This guide explains how to add ingress to any app running in Kubernetes and restrict access to users authorized through Microsoft Entra ID (formerly Azure Active Directory), using the ngrok Kubernetes Operator.
It walks you through (optionally) creating a Kubernetes cluster and example deployment, installing the Operator to expose your app through ngrok, and using the ngrok Kubernetes Operator’s Traffic Policy to enable SAML with Microsoft Entra ID as your identity provider for single sign-on.
The ngrok Kubernetes Operator is ngrok’s official controller for adding secure public ingress and middleware execution to your Kubernetes apps with ngrok.
Microsoft Entra ID is an identity and access management platform that helps administrators and DevOps engineers safeguard their organization’s multicloud environment with strong authentication and unified identity management.
The Operator and Microsoft Entra ID integrate so you can route public traffic to an app on a Kubernetes cluster and restrict access to users you authorize through Microsoft Entra ID.
What you’ll need
- An ngrok account.
- A Microsoft Azure account with access to an existing Microsoft Entra ID tenant or the ability to create a new tenant with a Microsoft Entra ID P1 or P2 license.
- A Kubernetes cluster (local or in a public cloud) with an app you want to make publicly accessible to specific users.
- kubectl and Helm 3.0.0+ installed on your local workstation.
- The ngrok Kubernetes Operator installed on your cluster.
- A reserved domain from the ngrok dashboard or API; this guide refers to it as
<NGROK_DOMAIN>.
1. Create a cluster and deploy an example app
This guide needs an app on a Kubernetes cluster to route traffic to.
It uses the Online Boutique demo, which exposes a frontend service on port 80.
If you already have a cluster and app, skip to 2. Add the ngrok Kubernetes Operator.
Otherwise, deploy Online Boutique by following Google’s microservices-demo instructions.
For a local cluster, minikube works.
Confirm your workloads are running before continuing:
2. Add the ngrok Kubernetes Operator
If you haven’t already, install the ngrok Kubernetes Operator so ngrok can route public traffic to your app.
Follow the Kubernetes ingress quickstart to install the Operator with your ngrok credentials.
You also need a reserved domain to serve as your NGROK_DOMAIN.
Reserve one from the ngrok dashboard or API.
Create a boutique-ingress.yaml file that tells the Operator to route traffic on your NGROK_DOMAIN to the Online Boutique frontend service.
Replace NGROK_DOMAIN in the manifest below with the domain you reserved (for example, one-two-three.ngrok.app).
To expose a different app, change metadata.name, service.name, and service.port.number to match it.
Apply the manifest:
Give your cluster a few moments to launch the necessary resources and for ngrok to pick up the new endpoint.
If you see an error when applying the manifest, confirm you updated the NGROK_DOMAIN value and re-apply.
Open your ngrok domain (for example, https://one-two-three.ngrok.app) in your browser to see the app, now served through ngrok.
3. Enable SAML with a Traffic Policy
Your Kubernetes-based app is now publicly accessible through ngrok.
To restrict access to authorized users with Microsoft Entra ID credentials, create a NgrokTrafficPolicy custom resource with the SAML action and apply it to your Ingress.
-
Create a file named
saml-policy.yaml with the following content:
-
Apply the Traffic Policy CR:
-
Update your
boutique-ingress.yaml to reference this policy with an annotation:
-
Re-apply the Ingress manifest:
-
Refer to the SAML action documentation to retrieve your SP Entity ID and ACS URL values, which you’ll need in the next step.
4. Create an enterprise app in Microsoft Entra ID
With a SAML Traffic Policy applied to your Ingress, configure Microsoft Entra ID to operate as your identity provider (IdP).
-
Open your Microsoft Entra ID tenant in the Azure console.
-
Click Enterprise applications in the left-hand sidebar, then + New application, then + Create your own application.
Give your app a name (for example,
online-boutique) and select Integrate any other application you don’t find in the gallery (Non-gallery).
-
Click Create to create your enterprise app; you’ll be taken to its Overview dashboard.
-
To give specific users or groups access to your app, click Assign users and groups and follow the steps, then go back to Overview.
-
Click Set up single sign on so users can sign in with their Microsoft Entra credentials, then choose SAML as the single sign-on protocol.
-
Click Edit in the Basic SAML Configuration box.
Refer to the SAML action documentation to retrieve your SP Entity ID and ACS URL, then copy them into the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) fields respectively.
Click Save before closing the modal.
-
In the SAML Certificates box, download the Federation Metadata XML.
With Microsoft Entra ID configured as your identity provider, update your Traffic Policy with the real IdP metadata.
-
Open your
saml-policy.yaml and replace YOUR_IDP_METADATA_XML with the contents of the Federation Metadata XML file you downloaded.
-
Re-apply the updated Traffic Policy:
6. Test authorization to your app using Microsoft Entra ID
You’ve finished integrating the ngrok Kubernetes Operator and Microsoft Entra ID.
Your app (the Online Boutique or a custom deployment) is now publicly accessible only to users authorized with their Microsoft Entra ID credentials.
-
Open an incognito or private browser window (or a different browser) and go to your
NGROK_DOMAIN.
You should see a single sign-on screen from Microsoft.
-
Enter credentials for a Microsoft account you assigned to your enterprise application in Microsoft Entra ID in step 4.
Behind the scenes, ngrok redirects you to your identity provider, Microsoft Entra ID, for authentication.
Once you sign in, or are already logged in, Microsoft Entra ID then returns a SAML assertion to ngrok, telling ngrok your authentication is confirmed and you have authorization to access the app.
Microsoft Entra ID will then redirect you back to your app.
What’s next?
You’ve now integrated the ngrok Kubernetes Operator with Microsoft Entra ID to restrict access to your app to only authenticated users.
With ngrok operating as middleware, handling both ingress to your Kubernetes cluster and the handshake with Microsoft Entra ID as an identity provider, you can deploy and secure new apps in a multi-cloud environment using your existing Microsoft/Azure identity and access management settings.
From an end user perspective, they only need to sign in once, using their Microsoft credentials, to authenticate themselves and access any number of applications you manage using Microsoft Entra ID.
From here, you have a few options:
Clean up
If you created a local cluster for the demo app, delete it (for example, minikube delete).
ngrok will delete your endpoint automatically.
To restore your previous authorization settings, open your Microsoft Entra ID tenant and delete your enterprise application.
Extend your ngrok Kubernetes Operator and Microsoft Entra ID integration
ngrok’s Traffic Policy system can secure multiple apps with single sign-on.
Combine NgrokTrafficPolicy resources with Ingress fan-out to route and secure several apps.
Custom domains and a circuit breaker are good next steps for production.
See the ngrok Kubernetes Operator GitHub repository and the Kubernetes Operator docs for more details.