I am trying to add basic auth to my kubernetes ins...
# replication-ask-ai
b
I am trying to add basic auth to my kubernetes installation, using helm. I have added to following to webapp
Copy code
ingress:
    annotations:
      <http://nginx.ingress.kubernetes.io/auth-type|nginx.ingress.kubernetes.io/auth-type>: basic
      <http://nginx.ingress.kubernetes.io/auth-secret|nginx.ingress.kubernetes.io/auth-secret>: basic-auth
      <http://nginx.ingress.kubernetes.io/auth-realm|nginx.ingress.kubernetes.io/auth-realm>: "Authentication Required"
      <http://nginx.ingress.kubernetes.io/proxy-send-timeout|nginx.ingress.kubernetes.io/proxy-send-timeout>: "600"
      <http://nginx.ingress.kubernetes.io/proxy-read-timeout|nginx.ingress.kubernetes.io/proxy-read-timeout>: "600"
      <http://nginx.ingress.kubernetes.io/proxy-connect-timeout|nginx.ingress.kubernetes.io/proxy-connect-timeout>: "600"
but it seems internal traffic does also get blocked, I cannot do any syncs anymore. What would be the best way to allow internal traffic, but add basic auth to external traffic?
k
Based on the information provided in the extracts, it seems that adding basic authentication to the ingress controller in Kubernetes can indeed cause issues with the Airbyte UI not loading properly or certain API calls not being made. This is likely due to the fact that the authentication is blocking internal traffic as well. Unfortunately, the extracts do not provide a direct solution to this issue. However, it's worth noting that in a [previous Slack conversation](https://airbytehq.slack.com/archives/C021JANJ6TY/p1669642035968719), it was mentioned that the Kubernetes deployments do not support the airbyte-proxy container, which is used in Docker deployments for handling authentication. Instead, you might need to find a solution to handle access in Kubernetes. One user mentioned that they found a workaround by adding annotations to the ingress controller, similar to what you have done. However, they did not provide specific details on how they configured it to allow internal traffic. For more detailed assistance, I would recommend reaching out to the Airbyte community on their [Slack channel](https://airbytehq.slack.com/archives/C021JANJ6TY/p1669642035968719) or [forum](https://discuss.airbyte.io/t/3120). They might be able to provide more specific guidance based on their own experiences and setups.
b
Should I then add a network policy so I can bypass the basic auth from internal traffic?