What you’ll need
- An existing remote or local Kubernetes cluster or the minikube CLI installed locally to create a new testing cluster.
- The Linkerd 2.x CLI installed locally (helper script, Homebrew, or binary in your
$PATH). - An ngrok account.
- kubectl and Helm 3.0.0+ installed on your local workstation.
- The ngrok Kubernetes Operator installed on your cluster.
- A reserved domain from the ngrok dashboard or API; this guide refers to it as
<NGROK_DOMAIN>.
Set up a local development cluster
-
Create a local Kubernetes cluster with minikube.
Assign it a profile named
ngrok-linkerdwith-p, and for the best compatibility with Linkerd, use thecontainerdcontainer runtime. -
Use
kubectlto verify your local cluster is running properly.
Deploy Linkerd’s service mesh to your cluster
Install the Linkerd CLI and deploy the control plane by following Linkerd’s getting-started guide, which coverslinkerd install --crds, linkerd install, and the pre- and post-install validation with linkerd check.
When linkerd check reports a healthy control plane, continue below to deploy a meshed application and route public traffic to it with ngrok.
Deploy an example microservices-based application
To demonstrate how Linkerd and the ngrok Kubernetes Operator integrate to add additional observability, security, and reliability into your cluster, you’ll deploy the Emojivoto demo application, which was developed by Buoyant, the company that originally developed Linkerd.-
Reserve an ngrok static subdomain for ingress from the Domains page of the dashboard if you don’t have one already.
This subdomain will be your
NGROK_DOMAINfor the remainder of this guide, and it provides a public route for HTTP, HTTPS, and TLS traffic. -
Deploy Emojivoto to the
emojivotonamespace. -
Add meshing by injecting Linkerd’s data plane proxies into each pod with a rolling deploy.
The following command retrieves all deployments from the previous step, injects the Linkerd proxy, and redeploys each pod.
-
Verify your data plane with
linkerd -n emojivoto check --proxy; it should end with a healthy status check. -
Create a new
emojivoto-ingress.yamlfile and add the following YAML content. It tells the ngrok Kubernetes Operator to route traffic on yourNGROK_DOMAINto theweb-svcservice you created when deploying Emojivoto.showLineNumbers -
Apply the
emojivoto-ingress.yamlmanifest you just created.Give your cluster a few moments to launch the necessary resources and for ngrok to pick up the new tunnel. -
Access your Emojivoto application by navigating to your ngrok domain (for example,
https://one-two-three.ngrok.app) in your browser.
Add Linkerd’s dashboard to verify meshing and mTLS
A service mesh adds observability and secures pod-to-pod traffic with mTLS, so confirm that your deployments and pods are properly meshed.-
Install the Linkerd dashboard.
-
To verify mTLS, restart all pods in the
emojivotonamespace to enable tapping. -
Use Linkerd’s tap feature: run
linkerd viz -n emojivoto tap deployto stream traffic from all pods in theemojivotonamespace to your terminal. The Emojivoto app generates traffic automatically, so you’ll see a consistent stream of requests.You should seetls=truein all of these requests between these pods. You can also usekubectl get pods -o wideto see the IP address of each pod, which lets you verify the source and destination of each request. For example, the request shown above is theweb-svcservice sending a POST request, with mTLS enabled, to theemoji-svcservice, which maintains and stores the votes database. -
Run
linkerd viz dashboard &to open the Linkerd dashboard in your browser. The default dashboard shows golden metrics (success rates, traffic, latencies per namespace) and the number of meshed pods per namespace. Some of the auto-generated traffic is designed to fail, which shows how to use the dashboard to debug pod-to-pod issues.
What’s next?
You’ve integrated a demo microservices application with Linkerd’s service mesh and ngrok’s Kubernetes Operator, adding security and reliability without configuring middleware, network interfaces, mTLS, or new monitoring services yourself. After deploying this local demo, you have a few options for moving forward.Clean up
To clean up from the work you’ve done for this local demo, you can stop and delete your minikube cluster with theminikube CLI: