What you’ll need
- A DOKS cluster reachable with
kubectl. If you don’t have one, DigitalOcean’s guide to creating clusters covers thedoctlCLI, API, and control panel. - A DigitalOcean account.
- An ngrok account.
kubectland Helm 3.0.0+ installed on your local workstation.- The ngrok Kubernetes Operator installed on your cluster.
- A reserved domain from the ngrok dashboard or API; this guide refers to it as
NGROK_DOMAIN.
Set up your cluster and demo app
This guide assumes a DOKS cluster reachable withkubectl and the ngrok Kubernetes Operator installed, as covered in the prerequisites above.
This guide uses the Bookinfo app from DigitalOcean’s sample Kubernetes apps repository.
Clone the repository and deploy Bookinfo:
Add ngrok’s Kubernetes ingress to your demo app
Your Bookinfo app is running, but you have no way to reach it from outside the cluster. Deploy anIngress resource that tells the ngrok Kubernetes Operator to route traffic arriving on your reserved domain to the productpage service on port 9080, which serves the Bookinfo UI.
Save the following manifest as bookinfo-ingress.yaml, replacing NGROK_DOMAIN with the domain you reserved:
showLineNumbers
https://NGROK_DOMAIN in your browser to see your Bookinfo app, then click Normal user to explore.
ngrok routes requests to the ngrok Kubernetes Operator, which forwards them to the productpage service.
Add OAuth authentication to your demo app
Now that your demo app is publicly accessible through ngrok, you can add capabilities like authentication without deploying extra infrastructure. This section restricts access to Google accounts under a specific domain. With the Traffic Policy system and theoauth action, ngrok handles OAuth entirely on its network.
You don’t need to add services to your cluster or change any routes, because ngrok authenticates and authorizes requests before they reach your endpoint.
To enable the oauth action, create an NgrokTrafficPolicy custom resource and apply it to your Ingress with an annotation.
You can also apply the policy to a specific backend or as the default backend for an Ingress.
See the doc on using the Operator with Ingresses for details.
Edit your bookinfo-ingress.yaml file with the following.
Note the new annotations field and the NgrokTrafficPolicy CR, which must be in the same namespace as the Ingress.
showLineNumbers
example.com.
Update the NgrokTrafficPolicy portion of your manifest after changing example.com to your domain.