Jamie Geddes
09/21/2023, 1:18 PMConor Barber (Airbyte)
09/21/2023, 2:44 PMapiVersion: <http://networking.k8s.io/v1|networking.k8s.io/v1>
kind: Ingress
metadata:
name: airbyte-server
namespace: ab
annotations:
<http://kubernetes.io/ingress.class|kubernetes.io/ingress.class>: "nginx"
<http://cert-manager.io/cluster-issuer|cert-manager.io/cluster-issuer>: "ca-issuer"
<http://nginx.ingress.kubernetes.io/ssl-redirect|nginx.ingress.kubernetes.io/ssl-redirect>: "true"
<http://nginx.ingress.kubernetes.io/configuration-snippet|nginx.ingress.kubernetes.io/configuration-snippet>: |
proxy_set_header "my-secret-header";
more_set_headers "Access-Control-Allow-Origin: *";
more_set_headers "Access-Control-Allow-Methods: 'GET, POST, OPTIONS'";
more_set_headers "Access-Control-Allow-Headers: authorization,content-type,X-Airbyte-Analytic-Source";
spec:
rules:
- host: my.internal.url
http:
paths:
- path: /api
pathType: Prefix
backend:
service:
name: ab-airbyte-server-svc
port:
name: http
tls:
- hosts:
- "my.internal.url"
secretName: "my-cert"
Note that this is not something we officially support in the OSS version, just some guidance to get you started down the path.
You would need to stand up this ingress alongside the airbyte installation in the same namespace (“ab” in this example), point it at the correct service, then whatever vpn solution you are using needs to resolve requests to my.internal.url pointing toward that ingress somehow. There are lots of options on how to do this, from internal load balancers to somehow designing a static ip for the service so that it always points to the ingress. The options will be very tailored to whatever setup you are usingConor Barber (Airbyte)
09/21/2023, 2:48 PMConor Barber (Airbyte)
09/21/2023, 2:49 PMConor Barber (Airbyte)
09/21/2023, 2:50 PMJamie Geddes
09/21/2023, 3:43 PM