Skip to main content
This guide walks you through setting up a local cluster (or using an existing one) to mesh a microservices-based application with Linkerd and use the ngrok Kubernetes Operator to route public traffic through an encrypted tunnel to your cluster. The ngrok Kubernetes Operator is the official controller for adding secure public ingress and middleware execution to your Kubernetes applications with ngrok. Linkerd is an open source service mesh: a set of network proxies that handle communications between microservices and add observability, security, and reliability at the platform level. Linkerd enables mutual TLS (mTLS) between microservices for confidentiality and authenticity. When integrated, the ngrok Kubernetes Operator and Linkerd simplify your networking stack (internal and external traffic) and give you additional monitoring and resiliency.

What you’ll need

  • An existing remote or local Kubernetes cluster or the minikube CLI installed locally to create a new testing cluster.
  • The Linkerd 2.x CLI installed locally (helper script, Homebrew, or binary in your $PATH).
  • An ngrok account.
  • kubectl and Helm 3.0.0+ installed on your local workstation.
  • The ngrok Kubernetes Operator installed on your cluster.
  • A reserved domain from the ngrok dashboard or API; this guide refers to it as <NGROK_DOMAIN>.

Set up a local development cluster

  • Create a local Kubernetes cluster with minikube. Assign it a profile named ngrok-linkerd with -p, and for the best compatibility with Linkerd, use the containerd container runtime.
    If your OS does not support containerd, you can run minikube without specifying the container runtime.
    If minikube defaults to using the docker runtime, you will likely see an error related to root privileges when installing Linkerd to your cluster. The error includes a workaround to let you install Linkerd despite using the docker runtime.
  • Use kubectl to verify your local cluster is running properly.

Deploy Linkerd’s service mesh to your cluster

Install the Linkerd CLI and deploy the control plane by following Linkerd’s getting-started guide, which covers linkerd install --crds, linkerd install, and the pre- and post-install validation with linkerd check. When linkerd check reports a healthy control plane, continue below to deploy a meshed application and route public traffic to it with ngrok.

Deploy an example microservices-based application

To demonstrate how Linkerd and the ngrok Kubernetes Operator integrate to add additional observability, security, and reliability into your cluster, you’ll deploy the Emojivoto demo application, which was developed by Buoyant, the company that originally developed Linkerd.
  • Reserve an ngrok static subdomain for ingress from the Domains page of the dashboard if you don’t have one already. This subdomain will be your NGROK_DOMAIN for the remainder of this guide, and it provides a public route for HTTP, HTTPS, and TLS traffic.
  • Deploy Emojivoto to the emojivoto namespace.
  • Add meshing by injecting Linkerd’s data plane proxies into each pod with a rolling deploy. The following command retrieves all deployments from the previous step, injects the Linkerd proxy, and redeploys each pod.
  • Verify your data plane with linkerd -n emojivoto check --proxy; it should end with a healthy status check.
  • Create a new emojivoto-ingress.yaml file and add the following YAML content. It tells the ngrok Kubernetes Operator to route traffic on your NGROK_DOMAIN to the web-svc service you created when deploying Emojivoto.
    Edit line 9 of the manifest below (the NGROK_DOMAIN variable) with your ngrok subdomain (for example, one-two-three.ngrok.app).
    showLineNumbers
  • Apply the emojivoto-ingress.yaml manifest you just created.
    Give your cluster a few moments to launch the necessary resources and for ngrok to pick up the new tunnel.
    Troubleshooting: If you see an error when applying the manifest, double-check that you’ve updated the NGROK_DOMAIN value and try again.
  • Access your Emojivoto application by navigating to your ngrok domain (for example, https://one-two-three.ngrok.app) in your browser.

Add Linkerd’s dashboard to verify meshing and mTLS

A service mesh adds observability and secures pod-to-pod traffic with mTLS, so confirm that your deployments and pods are properly meshed.
  • Install the Linkerd dashboard.
  • To verify mTLS, restart all pods in the emojivoto namespace to enable tapping.
  • Use Linkerd’s tap feature: run linkerd viz -n emojivoto tap deploy to stream traffic from all pods in the emojivoto namespace to your terminal. The Emojivoto app generates traffic automatically, so you’ll see a consistent stream of requests.
    You should see tls=true in all of these requests between these pods. You can also use kubectl get pods -o wide to see the IP address of each pod, which lets you verify the source and destination of each request. For example, the request shown above is the web-svc service sending a POST request, with mTLS enabled, to the emoji-svc service, which maintains and stores the votes database.
  • Run linkerd viz dashboard & to open the Linkerd dashboard in your browser. The default dashboard shows golden metrics (success rates, traffic, latencies per namespace) and the number of meshed pods per namespace. Some of the auto-generated traffic is designed to fail, which shows how to use the dashboard to debug pod-to-pod issues.

What’s next?

You’ve integrated a demo microservices application with Linkerd’s service mesh and ngrok’s Kubernetes Operator, adding security and reliability without configuring middleware, network interfaces, mTLS, or new monitoring services yourself. After deploying this local demo, you have a few options for moving forward.

Clean up

To clean up from the work you’ve done for this local demo, you can stop and delete your minikube cluster with the minikube CLI:
Then remove the Linkerd CLI from your local workstation:

Extend your ngrok Kubernetes Operator and Linkerd integration

For production and real-world applications, explore installing Linkerd with Helm and production runbooks. In more complex scenarios, you can follow the same steps to install the ngrok Kubernetes Operator and configure an Ingress so ngrok handles routing and middleware for simplicity, global load balancing, and automatic encryption. See the ngrok Kubernetes Operator GitHub repository and project documentation for more details.