SSH record contracts¶
The SSH record contracts module declares the contracts designating the SSH sessions Bastion must record. A contract binds user groups, sites and SSH applications; it applies to as many sites as needed.
Contract list¶
| Column | Description |
|---|---|
| Name | Contract name, preceded by a padlock icon. |
| Groups | Number of associated user groups. |
| Sites | Number of associated sites. |
| Applications | Number of associated SSH applications. |
As long as no contract exists, the grid shows No available contracts. The search field,
whose placeholder is Search, filters the list 700 ms after the last keystroke or
immediately with Enter. The grid footer offers an Items per page: selector set to 15,
25 or 50.
The toolbar carries the three standard actions, whose tooltips are Add, Properties (single selection) and Delete (multiple selection allowed). Double-clicking is equivalent to Properties.
Expand a row to see the detail
The arrow at the start of a row expands the contract: one row per domain, with the domain name in bold followed by its groups, then the list of sites, then the retained categories (in bold) and the individually retained applications. A tooltip repeats the same information in labelled form.
Add a contract¶
Clicking + opens the Add Contract window, made of two common fields and three tabs.
| Field | Description |
|---|---|
| Name | Mandatory. A value made of whitespace only is refused. |
| Description | Optional. |
The Validate button stays disabled until the three tabs are valid, that is until at least one group, one site and one application have been retained. The Previous and Next buttons at the bottom of the window move from one tab to the next.
A dual list — available groups on the left, retained ones on the right — topped by a Domain combo restricting the left list to the groups of one authentication domain. The search covers the group name and its domain. If no group is available, the list shows No user groups.
A dual list of the sites, with a Select All button. If no site is available, the list shows No Sites.
A tree of the SSH application categories, each category expanding onto its applications. Ticking a category retains all of its applications at once. Ticking a single application puts its category name in bold, to signal a partial selection; the bold disappears when no application is ticked in it any more. Unticking a category unticks all of its applications.
If no category exists, the tree shows No Categories.
Edit a contract¶
Select a row then click the Properties icon (or double-click). The Contract Edition window shows the same form, with the current selections pre-loaded in the three tabs.
Delete a contract¶
Select one or several contracts then click ×. A confirmation is requested: Are you sure you want to delete this access contract?, plural when the selection holds several.