← all publishers

gravitational

@gravitational source repo

7 published skills

  1. Flaky Test · gravitational
    Run when the user asks to investigate, troubleshoot, or fix a flaky Go test.
    0
    installs
  2. Teleport Discovery · gravitational bundle
    Configure and troubleshoot Teleport auto-discovery for AWS EC2 instances, AWS EKS clusters, and Azure VMs via the Teleport discovery Terraform module. Use to set up or extend auto-discovery, add a region, tag, or subscription, apply the discovery Terraform, check enrollment status, or diagnose why cloud resources are not enrolling. Not for GCP, AWS RDS or database discovery, static or manual join-token enrollment, or Teleport configuration unrelated to discovery.
    0
    installs
  3. Teleport Acl Review · gravitational bundle
    Review Teleport access lists that are due for audit. Use when the user asks to review access lists, audit Teleport ACLs, check which access lists need attention, perform periodic access list reviews, recertify access, or manage Teleport access list compliance. Trigger on phrases like "review access lists", "which access lists need review", "audit my ACLs", "recertify access lists", or any mention of Teleport access list reviews. Also trigger when the user follows up on access list findings from a previous command.
    0
    installs
  4. Teleport Investigate · gravitational bundle
    Use when investigating identity or resource activity in a Teleport cluster. Covers `tctl investigate` filter semantics, fast facet-only exploration, custom Lucene query construction, and token-efficient parsing patterns.
    0
    installs
  5. Teleport Access Review · gravitational bundle
    Use when reviewing who can access which resources in a Teleport cluster, or whether that access is actually used — access list / ACL recertification, "who can reach this database/server", "what can this user access", attesting access for audit/compliance, and finding dormant or unused standing privileges. Covers `tctl access-review`, the `access_path` SQL query language, output semantics, and combining it with `tctl investigate`.
    0
    installs
  6. Teleport Acl Lifecycle · gravitational bundle
    Use for Teleport access list work with tctl; listing available resources (servers, databases, apps, etc.) before choosing an access grant target, creating new access lists, updating existing lists, or deleting/retiring lists. Trigger for requests like "give alice access", "create an access list", "standing access", "Access Request", "custom access list", "show/list apps", "show AWS IC permission sets", "add AWS IC to this list", "change owners/members/access", "remove access", "delete/retire/tear down an access list". Handles access-type lists where Teleport creates supporting roles, and custom lists that grant existing roles/traits.
    0
    installs
  7. Teleport Session Review · gravitational bundle
    Review and investigate Teleport session recordings. Use when the user asks to review or audit recorded sessions, find out what happened in a session, or search sessions by what occurred in them (e.g. "sessions that touched production databases", "who ran sudo on prod"). Covers common security workflows such as SOC risk triage of the riskiest sessions, periodic compliance reviews of production access, threat hunting for techniques (privilege escalation, persistence, data exfiltration, SSH config tampering, secret exposure), and incident-response pivots ("what did this user do on that host"). Also lists recent SSH/db/Kubernetes/desktop recordings, summarizes a session, and downloads or plays one back. Trigger on phrases like "review session recordings", "search session recordings", "what happened in session <id>", "find risky sessions", or any mention of Teleport session recordings or session summaries. Also trigger when following up on a session from a previous command.
    0
    installs