Warning
This page was translated from the original Japanese version by PLaMo Translate. The Japanese version is authoritative; the English translation may contain inaccuracies.
Publishing Workloads as Web Applications
Using PFCP’s WebApp Identity-Aware Proxy (WebApp IAP) feature, you can expose your workloads as web applications to the internet. The exposed web applications will automatically implement authentication for access, allowing only users belonging to the same organization to access them via web browsers.
This section explains how to expose web applications to the internet using WebApp IAP.
Note
If you wish to expose your workloads as web APIs accessible via CLI or other means, please refer to Publishing Workloads as Web APIs.
Publishing Web Applications to Your Entire Organization
-
Prepare the workloads you wish to publish along with their Service resources. For this example, assume you can access the workload by connecting to port 80 of the
example-svcService. -
Create an Ingress manifest using the following template:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: example-ingress spec: rules: - # Specifies the domain to assign to the Ingress. # Note: Unlike API exposure, you specify a subdomain of `ingress.pfcomputing.com`. host: example.<organization-name>.<cluster-name>.ingress.pfcomputing.com http: paths: - path: / pathType: Prefix backend: # Specifies the name of the Service and its port to be exposed. service: name: example-svc port: number: 80Warning
Subdomain Restrictions
For web application Ingresses, only the domain
*.<organization-name>.<cluster-name>.ingress.pfcomputing.comcan be used.For example, if your organization name is
fooand your cluster name issr1-01, the valid subdomain would be*.foo.sr1-01.ingress.pfcomputing.com. -
Access the Public Endpoints page in the portal and select your cluster name and namespace name. Verify that the subdomain of your created Ingress appears in the list of generated public endpoints.
-
Access the specified subdomain in your browser, log in 1, and then confirm that you can access the published service.
Restricting Web Application Access to Specific Organization Users
You can limit the visibility of your web application to specific users or user groups within your organization.
First, follow the “Publishing Web Applications to Your Entire Organization” instructions to create the Ingress. Then, for the Ingress you want to restrict access to, add the following annotations: In the value field, list the email addresses or names of the user groups you wish to allow access, separated by commas.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: example-ingress
annotations:
# To allow specific users, add the allowed-users annotation
ingress.preferred.jp/allowed-users: "foo@example.com, bar@example.com, baz@example.com"
...
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: example-ingress
annotations:
# To allow specific user groups, add the allowed-groups annotation
ingress.preferred.jp/allowed-groups: "foogrp, bargrp"
...
When both annotations are used, access will be granted to both the specified users and user groups.
Tip
To check which user groups you belong to, use the
kubectl auth whoamicommand. The items in the list ofGroupsthat start withoidc:org-<organization-name>/represent user groups. The portion following the/is the user group name. Use this part as the value for the allowed-groups annotation.
Tip
Organization administrators can manage user groups. See Managing Organization Users for details.
Verifying Access Restrictions
After applying the annotations, test accessing the Ingress to verify that access restrictions are working properly.
Warning
Changes to user groups may take time to propagate to existing logged-in user sessions. Try logging out and back in, or clearing your browser cookies.
When access restrictions are enabled, the Ingress will automatically include the nginx.ingress.kubernetes.io/auth-url annotation.
If this annotation is missing, review your manifests for any annotation typos.
Restoring Full Organization Access
Remove all the following annotations from the Ingress:
ingress.preferred.jp/allowed-usersingress.preferred.jp/allowed-groupsnginx.ingress.kubernetes.io/auth-url
Limitations
- Does not support exposing services using
NodePort,LoadBalancer, orExternalNameservice types - Request body size is limited to 10MB
-
If your browser contains valid authentication cache, the login process will be skipped. ↩