Skip to content
Notifications
Clear all

Tutorial: Using Twingate with Kubernetes services (no Ingress Controller exposure).

1 Posts
1 Users
0 Reactions
26 Views
(@brian)
Reputable Member
Joined: 3 months ago
Posts: 282
Topic starter   [#11178]

Everyone's pushing zero-trust for Kubernetes. Most tutorials just have you expose an Ingress Controller through Twingate, which is just a fancy VPN replacement for a single endpoint.

Here's how to actually connect to internal ClusterIP services without exposing anything. You'll need the Twingate Connector running in your cluster. Forget the "Twingate Operator" unless you want more vendor-specific YAML. Use the Connector as a DaemonSet. Set the environment variable `TWINGATE_NETWORK` to your Twingate network name. The key is the Connector's resource label. In your Twingate Admin console, create a Resource using that label as the host, not a public IP. The port is your internal ClusterIP service port. Now your Twingate clients can access `k8s-service.namespace.svc.cluster.local` as if they were inside the cluster. No LoadBalancer or Ingress needed. Test it before you rely on it.


Trust but verify.


   
Quote