Skip to content
Browse Gluu Flex 6.4.0

Ingress Setup


tags:

  • administration
  • installation
  • helm
  • ingress
  • gateway-api

This guide explains how to expose and route external traffic to your Flex deployment, using either the modern Gateway API (recommended) or the legacy Ingress API.

#Networking Architecture Selection: Gateway API vs. Ingress

#Comparison Matrix

CapabilityGateway API (Recommended)Standard Ingress (Legacy)
Ecosystem SupportBroad: NGINX, Istio, Traefik, Envoy, kgateway, airlock-microgateway, ciliumLimited: NGINX, Istio
Audit gRPC APIYes (Note: NGINX requires Snippets enabled)No
Audit REST APIYesYes

#Which Pathway Should You Choose?

Selecting the correct networking model depends on your specific security and protocol requirements:

Choose Gateway API if:

  • You require gRPC auditing for your services.
  • You are using modern networking stacks like Cilium, Traefik, or Envoy.
  • You want a more expressive, role-oriented API that is the evolving standard for Kubernetes networking.

Choose Standard Ingress if:

  • You are operating in a legacy environment that only supports the standard Ingress controller.
  • You only require REST API auditing and do not use gRPC.
  • Your organization has strict policies against enabling NGINX Snippets (which are required for advanced Gateway API features).

The Kubernetes Gateway API provides a more expressive and extensible way to manage traffic.

#Install Gateway API CRDs

If your cluster does not have the Gateway API Custom Resource Definitions:

kubectl apply --server-side \
-f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/standard-install.yaml

#Install a Gateway Controller

You must have a conformant Gateway Controller installed.

Example using Nginx Gateway Fabric:

helm install ngf oci://ghcr.io/nginx/charts/nginx-gateway-fabric \
--create-namespace -n nginx-gateway

#Configure Gateway IP

Option A: Static IP (Recommended)

Reserve a static public IP with your cloud provider before installation. Add this IP to your override.yaml.

Option B: Dynamic IP

  1. Run initial Helm install without global.lbIp
  2. Wait for the cloud provider to assign an IP:
    kubectl get gateway -n gluu
  3. Add the IP to global.lbIp in override.yaml
  4. Run helm upgrade to apply

#Gateway API Configuration

Add this to your override.yaml:

global:
  lbIp: ""  # Add your static IP here
  fqdn: demoexample.gluu.org  # Your domain
  isFqdnRegistered: true  # Set to false if no registered domain
  gateway-api:
    enabled: true
  nginx-ingress:
    enabled: false
gateway-api:
  gateway:
    className: nginx  # Match your controller (nginx, istio, etc.)
    name: gluu-gateway
    httpPort: 80
    httpsPort: 443
    attachLbIp: false # Set the value to true if loadbalancer didn't assign IP address to the gateway automatically

#Option 2: Kubernetes Ingress (Legacy)

Use this if you prefer the traditional Ingress resource.

#Install Nginx Ingress Controller

helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
helm repo add stable https://charts.helm.sh/stable
helm repo update
helm install nginx ingress-nginx/ingress-nginx

#Get the Load Balancer Address

For GKE/AKS (IP address):

kubectl get svc nginx-ingress-nginx-controller --output jsonpath='{.status.loadBalancer.ingress[0].ip}'

For EKS (hostname):

kubectl get svc nginx-ingress-nginx-controller --output jsonpath='{.status.loadBalancer.ingress[0].hostname}'

#Ingress Configuration

Choose the configuration that matches your setup:

#With a Registered Domain (FQDN)

For GKE/AKS with a registered domain:

global:
  lbIp: ""  # Add LoadBalancer IP from previous command
  fqdn: demoexample.gluu.org  # Your registered domain
  isFqdnRegistered: true
nginx-ingress:
  ingress:
    path: /
    hosts:
      - demoexample.gluu.org  # Your domain
    tls:
      - secretName: tls-certificate
        hosts:
          - demoexample.gluu.org  # Your domain

For EKS with a registered domain (uses hostname instead of IP):

global:
  fqdn: demoexample.gluu.org  # Your registered domain
  isFqdnRegistered: true
config:
  configmap:
    lbAddr: http://YOUR-EKS-HOSTNAME.elb.amazonaws.com  # Add EKS hostname here
nginx-ingress:
  ingress:
    path: /
    hosts:
      - demoexample.gluu.org  # Your domain
    tls:
      - secretName: tls-certificate
        hosts:
          - demoexample.gluu.org  # Your domain

#Without a Registered Domain

If you don't have a registered domain, use the LoadBalancer address directly:

For GKE/AKS:

global:
  lbIp: ""  # Add LoadBalancer IP from previous command
  isFqdnRegistered: false

For EKS:

config:
  configmap:
    lbAddr: http://YOUR-EKS-HOSTNAME.elb.amazonaws.com  # Add EKS hostname here
global:
  isFqdnRegistered: false

#Next Steps

Proceed to Database Setup to configure persistence storage.

We use analytics cookies to measure which pages are useful, so we can improve them. They are only set if you accept. Essential cookies needed for the site to work are always on. See our privacy policy.