What you’ll need
- A GKE cluster. If you don’t have one, Google’s cluster creation guide covers provisioning one.
- An ngrok account.
kubectland Helm 3.0.0+ installed on your local workstation.- The ngrok Kubernetes Operator installed on your cluster.
- A reserved domain from the ngrok dashboard or API; this guide refers to it as
<NGROK_DOMAIN>.
Connect kubectl to your GKE cluster
GKE authenticateskubectl through the gcloud CLI and the gke-gcloud-auth-plugin credential helper.
Google’s cluster access guide covers installing the plugin and configuring cluster access.
Once you’re authenticated, add the cluster to your KUBECONFIG:
kubectl can reach the cluster before continuing:
Install the ngrok Kubernetes Operator
If you haven’t already, install the operator with Helm. See the Kubernetes ingress quickstart for the steps and how to pass your ngrok credentials.Install a sample application
Create a manifest file (for example,ngrok-manifest.yaml) with the following contents.
This deploys the tinyllama demo LLM application.
Replace <NGROK_DOMAIN> in the highlighted section with your reserved domain.
On a free account, use a static subdomain; on a paid account, you can use a custom domain or a subdomain of ngrok.app or ngrok.dev.
showLineNumbers
Troubleshooting: If you get an error when applying the manifest, double-check that you’ve updated the
<NGROK_DOMAIN> value and try again.https://my-awesome-k8s-cluster.ngrok.app) in a browser to confirm the tinyllama app is accessible from the internet.
Add authentication to your app
With the Traffic Policy system and theoauth action, ngrok handles OAuth entirely on its network.
You don’t need to add services to your cluster or change any routes, because ngrok authenticates and authorizes requests before they reach your endpoint.
To enable the oauth action, create an NgrokTrafficPolicy custom resource and apply it to your Ingress with an annotation.
You can also apply the policy to a specific backend or as the default backend for an Ingress.
See the doc on using the Operator with Ingresses for details.
Edit your existing ngrok-manifest.yaml, leaving the Service and Deployment as they were.
Note the new annotations field and the NgrokTrafficPolicy CR.
ngrok-manifest.yaml configuration:
example.com.
Update the NgrokTrafficPolicy portion of your manifest after changing example.com to your domain.