Does anyone have any advice, or know of any guidan...
# replication-ask-ai
j
Does anyone have any advice, or know of any guidance regarding setting up ingress for Airbyte running in GKE? It appears I need to setup DNS, including a new domain name, but can this be done via a private zone in Cloud DNS, such that the URL only resolves within a VPN that's connected to a shared VPC project? So for example, I would want a domain name of the form airbyte.example.com that would resolve to the ingress controller only for users within my company's VPN.
c
The answer is contingent upon your vpn setup to some extent, so you need some sort of internal routing to the ingress. Here is a sample server nginx ingress:
Copy code
apiVersion: <http://networking.k8s.io/v1|networking.k8s.io/v1>
kind: Ingress
metadata:
  name: airbyte-server
  namespace: ab
  annotations:
    <http://kubernetes.io/ingress.class|kubernetes.io/ingress.class>: "nginx"
    <http://cert-manager.io/cluster-issuer|cert-manager.io/cluster-issuer>: "ca-issuer"
    <http://nginx.ingress.kubernetes.io/ssl-redirect|nginx.ingress.kubernetes.io/ssl-redirect>: "true"
    <http://nginx.ingress.kubernetes.io/configuration-snippet|nginx.ingress.kubernetes.io/configuration-snippet>: |
      proxy_set_header "my-secret-header";
      more_set_headers "Access-Control-Allow-Origin: *";
      more_set_headers "Access-Control-Allow-Methods: 'GET, POST, OPTIONS'";
      more_set_headers "Access-Control-Allow-Headers: authorization,content-type,X-Airbyte-Analytic-Source";
spec:
  rules:
    - host: my.internal.url
      http:
        paths:
        - path: /api
          pathType: Prefix
          backend:
            service:
              name: ab-airbyte-server-svc 
              port: 
                name: http 
  tls:
    - hosts:
      - "my.internal.url"
      secretName: "my-cert"
Note that this is not something we officially support in the OSS version, just some guidance to get you started down the path. You would need to stand up this ingress alongside the airbyte installation in the same namespace (“ab” in this example), point it at the correct service, then whatever vpn solution you are using needs to resolve requests to my.internal.url pointing toward that ingress somehow. There are lots of options on how to do this, from internal load balancers to somehow designing a static ip for the service so that it always points to the ingress. The options will be very tailored to whatever setup you are using
I don’t remember off the top of my head how many endpoints you will need, but you will almost certainly need a second ingress rule for the webapp service that just points at / and not /api
I think if you just expose / and point it at the webapp and /api and point it at the server that might be enough, though don’t quote me on that
note that if you want ssl (you probably do), this setup implies you’ve already configured and set up cert manager, and if you don’t have that you need to figure out some way to get ssl
j
Thanks @Conor Barber (Airbyte), appreciate the guidance. I think I need to reach out to our infrastructure team to figure out the best way to tackle this, as I don't have any visibility on how the VPN is configured currently.
👍 1