Skip to main content
This guide shows you how to add public ingress to an app running on Azure Kubernetes Service (AKS). You’ll use the ngrok Kubernetes Operator to route public traffic to the app through an encrypted tunnel, then secure it with OAuth.

What you’ll need

  • An AKS cluster with a demo app running. If you don’t have one, Microsoft’s AKS quickstart covers creating a cluster and deploying the AKS Store demo app this guide uses.
  • An ngrok account.
  • kubectl and Helm 3.0.0+ installed on your local workstation.
  • The ngrok Kubernetes Operator installed on your cluster.
  • A reserved domain from the ngrok dashboard or API; this guide refers to it as NGROK_DOMAIN.

Set up your cluster and demo app

This guide assumes an AKS cluster reachable with kubectl and a store-front service listening on port 80, which the AKS Store demo app provides. If you don’t have this yet, follow Microsoft’s AKS quickstart to create a cluster, connect to it with kubectl, and deploy the demo app. To expose a different app, deploy it now and adjust the service name and port in the ingress below. Confirm your workloads are running before continuing:

Add ngrok’s Kubernetes ingress to your demo app

Deploy an Ingress resource that tells the ngrok Kubernetes Operator to route traffic arriving on your reserved domain to the store-front service on port 80. Save the following manifest as store-ingress.yaml, replacing NGROK_DOMAIN with the domain you reserved:
showLineNumbers
Apply it to your cluster:
Confirm the ingress was created:
Open your reserved domain (for example, https://NGROK_DOMAIN) in a browser to see the demo app. ngrok routes requests to the ngrok Kubernetes Operator, which forwards them to the store-front service.

Add OAuth authentication to your demo app

Now that your demo app is publicly accessible through ngrok, you can add capabilities like authentication without deploying extra infrastructure. This section restricts access to Google accounts under a specific domain. With the Traffic Policy system and the oauth action, ngrok handles OAuth entirely on its network. You don’t need to add services to your cluster or change any routes, because ngrok authenticates and authorizes requests before they reach your endpoint. To enable the oauth action, create an NgrokTrafficPolicy custom resource and apply it to your Ingress with an annotation. You can also apply the policy to a specific backend or as the default backend for an Ingress. See the doc on using the Operator with Ingresses for details.
  • Edit your existing ingress YAML with the following. Note the new annotations field and the NgrokTrafficPolicy CR.
  • When you open your demo app again, ngrok asks you to log in with Google. To limit access to just yourself or your colleagues, tighten the policy.
  • Use expressions and CEL interpolation to reject OAuth logins that aren’t under example.com. Update the NgrokTrafficPolicy portion of your manifest after changing example.com to your domain.
  • Check your deployed app again. If you log in with an email that isn’t under your domain, ngrok rejects the request.

What’s next?

You’ve used the open source ngrok Kubernetes Operator to add public ingress to an app on AKS without managing complex Kubernetes networking. Because ngrok handles ingress and middleware execution, you can follow the same process for your production apps. To go further, explore the Kubernetes docs for how the Operator works and how to integrate ngrok with an existing production cluster, or try bindings and endpoint pooling.