[v17] Adds IC plugin status value to trigger IC group import #52879
+463
−450
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Backports #52682
The IC plugin automatically imports IC groups into Teleport on its
first run, and uses the plugin status block to mark the import as complete,
and is not required the next time the plugin starts up.
New functionality in
tctl
allows Teleport admins to edit the IC pluginresource in order to modify group, account and permission set filters.
At the moment, the group filters are only applied during tis initial import,
so changing them has no effect.
In order to allow changes to group import filters to have an effect, this this
patch adds a new value to the
AWSICGroupImportStatusCode
enueration thatindicates that the import process should be re-run the next time the plugin
restarts.