Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Locking a role which grants access to an AWS ARN should revoke active AWS sessions spawned using that role #51178

Open
webvictim opened this issue Jan 17, 2025 · 0 comments
Labels
application-access aws Used for AWS Related Issues. bug sales-onboarding Issues related to prospects unlocks-potential Unlocks previously undocumented product potential ux

Comments

@webvictim
Copy link
Contributor

Somewhat debatable whether this is a bug or a feature request - we can go with bug for now (as I think it's unexpected behaviour in context) and change if needed.

Expected behavior

Locking a role which grants access to AWS ARN(s) should revoke/terminate active Teleport-initiated sessions which are using that ARN.

Current behavior

Locking a role which grants access to AWS ARN(s) only prevents future sessions from being spawned and does not revoke any active STS tokens for the ARN that Teleport has issued.

Bug details:

  • Teleport version: 17.1.6
@webvictim webvictim added application-access aws Used for AWS Related Issues. bug sales-onboarding Issues related to prospects unlocks-potential Unlocks previously undocumented product potential ux labels Jan 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
application-access aws Used for AWS Related Issues. bug sales-onboarding Issues related to prospects unlocks-potential Unlocks previously undocumented product potential ux
Projects
None yet
Development

No branches or pull requests

1 participant