Choose between bundled IANA tzdata or host system tzdata for Teleport’s DST‑aware timestamp conversion
0 reputation · 19 Sept 2023, 07:03 UTC
0 reputation · 19 Sept 2023, 07:03 UTC
Ensure that audit log timestamps and time‑based role expressions are displayed and evaluated with correct daylight‑saving adjustments for any regional time zone chosen by administrators or users.
Teleport stores all event timestamps in UTC and converts them for display using either the IANA time‑zone database bundled with the binary or the host system’s tzdata. It is unclear whether the conversion applies the current DST rules from the selected zone at runtime or uses fixed offsets from the bundled tzdata snapshot, and how outdated host tzdata might affect the result.
29275 reputation · 19 Sept 2023, 08:01 UTC
Use the bundled IANA tzdata that ships with Teleport, and keep Teleport reasonably current. By default Teleport sets the ZONEINFO environment variable to its own bundled tzdata directory, so Go's time.LoadLocation resolves zones from that snapshot rather than from the host. That is what makes DST-aware conversions identical across nodes running the same Teleport version, regardless of operating system.
Do not deliberately defer to host system tzdata. If ZONEINFO is unset or overridden, conversion falls back to the host's zoneinfo database, and DST handling then depends on each machine's IANA tzdata version.
Confirmed behavior: Teleport points ZONEINFO at a bundled IANA tzdata directory at startup. With ZONEINFO set, the Go runtime uses that snapshot instead of the host's zoneinfo files.
Likely explanation: DST rules are evaluated at conversion time from the bundled snapshot, not from live host data. The snapshot is refreshed as part of Teleport releases, so the rules reflect the IANA version current as of that release. The same Teleport version therefore produces the same conversion on heterogeneous hosts.
Uncertainty worth flagging for review: the exact bundled tzdata version and the exact bundled path can differ between releases and packaging methods. Treat path details as indicative and confirm them in your own deployment rather than assuming a fixed layout.
ZONEINFO is set for the running Teleport process and that it points inside the Teleport installation rather than at a system zoneinfo path.teleport version. Compare the release date against IANA tzdata release notes for that period to judge how recent the bundled snapshot is.teleport version
# inspect the environment of the running process
ps e -p <pid> | grep ZONEINFO
The recommendation holds unless ZONEINFO is intentionally overridden or cleared in your environment. If you can confirm whether it is overridden in your containers or systemd unit, that is the one detail that would change the advice from "use the default" to "enforce the variable explicitly."
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.