You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Nginx-Ingress Controller配置GitHub身份认证?

Hey there! Let's get your Nginx Ingress Controller set up with GitHub authentication on your Kubernetes 1.10.2 cluster. I’ve broken this down into straightforward steps that should fit your setup perfectly:

1. First, Create a GitHub OAuth Application

You’ll need to register an OAuth app with GitHub to handle the authentication flow:

  • Log into GitHub, head to Settings > Developer settings > OAuth Apps > New OAuth App
  • Fill in the details:
    • Application name: Pick something descriptive (e.g., "K8s Ingress GitHub Auth")
    • Homepage URL: The base domain of your cluster’s Ingress (e.g., https://your-cluster-domain.com)
    • Authorization callback URL: Must point to the oauth2-proxy’s endpoint, like https://your-cluster-domain.com/oauth2/callback
  • Once created, save the generated Client ID and Client Secret—you’ll need these later.
2. Deploy OAuth2 Proxy

Nginx Ingress doesn’t handle OAuth natively, so we’ll use oauth2-proxy as a middleman to manage the GitHub auth flow.

Step 2.1: Store GitHub Credentials in a Kubernetes Secret

First, create a secret to keep your GitHub client ID, secret, and a cookie encryption key safe:

kubectl create secret generic oauth2-proxy-secrets \
  --from-literal=client_id=YOUR_GITHUB_CLIENT_ID \
  --from-literal=client_secret=YOUR_GITHUB_CLIENT_SECRET \
  --from-literal=cookie_secret=$(openssl rand -hex 16)

Note: The cookie_secret is used to encrypt session cookies—we generate it with openssl here for convenience.

Step 2.2: Deploy the OAuth2 Proxy Deployment

Create a deployment YAML file (oauth2-proxy-deployment.yaml)—this version is compatible with K8s 1.10:

apiVersion: apps/v1beta1
kind: Deployment
metadata:
  name: oauth2-proxy
  namespace: default
spec:
  replicas: 1
  template:
    metadata:
      labels:
        app: oauth2-proxy
    spec:
      containers:
      - name: oauth2-proxy
        image: quay.io/oauth2-proxy/oauth2-proxy:v3.2.0
        args:
        - --provider=github
        - --email-domain=*  # Allow any GitHub email, or restrict to your org (e.g., "yourcompany.com")
        - --upstream=http://localhost:8080
        - --http-address=0.0.0.0:4180
        - --cookie-secure=true  # Set to false if you're not using HTTPS (not recommended for production)
        - --github-org=your-github-org  # Optional: Restrict access to members of this GitHub organization
        env:
        - name: OAUTH2_PROXY_CLIENT_ID
          valueFrom:
            secretKeyRef:
              name: oauth2-proxy-secrets
              key: client_id
        - name: OAUTH2_PROXY_CLIENT_SECRET
          valueFrom:
            secretKeyRef:
              name: oauth2-proxy-secrets
              key: client_secret
        - name: OAUTH2_PROXY_COOKIE_SECRET
          valueFrom:
            secretKeyRef:
              name: oauth2-proxy-secrets
              key: cookie_secret
        ports:
        - containerPort: 4180
          name: http

Deploy it with:

kubectl apply -f oauth2-proxy-deployment.yaml

Step 2.3: Expose OAuth2 Proxy with a Service

Create a service YAML (oauth2-proxy-service.yaml) to make the proxy accessible within the cluster:

apiVersion: v1
kind: Service
metadata:
  name: oauth2-proxy
  namespace: default
spec:
  ports:
  - name: http
    port: 4180
    targetPort: 4180
  selector:
    app: oauth2-proxy

Apply it:

kubectl apply -f oauth2-proxy-service.yaml
3. Configure Your Nginx Ingress to Use the Proxy

Now update your existing Ingress resource to route authentication requests to oauth2-proxy. Here’s an example (example-ingress.yaml):

apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: example-ingress
  annotations:
    nginx.ingress.kubernetes.io/auth-url: "http://oauth2-proxy.default.svc.cluster.local:4180/oauth2/auth"
    nginx.ingress.kubernetes.io/auth-signin: "https://your-cluster-domain.com/oauth2/start?rd=$request_uri"
    nginx.ingress.kubernetes.io/auth-response-headers: "Authorization, X-Forwarded-User"
spec:
  tls:
  - hosts:
    - your-cluster-domain.com
    secretName: your-tls-secret  # Replace with your existing TLS secret if using HTTPS
  rules:
  - host: your-cluster-domain.com
    http:
      paths:
      - path: /
        backend:
          serviceName: your-app-service  # Replace with your app's service name
          servicePort: 80
      - path: /oauth2
        backend:
          serviceName: oauth2-proxy
          servicePort: 4180

Let’s break down the annotations:

  • auth-url: Nginx sends requests here to check if the user is authenticated
  • auth-signin: Redirects unauthenticated users to the GitHub login flow
  • auth-response-headers: Forwards user identity headers (like the logged-in user) to your backend app

Apply the updated Ingress:

kubectl apply -f example-ingress.yaml
4. Test the Flow

Visit your cluster’s domain (e.g., https://your-cluster-domain.com). You should be redirected to GitHub’s login page. After logging in successfully, you’ll be sent back to your app—if you set a GitHub org restriction, only members of that org will be able to access it.

Quick Notes for Your Setup

  • Ensure your cluster has network access to GitHub’s API (critical for the OAuth flow to work)
  • If you’re not using HTTPS, set --cookie-secure=false in the oauth2-proxy args (but production environments should always use HTTPS)
  • Since you’re on K8s 1.10, we’re using the older extensions/v1beta1 Ingress API and apps/v1beta1 Deployment API—this matches your cluster’s version compatibility.

内容的提问来源于stack exchange,提问作者Johannes Bleher

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:55:08