Skip to main content
This guide shows you how to add public ingress to an app running on a Kubernetes cluster managed by Rafay. You’ll install the ngrok Kubernetes Operator, optionally packaged as a Rafay blueprint, then use it to route public traffic to a demo app through a secure tunnel. Rafay is a SaaS-based cloud controller that helps platform and DevOps teams manage their Kubernetes clusters and cloud environments. Packaging the ngrok Kubernetes Operator as a blueprint lets you apply the same ingress setup to any number of Rafay-managed clusters.

What you’ll need

  • A Rafay account.
  • An account with the privileges to create a cluster on one of the following managed Kubernetes services: Amazon EKS, Azure AKS, Google GKE, or a data center/edge or private cloud where you can deploy an upstream Kubernetes cluster.
  • An ngrok account.
  • kubectl and Helm 3.0.0+ installed on your local workstation.
  • A reserved domain from the ngrok dashboard or API; this guide refers to it as NGROK_DOMAIN.

Create a new cluster with Rafay

This guide assumes a cluster provisioned and managed by Rafay. If you don’t have one, follow the getting started guide for your Kubernetes service in Rafay’s documentation, completing the Provision steps for your provider.

Install the ngrok Kubernetes Operator

First, gather the ngrok credentials the Operator needs:
  • Log in to the ngrok dashboard to get your authtoken and create an API key.
  • Create a file named ngrok-values.yaml with the values below, replacing the placeholders with your authtoken and API key:
The Operator installs from the official Helm chart in the https://charts.ngrok.com repository. For the standalone Helm install with your ngrok credentials, see the Kubernetes ingress quickstart; for chart configuration options, see the Helm configuration reference. To install it through Rafay instead, add https://charts.ngrok.com as a repository, create a Helm 3 add-on for the ngrok-operator chart with your ngrok-values.yaml values file, then add that add-on to a blueprint and apply the blueprint to your cluster. See Rafay’s documentation for creating repositories, add-ons, and blueprints. Rafay deploys the ngrok Kubernetes Operator when it applies the blueprint.

Deploy an app with Rafay

You’ll deploy the AKS Store demo app and an ngrok ingress as a Rafay workload.
  • Download the AKS Store manifest to your local workstation:
  • Add the following ingress configuration to the bottom of your aks-store-workload.yaml file, replacing NGROK_DOMAIN with the domain you reserved. This tells the ngrok Kubernetes Operator to route traffic arriving on NGROK_DOMAIN to the store-front service on port 80.
    showLineNumbers
  • Create a Rafay workload from the aks-store-workload.yaml file using the default namespace, then place it on your cluster and publish it. See Rafay’s documentation for creating and publishing workloads. Give Rafay a few minutes to provision the AKS Store resources.
  • Navigate to your ngrok domain (for example, https://NGROK_DOMAIN) in your browser to see the app deployed and publicly networked via Rafay, Kubernetes, and ngrok. ngrok routes requests through the ngrok Kubernetes Operator to the store-front service.

What’s next?

You’ve used the open source ngrok Kubernetes Operator to add public ingress to a demo app on a Rafay-managed cluster. Because ngrok handles ingress and middleware execution, you can follow the same process for your other apps, and packaging the Operator as a Rafay blueprint lets you repeat it across clusters. Learn more about the ngrok Kubernetes Operator in the Kubernetes docs, or contribute to its development on GitHub.