usage: teleport start [] Starts the Teleport service. Flags: -d, --[no-]debug Enable verbose logging to stderr --[no-]insecure-no-tls Disable TLS for the web socket -r, --roles Comma-separated list of roles to start with [proxy,node,auth,app,db] --pid-file Full path to the PID file. By default no PID file will be created --advertise-ip IP to advertise to clients if running behind NAT -l, --listen-ip IP address to bind to [0.0.0.0] --auth-server Address of the auth server [127.0.0.1:3025] --token Invitation token or path to file with token value. Used to register with an auth server [none] --ca-pin CA pin to validate the Auth Server (can be repeated for multiple pins) --nodename Name of this node, defaults to hostname -c, --config Path to a configuration file [/etc/teleport.yaml] --apply-on-startup Path to a non-empty YAML file containing resources to apply on startup. Works on initialized clusters, unlike --bootstrap. Only supports the following types: token. --bootstrap Path to a non-empty YAML file containing bootstrap resources (ignored if already initialized) --labels Comma-separated list of labels for this node, for example env=dev,app=web --diag-addr Start diagnostic prometheus and healthz endpoint. --[no-]permit-user-env Enables reading of ~/.tsh/environment when creating a session --[no-]insecure Insecure mode disables certificate validation --[no-]fips Start Teleport in FedRAMP/FIPS 140-2 mode. --[no-]skip-version-check Skip version checking between server and client. Aliases: Notes: --roles=node,proxy,auth,app This flag tells Teleport which services to run. By default it runs auth, proxy, and node. In a production environment you may want to separate them. --token=xyz or --token=/tmp/token This token is needed to connect a node or web app to an auth server. Get it by running "tctl tokens add --type=node" or "tctl tokens add --type=app" to join an SSH server or web app to your cluster respectively. It's used once and ignored afterwards. Examples: > teleport start By default without any configuration, teleport starts running as a single-node cluster. It's the equivalent of running with --roles=node,proxy,auth > teleport start --roles=node --auth-server=10.1.0.1 --token=xyz --nodename=db Starts a node named 'db' running in strictly SSH mode role, joining the cluster serviced by the auth server running on 10.1.0.1 > teleport start --roles=node --auth-server=10.1.0.1 --labels=db=master Same as the above, but the node runs with db=master label and can be connected to using that label in addition to its name. > teleport app start --token=xyz --auth-server=proxy.example.com:3080 \ --name="example-app" \ --uri="http://localhost:8080" Starts an app server that proxies the application "example-app" running at http://localhost:8080. > teleport app start --token=xyz --auth-server=proxy.example.com:3080 \ --name="example-app" \ --uri="http://localhost:8080" \ --labels=group=dev Same as the above, but the app server runs with "group=dev" label which only allows access to users with the role "group=dev". > teleport db start --token=xyz --auth-server=proxy.example.com:3080 \ --name="example-db" \ --protocol="postgres" \ --uri="localhost:5432" Starts a database server that proxies PostgreSQL database "example-db" running at localhost:5432. The database must be configured with Teleport CA and key pair issued by "tctl auth sign --format=db". > teleport db start --token=xyz --auth-server=proxy.example.com:3080 \ --name="aurora-db" \ --protocol="mysql" \ --uri="example.cluster-abcdefghij.us-west-1.rds.amazonaws.com:3306" \ --aws-region=us-west-1 \ --labels=env=aws Starts a database server that proxies Aurora MySQL database running in AWS region us-west-1 which only allows access to users with the role "env=aws". ERROR: path '/etc/teleport.yaml' does not exist usage: teleport start [] Starts the Teleport service. Flags: -d, --[no-]debug Enable verbose logging to stderr --[no-]insecure-no-tls Disable TLS for the web socket -r, --roles Comma-separated list of roles to start with [proxy,node,auth,app,db] --pid-file Full path to the PID file. By default no PID file will be created --advertise-ip IP to advertise to clients if running behind NAT -l, --listen-ip IP address to bind to [0.0.0.0] --auth-server Address of the auth server [127.0.0.1:3025] --token Invitation token or path to file with token value. Used to register with an auth server [none] --ca-pin CA pin to validate the Auth Server (can be repeated for multiple pins) --nodename Name of this node, defaults to hostname -c, --config Path to a configuration file [/etc/teleport.yaml] --apply-on-startup Path to a non-empty YAML file containing resources to apply on startup. Works on initialized clusters, unlike --bootstrap. Only supports the following types: token. --bootstrap Path to a non-empty YAML file containing bootstrap resources (ignored if already initialized) --labels Comma-separated list of labels for this node, for example env=dev,app=web --diag-addr Start diagnostic prometheus and healthz endpoint. --[no-]permit-user-env Enables reading of ~/.tsh/environment when creating a session --[no-]insecure Insecure mode disables certificate validation --[no-]fips Start Teleport in FedRAMP/FIPS 140-2 mode. --[no-]skip-version-check Skip version checking between server and client. Aliases: Notes: --roles=node,proxy,auth,app This flag tells Teleport which services to run. By default it runs auth, proxy, and node. In a production environment you may want to separate them. --token=xyz or --token=/tmp/token This token is needed to connect a node or web app to an auth server. Get it by running "tctl tokens add --type=node" or "tctl tokens add --type=app" to join an SSH server or web app to your cluster respectively. It's used once and ignored afterwards. Examples: > teleport start By default without any configuration, teleport starts running as a single-node cluster. It's the equivalent of running with --roles=node,proxy,auth > teleport start --roles=node --auth-server=10.1.0.1 --token=xyz --nodename=db Starts a node named 'db' running in strictly SSH mode role, joining the cluster serviced by the auth server running on 10.1.0.1 > teleport start --roles=node --auth-server=10.1.0.1 --labels=db=master Same as the above, but the node runs with db=master label and can be connected to using that label in addition to its name. > teleport app start --token=xyz --auth-server=proxy.example.com:3080 \ --name="example-app" \ --uri="http://localhost:8080" Starts an app server that proxies the application "example-app" running at http://localhost:8080. > teleport app start --token=xyz --auth-server=proxy.example.com:3080 \ --name="example-app" \ --uri="http://localhost:8080" \ --labels=group=dev Same as the above, but the app server runs with "group=dev" label which only allows access to users with the role "group=dev". > teleport db start --token=xyz --auth-server=proxy.example.com:3080 \ --name="example-db" \ --protocol="postgres" \ --uri="localhost:5432" Starts a database server that proxies PostgreSQL database "example-db" running at localhost:5432. The database must be configured with Teleport CA and key pair issued by "tctl auth sign --format=db". > teleport db start --token=xyz --auth-server=proxy.example.com:3080 \ --name="aurora-db" \ --protocol="mysql" \ --uri="example.cluster-abcdefghij.us-west-1.rds.amazonaws.com:3306" \ --aws-region=us-west-1 \ --labels=env=aws Starts a database server that proxies Aurora MySQL database running in AWS region us-west-1 which only allows access to users with the role "env=aws". ERROR: path '/etc/teleport.yaml' does not exist