What you’ll need
- An AWS EKS cluster reachable with
kubectl. If you don’t have one, follow AWS’s Get started with Amazon EKS guide. - An ngrok account.
kubectland Helm 3.0.0+ installed on your local workstation.- The ngrok Kubernetes Operator installed on your cluster.
- A reserved domain from the ngrok dashboard or API; this guide refers to it as
NGROK_DOMAIN. On a free account, this must be a static subdomain, which you can claim from the banner in your dashboard. Paid accounts can use a custom domain or a subdomain ofngrok.apporngrok.dev.
Connect kubectl to your EKS cluster
Amazon EKS authenticates kubectl through the aws CLI.
Confirm your kubectl context points at the cluster before continuing:
kubectl to an EKS cluster, which walks through installing the aws CLI and running aws eks update-kubeconfig.
Install a sample application and Kubernetes ingress
Create a manifest file (for examplengrok-manifest.yaml) with the contents below.
This deploys the tinyllama demo LLM application from ngrok-samples/tinyllama and an Ingress that tells the ngrok Kubernetes Operator to route traffic on your reserved domain to it.
Replace NGROK_DOMAIN with the domain you reserved.
This is the URL you’ll use to access your service from anywhere.
showLineNumbers
Troubleshooting: If you get an error when applying the manifest, double-check that you’ve updated the
NGROK_DOMAIN value and try again.https://NGROK_DOMAIN) in a browser to confirm the tinyllama app is accessible from the internet.
Add security to your app
With the Traffic Policy system and theoauth action, ngrok manages OAuth protection entirely at ngrok.
ngrok’s network authenticates and authorizes all requests before allowing ingress to your endpoint, so you don’t need to add any services to your cluster or alter any routes.
To enable the oauth action, create a new NgrokTrafficPolicy custom resource and apply it to your entire Ingress with an annotation.
You can also apply the policy to a specific backend or as the default backend for an Ingress.
See the doc on using the Operator with Ingresses.
Edit your ngrok-manifest.yaml file with the following, leaving the Service and Deployment as they were.
Note the new annotations field and the NgrokTrafficPolicy CR.
ngrok-manifest.yaml configuration:
example.com.
Update the NgrokTrafficPolicy portion of your manifest after changing example.com to your domain.