如何为Nginx-Ingress Controller配置GitHub身份认证?
Hey there! Let's get your Nginx Ingress Controller set up with GitHub authentication on your Kubernetes 1.10.2 cluster. I’ve broken this down into straightforward steps that should fit your setup perfectly:
You’ll need to register an OAuth app with GitHub to handle the authentication flow:
- Log into GitHub, head to Settings > Developer settings > OAuth Apps > New OAuth App
- Fill in the details:
- Application name: Pick something descriptive (e.g., "K8s Ingress GitHub Auth")
- Homepage URL: The base domain of your cluster’s Ingress (e.g.,
https://your-cluster-domain.com) - Authorization callback URL: Must point to the oauth2-proxy’s endpoint, like
https://your-cluster-domain.com/oauth2/callback
- Once created, save the generated
Client IDandClient Secret—you’ll need these later.
Nginx Ingress doesn’t handle OAuth natively, so we’ll use oauth2-proxy as a middleman to manage the GitHub auth flow.
Step 2.1: Store GitHub Credentials in a Kubernetes Secret
First, create a secret to keep your GitHub client ID, secret, and a cookie encryption key safe:
kubectl create secret generic oauth2-proxy-secrets \ --from-literal=client_id=YOUR_GITHUB_CLIENT_ID \ --from-literal=client_secret=YOUR_GITHUB_CLIENT_SECRET \ --from-literal=cookie_secret=$(openssl rand -hex 16)
Note: The cookie_secret is used to encrypt session cookies—we generate it with openssl here for convenience.
Step 2.2: Deploy the OAuth2 Proxy Deployment
Create a deployment YAML file (oauth2-proxy-deployment.yaml)—this version is compatible with K8s 1.10:
apiVersion: apps/v1beta1 kind: Deployment metadata: name: oauth2-proxy namespace: default spec: replicas: 1 template: metadata: labels: app: oauth2-proxy spec: containers: - name: oauth2-proxy image: quay.io/oauth2-proxy/oauth2-proxy:v3.2.0 args: - --provider=github - --email-domain=* # Allow any GitHub email, or restrict to your org (e.g., "yourcompany.com") - --upstream=http://localhost:8080 - --http-address=0.0.0.0:4180 - --cookie-secure=true # Set to false if you're not using HTTPS (not recommended for production) - --github-org=your-github-org # Optional: Restrict access to members of this GitHub organization env: - name: OAUTH2_PROXY_CLIENT_ID valueFrom: secretKeyRef: name: oauth2-proxy-secrets key: client_id - name: OAUTH2_PROXY_CLIENT_SECRET valueFrom: secretKeyRef: name: oauth2-proxy-secrets key: client_secret - name: OAUTH2_PROXY_COOKIE_SECRET valueFrom: secretKeyRef: name: oauth2-proxy-secrets key: cookie_secret ports: - containerPort: 4180 name: http
Deploy it with:
kubectl apply -f oauth2-proxy-deployment.yaml
Step 2.3: Expose OAuth2 Proxy with a Service
Create a service YAML (oauth2-proxy-service.yaml) to make the proxy accessible within the cluster:
apiVersion: v1 kind: Service metadata: name: oauth2-proxy namespace: default spec: ports: - name: http port: 4180 targetPort: 4180 selector: app: oauth2-proxy
Apply it:
kubectl apply -f oauth2-proxy-service.yaml
Now update your existing Ingress resource to route authentication requests to oauth2-proxy. Here’s an example (example-ingress.yaml):
apiVersion: extensions/v1beta1 kind: Ingress metadata: name: example-ingress annotations: nginx.ingress.kubernetes.io/auth-url: "http://oauth2-proxy.default.svc.cluster.local:4180/oauth2/auth" nginx.ingress.kubernetes.io/auth-signin: "https://your-cluster-domain.com/oauth2/start?rd=$request_uri" nginx.ingress.kubernetes.io/auth-response-headers: "Authorization, X-Forwarded-User" spec: tls: - hosts: - your-cluster-domain.com secretName: your-tls-secret # Replace with your existing TLS secret if using HTTPS rules: - host: your-cluster-domain.com http: paths: - path: / backend: serviceName: your-app-service # Replace with your app's service name servicePort: 80 - path: /oauth2 backend: serviceName: oauth2-proxy servicePort: 4180
Let’s break down the annotations:
auth-url: Nginx sends requests here to check if the user is authenticatedauth-signin: Redirects unauthenticated users to the GitHub login flowauth-response-headers: Forwards user identity headers (like the logged-in user) to your backend app
Apply the updated Ingress:
kubectl apply -f example-ingress.yaml
Visit your cluster’s domain (e.g., https://your-cluster-domain.com). You should be redirected to GitHub’s login page. After logging in successfully, you’ll be sent back to your app—if you set a GitHub org restriction, only members of that org will be able to access it.
Quick Notes for Your Setup
- Ensure your cluster has network access to GitHub’s API (critical for the OAuth flow to work)
- If you’re not using HTTPS, set
--cookie-secure=falsein the oauth2-proxy args (but production environments should always use HTTPS) - Since you’re on K8s 1.10, we’re using the older
extensions/v1beta1Ingress API andapps/v1beta1Deployment API—this matches your cluster’s version compatibility.
内容的提问来源于stack exchange,提问作者Johannes Bleher

