What you’ll need
- A remote or local Kubernetes cluster with Consul installed or minikube to set up a demo cluster locally.
- An ngrok account.
- kubectl and Helm 3.0.0+ installed on your local workstation.
- A reserved domain from the ngrok dashboard or API; this guide refers to it as
<NGROK_DOMAIN>.
Set up a local Consul service mesh on Kubernetes
This guide needs a Kubernetes cluster running a Consul service mesh with Consul Connect and the sidecar injector enabled. If you already have one, skip to Configure the ngrok Kubernetes Operator. If you don’t, follow HashiCorp’s Get Started with Consul on Kubernetes tutorial to create a cluster and install Consul. For a local cluster, minikube works. Make sure Consul Connect is enabled so the mesh can inject sidecars. Verify Consul is installed and all its pods are healthy before continuing:Configure the ngrok Kubernetes Operator
Consul requires a bit of extra configuration to work with ngrok’s Operator for Kubernetes ingress. You’ll need to use a pod annotation to enable the Consul Connect sidecar injector. This allows using Consul Connect to secure the traffic between the ngrok Kubernetes Operator and your services.-
First, create a Kubernetes Service for the ngrok Kubernetes Operator in the
consulnamespace. Consul relies on this to name services to declare Service Intentionsourceanddestinationvalues. -
Next, install the ngrok Kubernetes Operator into your cluster.
Its pods must join the Consul service mesh so they can proxy traffic to your other services.
You do this with two pod annotations: one to enable the Consul Connect sidecar injector and one to allow outbound traffic through the mesh.
Consul documents these annotations in Configure Operators for Consul on Kubernetes.
Follow the Kubernetes ingress quickstart to install the Operator with your ngrok credentials. Then set the annotations with a Helm upgrade, replacing the CIDR with your own:
Consul annotation: HashiCorp’s docs also mention the annotation
consul.hashicorp.com/transparent-proxy-exclude-inbound-ports.
This does not apply to the ngrok Kubernetes Operator, which creates an outbound connection for ingress rather than exposing ports.Helm: The backslashes escape the dots in the annotation keys, and --set-string keeps each value as a string rather than a boolean, which pod annotations require.Production: To manage your credentials with Infrastructure as Code or source control, see the Helm configuration reference.Install a sample application
Install a sample application to try out the service mesh and Operator combination. This guide uses the HashiCups Demo Application provided by HashiCorp. This application is a simple e-commerce application that allows users to order coffee cups. It has afrontend and public API services that are also backed by a private API and database.
These communicate with each other through the Consul service mesh.
It comes with nginx installed as a proxy for the frontend and Public API services.
Replace this with ngrok to provide public access and other features.
-
Clone the HashiCorp Learning Consul repo, which includes example applications for Consul and Kubernetes.
-
Install the HashiCups sample app in the
consulnamespace. It consists of several Services and Deployments that make up a tiered application. -
Replace the existing Service Intentions with new ones.
Service Intentions are how Consul configures the mesh to allow or deny traffic between services.
HashiCups ships with
nginxintentions to thefrontendandpublic-apiservices. Remove these and add new intentions that allow traffic from the ngrok Kubernetes Operator to thefrontendandpublic-apiservices.
frontend and public-api services.
Save the following manifests to a file and apply them with kubectl apply -f <file> -n consul.
Configure Public Ingress for the sample application
Now that the ngrok Kubernetes Operator can communicate with thefrontend service and public-api service through the Consul Service Mesh via Service Intentions, create an ingress to route traffic to the app.
Create ingress objects to route traffic to the frontend service and the public-api service.
<NGROK_DOMAIN> domain in your browser to see the HashiCups application.
Add OAuth protection to the app
Now that HashiCups is publicly accessible through ngrok, you can add Google OAuth to restrict access without deploying extra infrastructure. With the Traffic Policy system and theoauth action, ngrok handles OAuth entirely on its network.
You don’t need to add services to your cluster or change any routes, because ngrok authenticates and authorizes requests before they reach your endpoint.
To enable the oauth action, create an NgrokTrafficPolicy custom resource and apply it to your Ingress with an annotation.
You can also apply the policy to a specific backend or as the default backend for an Ingress.
See the doc on using the Operator with Ingresses for details.
Edit your existing ingress configuration with the following.
Note the new annotations field and the NgrokTrafficPolicy CR, which must be in the same namespace as the Ingress.
example.com.
Update the NgrokTrafficPolicy portion of your manifest after changing example.com to your domain.