Groups
Groups
Sign in
Groups
Groups
Kubernetes user discussion and Q&A
Conversations
Labels
About
Send feedback
Help
nginx-ingress, oauth and downstream services
406 views
Skip to first unread message
Christopher Schmidt
unread,
Jun 5, 2018, 8:57:52 AM
6/5/18
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Kubernetes user discussion and Q&A
Hi,
I just saw, that nginx-ingress supports OAUTH. See
https://kubernetes.github.io/ingress-nginx/examples/auth/oauth-external-auth/README/
What is the best solution to hand over Tokens or Usernames to the downstream services (defined by the Ingress resource)?
best Christopher
iain....@gmail.com
unread,
Jun 11, 2018, 6:23:49 AM
6/11/18
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Kubernetes user discussion and Q&A
Add this annotation to the downstream services ingress:
nginx.ingress.kubernetes.io/auth-response-headers
: x-auth-request-email, x-auth-request-user
Christopher Schmidt
unread,
Jun 12, 2018, 1:02:38 PM
6/12/18
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Kubernetes user discussion and Q&A
Thanks Iain,
adding the annotations was one part of the solution.
I basically followed this example:
https://github.com/kubernetes/ingress-nginx/tree/master/docs/examples/auth/oauth-external-auth
What I had to add to the oauth2_proxy was a --set-xauthrequest option.
Thanks for help
Reply all
Reply to author
Forward
0 new messages