Skip to main content

Identity Governance is available only with Teleport Enterprise. Start your free trial.

Start your free trial

Creating an Access List with the Custom Form

Report an Issue

The web UI's Custom Form creates an Access List by directly assigning existing roles to members and owners. Unlike the guided flows (Standing and Just-in-Time), it does not generate roles for you — you pick from roles that already exist in the cluster.

This guide will help you:

  • Decide when the Custom Form is the right fit
  • Create an Access List with the Teleport Web UI, tctl, or Terraform
  • Verify that members get access on login

When to use this flow

Use the Custom Form when:

  • You already have roles in the cluster that capture the access you want to grant, and you'd rather assign those roles than have the guided flow generate new ones.
  • You need fine-grained control over the role and trait grants that isn't exposed in the guided flow.
  • You're comfortable editing the underlying roles yourself.

If you'd rather have Teleport generate the roles for you from a resource picker, use the Standing Access Guide (access on login) or the Just-in-Time Access Guide (access on request).

Prerequisites

  • A running Teleport Enterprise cluster accessible at a hostname with a valid TLS certificate. If you want to get started with Teleport, sign up for a free trial or set up a demo environment.

  • The tctl and tsh clients, required only if creating the list with tctl or Terraform.

    Installing tctl and tsh clients
    1. Determine the version of your Teleport cluster. The tctl and tsh clients must be at most one major version behind your Teleport cluster version. Send a GET request to the Proxy Service at /v1/webapi/find and use a JSON query tool to obtain your cluster version. Replace teleport.example.com:443 with the web address of your Teleport Proxy Service:

      TELEPORT_DOMAIN=teleport.example.com:443
      TELEPORT_VERSION="$(curl -s https://$TELEPORT_DOMAIN/v1/webapi/find | jq -r '.server_version')"
    2. Follow the instructions for your platform to install tctl and tsh clients:

      Download the signed macOS .pkg installer for Teleport, which includes the tctl and tsh clients:

      curl -O https://cdn.teleport.dev/teleport-${TELEPORT_VERSION?}.pkg

      In Finder double-click the pkg file to begin installation.

      danger

      Using Homebrew to install Teleport is not supported. The Teleport package in Homebrew is not maintained by Teleport and we can't guarantee its reliability or security.

    Connecting with TLS routing disabled

    This guide's commands assume your Teleport cluster uses TLS routing (proxy_listener_mode: multiplex), where the tctl and tsh clients reach every Teleport service through the Proxy Service's web address on port 443. If you're not sure whether this applies to your cluster, check with whoever manages it.

    If your cluster uses separate listener ports instead, adjust ports as follows:

    • tsh commands (e.g., tsh login --proxy=...): continue using the Proxy Service web address on port 3080 (or 443 if behind a load balancer). Do not change these to port 3025.

    • Direct tctl or Auth Service API commands: use port 3025 for the Auth Service gRPC listener:

      tctl status --auth-server=teleport.example.com:3025
  • At least one user who will be a member of the list, preferably a user with no access to resources to verify the access flow later.

  • At least one resource enrolled in the cluster for the Access List to grant access to.

  • Permissions to create Access Lists, users, and roles. These are included in the preset editor role, or you can copy and paste the following into your own role:
    allow:
      rules:
      - resources:
        - access_list
        - user
        - role
        verbs:
        - read
        - list
        - create
        - update
        - delete
    

Step 1/2. Create the Access List

Choose how to create the list.

In the Teleport Web UI, hover over Add New from the sidebar menu then click Access List.

Enter a name and optional description for the list, then click Use Custom Form Instead.

The Custom Form is a single page split into three sections. Fill them out top to bottom, then click Create Access List at the bottom.

Basic Information

  • Title — required. The display name of the list.
  • Description — optional context.
  • Review recurrence — how often the list must be reviewed (frequency and day of month). Periodic reviews are how owners reaffirm that the right members are still on the list.
  • Deadline for first review — the first review date. Pick a date in the future.

List Owners

Owners manage members and membership requirements, and conduct periodic access reviews.

  • Eligibility (required roles) (optional) — restrict who can be added as an owner. A Teleport user assigned as an owner takes effect only if they hold every role listed here; if they later lose one, ownership has no effect until it is restored.

  • Owners — the users to enroll as owners.

  • Grants (optional) — roles an owner receives by being an owner. Typically used to grant the ability to review Access Requests for this list — the preset reviewer role is a common choice.

Members

Members are the users who receive the list's grants. Granting members access is the primary purpose of most Access Lists.

  • Eligibility (required roles) (optional) — restrict who can be a member. A user added as a member takes effect only if they hold every role listed here; if they lose one later, the list's grants no longer apply to them until it is restored.

  • Members — the users to enroll as members.

  • Grants — the roles members receive by being on the list.

Step 2/2. Verify the access

Log in as one of the members you added. The resources granted by the roles you assigned should appear in the resource list and you should be able to connect to them.

Next steps