it into mainline VyOS, of course.