Skip to main content
This guide shows you how to add public ingress to an app running on an RKE2 cluster managed by Rancher. You’ll use the ngrok Kubernetes Operator to route public traffic to the app through an encrypted tunnel. Rancher is an open source multi-cluster management platform from SUSE that DevOps teams use to run Kubernetes across on-prem and cloud environments. The ngrok Kubernetes Operator adds secure public ingress and middleware execution to the apps running on those clusters.

What you’ll need

  • One or more Linux hosts that meet Rancher’s requirements for operating as Kubernetes nodes. These can be on-prem or cloud virtual machines or bare-metal servers.
  • An ngrok account.
  • kubectl and Helm 3.0.0+ installed on your local workstation.
  • The ngrok Kubernetes Operator installed on your cluster. You can install it through Rancher, but this guide recommends the official Helm chart.
  • A reserved domain from the ngrok dashboard or API; this guide refers to it as NGROK_DOMAIN.

Set up your Rancher cluster

This guide assumes an RKE2 cluster managed by Rancher and reachable with kubectl. Disable Rancher’s built-in NGINX ingress when you create the cluster, since ngrok provides ingress. If you don’t have this yet:
  • Install the Rancher management server. Rancher’s single-node Docker install is a quick option for test and demonstration environments.
  • Create an RKE2 cluster and register your Linux nodes, following Rancher’s guide for launching Kubernetes on existing nodes.
  • Set up kubectl with the cluster’s kubeconfig, which you can copy from the Rancher dashboard.
Confirm your cluster is reachable before continuing:

Install a sample application

With the ngrok Kubernetes Operator running on your cluster, add a sample application. The Operator connects this application to ngrok, which routes external traffic to it through your Rancher-managed cluster.
  • Create a new Kubernetes manifest (tinyllama.yaml) with the contents below, replacing NGROK_DOMAIN with the domain you reserved. This manifest defines the tinyllama demo LLM application service and deployment, then adds an Ingress that tells the ngrok Kubernetes Operator to route traffic arriving on NGROK_DOMAIN to the tinyllama service.
    showLineNumbers
  • Apply the tinyllama.yaml manifest to your RKE2 cluster.
  • Access your tinyllama demo app by navigating to your ngrok domain (for example, https://NGROK_DOMAIN). ngrok’s network and the Operator route traffic to your app from any device or external network.

What’s next?

You’ve used the open source ngrok Kubernetes Operator to add public ingress to a Rancher-managed cluster and sample application without worrying about IPs, network interfaces, or VPC routing. Because ngrok offloads ingress and middleware execution to its global network, you can follow a similar process for Rancher-managed clusters in any on-prem or cloud Kubernetes environment, including EKS and GKE. To move this proof of concept toward production, back up your Rancher installation and migrate it to a high-availability cluster with Rancher’s backup, restore, and disaster recovery docs. Your ngrok ingress configuration carries over with no extra changes. Learn more about the ngrok Kubernetes Operator in the Kubernetes docs, or contribute to its development on the GitHub repository.