# How to add external access with authentication to K8s deployment?

**URL:** <https://discuss.dgraph.io/t/how-to-add-external-access-with-authentication-to-k8s-deployment/5858>\
**Category:** Users\
**Created:** [January 19, 2020, 6:43pm UTC](https://discuss.dgraph.io/t/how-to-add-external-access-with-authentication-to-k8s-deployment/5858 "2020-01-19T18:43:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![marvin-hansen](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/marvin-hansen/32/2409_2.png) [@marvin-hansen](https://discuss.dgraph.io/u/marvin-hansen)\
**Post date:** [January 19, 2020, 6:43pm UTC](https://discuss.dgraph.io/t/how-to-add-external-access-with-authentication-to-k8s-deployment/5858/1 "2020-01-19T18:43:56Z")

</div>

## Cluster information:

Kubernetes version: 1.14.8-gke.12  
Cloud being used: GKE  
Dgraph version: Master (Jan/19/2020)

## Goal

Add authentication & TLS to access DGraph & Ratel securely from outside the cluster.

## Installation

I have installed Dgraph usings the latest helm chart and that keeps all services internally as ClusterIP. After the setup, I got the following pods:

web goci-dgraph-alpha ClusterIP 10.126.9.214 8080/TCP,9080/TCP  
web goci-dgraph-alpha-headless ClusterIP None 7080/TCP  
web goci-dgraph-ratel ClusterIP 10.126.10.114 8000/TCP  
web goci-dgraph-zero ClusterIP 10.126.2.66 5080/TCP,6080/TCP  
web goci-dgraph-zero-headless ClusterIP None 5080/TCP

## Verification

I can port-forward locally and acces the DB & Ratel like so:

kubectl port-forward dgraph-alpha-0 8080  
kubectl port-forward dgraph-ratel 8000

That stuff works.

## Complication

However, external access through a conventional LoadBalancer falls flat because in that case, there is no authentication and encrypted connection. Adding a [default ingress that allows easy auth, simple routing & TLS](https://docs.bitnami.com/kubernetes/how-to/secure-kubernetes-services-with-ingress-tls-letsencrypt/), however, also falls flat because it isn’t support in the DGraph Helm chart. I already opened an issue:

> <https://github.com/dgraph-io/dgraph/issues/4616>
>
> \*\*\[SOLVED\]\*\* I ended up adding a custom \[Kong\](https://konghq.com/products/kong-…enterprise/kong-kubernetes/?itm\_source=website&itm\_medium=nav) ingress \[controller \](https://itnext.io/kong-gateway-in-kubernetes-ad86981f93a5) with central routing, end to end connection encryption & http based authentication. 
> 
> \## Experience Report
> 
> Essentially, I wanted to add secure remote access to Dgraph deployed in a GKE cluster. 
> 
> \### What you wanted to do
> 
> Authentication & httpS connection encryption because it's not there. 
> 
> \### What you actually did
> 
> Still working around this crap. NGNIX reverse proxy has largely been replaced with ingress controller in k8s, but no ingress is there in the deployment yaml nor the helm chart. 
> 
> \### Why that wasn't great, with examples
> 
> It's not solved. 
> 
> \### What would be truly great. 
> 
> Add ingress support because it allows out of the box http authentication, https encription, and proper routing. Essentially, it enables everything that is missing right now. 
> 
> \### Any external references to support your case
> 
> Here is a walkthrough for authentication for another helm-chart that supports ingress controller. Adding authentication, encryption & routing is a piece of cake:
> 
> https://docs.bitnami.com/kubernetes/how-to/secure-kubernetes-services-with-ingress-tls-letsencrypt/
> 
> Documentation 
> http://kubernetes.io/docs/user-guide/ingress/
> 
> Ingress explained. 
> https://codeburst.io/kubernetes-ingress-simply-visually-explained-d9cad44e4419
> 
> Example values for ingress support.
> https://github.com/helm/charts/blob/master/stable/joomla/values.yaml

Adding a reverse http proxy, however, while feasible feels a little bit overkill here.

## Current try:

For now, the best I can do is to an ingress controller manually to access the alpha & ratel node from the outside world and that that is where the real headache starts.

First, I made a TLS secret like so:

> $ openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout tls.key -out tls.crt -subj “/CN=nginxsvc/O=nginxsvc”

> $ kubectl create secret tls tls-secret --key tls.key --cert tls.crt

Next, I wrote an ingress.yaml like so:

[https://github.com/marvin-hansen/ngnix-k8s/blob/master/Ingress.yaml](https://github.com/marvin-hansen/ngnix-k8s/blob/master/Ingress.yaml)

And I added a service.yaml like so:  
[https://github.com/marvin-hansen/ngnix-k8s/blob/master/service.yaml](https://github.com/marvin-hansen/ngnix-k8s/blob/master/service.yaml)

Then, I added an A record to the domain so that it points to the public IP of the LoadBalancer.

However, the above config doesn’t work and I get no connection.

What am I doing wrong?

Also, this is not about exposing the DB & Ratel, but ultimately about using an ingress controller for adding missing TLS & authentication to secure the DB while ensuring external access.

Also, is there a simpler way to add even basic security to ensure secured remote access to Dgraph?

I don’t mind sharing a working config, but getting there is surprisingly hard.

Any help is most welcome.

TIA

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex007/uploads/dgraph/original/2X/2/2b38fdece2abe5814f2e51bee69d1e67fc304b0a.png) [@system](https://discuss.dgraph.io/u/system)\
**Post date:** [February 18, 2020, 6:43pm UTC](https://discuss.dgraph.io/t/how-to-add-external-access-with-authentication-to-k8s-deployment/5858/2 "2020-02-18T18:43:57Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
