What you’ll need
- An AKS cluster with a demo app running. If you don’t have one, Microsoft’s AKS quickstart covers creating a cluster and deploying the AKS Store demo app this guide uses.
- An ngrok account.
kubectland Helm 3.0.0+ installed on your local workstation.- The ngrok Kubernetes Operator installed on your cluster.
- A reserved domain from the ngrok dashboard or API; this guide refers to it as
NGROK_DOMAIN.
Set up your cluster and demo app
This guide assumes an AKS cluster reachable withkubectl and a store-front service listening on port 80, which the AKS Store demo app provides.
If you don’t have this yet, follow Microsoft’s AKS quickstart to create a cluster, connect to it with kubectl, and deploy the demo app.
To expose a different app, deploy it now and adjust the service name and port in the ingress below.
Confirm your workloads are running before continuing:
Add ngrok’s Kubernetes ingress to your demo app
Deploy anIngress resource that tells the ngrok Kubernetes Operator to route traffic arriving on your reserved domain to the store-front service on port 80.
Save the following manifest as store-ingress.yaml, replacing NGROK_DOMAIN with the domain you reserved:
showLineNumbers
https://NGROK_DOMAIN) in a browser to see the demo app.
ngrok routes requests to the ngrok Kubernetes Operator, which forwards them to the store-front service.
Add OAuth authentication to your demo app
Now that your demo app is publicly accessible through ngrok, you can add capabilities like authentication without deploying extra infrastructure. This section restricts access to Google accounts under a specific domain. With the Traffic Policy system and theoauth action, ngrok handles OAuth entirely on its network.
You don’t need to add services to your cluster or change any routes, because ngrok authenticates and authorizes requests before they reach your endpoint.
To enable the oauth action, create an NgrokTrafficPolicy custom resource and apply it to your Ingress with an annotation.
You can also apply the policy to a specific backend or as the default backend for an Ingress.
See the doc on using the Operator with Ingresses for details.
- Edit your existing ingress YAML with the following.
Note the new
annotationsfield and theNgrokTrafficPolicyCR.
- When you open your demo app again, ngrok asks you to log in with Google. To limit access to just yourself or your colleagues, tighten the policy.
-
Use expressions and CEL interpolation to reject OAuth logins that aren’t under
example.com. Update theNgrokTrafficPolicyportion of your manifest after changingexample.comto your domain.
- Check your deployed app again. If you log in with an email that isn’t under your domain, ngrok rejects the request.