Skip to main content
This guide shows you how to add public ingress to an app running on DigitalOcean Kubernetes (DOKS). You’ll use the ngrok Kubernetes Operator to route public traffic to the app, then secure it with OAuth.

What you’ll need

  • A DOKS cluster reachable with kubectl. If you don’t have one, DigitalOcean’s guide to creating clusters covers the doctl CLI, API, and control panel.
  • A DigitalOcean account.
  • An ngrok account.
  • kubectl and Helm 3.0.0+ installed on your local workstation.
  • The ngrok Kubernetes Operator installed on your cluster.
  • A reserved domain from the ngrok dashboard or API; this guide refers to it as NGROK_DOMAIN.

Set up your cluster and demo app

This guide assumes a DOKS cluster reachable with kubectl and the ngrok Kubernetes Operator installed, as covered in the prerequisites above. This guide uses the Bookinfo app from DigitalOcean’s sample Kubernetes apps repository. Clone the repository and deploy Bookinfo:
Confirm the workloads are running before continuing:
To expose a different app, deploy it now and adjust the service name and port in the ingress below.

Add ngrok’s Kubernetes ingress to your demo app

Your Bookinfo app is running, but you have no way to reach it from outside the cluster. Deploy an Ingress resource that tells the ngrok Kubernetes Operator to route traffic arriving on your reserved domain to the productpage service on port 9080, which serves the Bookinfo UI. Save the following manifest as bookinfo-ingress.yaml, replacing NGROK_DOMAIN with the domain you reserved:
showLineNumbers
Apply it to your cluster:
Open https://NGROK_DOMAIN in your browser to see your Bookinfo app, then click Normal user to explore. ngrok routes requests to the ngrok Kubernetes Operator, which forwards them to the productpage service.

Add OAuth authentication to your demo app

Now that your demo app is publicly accessible through ngrok, you can add capabilities like authentication without deploying extra infrastructure. This section restricts access to Google accounts under a specific domain. With the Traffic Policy system and the oauth action, ngrok handles OAuth entirely on its network. You don’t need to add services to your cluster or change any routes, because ngrok authenticates and authorizes requests before they reach your endpoint. To enable the oauth action, create an NgrokTrafficPolicy custom resource and apply it to your Ingress with an annotation. You can also apply the policy to a specific backend or as the default backend for an Ingress. See the doc on using the Operator with Ingresses for details. Edit your bookinfo-ingress.yaml file with the following. Note the new annotations field and the NgrokTrafficPolicy CR, which must be in the same namespace as the Ingress.
showLineNumbers
Re-apply your configuration:
When you open your demo app again, ngrok asks you to log in with Google. To limit access to just yourself or your colleagues, tighten the policy. Use expressions and CEL interpolation to reject OAuth logins that aren’t under example.com. Update the NgrokTrafficPolicy portion of your manifest after changing example.com to your domain.
Check your deployed app again. If you log in with an email that isn’t under your domain, ngrok rejects the request.

What’s next?

You’ve used the open source ngrok Kubernetes Operator to add public ingress to an app on a cluster managed by DigitalOcean without managing complex Kubernetes networking. Because ngrok handles ingress and middleware execution, you can follow the same process for your production apps. To go further, explore the Kubernetes docs for how the Operator works and how to integrate ngrok with an existing production cluster, or try bindings and endpoint pooling.